Now install tools that are only available as github released binaries. And ensure that hashes match for that. Maybe install a tool that needs to be compiled.
- 0 Posts
- 7 Comments
What if, get this, we put the bash scripts in yaml. And then put it in kubernetes.
fireflash38@lemmy.worldto Programming@programming.dev•OP finds vulnerability where a forum sends you your password in plaintext over email and everyone misses the forest for the treesEnglish51·2 years agoAnd what is the token in the link?
fireflash38@lemmy.worldto Programming@programming.dev•What are the pros and cons of authentication with API key vs client_id+secret?English4·2 years agoConsider that a ‘username+password’ is much harder to ‘revoke’ individually. As in, you can have 3-4 API keys in use, and can revoke any one of them without having to change a password.
You can also change password independently of the keys, or have it linked so keys are revoked on a password change. It also allows traceability as to where accesses are coming from (auditability). If everything is using the same client-id+secret (or usn/pwd), you don’t know which ‘client’ is doing what.
fireflash38@lemmy.worldto Technology@lemmy.world•HW News - Linus Tech Tips' Terrible Response, ESMC, & Starfield x AMD GPUsEnglish951·2 years agoIt’s the sort of thing that makes me really, really sad for the people working there. That crazy breakneck pace cannot be good for mental health.
fireflash38@lemmy.worldto Technology@lemmy.world•Why you shouldn't use Brave BrowserEnglish3·2 years agoDid you only make it past the first paragraph? Cause you missed the years of scummy shit they’ve done, completely unrelated to politics.
Got a source for the majority claim?