• 7 Posts
  • 47 Comments
Joined 1 year ago
cake
Cake day: June 15th, 2023

help-circle


  • SQL, where injection is still in the top 10 security risks

    This is absolutely true, but it’s not what it looks like on the surface, and if you dig into the OWASP entry for this, you’ll see they talk about mitigation.

    You can completely eliminate the possibility of injection attacks using well-understood technologies such as bind variables, which an ORM will usually use under the covers but which you can also use with your own queries. There are many, many database applications that have never once had a SQL injection vulnerability and never will.

    The reason SQL injection is a widespread security risk, to be blunt, is that there are astonishingly large numbers of inexperienced and/or low-skill developers out there who haven’t learned how to use the tools at their disposal. The techniques for avoiding injection vulnerability are simple and have been well-documented for literally decades but they can’t help if a lousy dev decides to ignore them.

    Now, a case could be made that it’d be better if instead, we were using a query language (maybe even a variant of SQL) that made injection attacks impossible. I agree in principle, but (a) I think this ends up being a lot harder than it looks if you want to maintain the same expressive power and flexibility SQL has, (b) given that SQL exists, “get bad devs to stop using SQL” doesn’t seem any more likely to succeed than “get bad devs to use bind variables,” and © I have too much faith in the ability of devs to introduce security vulnerabilities against all odds.





  • I think the value of standups depends a ton on the team’s composition and maturity.

    On a team with a lot of junior or low-performing devs who don’t have the experience or the ability to keep themselves on track, or a team with a culture that discourages asking for help as needed, a daily standup can keep people from going down useless rabbit holes or unwittingly blocking one another or slacking off every day without anyone noticing.

    On a team of mostly mid-level and senior devs who are experienced enough to work autonomously and who have a culture of communicating in real time as problems and updates come up, a daily standup is pure ceremony with no informational value. It breaks flow and reduces people’s schedule flexibility for no benefit.

    When I’m thinking about whether it makes sense to advocate for or against daily standups on a team, one angle I look at is aggregate time. On a team of, say, 6 people, a 15-minute daily standup eats 7.5 hours of engineering time a week just on the meetings themselves. The interruption and loss of focus is harder to quantify, but in some cases I don’t even need to try to quantify it: when I ask myself, “Is the daily standup consistently saving us a full person-day of engineering time every week?” the answer is often such a clear “yes” or “no” that accounting for the cost of interruptions wouldn’t change it.


  • Especially infuriating when the other person is in a very different time zone. I once worked on a project with a partner company in a time zone 10 hours ahead of mine and it was common for trivial things to take days purely because the other person insisted on typing “Hi,” waiting for my “Hi, what’s up?” response (which they didn’t see until the next day since our hours didn’t overlap), and then replying with their question, which I didn’t see until my next day. Answering the actual question often took like 30 seconds, but in the meantime two or three days had gone by.

    I came to believe they were doing it on purpose so they could constantly slack off and tell their boss they were blocked waiting for my answer.








  • Not the person you’re replying to, but I’m also a “try the local cuisine” person. A good percentage of the places I’ve visited have had some local thing that you’d have to really look for to find elsewhere. I don’t end up liking all of them, but I like the experience of trying something new. Some specific examples:

    • St. Louis, MO, USA: Gooey butter cake which is as gross and as delicious as it sounds.
    • Changsha, Hunan, China: Stinky tofu. The local Changsha style of stinky tofu is completely unlike the more common style you’d find in night markets in Taiwan or elsewhere; it’s only a little stinky but is dense, savory, and spicy.
    • Singapore: Kaya toast. Kaya is a sweet coconut-based spread and they put it on buttery thick toast. I was addicted to this when I was in Singapore for work.
    • Scotland: Haggis. It was… okay? Didn’t love it, didn’t hate it, don’t see why it has the reputation it has.
    • Jingdezhen, Jiangxi, China: Jiaoziba, which is a little local style of dumpling that’s rich and quite spicy.
    • Hiroshima, Japan: Okonomiyaki, a kind of savory pancake. Okonomiyaki is common in Japan but it’s usually Osaka-style. The version they make in Hiroshima includes noodles in the dough.

    In my experience, if you talk to a few locals, one of them will usually think of a local specialty and tell you where to try it.


  • I think this is a more subtle question than it appears on the surface, especially if you don’t think of it as a one-off.

    Whether or not Scientology deserves to be called a “religion,” it’s a safe bet there will be new religions with varying levels of legitimacy popping up in the future. And chances are some of them will have core beliefs that are related to the technology of the day, because it would be weird if that weren’t the case. “Swords” and “plowshares” are technological artifacts, after all.

    Leaving aside the specific case of Scientology, the question becomes, how do laws that apply to classes of technology interact with laws that treat religious practices as highly protected activities? We’ve seen this kind of question come up in the context of otherwise illegal drugs that are used in traditional rituals. But religious-tech questions seem like they could have a bunch of unique wrinkles.


  • Depends on where I’m going, whether I’ve been there before, and how long my trip is, but as a rule I’ll always seek out the local food and try to see a mix of famous big-name sights and weird niche things that interest me. For example, when I was in Tokyo last, I went to the top of Tokyo Tower at sunset (normal tourist sightseeing thing) and also went to see their underground flood-control tunnels.

    I don’t enjoy “sit on a beach and do nothing” vacations, but more power to you if that’s your style.