Minutes of the SIPB Meeting of 2021-11-22 The meeting was called to order at 19:30 by asahteck. In attendance were         Student keyholders: asahteck, cela, cjq, huydai         Associate keyholders: '()         Members: cbsu, javsolis, agrebe, markchil, rgabriel         Guests: '() Administrivia:         asahteck: Hi! I'm currently in Rhodes Island                 cela: Can we recap what happened in Administrivia for those of us in-person?                 agrebe: We had our first Cluedump of the semester last week, with more than a dozen attendees. Mark gave an excellent talk on Pytorch!                 asahteck: Once again thanks to everyone who helped organize and run the event. Project Reports:         cela: HWOPS continues. We sent out a bunch of emails last week asking for information on the servers in the SMRs. If you got one of those emails, *please!* fill it out and return it to us. We've narrowed our UPS choice to about 3 suppliers, and hopefully we'll be able to finish up selecting an UPS and buy it in the upcoming weeks, so we can get to setup and migration in January.                 asahteck: As someone who's been CC'd to all these e-mails, I'm very amused by all of the server names                 rgabriel: what are some examples?                 cela: Remember one of the benefits of being one of the hardware maintainers                 cela: We have, Blink Dog, Bonfire of Manatees, Lion Killer, Blue Beacon, Rosebud 2, Twilight, Century, Neutron Star, Froyo Machine, Rack Forward, Rack Backward, Stuff!, Joss Whedon (as mentioned before), SIPB-tour, and Children's Television Workshop [which is technically a UPS].                 asahteck: Joss Whedon is a good server name                 rgabriel: How many servers do we have?                 cela: We have a lot of servers. Many of our servers are in the next room, though we also have some in E14, W901, OC 11 (Off-campus 11). Other:         huydai: In SIPB we often talk about the latest and greatest security exploits found by researchers, but this past week when I was reading some threat reports from security companies like Crowdstrike and SonicWall, I noticed types of vulnerabilities that they see most often in the real world are these very basic security mistakes, like forgetting to turn on encryption for SQL databases (*facepalm*), not enabling firewall rules, accidentally exposing valuable data to the public, etc.             huydai: It just makes me think for a moment the difference between the kind advanced security threats we often study about in school versus like the super basic security stuff that are actually most often exploited by hackers.                 rgabriel: Actually Zoom made that mistake a while back.                 huydai: What did they do?                 rgabriel: They at some point had a bug where they weren't checking if users were actually authenticated                 cjq: Wow, that's just, wow. Other Other:         cjq: Pre-registration opens sooner than you think                 rgabriel: Like today?                 cjq: Next week.                 rgabriel: I'm also glad the list of spring classes were released recently.                 cjq: Yup, I believe it was released this morning.                 asahteck: IAP registration for PE classes opens soon! If you want to get your courses in soon, be sure to sign up for them                 rgabriel: Also, how / What is Cluedump?                 cela: Cluedumps are usually talks hosted on specific topics that SIPB members understand                 rgabriel: Usually each cluedump is a single speaker?                 cela: Yes, they are organized by whoever wants to give a talk.                 ciq: IAP is coming right, isn't there usually Cluedumps during IAP?                 cela: Not frequently                 rgabriel: As a sophomore, the end of the semester is terrifyingly close. Don't we have like 2 weeks after Thanksgiving before the end of semester?                 cela: Something like that, yes. The meeting was adjourned at 19:45.         Minutes taken and submitted by huydai.