Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nupark
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
nupark
15y ago
I'm not offering a "pointed critique of Rails" ([edit] although your framing it as such seems to encourage downvotes into the negatives). I'm demonstrating how the use of non-parameterized queries source of error that has repeatedly result
2.
▲
by
nupark
15y ago
A "vast number of issues"? Huh? Citation needed. The last time I researched this, I started here: http://www.google.com/search?sourceid=chrome&ie=UTF-8... ... would up and sources like this: http://lists.rubyonrails.org/pipermai
3.
▲
by
nupark
15y ago
It is not unreasonable to assert that SQLI defense is a framework concern, not a database issue. The database is the normative reference on what is and is not a special cased character and how escaping should be implemented. I don't think
4.
▲
by
nupark
15y ago
Could you expand a bit on how parameterized queries are not sufficient for defense against SQL injection (assuming, of course, that developers use the escaping and do not concatenate unescaped data into queries)? As for them being required
5.
▲
by
nupark
15y ago
> You don't need parameterized queries or stored procedures for protection against injection ... There's no need for the database's native wire protocol to explicitly support parameterization to implement this. This means that every pro
6.
▲
by
nupark
15y ago
I honestly have no idea what you're talking about or advocating, if anything. If you switch to the JVM, a buffer overflow triggers determinate behavior -- it throws an exception rather than writing over the saved return address or the heap.
7.
▲
by
nupark
15y ago
The fix IS that simple. Stop using non-sanitizing APIs. Your equated that with saying "stop making mistakes," which is what I objected to. The original poster was right: people need to simply stop using frameworks that do not sanitize their
8.
▲
by
nupark
15y ago
For example, lots of programs written today still have buffer overflow vulnerabilities. Those are even older. The fix is also very simple: "Check the bounds of your arrays before you use them". That is, again, just telling the developer to
9.
▲
by
nupark
15y ago
How many NEW desktop apps have you installed recently? I don't install new desktop apps very often because my needs are already solved. I do nearly all my work in: - Mail.app - Xcode - Eclipse - TeXShop - Terminal - Chrome (JIRA, and brow
10.
▲
by
nupark
15y ago
Your boss wasn't far off base. A web application is not a replacement for a native application, even if you bundle it up in a UIWebView and sell it through the app store. My organization works in a variety of languages/runtimes, from ObjC t
11.
▲
by
nupark
15y ago
"Lux Living" is a satirically named blog focused on the huge Stuy Town ( http://www.stuytown.com/ ) complex in the East Village. The full set of articles: http://stuytownluxliving.com/cgi-bin/mt-search.cgi?blog_id=1...
12.
▲
No love lost for AirBnB on NYC's neighborhood blogs
(stuytownluxliving.com)
2 points
by
nupark
15y ago
|
1 comments
13.
▲
by
nupark
15y ago
do you know how many web/ISP hosting providers are out there that give out non-root SSH access to their customers? or how many do shared PHP hosting that make it easy to run local commands on the server? Yes. In the late 90s, I worked in
14.
▲
by
nupark
15y ago
Work on it how? Acquiring root locally is easy because local exploits are a dime a dozen, and once you have local access you can simply piggyback on valid authentication: alias sudo="sudo and do something evil instead" Once an atta
15.
▲
by
nupark
15y ago
Why not? My servers have no passwords at all -- they either use SSH keys or kerberos. Once you have access to a local shell, the game is over. Acquiring root is easy, between local exploits or simply piggybacking on (or sniffing) a valid,
16.
▲
by
nupark
16y ago
Given where Core OS sits in the software stack (kernel, libc, file systems, etc), being "academic" and "by the book" shouldn't be surprising. :) As to the rest; my point was that Bertrand was very opposed to change in 'his' code, not that h
17.
▲
by
nupark
16y ago
Speaking as a former Apple engineer in Core OS, this is a bit too glowing. Serlet wrote quite a bit of code in the NeXT days, much of which does not meet what you would call modern best practices, and even when written was fairly unusual. H
18.
▲
by
nupark
16y ago
Figuring out a way around the standardized admissions process is the admissions process for nonstandard applicants. This is no different than anything else in life, from job applications to pitching a client, and the world hasn't changed
19.
▲
by
nupark
16y ago
Providing a poor quality application doesn't necessarily tell you anything about the audience a proper port would have, it can be significantly damaging to your brand, and is a waste of press attention.
20.
▲
by
nupark
16y ago
Yes, this applies to the original article -- and the minority use of this vernacular in general. People (like myself, and I believe the original poster) take issue with the use of 'hustler' because we see clear parallels between the negativ
21.
▲
by
nupark
16y ago
Your definition of 'hustler' is both valley-centric as well as seemingly predicated on a wink and a nod denial of the sleazy origins of the term. http://www.google.com/search?sourceid=chrome&ie=UTF-8...
22.
▲
by
nupark
16y ago
The most efficient way for a platform to cache many types of state is in the process itself, local to where that state is required. Database connection pooling, for example, is more efficient implemented within a single multithreaded proces
23.
▲
by
nupark
16y ago
Shared memory makes perfect sense for a webapp, too. I question the whole stateless mantra -- if state is reconstructable on other nodes, then what is wrong with state that improves performance -- such as caching. Everything from database c
24.
▲
by
nupark
16y ago
I think you're overestimating your ability to note a small security bug in a diff. If it was as easy as you seem to think, we probably wouldn't introduce such bugs by accident in the first place. It can be as innocuous looking as using strn
25.
▲
by
nupark
16y ago
> As for the GIL, the author didn't even consider multiple processes ... I really hate this argument for its disingenuity. Some things (including message passing) are naturally fastest with shared memory. Multiple processes are not an e
26.
▲
by
nupark
16y ago
People rarely look at diffs closely enough to detect intentionally obscured malicious additions. Unintentionally malicious additions slip through all the time: they're called bugs.
27.
▲
by
nupark
16y ago
No, one of the authors of the library in question was the one that raised the issue: http://twitter.com/#!/therealkerni/status/48341474210881536
28.
▲
by
nupark
16y ago
If it worked well to self-fund giant companies using the income from small ones, we should see instances of it happening in the wild. We don't have much of a history to work from, and the majority of the enabling tools available to us sim
29.
▲
by
nupark
16y ago
I run what would likely be classed as a lifestyle business (though I prefer to think of it as a large business in the process of bootstrapping). The more people there are running lifestyle businesses, the bigger the 'lillypad'. With a suffi
30.
▲
by
nupark
16y ago
This exchange cements my concerns about AirBNB only being huge if they can end-run the hotel regulatory system. pg: Did they explain the long-term goal of being the market in accommodation the way eBay is in stuff? That seems like it woul
More ›