I Just Logged In As You
codinghorror.com
codinghorror.com
1. His blog and podcasts are pretty entertaining, even if he is wrong sometimes.
2. He created Stack Overflow, which is a pretty nice site. At least, I like it.
3. He admitted and blogged about an extremely embarrassing oversight on his part today. Which takes some backbone.
That being said, I don't think we need a link to him on every single blog entry. This particular entry is more interesting from a Hacker News perspective though.
He's done some good things, and some stupid things; I think a lot of people have probably gotten started reading up online on their own because of Coding Horror, and anything that gets the 9-to-5 set doing some extracurricular reading can't be all bad.
2. Yes, much better then experts exchange.
3. He does that often, make mistakes and then boldly admit to them. The last one I remember was his article on password salting. Yes, that's good but then again what choice does he have, you can't erase your past from the internet.
That being said, this particular entry is a tease to the NEXT entry where we might learn something valuable about security.
I'd prefer if we saw many, many fewer coding horror articles here because I do believe the interests of his fans and those of elite hackers are mutually exclusive.
As Dennis Forbes so aptly put it, "Be careful diving in [to CodingHorror] headfirst, though, as the technical depth is generally so shallow you'll be hitting the bottom before you've even broken through the surface tension."
Makes me wonder about the ways of being wrong, and who do people here think tend to be wrong in a good or valuable way?
E.g., making conjectures that at least posit novel interaction of events and ideas, or are wrong due to lack of current knowledge and over-optimistic conjecture, not because of willful ignorance or bias.
(I suppose that describes any good sci-fi writer; I'm thinking more of bloggers or essayists.)
They all have an implied "why the fuck do you listen to me anyway?" tone in the final paragraph. Jeff Atwood knows, deep in his heart, just how much of a pretender he is.
You talked about it but didn't implement it? Yikes.
Good thing stackoverflow is a tech help site and not porn/gambling, eh?
I put the source IP in my browser and came up with a XAMPP administration page which had a link to phpMyAdmin, which gave me admin access to all the databases on that server.
I poked around long enough to get a contact email for the server admin and sent him a polite email explaining everything. He was grateful for the email and explained that he never thought anyone would try to access his raw IP. I don't think he checks his logs much. ;)
That said, I enjoy listening to the podcast, even if sometimes because I get to laugh at the things Jeff said. But as someone else said here, it's hard to be too down on someone who was a key factor in making a site like Stack Overflow. He also makes some good points. Sometimes.
But objectively, about 90% of the time I agree with Joel when the two have a disagreement. Guess that means I shouldn't apply for a job at Fog Creek :-).
Easier on the user, harder for hackers: that's a total no-brainer. I've adopted passphrases across the board on all the systems I use.
I guess the anonymous person discovered his passphrase?
Stepping back for a moment, why are we using passwords for authentication and security in 2009?
No, he is not. He is at best average.
A while back Joel published an article in Inc, about his experience of run and gun with stackoverflow. He was surprised how well it went. In fact it merely appeared to have gone smoothly. I'm guessing more subtle long term problems will continue to appear as time goes on.
And yet still, I think stackoverflow is much much better then experts exchange.
I agree, but he is perceived as being some elite coder by a large portion of pretty fresh web-devs, probably mostly because of the prevalence of his blog, and the readers lack of technical skill/knowledge.
I know that I thought that he must have known what he was talking about a while ago. That is, before I knew what I was talking about.
And in answer to your question, yes. Everyone is supposed to become an authority on choosing strong passwords. I fail to see why this is unreasonable.
peopel have been saying this for decades, that users should get with it and learn how to create passwords like "as723HASD-23", to change it every month, to use a different one for each system, to never write it down, and so on and so on.
And for decades users haven't been doing this.
So. Are we to blame the rest of the universe for not doing what we tell it? Or decide for ourselves that This doesn't work and we as programmers must think of something else?
If none of the alternatives appeal to you, think up a new one and get some YC funding going :-)
For example, one technical fix is a widely deployed public key authentication system. It would take a company as large as Google to force people to adopt it, however. Plus operating systems would have to start shipping the software to make the average user understand it. Private key creation would need to be integrated into the create user process of Windows and Mac OS X. That's not realistic because there is little profit for the companies involved.
I think we'd see quite a bit of progress if OpenID providers just started using PKI.
i wonder if the value saved by well-protecting a user's data is a net gain or loss on the whole... http://qzip.in/nX
More 'wonk' than security at that site, I'd wager.
"If you're a moderator or administrator it is especially negligent to have such an easily guessed password."
Actually, I find just the apparent fact that he uses a 3rd party openid provider (whichever one it is) for his StackOverflow admin account disturbing. The OpenID provider has the credentials - they can therefore log in as him any time they like. Only their integrity / reputation prevents them from doing that. I think it's fine for individuals using the system to trust a 3rd party like that but I don't think it's fine for someone with admin powers to do so.
* Ignore this whole comment if he runs his own OpenID provider :-)
A perfect complement to NoScript's proper apology article.
As far as not "really" needing to post this, that's true of any breach of security with no obvious user-observable consequences, regardless of the kind or degree of the breach.
edit: Besides, as is the case with the softcore porn in a technical presentation, I'm more worried about the fact he says it's no big deal than the actual security problem. I think "I screwed up totally and apologize for having failed you, this will not happen again" would have been more appropriate than (paraphrase) "I screwed up but this is pretty inconsequential."
I choose a word, for example if it's Hacker News, then i choose hacker and then add random number to it while they are complex chrachters.
Just look on your keyboard, there are numbers that matches chr, like 1 -> & and 2 -> é
so i write é(hackerénews while i memorize 25hacker2news
i think in such way it's 98% impossible to crack it
Well this may be a stab in the dark, but I'm guessing it has something to with the fact that you are NOT a great programmer. Learn some C you average coder!