Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
vOv
Feb 8, 2014

NEED MORE MILK posted:

why does PayPal not have an spf policy configured with dkim signing?

it looks like it has an spf policy with softfail enabled and the last e-mail i got from them does have dkim headers

so maybe this really was a legit e-mail that got missent

Adbot
ADBOT LOVES YOU

vOv
Feb 8, 2014

anthonypants posted:

okcupid doesn't currently do any validation against facebook like other dating sites/apps, so either
1) they're introducing facebook account validation, so whatever your facebook name is will get pushed to okc
2) it's a new freeform field but they'll make it validate against "real" names like Hannah or Jordan or Chloe
3) everyone has to use a credit card now and even if they don't charge you they'll use the name associated with it

https://twitter.com/okcupid/status/944255764193038343

so why are they even doing this in the first place???

also i'm relieved i haven't gotten any creepy poo poo on my (non-work-linked, personal) twitter yet but i'm sure it's just a matter of time

vOv
Feb 8, 2014

Doom Mathematic posted:

I guess the "no, you have to use a real name" bit is scheduled for a year from now, because it causes less attrition to phase it in as several smaller changes.

well apparently they have a first name/last name field so they're already 'ahead' of the game there. no clue if they do any validation on em

vOv
Feb 8, 2014

apseudonym posted:

It's a big foot gun and you should be really careful.

yeah this. hsts is one thing because it's not hard to get some certificate, but hpkp can gently caress you over real hard if you lose the key

vOv
Feb 8, 2014

ymgve posted:

like delivery drivers who won't even use the doorbell would ever care about that

i had a package marked as 'not at home' even though i live in an apartment complex with an intercom

vOv
Feb 8, 2014

DJ Commie posted:

like the post office has always had?

only USPS can deliver to a PO box though

vOv
Feb 8, 2014

RISCy Business posted:

i just have anything worth more than $50 shipped to my office and then i bring it home

ever since i had something stolen out of my apartment complex's lobby this is what i do

vOv
Feb 8, 2014

geonetix posted:

https://twitter.com/s1guza/status/947603265700601856

don’t know if it holds any merit but looks woops

i'm on an mbp so i could try it but lol if you think i'm going to

vOv
Feb 8, 2014


is this why they call it fuzzing

vOv
Feb 8, 2014

Sereri posted:

I hope the translation works well enough

i wonder if the author read something about 'designers' and just figured that it was like a fashion designer

vOv
Feb 8, 2014

https://twitter.com/_MG_/status/949684949614907395

vOv
Feb 8, 2014

apparently the vulnerability is that it spins up an RPC server on localhost and it had an Access-Control-Allow-Origin header of * which means that any website could send rpcs to your wallet

vOv
Feb 8, 2014

Subjunctive posted:

I’m not au courant, what’s the functional effect of that?

gets you some very interesting attention if you try to go through security with it

vOv
Feb 8, 2014

Subjunctive posted:

fair enough, I’ve not taken a desktop PC through security before

does the plastic show up on X-ray, then?

i don't actually know, i was just making poo poo up

vOv
Feb 8, 2014

Lain Iwakura posted:

hi. i play derby and i love it a lot

https://twitter.com/KateLibc/status/951211904482951168

this is a problem for me directly :(

isn't this a pci violation

i mean not that that has any teeth

vOv
Feb 8, 2014

Subjunctive posted:

no, unless you configure the local service to permit it, via CORS headers

E: similarly, something awful dot calm can't fire off a request to gmail and get your mail. cross-origin requests aren't permitted to read responses into script unless the site explicitly opts into it

sometimes just sending the request can be enough even if you don't get to read the response

Condiv posted:

I really don’t get why they don’t make a bytecode for webpages that all weblangs can compile to?

that's what wasm is supposed to be

vOv
Feb 8, 2014

ate poo poo on live tv posted:

If it was all of them and it happened at basically the same time, you would straight up erase most companies (because of course they don't have backups). Not to mention many code bases live in Github etc. and some of them may be hosted on AWS themselves, or at least have assets that would need to be pulled down from AWS.

S3 outage last year on it's own knocked out a significant amount of web-traffic, so yea I could see that being pretty huge.

at least stuff that's stored on github has distributed backups by the nature of git

though you'd lose the issue tracker

vOv
Feb 8, 2014

mrmcd posted:

I'm the rich text editor for something that goes out over sms and every legacy teletype system shoved in the back closet of every tv station on the planet.

the thread suggests that the rich text stuff is just metadata and that the alert text is entered elsewhere

vOv
Feb 8, 2014

it's basically trivial to pick most locks but i'm still gonna lock my door

vOv
Feb 8, 2014

the article on humans is probably one of my favorite examples of wikipedia deadpan

vOv
Feb 8, 2014

Arbitrary Coin posted:

Honestly not sure but earlier/ a few weeks after the Malwarebytes email we all got emails to immidietly change our comp passwords, that the wifi/network passwords have all changed and that the dude who sent the Malwarebytes solution email was "no longer with the company" with an effective date in the middle of the week.

lmao

vOv
Feb 8, 2014

https://twitter.com/EdOverflow/status/954093588362809345

vOv
Feb 8, 2014


someone once described the reason for this kind of thing as being that judaism views god as saying 'okay, i'm giving you these sets of rules, and if you can figure out how to work around them, good on you'

which is why asking a non-jewish person to do stuff for you is (sometimes) acceptable. iirc the person doing it has to receive some kind of inherent benefit

vOv
Feb 8, 2014


oh my god

vOv
Feb 8, 2014

Doom Mathematic posted:

Maybe the tweet was deleted while you were looking at it?

yeah i can't find this particular tweet either

Adbot
ADBOT LOVES YOU

vOv
Feb 8, 2014


one of the replies says it's a wind farm

  • Locked thread