Php is more secure than C.
For example, it is hard with C API for databases or templates to get SQL injection or XSS bugs. With PHP it is trivial and such usage still simpler than safer versions.
51–60 of 71 posts
Php is more secure than C.
For example, it is hard with C API for databases or templates to get SQL injection or XSS bugs. With PHP it is trivial and such usage still simpler than safer versions.
Earlier quoted context omitted.
I'm curious... Which is more secure? A) Slack. B) Open source software on a LAN accessible only through physical entry, SSH, and/or a VPN.
I'd vote slack.
Then I suggest you put more effort into securing your LAN situation because that is a vote indicating your belief your workstations are insecure.
Earlier quoted context omitted.
I'd vote slack.
> I'd vote slack. Then I suggest you put more effort into securing your LAN situation because that is a vote indicating your belief your workstations are insecure.
TLDR we chose Mattermost over Slack because of security. https://www.mattermost.com We recently evaluated many chat systems for a large tech consulting project that includes security needs. Slack was the frontrunner because of ubiquity, ease of use, plentiful third-party integrations, openness to free areas, and helpful in-person meetings with the Slack staff. We picked Slack for our informal connections with externa…
Perhaps this is a bit immature of me, but I despise Ryver for their ads that they put on Twitter a few months (a year?) back where it was completely trying to discredit Slack while having a sub-par UIX itself. Maybe I'll give it another look in the near future. EDIT: Security-wise, I would think Slack, as a bigger company, would have better security, but that's all assumption. Do you have anything to back up the idea…
My threat model emphasizes ease of security by normal users. For example, is it easy for my teammates to see when they're in a public area or private area? Can my teammates manage access controls the ways that they want? IMHO Ryver is better at this than Slack.
My sec team's threat model emphasizes the underlying platform getting hacked. IMHO Ryver and Slack are both SaaS, so both in the same boat on this: the info is outside the firewall, which incurs legal issues, compliance issues, revocation issues, etc. I believe that SaaS providers can be excellent at security, yet the SaaS target is much bigger, and the alerting is murkier, and revocation is not thorough. This is why we chose Mattermost for secure chat.
Earlier quoted context omitted.
I'd vote slack.
> I'd vote slack. Then I suggest you put more effort into securing your LAN situation because that is a vote indicating your belief your workstations are insecure.
Umm... why do people always assume "hosting it yourself" is more secure and not less? Do you have Slack's security expertise and budget? In my experience when small to mid-size companies attempt to manage security themselves they do a passable job but are convinced they are doing an excellent job - until they get hacked. Larger companies usually have the budget, tools and expertise. But even then there are lots big c…
> Umm... why do people always assume "hosting it yourself" is more secure and not less? Do you have Slack's security expertise and budget? In my experience when small to mid-size companies attempt to manage security themselves they do a passable job but are convinced they are doing an excellent job - until they get hacked. I'm not exposing it to the WAN, just the LAN. :\ I don't think people really appreciate how mas…
The majority of non-trivial breaches involve some sort of pivot or lateral movement inside the "protected" LAN. These often originate from a workstation.
I read a story from a blogger [1] who was visiting an Airbus facility for an A350 presentation and when he came back in plane, his neighbor, an Airbus sensitive contractor, was editing internal documents on a Chromebook using google doc. Yep. No fear.
[1] https://korben.info/vous-proteger-de-lespionnage-industriel-...
Weird, this post appears to have been nuked from orbit. What happened?
Weird, this post appears to have been nuked from orbit. What happened?
Well, I flagged it and I imagine others did too. It's not an 'Ask HN' it's 'Yell my opinion at HN while pretending to ask something'. Which isn't that great.
Earlier quoted context omitted.
Well, I flagged it and I imagine others did too. It's not an 'Ask HN' it's 'Yell my opinion at HN while pretending to ask something'. Which isn't that great.
You're kind of right. At the same time, the comments appear to be answering the question, so...