Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Jabor
Jul 16, 2010

#1 Loser at SpaceChem
it's called a ctf

Adbot
ADBOT LOVES YOU

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
is mongoloid ableist? i always figured that was a racist one

(and a very strange thing to name your database after, in any case)

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
it's exactly the same reason calling your package manager a racial slur is a bad idea. no-one cares that you got there by shortening "raccoon"

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

BattleMaster posted:

did this happen I don't want it in my google history

http://erlang.org/pipermail/erlang-questions/2018-February/094769.html

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
if a device on your internal network asks your router about what other devices on your internal network it can talk to, and your router then decides to open that device up to external connections from anywhere on the internet, it's the router that's the secfuck

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
Wait, so the validation APIs don't give you any way to tell "hey, here's the trust chain the platform used to determine that this certificate is valid"?

Are there any examples from whoever designed that api showing you how it's supposed to be used? Are you just supposed to do 100% of the certificate validation yourself and not rely on the platform doing anything?

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
Though thinking about it, in common use cases (you're using certificate pinning to ensure you're talking to a server you control), wouldn't it be easy enough to fail validation if the certificate bag contains more certs than you expect?

Like, you expect it to contain the leaf cert, your pinned intermediate, and that intermediate's root cert, and absolutely nothing else.

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

Penisface posted:

shouldn't there be the bit where you configure the passes and define the salt as well?

There should never be a bit where you define the salt - if you're storing a new password, it generates it randomly; if you're checking an existing password, the salt is stored in the hash string that you're checking against.

Configuring parameters like number of passes is part of storing a new password as well (the parameters chosen get stored in the hash string too), but really the library should just have sane defaults.

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
if only everyone could have that privilege

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
more like should-be-in-prison book.

not even joking, lock up whoever made the decision, and also their entire management chain including zuckerberg (they all knew exactly what was going on).

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
"certification" is not "certificate". Sounds like they pinky-promised not to misuse the enterprise program and apple gave them a new cert.

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

Partycat posted:

the article also explicitly says they retain control of the encryption keys . they release data based on Chinese law , for iCloud , which you can turn off.

If you want to argue that this is just a sham and they are giving away customer data , I guess you can make that claim but the article given doesn’t support that in any way.

the claim is that they're selling out dissidents to a totalitarian regime that is rounding up minorities in interment camps and has a history of human rights abuses

"we only do it when then the totalitarian regime asks us to" is not much of a fig leaf there

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
kinda convenient that apple catches someone else loving up shortly after they've had a major fuckup of their own and would want people to stop talking about it

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
how in the heck does this get certified as a class anyway

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
one thousand two hundred and thirty four people is a pretty nice total for a movie monster

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

Powerful Two-Hander posted:

you joke but wasn't there some idiot bitcoin wallet generator that was just returning the dame key for everyone because the domain that they sourced entropy from expired/they were total idiots

iirc they were making http requests to a random number generator site, then that site turned off that feature and started returning an error page telling you to use https, and the app dutifully used the error page as its "random" bytes

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
hey, it's a good way to screen for applicants that can follow orders to the letter even though they're pointless and stupid

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
not actively sheltering nazis is censorship now? when did that happen?

Adbot
ADBOT LOVES YOU

Jabor
Jul 16, 2010

#1 Loser at SpaceChem

The Fool posted:

There's a difference between actively sheltering and just treating them the same as every other customer.

nah

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply