• 4 Posts
  • 227 Comments
Joined 2 years ago
cake
Cake day: January 16th, 2024

help-circle

  • JasonDJ@lemmy.ziptoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    462
    arrow-down
    3
    ·
    edit-2
    9 days ago
    • admitted the issue immediately

    • reassured users as to actual scope of breach, probable risk

    • provided recommended actions for users who think they may be impacted.

    • explained best-practices (enough for a laymen’s audience) and how they limited scope and impact.

    • did not deflect blame

    My god…I’ve got to hand it to plex. This is the perfect incident response letter. Love 'em or hate 'em, this is a good example for other CISOs.










  • HTTPS may be the official designation for the port, but it is the de facto standard port for TLS. Whatever you want to send over TLS, doesn’t really matter.

    HTTPS is just HTTP served over TLS (originally SSL).

    Step by step, if you were to analyze a web connection over port 443, you would see that the client first negotiates the TCP connection (via three-way handshake), then TLS, and it’s not till after TLS is established that HTTPS is negotiated.

    In that way, it’s kinda wrong to say it’s the HTTPS port. It’s really, nowadays, the TLS port. HTTP is just one of many protocols that can ride on top of it, and when we do that, we call it HTTPS.









  • Oh for sure, but at least Alexa’s rankings were rather transparent and somewhat trusted built up on a reputation.

    I hadn’t even realized Amazon bought and discontinued the service, but that’s clearly exactly the type of instance that needs to be guarded against. I’m sure that a big part of why Amazon wanted that Alexa gone was because it would show rising competition, and Jeff can’t have that.


  • But that just tells you all the people that have visited the site and downloaded a script.

    I find it hard to believe that OpenMandriva is the most popular distro. I distrohop quite a bit and never even came across it (currently using Nobora on my PC, KDE Neon in the living room, tumbleweed on the kids laptops (though I may move them to silverblue or another immutable), and Pop on my laptop. It takes me a minute when I sit at any console to remember which package manager is the right one)

    If you want honest results of actual use on general-purpose PCs…I’d wish for something like Alexa Page Rankings that could get deep enough to know Distro, but that’s not possible (I don’t think, without every distro having its own User Agent signature in the browsers), and Amazon bought Alexa and discontinued those services