Agree, when MS moved their office file formats to xml, I made plenty of money building extremely customizable templating engines all based on a very small amount of XSLT - it worked great given all the structure and metadata available in xml
Probably the only improvements I can think is running the runner as a gMSA and applying the relevant ACL's to that, so you can avoid needing to supply creds.
Otherwise, on our fleet of hundreds of IIS, we've had success just pointing IIS to a hardlink, deploying the new version to a new folder and updating the hardlink - from memory this does trigger an app pool restart but its super fast, lets you go back and forth very easily.
This is just to make it an IdP initiated flow (instead of a SP initiated flow) and its to prevent the extra hop back and forwards between Okta/IdP and the application.
Very well said - even with open source there seems to be a general lack of willingness to actually read code, let alone crack open the disassembler or attach a debugger - the skill is apparently not taught anymore
In AU, even for aerial powerlines, we run our own mix of fibre and radio comms between zone subs and stuff like ACR's... in fact I dont think any of the transmission or distribution operators utilise any telco stuff for their control networks
Yah, this is why third party risk management is a thing. When I ran sec training, I always hammered home the point that a third party security issue is your issue.
Now, sure, technically there may be circumstances when you can technically/legally shift liability. But your customers don't care - they have the relationship with you. So the third parties problems, are your problems.
Global namespace shared resources, regional namespace shared resources, then each app provisions its own bit, consuming/linking the two aforementioned layers.
Everyone gets here eventually and you can just fight over stuff like “is an alb shared regional or app specific”
bowling is fucken weird..I was a junior almost pro bowler and I know Belmo, being around the same age, coming up at the same time and in the same area as him…he’s a freak in the best sense of the word. I remember some other kids who would bowl with a bigger hook (and their thumbs) but Belmo was just super consistent…knew he would do great and very glad he has, despite all the haters
The amount of ideas that Karl had which came to reality, that Steve and Ricky dismissed as mental is what keeps me listening to Youtube compilations of their show to this very day :D
Yah, that's the OAuth Client Credentials flow but as noted, you still have a static set of creds that are required to generate the short lived access token. Besides being useful for being able to limit scope in some circumstances, the main point of the client cred flow is to appease eager sec arch's who insist on OAuth.
To answer the why plain text, the feature this talks about is the Okta Secure Web App - basically if an app cant do proper SSO you can set it up as SWA which just acts like a password manager. The Okta browser plugin will just fill out the login form of whatever site for you. One bonus feature with SWAs is the admin can set a password for all users, making it a cheap way to share an account transparently for all your users.
In the words of Raymond Chen this exploit is basically being on the other side of the air tight hatch
Heh your bit about Github resonates. I hire plenty of devs and the whole "make sure you have a GH body of work" has become such a meme that when people do include it on their CV, it's usually just a big list of forked repos with no contributions.
For me, Github/personal projects have not been a useful signal either way, but it is apparent in recentish years that the advice has been to have one regardless.
Don’t know your exact specs or the premium you pay over consumer level but I buy/install commercial display panels and when I need a new TV or such, I just grab one of them. No extra stuff, fast input switching etc etc