4 ms·
Here are the slides from Percona Live 2018: https://www.percona.com/live/18/sites/default/files/slides/Accelerating%20MySQL%20with%20JIT%20Compilers%20-%20File
by davidyeager 8y ago
Here are the slides from Percona Live 2018:
https://www.percona.com/live/18/sites/default/files/slides/Accelerating%20MySQL%20with%20JIT%20Compilers%20-%20FileId%20-%20129518.pdf https://www.percona.com/live/18/sites/default/files/slides/A...
- SafPlusPlus 8y agoMentioned as the installation method in those slides: sudo bash c 'bash <(wget O https://dynimize.com/install) default' Come on, please don't teach people horrendous security practices... :(
- stephenr 8y agoIt’s depressing how commonplace `curl|(ba)sh` has become. This will sound clichéd but I blame the rise of “poor mans devops” whereby management fires all the ops, and lets developers manage infrastructure.
- ddtaylor 8y agoJust pasting commands alone into a terminal is pretty insecure now too. Their are proof-of-concepts that show some control characters and other invisible characters will make it to the clipboard and even someone pasting into a text editor won't see them.
- stephenr 8y agoBetween that and delivering different responses to curl|sh vs a browser or regular curl [1] you’d think this kind of bullshittery would be abandoned, but no. 1: https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
- da_chicken 8y agoI agree, it may be cliche, but I think the exact same thing whenever I see this kind of practice, too. Or that the developer that has never had to manage a live system with users that know his phone number and his boss's phone number. "Oh, this is just for a test mock up. Nobody is supposed to actually use this to install it for real." Well, to experienced people it makes you look moderately stupid, and to inexperienced people it looks like an elegant solution. It's actively hostile to secure system planning. It reminds me of the NPM left-pad debacle[0] and some of the criticism[1] that came up from that. 0: https://www.theregister.co.uk/2016/03/23/npm_left_pad_chaos/ https://www.theregister.co.uk/2016/03/23/npm_left_pad_chaos/ 1: http://www.haneycodes.net/npm-left-pad-have-we-forgotten-how-to-program/ http://www.haneycodes.net/npm-left-pad-have-we-forgotten-how...
- stephenr 8y agoI’ve given up waiting for nodejs to become a reliable environment. Just recently the `is-even` package came to light and highlighted that things aren’t getting any better than when leftpad was a thing. I can’t wait to see tc39’s response to the `is-even` shit show after they decided to just add leftpad to the stdlib.
- da_chicken 8y agoWow, I hadn't heard about the is-odd/is-even/is-number thing. That's hilarious and awful. Reminds me of: https://github.com/jezen/is-thirteen https://github.com/jezen/is-thirteen
- stephenr 8y agoThe “best” part of it all is that apparently js engines have an internal optimisation for `foo % 2 === 0`, because it’s such a common thing. This clown was using a bit wise operation in `is-even` “because everyone already knows about % 2 === 0`, and thus was hurting performance (on top of whatever extra memory is used for the module, function call overhead etc)
- davidyeager 8y agoFair enough. This is valuable feedback. We have provided a more secure method on our home page and will provide package managed downloads as well, however the reality is that nothing is 100% secure. In the meantime, you can just download the script and inspect it (it’s pretty simple) and then do it all manually if you prefer.