Readit News logoReadit News
rcconf commented on Multiple vulnerabilities in ingress-Nginx (Score 9.8)   groups.google.com/g/kuber... · Posted by u/numbsafari
mort96 · 9 months ago
Score 9.8 ought to mean, "this is almost the worst conceivable vulnerability".
rcconf · 9 months ago
This is literally true, it is the worst conceivable vulnerability, total access to your k8s cluster by hitting a URL, how about a 10 instead of 9.8, these comments are wild.
rcconf commented on Multiple vulnerabilities in ingress-Nginx (Score 9.8)   groups.google.com/g/kuber... · Posted by u/numbsafari
rcconf · 9 months ago
I am a little confused about the comment section about this being overblown, it really isn't. Ignore all the comments in this post and fix this ASAP.

Here's a simple test:

`kubectl exec -it` a pod:

curl -k --fail https://ingress-nginx-controller-admission.ingress-nginx.svc...

If you see 400 Bad Request, that means this pod has access to the admission controller.

How easy would it be to find an avenue to make a request to the admission controller for anything running on your k8s cluster? (maybe your service takes any kind of URL and makes a request on your server...there's infinite possibilities of exploiting this.)

I am rethinking my choice in using ingress-nginx entirely, perhaps it's time to find a simpler solution that has more secure defaults.

rcconf commented on Show HN: AI Tool Is Now Supporting React, Angular, CSS, Svelte, Vue   webcrumbs.org/frontend-ai... · Posted by u/m4rcxs
rcconf · a year ago
Should we as developers put more effort into defending our craft? The movements in the artistic space with AI were very widespread and vocal, but we developers seem not to care. I feel like developers in general are a bit more quiet and timid with things and it leads to companies or entire industries taking advantage of us.

Am I the only one who feels like developers really need to be a bit more vocal in defending themselves, their craft, and even their sanity? Are we quiet because of the large salaries in the space?

I suppose the biggest question is how do you defend the craft but at the same time keep the advantage of automation and AI? (is it unions?)

rcconf commented on Valkey Is Rapidly Overtaking Redis   devops.com/valkey-is-rapi... · Posted by u/CrankyBear
rcconf · 2 years ago
Redis holds such a special place in my heart. It was the definition of awesome, open-source software. It always felt like Redis was THE definition of open source. The fact that the license has changed is heart-breaking.
rcconf commented on Instagram overtakes TikTok as most downloaded app   theguardian.com/technolog... · Posted by u/tosh
rcconf · 2 years ago
Basically Instagram Reels algorithm started to get very good, they found the magic algorithm and it's so much easier to click the Reels button than switch to the TikTok app. Plus, everyone has their friends on Instagram so why switch to another app?

That's my theory anyway. I remember when Instagram Reels was just awful and all the suggestions sucked, now it's actually good.

Surprising outcome, but very similar to what happened with Snapchat. Everyone used Snapchat and suddenly Instagram added Stories and over time people just used Instagram again when Instagram polished Stories enough.

Hmm, I guess Meta is unstoppable in the social media space.

rcconf commented on Ask HN: Alternative to Mint.com?    · Posted by u/SMAAART
qrush · 2 years ago
YNAB has turned my financial life around. I wish I had started using it 10 years ago. They also have built an importer from Mint. Some highlights I love:

* One window to every account I have, which mostly automatically updates/syncs

* Envelope budgeting has forced me to look at every penny and figure out what it's for

* API to work with other tools (for me, Splitwise - https://github.com/vascopinho/split2ynab/)

And here's my referral code for a free month: https://ynab.com/referral/?ref=ASH303nViLPCKyr-

rcconf · 2 years ago
I have YNAB and the most annoying part of the entire thing is that you cannot see your total expenses? I mean, the most basic feature is not in this app.

If I want to see my monthly expenses (total), it doesn't let me. It just shows me how much I need to save this much in each bucket.

Weird.

rcconf commented on Improving deep sleep may prevent dementia, study finds   monash.edu/news/articles/... · Posted by u/clouddrover
aantix · 2 years ago
If you're a slow metabolizer of caffeine like I am, stay away from caffeine.

CYP1A2

https://www.geneticlifehacks.com/liver-detox-genes-cyp1a2/

The difference in sleep quality is dramatic.

If I have caffeine, even a small 20mg at 7am, I'm up 4-6 times the next night, going to the bathroom, superficial sleep.

Without caffeine, I'm in a deep sleep. So much so that I don't change positions at all, and my body slightly aches from being in the same position so long. My bladder nearly feels like it's going to burst, because I've slept so long.

There was a study I saw while back that said eating cruciferous vegetables speeds up caffeine metabolism. I've tried that, but that didn't seem to help. The caffeine still seemed to disturb my sleep. I tried BrocoMax, a broccoli supplement, that didn't seem to help either.

Exercise helps a little bit. But it's still not the quality of sleep I receive with zero caffeine.

I think much faster when I drink caffeine. Recently I revisited this issue and tried micro-dosing 5-Hour Energy (2mL). At first it seemed promising. But then it seems to slowly build up in my system. Sleep quality deteriorates slower. But the deterioration is there. I prematurely posted this status.

https://twitter.com/aantix/status/1706020516060971399

Sadly, it doesn't appear that I can drink caffeine and have quality sleep.

I hate that I have to choose.

rcconf · 2 years ago
I have the same issue, it's truly unfortunate. What's odd is I forget about what caffeine does to my sleep and after a few weeks/months of drinking it, I'm wondering why I'm so stressed, tired and can't get ANY sleep.

I stop drinking coffee and BAM, I sleep like a baby. It doesn't MATTER when I drink it, I can drink it at 6AM and I will not have a good deep sleep. I am unsure if this is coincidence, but I also notice I remember way less dreams when I am on caffeine than not. I also find it's a compounding effect which is why it's slightly annoying.

If I drink 1 cup, in 2 weeks, my sleep will be fine so I will think, okay, it's not the caffeine. Then I will continue drinking it for weeks and suddenly I haven't had a good nights rest in weeks and I'm wondering what is going on. Not having deep sleep for weeks really has a big impact on your stress levels, memory, emotional well being and general energy levels.

The annoying part is coffee is so good for productivity so I go through cycles (also you start to think it's the stress not the caffeine that's causing the sleep issue!)

Weeks of stressful work - drink more caffeine to get all the work done - bad sleep, bad mood, bad energy levels, aka all the negative affects from not having enough deep sleep.

Weeks of less stressful work, no caffeine, great sleep, great mood/energy levels, etc.

I've always convinced myself that not drinking caffeine for deep sleep is just placebo, but I've tested it so many times that it just can't be.

Is there a way to test if you're a slower metabolizer? I know my partner can drink 3 cups and she is totally fine, lucky her! I'm 100% convinced I am, but it would be cool to test by some sort of blood/urine test?

rcconf commented on Apple Vision Pro: Apple’s first spatial computer   apple.com/newsroom/2023/0... · Posted by u/samwillis
rcconf · 3 years ago
Regardless of how well this product does, the presentation and vision from Apple was phenomenal. It was like watching a cinematic AAA movie, so exciting and inspiring. There has been no other company that has been able to present AR and VR in such a way that is so exciting.

The augmented reality shifting to virtual with the dial is so genius. I feel like a kid, and that's rare to feel these days. Love it, dream on Apple!

u/rcconf

KarmaCake day851January 15, 2013View Original