Hacker Newsnew | past | comments | ask | show | jobs | submit | fossguy's commentslogin

Remember those "offline" weekends? They are gone too... :)


For people that care about security, I would add those monitoring tools:

-OSSEC - log + file system security monitoring (http://ossec.net)

-Snort - Network-based IDS (http://snort.org)

-Sucuri (not free) - web site monitoring (http://sucuri.net)


Try OSSEC: http://www.ossec.net (open source log-based intrusion detection tool).


Nginx with 14% of market share is indeed very interesting, very close to IIS (17%).


The stats can be misleading, nginx is very good at being a reverse proxy or software load balancer and tends to be put to use in those contexts with pass-thru to existing web servers.

Because the stats look at headers, the last header before hitting the internet will be the nginx caches.


I think the 15 second was just an expression to "very quickly"


Perhaps, but that doesn't change my impression of the story: phone call is made, and everything is shut off in a flash immediately afterwards.

Even if not a literal 15 seconds, the phrase doesn't seem to imply that there was a length of time where someone on that end might have been investigating the issue. It implies that someone flipped the switch to "off" the instant one was able to get within reach of the switch.


It will be way less common, specialy considering that you can't execute anything in there...


That's a very, very silly idea. If the device can be jailbroken by browsing a webpage that exploits a vulnerability in the browser, such a page could also infect your device. The idea that the iPhone/iPod touch/iPad are any less vulnerable to viruses than any other networked device out there is just plain wrong. People can and will attack these devices, it's just a matter of how difficult it is; from my experience with auditing Apple's products, the difficulty level is generally somewhere between trivial and damn-near-trivial.


The difference is that fixing an iPad won't require a repair shop; it'll require plugging it into your computer, which will go through its normal syncing cycle of backing it up, then upgrading apps—but it'll notice the invalid app checksums on infected apps and overwrite them with App-Store-canonical versions. If kernel-level viruses become prevalent, it'll simply start checksumming that too, and offering to restore from an IPSW with all your data (but nome of your config) intact (but that won't be a problem, since part of Apple's aesthetic is "low configuration.")

Interestingly, it'll mean that only jailbreakers—and those with no access to a computer to sync with—will ever have viruses for more than one sync cycle.


But given a sufficiently complex code, you can execute from unexpected places. Sometimes even without any bugs involved:

http://blog.didierstevens.com/2010/03/29/escape-from-pdf/


Just have a kid and you will learn by yourself. If he is colic, you will get even less.


The best cheapest and easiest one is Paypal.


Until they steal all your money.


PayPal never steals all of your money. The worst that can happen is a 180 day freeze before funds are turned over to you, which is exactly the same way all payment processors handle risk issues. That's how long Visa/MC tells MAPs to hold the funds because that's the standard time limit on customers performing chargebacks, which becomes the basis of the policies set by the 3rd party processors that are in contract with MAPs to do the actual card charging.


Results 1 - 20 of about 32,000 for "paypal stole my money". (0.29 seconds)

No, Paypal's thefts are not generally about issues with Visa/MC, but rather with Paypal unilaterally deciding that an account is "fraudulent", and Paypal deciding to permanently keep all funds in that account. This is in addition to their broken dispute resolution process as well. Using Paypal is a risk that a corporation should be required to disclose to all investors in bold print. "WARNING: THIS COMPANY USES PAYPAL TO PROCESS PAYMENTS AND THUS MAY BE PUT OUT OF BUSINESS AT ANY TIME WITHOUT NOTICE."


The worst that can happen is your company goes out of business. http://whiteelephantmedia.com/ - Paypal requested $600k to keep the account open.


That is a pretty amazing story, the likes of which I've never read before. I can't even imagine how that situation came to be!


No doubt: open source it. It will benefit more people and it is better than shutting down or getting pennies for it.


I wish I could mod you up more. I am a big foss fan boy (can see by my nick), but most people don't care about licensing, if the code is open or not, etc.

They want something that works and fit their needs. That's it.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: