Earlier quoted context omitted.
You suggest it was just one lone engineer being incompetent. Then you respond to downvotes with the non-sequitur "take some pride in your work" - are you suggesting pride is a fix for incompetence? What?
There are two points. 1) Any engineer involved in implementing this "fix" is incompetent. 2) If you are not incompetent and management tries to force you to implement this "fix" then you should take pride in your work and refuse to do it, even if it means quitting your job (or forcing the company to fire you).
Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
151–160 of 322 posts
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#152Earlier quoted context omitted.
I honestly envy the sort of person who can post something like this. Not liking nodejs is fine, but to extrapolate from "I don't like nodejs" to "Thousands of engineers at companies like Google are wrong and I am right" must require such a level of myopic, ignorant self-belief that is completely alien to me. I just find myself respecting other people's work too much, even if I don't like it.
> Thousands of engineers at companies like Google That's an appeal to authority. It's also worth noting that nodejs is not a Google project and it is barely used internally at all. Only for small toy projects. Google uses python for scripting, or java for real servers.
It is, but it's also shorthand for "people who are likely to be good based on the fact they've been through a rigorous hiring process designed to filter out the worst engineers". Sometimes, maybe, you should let the principle of charity win over the rigorous rhetorical logic you can use to dismiss an argument because it broke The Rules you learned on LessWrong.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#153Earlier quoted context omitted.
I honestly envy the sort of person who can post something like this. Not liking nodejs is fine, but to extrapolate from "I don't like nodejs" to "Thousands of engineers at companies like Google are wrong and I am right" must require such a level of myopic, ignorant self-belief that is completely alien to me. I just find myself respecting other people's work too much, even if I don't like it.
I might be inclined to believe you, but node's ecosystem really is a trainwreck
However, this is true for literally every language we code in.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#154Earlier quoted context omitted.
You live in a nice world, because usually the actual power (and duty) of a dev team member is to advise, not to agree or refuse.
So whose fault is the cancerous heap of flaming dogshit that is nodejs, then? Some manager managed it into existence? No, it's the brainchild of an engineer. Somebody actually thought nodejs was a good idea. Face it, there are lots of really bad engineers out there.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#155Of all the security post-mortems I’ve ever wanted to read, it’s sad I’ll probably never get to read this one and its tale of how a team of well-paid comfortable engineers got together and decided this patch was a good idea.
>how a team of well-paid comfortable engineers got together and decided this patch was a good idea Test-driven development
It's completely unrelated to any development methodology, this is someone unaware of basic HTTP protocol semantics.
So just bad development, period.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#156Of all the security post-mortems I’ve ever wanted to read, it’s sad I’ll probably never get to read this one and its tale of how a team of well-paid comfortable engineers got together and decided this patch was a good idea.
Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…
1. Explain that the 'hack' does not actually fix the problem. This is absolutely the engineers responsibility. In your example Alice does not say that. This has always been sufficient.
2. I make a habit of sending emails or keeping minutes confirming such meetings and the details of who said what.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#157Earlier quoted context omitted.
So when I check desktop site in chrome I'm hacking?
Of course! So is right clicking and selecting inspect element to modify the page!
Or also when you run into those websites designed on a $2000 screen that thinks it’s tres moderne to use 808080 text, so you “hack” it into readable text.
I think those are all happy little hacks :-)
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#158Earlier quoted context omitted.
I like the original more without your embellishment. The addition sounds like every attempt at follow up humor on reddit.
Yeah but it's not Reddit, it's HN. You have to know your audience, read the crowd. On Reddit it's 90% sarcasm so there's no fixing it. Here it's the reverse and people take things seriously without a tell. You just have to bury the tell in another joke or it will ruin the funny.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#159Cisco is crumbling under its own weight. This is a symptom of the rot in their management, and probably also a sign that they have hired too many incompetents. It probably also is a sign of the current age. After the recovery from the IT-bubble programming got really hot. Thus: Too many of the new programmers wants to be programmers because it pays well - not because they love their craft. So therefore we have a bunc…
> I want my socially maladept neckbeards and terminal junkies back plz. the MBA types don't like these hacker types - personality clash and whatnots. But the MBA types control the company from above, and the hacker types don't like to do management work. The result is obvious.
My conclusion was that I would buy my infrastructure from Allied Telesis. It's pretty much a Japanese version of Cisco, but it's still healthy.
Ubiquity was number 2. I refrain from buying from them only because of their glossy UI.
Mikrotik was on that list. Until I saw how horrible their winbox protocol was. And their implementation of SMB.. I must assume there are still plenty of unknown RCEs there.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#160Earlier quoted context omitted.
On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…
You live in a nice world, because usually the actual power (and duty) of a dev team member is to advise, not to agree or refuse.