77 karma · joined June 19, 2011
The problem is that there is a way for untrusted user input to ever touch a shell in the first place.
Seriously, I challenge you to find a language reference that doesn't decry the use of their version of system(3)---because all that does is run the given command under the user's shell.
All that said, between Gmail's spam filter, my avoidance of all things bitcoin, and common sense with passwords (don't ever re-use them), most of the damage caused by this doesn't affect me.
I will note, however, that this are why "when you hit return in the URL bar, what actually happens," is a valid interview question, in the same unfortunate sense that FizzBuzz is a valid interview question.
I'm asking you why you thought the knife would stop cutting things when it hit your hand instead of the loaf of bread.
If you give rsync command a source or destination with an unescaped colon, it will read an ENVIRONMENT VARIABLE to figure out a command to run to AUTOMATICALLY CONNECT TO ARBITRARY NETWORK RESOURCES. If you have keys, it will even SKIP PASSWORD ENTRY, and with default Kerberos, it will not only skip password, but make a network connections to a login server:port specified by a DNS ENTRY.
Seriously, who is this guy, and why is this trainwreck #1 on HN?
Similarly, if we do the obvious thing and conflate "left wing" and "socialist", and believe that socialism has an ideological character beyond simply hating the existing organization of society, then extermination, slavery, thuggery, coercion, and violence are inherently anti-socialist.
This view is also the conclusion Orwell was operating under---the utopian ideal of capital-S Socialism which he approved of was used as operating cover to assist in the seizing of power by technocratic middle classes.
This view was pretty much explicitly stated in the Goldstein treatises in 1984, which described "English Socialism" as actually a form of "oligarchical collectivism," and claimed that "The Party rejects and vilifies every principle for which the Socialist movement originally stood, and it does so in the name of Socialism."
Similarly, there's this bit from the supposedly ex-Trotskyist James Burnham (who Orwell rightly abuses for being a power-worshiping scumbag):
"Some apologists try to excuse Marxism by saying that it has ‘never had a chance’. This is far from the truth. Marxism and the Marxist parties have had dozens of chances. In Russia, a Marxist party took power. Within a short time it abandoned Socialism; if not in words, at any rate in the effect of its actions. In most European nations there were during the last months of the first world war and the years immediately thereafter, social crises which left a wide-open door for the Marxist parties: without exception they proved unable to take and hold power. In a large number of countries — Germany, Denmark, Norway, Sweden, Austria, England, Australia, New Zealand, Spain, France — the reformist Marxist parties have administered the governments, and have uniformly failed to introduce Socialism or make any genuine step towards Socialism... These parties have, in practice, at every historical test — and there have been many — either failed Socialism or abandoned it. This is the fact which neither the bitterest foe nor the most ardent friend of Socialism can erase. This fact does not, as some think, prove anything about the moral quality of the Socialist ideal. But it does constitute unblinkable evidence that, whatever its moral quality, Socialism is not going to come."
To be fair, it's easy to believe claims about Stalin not being a socialist are simply ego-bruised leftists invoking the No True Scotsman fallacy. I don't think this necessarily applies simply because socialism is inherently an ideology. If someone claims to be a pacifist while marauding through a public place with an assault rifle, massacring people as they go, we have no problem resolving this dissonance: the murderer's claims of pacifism are simply lies.
Of course, pacifism was never taken all that seriously to begin with, so it's safe for us to simply say "you're lying about being a pacifist." We feel a bit more constrained telling someone they're lying about their status as a Christian or a socialist.
I agree that Java should use the certs the system provides, and that is a PITA to wrestle with keytool, but I also know that the self-signed cert that apache is using is not trusted by your PC either (so you've got work to do regardless).
HTTPS is built on top of PKI, which involves a list of trusted root authorities who verify that the certificate for blahblah.com is actually for blahblah.com. A self-signed certificate won't have that, and any application that doesn't validate that the certificate is signed by a trusted authority and not expired, etc. has no security.
If an application doesn't validate it's certificate, anybody sitting between you and the HTTPS server can step in between you and your traffic, give you a phony certificate, and then proxy all your "secure" traffic to the HTTPS server. And, of course, "sitting between you and the HTTPS server" means not only the NSA with their low-latency network specifically built to conduct these types of attacks, it also means the guy in the corner at Starbucks too (because WiFi is a radio).
Java only actually started checking if certificates were valid very recently (IIRC it was J7, r51). Prior to that, Java was just as lax as every other toolkit---probably specifically to address complaints like Bray's: "testing HTTPS is tough".
Ironically, those who have lived and breathed vaccines for years (i.e. experts) seem to know nothing about that enormous trust placed in the vaccination process by the public---the public assumes it works and assumes it's there to keep you safe, but knows so little about them that even simple questions of safety will be translated into "vaccines bad."
http://www.carnegiecouncil.org/publications/journal/17_1/rou...
Given that Iraq was a belligerent in both the Iran-Iraq war and Kuwaiti invasion, that's reasonable on it's face. Of course, that presumes you aren't aware the U.S. supported Iraq in the former (to the degree that we ignored the only successful missile attack on a U.S. ship in history), and said "we have no opinion" two months before the latter. I presume an "expert" on IR and national security would know both of those facts---so why make that claim? Regarding Iraqi deception about WMDs... well, we know how that one turned out, don't we?
There are conscientious members of every university's IR staff, but there are also plenty of cryptofacists and priests-for-hire giving the discipline a bad reputation. I certainly hope students challenge this kind of man's pronouncements, because they are better humans and better thinkers for doing so.
In other words, he is very much an expert on (at least) the vaccinations in his study. His celebrity came later.
Seriously, it's a link of this:
"Oh my goodness, Google University means people are now increasingly questioning experts, like me! And doctors!"
"What are you an expert in?"
"History. I teach at the War College and write about nuclear weapons. For example, I just republished an essay I wrote 14 years ago on how responsible documentaries of the Cold War must necessarily exclude examinations of Soviet motivations, because Stalin was the bad guy."
"...Yes, it's truly a wonder why anyone could fail to trust your proclamations of genius."
Regarding proposing solutions, Bruce Schneier, who was describing TSA efforts as "security theater" at least 5 years ago, is perhaps among the most famous: he's been on 60 Minutes over the issue, publicly debated the former head of the TSA, and testified before Congress as to what measures real security would entail. Just last week there was a humorously worded rant about the TSA's stunning lack of competence by the former head of Israeli airport security, Rafi Sela.
It's also worth noting that the biggest objectively measurable improvement to travellers' security is the change in attitude of travellers themselves. The belief of passengers that they will be flown to Cuba and a release negotiated was dispelled even before 9/11 was over. These days, when someone tries to light their shoes on fire, passengers can be reliably counted upon to beat them down. Literally.
Stockbrokers (broker-dealers) are required by the SEC to record all text-based electronic communications, keep 7 years worth of backup on write-once, read-many media (e.g. DVD), and upload copies to a third party (to prevent "sorry, sir, the dog ate all the emails where the traders were talking about rigging LIBOR"-style excuses).
I assume there's something similar for US-listed companies, thanks to Enron.
Pointing out that someone whose point I agree with is using bad math as evidence is not disagreeing with the point, it's asking that people who agree with me behave like honest, civilized, human beings---I don't care that you've already gone through the hassle of getting your pitchforks out of storage.
Speaking of which... your accusation that they are lying means that Github has had nearly 37 days of total outage this year---that they're down for two and a half hours a day, every day, for a year straight. And by honest, I assume you mean "they are lying", as opposed to "they are using a different definition of uptime than I would like." Naturally, you have some evidence for these claims, right?
It's 99.770% for a single month, immediately following a major event. If you sampled yesterday (or tomorrow, assuming no further issues) it would be higher. If you just look at today, it's at the much lower at 95.871%. If you assume no availability issues for the last 12 months (not true, but the point remains) then it's 99.981%. During an actual outage, availability was at the unacceptable 0%.
Unfortunately they don't provide 12mo stats, which is what you typically want if you're going to start calculating nines of availability.
Those bastards!
gasp
hahahahahahahahahahahahahahahahahahahaha.
Also, I'd like to meet people that don't resort to emotional blackmail in order to try and force nerds to provide them free goods or services.
And I'd also like a pony.
FC getting banned from GNOME's bugzilla isn't a GNOME thing, it's an FC thing.