HN user

westi

537 karma

Code Dreamer / Photographer / Classic Car Nut. Blog - http://blog.ftwr.co.uk WordPress.org Lead Developer - http://wordpress.org Automattician - http://automattic.com/work-with-us/ Email peter dot westwood at ftwr dot co dot uk

Posts47
Comments109
View on HN
twitter.com 10mo ago

The Larger a Company Gets, the Harder It Is for Anyone to Know What's Happening

westi
1pts0
blog.ericgoldman.org 1y ago

Verizon and Its Cloud Vendor Must Face Lawsuit for Reporting "CSAM" That Wasn't

westi
5pts1
www.wired.com 1y ago

Two Years of Turmoil at Big Tech's Anti-Terrorism Group

westi
2pts1
automattic.com 1y ago

Open Source, Trademarks, and WP Engine

westi
61pts48
ma.tt 1y ago

WordCamp US and Ecosystem Thinking

westi
2pts1
www.businessinsider.com 1y ago

What to do if you catch your staff on a quiet vacation, according to an HR exec

westi
14pts8
www.axios.com 2y ago

FTC launches inquiry into Reddit's AI deals, ahead of IPO

westi
9pts0
hbr.org 3y ago

The Hidden Toll of Microstress

westi
2pts0
www.nytimes.com 3y ago

What It’s Like to Learn You’re Going to Live Longer Than You Expected

westi
2pts1
staff.tumblr.com 3y ago

Not a drill. Our new Community Guidelines are here

westi
4pts0
swarm.ptsecurity.com 3y ago

Exploiting Arbitrary Object Instantiations in PHP Without Custom Classes

westi
1pts0
www.nytimes.com 3y ago

Study Finds Another Condition That Vitamin D Pills Do Not Help

westi
1pts0
www.theregister.com 4y ago

RISC OS: 35-year-old original Arm operating system is alive and well

westi
9pts1
www.fastcompany.com 6y ago

Filter out male privilege, and the web can be a ghost town

westi
2pts0
mosuleye.wordpress.com 8y ago

Finally .. My Face Is Out in the Open

westi
94pts4
twitter.com 8y ago

Web Developer v0.5 for Chrome is now live which removes the compromised code

westi
3pts0
www.theatlantic.com 9y ago

The Myth That Humans Have Poor Smell Is Nonscents

westi
2pts0
www.theatlantic.com 9y ago

The Ambition Interviews: A Table of Contents

westi
2pts0
www.glassdoor.com 9y ago

Best Places to Work 2017 Employees' Choice

westi
2pts0
www.nytimes.com 9y ago

Gwen Ifill has died

westi
250pts31
www.npr.org 10y ago

Episode 709: The Quiet Old Lady Who Whispers “Fair Use”

westi
1pts0
www.theatlantic.com 10y ago

Slack, the Facebook Slayer

westi
1pts0
www.theatlantic.com 10y ago

Why White People Don’t Use White Emoji

westi
1pts0
www.theatlantic.com 10y ago

The Silicon Valley Suicides

westi
4pts1
www.theatlantic.com 10y ago

What ISIS Really Wants

westi
12pts2
medium.com 10y ago

Can versus Should

westi
5pts0
motherboard.vice.com 10y ago

Variety Jones: A Corrupt FBI Agent Is Hunting Me, So I'm Turning Myself In

westi
4pts0
noscope.com 10y ago

Ethical Adblocking

westi
28pts92
blog.trello.com 10y ago

Introducing Trello Enterprise

westi
3pts4
www.theatlantic.com 11y ago

What Happens When Struggling High-Schoolers Take College Classes

westi
1pts0

The Mythical Man Month - important lessons for any developer

Bird by Bird: Some Instructions on Writing and Life - A really good read on how to write which is applicable to everyone who needs to communicate well

Producing Open Source Software - This is such an in depth book into everything you need to consider when working “in public”

This is pretty cool.

It might be work stopping the browser 'loading' itself inception style with some kind of blacklisting of loadable urls - I assume you already have something to protect against SSRF type attacks on the platform itself.

Automattic | Front-end, Back-end | Full-time | Worldwide Telecommute | REMOTE | http://automattic.com/work-with-us/

Automattic is currently hiring for a variety of positions.

We are passionate about making the web a better place and are strong believers in Open Source. We build WordPress.com, contribute to the WordPress Open Source project (http://wordpress.org) and work on a lot of other really cool stuff including CloudUp, Gravatar and Akismet. Join us if you are passionate about making the web a better place.

If you like solving interesting problems in different ways, are passionate about giving people the platform to share their knowledge, views etc we would love to hear from you :)

Head here to read more - http://automattic.com/work-with-us/

I _think_ you can get away with not selling ever at full price if your comparison price is the manufactures RRP.

You can't do this for "bespoke" products which is where the UK law seems to most hit businesses - things like furniture which are specific to the retailer.

Of course the $1200 candy bar price is never the RRP :)

V8 Release 5.1 10 years ago

FYI - Your https link generates a cert error because node.green is being served with the www.github.com ssl cert.

Some of the original discussions around the status code referred to proxies but adoption at the moment seems to be mostly but hosting platforms like github, wordpress.com [1] etc.

I think the original ideal scenario was that a 451 would be generated by the in-country blocks that get put in place by ISPs due to legal requests from organisations.

However, they aren't incentivised to do this as much as hosting platforms are and so I don't think we will see large adoption there.

Instead, hosting platforms are using the status code both for DMCAs and other legal requests where the content may only be blocked for certain countries as part of a pragmatic response that keeps the rest of the service up in those countries (In country blocks are usually overly heavy handed :)).

[1] https://transparency.automattic.com/2016/01/05/error-451-una...

Previously: https://blog.shodan.io/dont-be-clever/

For example, you might know that Shodan crawls the Internet for industrial control systems (ICS). One of the most popular protocols in ICS is called Modbus that runs on port 502. At the moment, there are about 17,000 devices listening to Modbus on the default port. It turns out there are also 700 devices listening on port 503, again a one-off sort of situation.

Probably over 20k by now

This is the unfortunate outcome of a bunch of factors.

OEMs moving to XXX over TCP protocols which have zero security by default and documenting this in the datasheets.

VAR installers switching to the newer products because CAT5 cable is cheaper and easier to pull than what they used to use.

The previous solution was just as insecure but harder to hack because you needed more specialised equipment.

I'm not sure how we are going to fix this without getting the OEM industry and the industry bodies behind xxx over TCP to understand that they need to bake a security model in.

The CapEx versus OpEx game doesn't make as much difference with depreciating assets because you balance the initial expense against the asset value you are depreciating and so you spread the cost in your P&L over the time it takes to depreciate the value down to 0. So the balance between OpEx and CapEx is more which is better value for the business.

Appreciating assets like building of course have a different affect on the P&L, but then so do the loans you take out to finance them.