Hacker Newsnew | past | comments | ask | show | jobs | submit | bogomipblips's commentslogin

Just from looking right now, I'm a bit puzzled by being told right away that it has all open APIs in a warning in the install guide. Would I really want to tell someone to try starting something for our security that is an immediate attack vector?


if you leave the admin APIs unsecured in production it is an attack vector, not sure what you would prefer being told here?

It says "When deploying Ory open-source Servers, protect access to their APIs using Ory Oathkeeper or a comparable API Gateway."


Since docker/k8s I've started to encounter containers that just start with a default user and no password. The Cuckoo's Egg was published in 1989. Choose a random password if you don't have one and print it to the console.


Insiders know how to work a ponzi scheme without any provable evidence of collusion.


I've come to the realization recently that the moat terminology doesn't work for tech. A moat is the same in all senses but in tech you can design reverse moats for existing players. I.e. Data retention for past orders or operating at a loss something you'll be able to do cheaper later make new entrants instantly better.


This is why all big tech companies eventually move to regulatory capture as their moat.


Looking for book time, etc, ford doesn't seem likely to be as high complexity as similar large diesel.. I think the issue is similar to workstation repair vs PC repair.. 5 years learning this is instead of making a similar hourly rate on higher volumes of cars, risking that others are trying to close that gap too and wondering how long that skill as it is stays stably useful.


You are obviously someone who would appreciate pedantic style educators. The average customer is not at all appreciative of not being met where they are which tends to lead to an expert using AI as short for OpenAI, etc, with the customer unless they use a careful hedging..

Similarly if they participated in all the early arguments about where your models would be located then they have no idea now that they are fed up with the endless thread of subtle change requests.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: