Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×

Comment oh. Wait, what? (Score 3, Insightful) 164

"Sadly Rails documentation doesn't warn you about this pitfall, but if you know anything at all about using SQL databases in web applications, you'd have heard of SQL injection, and it's not hard to come across warnings that find_by_sql method is not safe," Dmitry Borodaenko, a former production engineer at Facebook who brought the commit to my attention wrote in an email. "It is not 100% confirmed that this is the vulnerability that was used in the Gab data breach, but it definitely could have been, and this code change is reverted in the most recent commit that was present in their GitLab repository before they took it offline." Ironically, Fosco in 2012 warned fellow programmers to use parameterized queries to prevent SQL injection vulnerabilities.

So, this was the vulnerability, unless maybe it wasn't the vulnerability, because we don't know.

Also, Rails documentation absolutely does warn you about the ">pitfalls of using find_by_sql indiscriminately:

Ruby on Rails has a built-in filter for special SQL characters, which will escape ' , " , NULL character, and line breaks. Using Model.find(id) or Model.find_by_some thing(something) automatically applies this countermeasure. But in SQL fragments, especially in conditions fragments (where("...")), the connection.execute() or Model.find_by_sql() methods, it has to be applied manually.

Comment Key bits (Score 1) 772

So, there are a few key takeaways here. I'm just going to blatantly steal the author's version:

First, there is zero correlation between saying one "believes" in evolution & understanding the rudiments of modern evolutionary science...
Second, "disbelief" in evolution poses absolutely no barrier to comprehension of basic evolutionary science...
Third -- and here we are getting to the point where the new data come in! -- profession of "belief" in evolution is simply not a valid measure of science comprehension.

Okay, well and good. But I'd argue that he's also eliding a key epistemological question. Namely, can you lay claim to fundamentally understanding a theory of science if you're wrong about it?

Let's say I'm Tycho Brahe. My contemporary, Nicolaus Copernicus, has published a book in which he suggests that the Sun is the center of the solar system. Based on my knowledge of astronomy, mathematics, and religion, I propose an alternate view, one which says that it's actually the sky spinning around the Earth. After all, the Earth is way too heavy to spin like Copernicus suggests.

So with regard to this subject, does Tycho Brahe understand the science?

Comment Re:Further disconnect from the "GOP". (Score 1) 1010

Republicans are such a perverted facsimile of what used to be a very reasonable party. If 6 years of Obama has taught us anything, it's that the empty can gets the grease. USA Politics desperately needs the GOP to fork into two factions - there are enough independents currently voting "D" to jump over to make a center-right candidate feasible. Center-right by US Standards, that is.

I'd say that's pretty self-evident - the last two presidents that ran on the Democratic ticket were both center-right candidates.

Comment Re:alternatively (Score 3, Insightful) 193

There is actually a separate edition of the book called Modernist Cuisine at Home which is specifically tailored to home chefs who want to try out the techniques, for substantially less money than the full version. Actually, the ebook which is the topic of the article is based on the "at Home" edition, which means the price differential between the ebook and dead tree version is only about thirty bucks, not several hundred.

Comment Re:Technology costs? (Score 1) 336

First of all - werd. To just about all of this.

Secondly I want to add that it's not as if there is some other definitive source that the government can use to determine the appropriate reimbursement rate for procedures. Hospitals have something called a "chargemaster list," but the prices on those lists vary wildly from hospital to hospital. And most hospitals, when quizzed as to why the prices seem so out of whack, argue that it doesn't matter because consumers "rarely" ever pay those prices.

Steven Brill had an amazing article on this subject in Time magazine, but it's now behind a paywall. You can find it here: http://www.time.com/time/magazine/article/0,9171,2136864,00.html.

And the Washington Post has a brief discussion of the article here: http://www.washingtonpost.com/blogs/wonkblog/wp/2013/02/23/steven-brills-26000-word-health-care-story-in-one-sentence/

Comment Today in the annals of unfortunate capitalization: (Score 3, Insightful) 84

Just to be clear: the title of this story should be interpreted "The combined traffic of Google's internet properties now account for 25% of all Internet traffic in North America."

Not, as I thought upon my first reading, "Google's mobile device software package, "Google Now", accounts for 25% of all Internet traffic in North America." That made me do a spit-take.

Comment Re:Differential equations is not advanced math. (Score 1) 656

The irony here is that I found discrete math and data structures to be far, far easier than many of my other math classes.

On the other hand, I'd already had an introduction to topics like predicate calculus. I had the feeling sometimes that the comp sci professor teaching my discrete math course didn't understand the topic much better than I did.

Comment Re:Reciprocity. (Score 1) 272

They do actually address this in a couple of episodes. Part of the explanation of the retrograde technology on board the Galactica is that the Cylons were just so much better at cyberwarfare that the colonists essentially ceded that field - all computer systems were isolated so that even should one be compromised, it could not be used to stage attacks on other systems. There was a good deal of hocus-pocus involved, but at least there was an effort to explain it.

Comment Warning: snark. (Score 1) 931

I'm sorry, my inner snarky atheist is about to chime in. Please ignore the rest of my comment if you're not in the mood.

Ahem:

In the study, published in the current issue of Journal of Affective Disorders, researchers comment that people with a moderate to high level of belief in a higher power do significantly better in short-term psychiatric treatment than those without.

...researches also identified a notable exception to this phenomenon. Certain types of psychotic disorders, notably delusional disorders concerning the existence of supernatural entities, were strongly associated with belief in god.

Slashdot Top Deals

He has not acquired a fortune; the fortune has acquired him. -- Bion

Working...