Totally a lame vulnerability? Yes. Pretty effective? Also yes. If you go back in the github issue[1], it was even good enough to fool Chris, who founded the site, for 10 seconds.
511 karma · joined September 8, 2014
[ my public key: https://keybase.io/ej; my proof: https://keybase.io/ej/sigs/C3HkPc4k5SISC7AK-sWYBiQ6q08dOW-MVrdoWl16x_4 ]
Totally a lame vulnerability? Yes. Pretty effective? Also yes. If you go back in the github issue[1], it was even good enough to fool Chris, who founded the site, for 10 seconds.
The thing about the process is one bad moment spoils the entire process for the candidate. Shallow/No responses, or horrible questions, or something unprofessional being said during the interview.
It's not just $AAPL it is everyone, but if you are an interviewer or a recruiter, please fight for the candidates to get good responses and good questions, especially if you fly someone across the globe to awkwardly sit in a room for 6 hours.
We each had a 9 digit code that looked like 10XXXXXXX. These numbers were incremented from one student or faculty to the next.
The only track that mattered was track 2. It had your 9 digit code, followed by a the school code (3 digits), followed by a "lost card digit" that was incremented each time a card was lost (obviously mod 10 here).
So if my ID was 100000001, I went to school 002, had lost my card two times, my current card's Track 2 would say: 1000000010022
Needless to say there are tons of things that can be done here. From getting access to rooms does not, to getting free lunches.
Pretty interesting things. I told my school and they didn't really care at all (as expected). The potential loss from this is so low that it they didn't bother since abusing these issues would get you arrested and expelled pretty quick.
In reality, it is probably pretty serious. This student id is used somewhat as a School social security number. You can take tests as other students or impersonate other students in a lot of different situations.
If you are able to demonstrate all that talent (github, outside projects, anything else) and you are able to hold a conversation with people, there are literally thousands of openings for you.
The certifications only really matter to Washington DC (or people making money off of DC).
Apply more places, make some things on the side that demonstrate you know what you're talking about, and look for positions at large, stable companies.
While working on a project to learn go, I was using postfix to pipe email directly to a Go program, that then sent them as an SMS. I couldn't help but thinking how old and clunky the software I was using felt. The Go ended up being done in an hour and the postfix part took me 2 nights.
The same goes for all of the other email protocols and software. It's all big, bulky, and complicated. especially considering how much of a backbone email is to business today.
I know of the mailinabox project that was meant to package and abstract out a lot of the difficulties, but found that even that was too complicated.
Does anyone know of any projects meant to simplify the email stack?
It will get better but for now I think writing a full web-app in Go, (presentation etc) is pretty annoying.
I must say, writing an API and some other services (SMTP pipe listener) was much nicer in Go than Authentication.
There is gorilla/sessions for sessions, but there's a lot to be desired here. A weak secret here means other people can decrypt the SessionStore Blob and possibly get secret information as a passive attacker or authenticate as another user. This sessionstore passphrase is the key to your entire webapp.
There's also nothing built in to Go for CSRF tokens, and HTMLTemplates are nice for preventing XSS but a pain in the butt for embedding, generating, and storing/regenerating (depending on how big you are) CSRF tokens.
Overall though....Writing Go has been pure joy for me. These are super knitpicky things to complain about.
Alsp, many speakers are working on their slides and talk minutes before going on. These talks get finished notoriously late
For example, I don't have the slightest clue what the answer is to probably half of these and a lot of my job is to write javascript that gets run millions to billions of times a day. The "code questions", by contrast, were all ridiculously easy.
So, would it really matter if you are hiring someone who doesn't remember the difference between .call and .apply off the top of their head?
I fall into the category of starting too many things that I don't finish. I've recently realized that the size of the things I was working in was just way too big, especially since When working on a side project you are working around your life schedule.
After limiting the size of my projects I've found I am completing all of them
Things like "Using an API Key", and "Using git" cause students to HAVE to go above and beyond the assignment Because they will undoubtedly run into a problem with some of these extra steps along the way.
I think this type of learning can be more beneficial than the assignment itself. It's real problem solving using the computers.
That's just cool to see.
Having code like this to begin with changes how all your future code works. It also is easier to debug, simpler to explain, etc. You think twice about adding new API calls, which makes you think twice before you add new bugs. Having the ability to muck around with API calls you shouldn't be making will catch you eventually.
I've posted this before, but web-app security in most startups I look at is so bad. If it's written in PHP, I can normally find every bug in the book in under 5 minutes. What is worse on top of that is many companies don't respond (and don't fix) when you report bugs. I'm talking well known startups too.
I really think the OWASP Top 10 needs to be required reading for startup founders (or technical leads).
The legal system is very complicated and sometimes small details make very big differences in cases. I'm not convinced others in the legal system would see this as different
This type of blatant insecurity definitely should be punished and I wish more policy makers both cared, and made the effort to understand the terminology behind phrases like "No authentication", "Plaintext", Etc.
https://www.facebook.com/notes/facebook-engineering/xhp-a-ne...
I've been using XHP at work and love the improvements it has made to the new code we are writing.
Posting this might not seem relevant, but the examples of "replacing php with javascript" show one of the ugliest parts of PHP, and that is when presentation becomes super tangled with business logic.
XHP is really really nice for outputting the contents of an array into HTML (for example..it has many other really nice uses), and it would be very cool to see them do something like that.
I got the woff files, base64'd them, and then threw the output into several CSS files.
Words of warning, If you use Content Security policy, you must allow Unsafe Inline for the style-src directive.
It makes my life a little more convenient. https://github.com/steakejjs/OpenSans-CSS/blob/master/OpenSa...
While a company should definitely have a whois page, most startups make it abundantly clear how to get ahold of someone at the company with large "Contact Us" buttons.
I've never contacted a startup to report a security issue, gotten a response (some don't respond), and had it not be from someone in a position to have the issue worked on immediately.
Re run my program on a different port, point nginx at the new port, reload nginx, kill the old.
Curious what is so bad about this approach? I admit it's hacky, but it works. Is there just too many things to do?
Using goto for error cleanup is pretty standard, easily readable, and understandable.
It avoids ugly braces and depth.
So, are gotos bad? It depends.
One thing that it is proving (exactly as a lot of people expected) is, we don't have any idea where security bugs (think the next heartbleed or shellshock) are going to show up, we have no idea how good the software out there is (meaning it is bad), and most of the time we don't even know what's running on our own boxes.
If these basic things we use hundreds of times a day (less, strings) have huge flaws, we have a lot of work ahead of us.
Some were tricky but some were things that you definitely should have (like Sam Adams Winter). This will be really great when it's more complete but there is still some work to do
Seems neat to me, and pretty unexpected. One scary thing is just how bad a lot of passwords are for mobile applications. I'm sure it is even easier to brute force passwords on mobile and send a snapcash to yourself
api.com/steakejjs/v1/
This way, user's of your API can implement Content-Security-Policy in a secure manner (where an attacker can't use your 3rd party API to exfiltrate data). It's not like there aren't other ways to exfiltrate data, but this will definitely help.
carbs, sugar, low dairy, small portions? What does this leave you to eat? The average person will go crazy following these rules.
The problem is people aren't realistic about what they are eating and their activity level. It is okay to eat poptarts, icecream, whatever it is you like. But do so in moderation. It's not okay to develop a habit of gluttony while on the couch.