Daily Shaarli

All links of one day in a single page.

June 29, 2022

Export PuTTY for Windows Sites

PuTTY for Windows saves all sites and configuration in Windows Registry.

Batch file to export sites and configuration from Windows Registry to a .reg file:

@echo off
::
:: export putty sites in ANSI mode
::
regedit /ea "o:\my documents\.ssh\putty-ini.reg" HKEY_CURRENT_USER\Software\SimonTatham\PuTTY

To later import, right-click on putty-ini.reg and select "import" or "merge".

More Implosion of Hutchinson's J6 Claims as Adam Schiff Steps in It Big Time on CNN – RedState

Julio Rosas
@Julio_Rosas11
·
Follow
A Secret Service source told me earlier: “FYI, I’m calling bullshit on the Secret Service story. You think none of us would have never heard of this as an internal rumor? No fucking way.”
Peter Alexander
@PeterAlexander
🚨 A source close to the Secret Service tells me both Bobby Engel, the lead agent, and the presidential limousine/SUV driver are prepared to testify under oath that neither man was assaulted and that Mr. Trump never lunged for the steering wheel.
7:32 PM · Jun 28, 2022 //

John Santucci
@Santucci
·
Follow
New: Source close to the Secret Service tells @PierreTABC to expect the Secret Service to push back against any allegation of an assault against an agent or President Trump reaching for the steering wheel.
6:57 PM · Jun 28, 2022 //

So, it would seem that that story didn’t even make it a day without imploding — must be a new record for fake, anti-Trump stories.

This should do in any credibility that the Jan. 6 Committee had left, if any. How can you not do the simplest thing and check with the agents and the other people before you throw these stories out there before the world? The answer is they didn’t care–they just wanted to skewer Trump and the truth didn’t matter, yet again. Why does anyone believe these liars anymore after all the lying they have done, not only over this but over Russia collusion and so many other things.

But even as the lie was falling apart, that didn’t stop Rep. Adam Schiff (D-CA) from trying to push the claim on CNN on Tuesday, with what little time he has left to push it before everyone figures out that it’s nonsense.

Erin Burnett asked him if he was able to corroborate Hutchinson’s claim with any of the agents, like Tony Ornato or Bobby Engel — the two agents Hutchinson named.

So, how did Schiff respond?

“I can’t comment on other testimony before the Committee,” Schiff claimed. Why not? You’re doing plenty of commenting on Hutchinson’s testimony. The reason he can’t is that he knows he doesn’t have testimony from the agents that backs this whole ridiculous story up. Yet even now, on CNN, as the story was falling apart, Schiff still was trying to work it and deceive the public, and tap dance on the answer. It was disgraceful.

Burnett asked Schiff if he had any concerns that the story wasn’t true, and he said he believed Hutchinson. //

Chelan Jim
2 hours ago edited
Of course the J6 committee is not going to corroborate a witness. The witness was saying what they want to hear. They are going to run with it. They follow the principle "Don't ask a question that you don't want to hear the answer."

Many email messages are sent from PHP scripts on a Plesk server. How to find domains on which these scripts are running if Postfix is used? – Plesk Help Center

Many email messages are being sent from PHP scripts on a server. How to find domains on which these scripts are running if Postfix is used?

When Security Locks You Out of Everything - Schneier on Security

Thought experiment story of someone who lost everything in a house fire, and now can’t log into anything:

But to get into my cloud, I need my password and 2FA. And even if I could convince the cloud provider to bypass that and let me in, the backup is secured with a password which is stored in—you guessed it—my Password Manager.

I am in cyclic dependency hell. To get my passwords, I need my 2FA. To get my 2FA, I need my passwords.

It’s a one-in-a-million story, and one that’s hard to take into account in system design.

This is where we reach the limits of the “Code Is Law” movement.

In the boring analogue world—I am pretty sure that I’d be able to convince a human that I am who I say I am. And, thus, get access to my accounts. I may have to go to court to force a company to give me access back, but it is possible.

But when things are secured by an unassailable algorithm—I am out of luck. No amount of pleading will let me without the correct credentials. The company which provides my password manager simply doesn’t have access to my passwords. There is no-one to convince. Code is law.

Of course, if I can wangle my way past security, an evil-doer could also do so.

So which is the bigger risk?

  • An impersonator who convinces a service provider that they are me?
  • A malicious insider who works for a service provider?
  • Me permanently losing access to all of my identifiers?

    I don’t know the answer to that.

Those risks are in the order of most common to least common, but that doesn’t necessarily mean that they are in risk order. They probably are, but then we’re left with no good way to handle someone who has lost all their digital credentials—computer, phone, backup, hardware token, wallet with ID cards—in a catastrophic house fire.

I want to remind readers that this isn’t a true story. It didn’t actually happen. It’s a thought experiment. //

Kent Brockman • June 28, 2022 11:04 AM

Any plan should take into account the possibility of memory loss (permanent or otherwise) due to shock or physical injury from an incident (car crash,fire, etc.,etc.) which would render moot a passphrase, plan, etc. unless written down and distributed to others (trusted implicitly, of course). This is to my mind at least, possibly the largest risk to even a well thought out scheme.

which one is best for PTR record: domain or hostname - Server Fault

The domain name in the email address is fairly irrelevant. The name used in the MX record doesn't really matter either. ISPs will often use something like mail.customer-domain.com in MX records, all pointing to one server whose real name is obviously not mail.customer-domain.com. What does matter is the servers actual hostname.

When talking via SMTP, your server will identify itself in the SMTP conversation using its full hostname, in this case 'server.example.com'.

The A record for 'server.example.com' should point to the IP of your server, and the PTR record for this IP address should match the hostname.

server.example.com. A 82.197.45.124

124.45.197.82.in-addr.arpa. PTR server.example.com
When Security Locks You Out of Everything - Schneier on Security

Ape • June 28, 2022 4:01 PM

It seems to me that the impact of the thought experiment resides in this: we have evolved backwards. Rather than insisting that it is robots who have to prove they are humans, we have evolved into a situation where humans have to prove they are not robots. Whatever happened to cognito ergo sum? It is now: I exist because the robot says I exist. If the robot says I don’t exist, I don’t exist. There is probably some fancy Latin way of saying it. So the heart of the problem is not “code is law”. The heart of the problem is that we have devolved law to programmers. Not just law, either, but the reality of our lives.

Now let’s imagine a different thought experiment. One where a person physically exists so they have an identity. In that cultural reality the question is not a question of token verification but a question of “Who is this person?”. They must be somebody. So we go about deciphering who they are. It is humans who have control, not the code, not the programmers, not the token. Maybe we even decide that the person is not the person who he was before the house burned down. Does it matter if the victim cannot regain his old identity if we give him a new one? Why the need for convergence on the old, on perpetuation?

It is time to regain control of our own identity.

When Security Locks You Out of Everything - Schneier on Security

Security Sam • June 28, 2022 11:25 AM

For safety the security abhors
With a mutually exclusive rule
Just like the set of double doors
Located in every bank vestibule.

First Time Visitor - HamiltonBook.com

At HamiltonBook.com, you save up to 80% on a large selection of in-stock titles in a wide variety of subject areas. You can buy with confidence because your satisfaction is guaranteed.

HamiltonBook.com LLC is a separate company that obtains its inventory from Edward R. Hamilton Bookseller Company. You can place orders online at HamiltonBook.com using MasterCard, VISA, or Paypal, however, you may still use this site to order by mail from Edward R. Hamilton Bookseller Company by choosing “Print & Mail - Check” in the shopping cart and mailing your order along with a check or money order.