405 karma · joined April 24, 2013
For the price, what does it get you?
<script>javascript</script> is the first payload you try when looking for the stupidest XSS you can find....
To people out there. If you are going to talk about somewhat controversial topics, the ``my opinions are my own'' you put on your twitter probably isn't enough protection.
I specialize in webapp security, cryptography, android security, and love PHP (developers nightmare is a hackers dream).
Contact me at my profile's email address
I'm about to start working at a SaaS startup security company.
My point is that while open-source should be better, right now it seems that everything is equally not good enough.
Both of these are hypothetical, however. We've seen tons of vulnerabilities from both. IMHO Open Source works a lot better on paper but once projects get very large auditing them is really hard...which definitely cuts down on the amount of eyes looking at them.
You're drawing conclusions from information that doesn't lead you to one.
So I applied to college and went to a pretty big state school (for my area).
I'm really blessed to end up where I've ended up after graduation. I know so many really really good classmates who have a lot of talent and never even get a glance when looking for jobs at some of these companies. It really just isn't fair sometimes...
It depends on what you do. A secretary will make far less than the chief of police but they both happen to be government workers....how is that not obvious..?
At the University I went to, anyone who expressed interest in security and had good grades could get a ridiculously generous scholarship (tuition + $20k stipend + books + $1000 for conferences, and a guaranteed summer internship). A catch to this is you must be able to get a clearance, and if your clearance is denied you lose the scholarship and have to pay back the money.
Basically, all the students who were not into that kind of stuff went straight for it and had jobs at 3 letter agencies on graduation.
Yeah a lot of security people like marijuana but a lot of them don't.
The way I looked at it was "If I'm going to choose to smoke marijuana I have to be twice as good as everyone else in order to ensure I get a job that does not require a security clearance" (which is odd because I later chose not to smoke marijuana).
But...there are plenty out there who already have no problem getting jobs at these agencies after being clean for 1year or just not being interested in those things.
It also isn't hard to find gyms with bumper plates that are powerlifting/oly friendly, or specialized gyms that have whatever your in to (rock climbinb gyms exist, etc)... You just have to do your research
I disagree that their goal is "Sports conditioning training". Because this is not consistent with their who their clientele is. Their vast majority of their clientele is average people, with no prior lifting experience, who have heard of it.
But the diehard fans aren't the worst part. Cross fit the organization loves to shut people down who speak poorly of them. They also have made a lot of unsubstantiated claims about the type of results that can be expected by following cross fit programming (which is laughably bad). Its also thought that they run the cross fit games unfairly since there is a conflict of interest in sponsoring their top athletes and putting on the cross fit games where their sponsored athletes and no sponsored compete.
The worst part is the bad programming and the dangers of having a coach who is instructing you to do things that are obviously bad ideas. Extremely high rep oly lifting is a reciepe for disaster since the lifts are very skill based.
With all that said. One thing about cross fit is really good. They have got people training with barbells and started a lot of people down a path where they can start getting information they need to train better and smarter. But I'll be saving my 100 a month..
You're echoing the problem that my question is asking if it solves...
Edit: Also, you definitely need more than the code to come from a "trusted third party", otherwise we would see SaaS startups on HN providing "crypto as a service" (god help us).
I don't understand what people's obsession with browser crypto is...but I don't know enough about browser's to think of a reason this solution is bad. Any guidance?
edit: I understand that this won't solve all the problems...but at least the problem that you are constantly being served this chunk of potentially unsafe code.
edit2: I've been doing some thinking. Even though I didn't really get a response I think the reason is that it doesn't buy you the ability to do anything new safely. You still have the old problems of other dom elements mucking with your dom elements that control the code, or whatever the site does...so it doesn't really buy you anything...it's just work for nothing.
I still think it would be a useful start to one day having safe browser crypto
All I know is they sent her plaintext passwords to her, which she redacted before sending to me....