Тёмный

NCSC Is Scanning Every Machine in the UK's Internet 

Mental Outlaw
Подписаться 679 тыс.
Просмотров 268 тыс.
50% 1

Опубликовано:

 

20 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 1,1 тыс.   
@isbestlizard
@isbestlizard Год назад
'opting out' of the voluntary government scanning sounds like a sure fire way of opting in for more intensive secret involuntary scanning o.o
@marcmedeiros8857
@marcmedeiros8857 Год назад
Ohhh. We can't scan your site/system? What do you have to hide? You just made a list somewhere for sure.....
@whatamievendoing
@whatamievendoing Год назад
@@marcmedeiros8857 Yeah I hate this already
@terrydavis8451
@terrydavis8451 Год назад
Thats what I was thinking? "Oh now Ima scan your shit way more".
@kreuner11
@kreuner11 Год назад
@@marcmedeiros8857 people keep talking about lists but nothing ever comes of it
@faxenmacher4633
@faxenmacher4633 Год назад
@@kreuner11 That's because you're not allowed to see the lists, and anyone who has them doesn't want to throw away their 70k a year job. Jk. Nah, in the UK, the terrorjism lists don't even really do much. Our system kinda runs on a 'no complaint, no harm, no fowl' basis. It's why I can punch a guy on CCTV and be fine, but if you call a politician a Nazi it'll be *a* fine.
@holeefuk8535
@holeefuk8535 Год назад
I hecking love governments keeping us safe and totally never doing anything in violation of human rights. Heck yeah!
@aldrinmilespartosa1578
@aldrinmilespartosa1578 Год назад
Yeah... totally safe lol.
@ORLY911
@ORLY911 Год назад
I mean in this case its probably a good thing. private companies arent going to spend money on this at least on this scale, this is a step to a bit less data breaches being exploited. We already know they're watching us they might as well keep an eye out on hackers instead. Until the day we get a fool proof system this is unfortunately going to be somth we'll have to deal with.
@kesho1516
@kesho1516 Год назад
Government is 100% safe and effective, with unexplainable coincidences
@w花b
@w花b Год назад
@Nobody whoops, I pinged you, my bad!
@typingcat
@typingcat Год назад
All I want the government to is securing their own IT infrastructures first. They can't do that, and why bother with civilian infrastructures?
@龗
@龗 Год назад
wait so if NCSC scans servers its "for safety" and "to discover zero day vulnerabilities" but when I do it its "insane" and illegal!?
@xyz3524
@xyz3524 Год назад
@yesAre you sending those messages manually or is it a bot?
@Whatthellisthisthing
@Whatthellisthisthing Год назад
Well scanning is not actually illegal, it’s the exploiting that crosses that line.
@mongolman3492
@mongolman3492 Год назад
​@@xyz3524 its a bot man, it's on every popular youtube video, the same comment from different accounts
@santiagoeltoma5122
@santiagoeltoma5122 Год назад
Goverments have the violence monopoly, the can do literally what ever they want
@michaelatlas2341
@michaelatlas2341 Год назад
@@Whatthellisthisthing go scan the government's servers, let's test if what you said is true
@gamin9wizard945
@gamin9wizard945 Год назад
Fun fact about "Wix" since you mentioned their brand - In my country their advertising literally consists of putting their name into a pun regarding "self-satisfaction" (yes, *that* suggestive kind of self-satisfaction). Their ads are beyond cringe.
@dimasskarabas
@dimasskarabas Год назад
lmfao
@Zenchyi
@Zenchyi Год назад
"sich einen wixen"? never seen those in germany
@kreevisful
@kreevisful Год назад
What country do you live in by chance? I want to laugh at those ads!
@lptimey
@lptimey Год назад
„Ich wixe jetzt“ oder so war’s doch, oder?
@bdnugget
@bdnugget Год назад
Lmao wixen You mean this one right? ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-afOPTRKZvko.html Ignore what that yes dude posted, it's some video about potatoes
@glitchy_weasel
@glitchy_weasel Год назад
I find that this is a very interesting government program that can be actually useful for once. That is of course, if the NCSC actually upholds their word and no, you know, keep the pen-testing data for themselves to misuse.
@masenko4519
@masenko4519 Год назад
Yeah that's the thing...
@damnedmadman
@damnedmadman Год назад
That's exactly why they're doing it. It's naive to think they do it just to help. No, they're doing this to have a legal excuse to scan all of their internet in search of potential "criminals", like people serving some crypto, torrents, tor, etc.
@alifelessrock48
@alifelessrock48 Год назад
These are public websites on the internet, so they are allowed to do scanning. Of course penetration testing isn't the best thing ever, and keeping the data is definitely a risk you take when you opt in.
@ErevanDB
@ErevanDB Год назад
@@resyntax I trust the US system more, but I'd prefer it if we had different people in charge.
@ffwast
@ffwast Год назад
@@resyntax I don't trust the uk government at all and think it's silly that you do, no matter how little.
@linuxtuxvolds5917
@linuxtuxvolds5917 Год назад
For youtube: This video was: Comforting. Entertaining. Feel-good. Educational. Heartwarming. Wholesome.
@NubeBuster
@NubeBuster Год назад
For @linux_tuxvolds: This comment was: Bot-like. Interesting. Questionable. Unique. Using punctuation.
@uniqueprogressive9908
@uniqueprogressive9908 Год назад
This comment format was: Already seen. Botted. Fits every video. Copied and Pasted
@PierreMiniggio
@PierreMiniggio Год назад
3:42 The main thing IMO is that people using these kind of websites usually are in sales / marketing, and are very aware that using these services will be the fastest way for them to have a website up and running so that they can then focus on finding / building the product they want to sell.
@RoboPutinPresidentinCE
@RoboPutinPresidentinCE Год назад
Exactly you dont want to be dealing with webb development and pen testing if youre trying to get a business idea going. Sure you could but that has time for when you already kmow that you can invest more time into your idea and the infrastructure behind it.
@bonbonpony
@bonbonpony Год назад
Lemme have a car, but I can't really drive it, so… can I haz car? :q
@counterleo
@counterleo Год назад
a hacked/shutdown website, ransomware and leaked customer data don't do well for reputation and revenue tell the marketing bois that security is like insurance, you don't need it until you do
@PierreMiniggio
@PierreMiniggio Год назад
@@counterleo If you're a brand starting out, picking between a Shopify (or alike) and building a website from scratch makes almost no difference when it comes to security. Migrating to your own thing is a decision you can make later once your business is stable enough. Marketing people are not "wrong" for picking that choice. It financially, and timely, and risk taken into account makes the most sense in very many situations.
@silak33
@silak33 Год назад
@@bonbonpony no, having to learn web development from scratch is more like if you were asked to build a car before you were allowed to use it :P
@sammydepresso
@sammydepresso Год назад
British people really read 1984 (a book about an extremely authoritarian Britain) and said I like this, let’s do it.
@skinwalker69420
@skinwalker69420 Год назад
The government website scanning, even if it is for a good cause and they're completely open about what they're doing is still very spooky. I'm glad I live in the USA where they at least lie about it and pretend they don't do it. Edit: it was a joke
@ME0WMERE
@ME0WMERE Год назад
I'd rather them scan my system and tell me about it than them scan my system and pretend they're not doing it
@UnspeakableNightmare
@UnspeakableNightmare Год назад
ok yankee
@skinwalker69420
@skinwalker69420 Год назад
@@UnspeakableNightmare it was a joke you mong
@AcidiFy574
@AcidiFy574 Год назад
Hey you high or something
@skinwalker69420
@skinwalker69420 Год назад
@@AcidiFy574 usually
@ares106
@ares106 Год назад
“They have an option to opt out of being scanned” I wouldn’t want to voluntarily place myself on that list LOL
@jan_Sanku
@jan_Sanku Год назад
Nah if enough ppl do it, it won't be sus. You gotta drop the mindset of not getting on that list, because then the ppl who actually want to opt out will be sus
@escapetherace1943
@escapetherace1943 Год назад
why? I'd opt out. If nobody stands up it just happens. What can they do if you say no? Nothing dude
@nosuchthing8
@nosuchthing8 Год назад
@@escapetherace1943 they forward you to a super secret group that goes over your history even deeper..
@escapetherace1943
@escapetherace1943 Год назад
@@nosuchthing8 who cares, let them. Holy shit how scared is everyone, stand up for your rights
@robotswithgunzlol
@robotswithgunzlol Год назад
"They said leave me alone" is not grounds in the UK to subject someone to further surveillance. Quite the opposite. Offering an opt out, and then not observing said opt out will just land the government in court and they know it.
@happyfella89
@happyfella89 Год назад
No thank you. 11:40 I believe this is a big step in the wrong direction. I can't speak directly for what the UK does since I'm in the US, but the argument should be around the NSA performing the scan in the first place, not being complacent that "well they do it anyways so might as well get some benefit from it". Eff the Patriot Act. Love your content even though I disagree with you here.
@josephbrandenburg4373
@josephbrandenburg4373 Год назад
The problem is, they're gonna do it regardless of whether it's legal or not.
@happyfella89
@happyfella89 Год назад
@@josephbrandenburg4373 I agree that's a problem, a big one.
@Will-kt5jk
@Will-kt5jk Год назад
If they don’t run the scans, can’t they just pay for Shodan though? It’s not just Gov’ts that are running scans (albeit Shodan isn’t ‘looking for new 0-days’, but is a fairly comprehensive mass scan) so a lot of the info is already out there, right?
@happyfella89
@happyfella89 Год назад
@@Will-kt5jk the infrastructure, mainly the policy, is what bothers me. In 10 years once everyone is used to the government performing these "helpful" scans, it always goes a step further. "We need to scan your db now for any *thing, you have nothing to hide so why do you care if we scan your file system, this is for the greater good, for safety." That door should remain tightly closed.
@tonyblack3401
@tonyblack3401 Год назад
It’s like police just staring in all your windows, walking around your garden, asking your neighbours about you, looking in your garage… all without a warrant. To keep you “safe”.
@damnedmadman
@damnedmadman Год назад
Exactly. Totalitarian.
@aeases-
@aeases- Год назад
Nah its more like they're walking around a parking lot looking for old cars that have vulnerabilities that make them easy to break into, and leaving you a polite little note telling you about it and how to fix it instead of waiting for the thief to notice and just steal your car.
@damnedmadman
@damnedmadman Год назад
@@aeases- No, your analogy is wrong. Seems like you don't know what pentesting is. The act of "looking" here means making multiple connections and requests to every machine out there, in order to obtain as much information as possible about its vulnerabilities. And it's done by a government that can easily use this information against the very people it claims to protect. If it were done by an NGO then I wouldn't be worried.
@aeases-
@aeases- Год назад
@@damnedmadman That is the whole point, they are making basic NMAP requests that any rando on the internet might make to determine whether outdated, known insecure software, e.g. older version of Java vulnerable to Log4J, are still being run and are notifying the technically inept that this is an issue and directing them on how to solve it. It makes self-hosting at least a little bit more viable to someone who doesn't keep up w/ the latest vulnerabilities/keep their server up to date. though yea I do agree it would be better for a NGO to do it since it does provide them a bunch of data that they wouldn't have had otherwise which they might misuse. though that can be kinda avoided by just not accepting connections from the IP's that they say they use.
@bonbonpony
@bonbonpony Год назад
I can already feel the scammers getting ready to send fake NCSC notifications to people with some shady instructions about what they should do to increase their security, which will in fact decrease their security or let them install some malware :q
@UNSCPILOT
@UNSCPILOT Год назад
Reminds me of Nintendo telling people to "forward all ports" on their router because they are too daft to fix the multiplayer games on switch, wouldn't be shocked if something like that is done to fool gullible idiots into opening their network wide for easy exploitation
@l3g3ndarybanana
@l3g3ndarybanana Год назад
Microsoft did too for years. Specifically remember several forums advocating putting your Xbox IP in the DMZ window just to get matches on halo.
@UNSCPILOT
@UNSCPILOT Год назад
@@l3g3ndarybanana didn't know that, then again my net back then was so aweful there was no helping it, that's hilarious that console makers are just so terrible at networking and security
@MrJellekeulemans
@MrJellekeulemans Год назад
I disagree with what you said about shopify. I think it's great to abstract away security details because it just makes the chance of making a mistake resulting in a vulnerability much smaller. Dont go code your own shopping system if you're not familiar with basic app security.
@aaaaaa-hh8cq
@aaaaaa-hh8cq Год назад
He says a lot of bs don't mind him
@decreer4567
@decreer4567 Год назад
That’s why you use a payment system like Stripe or an api. It’s just as vulnerable as Shopify. In fact they may even be using that behind the hood.
@MrJellekeulemans
@MrJellekeulemans Год назад
@@decreer4567 stripe still requires you to use asymmetric encryption keys and stuff..
@LainShotCS
@LainShotCS Год назад
Germany already does this, and if you run a server there using insecure technologies you will get a polite letter explaining what they detected and how it can be fixed.
@24hhhhours
@24hhhhours Год назад
@@pkelly20091 isp
@hhvhhvcz
@hhvhhvcz Год назад
ye and if you run Bit bittorrent over your net, you get fined for "possible piracy", such a bs
@newaccountbecauseytvanceds1465
@@hhvhhvcz ironic, my fav movie pirating site is hosted in germany.
@longnamedude3947
@longnamedude3947 Год назад
@@pkelly20091 Well, if your server is hosted on premise then they look up the details of all ISP's to find out who provides service to that premise and then ask for the contact details that were provided when the owner of the ISP service originally signed up/their bank details (depends how you pay for your internet service). If you server is hosted off-site they contact the people hosting your off-site services to try and work out who owns that server and then contact you once they've worked out who owns it. This is why anonymous sign-up services are heavily disliked by government entities, because anybody could sign-up from anywhere and they can't easily track you down, that isn't to say they couldn't track you down if they wanted to, only that it is unlikely that as a regular person you will be worth the financial outlay of trying to work out who you are only to discover you just want to host an off-site encrypted backup elsewhere or something equally boring and average.
@purdysanchez
@purdysanchez Год назад
The headline made it sound like the NCSC was compelling everyone in the UK to give them access to their machines. I see nothing wrong with them doing pen testing and reaching out to system admins/ owners about thei findings.
@nackscrack4593
@nackscrack4593 Год назад
100% intentional gotta get clicks somehow.
@FortressLordJP193
@FortressLordJP193 Год назад
If the UK or France do something it legally has to be spun as a horror story and spread on Reddit.
@DudeSoWin
@DudeSoWin Год назад
learn2code: "UK just asked every ISP to tear a gaping hole in their firewalls and traffic shaping to install a police lane for those who drive the sh0rt bus." I suggest you run a honeypot with every vulnerability they mention on that site. And when they call you out for camouflaging the vulnerable, tell them to f' off with their treason. (RU-vid is clamping down hard on this dialogue.)
@voncheeseburger
@voncheeseburger Год назад
As a UK resident with a public facing server, I'm totally happy about this. They're only doing what anyone else on the internet can do, poke my public vulnerabilities, and tell me about them so I can mitigate. I'd say this is one of the better ways to spend taxpayer money in the UK lmao
@acex222
@acex222 Год назад
@@thatradioboy to what? Something they could have kept their mouths shut about and done anyway? Something millions of servers do all day every day?
@nuggert
@nuggert Год назад
​@@acex222 let's see how long this data stays secure
@halogeek6
@halogeek6 Год назад
@@quercus3290 not if you cut the plug. Cant track what's not part of the system.
@brymstoner
@brymstoner Год назад
@@halogeek6 i see a bright future for you in air-gapping air.
@arstulex
@arstulex Год назад
@@quercus3290 _"The government if it so chooses could remote into your computer, smart phone any time it likes without you ever knowing."_ [citation needed]
@More_Row
@More_Row Год назад
"It's for your safety"
@lelonfurr1200
@lelonfurr1200 Год назад
do YOU really believe that?
@paegr
@paegr Год назад
@@lelonfurr1200 It doesn't matter if you believe it or not, they will continue because it's been proven time and time again that absolutely nobody will stop them. Our children will curse our names for allowing the NWO
@More_Row
@More_Row Год назад
@@lelonfurr1200 no, obviously not.
@yoyogre
@yoyogre Год назад
You do realize that scanning the whole range of possible IP addresses is absolutely trivial? It only takes about half an hour. Even if you're going to do the most thorough port scan it takes less than a day. So if you have any machine with an IP address, it's going to be scanned anyway, multiple times a day, from the script kiddie to the state actor. At least, the NCSC lets you opt out of it, but you would be naive to think the MI6 (or really any other alphabet agencies) hasn't been already doing it for years.
@generalshepherd457
@generalshepherd457 Год назад
we are from the government and we are here to help...
@N.S.A.
@N.S.A. Год назад
The consequences will never be the same.
@varsityathlete9927
@varsityathlete9927 Год назад
you dun goofed
@GhostOfSnuffles
@GhostOfSnuffles Год назад
I'm reporting the cyber police to the cyber police.
@jackalenterprisesofohio
@jackalenterprisesofohio Год назад
NNOOOO NOT THE " _NATIONAL SCARY ASSOCIATION_ ."
@sciencecat5140
@sciencecat5140 Год назад
Mmmmmm yessss big mama watching us. I bet she worried about our safety.
@xp8969
@xp8969 Год назад
Trump's 2018 Cybersecurity and Infrastructure Security Agency Act has had the government controlling the internet here in the United States ever since Trump signed it into law
@The_10th_Man
@The_10th_Man Год назад
They didn’t mean your safety.
@MarekParek68
@MarekParek68 Год назад
this man is again killing me with his skill of making the perfect wallpapers
@deidara_8598
@deidara_8598 Год назад
This is kinda like the Police coming to your house and shaking your door handle to make sure you've locked the door to keep you safe from burglarly. And one can't help but think there's an ulterior motive here.
@damnedmadman
@damnedmadman Год назад
💯
@117johnpar
@117johnpar Год назад
That, except all your tax documents from the last 5 years and all your padlock codes fall out of the mail slot when they do it and they pick it all up and file it in your profile folder.
@vorynrosethorn903
@vorynrosethorn903 Год назад
Considering what the UK police are like you'd be right to.
@deidara_8598
@deidara_8598 Год назад
@@vorynrosethorn903 The Snowden documents revealed that the GCHQ have been close partners with the NSA when it comes to developing their SIGINT and mass surveillance capabilities. No doubt they will abuse this for a similar purpose. It gives them lots of data which can be used to find commonly vulnerable services are being used, which can help them divert effort towards developing vulnerabilities for that specific platform/software/service. Also it enables them to more easily mask active offensive cyber operations as passive port scanning by an automated system. Now when the GCHQ port scans your servers you don't know if they're doing it as a control or if they're doing it because they are actively looking for ways to break into your system. It's a genius move, really.
@supernenechi
@supernenechi Год назад
We have become too suspicious of our own governments these days. Why is that? Because every single little mistake they make is blown up on Twitter and thus outshines the thousands of great achievements maybe? I doubt there is an ulterior motive, the government isn't evil like China's. If they were evil you would know by now.
@washboardman7435
@washboardman7435 Год назад
It would be fine if this was opt-in, but I doubt King Britbong would give a shit about opt-out. And if someone defends the feds scanning your public boxes under the "plain view" doctrine, I'm defending hacking back under the second amendment.
@mudi2000a
@mudi2000a Год назад
Well if you can see where they are coming from you can just serve them some hello world website and not the real one.
@wclifton968gameplaystutorials
0:45 that's funny because the UK has terrible security practises when it comes to computers. When I was at high school I successfully installed a copy of Kubuntu on a school computer without permission because the sysadmins were dumb enough to have the 1st boot device be USB instead of Hard Drive or Network, once they found the install they reinstalled Windows 7 and changed the boot order on all PCs in the canteen where the PC was located; I repeated the same thing but at College a year later on a HP AIO computer in a GCSE English Language classroom but these sysadmins were even dumber because they didn't password protect the computer's bios but this time I installed KDE Neon and this was all around 2017-2018, within a week they had reinstalled Windows 7 and password protected the computer's bios. It is safe to say that I do not care for or trust any part of GCHQ incl. the NCSC or MI5 or MI6 or any other Government Organisation... EDIT: I should also note that I live in a suburb of London, GB
@XYZW
@XYZW Год назад
school sysadmins are just generally braindead
@SomeRandomPiggo
@SomeRandomPiggo Год назад
Just as bad if not worse here in the South West XD
@龗
@龗 Год назад
i live in turkey and the bios of all computers were unprotected
@jbillion
@jbillion Год назад
Public schools in general don't have great security. In the US our IT person was just some random lady that didn't have any certifications or anything, she just happen to teach the typing/basic information systems class. This was a high school with 2000 students.
@Silentguy_
@Silentguy_ Год назад
BIOS protection has always been garbage anyways because of the need to manually set it up across potentially thousands of devices one at a time. Even with a team of people that’s still one hell of a time consumer and the more people you have is just more chances for that password to get out. That’s one of the reasons why schools specifically have gone to things like Chromebooks, which were built from the ground up to be managed by a centralized system over a network.
@AvalonAlgo
@AvalonAlgo Год назад
So what colour does the NCSC glow in?
@ttheno1
@ttheno1 Год назад
red
@sarunotaslt
@sarunotaslt Год назад
cycles between red and blue
@NKillBruh
@NKillBruh Год назад
i think they glow black with white... reminds me of a type of tea which i cant pin point
@The10thdrago
@The10thdrago Год назад
I'm dead
@sigmamale4147
@sigmamale4147 Год назад
@@bindkey all alphabet boys do
@Whatthellisthisthing
@Whatthellisthisthing Год назад
Really not something Shodan or Census isn’t doing already. If they find a vulnerability and reach out to you though, that’s interesting.
@sierra991
@sierra991 Год назад
literally this. why is everyone so mad?
@ryshellso526
@ryshellso526 Год назад
Funny enough. I used to watch UK citizens from their home cameras. Your tea is shite by the way.
@wristocrat
@wristocrat Год назад
the uk has insanely bad internet privacy. so many unlawful arrests
@someguy4405
@someguy4405 Год назад
@RR Oh shit, I can’t believe they’d do that. The rule of law is basically compromised.
@xp8969
@xp8969 Год назад
Trump's 2018 Cybersecurity and Infrastructure Security Agency Act has had the government controlling the internet here in the United States ever since Trump signed it into law
@Kyle-xv5kv
@Kyle-xv5kv Год назад
It's because boomers rule the UK and have no idea about privacy and IT.
@oz2362
@oz2362 Год назад
Could you elaborate?
@sabersz
@sabersz Год назад
@@oz2362 people get arrested for mean words on twitter.
@ssj1260
@ssj1260 Год назад
You could win an award for how to say something in 10,000 words that could be said in 100
@JorvikBerserkir
@JorvikBerserkir Год назад
That Kali wallpaper got me good
@cgme9535
@cgme9535 Год назад
Lol yeah 😂
@michaelatlas2341
@michaelatlas2341 Год назад
Privacy in the UK is so non existent that the government scanning you is normal. It's not the NSA does bad things and government in UK doesn't, in the UK It's the golden standard to have the government do everything. Remember, not saying something out loud isn't keeping a secret, and the UK gov knows that better than anyone. Not that people in the UK would give a shit.
@MrVecheater
@MrVecheater Год назад
The UK is Europe's North Korea
@NekoBoyOfficial
@NekoBoyOfficial Год назад
And there's far less uproar than the US.
@egg5474
@egg5474 Год назад
remember MI6 spies on US citizens as a proxy for minecraft youtubers
@newaccountbecauseytvanceds1465
Something needs to change, but that won't happen until all the current UK politicians die out. Making way for a generation that knows about Internet privacy and everything related to it.
@failureforbeginners10
@failureforbeginners10 Год назад
@@newaccountbecauseytvanceds1465 A politician understanding internet privacy will only lead to them more proactively trying to undo it. Why would any politician bother giving more rights to people when it's clear you can give a good sounding excuse to not lose any votes.
@carrottopadc
@carrottopadc Год назад
United Kingdom is competing with India for least free internet in a developed country
@hanqnero
@hanqnero Год назад
Implying India is a developed country.
@carrottopadc
@carrottopadc Год назад
@@hanqnero well, some parts LOL
@carrottopadc
@carrottopadc Год назад
@kevin you got me🇬🇧
@fourseven9121
@fourseven9121 Год назад
@kevin American?
@xp8969
@xp8969 Год назад
Trump's 2018 Cybersecurity and Infrastructure Security Agency Act has had the government controlling the internet here in the United States ever since Trump signed it into law
@leavemealone535
@leavemealone535 Год назад
Just like the RIPE spooks constantly portscanning every publicly accessible device I own. You should do a video on them. Definitely a government operation.
@Anon_Spartan
@Anon_Spartan Год назад
That title made me think the UK was doing something really nefarious. I mean they probably still are. Would you ever consider making a guide to having a home media server, specifically which programs/apps are best. My ideal would be to let me use my phone to stream something to a chromecast/smart TV (useful for home gym workouts).
@BALLOOROOM
@BALLOOROOM Год назад
You can stream from an iPhone using Airplay or use the Android equivalent. On a computer set up file sharing SMB for your media folders and create a sharing account for authentication then use VLC player to connect to server, put in the local IP address and enter the credentials for the sharing account you created.
@Anon_Spartan
@Anon_Spartan Год назад
@@BALLOOROOM I'll give that a shot. I'm too dumb to understand it now but since I have a direction I can research it on my own.
@nobody4y
@nobody4y Год назад
"To make UK safest place to live" Sorry but how is scanning someones PC is going to stop the knife crimes
@df23
@df23 Год назад
Obviously talking about cyber crimes
@tailsorange2872
@tailsorange2872 Год назад
Human intelligence or "HUMINT" is how they are going to stop it
@BichaelStevens
@BichaelStevens Год назад
@@df23 Of calling migratory future engineers a much nastier word
@alphamikeomega5728
@alphamikeomega5728 Год назад
You're less likely to die of knife crime in the UK than in the US.
@d3stinYwOw
@d3stinYwOw Год назад
@@df23 cyber crimes require cyber knifes
@shaunpatrick8345
@shaunpatrick8345 Год назад
At least I know someone will be reading my manifesto!
@mllenessmarie
@mllenessmarie Год назад
I laughed out loud so hard, thank you sir! o7
@Croissinate
@Croissinate Год назад
Australian here. Our government does this too - they've been doing it for a few years now.
@Beetless
@Beetless Год назад
@Oscar ok
@zdrux
@zdrux Год назад
Nobody would be happy if cops tried to enter your house on a regular basis to keep you safe.. I don't see why this is any different. Anytime government does something for your safety, you know its a scam.
@tonyeezi7315
@tonyeezi7315 Год назад
I run a small UK web hosting company and can verify exactly what you're saying, but the issue goes a lot further and deeper. Most of my clients are ones who have been shut down by the bigger hosting companies and their access logs show thousands upon thousands of penetration attacks from governmental bodies from around the world. On top of this there's also the amateur hacker who just wants to see what is out there by leaving their scanning software running constantly in a loop day after day. I blame the creators of AngyIPScanner - they started it all off twenty years or so ago! :) What really annoys me though, is that these attempts are stealing MY expensive bandwidth and NOT allowing my clients the full experience their customers deserve while browsing their websites. Also, got to mention the amount of my time and effort required to check that these IP addresses have been automatically permanently banned - just in case. They say it is for our own safety but come on, does anyone really believe what our governments say any more? Really?
@nogr3369
@nogr3369 Год назад
Do you have any videos on independent web dev/hosting already, and if not, would you be interested in making one? I’m all for self-hosting, but it seems like a lot of work, especially on top of designing the website yourself too.
@whatamievendoing
@whatamievendoing Год назад
Just install Apache and use port forwarding. Pretty straightforward if you have a static IP actually
@me-vb5xk
@me-vb5xk Год назад
Pretty easy actually. Grab a virtual machine from digital ocean or similar and follow online guides
@transforgoku
@transforgoku Год назад
Wait, so I don't have to pay a hosting site to run my web page? I can do it on my own?
@paaao
@paaao Год назад
China and Russia have been scanning every box I put online since the mid 2000s. Sadly they don't tell me my vulnerabilities, they just try to get in to see what's going on and then leave.
@i34g5jj5ssx
@i34g5jj5ssx Год назад
I think any country with reasonable amount IT specialist do this. One with stripes and stars on flag even scan worldwide.
@paaao
@paaao Год назад
@@i34g5jj5ssx maybe, but the IPs always resolve to China. Sometimes to Russian federation countries
@jackalenterprisesofohio
@jackalenterprisesofohio Год назад
sounds like my mother in law. _audience laugher_
@horsemology
@horsemology Год назад
@@paaao I noticed a large amount of the same activity in my logs. On the chance you're unaware, if you're not worried about denying access to those countries you could always setup an iptables rule to block CH and RU ips.
@paaao
@paaao Год назад
@@horsemology I have no password login, and ssh never running on standard port, so they always fail at whatever they're up to. It's interesting to watch though...
@joshuamaserow
@joshuamaserow Год назад
Dude, I opened the video, just to say that your thumbnails are beyond!
@Zxv975
@Zxv975 Год назад
This guy is the modern equivalent of a digital Amish person. His suggested solution to every problem is literally "just spend several years learning all the skills and do everything yourself"
@Vickman_
@Vickman_ Год назад
I love how on the nose their logo is for a certain book we’ve all heard about was told they’re crazy and then all of a sudden
@Krawurxus
@Krawurxus Год назад
This is basically the equivalent of the government driving around the country and making note of the color and material of your house and the size of your driveway. Kind of benign but a waste of resources and annoying if you know about it. However, tons of entities online do this. Anyone who ever did monitoring or security stuff for a large network will see some Chinese or Russian IPs knocking every couple minutes or even seconds. It's usually just botnets hoping to get lucky. If you don't want your frontend scanned by the UK gov. you can simply blacklist the provided IPs so that all incoming packets from them are dropped and move on with your life.
@mattatwar
@mattatwar Год назад
At least in the states, they pretty much do that the county assessor keeps track for taxes on the property. ( based on value of the property) Some things are reported to the assessor when you get permits for upgrades (remodeling etc)
@vonvision
@vonvision Год назад
The only helpful comment on this vid. It's nice that they've provided the IP range.
@go_better
@go_better Год назад
That was surprising that you kinda approve what they do. And it could be nice to cooperate with governments if they wouldn't become dictatorships one day.
@DsiakMondala
@DsiakMondala Год назад
>one day Boi do I have news for you.
@117johnpar
@117johnpar Год назад
Oh, my sweet summer child. Dictatorships are far too unstable for those megalomaniacs who run our stable democracies. These evil villains have more long term goals.
@go_better
@go_better Год назад
For the record, I'm open for discussion, but not if you look down on me. Since that's the case, you're not welcome.
@kayobGH
@kayobGH Год назад
MSc cyber Security student here, we had a discussion on this issue in one of our lectures and it was quite interesting listening to people on both sides of the argument for and against this move by the NCSC. I have a strong feeling these guys know something that a lot of commercial bodies,businesses and corporations just don't know yet. I'd also be very interested to know what in-house NCSC data assurance (GDPR,etc) and risk policies are in place to mitigate any unforeseen problems that would come out of this
@DjDolHaus86
@DjDolHaus86 Год назад
My immediate thought is that it has something to do with Russia. Correct me if I'm wrong but I believe they're fairly hot on cyber and economic warfare so it's not implausible that if things keep going bad for Russia that they could potentially seek to cause economic damage through these vulnerabilities? Please don't think I'm being conspiratorial, it just seems like a potential route to further weakening Britain in terms of finances.
@DudeSoWin
@DudeSoWin Год назад
Students should learn to raise their hand before commenting.
@jhonbus
@jhonbus Год назад
@@DudeSoWin Oh, you've already learned _everything_ have you? Only someone in the deepest grasp of the Dunning Kruger effect would say something this dumb.
@DudeSoWin
@DudeSoWin Год назад
@@jhonbus
@hazelanderson1479
@hazelanderson1479 Год назад
I’m glad that the NCSC has nothing better to do than look at my collection of cross stitch and knitting patterns, as well as photos of pets past and present. Oh, and some emails to friends complaining about my arthritis and other ailments.
@durden91tyler
@durden91tyler Год назад
I'm so glad I found this channel
@WistrelChianti
@WistrelChianti Год назад
Just to confirm, this is true. Spotted them in server logs a few weeks back. They were not doing a lot though. Fairly minimal number of entries looking for stuff we were not running. Can't remember exactly what. Things with admin and references to mysql in the URLs IIRC.
@jasonpocaro2730
@jasonpocaro2730 Год назад
Firewall, DNS "Block" list, Repeat DOS flag and Good LAN administration are best to keep out ANY unwanted / snooping internet scans. 😉👍
@alexandriat5929
@alexandriat5929 Год назад
Castle doctorin, nice we need a voluntary opt in. I agree with your perspective, the public needs tech education 100% this is good. The USA needs a Linux forum for public educatio n. Good video!
@realastropulse
@realastropulse Год назад
I've built my own website from ground up, I've used Wordpress, I even am pretty experiences in js and can make some very nice aesthetic animations. I will happily help someone build a custom site. But, when it came to my own portfolio site, I didn't want the hassle or maintaining it. So much easier to just outsource.
@marcopeterson805
@marcopeterson805 Год назад
Soydev, use php and css like a real man. Javascript is known to cause cpu and brain damage.
@Hunter_Bidens_Crackpipe_
@Hunter_Bidens_Crackpipe_ Год назад
@@marcopeterson805 PHP is by dinosaurs, for dinosaurs
@GoshaTnimov
@GoshaTnimov Год назад
Just use wasm lmao
@vinzer72frie
@vinzer72frie Год назад
It be funny if people in the uk would suddenly start torrenting large text files with random arrays of numbers for no particular reason
@ricequackers
@ricequackers Год назад
This is the digital equivalent of police driving around the neighbourhood, looking for houses with doors and windows left wide open, and leaving a leaflet with tips on how to avoid being robbed. Fairly benign imo, it would only be an issue if they started testing the locks without permission.
@kpcraftster6580
@kpcraftster6580 Год назад
More like driving around testing everyone's doors and windows with a crowbar and keeping records for later use by anyone they sell, give or leak that data to.
@axelolord
@axelolord Год назад
If you need a good indication that NMAP is easy to run, it is the fact that the UK gov can do it.
@michalroesler
@michalroesler Год назад
Great video as always.
@Bosco247
@Bosco247 Год назад
10:13 That Desktop wallpaper made my day :DDD
@defnlife1683
@defnlife1683 Год назад
I remember reading that over 60% of businesses in the UK had hacks. There's no way INGSOC would exploit this. OCEANIA on the other hand!
@JavoCover
@JavoCover Год назад
John Mcafee sure told about goverment involvement in cyber "security".
@delqyrus2619
@delqyrus2619 Год назад
On the first glance, pentesting by government sounds like a neat idea. But what you get is somehow the stuff, that is already out there - the bots, that many "hackers" use to scan the internet. You can simply download scripts which do this for you. I mean: Most of the people don't do it, because they set up a webserver and never come back again. A nice mail from the govs won't change that. I have a bot running which scans for hacked amazon-vendor accounts. If it finds one, i write an email to owners. Guess how many of them reply... Less than 1%. So you gain basically nothing out of it. On the other hand, there are a lot of suspicious actions which could be hidden by such "pentesting". If you - for example - want to controll a medium like the internet, a map of private servers which could post critical content, might be helpfull. Even more if you also have a map of their vulnerabilities. This might be the perfect curtain to hide such things. Not that i want to imply that, but... It is possible, you know?
@MrDoomedtofail
@MrDoomedtofail Год назад
To be honest, if you randomly sent me an email like that I would just assume you are trying to hack me.
@billfarley9015
@billfarley9015 Год назад
@@MrDoomedtofail I thought that might be a possibility but how does sending someone a message saying their acct was hacked help them to hack you? It's possible some of them contacted Amazon or some government agency if they can find one that will do something. They should have contacted Amazon at the very least.
@laaddd23
@laaddd23 Год назад
Is this just a scan for webservers, or will this be for regular router boxes/pc's as well?
@tjgdddfcn
@tjgdddfcn Год назад
nmap scans for services on a network. So basically anything that responds after you ping it. Basically if you’re affected, you’re probably already tech savvy enough to know that you are
@markp8295
@markp8295 Год назад
This is great. Once set up, this is cheap to run and maintain as a service to provide to all British companies meaning fewer economic losses on home soil helping British businesses and making more than the cost back in additional VAT and income taxes.
@christopherleadholm6677
@christopherleadholm6677 Год назад
"The louder you are... "😄 Noice. I see what you did there. 😉
@herbert-kenumera960
@herbert-kenumera960 Год назад
Goddamn it pen testing looks hella fun.
@adrianfisher3349
@adrianfisher3349 Год назад
I think the future is self-hosting where people host more and more privately, and away from big tech. I've been running OpenBSD as my private firewall for years without incident, and want to use that and only that for anything open to the general Internet whenever possible.
@bonbonpony
@bonbonpony Год назад
Hosted on what? Connected to the Internet how? Domain name from where and for what price? Money where from? Payments how? First one needs to answer such questions in order to be truly "self-hosted", because many of these things are getting harder and harder to do for an individual when compared to 5…10 years ago :q
@counterleo
@counterleo Год назад
Decentralisation was how the Internet was initially meant to function back in the days. Web2.0 saw a great shift towards centralisation, with all the Cloudflares and the CDNs and the AWS and all the other SaaS BS. I sure hope Web3 will initiate a shift back to the basics :)
@adrianfisher3349
@adrianfisher3349 Год назад
@@bonbonpony For most people this may be nothing more than a NAS, for others, a firewall with storage, etc. Answering your questions would require too many generalities and assumptions.
@bonbonpony
@bonbonpony Год назад
@@adrianfisher3349 My point was that the Internet is closed with so many locks now that it's getting more and more easy for corporations and govrnments to cut you off of it. The ISP can deny to connect you. The domain name registry can cancel your domain even if you paid for it. The hosting provider can deny you service and dump your website down the drain and you can't do much about it. If you wanted to host it yourself, you would need your own server machine and Internet connection with good throughput, hence see above. If you want an SSL certificate, you need to buy one from the CAs and they can deny you too. And lastly, browsers can block your website as "malicious" if they decide to blacklist you from some reason. Therefore, until you remove all those obstacles, "self-hosted" is a myth.
@bonbonpony
@bonbonpony Год назад
@@counterleo The Internet was never decentralized, if you study its history and protocols carefully enough. Sure, the protocols might be public, but there's always some "blank areas" in their description and "reserved stuff" for certain organizations that keep the authority over it. From registering new protocols or protocol extensions, through cryptographic algorithms, through certification authorities, domain name registry, so called W3C standards (which are mostly managed by only a bunch of corporations, and wider public, Internet users, web developers etc., usually have no say about their shape), web browser technologies, and even the physical infrastructure of the links is mostly star topology, either physically or logically. To this day, the last word about the shape and function of the Internet is held by just a bunch of government institutions from the USA, where it originally started as a DARPA project. If you want a decentralized Internet, I'm afraid that we have to build it for yourself, from the ground up. Only then it will be truly decentralized and free.
@harveybolton
@harveybolton Год назад
Glad I saw this before I saw "NCSC Scanning agent" in my analytics haha
@TheSubzeto
@TheSubzeto Год назад
CSE (Canadian version of the NSA essentially) offers a virus scanning program that you can code into the backend of your services. That is, if you can convince anyone in your dev team to do it lol
@ForbiddenUser403
@ForbiddenUser403 Год назад
Meahwhile the NCSC thinks the UK only has a couple active webservers after every good sysadmin's fail2ban policies firewall off NCSC's automated scans...
@kvolikkorozkov
@kvolikkorozkov Год назад
I love your desktop background :) I want it
@mgh7634
@mgh7634 Год назад
Of course its britbongistan
@untag4066
@untag4066 Год назад
youre brown
@Edwardify
@Edwardify Год назад
Tbh I don't mind the NCSC. I think this is for the better for the UK in terms of security and the information they post is always useful
@anon_y_mousse
@anon_y_mousse Год назад
I see this as a bad idea, and it's going to catch on here as well. Opt out you're screwed. As for nmap, I use it on occasion myself. It's a pretty useful program for all kinds of different things.
@JulioRad954
@JulioRad954 Год назад
That background on Kali, ROFL !
@Sponsor_Block
@Sponsor_Block Год назад
“Those that give up freedom for safety deserve neither.” ~Benjamin Franklin~
@psiquestate7863
@psiquestate7863 Год назад
F**you Twitter
@MoneylessWorld
@MoneylessWorld Год назад
They are scanning to take dissenter websites down later on. If they started scanning without this bunk "for your safety" excuse, some admins would notice the port scanning and call them out.
@frozenbaguette
@frozenbaguette Год назад
I think if that if government start actually testing server security for their citizens properly it would be great! BUT, asking a governement not to spy on you while doing anything is like throwing your gaming PC in the bath for better performance, it's not gonna end well.
@gizmo9987
@gizmo9987 Год назад
Wow, that hacker at 3:54 is on point!
@ab-oj9wv
@ab-oj9wv Год назад
Are they going to try breaking into every home and picking every lock, and then send a report, too? Who'd be comfortable with that?
@P.G.Wodelouse
@P.G.Wodelouse Год назад
it is not uncommon for patrolling police to let property owners know about security risks that they notice.
@MattM-oe6qs
@MattM-oe6qs Год назад
Do all your neighbours try to break into your place?
@GaryOK
@GaryOK Год назад
If you've got nothing to hide .... then cyber security is super important !!!
@manowasthere
@manowasthere Год назад
they're looking for my epic osu plays and maps
@jmnetworkuk
@jmnetworkuk Год назад
NCSC are usually pretty chill compared to other lettered agencies in the UK. Happy for them to do this. I have only had positive experiences with the NCSC as a security professional.
@MooseCastle
@MooseCastle Год назад
You're glowing bruv.
@toomanycharacter
@toomanycharacter Год назад
Your privacy is dead, not big suprise!
@TheRedneckPreppy
@TheRedneckPreppy Год назад
I don't know what's scarier, much of MA's video sounding like a glowy press release or so many comments proclaiming how happy this is being done.
@Celciusssify
@Celciusssify Год назад
lmao, I bet I can predict the future. They start charging fees even for the lowest of "security" warnings.
@johnsimon8158
@johnsimon8158 Год назад
thanks! great video learned a lot of great stuff
@baliandeibelin7640
@baliandeibelin7640 Год назад
Remember, remember the 5th of November.
@duard8652
@duard8652 Год назад
A rare case where I disagree with author, on managed web site platforms. Their main cases are IMO: 1) super small businesses where one or two people is the whole business, and they have hands full with other things, and their size is unlikely make them a target 2) MVPs In both cases, as long as business survives the impact, site should migrate. Small businesses will benefit from saved money from self-hosting. And MVP matures and quickly outgrows boundaries set by managed platform.
@marcmedeiros8857
@marcmedeiros8857 Год назад
Hello, we are from the government. We are here to help.....
@KeligAvignon
@KeligAvignon Год назад
I f*ing love your Kali wallpaper
@srgantmoomooo
@srgantmoomooo Год назад
before i watch, let me guess. its for their safety!!!!
@astanfartin1647
@astanfartin1647 Год назад
just watching this video puts u on a list..... lol ...... my super cool people list
@jorcornel558
@jorcornel558 Год назад
Get out of my machine
@xp8969
@xp8969 Год назад
Trump's 2018 Cybersecurity and Infrastructure Security Agency Act has had the government controlling the internet here in the United States ever since Trump signed it into law
@ch0wned
@ch0wned Год назад
I think it's funny how we're now footing the bill for open source software that these "experts" barely know how to use in the first place. Now I can "major' in cybersecurity. It's rich.
@alanmott-smith9358
@alanmott-smith9358 Год назад
Nah, I always believe the opposite of what any government tells us.
@graememadison9344
@graememadison9344 Год назад
Just got a shopify ad for the first time
@lefr33man
@lefr33man Год назад
"make the UK the safest place to live" this is working brilliantly so far, right?
@P.G.Wodelouse
@P.G.Wodelouse Год назад
..........."and do business online" what is wrong with you people and your reading ability.
@TheLampl1ghter
@TheLampl1ghter Год назад
"Hey, I've seen this one before! It's a classic!" "What do you mean? It's brand new."
@workandplay9874
@workandplay9874 Год назад
I like the guberment. Don't you like the guberment, too?
@au7weeng534
@au7weeng534 Год назад
I think this is terrific and countries R. and C. should do something like this, too. And of freaking course it's not for anyone's safety and certainly not freedom, because the potential for abuse is astronomical. It's to R.-proof / C.-proof the local segment of the Internet. But from a purely statecraft pov, this is terrific.
@gamereditor59ner22
@gamereditor59ner22 Год назад
That's interesting.... 🤔
Далее
Where People Go When They Want to Hack You
34:40
Просмотров 2 млн
#kikakim
00:17
Просмотров 6 млн
What’s your height?🩷🙀💚
00:59
Просмотров 3,1 млн
The Invasion Russia Doesn’t Want You to Know About
26:09
Tactics of Physical Pen Testers
44:17
Просмотров 908 тыс.
Worlds Dumbest Darknet Admin Gets Busted
14:54
Просмотров 455 тыс.
We hacked Rabbit R1 and found THIS
10:31
Просмотров 96 тыс.
Now THIS is What a Private VPN Looks Like
12:02
Просмотров 489 тыс.
Flipper Zero: Hottest Hacking Device?
10:01
Просмотров 7 млн
#kikakim
00:17
Просмотров 6 млн