473 karma · joined March 12, 2020
1. The Neocities random page: https://neocities.org/browse?sort_by=random
2. The Neocities recently updated page: https://neocities.org/activity
3. Status Cafe: https://status.cafe/
4. The MidnightPub: https://midnight.pub/
I stick to the POSIX standard for the reasons you note: https://pubs.opengroup.org/onlinepubs/9699919799/utilities/a...
If POSIX awk is insufficient, then I probably should be using something other than awk, so its limits are actually a good guardrail; however, it's shocking how powerful POSIX awk is with built-in arrays, hashmaps, regular expressions, etc., although no doubt there are quirks.
I guess and hope that simply directly asking for this is another strategy (and what I plan to do if I ever lose this job); otherwise, performing the above sort of misdirection, consciously, might also help justify the exception for management and peers.
No backlash or retaliation so far after more than 2 years.
Edited to add that the 3 day work week totals 20 hours.
It looks like you can just use OpenStreetMap instead, although the resources are donated so there is no guaranteed Service Level Agreement: https://operations.osmfoundation.org/policies/tiles/
Clearly display license attribution, normally in the bottom-right corner of the map.
Do not actively or passively encourage copyright infringement.
Recommended: Do not hardcode any URL to tile.openstreetmap.org as doing so will limit your ability to react if the service is disrupted or blocked. In particular, switching should be possible without requiring a software update.
Recommended: add a link to https://www.openstreetmap.org/fixthemap to allow your users to report and fix problems in our data.
Recommended: a contact email on your web page or app store page. If we cannot find contact information we will be unable to do anything except block if an issue arises.
Of course, there is no Service Level Agreement: Although our map tiles are generally very reliable, their availability to others is on a best effort basis and we offer no SLA or guarantees.
But that seems quite reasonable for donated resources. > [F5] decided to interfere with security policy nginx
> uses for years, ignoring both the policy and developers’ position.
>
> That’s quite understandable: they own the project, and can do
> anything with it, including doing marketing-motivated actions,
> ignoring developers position and community. Still, this
> contradicts our agreement. And, more importantly, I no longer able
> to control which changes are made in nginx within F5, and no longer
> see nginx as a free and open source project developed and
> maintained for the public good.
I'm not sure what "contradicts our agreement" means but the simple interpretation is that he feels that F5 have become too dictatorial to the open source project.The whole drama seems very short-sighted from F5's perspective. Maxim was working for you for free for years and you couldn't find some middle ground? I imagine there could have been some page on the free nginx project that listed CVEs that are in the enterprise product but that are not considered CVEs for the open source project given its stated policy of not creating CVEs for experimental features, or something like that.
To nuke the main developer, cause this rift in the community, and create a fork seems like a great microcosm of the general tendency of security leads to wield uncompromising power. I get it. Security is important. But security isn't everything and these little fiefdoms that security leads build up are bureaucratic and annoying.
I hope you understand that these uncompromising policies actually reduce security in the end because 10X developers like Maxim will start to tend to avoid the security team and, in the worst case, hide stuff from their security team. I've seen this play out over and over in large corporations. In that sense, the F5 security team is no different.
But there should be a collaborative, two-way process between security and development. I'm sure security leads will say that they have that, but that's not what I find. Ultimately, if there's an escalation, executives will side with the security lead, so it is a de facto dictatorship even if security leads will tend to avoid the nuclear option. But when you take the nuclear option, as you did in this case, don't be surprised by the consequences.
It probably helps to be a top performer and have years of experience. But if I were to be let go tomorrow, I'm sure it'll be difficult to find again. But I'm going to try! Never hurts to try when you know what you want.
I keep a low profile but the extra days per week are fun to fill! There does seem to be some sort of mental flip between 3 days and 4 days because I know that the majority of my week is whatever I want to do versus the majority (or vast majority) being work.
If it was the latter, I'm sorry to CloudFlare as this was user error.
However, I do think the two meta points still stand:
1. Better diagnostics: perhaps a FAQ page that lists common issues such as an overridden general.useragent.override, etc. (obviously without giving anything away to bad people, but I'm sure certain things such as this can be pointed out)
2. Better responsiveness in the community forum particularly to this category of errors which blocks public internet activity.
If it was the latter, I'm sorry to CloudFlare as this was user error.
However, I do think the two meta points still stand:
1. Better diagnostics: perhaps a FAQ page that lists common issues such as an overridden general.useragent.override, etc. (obviously without giving anything away to bad people, but I'm sure certain things such as this can be pointed out)
2. Better responsiveness in the community forum particularly to this category of errors which blocks public internet activity.
Right now I'm reviewing about:config for non-standard settings. I did find that I did set general.useragent.override at some point and I forgot about it; however, unsetting it didn't help. I went through all other non-default settings and haven't found anything yet.