172 karma · joined June 26, 2018
I believe it's everything since around 10pm ET last night. I would consider any runs in the past 24 hours to be suspect.
In case anyone is wondering where the next Celery release was.
We don't even have the job posted publicly anywhere and we get >100 submissions per day. Many are duplicates. I've found some that with some minor research turn out to be foreign organized crime. A large number of them had the exact same cover letter with changes in the names and past jobs.
Not only is it difficult to find candidates that actually fit the job role, it's hard to go through any that are even real people.
I've told many friends of mine to use connections and not online job postings because it's basically impossible right now with the automated resume submission companies.
And then the candidate management tools such as lever told me that no, every one of those candidates that applied were real people -- even when I provided proof that at least 40 of them were linked to a single organized crime group out of China.
Another example was he decided that all of PayPal needed to be Windows computers so every engineer has to stop what they were doing and convert. Board said stop, he said okay, then continued.
> Thank you for reaching out with your concern. Firefox is committed to creating an online experience that puts people first, as such we quickly stopped running the ad experience, and are reviewing internally.
> Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.
[1]: https://pages.nist.gov/800-63-3/sp800-63b.html#memsecretver
I have worked at another organization (hosted server provider) where I was in contact with the FBI and other law enforcement.
There's a world of difference between what was shown they did at twitter by noting things that were "worrisome" or against a reasonable site's ToS and forcing anyone to take things down.
I have told agents that certain materials were acceptable and that we would take no action. Not much they could do there without an actual warrant.
You might want to take a step back and evaluate that thought process.
Private entities are not violating freedom of speech as a legal construct and as an issue of an ideological construct - isn't it violating the private entities freedom of speech when they're being forced to host speech they don't agree with?
If you're saying that you believe a shadow governnent is controlling twitter and that's why it's considered free speech - since it's a government entity in that case, uh, I don't really think that's plausible.
I don't think this is a freedom of speech issue.
Instead, it's an issue that the private operators (codeberg & sourcehut) are looking to apply their own freedom of speech to take a stance against projects that have a high case of fraud.
You see the same thing from Stripe[1]: they ban similarity predatory systems from using their services & tarnishing their brand.
Medplum is a truly amazing solution to so many problems of building healthcare apps quickly. Before I had started chatting with the Medplum team it felt like an insurmountable task to experiment in the EHR area - the amount of infra & prep work we'd have to do made it so even for a proof of concept we'd have months before we could see anything useful.
It's really awesome to have so much of the hard part of handling health records done for us - and the depth of knowledge of the Medplum team is bar none when it comes to this area.
Y'all rock, congrats on the launch.
Solves some of the session problems..
Benefits:
Cookies - when set to http only + secure only are safer?
Drawbacks:
They're not cross-compatible No expiration baked in No not-before baked in Limited to hmac validation (no public key crypto options that I know of)
Unless you mean using a JWT as a cookie value. I guess that could work?