[0] https://bethmathews.substack.com/p/why-so-many-control-rooms...
1,355 karma · joined September 30, 2013
[0] https://bethmathews.substack.com/p/why-so-many-control-rooms...
Of course, some users were still blocked, because the Turnstile JS failed to load in their browser but the subsequent siteverify check succeeded on the backend. But overall the fail-open implementation lessened impact to our customers nonetheless.
Fail-open with Turnstile works for us because we have other bot mitigations that are sufficient to fall back on in the event of a Cloudflare outage.
[0] https://www.crunchbase.com/acquisition/montefiore-investment...
[1] https://news.gandi.net/en/2019/02/futureofgandi-the-adventur...
https://www.cloudsek.com/blog/compromising-google-accounts-m...
"Highly likely"? No. You are ignoring probability. See UUIDv4, which does not use time or NIC/MAC but does use 122 random bits.
It sounds like your domain name entered the redemption period. The high fee to restore a domain in the redemption period is mandated by the registry, not the registrar. So Gandi is not price gouging; they are required to collect that fee for restoring the domain.
It is true that browsers will cache 301 redirects eternally, but only if the server does not supply cache directives to indicate otherwise. For this reason, it is always advisable to include some cache directives in 301 redirect responses, like `Cache-Control: max-age=86400`. I'm surprised that this isn't more universally acknowledged as an important practice.
As far as search engines, there will not be a problem if a URL that used to return a 301 now returns a 200. The web changes, and search engines know that very well.
Add: There also seems to be a lot of confusion about the meaning of permanent. Permanent should not be taken to mean eternal. If I move to a new house, I consider that a permanent move, because I no longer live at the old address. But it would be unreasonable to assume that I will never move again. I might even move back to the original house! Such moves are like permanent redirects; I might have my mail forwarded, but it is not an indelible, eternal change. Temporary redirects (302, 303, 307) are more like leaving a sticky note on the door while you're out running an errand; you have not permanently relocated.
https://docs.python.org/3/library/pickle.html
https://blog.nelhage.com/2011/03/exploiting-pickle/ (referenced from https://cwe.mitre.org/data/definitions/502.html#REF-467)
That is not exactly right. The risk is when you unpickle data that was pickled by someone else or that was tampered with after you pickled it.
> "As set forth in the Dodd-Frank Act, the SEC protects the confidentiality of whistleblowers and does not disclose any information that could reveal a whistleblower’s identity."
It would be nice if the mods/dang would update the link.
As of 2019, Bing was looking at those links for URL discovery. https://twitter.com/CoperniX/status/1108790528773021696
For example, I might read parts of a dozen different cross-referenced IETF RFCs just to decide what flavor of URL syntax I should accept in my API. At other times I might not even know whether a relevant standard already exists, so I skim a bunch of standards just to confirm it is necessary to invent a new thing. This would be very expensive in ISO Land, and the reality would be that the standards are never used.
Non-free standards for software and networking impede innovation. I can't imagine what the internet would look like today if the IETF and W3C charged for access to standards.
Consider also the pace of innovation in software and networking—the internet at large. I think it's both a consequence and a cause of the change in culture you described.
Industries that are more reliant on ISO or other non-free standards are surely worse off because of it.
HTTPS://S.NSW.GOV.AU/C/121321/Test+NSW+Government+QR+code (binary mode)
HTTPS://S.NSW.GOV.AU/C/121321/TEST+NSW+GOVERNMENT+QR+CODE (alphanumeric mode)
He ruled out full alphanumeric mode early on, prior to ditching Base64, but it's sensible to reconsider it by the time you reduce the URL this far. He goes on to allude to simplifying or even dropping the business names to save more space at the cost of lost functionality, but just uppercasing them seems benign to me.
It's a nice write-up all the same.
Yeah. An important, long-lived ID that will stick with an individual for their entire life, and that they may want to commit to memory. That seems like a good time to take a hypersensitive approach and adopt some kind of filter.
Edit: But I'll concede that when your outputs are only four characters long and end users will actively interact with them (write them down, type them again later, etc.), additional safeguards might be appropriate. Or simply omit all alphas and use only numerics.