Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Docjowles
Apr 9, 2009


I mean, it's the NHL playoffs. So that's a given for him for at least the next month or so.

Adbot
ADBOT LOVES YOU

Furism
Feb 21, 2006

Live long and headbang

CLAM DOWN posted:

Am I the only one who can't stand that guy

Not everyone can handle "fame" apparently.

CLAM DOWN
Feb 13, 2007




Docjowles posted:

I mean, it's the NHL playoffs. So that's a given for him for at least the next month or so.

Please, I'm a Canucks fan :smith:

SeaborneClink
Aug 27, 2010

MAWP... MAWP!

CLAM DOWN posted:

Please, I'm a Canucks fan :smith:

:smith: :hf: :smith:

Docjowles
Apr 9, 2009

CLAM DOWN posted:

Please, I'm a Canucks fan :smith:

Goondolences. I thought you rooted for the Jets for some reason but idk why since I know you're in Vancouver.

My Bruins advance :getin:

Docjowles fucked around with this message at 06:01 on Apr 26, 2018

Siochain
May 24, 2005

"can they get rid of any humans who are fans of shitheads like Kanye West, 50 Cent, or any other piece of crap "artist" who thinks they're all that?

And also get rid of anyone who has posted retarded shit on the internet."


Docjowles posted:

Goondolences. I thought you rooted for the Jets for some reason but idk why since I know you're in Vancouver.

My Bruins advance :getin:

Jets are heading to the finals - after that its an unknown.
Go Jets.

CLAM DOWN
Feb 13, 2007




Vegas has actually become my backup team, I'm super impressed by them.

mewse
May 2, 2006

Having the Jets do so well in the playoffs is like some kinda dream after having the team taken away from us in the 90s

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal

CLAM DOWN posted:

Vegas has actually become my backup team, I'm super impressed by them.

Can't wait for Jets Vegas conference finals, that's going to be better than the stanley cup.

Siochain
May 24, 2005

"can they get rid of any humans who are fans of shitheads like Kanye West, 50 Cent, or any other piece of crap "artist" who thinks they're all that?

And also get rid of anyone who has posted retarded shit on the internet."


Judge Schnoopy posted:

Can't wait for Jets Vegas conference finals, that's going to be better than the stanley cup.

gently caress yes. I'm honestly ok with either (would prefer the Jets, but, hey - Manitoba pride on the line). Mainly want to see Winnipeg in it because hooooooooooly poo poo the city will go nuts(er).

Antioch
Apr 18, 2003

Siochain posted:

gently caress yes. I'm honestly ok with either (would prefer the Jets, but, hey - Manitoba pride on the line). Mainly want to see Winnipeg in it because hooooooooooly poo poo the city will go nuts(er).

As long as it's not the god damned Leafs.

Vegas is my backup team too, as a Detroit fan and part time Oilers fan it feels nice to have something interesting happen these last few years.

Absurd Alhazred
Mar 27, 2010

by Athanatos
https://twitter.com/tladycoder/status/989945786216714241

CLAM DOWN
Feb 13, 2007




John McAfee is the hero we deserve, just not the one we need.

Proteus Jones
Feb 28, 2013



I always ask myself “Is that a real photo of McAfee?” every time I see a weirdly questionable photo of him.

Then I come to my senses and realize OF COURSE it is. I mean, that might be staged for that particular pic, but I 100% believe that reflects his everyday life.

astral
Apr 26, 2004

Proteus Jones posted:

I always ask myself “Is that a real photo of McAfee?” every time I see a weirdly questionable photo of him.

Then I come to my senses and realize OF COURSE it is. I mean, that might be staged for that particular pic, but I 100% believe that reflects his everyday life.

It's from:

https://www.youtube.com/watch?v=bKgf5PaBzyg

Furism
Feb 21, 2006

Live long and headbang

Proteus Jones posted:

I always ask myself “Is that a real photo of McAfee?” every time I see a weirdly questionable photo of him.

Then I come to my senses and realize OF COURSE it is. I mean, that might be staged for that particular pic, but I 100% believe that reflects his everyday life.

Honestly, if I was rich as gently caress from selling my company, I'd do something along those lines. Not the coke part though.

Klyith
Aug 3, 2007

GBS Pledge Week

Furism posted:

Honestly, if I was rich as gently caress from selling my company, I'd do something along those lines. Not the coke part though.

Lose 95% of your money on speculative bubble assets, blow the remaining amount on experimental drugs and underage prostitutes in belize?

(the bit about murdering your neighbor is free)

Absurd Alhazred
Mar 27, 2010

by Athanatos

Klyith posted:

(the bit about murdering your neighbor is free)

Getting away with it isn't.

Furism
Feb 21, 2006

Live long and headbang

Klyith posted:

Lose 95% of your money on speculative bubble assets, blow the remaining amount on experimental drugs and underage prostitutes in belize?

(the bit about murdering your neighbor is free)

Well okay if you put it that way I might have spoken too quickly.

PBS
Sep 21, 2015
My company has recently started forcing cache-control headers that turn off all client/server side caching for all of our webapps via our shared apache servers.

Is this common, or is it as dumb as it seems?

Last Chance
Dec 31, 2004

that sounds dumb to me

Space Gopher
Jul 31, 2006

BLITHERING IDIOT AND HARDCORE DURIAN APOLOGIST. LET ME TELL YOU WHY THIS SHIT DON'T STINK EVEN THOUGH WE ALL KNOW IT DOES BECAUSE I'M SUPER CULTURED.

PBS posted:

My company has recently started forcing cache-control headers that turn off all client/server side caching for all of our webapps via our shared apache servers.

Is this common, or is it as dumb as it seems?

If you're only talking about APIs, it might make sense as step zero in figuring out a caching strategy. API response caching gets important at scale, but "don't cache anything" is a safe default while you catalog your endpoints and try to understand what requests you can serve from cache and what needs to hit the backing server every time.

If it includes static content it is the second dumbest possible option; I hope you like pointless infrastructure load.

(But watch out for the even dumber option of "oh crap, we can't sustain this load, better set client-side max-age to some very high value everywhere!" that you might see in the backlash - if you're not set up with sensible revision control already then you're going to have a very bad time rolling out hotfixes to static content)

PBS
Sep 21, 2015

Space Gopher posted:

If you're only talking about APIs, it might make sense as step zero in figuring out a caching strategy. API response caching gets important at scale, but "don't cache anything" is a safe default while you catalog your endpoints and try to understand what requests you can serve from cache and what needs to hit the backing server every time.

If it includes static content it is the second dumbest possible option; I hope you like pointless infrastructure load.

(But watch out for the even dumber option of "oh crap, we can't sustain this load, better set client-side max-age to some very high value everywhere!" that you might see in the backlash - if you're not set up with sensible revision control already then you're going to have a very bad time rolling out hotfixes to static content)

No, everything. I'm told the decision comes down from infosec.

I assume they blindly don't trust that applications are handling caching properly and so strip the headers and force their own.

Blinkz0rz
May 27, 2001

MY CONTEMPT FOR MY OWN EMPLOYEES IS ONLY MATCHED BY MY LOVE FOR TOM BRADY'S SWEATY MAGA BALLS

PBS posted:

My company has recently started forcing cache-control headers that turn off all client/server side caching for all of our webapps via our shared apache servers.

Is this common, or is it as dumb as it seems?

https://www.owasp.org/index.php/OWASP_Application_Security_FAQ#Browser_Cache

PBS
Sep 21, 2015

Yeah, I assume that's talking about using it for pages that it should be used for, not recommending it be blindly set for 100 random applications.

geonetix
Mar 6, 2011


PBS posted:

Yeah, I assume that's talking about using it for pages that it should be used for, not recommending it be blindly set for 100 random applications.

It goes for APIs over http used by websites too (hello overcomplicating “front end engineers”), not just pages; but generally this is a problem with authenticated pages and leaking through user state for other users if it’s cached somewhere. So as stated before: cache nothing is a good default for “logic” endpoints.

orange sky
May 7, 2007

https://twitter.com/Reuters/status/992133254550519808?s=19

Quite a coincidence they decided to come forward with this some weeks before GDPR comes into effect

E: I bet if they hid this and it was found out authorities would go for the 4% turnover

22 Eargesplitten
Oct 10, 2010



“Glitch”

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


It was being spat into logs, no? Pretty common form of bug.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Subjunctive posted:

It was being spat into logs, no? Pretty common form of bug.
They haven't said, but that's what the github one from a few days ago was.

Wiggly Wayne DDS
Sep 11, 2010



anthonypants posted:

They haven't said, but that's what the github one from a few days ago was.
they said it a while ago:

https://twitter.com/TwitterSupport/status/992132808192634881

https://blog.twitter.com/official/en_us/topics/company/2018/keeping-your-account-secure.html

quote:

About The Bug

We mask passwords through a process called hashing using a function known as bcrypt, which replaces the actual password with a random set of numbers and letters that are stored in Twitter’s system. This allows our systems to validate your account credentials without revealing your password. This is an industry standard.

Due to a bug, passwords were written to an internal log before completing the hashing process. We found this error ourselves, removed the passwords, and are implementing plans to prevent this bug from happening again.

orange sky
May 7, 2007

Yes, it was in the logs. That's not as serious, but in case there was a leak, ohh boy

Besides, who has had access to these logs

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
ah, yeah, I didn't see that one yet. welp

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Wiggly Wayne DDS posted:

they said it a while ago:

By which you mean "earlier today", I guess!

Wiggly Wayne DDS
Sep 11, 2010



Subjunctive posted:

By which you mean "earlier today", I guess!
30 minutes may as well be a lifetime ago by today's news standards

CLAM DOWN
Feb 13, 2007




Quick, someone hack the twitters and delete Trump's account

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
Two weeks ago I made a quip about this:
https://twitter.com/KateLibc/status/986990790088900608

CLAM DOWN
Feb 13, 2007





Their security engineers need to listen to your talk, how the f didn't they catch this

Potato Salad
Oct 23, 2014

nobody cares


They weren't going over the actual raw logs with their eyes to see if if any info wasn't being consumed :shrug:

Or, at least until someone eventually did

Adbot
ADBOT LOVES YOU

CLAM DOWN
Feb 13, 2007




Potato Salad posted:

They weren't going over the actual raw logs with their eyes to see if if any info wasn't being consumed :shrug:

Or, at least until someone eventually did

I dunno, I feel they should have done a secure code review to catch this kind of thing.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply