Show more

"Der Chatbot erwies sich als Hardliner und empfahl, Babys in Energydrinks zu taufen" 💪 😂

dbread boosted

One of the things that the Stack Overflow brouhaha demonstrates is that it doesn’t matter if a service was founded by people trusted by the community (Atwood and Spolsky) and was broadly community-led. If it’s a VC-funded startup, they will sell out their users at some point.

dbread boosted
dbread boosted

Today, 16 years ago, Debian published a security advisory announcing CVE-2008-0166, a severe bug in their OpenSSL package that effectively broke the random number generator and limited the key space to a few ten thousand keys. The vulnerability affected Debian+Ubuntu between 2006 and 2008. In 2007, an email signature system called DKIM was introduced. Is it possible that people configured DKIM in 2007, never changed their key, and are still vulnerable to CVE-2008-0166? 16years.secvuln.info/ 🧵

Delete a cloud on multiple sites, to make sure it is gone. This is dedication.


Google Cloud accidentally deletes UniSuper’s online account due to ‘unprecedented misconfiguration’ | Superannuation | The Guardian
theguardian.com/australia-news

dbread boosted
dbread boosted

@simon in the context of filtering, the opposite of spam is ham, so what is the opposite of slop?

A car which is called bug with the word feature on the number plate. Makes my head implode and explode at the same time.

dbread boosted

"Der Chatbot erwies sich als Hardliner und empfahl, Babys in Energydrinks zu taufen"

@jonty

*innocent configuration oversight*

"If all those misconfigured systems were attempting to back up their data into my S3 bucket, why not just let them do so? I opened my bucket for public writes and collected over 10GB of data within less than 30 seconds. Of course, I can’t disclose whose data it was. But it left me amazed at how an innocent configuration oversight could lead to a dangerous data leak!"

This is so infuriating. Not only that devs use some magic packets with default configuration and produce data loss, but also that the managers require the devs to produce results asap. That's how such mess happens.

@merospit @jonty

Does this apply for billing too? The bucket is also simply a part of the query url.

Show more
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.