We could, by laws and software, enforce a certain standard of security for organizations. The question is how liable you should be for that. Would have to consider many variables like size of company, importance of information and such.
1,131 karma · joined March 5, 2022
https://ChockChocsChoirChoke.com
ChockChocsChoirChoke@protonmail.com
https://github.com/Esc4iCEscEsc
https://twitter.com/Esc4iCEscEsc
We could, by laws and software, enforce a certain standard of security for organizations. The question is how liable you should be for that. Would have to consider many variables like size of company, importance of information and such.
Granted, single-focus vs multi-focus is not the only factor, as sometimes multi-focus companies prove to us, but it is a great factor.
> And I don't believe that this kind of obsession with being technically correct will lead to great social outcomes.
There is no such obsession. It's a joke, meant in jest. I'm confirming that parent is correct, and that I'm just being nitpicky for the sake of giving the title a meaning even if it's incorrect.
Granted, in real-life social situations, it's easier to spot when people are joking, in comparison to online text-only comments. Especially when the place where you leave the comment is particularly famous for being dry.
You're right, it's probably a typo. But the typo at least doesn't make the title incorrect, just changes the focus a bit. Most things in our computers are "virtualized".
Edit: seems people are thinking that this comment is trying to "correct" something. It's not. It was a failed attempt to bring humor to a typo that might as well not be incorrect. No need to further try to prove how socially inept I am.
This is a chain letter which I received from Peter Baumbach a little while
ago. I know that all of you don't know me, but if you don't then you probably
know Bill "Wadd" Waddington, who was here helping me think of names to whom
to send this. This letter is the infamous ARPA-net chain letter which
caused much havoc a few years ago on the ARPA-net. I think that it's pretty
dead by now, but I just can't help but to send it along.Speaking about accessibility, who came up with that name "magic number"? It's already an overloaded term with multiple meanings and even has one negative one (for constants that has seemingly "magic" meaning or not a fully understood one).
Even something like "contrast ratio" would be immediate to come up with, and much better name as it actually says something on the tin.
> Hey Pete, what is the magic number for our color scheme in article body text?
Makes no sense... Replace "magic number" with "contrast ratio" and suddenly it does make sense.
If a non-US company does business in the US, most people would expect the business to also answer to US law enforcement. You can't just operate in a business and not follow the law of that country. Same applies the other way around, you do business as a US company in Germany, you better follow German law. Hence companies tend to have HQ in one country, and then subsidiaries in other countries, who know how the local market and laws work.
"But judge, they never patched their $software to the latest version, so technically the software allowed me to dump the contents of the IMAP server"
Intents matter. If you commit a crime ("Stealing" is a crime), it doesn't matter if you did so via software, contracts, smart contracts, blockchain or else. A crime is a crime is a crime.
But re JSON:
> object keys in a different order
They can't be "in a different order" as JSON keys are not ordered. They can be whatever order, and would still be considered the same.
> array items are out of order
Then it's different, as JSON arrays are ordered. ["a", "b"] is not the same as ["b", "a"] while {a: 1, b: 1} and {b: 1, a: 1} is the same.
> you could UTF-8 encode characters or write out the same character using backslash notation, numeric or boolean data that might be wrapped in a string in one file but not in another
Then again, they are different. If the data inside is different, it's different.
I understand that logically, they are the same, but not syntax-wise, which is why I included the "differently formatted" "disclaimer", it wouldn't obviously understand that "one" and "1" is the same, but then again, should you? Depends on use case I'd say, hard to generalize.
Again, it's based on watching hearings and other media released by my government when they are talking about technology.
I'm in no way laughing at them for not understanding something. But I am laughing at those who pretend to understand something, or who simply ignore something because they don't understand it. It's not that hard to find experts in certain subjects, and it's really bad that they don't leverage this more for subjects they don't understand.
Watch any senate/congressional/government hearing about technology related subjects from your country's government and you'll see what I mean.
This way there won't be any misunderstandings about why some people seem more responsive than others, because now that person knows how to communicate with you.
Even without any proxies/WAF, PHP is always run (except in development environments with `php -S localhost:4124`) behind a web server, usually apache or nginx. Not sure about apache, but nginx defaults to a limit of 1MB for the request size (via `client_max_body_size` https://nginx.org/en/docs/http/ngx_http_core_module.html#cli...) and I can imagine apache have a similar default as well. Even if you allow requests to carry 1GB of data, this is still not exploitable, and if you have that large requests anyways, you usually find another way of doing the transfer than using plain HTTP requests.
Such an optimist!
For real though, I've heard this for every single "paradigm change" that has happened during the last ~20 years (and I'm sure many before me has heard it for even longer). Things will continue to move in some sort of direction.
From the screenshot:
> I don't think storing AWS keys within Slack would comply to any of these standards?
This is very interesting, I didn't know this. This is a perfect fit for PHP, as it was always designed with this model in mind, and the programmers that use PHP are already used to this way of developing, as that's exactly how php-fpm and mod_php already work and always have.
So I guess the killer feature for Fossil would be Fossil in that case, as Fossil is basically Git + GitHub but in one package, that works offline and local first.
As an interesting example, the very website in this submission (fossil-scm.org) is in fact just a standalone Fossil website, running as you'd run your own repository. Everything that is on that website, is something you get for free for each repository you use Fossil for.