Forgot your password?
typodupeerror

Comment Dude if they can barely come up with 200 mil (Score 5, Insightful) 79

To get out from under the SEC regulations then they are going to be buying a presidential election for anyone. Elon Musk dropped a quarter billion just on Trump's last election and he's going to spend the same amount of money getting the Republicans the midterms. Maybe some more.

Years ago I saw an interview with a multi-millionaire woman who was complaining that she couldn't get the time of day from congressman anymore because the billionaires could outspend her. That's the level we're at.

It's not just that you and I don't matter. If you've only got a few hundred million to spend that's not enough anymore to buy an election. That's how much money and power we have given the billionaires. Or should I save the trillionaires...

Comment Re: Nothing of value was added (Score 0) 148

This is only really a useful observation if you can tell me ahead of time which developers are competent and which ones are incompetent.

If you are hiring a developer your chances of finding one who is not incompetent is vanishingly small. The correct approach is to train them to be competent, and set standards. This should begin with requiring the bug tracker to be emptied out (or decreasing bug count, if the total number is currently overwhelmingly large), and there are plenty of online and in-person resources for training developers to learn how to write secure code.

and use tools like memory-safe languages to mitigate that risk.

Security vulnerabilities happen in every language. Anyone who thinks the language will make them safe is an idiot. What I mean is, you are an idiot, cmseagle 1195671.

Comment Re: Nothing of value was added (Score 4, Insightful) 148

The problem as I see it is coming up with good standards. We do have standards in some places, for example, SOX requires changing passwords every three months as best practices. But that is probably not actually best practice, so the wrong thing was codified.

How do we get the right things codified is the question.

Comment Re: We are going so fast we need to slow down! (Score 1) 118

** - It seems dubious that Truman really understood what he was signing onto.

My take was that he could have stopped it if he wanted to, but the bureaucratic machine was already in motion, and he would have had to put some effort into stopping it. I'm glad we didn't bomb Kyoto but maybe Xi will.

Comment Re: Nothing of value was added (Score 4, Insightful) 148

Yes of course when there is a skill and no standards of training, some people are bad at it

This. Most companies don't follow best practices when it comes to good code (for example, they have a bug tracker that is always growing, never empty). They don't try to write secure code, they don't have trainings in secure code, they don't penalize insecure code (although they should in a lot of cases). That is why most corporate programmers can't write secure code.

Comment Re: Nothing of value was added (Score 2, Insightful) 148

History shows that developers cannot write safe code

History shows that incompetent developers cannot write safe code. There are examples of programmers writing safe code.

People who make excuses for unsafe code are usually crappy developers, and that is what I think of you. You're a crappy developer if you can code at all.

Comment Re: Nothing of value was added (Score 3, Insightful) 148

I think Ubuntu (and other's desire) to remove coreutils is precisely because coreutils is old, brittle and written in an unsafe language.

They aren't brittle. I've looked at them. The code is fine, but it uses an older style that is annoying to newbies.

If I were going to rewrite something in Rust, I would look at Firefox, not Coreutils which I would consider a waste of time.

Slashdot Top Deals

If the code and the comments disagree, then both are probably wrong. -- Norm Schryer

Working...