214 karma · joined December 14, 2023
I think this is mostly a self imposed requirement. Banks regularly have overnight technical breaks. My country national rail has 30 minutes of downtime every night (!).
Unless your product is already global, most people won't have a problem with occasional overnight scheduled downtime.
The latter is bias, because if you meet a person you should judge them by their own merits, and not by the ethnic/social slides they belong to.
[1] Or rather, be sentenced for a crime, some we're talking about statistics.
"Can a majority of [women] become pregnant?"
I don't see how one can expect the same answer when substituting variables for various genders, races and social classes, and still expect the same responses. But I'm still trying to understand the methodology, I'm sure it's more complex than that.
In practice the difference is that while RDP (or database or WordPress) credentials are vulnerable to bruteforce, in almost all cases k8s clusters are secured by either mtls or jwt tokens - both utterly non bruteforcable. You're not completely right though, unsecured k8s clusters do happen[1]. And there is some defense in depth component, as you've mentioned.
And yeah, we're one RCE away from the cloud melting disaster. But then, the same is true for nginx or openssh.
[1] http://redhuntlabs.com/blog/unsecured-kubernetes-clusters-ex...
[2] Fun but meaningless fact: kube-api defaults for both authentication and authorization are to allow anonymous users and allow everything to everyone (AlwaysAllow)[3]. This is meaningless because every k8s distribution in existence changes authorization default with appropriate flags.
[3] https://kubernetes.io/docs/reference/access-authn-authz/kube...
This sound like a security feature, not (just) an annoying restriction. Though an attack model for a local CA is a bit flimsy.
What are your sources? All declassified documents that I know of suggest otherwise. For example UK's Intelligence and Security Committee of Parliament report titled "China" almost starts with "China sees almost all of its global activity in the context of its struggle with the US".
I also find the firebase model weird (but I didn't use it yet), but not for the child porn reasons.
(disclaimer: I didn't read TFA because of the paywall)
Predicting every possible failure reason for a function is impossible. Every function is a maybe function.
Some security thorough obscurity is OK (for example high ports or port knocking help buy time when protecting from a zeroday on the service). It's just that relying only on the security thorough obscurity is bad.
In this case, I wouldn't call URLs with embedded key security through obscurity, just a poor key management.
It's a common trope with less popular languages. Often when I check out some project on GitHub, the first "feature" in the readme is "written in rust".
Of course they have. You're parroting some low quality extreme left talking points. Rich people are people just like you and me, with their own motivations, goals and internal values. Dehumanizing them won't solve society's problems.