70 karma · joined August 31, 2015
Literally ever device has dubious utility and security so far.
Also its not even the right tool to build .net stuff. Add the shoddy dependency resolution steps plus the shitty performance of NTFS on lots of small files (MFT contention) we have to wait 8 minutes for a build. I wrote my own system in powershell and we're down to two minutes. Also, powershell sucks awfully too but that's another story.
Frustratingly I've played around with golang on and off for around two years now. I've not written anything significant in it yet (lack of opportunity more than anything else). You know what's cool about it?
I mastered the entire build system in about an hour and its the same on all platforms and it just works and works quickly.
MS: go look there for some inspiration. Building stuff for the CLR is horrible.
Having dealt with it for years, it's unadulterated pain and bad performance and nothing else.
http://docs.aws.amazon.com/AWSSdkDocsNET/latest/V3/Developer...
2. He pushed code to a new repository without verifying the security configuration of the created repository (granted the tool made it easy to do this but you should create a repo, verify it, then push code).
3. He used his master AWS account key/secret in the code which gave global access to everything.
4. He didn't use IAM credentials with a restrictive policy set to just access the resources required.
No, clearly not security concious.
I'm a solution architect in the financial services industry and have been for 16 years. Never do I assume I know what the hell I'm doing.
Also if you use a proper IAM profile locked down to specific resources then you wouldn't expose your entire account. The author stated he didn't use EC2 so why wasn't the key/secret pair an IAM account with a policy set for minimal access?
What I'd worry more about is that the VS bug exposed private source code, data and proprietary intellectual property.
We use github and I worry every day someone will public fork one of our repos by accident. That would be a grave fuck up but it's waiting to happen. We should have stuck with centrally controlled active-directory integrated SVN from a security perspective (even if it is a pain in the ass).