626 karma · joined May 30, 2011
* Before giving you my email address, I'd like some reassurances that you won't spam me, etc.
* It took 10-20 seconds to create my account. Not sure what's going on there, but you might want to investigate that. This doesn't appear to be a fluke. When I logged out, then logged back in again, it also took 10-20 seconds to log in after entering my credentials.
Also, if I log in, then go to the Kwelia home page, then click on "Apartment Ratings", it brings up a login page stating that I'm already logged in, whereas I would expect it to take me to the Apartment Ratings page.
This tool looks really promising. Let me know if you ever add support for Portland, OR.
With that said, I'm not convinced that your pseudocode actually works. Specifically, the following doesn't make sense to me:
pos_a = key[0];
pos_b = key[1];
pos_c = key[2];
...
pos_a = key[pos_b] % key_size;
It would be really cool if you posted functioning encrypt() and decrypt() methods to github. Something that people can actually compile/run/analyze. In fact, if you do that get in touch with me and I'll try to crack it.
http://en.wikipedia.org/wiki/File:2008_Top1percentUSA.png
http://en.wikipedia.org/wiki/Income_inequality_in_the_United...
-Sleeping better
-Being awake and functional in the morning, even before the caffeine kicks in
-Having a consistent energy level throughout the day
-24oz of soda/day is not healthy, so getting that out of my diet was definitely a good thing
The only downside is that the startup I work for now has a tab with a number of local coffee shops that I can't take advantage of :(-Estonia has an internet voting system
-Estonia just released the source code to their voting system
Even if internet voting is a terrible idea, a transparent election system is a very good idea, and releasing the source code for your voting system is a big step in that direction.
Edit: one advantage I can think of is you don't have to ask your users to set up a bond0 interface, for example. Any other advantages?
The vulnerability allows users to use a command-line switch for a PostgreSQL connection intended for single-user recovery mode while PostgreSQL is running in normal, multiuser mode. This can be used to harm the server.
"What we have today works pretty well for our current size—around 45 people."
So if I can manage to get the Google authentication credentials for just one of Stripe's 45 employees, I can get access to the vast majority of Stripe's email? I hope they require two factor authentication.
# Invoke curl in silent mode (-s), pipe the output to grep
# and use an extended regex (-E) to only show the resulting
# digits (-o: only print matching text, not the whole line):
curl -s checkip.dyndns.org | grep -Eo '[0-9\.]+'
<shameless plug> For those interested, a recent blog post of mine analyzes a similar attack that uses CVE-2008-5353: http://jsaxton.com/fun-with-wireshark-and-ie-java-exploits-p... </shameless plug>
Its flaws are very very well known, and this is a virtue. All languages and implementations have gotchas and hangups. C is just far more upfront about it. And there are a ton of static and runtime tools to help you deal with the most common and dangerous mistakes. That some of the most heavily used and reliable software in the world is built on C is proof that the flaws are overblown, and easy to detect and fix.
On the other hand, as the author said, C is over 40 years old. Many consider that a weakness, but he considers it a strength, given the large number of C libraries available, whereas you don't have the same number of libraries with native Go bindings. Ultimately, of course, it comes down to using the right tool for the job. That may be C, that may be Go, that may be a higher-level language like Python, Ruby, etc.
What if dropping Pinball was not an option? The cost to the shareholder would have been much higher than it needed to be.
* If memory serves correctly, if your system runs out of memory, shouldn't the scheduler kill processes that are using too much memory? If this is the case, the system should recover from the OOM error and no restart should be needed.
* OOM errors aren't the only way to get a system into a state where you cannot SSH into a system. It would be great to have a more general solution.
* Even if you do restart, unless you had some kind of performance monitoring enabled, the system is no longer in the high-memory state so it will take a bit of digging to determine the root cause. If OOM errors are logged to syslog or something, I guess this isn't a big deal.
I suppose the best fail-safe solution is to ensure you always have one of the following:
* physical access to the system
* a way to access the console indirectly (something like VSphere comes to mind)
* Services like linode allow you to restart your system remotely, which would have been useful in this scenario
Age bias is awful, and I have worked with a lot of older developers who know their stuff and are extremely competent, but the idea that 25 years of experience automatically makes you a better programmer is wrong. Good developers are able to learn and adapt quickly, and often older developers can't do that.
If you decrease the amount of time a connection sits in a TIME-WAIT state, you will increase the probability that a new connection could receive a packet from a previous connection. Given the latency of mobile networks, I would expect the probability of receiving a packet from a previous connection to be even higher.
If you're interested, the beginning of the following paper provides a great overview of the problem: http://www.isi.edu/touch/pubs/infocomm99/infocomm99-web/
On another note, the original statement in question kind of reminds me of a Steve Jobs quote:
"I really didn't want them to open up my body, so I tried to see if a few other things would work."
I agree that there's a fine line between making a legitimate sales pitch for your startup and lying to your investors, but the article doesn't address that point at all.