Report - Credentials in public GitHub repositories increase 20% during 2020
https://blog.gitguardian.com/state-of-secrets-sprawl-2021/
https://redd.it/m18hgk
@programmingreddit
https://blog.gitguardian.com/state-of-secrets-sprawl-2021/
https://redd.it/m18hgk
@programmingreddit
GitGuardian Blog - Automated Secrets Detection
State of Secrets Sprawl on GitHub - 2021 report - GitGuardian Blog
GitGuardian has been scanning every single public commit made on GitHub for secrets since 2017, now we are releasing our findings in the most comprehensive study on secrets sprawl ever conducted.
CVE-2021-21300 - Update your Git client RIGHT NOW (especially if you're using Windows or macOS)
https://github.blog/2021-03-09-git-clone-vulnerability-announced/
https://redd.it/m1g3y2
@programmingreddit
https://github.blog/2021-03-09-git-clone-vulnerability-announced/
https://redd.it/m1g3y2
@programmingreddit
The GitHub Blog
Git clone vulnerability announced
Today, the Git project released new versions to address CVE-2021-21300: a security vulnerability in the delayed checkout mechanism used by Git LFS during git clone operations affecting versions 2.15 and newer.
GitHub bug briefly gave valid authenticated session cookies to wrong users
https://www.theregister.com/2021/03/09/github_authentication_bug/
https://redd.it/m1g8h0
@programmingreddit
https://www.theregister.com/2021/03/09/github_authentication_bug/
https://redd.it/m1g8h0
@programmingreddit
The Register
GitHub bug briefly gave valid authenticated session cookies to wrong users
Don’t panic: Fewer than 0.001% of sessions compromised through flaw that couldn’t be maliciously triggered
Git: Malicious repositories can execute remote code while cloning
https://www.openwall.com/lists/oss-security/2021/03/09/3
https://redd.it/m1n69p
@programmingreddit
https://www.openwall.com/lists/oss-security/2021/03/09/3
https://redd.it/m1n69p
@programmingreddit
reddit
Git: Malicious repositories can execute remote code while cloning
Posted in r/programming by u/iamkeyur • 150 points and 15 comments
Today one of OVH Datacenter got destroyed in a fire. It might be the reason why some of the services you depend on are down. Also a good lesson for having a good disaster recovery plan!
https://twitter.com/olesovhcom/status/1369478732247932929
https://redd.it/m1w93m
@programmingreddit
https://twitter.com/olesovhcom/status/1369478732247932929
https://redd.it/m1w93m
@programmingreddit
Twitter
Octave Klaba
We have a major incident on SBG2. The fire declared in the building. Firefighters were immediately on the scene but could not control the fire in SBG2. The whole site has been isolated which impacts all services in SGB1-4. We recommend to activate your Disaster…
How the New York Times A/B tests their headlines
https://blog.tjcx.me/p/new-york-times-ab-testing
https://redd.it/m2iggf
@programmingreddit
https://blog.tjcx.me/p/new-york-times-ab-testing
https://redd.it/m2iggf
@programmingreddit
TJCX
How the New York Times A/B tests their headlines
Part 1 of a series on the New York Times, in which I take a close look at how (and when) the New York Times tests multiple headlines for a single article.
I bought 300 emoji domain names from Kazakhstan and built an email service
https://tinyprojects.dev/projects/mailoji
https://redd.it/m2o0rf
@programmingreddit
https://tinyprojects.dev/projects/mailoji
https://redd.it/m2o0rf
@programmingreddit
tinyprojects.dev
Mailoji: I bought 300 emoji domain names from Kazakhstan and built an email service | Tiny Projects
I bought 300 emoji domain names from Kazakhstan and built an emoji email address service. In the process I went viral on Tik Tok, made $1000 in a week, hired a Japanese voice actor, and learnt about the weird world of emoji domains.
Going from O(n) to O(log n) makes continuous profiling possible in production
https://github.com/pyroscope-io/pyroscope/blob/main/docs/storage-design.md
https://redd.it/m295kn
@programmingreddit
https://github.com/pyroscope-io/pyroscope/blob/main/docs/storage-design.md
https://redd.it/m295kn
@programmingreddit
GitHub
pyroscope/storage-design.md at main · pyroscope-io/pyroscope
Continuous Profiling Platform. Debug performance issues down to a single line of code - pyroscope/storage-design.md at main · pyroscope-io/pyroscope
TIL \r\n (CRLF) is a single grapheme cluster according to the Unicode standard (like an emoji)
https://unicode.org/reports/tr29/#Table_Combining_Char_Sequences_and_Grapheme_Clusters
https://redd.it/m274cg
@programmingreddit
https://unicode.org/reports/tr29/#Table_Combining_Char_Sequences_and_Grapheme_Clusters
https://redd.it/m274cg
@programmingreddit
reddit
TIL \r\n (CRLF) is a single grapheme cluster according to the...
Posted in r/programming by u/larikang • 102 points and 21 comments
7-Zip developer releases the first official Linux version
https://www.bleepingcomputer.com/news/software/7-zip-developer-releases-the-first-official-linux-version/
https://redd.it/m37lt7
@programmingreddit
https://www.bleepingcomputer.com/news/software/7-zip-developer-releases-the-first-official-linux-version/
https://redd.it/m37lt7
@programmingreddit
BleepingComputer
7-Zip developer releases the first official Linux version
An official version of the popular 7-zip archiving program has been released for Linux for the first time.
SQLite 3.35: math functions, materialized CTEs, RETURNING, and DROP COLUMN
https://nalgeon.github.io/sqlite-3-35/
https://redd.it/m3rm9r
@programmingreddit
https://nalgeon.github.io/sqlite-3-35/
https://redd.it/m3rm9r
@programmingreddit
Anton Zhiyanov
What’s new in SQLite 3.35
SQLite developers often prefer to work on database internals. For an external observer nothing really changes. 2020 was a pleasant exception - SQLite received a bunch of nice features for ordinary users, such as generated columns, UPDATE FROM and fantastic…
How to send an 'E mail' (1984)
https://www.youtube.com/watch?v=szdbKz5CyhA
https://redd.it/m3i3t7
@programmingreddit
https://www.youtube.com/watch?v=szdbKz5CyhA
https://redd.it/m3i3t7
@programmingreddit
YouTube
How to send an 'E mail' | Database | Retro Computers | Early E mail | 1980s Technology | 1984
How to send an e mail 1980's style. Electronic message writing down the phone line. First shown on Thames TV's computer programme 'Database' in 1984
07/06/1984
If you would like to license a clip for your production please e mail archive@fremantle.com
Quote:…
07/06/1984
If you would like to license a clip for your production please e mail archive@fremantle.com
Quote:…
Let's port Diablo to SerenityOS! [devilutionx]
https://www.youtube.com/watch?v=ZOzZ8R4gphE
https://redd.it/m2t3sr
@programmingreddit
https://www.youtube.com/watch?v=ZOzZ8R4gphE
https://redd.it/m2t3sr
@programmingreddit
YouTube
Let's port Diablo to SerenityOS!
devilutionX on GitHub: https://github.com/diasurgical/devilutionX
SerenityOS is open source on GitHub: https://github.com/SerenityOS/serenity
Merch: https://teespring.com/stores/serenityos
Follow me on Twitter: https://twitter.com/awesomekling
Sponsor me…
SerenityOS is open source on GitHub: https://github.com/SerenityOS/serenity
Merch: https://teespring.com/stores/serenityos
Follow me on Twitter: https://twitter.com/awesomekling
Sponsor me…
Critics fume after Github removes exploit code for Exchange vulnerabilities
https://arstechnica.com/gadgets/2021/03/critics-fume-after-github-removes-exploit-code-for-exchange-vulnerabilities/
https://redd.it/m357wh
@programmingreddit
https://arstechnica.com/gadgets/2021/03/critics-fume-after-github-removes-exploit-code-for-exchange-vulnerabilities/
https://redd.it/m357wh
@programmingreddit
Ars Technica
Critics fume after Github removes exploit code for Exchange vulnerabilities
Microsoft-owned Github pulls down proof-of-concept code posted by researcher.
Clone Wars – a list of 70 open-source clones of sites like Airbnb, TikTok, Netflix
https://github.com/GorvGoyl/Clone-Wars
https://redd.it/m4awot
@programmingreddit
https://github.com/GorvGoyl/Clone-Wars
https://redd.it/m4awot
@programmingreddit
GitHub
GitHub - GorvGoyl/Clone-Wars: 100+ open-source clones of popular sites like Airbnb, Amazon, Instagram, Netflix, Tiktok, Spotify…
100+ open-source clones of popular sites like Airbnb, Amazon, Instagram, Netflix, Tiktok, Spotify, Whatsapp, Youtube etc. See source code, demo links, tech stack, github stars. - GorvGoyl/Clone-Wars
A Spectre proof-of-concept for a Spectre-proof web | Google Online Security Blog
https://security.googleblog.com/2021/03/a-spectre-proof-of-concept-for-spectre.html
https://redd.it/m42jtf
@programmingreddit
https://security.googleblog.com/2021/03/a-spectre-proof-of-concept-for-spectre.html
https://redd.it/m42jtf
@programmingreddit
Google Online Security Blog
A Spectre proof-of-concept for a Spectre-proof web
Posted by Stephen Röttger and Artur Janc, Information Security Engineers Three years ago, Spectre changed the way we think about security b...