Not deploying a simple HTTP header, something that literally every website security scan out there would flag, is apparently not a sign of crappy security practices, folks.

Oh for fuck's sake, OpenSSL. Just when I was starting to think they'd finally gotten their shit together

Yes, OpenStack Horizon, sending a HTTP request for every object in a directory is surely the best way to implement directory deletion. I don't mind letting Chrome run for a few days.

I used to complain about Apple Music recommendations being crap, but I found this in my weekly new music playlist today, so kudos to them for improving the personalization aspect, even if it's based on my professional interests rather than music, I guess.

TFW you get a mail like this and your password manager indicates you were using a random & unique 20 character password ...

The level of frustration experienced while trying to fix a bug is directly proportional to the number of browser tabs it takes to find the solution.

My sidekiq process (specifically the one handling the "push" queue) just ran into its ulimit for some reason and started failing jobs with "Too many open files - getaddrinfo".

Monitoring shows that the open socket count has been increasing ever since I updated to 2.1, making me think it's somehow leaking sockets. Is anyone else seeing this?

If your monitoring isn't tracking this, you can count manually with:

ls -l /proc/<SIDEKIQ_PID>/fd | wc -l

Amazon launched a preview of their Translate API today, and there's no attribution requirement! πŸŽ‰

This service is the best fit for Mastodon so far, so I can probably (finally!) push that feature once they release the Ruby SDK and process my preview application.

We might be looking at another "Apple pls sign firmware with backdoor" court case soon:

Unlike the San Bernardino case, this iPhone has a Secure Enclave. Law enforcement could try to find someone that sells them an exploit (which should not be an option unless there's a design flaw in the Secure Enclave), or they could go through the courts, who could force them to sign firmware that disables PIN rate-limiting and the auto-wipe feature.

