okta vulnerability, grumbling about security
Another year, another critical vulnerability in Okta's infrastructure - an authentication bypass for users with long usernames, this time.
They ran up against bcrypt's input limit. You know, exactly the kind of footgun that causes people to recommend "don't try to roll your own authentication, outsource it to experts". Like... Okta. Who used bcrypt. And did it wrong.
I would really like for people to stop recommending external authentication providers. It's not actually *that* hard to implement authentication correctly for the vast majority of cases, if you take some time to read up on how to do it. Outsourcing isn't the answer here.
I find myself wishing on a daily basis that I had built @bitfolk database as postgres from the start instead of MySQL (now MariaDB).
Don't be like me. If your new thing needs a relational DB, Just Use Postgres.
Just after posting this I lost 3 hours of my life to MariaDB's unhinged and cursed "utf8 charset/collation isn't really utf8" nonsense.
It's 1214 days since I filed a React Native bug because an external keyboard user on Android cannot get focus into a text input field so can't fill in forms. No-one cares. Except people with access needs, of course. https://github.com/facebook/react-native/issues/31820
Tyre mobility kit (spare tyre substitute) says to read the manual for instructions. We check the manual. Not under Tyre. Not under Puncture. Not under Tyre Mobility Kit. Not under Flat.
It's under I. For 'If'. Of course.
LB (https://phpc.social/@elazar/113402568468392900)
Please, as an absolute minimum to participate in society,
*Mask if you know you're sick*
Absolute. Bare. Minimum.
Opinie: Wrang dat postcovidcentra ME-patiënten weren https://www.volkskrant.nl/columns-opinie/opinie-wrang-dat-postcovidcentra-me-patienten-weren~b9b34816/
Trans people! I want to hear your coming-out stories (both to yourself and to others) that didn't fit the usual stereotypes and expectations. I want to hear about wrong assumptions that hurt you and made you repress even more.
Figuring out one's gender identity outside of the "wanted to be a girl in early childhood" and the "cross-dressing realization at Halloween" stories can be pretty lonely. So let's light some lights for our baby queers together
Finding life in unexpected places. It looks like someone was instructed to refresh the yellow paint on this concrete lamp base, and they just sprayed over the mosses and lichens, which have managed to continue growing anyway.
#mosstodon
Fascinatedly watching some of the crowd management for Danse Macabre's opening day: https://www.youtube.com/watch?v=6T1XEU-bX6s
If an employer ever asks you to resign, tell them "no".
There is no benefit to resigning unless you have another job lined up already.
Make them fire you. Get your unemployment benefits. Make sure you are legally protected in case of malfeasance. Resigning undermines all of that.
This message brought to you by AWS telling workers to return to office 5-days-a-week by commuting or relocating, or they should resign.
Again, the answer is "no, you'll have to fire me."
EDIT: To clarify, in most areas "fired" and "let go" are not legally meaningful terms and can be used interchangeably. The important term is "for cause" or not. So don't commit misconduct to get fired. Poor job performance is typically not a "for cause" reason, nor is failure to accept changes like RTO
@sinbad the main thing you would have missed is an increasingly heavy-handed series of lessons on the topic of how much it's appropriate to trust software companies
In the process of moving to @joepie91. This account will stay active for the foreseeable future! But please also follow the other one.
Technical debt collector and general hype-hater. Early 30s, non-binary, ND, poly, relationship anarchist, generally queer.
- No alt text (request) = no boost.
- Boosts OK for all boostable posts.
- DMs are open.
- Flirting welcome, but be explicit if you want something out of it!
- The devil doesn't need an advocate; no combative arguing in my mentions.
Sometimes horny on main (behind CW), very much into kink (bondage, freeuse, CNC, and other stuff), and believe it or not, very much a submissive bottom :p
My spoons are limited, so I may not always have the energy to respond to messages.
Strong views about abolishing oppression, hierarchy, agency, and self-governance - but I also trust people by default and give them room to grow, unless they give me reason not to. That all also applies to technology and how it's built.