> I wanted to move all those functions on a server in my LAN.
Not so "serverless" after all eh?
117 karma · joined May 10, 2021
> I wanted to move all those functions on a server in my LAN.
Not so "serverless" after all eh?
If you're going to force MFA on users give them another option besides receiving a text message or phone call. I don't want to live with my phone attached to my body at all time, sometimes I just want to log in without having to go find where I left it. I have Yubikey, let me use that, or worst case, send a code to my email.
Standardizing on things like `cargo fmt`, `go fmt`, and `terraform fmt` remove a ton of nitpicking out the gate. The javascript world can't seem to make up their mind though (jslint is rarely used these days, jshint died, I think eslint is the thing now?)
Though I like Lightphone's aesthetic more.
Oh please do, its absolutely horrid. How are they even keeping up with Firefox security updates? The only conclusion I could come to, when investigating this, was that they aren't, and when I asked the company in a comment on their public blog how they were handling it they deleted my comment.
I was hoping Lightphone would be a strong contender for a non-smartphone but the reviews so far have been mixed and there seems to be a few serious issues (e.g. battery life), also there's no 2FA which honestly is one of the main things I use my phone for these days (not everything supports hardware 2FA)
I've seen this trip up people in the past, in one case a CI/CD system running Linux was used to produce a project deployed to a mostly windows environment this didn't cause any issues until the day a developer added a binary module. Honestly, I'm surprised it worked as long as it did, it took a little over a year before anyone hit that issue.
Aside from the Dreamcast, there's a few Japanese NAS devices that run the SH3 port too.
I've used both MySQL and PostgreSQL and I prefer MySQL, it seems to work and scale better "out of the box" and has a more comprehensible permission model than Postgres. I might be biased somewhat as I've used MySQL a lot longer and have even written plugins to interop with it but its still my number 2 go to (after SQLite)
One bank specifically I have to deal with will:
- Not allow you to paste a username/password (ctr+c/ctrl+v, right click disabled)
- Lastpass autofill doesn't work
- If the page loses focus, both user/password inputs are cleared, you get to start all over.
There is also a very small subset of special characters that are allowed. If you do not reset your password as often as they'd like, you have to agree to waive any responsibility for any issues with your account before logging in.
SMS 2FA required, there's no other 2FA option.
After entering your 2FA code, the "proceed" and "cancel" buttons are the exact same shape and color and I've hit the wrong one multiple times, in which case there is also SMS 2FA cool down and you have to wait 15 mins to start all over again.
It's absolute insanity and every time I have to login its an adventure.
Back when I was starting school and learning programming I also picked up an Arduino Duemilanove and learned Wiring and Processing which went together like peanut butter and jam. What an amazing time. I recall getting some of my processing apps to run on my Sony Erricson phone as they once had a way to convert the Processing sketches to a Java Mobile Edition apps (back before Andriod was widespread)
You can get around that requirement by having a specific location set aside for global modules (I use ~/.config/node/node_modules) and then putting the node_modules/bin directory in your path. Install anything there that some bone-headed project things you should install globally (mocha, grunt, serverless, etc.)
Also, I'm not disagreeing with the post at all, but there is at least one important distinction between piping curl output into bash and that is the expectation of what will happen after running the command.
Piping the output of curl into bash can result in absolutely anything happening, just like running a script you've never looked at.
Running `npm install` or `yarn install` _should_ just install the NPM module, possibly build a native module and not much else. There's numerous cases of NPM modules doing other things they shouldn't, and I'd argue invoking a compiler to build a native module is one of them too but there is at least an intention of what will occur. NPM is not alone in this regard either.
RPMs can execute arbitrary commands too (though coming from your distribution they will be vetted and signed), so can Make, but there are some expectation around what they will and will not do. With curl/bash anything is fair game as to what to expect.
Consider the usecase of generating a user their initial password for a service, this almost always results in the user needing to immediately reset their password after initial login, this doesn't happen if someone is generating both parts of the key pair for you.
My sysadmin doesn't need to know my password, and doesn't need to know my private key or passphrase, that would allow them to impersonate me.
> Send the user their private key via 1Password.
Why are you generating *private keys* for users, then sharing them? Not that this impacts the automation bits but IMHO users should known how to generate and maintain a key pair, and send you the public key.
I recall coming across a more detailed write up a long time ago but still found mention of the issue [0]
> our clients rarely have ECC memory. We see a constant rate of memory corruption in the wild and end-to-end integrity verification always pays off.
[0] https://dropbox.tech/infrastructure/-broccoli--syncing-faste...
Same thing with the "Grab" app in Asia, its just not worth fighting the cab drivers in Manila or Bangkok, when you can get a Grab driver they will give you zero drama but the cab drivers in those cities will haggle you, not use the meters, try to get you to go to some tourist trap, etc. Its not like that across those entire countries (Davao City notably has absolutely amazing taxi drivers) but the big cities are terrible.
South Korea, Japan, and Singapore have such amazing public transpiration options there's little need for taxis most of the time (though its worth noting that when I have used them I had zero issues in those countries, even in Seoul and Tokyo.)
> List of Items Controlled
> a. Any type of telecommunications equipment having any of the following characteristics, functions or features
> a.2. Specially hardened to withstand gamma, neutron or ion radiation;
is ECC memory now a controlled item?
FTP is plain text file transfer protocol, there's not really any good reason to use it anymore IMHO
FTPS is an extension to FTP to support SSL/TLS
SFTP is "Secure Shell File Transfer Protocol" (e.g. over SSH)
We had a project once where the customer asked us to use "SFTP" to manage some critical files. This was handled in-app, we added the functionality, did our testing and moved on.
Later when we did integration testing with their system we discovered that what the customer actually meant was to ask us for "FTPS" and we had to rip out the SFTP library with FTPS stuff.
Something similar _almost_ happened a couple of years later in another project (due to miscommunication by someone doing requirements gathering) and this time we caught it early.