166 karma · joined May 26, 2019
Previously I worked on an open source project that pulled in many third party libraries. Users would run their corpo vulnerability scanners on the project and find dependencies with open CVEs and demand fixes, not understanding that in our usage of the libraries, the vulnerability is not exposed.
I think in 4 years, we had users open roughly 50 issues like this, which corresponded to exactly 0 real world exploitable issues.
A central vuln DB makes sense for sysadmins, but too many make it the end-all-be-all.
> Lt. Cmdr Tim Gorman [...] said that emails sent directly from the .mil domain to Malian addresses “are blocked before they leave the .mil domain and the sender is notified that they must validate the email addresses of the intended recipients”.
I think the issue is people sending emails from personal accounts that the DOD cannot control. The article also mentions travel agents as another source of the email.
> Many supporters like you who understand the usefulness of planning ahead have chosen to include a gift to Wikipedia in their will. They want to do more to protect free knowledge and are invested in building a legacy with Wikipedia to ensure their values live on for many years to come.
"If you understood the importance of planning ahead, you'd already have WikiMedia in your will, bozo"
https://github.com/cypress-io/cypress/blob/develop/cli/types...
[0]: https://github.com/JoshuaKGoldberg/eslint-plugin-expect-type
`xfinity2@mydomain.com` is the only email that I've ever caught being sold via my catch-all email. I get a decent amount of phishing, scams, malware, etc. to that address. But I guess the author is still correct, since Xfinity/Comcast are sometimes less than legitimate.
What is this referring to? You've piqued my interest.
Otherwise, that would work fine, but not all motherboards support power-on via USB HID, most support PS/2 though.
Yup, that matches my experience, that's (partially) why I called the site "unusable"
I do think that they were being "more honest" than other cloud providers, since I've noticed that almost every PAAS or SAAS will have brief outages for small sections of the userbase that aren't mentioned on their status page, either out of laziness or for the PR.
It's a little awkward since a lot of internal software is still configured to whitelist all access from that space since it was a constant for so long.