222 karma · joined May 31, 2013
It is far from certain that any application has such a "steady state", most of the ones I've worked on sure don't. There are obviously ways to analyze things and correlate enqueued and dequeues, but it is far from as simple and black and white as you suggest, especially with truly distributed systems and unknown cause of the reported behavior.
Heck, we don't even know if the messages are being "dropped" or just duplicated.
Then, the entire point for some lawsuits existing is to set the stage for that information to come out for no good legal reason.
You can think of it as legal hacking.
I regret writing that last sentence.
No idea how far between concept and reality that is and obviously this is a whole different class of vehicle than a tank.
Modules are also part of the reason why so many folks got "stuck" on java 8.
It is definitely an interesting study in the challenges of trying to make advances in a platform when a lot of the ecosystem is very much in maintenance mode and may not have a lot of eyes on the combination of existing libraries vs new versions of Java.
It looks like the Spring code, when written, did properly filter out existing unsafe methods in java.lang.Class deliberately. Obviously not in a defensive enough way to avoid this, but adding methods to java.lang.Class is a very rare event.
I know there are other AWS features/services that are lined up behind that validation for FIPS support.
(DON'T ACTUALLY DO THIS on anything other than a personal test db as it will kill all the connections it has permission to kill)
Related, postgres has a number of different volatility options for functions so you can declare if there are side effects: https://www.postgresql.org/docs/14/xfunc-volatility.html These can become very important in some cases to let the optimizer have the freedom to shine.
In addition, unless you can cleanly survive an AZ going down, which can take a bunch more work in some cases, then being multi-AZ can actually reduce your availability by giving more things to fail.
AZs are a powerful tool but are not a no-brainer for applications at scale that are not designed for them, it is literally spreading your workload across multiple nearby data centers with a bit (or a lot) more tooling and services to help than if you were doing it in your own data centers.
"You can revert to your previous master password only if the change had taken place within the last 30 days."
I guess it is possible it is another UX issue and would fail if you tried, but that still isn't very reassuring.
To be safe you would probably want to disable that then change your password again. Just don't lose your new password as you then can't revert.
See https://support.logmeininc.com/lastpass/help/recover-your-lo...
Note the classes aren't at fault or doing anything wrong (even though you could imagine other mitigations they could use), they are just conveniently there to use if you have a vulnerability that lets you de-serialize untrusted data.
See https://www.veracode.com/blog/research/exploiting-jndi-injec...
There is a very nice comment talking through some of the reasoning here that is worth a read: https://github.com/aws/aws-cli/issues/4947#issuecomment-5860...
I am quite annoyed v2 isn't in PyPI as it makes updating to v2 a sizable project in some cases and v1 does not support all services, but also quite understand their reasoning.
Granted the tradeoffs may be weigh out differently for an internal tool as the post describes, or if distributing the tool to a more constrained audience.
Default timeouts in the database layers are hidden time bombs that turn operations that just legitimately take a bit longer than some value the library author set that you didn't even know existed into failures that get retried over and over causing even more load than just doing the thing once. Don't get me wrong there are lots of uses for setting strict timeouts and being able to do so is very important, but as a default no thanks.
Many other countries such as Canada use Lowest Astronomical Tide. The difference is actually important to know at times when boating between the countries.
See https://en.wikipedia.org/wiki/Chart_datum#Choice_of_tidal_ph...
...
"Hey look another tool that can generate a lot of boilerplate code you then have to deal with and makes the easy stuff easier and the hard stuff almost impossible!"