Security quotes of the week
I would say running each service on an individual machine is the most
secure. Running Each Service
on a separate VM is the second most, especially if you are using
SELInux/Svirt for separation of your VM's.
Third level is running each Service in a different container, (Again you
want SELinux for some separation).
Fourth is each Service running on the host, (Wrapped with SELinux).
Fifth setenforce 0.
— Daniel
J Walsh (Thanks to Peter Robinson.)
Control is moving back to the center, where powerful companies and governments are creating choke points. They are using those choke points to destroy our privacy, limit our freedom of expression, and lock down culture and commerce. Too often, we give them our permission—trading liberty for convenience—but a lot of this is being done without our knowledge, much less permission.
— Dan
Gillmor moves away from Apple, Google, and Microsoft products
Some will point out that an MITM [man-in-the-middle] attack on the NSA is
not really an 'MITM
attack on the NSA' because NSA outsources its web presence to the Akamai
CDN (see obligatory XKCD at right). These people may be right, but they also lack poetry in their souls.
— Matthew
Green (Thanks to Paul Wise.)
Encryption backdoors will always turn around and bite you in the ass. They are never worth it.
— Matthew
Green (in the same blog post)
