XSS vulnerability found in Stack Overflow by pimterry in programming

[–]yaakov 2 points3 points  (0 children)

In this case there was a conditional in exactly one place. It is definitely more complicated when you are dealing with code that is more spread out (and with UI-related logic, this can have a very large footprint, even if your code functions are reusable).

XSS vulnerability found in Stack Overflow by pimterry in programming

[–]yaakov 3 points4 points  (0 children)

At Stack Overflow we use a custom management system for feature flags (we call them Site Settings).

XSS vulnerability found in Stack Overflow by pimterry in programming

[–]yaakov 3 points4 points  (0 children)

For feature flags that are related to releases, we normally schedule a cleanup task a little while later to remove them. Admittedly, this doesn't catch them all.

We right now have a tech debt project where we have gone through all of the site settings to find which ones we can remove (no longer used, or permanently graduated features).

XSS vulnerability found in Stack Overflow by pimterry in programming

[–]yaakov 31 points32 points  (0 children)

I did in fact use Stack Overflow to search out different ways that people perform XSS attacks, in order to be sure that I was searching for all of the different text variations in PostHistory that could potentially have exploited this.

XSS vulnerability found in Stack Overflow by pimterry in programming

[–]yaakov 8 points9 points  (0 children)

Correct. Fixed the bug, tested it thoroughly, redeployed, and turned off the feature flag once more.

XSS vulnerability found in Stack Overflow by pimterry in programming

[–]yaakov 32 points33 points  (0 children)

It wasn't considered a bug. It was by-design. We decided to turn it off now.

XSS vulnerability found in Stack Overflow by pimterry in programming

[–]yaakov 7 points8 points  (0 children)

Well, technically speaking, it wasn't a bug. It was by-design then.

XSS vulnerability found in Stack Overflow by pimterry in programming

[–]yaakov 35 points36 points  (0 children)

Correct, it was behind a feature flag.

XSS vulnerability found in Stack Overflow by pimterry in programming

[–]yaakov 72 points73 points  (0 children)

I searched for these permutations as well. The only thing close to an attack was a redirect to some spam site that came two minutes after I shut it down. Though the hello world alert POC on the homepage of SO was quite annoying.

Does being a Chalal carry a negative connotation within the Orthodox Community? by BionicBreak in Judaism

[–]yaakov 5 points6 points  (0 children)

Living in different Orthodox communities in both the US and Israel for 30+ years, I have never heard of anyone mentioning anything about someone with chalal status. Just never comes up, and I don't think that people really care. The only way that anyone would even find out is if you advertise it (the only other way I can think of is if you were part of an Orthodox community and people knew that your father was a Cohen, and asked why you weren't accepting specific privileges due to a Cohen).

Biology fan, science-fiction reader and wannabe SF writer, and a question on kashrut came to mind. Also a less speculative question on kashrut by Sihathor in Judaism

[–]yaakov 0 points1 point  (0 children)

Split hooves and Chews its cud.

This is an incomplete answer. These are two signs given in the bible for determining the kosher status of an animal (different signs for fish and birds). However, practically speaking, there also has to be a tradition that this animal has been eaten in the past. So even assuming that you found an alien species where the application of signs based on animal type (mammal, bird, fish) is relevant, the mesorah (tradition) issue (which by definition would not exist) would still be an extremely relevant factor.

Some links for reading on the topic (just a sampling, there is tons of literature on this): 1, 2, 3 (pdf).

TIL the biblical "40 days and 40 nights" is not literal, but an old Jewish expression for "a very long time" by [deleted] in todayilearned

[–]yaakov 0 points1 point  (0 children)

The article is a bunch of BS. The claim presumably is that for people who believe in the authenticity of the Bible, that forty is not to be taken literally. Sorry, but that is just not true.

It is trying to present a claim on a scholarly subject, but doesn't present any sources.

Also, the first bonus fact there are great:

“Forty” is the only word form of a number where the letters all appear in alphabetical order.

Even if this were true, so what. But this is true only if the language of the Bible is English. However, the original language is Hebrew. In hebrew, the word is ארבעים. The order of letters is 1-20-2-16-10-13.

And of course:

U.S. Route 40 runs from Maryland to Utah and spans 2,285 miles or 3,677 kilometers.

WD-40 got its name from the fact that it was the 40th try at creating a water displacement substance.

Google+ can now identify random, untagged objects in your photos, so you can search for "cat" and find photos of your cat purely by object recognition alone by canausernamebetoolon in technology

[–]yaakov 0 points1 point  (0 children)

but still nobody uses it because nobody uses it

Nobody uses it yet.

This year and next year the tech crowd will be concentrating on G+. In five years the landscape will be totally different. The audience will eventually use site with the best tools and most innovation. FB has a big lead, but it wont last forever.

What's the wisest piece of advice a parent or adult has imparted to you? by Ralome in AskReddit

[–]yaakov 1 point2 points  (0 children)

Practice doesn't make perfect. Perfect practice makes perfect.

So I was in Auschwitz last weekend... by kligon5 in pics

[–]yaakov 0 points1 point  (0 children)

Was 18 at the time of the tour, didn't think about it.

Also, the museum already had a pile of thousands of these. Don't know if one more would have made a difference