The guys behind this report have an interesting pricing model: Pay what you want! https://detectify.com/pricing The pricing models has apparently worked so far. Are any active users of Detectify here and can share their experience?
I like the price but they found nothing, honestly, and we're not very nice when I emailed them for support.
How we got read access on Google’s production servers
171–180 of 197 posts
Re: How we got read access on Google’s production servers
#172Earlier quoted context omitted.
Sure, but didn't YAML in Rails do mostly the same type of thing? It's not just XML that is dumb like this.
YAML and XML seem too powerful and too complex for their own common use cases (data storage). Markdown too - how many Markdown parsers allow for strict parsing against an HTML whitelist, and don't allow native HTML at all by default?
Re: How we got read access on Google’s production servers
#173Earlier quoted context omitted.
Hmm a pretty cheap road trip for just ten dollars, and I'm also not sure why they thought it necessary to include an extra significant figure for cents.
Some countries reverse the role of period and comma in numbers. The author meant ten thousand.
Re: How we got read access on Google’s production servers
#174Earlier quoted context omitted.
YAML and XML seem too powerful and too complex for their own common use cases (data storage). Markdown too - how many Markdown parsers allow for strict parsing against an HTML whitelist, and don't allow native HTML at all by default?
I've never even thought of that. Wow. Obvious now of course.
Re: How we got read access on Google’s production servers
#175Earlier quoted context omitted.
So you pay money to hire somebody to send a company a letter informing the company of the companies problem in hopes that maybe, just maybe, the company will reward the the firm a small sum of money and you will get a small amount back. I think you have a winner on your hands.
They wouldn't be doing it for the money. The EFF would be a good example of a firm that could take this practice up.
The only thing I can think about is some security firm doing this, using the exposure as a marketing tool and establish them as an authority on the subject.
Re: How we got read access on Google’s production servers
#176Re: How we got read access on Google’s production servers
#177Earlier quoted context omitted.
With the kind of monitoring that Google has in place your access will last a very short time.
What kind of monitoring would you deploy that would raise an alert for a process opening and reading readable files?
Re: How we got read access on Google’s production servers
#178Earlier quoted context omitted.
XML made it for more manageable to create machine to machine API's. I can say we surely would not want go back to the 80's and 90's when dong that stuff was a nightmare.
Yes, it was a drunken, stumbling step forward. Let's take another one, and move to something simpler, which solves the problem better. To quote Phil Wadler's paper about XML, where he established some of the principles that influenced Xquery: "So the essence of XML is this: the problem it solves is not hard, and it does not solve the problem well."[1] I suggest reading the entire paper; It shows a number of shortcomi…
Re: How we got read access on Google’s production servers
#179... And this is why you want to discontinue products and services your engineers can't be motivated to maintain. Amazing. This should scare anyone who has ever left an old side project running; I could see a lot of companies doing a product/service portfolio review based on this as a case study.
Or just move it to some cheap VPS where it cannot damage other services or your infrastructure.
Even better, host on your competitor's servers.