In addition, the new work mentioned in this letter is ARI, or ACME Renewal Info, which is not directly tied to any of the aforementioned renewal methods.
1,065 karma · joined September 1, 2015
In addition, the new work mentioned in this letter is ARI, or ACME Renewal Info, which is not directly tied to any of the aforementioned renewal methods.
And then 60 days later, every single client tries to renew that certificate. That's another 200 million certs in 24 hours. And that'll repeat every 60 days.
So the ACME draft is also about being able to pro-actively smooth out that renewal spike. Some clients would be told to renew again immediately, less than 24 hours after their replacement. Others would be told to wait the whole 60 days. And then after a couple months of managing that, things would be back to normal.
> The singular includes the plural; the plural includes the singular. The masculine gender includes the feminine and neuter genders; and the neuter gender includes the masculine and feminine genders. "And" as well as "or" shall be construed either disjunctively or conjunctively, to bring within scope of this Special Order all responses that might otherwise be construed to be outside the scope. "Each" shall be construed to include "every", and "every" shall be construed to include "each". "Any" shall be construed to include "all", and "all" shall be construed to include "any". The use of a verb in any tense shall be construed as the use of the verb in a past or present tense, whenever necessary to bring within the scope of the document requests all responses which might otherwise be construed to be outside its scope.
I've seen similar paragraphs on other legal documents, but this is the most thorough I've seen. It's basically just a huge middle finger to all (any?) armchair lawyers who want to weasel out of the order.
[1] https://chromium.googlesource.com/chromium/tools/depot_tools... [2] https://commondatastorage.googleapis.com/chrome-infra-docs/f... [3] https://commondatastorage.googleapis.com/chrome-infra-docs/f... [4] https://commondatastorage.googleapis.com/chrome-infra-docs/f...
You don't need to own the CI server in order to own a project. You can take over all of the individual executors and replace their linker with your own version that links against an attacker-supplied backdoored fork of openssl (for an extreme and topical example). Doesn't even require constantly-running code which might be detected by a monitoring system, and naturally persists across reboots (but not reimagings).
I'm glad that GitLab is paying attention to these things. The Travis which is tightly integrated with GitHub also seems to do a good job, although I haven't looked into it extensively. But plenty of orgs run self-hosted CI that simply isn't up to proper security standards in this respect.
The real trick is owning someone's CI system via the code under test. And it's even more versatile because it works even for projects which keep their executor scripts checked in to source.
1) Check out and gain an understanding of the target's CI scripts
2) Create a pull request (or whatever) which makes some reasonable code change but also introduces a vulnerability into the build/test scripts themselves. For example, curl'ing a domain you control.
3) Kick off pre-commit runs of all the tests to see if your patch should be accepted.
4) Own all the devices testing your patch.
We didn't use Fortune's for historical reasons (the first versions of the code were in Fortran 77, and written well before he published his paper). Instead we generated triangulations and then flipped edges until they were Delaunay, and then used the corresponding Voronoi diagram. It turns out that flipping edges to produce a nicer triangulation is reasonable in two dimensions, but intractable in 3D and up.
a) what part of the regex am I currently trying to match
b) what point in the string am I currently starting at
c) how much of the string has this piece of the regex consumed so far
Then the state machine basically has three transitions:
* if (b+c) terminally matches (a), increment both (a) and (b) and reset (c)
* if (b+c) matches (a), but more could be consumed, increment (c) and check again
* if (b+c) doesn't match (a), increment (b) and reset (c)
So yeah, you could put in short cuts for things like "well this didn't match because the next piece of the regex is matching on a line ending", but keeping it simple is straightforward and generally smiled upon.
It turns out[3] that Jefferson wrote a first draft (of which only a fragment survives), then wrote the "original Rough draft" which is very similar to the document we know. 47 alterations were made before the vote for Independence, and 39 more between then and the official adoption of the document on July 4th.
I'd really like to see a version of this git repository accurately reflecting the fragment, original draft, all 86 revisions (in approximate order and attributed as well we can), and final version published as the Dunlap Broadside, instead of this anachronistic heap.
[1] https://github.com/usgov/forget-the-king/pull/1/commits/f9ff...
[2] https://github.com/usgov/forget-the-king/pull/1/commits/d041...
Both are forms of moral bankruptcy, I was just curious whether the seemingly-desperate employee was a victim or a player.
By your logic, I should hire 2 men, because dividing that candidate pool in half leaves the women at "less than half of a person". Equivalently, I should leave it up to a coin flip, which has an expected value of E(two men).
But why? Since we have already established that the candidates are in all other respects equal, why shouldn't I choose the candidates that I think will do my company the most good: bring in the most diverse perspectives, life experiences, and skill sets?
Of course it is a simplified example. And maybe you think that expressing an interest in diversity in this fashion is "reverse sexism". But I think it is a clear win for my company, a clear win for women everywhere, and I don't care if it isn't a clear win for men -- we win often enough anyway.
This isn't about the number of departments. This is about companies needing to make very real tradeoffs between maintaining their current speed/security/stability and investigating future talent.
The real cause is downgrade protection. When your browser loads an HTTPS page, it will refuse to load (or at least warn when loading) any other resources over HTTP: js, css, iframes, etc.
This is to ensure that the icon you see in your URL bar is actually accurate: if a page loads over HTTPS, but consists entirely of a single HTTP iframe, that nice green lock is totally meaningless.
So when the OP switched their site to HTTPS-only, they lost the ability to ever display any from HTTP-only bidders. So the set of people bidding on their ad slots went down, the price went down, and their revenue went down.
Assigning issues to multiple owners is a recipe for complete and utter inaction from all parties involved.