Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ehsanf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
ehsanf
12y ago
You should probably file it as a bug or ask for support on github rather than HN! :)
2.
▲
by
ehsanf
12y ago
Lots of reasons. For example, you can't just paste a picture from your Clipboard into a IRC channel and expect it to work. Granted there are image hosting services out there, but if you want a chat server on your private network and yo
3.
▲
Why remediating assessment results might be harmful to your business
(blog.sdelements.com)
5 points
by
ehsanf
13y ago
|
0 comments
4.
▲
Takeaways from the 2013 Verizon Data Breach Report for Development Teams
(blog.sdelements.com)
7 points
by
ehsanf
13y ago
|
1 comments
5.
▲
by
ehsanf
14y ago
Wow. That's a lot of servers exposed. I bet majority of them have the application/web server running on the same host. I think they should change the default to 127.0.0.1 and let people knowingly expos them to outside of localhost.
6.
▲
by
ehsanf
14y ago
MongoDB manual has some good recommendations on operations here: http://docs.mongodb.org/manual/administration/security/#oper... It certainly helps limit the damage. However, unless it is chroot-ed, it will still pose a very serious risk.
7.
▲
MongoDB remote command execution vulnerability: nightmare or eye opener?
(blog.sdelements.com)
70 points
by
ehsanf
14y ago
|
25 comments
8.
▲
by
ehsanf
14y ago
The article suggests, but doesn't explain why LLC / S-Corp is better if you are taking all the money out. It feels to me that if you don't have to retain any money, then they both collapse to the same situation more or less. The only differ
9.
▲
by
ehsanf
14y ago
We should call it "insecurity by default" (in contrast to insecurity by design). A major problem is that nobody takes responsibility or pays attention for default choices. A ton of packages have default choices that are inherently bad/insec
10.
▲
by
ehsanf
14y ago
I believe over-engineering is also a culprit here. We had a similar situation in JSON handling in browser. Some over engineered feature allows custom objects to replace built in object for lists, allowing XSS through JSON parser. The soluti