Not sure where you got this from, but we've been using yubikeys for a few months now. They even allow policies to only allow physical 2FA methods.
1,232 karma · joined December 17, 2021
Not sure where you got this from, but we've been using yubikeys for a few months now. They even allow policies to only allow physical 2FA methods.
Hard disagree. Why is he reporting it to his own company? It's in his company's best interest for a competitor to have a security issue. He should have gone directly to the competitor's security team. Could have potentially gone anonymous. Could have gone through another person. A reputable security researcher. Lots of other things he could have done, but didn't.
Taking your example, if my friend doesn't show up, assuming I don't buy his excuse, it means a) I lose trust in him when it comes to something that matter, and b) I'm less likely to ask him to help me move next time.
First job after I finished university, and I joined a start up that looked relatively promising. It was my first my second corporate job, though the first was a terrible year in industry as part of my studies.
Leadership gave lots of promises (not just to me) about the company and all, and honestly, I'm pretty sure in the early days much of it was okay to promise.
I started on a relatively low salary. Got no options. Moved up the ladder, and got some options. It wasn't a lot, so I didn't think much of it. Heck, here in London, the stock options game for start ups is nowhere near as strong as the US (mind you, I didn't know about this back then either). I was never told about a strike price. I never read the options contract. Lots of mistakes on my part.
About a year and a half after I joined, I got a sizeable pay increase because I suppose I had shown my worth maybe? I dunno. Right around that time, structure changed a little bit. I made the mistake of not checking my pay cheque to validate I had been given my pay rise. For about 6 months I hadn't been given my new pay. I raise it with the relevant people. Because we had hired someone new, and they couldn't find the new contract I'd signed (???), the new person had to go to the CEO to double check. That took another 2 months (don't ask me why).
So I had about 8 months of the pay increase difference not paid, about ~£12k. They get back to me telling me they've confirmed that I was given the pay rise, but they won't be able to pay it in cash, and instead have to pay it in stock options. Without challenging it, I accepted, because I did believe the company would grow.
Fast forward another 1.5-2 years, and I realise the company is a sinking ship, or if not, it's just drifting aimlessly. So I leave. I hand in my notice. Over the next week or so I have meetings with plenty of people to persuade me to stay with all the promises (not even a promise of a pay rise). I'm not persuaded, so our CEO straight up tells me I will lose my stock options if I leave. Didn't even get possibility get my money back. Nothing.
7/8 years later, the company is still drifting. Many aren't paid in full, or on time. It may have been a bunch of costly naive mistakes on my part, but from what I'm hearing it would have cost me more if I'd stayed.
Moral of the story: you should double and triple check your contract, whether you're young or not.
YouTube has this built-in nowadays. The button is at the bottom of the player, on the right hand side, on the left of the subtitles/captions button.
> The biggest impediment is the ceremony for subprocessing out
Not sure I fully understand what you mean with this, but if I'm understanding it right, gorun attempts to solve this by doing `syscall.Exec()` on the compiled binary. Combined with slight variation on the "comment" hack (see examples in gorun's readme), signals get fully directed your binary.
// 2>/dev/null ; exec gorun "$0" "$@"
package main
// rest of the codeI hope the go devs will reconsider. I'd love to be able to use go for scripting. But as it stands, it's a sad state of affairs because you have to rely on hacks.
I've a BSc in one of the better universities for CS in the UK. I can barely implement any algorithm that I learned during my university years. The amount of times I've been told implement algorithm x, y, and z in the past ~10 odd years in my professional career has been zero. Conversely, the amount of times I've been asked to implement them during interviews has been way higher.
Unless you're hiring someone to implement such an algorithm, you shouldn't be using them as a test, because most, if not all, the algorithms we got taught during my CS degree, have one or more implementations to the point where I can just use those implementations. Heck, I wouldn't even want to waste time re-implementing it, and probably doing a bad job of it, when I can just use someone else implementation, who most likely will do it better than anything most people can.
I totally understand where you're coming from. The coding test I had to do at my current place took me few hours to do. The company is great, and I'm happy at the place, however, I would be lying if I didn't think twice when I got told I'd have to do a coding test after the initial screening. Certainly, I did feel insulted. The reason I ended up taking it was because it was very obviously just a test (i.e. they weren't trying to get free labour out of me). In the end, it all worked out, and I'm glad I did end up doing it.
On the flip side, sadly I've worked with a lot of people who just don't know how to code. Coding exercising aren't perfect either, but it certainly weeds out a whole lot of bad hires. I've worked with individuals who have essentially become "the documentation person". This is fine if you're in an enterprise, but in a small 3/4 person team, that one person holds back the rest a lot.
I think having a _set_ coding exercise that doesn't get free labour out of the candidate, it can help a lot towards having a stronger team. As a candidate, do be careful whose coding exercise you end up doing. There are still quite a few companies that try to get free labour out of candidates.
So yes, I think it is insulting unfortunately, but it is a necessary evil to build better teams, and avoid those who are, quite frankly, lying and are going to hold the team back.
One is the audio sometimes randomly jitters while simply playing music. It seems this only happens when I use my bluetooth headset, but is fine with built-in audio.
The other is, when the automatic switching to bluetooth headset is hit and miss. Sometimes it switches, sometimes it doesn't, and sometimes one applications switch, but others don't. So I'm left to use pavucontrol to switch things over correctly.
My searches haven't returned any fruitful results so I'm not if I'm just searching for the wrong things or I'm the only person who has these issues.
For example: "What would happen if all companies blocked individuals from doing what they want with the hardware they bought?" You get a hacking community and people imprisoned for the unlocked hardware they paid for. Not to mention a whole lot of ewaste that could otherwise work for years.
No, that's not a good example. How about this one: "What would happen if all companies opened up their hardware and stopped forcing people to upgrade for no reason?" Eutopia, that's what! Less ewaste. Less consumerism. People can actually use the hardware they paid for the way they want to use it.
This argument has been (ab)used since piracy has been a thing. I'm not aware of any company going under directly because of piracy, especially not just because of emulators. If there is one, I'd love to know, but even so, the numbers is negligible. Also, emulation is not the same piracy. While emulation can be used for piracy, it is not the main use case.
Corporations like Nintendo are not your friend.
<?php
function pipe(...$args) {
// Retrive first argument as initial value
$value = array_shift($args);
// Call the functions passing $value and assign its return
foreach($args as $func) $value = $func($value);
// Return computed value
return $value;
}
echo pipe("10 WAYS to EAT more HEALTHY",
fn($s) => strtolower($s),
fn($s) => str_replace(" ", "-", $s)
);
Works just as well.No because law makers have at every turn attempted to undermine encryption. What makes you think they'll suddenly fine and/or dismantle the assets of the NSA/GCHQ? These are the agencies that have been central to both countries' security in times of war. Times of war that seemingly has never ended.
I mean, sure, but let's be honest, a big majority of that is going to be spam, the next step down from that are silly little things like email verifications, password resets, notifications, newsletter spam, and other similar crap. As a millennial who doesn't touch emails for work or for personal reasons (because there is Slack, Signal or some other alternative to those two), I could very well be out of touch, but I'd be surprised if actual legitimate emails (both business and consumer) are more than 5% of that number.
I suppose 5% is still a big number, putting it at a comfortable ~16 billion emails.
Anyway, yes, we should be using encryption by default wherever possible, but honestly, encryption isn't easy for the common folk, which is going to be the majority of those 333 billion. Heck, I migrated away from PM and I struggled with a lot of it. As someone who mostly lives in the CLI, GnuPG is not easy to use. Something like MailVelope makes it easier, but still not that easy.
Then there is the matter of administration. Your sysadmin, especially of the bigger orgs, do not want encryption on your emails. Especially when the business you're in is regulated. Imagine being able to casually leak something without anyone knowing what's in the content? I know regulation is usually not a good answer for why not, but within a business, yes, it totally is. As a customer of Big Bank Corp, I do not want employees to be able to mess with my data, money, or worse, the money of the bank so that it can fail and for my money (or the tax payer's in case of govt protections) to be gone because everyone's emails were encrypted.
The only viable solution here is something like ProtonMail, which actually makes it easier to use, at $/£/€ 5 per month, not many are able to afford to part with that. And no, their free tier is really not that great. But regardless, even PM doesn't really help if a non PM user sends you an email.
> 1. Similarity in name with "Postman" may introduce trademark violations in future.
> 2. We don't want to hurt any other project's goodwill.
> 3. Rather than being an "alternative to Postman", we focus to become the best available testing suite in web.
[0] https://dev.to/liyasthomas/postwoman-is-changing-name-igp