3 ms·
Do you have your commit history available in a public repository? I don't. Honestly, i'm paid for being a professional fuck-up. I just fix things quickly and su
by NotPavlovsDog 6y ago
Do you have your commit history available in a public repository? I don't. Honestly, i'm paid for being a professional fuck-up. I just fix things quickly and support my team enough for us to bear the mutual guilt in silence.
- bosswipe 6y agoIf you're suggesting that the obscurity of closed source would have prevented the hack then I very much disagree. There are countless examples of sql injection attacks in closed source software.
- NotPavlovsDog 6y agoI am commenting on the core foundation of the "article", to quote: > "A quick review of Gab’s open source code shows that the critical vulnerability—or at least one very much like it—was introduced by the company’s chief technology officer." What would the writer have without the open source?
- bosswipe 6y agoOk that's true. With a closed source process the company gets to more carefully control the narrative. That might be better for the company and for protecting reputations, but it's not better for the public at large.
- NotPavlovsDog 6y agoFurther, with a closed model, one can always peruse the emergency clause, force majeure, the ever popular "state actor". "Independent experts indicate (fee undisclosed), a powerful malevolent actor was involved in the recent malicious attack on our infrastructure. This aligns with the recent series of threats identified by the State Department and other US government agencies as enemy state activity to undermine Democracy! They hate our Freedom!"
- spamizbad 6y agoThere are SQL injection fuzzing tools that will have no problem catching this. This is not the kind of security defect that would depend on "white box" testing.
- tootie 6y agoMost of my company's code is open source.