This recent one in regards to an AVG Chrome extension is slightly "less-worse" than this TrendMicro issue: https://code.google.com/p/google-security-research/issues/de...
HN user
johngd
Careful about installing Influxdb and Telegraf on the same system via RPM (maybe DEB too), they both share common paths and filenames, and cause one (or the other) not to start.
https://github.com/influxdb/telegraf/issues/22 https://github.com/influxdb/influxdb/issues/3123
Also, the changelog items for telegraf all point at influxdb issues.
https://github.com/influxdb/telegraf/blob/master/CHANGELOG.m...
I am really excited about telegraf, but am worried about long term maintenance of yet another stats collector. It is very easy to setup, and seems like it will be quiet easy to extend.
Have you used cyanite in any meaningful way? The original author's (pyr) repo has been pretty dead.
This person has been doing a lot of good work: https://github.com/mwmanley/cyanite
Would it be possible to use this method against something like a Java app loaded in tomcat where as to test for bugs within a certain library? Say, for instance that I wanted to see if certain malformed xml posts were able to cause unexpected behaviors in a passing endpoint? As I write this I think that in some cases some kind of httppenetration tool might be more suited but I think im wondering what would happen with a tool that isn't necessarily confined to a ruleset and pattern matching.
Curious how/if Redhat would deal with date-based versioning. 2.6.32 was originally released ~6 years ago and for-better-for-worse their frequent security patching would make the original release date fairly irrelevant.
I think the more interesting part is the comments that crept out of the wood work days after the article was posted to HN.
hautit 5 days ago (1 comment - account created 324 days ago) Get over it, CBInsights, your UX sucks.
theUXclub 4 days ago (brand new account)
CB Insights, cheap and creepy as always. A 'low-drama' group of people that decided to tweet and share the story all over the place claiming something like 'Look! They copied us!'- Your UX is bad as hell, I wouldn't be very proud. Plus, your site is Bootstrap (a framework created for people who have no skills or time to invest on CSS or design), did you also invent it and they copied you as well?
frumpywooly 4 days ago (brand new account)
"...12 folks from their team have signed up for our free trial since September including the CEO, head of product, designer, product manager and a senior ruby developer." CBInsights, creepiest company in America
Re #1: Correct.
Re #2: Unless you are a contractor. I was shocked to learn how much the about-to-retire ~20-30 year guys were making compared to my mid/senior level long-term contractor position was paying.
I am not sure about medium-risk public trust positions, but for high-risk public trust positions (think access to PII, social security # type stuff) they require an in depth personal history, including a meet and greet with an investigator (usually ex-law enforcement, so I was told).
Protip: Contractor or FTE, make sure you specifically ask HR whether or not there will be an additional screening, and whether or not it is a 'public-trust' position and what level that would be following your hiring.
I was pretty miffed when 'they' told me after the fact that my position required an additional background check and that my continued employment would be predicated on the outcome.
Indeed. You can do this using the BMW manufacturer software (which is comically not hard to find), at least for the E9* series of BMW's. Not sure about the newer F3* series, but I wouldn't be surprised.
There was also this one[1] from a couple of years ago (that you may be referring to?) where with a inexpensive kit, a thief could intercept the drivers key fob transmissions to open the car, and then a ODB programmer to pair the car with a key blank.
[1] https://nakedsecurity.sophos.com/2012/09/18/bmw-stolen-hacki...
My car's USB port can barely charge my Samsung Galaxy 5.... I can't imagine how long it would take via radio wave.
"Has everybody in IETF forgotten CNN's exponential traffic graph from 14 years ago?"
Any ideas?
As someone who is in the process of cutting the cord (just ordered some gear, very excited!), I am hoping that the KODI(XBMC)/MythTV/etc community will work on something that integrates with this service as I can only imagine it will be a hot commodity when it comes out. It looks like they have already been working on a Xbox One app.
I will be trying this out day-one.
Yea, you're right; I thought that some context might be needed after I posted.
They aren't related whatsoever, however the thought process of being put into the same position as the security research in this article is what made the connection for me. Assuming that the author wasn't from the UK (he probably is, but bare with me), as someone from the States I would have assumed that having an email exchange with the company was more than enough especially if there a reply on their end.
From my perspective, again knowing nothing about UK law (as much as people in the UK, China, or Fiji may know about US Law), I wouldn't know where to turn after that. Maybe a teaser post, without disclosing everything? If it weren't for the fact that the author stated that he had several two-way conversations with a representative of the company, I would have more sympathy for moonpig.
Speaking of which: How effective is the ICO?
I'll add my two cents a non-Brit: I have never heard of the ICO until this thread. Someone please correct me, but the closest thing we have in the states may be contacting the Attorney General?
I say this thinking of the argument the rest of the world makes when the DMCA threat is used against a non-US entity.
They have 3 other brands: http://photobox.co.uk http://uk.paper-shaker.com https://sticky9.com
Only the later seems to enforce SSL. I registered a dummy account on photobox, username/password/email, via their form which was not using ssl.
The author may have, mistakenly, attributed a quote as fact from one of the interviewees.
Interestingly enough, from the same link, Dupont appears to have invented/optimized a moisture-proof cellulose, which may have been what the author was referring to?
I've taken a personal record number of UberX rides, 3, in the last week. I prefer not taking them if I can help it, but safety trumps politics sometimes.
Regardless, each driver I met was absolutely fantastic; very friendly and professional. The one complaint all of them had when I asked their opinion of Uber: The GPS is horrible.
One guy was going to make the switch to Lyft JUST because the Lyft maps use Google, and apparently it is simply just that bad.
I did witness this myself while on a work trip this past weekend - Uber GPS led them off the highway and then back onto the highway adding an extra 5 miles for no apparent reason.
This is very true. Logistically (not technically) this wasn't an option - read: business decision. Before the days where everything had an API, and things were done with spreadsheets, and billing codes, and product codes, and typos... managing DNS for a large number of domains was not fun and rather expensive. Want to move a bunch of domains to a new IP address? $$$+Time + more time and money. We weren't able to trust our domain broker and had to double check EVERYTHING they did.
To you point, if you are a large provider, especially one that passively and actively sends a lot of money towards the search engines, there are some additional options at your disposal. We (the business units) had contacts with adsense etc, which would come in handy.
Very true, however the incidents I reference this was definitely not the case.
In fact for a while we would get Bing (MSN bot back then) crawl us everyday at the same time, almost on the dot.
Let me plug project honeypot (which I am in no way affiliated with). This is truly an awesome, and surprisingly accurate, free, service that does an amazing job at collecting heuristics on suspicious IP activity and exposing it in a easy to interpret way..
My main focus for the entirety of my career has been on internet facing consumer web applications. I have seen many, many, DOS attacks from IRC bots to Ukrainian web scrapers to Chinese get-lucky wordpress exploit scanners. Most of these can be ignored and blocked with little effort.
By FAR the most annoying of any of these is when Google, Bing and/or Yahoo decide to wake up and crawl your infrastructure with little regard to your robots.txt or webmaster settings, if available. I think they have got better in recent years, but they used to be the absolute worst. It came down to: Let us DOS you, or have your ranking suffer. Suing Google, Bing, Yahoo isn't exactly an option.
Some context: I was the lead architect/engineer combo for a CMS that hosted ~500k domains for a fairly large international company. Some days I could login and see them crawling every domain from A-Z. Some days I would get caught by Google and Bing at the same time. They were the largest consumers of data on this system.
Absolutely. I think it is a very difficult problem to solve as companies grow larger and larger and rise to behemoth proportions all while trying to tackle something that is relatively new (the security concerns of today, as opposed to say the 80's,90's,2000's when Sony didn't have to be as competitive in the products that they offered) and typically expensive (for a company Sony's size) where funding for these things seem to be viewed in terms of $ now, instead of potential $ later.
Anecdotally, I knew some guys who worked at (or with?) the global security division at Sony US HQ.
The story went that each of the Sony subsidiaries[1] had their own security division that was largely autonomous for reasons of politics and budget, of course. Each part of the company had different vendors, different policies and procedures, and different philosophies on how security should be implemented.
When they would all send their representatives to have a global security pow wow, however often it happened, it ended up like an episode of game of thrones.
[1] http://en.wikipedia.org/wiki/Sony_Corporation_shareholders_a...
Amazon.com's content cdn is returning 0 byte replies for images.
I am generally curious about the source for your claim. Would you mind sharing, please?
Interestingly, their largest publicity bump since July was largely negative, at least among those that that would read tech news: http://www.google.com/trends/explore#q=groupon
Considering that their <name-TBD> point-of-sale platform was largely targeted at small businesses that assumingly would follow this type of news, I am curious how long it takes for them to rebrand this product and how long they wait to roll it out... if at all.
I second this. I cannot wait for the day where I don't second guess myself whether I want to put an event in my company's MSExchange calendar, or google calendar because I don't know if I will see it if saved to the latter.
Forever grateful to FreeBSD as it was my first non-windows/mac distro that had installed on one of my own machines. I snagged a copy of FreeBSD 4 that was bundled in a book that they sold at BestBuy. I spent all of Christmas installing it on a old Packard Bell Pentium 1, several times if I recall correctly (disk partitioning was rough for a newbie). That one day set my path for the next ~15 years
Is it common to use bit.ly links when linking to your products off your own press release? I understand that bit.ly offers link analytics but I can't imagine they offer something that you couldn't do in house that offsets the loss of branding by not advertising with your own domain.
Typically, in Oracle speak, Webcenter typically refers to Webcenter Content or Webcenter portal, which are products that existed (under a different name?) prior to the Fatwire acquisition. The fatwire product was specially rebranded to 'Webcenter Sites'. From what I understand, from talking to Oracle VARs and consultants, the Sites suite isn't as common as the other two.
Browsing through the PDF, they make references to Webcenter Portal and Webcenter Content, but not Webcenter Sites.
Source: I implemented and supported the largest (in terms of assets and users) (allegedly, according to Oracle) installation of Fatwire as of a year ago. I work on a Portal/Content project now.