https://agileforall.com/history-of-tdd-as-told-in-quotes/
Djikstra proposed the idea in the 1970s. Rails did not in any way pioneer TDD. They were very vocal about it but “[stood] on the shoulders of giants.”
262 karma · joined January 18, 2009
https://agileforall.com/history-of-tdd-as-told-in-quotes/
Djikstra proposed the idea in the 1970s. Rails did not in any way pioneer TDD. They were very vocal about it but “[stood] on the shoulders of giants.”
Shor's algorithm is very tasty, but when the real world demonstrations at top research facilities are saying, "yes, we factored 21 into 7x3, but WITH ENTANGLEMENT"[1] it makes me think that scaling to RSA-size prime factors is still a good way off.
Listen, the US government is powerful, but building a full scale quantum crypto decoder ring in complete secrecy _decades_ ahead of everyone else? I just don't think so. Maybe I'm a sheep for not wanting to believe the government so powerful and corrupt, but the whole thing sounds like a tin foil fantasy.
I don't doubt they would if they could, though. And they've done as much as they can with present day tech: supercomputers, mass data collection, penetration of target systems, exploiting SSL's many weaknesses, tapping undersea lines, and legally strong-arming perceived threats into giving up their encryption keys. I just don't think we need to get science fiction involved.
[1] http://www.nature.com/nphoton/journal/vaop/ncurrent/full/nph...
In any case, you can choose a public key exponent large enough to still make it a hard problem to crack in a reasonable amount of time. Barring some huge vulnerability in RSA that hasn't been discovered in 30 years of public scrutiny, of course.
RSA has issues but as of yet hasn't yielded entirely to cryptanalysis.
As the article says, it's easier to attack the system and try to get the plaintext, or coerce you into giving up your key through legal means.
Edit: adding a link to Wikipedia's article on post-quantum crypto, it's a good place to start understanding how to answer these type of questions:
http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-hona...
It appears to be a configuration management / deployment tool for KVM containers. New to me too, gonna dive in and check it out.
It also illustrates a really key point about crypto: because it looks simple (oh, just run the bytes through that function/hash/send them over SSL), people assume that it is simple they know enough to hack together a decently secure system.
At the very least, a healthy respect of crypto theory is called for. In my experience most developers do not have this healthy respect and see crypto as a magic black box that makes data unreadable.
I find attacks on cryptosystems illustrative for the "oh CRAP" moment. Oh CRAP salted hashes are a terrible idea. Oh CRAP you can pad a hash to make a remote system accept "signed" data. The more I learn and the older I get, the more cautious I am.
The idea that a company composed if hackers could have not a single whistleblower, no single person that objects so strongly that they must speak up regardless of their personal situation is betting against human nature. Nay, hacker nature.
Freedom ain't looking good nowadays, but this is not the vast conspiracy it may seem.
As far as API vs. user account, it depends on the loot. An API might let me do more damage faster, or subtly lurk and alter/steal data over time. It might also be harder to detect from the UI, no "last logged in" giveaway.
Also, some API vendors recommend disabling SSL cert validation client side. Even for credit card gateways, unbelievably. Since it's a script talking to a script, no one is going to see the cert problems from a MITM until it's too late.
And who's to say that your forum server (for example) is just as secure? That could be a foothold into your environment too. And let's not forget social manipulation of your staff and users. Maybe I'll just steal the machine in question, or your laptop.
After I try all those avenues, I'm either finding another target or ramping up for a protracted attack on your SSL connections.
If your site attracts this dedicated of an attack, you'd better get that high paid security consultant. ;)
That tool you posted is great, hugely helpful for anyone who has to deal with this stuff.
Nowadays I'm downright spoiled and use org-mode[1] to keep my systems journals. Org files are plain text as well, and org-mode takes care of setting up the tree by date. I can also add a journal entry from anywhere in Emacs with just a couple keystrokes, which makes it incredibly low-friction to use.
Like I said, the most important thing is to TAKE NOTES. Even pen and paper. It's one of Limoncelli's big points in Time Management for System Administrators.
Tooling doesn't really matter, the important part is being able to remember what the heck I did and when I did it. Invaluable for troubleshooting.
[1]: http://orgmode.org
http://practicalops.com/my-first-5-minutes-on-a-server.html
Happy to answer questions about it. :)
There are much easier attack vectors.
Just sayin', this is a tough business, and people get very cranky when things break. :-)
All that said, this is a huge space for new business, and I'm glad to see you guys throw your hat in the ring. Definitely an interesting take on things. Best wishes!
Not to nay-say, but if you don't price according to value delivered, you don't stay in business long. Your income should grow faster than the infrastructure that you need to run the business.
It's also not clear what company is backing this service and how you're structured. Are you VC-backed? What happens when the money runs out, am I left holding the short end of the stick?
window.location.href = 'nyan.cat';
Neat little app, nice to see a simple non-Flash version of http://e.ggtimer.comDid he bang out LZEXE the first time he sat down at a terminal? Probably not. But over time, through pursuit of a passion and hard work, his skill has progressed incredibly.
We can get there too, with persistence. And we can have fun on the way.
This is as much a reminder for me as anyone, I have a tendency to compare myself to amazingly talented and productive people and get discouraged with where I am now. But you know what? I'm farther along than I was a few years ago, and that ain't nothing. :-)
One of my favorite quotes on the subject:
"Never compare your beginning to someone else's middle."Just a friendly reminder that depressed people cannot, for the most part "snap [ourselves] out." If the solution was to double down and power through I'd have cured my own depression years ago.
The shitty thing is that it's a long-living subconscious emotional drain. It's a downward slide that for me happened so slowly I didn't even notice until I'd lived at the bottom, completely burned out on life and barely functional for two years. It's not only a mental disorder, it's technically called "psychomotor depression" because it will by degrees affect mind and body in a downward spiral.
I've never lost sight of the bigger issues, the disorder and opportunity for change in world-at-large, but it's impossible to make meaningful progress toward /anything/ whilst waking up every day with a gnawing emotional emptiness and pain thrusting itself into the center of my consciousness. It's care about those bigger issues and for my family that has kept me in this world.
My point is this: whether you mean to or not, you suggest that people can get themselves out of depression. In general, this doesn't happen. Therapy, medication, and support of friends, combined with healthy living have begun to move me forward in my own struggle.
I hope to see in my lifetime an elimination of the social stigma of depression. We're not miserable entitled bastards that need a reminder of our incredible opportunities. We're folk who feel sad and whose brains work in a way such that we can't always see the way forward. That's all there is to it.
High school science was all in SI, of course.
I'm certain that at least one older algorithms text I own mentions skiplists, and there is no doubt much other prior art here, seems like the kind of thing that might find its way into kernel scheduling queues.
Seeming clueless when doing malicious things is unquestionably a form of social engineering.