HN user

thefsb

80 karma
Posts5
Comments11
View on HN

Here are the first 3 paragraphs of the section on Duct-tapers from Chapter 2.

https://monosnap.com/file/L41lTePrEn3wAJxD4sMZxeIYacxDqK

This was striking for me because I immediately thought that all the stuff I've authored for salt, ansible, grunt, etc. is duct tape. And I hated doing that work. I always did.

It's necessary and necessarily complex but a lot of the complexity is because fitting all this stuff together is going to be a mess no matter what. We can argue about better and worse approaches to managing the complexities (micro-services, whatever) but it's still complex and I resent that.

cweagans is right. PHP is deeply unfashionable, ridiculous even to some programmers using other langauges. But quietly, somewhere out of sight, it has been enjoying something of a renaissance in recent years. Generally I'm pleased with changes in the culture, tools, standards and even in the language. But just can't get behind this decision to keep mcrypt.

it's mostly good. NIST abolished their algo for pasword entropy estimation some time ago. i do not much like any password strength tests, most of which rate any number of terrible passwords as strong. as such i think they give a false sense of security. maybe consider cracklib.

as DenisM said, always use SSL for all traffic if security matters and don't trust SO for security advice.