174 karma · joined September 3, 2017
Here is the video of the conference: https://www.youtube.com/watch?v=xVfLW2JhBq8
IMHO static code analysis for this seems utterly useless, dead-end path to improve real-world NodeJS security.
But this is definitely not a security software company trying to spread FUD like some suspecting here
a fantastic tree visualization framework, its intended for phylogenetic analysis but can really be used for any type of tree/hierarchical structure
but hey, its Guido, I still can't fathom that he moved reduce into functools.
> We have an integrated terminal emulator supporting ecma-48. You can run vim or anything else within openage. This is neat to interactively edit scripts.
it runs vim!
My point would be that there are no "right" use-cases, I pointed it out because the article was talking about a specific thing: as the article points out in the outlined scenario: "It’s clear now, that throughput for PostgreSQL and MongoDB now is almost the same before the spinlock performance degradation hits MongoDB."
So the article points out there is a significant performance degradation after a certain number of connections in MongoDB, such things won't surprise me anymore I'll add it to the heap of things wrong with MongoDB, thats why I was making the comment.
> "We’ve got so far that throughput of PostgreSQL and MongoDB is the same for read workloads. Is it surprising? Not at all - I’m going to show you, that under the hood all our databases use more or less the same data structures and the same approach to store documents."
I'd argue that there is no reason to use MongoDB because there are no use-cases other more mature databases won't be equally or better suited for. MongoDB is horrid, you won't know all its deficiencies when you get started with it, but over time you will come to despise it, it is really far away from being a mature database and I would advice anyone against using it for any task, and I'm not the only one who was burned using it and who adopted this attitude towards it.
https://software.intel.com/en-us/articles/tensorflow-optimiz...
I don't think its such a good idea to over-dramatize these things for personal gain (like the author) because it hurts the security researcher community as a whole. I've already lost ANY trust of any security guys talking about the end of the world vulnerability they found, 99% of the time its bullshit like this. But I can read their disclosure and quickly discern whats irrelevant, I can imagine most non-IT people not able to do this and thus becoming MUCH more desensitized to ACTUAL vulnerabilities. Yet another boy who cried wolf security guy, they should've published this as "how to root your alexa" that would've been actually cool, this is just garbage.
https://www.theguardian.com/world/2017/dec/01/un-extreme-pov...
[1] https://en.wikipedia.org/wiki/Threshold_of_originality [2] https://en.wikipedia.org/wiki/Transformation_(law)
> Can I access to the network from the virtual machine ?
> Yes it is possible. It uses the websocket VPN offered by Benjamin Burns (see his blog[1]). The bandwidth is capped to 40 kB/s and at most two connections are allowed per public IP address. Please don't abuse the service.
[1] http://www.benjamincburns.com/2013/11/10/jor1k-ethmac-suppor...
One example is the way the request context works in flask, I venture to say thats just terrible software design in my book (from flask import request, g). And seriously to have your framework give you a "global" variable to put random stuff in, wth?
Also I rather not use Flask-SQLAlchemy since why should my database models be tied so incredibly closely to some library of my web MICRO framework, it doesn't make sense, I mean its not django why introduce this coupling?
It seems if you need all the dependent libraries (like webassets and wtforms) just use django from the get go instead of going through the pain of trying to cleanly integrate dozens of flask libraries.
To see how a proper simple middleware-based framework should look like consider express, koa (nodejs), or bottle, falcon. Aiohttp and tornado also have their place of course.
I would say the worst are the people who religiously believe everything he says, independent of any constraints or consideration of reality. I think he does undeniably accomplish some pretty amazing stuff, but that doesn't make me blind to his more idiotic ideas.
My favorite symptom of Elons delusions of grandeur so far, is his announcement to wanting to utilizing rockets as a means for intercontinental transportation, "London to New York rocket flights in 29 minutes". Maybe we can find some volunteers for a few test flights in a falcon 9? [http://www.bbc.com/news/science-environment-41441877]