placeholder

How we found and fixed a rare race condition in our session handling - The GitHub Blog

On March 8, out of an abundance of caution, we logged all users out of GitHub.com. In this post we share technical details of the vulnerability and steps we're taking to ensure it doesn't happen again.

Click to view the original at github.blog

Hasnain says:

So this explains why everyone was logged out of GitHub the other day. Interesting technical analysis of a bug and a reminder of how hard it is to get complex code right.

“Taking a step back, a bug such as this is not only challenging from a technical perspective in how to identify complex interactions between multiple threads, deferred callbacks, and object sharing, but it is also a test of an organization’s ability to respond to a problem with an ambiguous cause and risk.”

Posted on 2021-03-19T03:14:58+0000

placeholder

Facebook's ‘Red Team X’ Hunts Bugs Beyond the Social Network's Walls

The internal hacking team has spent the last year looking for vulnerabilities in the products the company uses, which could in turn make the whole internet safer.

Click to view the original at wired.com

Hasnain says:

This is a pretty cool profile of a team within the security org at Facebook. The lede sums it up well:

"IN 2019, HACKERS stuffed portable network equipment into a backpack and roamed a Facebook corporate campus to trick people into joining a fake guest Wi-Fi network. That same year, they installed more than 30,000 cryptominers on real Facebook production servers in an attempt to hide even more sinister hacking in all the noise. All of this would have been incredibly alarming had the perpetrators not been Facebook employees themselves, members of the so-called red team charged with spotting vulnerabilities before the bad guys do. "

Posted on 2021-03-18T21:48:01+0000

placeholder

AAJA Guidance on Atlanta Shootings, Asian American Journalists Association

March 17, 2021 AAJA Guidance on Atlanta Shootings Contact: Naomi Tacuyan Underwood, Executive Director / naomitu@aaja.

Click to view the original at aaja.org

Hasnain says:

While I’m still processing the terrible, racist shootings in Atlanta yesterday, I found this useful - not just for journalists, but for us everyday folk learning more about this so we can empathize. I’d known a bit superficially about the history of anti-Asian racism in the US but the more I learn the more horrified I get.

“Understand anti-Asian racism and invisibility. Racism against AAPIs is highly nuanced, complex, and has remained historically invisible, and includes a long history of hypersexualization of Asian women that is rooted in Westernized and colonial perceptions of Asia.

This is inextricably linked to harassment and sexualized violence against Asian women. Women of Asian descent have reported 2.3 times more incidents of violence than AAPI men, according to a new Stop AAPI Hate report of nearly 3,800 hate incidents reported since March 2020. “

Posted on 2021-03-17T20:00:57+0000

placeholder

Exclusive: 'Landlord from Hell' Defends Terrorizing Apartment Tenants

Kip Macy, 38, and his wife, Nicole Macy, 37, were deemed "landlords of hell" by authorities for menacing the tenants of their San Francisco apartment building.

Click to view the original at abcnews.go.com

Hasnain says:

I just learnt today that this is the guy that contributed a lot of the wireguard code to pfsense and is still going strong.

Also who the hell saws their tenant’s floor?!

“Eventually he and Nicole Macy were arrested at Kip Macy's parents' house in 2008 and released on $500,000 bond, for which Kip Macy's parents drained much of their retirement savings to pay. His mother Marie even sold her jewelry to help finance their release. Once free, Kip and Nicole Macy jumped bail, fleeing to Italy, leaving Kip Macy's father and mother, potentially at a loss of half a million dollars.”

Posted on 2021-03-17T02:56:43+0000

placeholder

Atlas: Our journey from a Python monolith to a managed platform

Dropbox, to our customers, needs to be a reliable and responsive service. As a company, we’ve had to scale constantly since our start, today serving more than 700M registered users in every time zone on the planet who generate at least 300,000 requests per second. Systems that worked great for a s...

Click to view the original at dropbox.tech

Hasnain says:

“In our view, developers don’t care about the distinction between monoliths and services, and simply want the lowest-overhead way to deliver end value to customers. So we have very little doubt that a managed platform which removes operational busywork like capacity planning, while providing maximum flexibility like fast releases, is the way forward. We’re excited to see the industry move toward such platforms.”

Posted on 2021-03-16T08:36:36+0000

placeholder

30 current and former Mailchimp employees detail the conditions that led to a 'mass exodus' of women and people of color

Mailchimp employees repeatedly complained about problematic executives and bosses. They say the company turned a blind eye.

Click to view the original at businessinsider.com

Hasnain says:

What the actual.. This quote is not even the worst bit, it keeps getting worse

“Konikowski quit, but her managers — both white men — were eventually promoted to senior management. Van Aalten said the promotions troubled them because one of those managers had called them a Nazi, despite knowing they are Jewish. Multiple former Mailchimp employees also said that the manager questioned whether people with Down's Syndrome were "real people" because they inherit an extra chromosome.”

Posted on 2021-03-16T07:35:15+0000

placeholder

A Hacker Got All My Texts for $16

A gaping flaw in SMS lets hackers take over phone numbers in minutes by simply paying a company to reroute text messages.

Click to view the original at vice.com

Hasnain says:

This attack is quite scary.

“"While text message forwarding might have legitimate applications for businesses, the particular implementation underpinning this attack is appallingly weak in security and data privacy. Telcos have different ways of authenticating their customers, obviously including text messaging. The fact that none of these authentication methods are used in this case to get consent from the owner of a forwarded phone number is shocking," Nohl added.”

Posted on 2021-03-15T23:32:14+0000

placeholder

Answers on grant reports if nonprofits were brutally honest with funders

[Image description: A cute little raccoon, standing in the grass, one paw raised. They look serious. But so cute! Admit it, this is one of the cutest raccoons you’ve ever seen. Not sure this …

Click to view the original at nonprofitaf.com

Hasnain says:

“How did you spend the grant that we provided you? The grant you gave us went into our bank account, which is used to pay for everything. Disaggregating what you paid for versus what others paid for is one of those meaningless time-wasting activities you force on us that harm our work. Here’s a detailed financial report of every expense we made this year. Look through it, and if it makes you feel better to think that you paid for books for low-income children and not staff salaries or whatever, please use your own time to craft that delusion.”

Posted on 2021-03-14T08:38:39+0000

placeholder

Hasnain says:

“Then I started thinking about it, and realized there’s no way this happened in a vacuum. It’s unlikely that Ryan Parr saw my tweet and immediately escalated it to, “We’re sending this to our legal team.” I think it speaks a lot to their company culture that things went this far. I wonder how many people they’ve threatened with legal action like this. How many people didn’t have the time or the energy to stand up for themselves in the face of a three billion dollar company’s legal team coming after them? It honestly makes me a little sick.”

Posted on 2021-03-13T18:20:40+0000

placeholder

Hasnain says:

Interesting take on this whole story from an HR perspective

“The core of Google’s culture is to thrust ahead and discover operational flaws as the result of execution. This “move quickly and break things” approach is at the heart of many Silicon Valley firms. The paper urges restraint, research discipline, preplanning, consideration of all stakeholders and investigation of alternative approaches.

It’s hard to imagine a more sensible approach. It’s also hard to imagine a more substantive critique of the culture at Google. It is easy to understand why the company’s leadership responded as they did.”

Posted on 2021-03-12T18:59:09+0000