Readit News logoReadit News

Loading parent story...

Loading comment...

rcconf commented on Multiple vulnerabilities in ingress-Nginx (Score 9.8)   groups.google.com/g/kuber... · Posted by u/numbsafari
rcconf · a year ago
I am a little confused about the comment section about this being overblown, it really isn't. Ignore all the comments in this post and fix this ASAP.

Here's a simple test:

`kubectl exec -it` a pod:

curl -k --fail https://ingress-nginx-controller-admission.ingress-nginx.svc...

If you see 400 Bad Request, that means this pod has access to the admission controller.

How easy would it be to find an avenue to make a request to the admission controller for anything running on your k8s cluster? (maybe your service takes any kind of URL and makes a request on your server...there's infinite possibilities of exploiting this.)

I am rethinking my choice in using ingress-nginx entirely, perhaps it's time to find a simpler solution that has more secure defaults.

rcconf commented on Show HN: AI Tool Is Now Supporting React, Angular, CSS, Svelte, Vue   webcrumbs.org/frontend-ai... · Posted by u/m4rcxs
rcconf · 2 years ago
Should we as developers put more effort into defending our craft? The movements in the artistic space with AI were very widespread and vocal, but we developers seem not to care. I feel like developers in general are a bit more quiet and timid with things and it leads to companies or entire industries taking advantage of us.

Am I the only one who feels like developers really need to be a bit more vocal in defending themselves, their craft, and even their sanity? Are we quiet because of the large salaries in the space?

I suppose the biggest question is how do you defend the craft but at the same time keep the advantage of automation and AI? (is it unions?)

rcconf commented on Valkey Is Rapidly Overtaking Redis   devops.com/valkey-is-rapi... · Posted by u/CrankyBear
rcconf · 2 years ago
Redis holds such a special place in my heart. It was the definition of awesome, open-source software. It always felt like Redis was THE definition of open source. The fact that the license has changed is heart-breaking.
rcconf commented on Instagram overtakes TikTok as most downloaded app   theguardian.com/technolog... · Posted by u/tosh
rcconf · 2 years ago
Basically Instagram Reels algorithm started to get very good, they found the magic algorithm and it's so much easier to click the Reels button than switch to the TikTok app. Plus, everyone has their friends on Instagram so why switch to another app?

That's my theory anyway. I remember when Instagram Reels was just awful and all the suggestions sucked, now it's actually good.

Surprising outcome, but very similar to what happened with Snapchat. Everyone used Snapchat and suddenly Instagram added Stories and over time people just used Instagram again when Instagram polished Stories enough.

Hmm, I guess Meta is unstoppable in the social media space.

Loading parent story...

Loading comment...

Loading parent story...

Loading comment...

Loading parent story...

Loading comment...

u/rcconf

KarmaCake day851January 15, 2013View Original