114 karma · joined December 10, 2016
Using the fastapi example, it points to CVE-2024-24762 which, if you're looking at the NIST or CVE pages for it, doesn't give the clearest info for how to resolve.
Maybe consider linking to advisories in the Python Packaging Advisory Database when possible, like pip-audit does. https://osv.dev/vulnerability/PYSEC-2024-38 is a lot clearer that fastapi is affected and which version fixed the vulnerability.
There was a "Gold" version they sold at retail for some time that had a WYSIWYG editor in it, until they made it standard as part of the Communicator suite.
We also aren't just talking about blocking DDoS and other common vulnerability scanning. Depending on your business there are other potentially costly fraud and abuse scenarios that you are blocking just by blocking other countries outright. Until there are tools to block all this that are as easy to apply as a geoblock, this will probably remain the unfortunate state of things. A lot of businesses just don't have the time or resources to manage all of this without applying geoblocks.
I do get the desire for them to want an audience to give updates to and try to have a consistent user base. The thing that sucks is that not only do they want to email me, so does everyone else. I've never been very protective of my inbox but the volume has gotten crazy recently so that's had to change. If they let me in and then asked for my email to continue after a couple minutes I'd be more inclined to provide it.
In that example the domain is likely compromised though, so you need to be reporting to all the hosting providers involved as well and not just the registrar.
why would anyone ever WANT to work for a company that... vs why would anyone ever work for a company that...