No pre-compiling is required, so you just ship the files. Especially true for anything that offers an Apache module (like mod_php).
I can tell you it's not the case with Python.
Looks like it's been dead since 2010: https://en.wikipedia.org/wiki/Mod_python
In practice, I think modern Python webapps usually use WSGI or similar, where you wouldn't be just dumping a bunch of files somewhere.
For, say, Java or Ruby web apps, your code is more likely to live elsewhere (people love to fight over exactly _where_...), and run its own web server; nginx or apache or whatever will then proxy requests to that webserver. No matter how it's configured, you're never going to show the end-user the code, or extraneous files like .gitignore. Python's a bit of a corner-case (or at least it used to be last time I worked with Python webapps about a decade ago); it's customary to use WSGI or similar rather than a proper web server, but the effect is much the same.
By now, stateful application servers are also powering modern php deployments: They also listen to a socket, and keep parts of the application in memory, next to an event loop.
So yeah, not exactly a secret.
Haven't seen Drupal in the wild for years. Good on them!
Twitter made $5bil in 2021. Do you really think this or the next quarter, post-Musk acquisition, post-him running off big name advertisers, will even approach any of the worst quarters from the last 3 or 4 years under previous management?
He has all the data. We know for certain Musk would be shouting from the rooftops if that brief burst of Twitter Blue subs made any real dent in revenue.
Do you really believe Twitter will become more profitable under Musk than before when even the new CEO already prepped the workers for a possible bankruptcy, a fat pending debt repayment date coming closer and advertisers running away?
.well-known is much more recent and an exception. Can you think of any other .file or .folder which is wise to be exposed publicly?
What is your basis for this standard? Was there a mailing list agreement I missed?
I’d say it’s closer to good thing than bad thing due to simplicity.
Unless they intended to publish their .gitignore, I'd say it's closer to a bad thing than to a good thing to have random files from your repository open to the public.
The simplest S3 permissions is to allow "*" publically too, but simple doesn't make it better.
I look forward to meeting the Tesla engineers who work on their core tech and also their webpage.
For some reason, a considerable number of people don't seem to think twice about adding sensitive paths to robots.
also sometimes what's in robots.txt becomes invisible to the corporation as well and abviously bugs creep in
That said, avoiding security through obscurity doesn't preclude you from giving away less information than is being given away here, nor does it make the act of removing that information entirely pointless. While this isn't the only way that the Drupal version can be identified, it is one, and there's no guarantee your adversary will find it via other avenues. Also keep in mind that with absolutely nothing changing on Tesla's end, this may go from secure to vulnerable, should, for instance, a remotely exploitable vulnerability in the running version of Drupal be discovered and published in the future.
I regularly see bad pentesters fall for this.
Relatively common to find sensitive or embarassing links singled out in robots.txt
Especially in old large organizations, like universities.
from autopilot import *It's far from "full" self driving.
I wonder if these are some of the same people that Musk brought in to refactor Twitter.