596 karma · joined February 20, 2015
- FAA ATP AMEL and ASEL certificate with CL-65 SIC rating and Part 121 experience; CE-510S rating (single pilot, Cessna Mustang)
- Helicopter ATP
- single-engine seaplane rating at the commercial level
- FAA Flight Instructor certificate with airplane single-engine, airplane multi-engine, helicopter, instrument airplane, and instrument helicopter ratings
He has also worked as a commercial pilot for Delta/Comair. See https://philip.greenspun.com/flying/resume
Given that it was just made public this morning, it would be surprising if it were otherwise. The real question is what the contribution model looks like going forward. The blog post says "Contributions are welcome, as are bug reports and feature requests"[1], but of course the devil is in the details.
1 - https://aws.amazon.com/blogs/aws/new-open-distro-for-elastic...
1) Extremely weak ones that lots of people use (e.g. 'password1') 2) Somewhat unique ones (their pet's name and birthday) 3) Truly strong ones (random, long strings)
I don't want users on my site using type 1 passwords at all. If a password is really type 3, the odds say that no user will ever try to use it again, so there's no collateral damage in blocking it. The person signing up with a type 2 is almost certainly the same user whose credentials are in the breach. I don't want them to reuse that password on my site because it makes their account vulnerable to credential stuffing.
Money quote: "You open the newspaper to an article on some subject you know well. In Murray's case, physics. In mine, show business. You read the article and see the journalist has absolutely no understanding of either the facts or the issues. Often, the article is so wrong it actually presents the story backward—reversing cause and effect. I call these the "wet streets cause rain" stories. Paper's full of them.
"In any case, you read with exasperation or amusement the multiple errors in a story, and then turn the page to national or international affairs, and read as if the rest of the newspaper was somehow more accurate about Palestine than the baloney you just read. You turn the page, and forget what you know."
[1] - https://hobbypcb.com/rs-hfiq [2] - https://www.pi-sdr.net/pi-sdr/index.php/pi-sdr-projects/pi-s...
Here's the source for the Gell-Mann Amnesia Effect quote: https://web.archive.org/web/20061020012137/http://www.cricht...
https://docs.aws.amazon.com/lambda/latest/dg/running-lambda-...
Still, it's definitely a bug. They should either fix it or remove the feature so people aren't misled into thinking their two-factor codes are secure when they're not.
1 - https://www.amazon.com/Stiff-Curious-Lives-Human-Cadavers/dp...
Here's a quote from one of them:
"We recently learned that certain hotel reservations made for Google business travel were among the many reservations affected by a security incident impacting a third-party provider’s electronic reservation system that serves thousands of travel agencies and hotels. This did not affect Google’s systems. However, this incident impacted one of the travel providers used by Googlers, Carlson Wagonlit Travel (CWT)."
The argument is that self-signed certificates on internal-only IPs aren't any less secure than plain HTTP.
1 - https://gitlab.com/android-on-freerunner/android-on-freerunn...