Don't log usernames for bad logins

This used to be widely understood around Unix, but it's evidentlyslipped from common knowledge over time:

It's a mistake to log nonexistent usernames on bad logins .

(Corollary: it is an especially bad mistake to log them by default.)

To illustrate why I say this, let me tell you what happened tome recently. I normally leave myself logged in to my officeworkstation with the screen locked and blanked. This weekend, my officeworkstation crashed and rebooted because of some ongoing issues ; as


是日金句090224

A:「你既寫作風格可以用兩隻字形容。」

B:「係咩呀?」

A:「頹廢。」

B:「... ... 」

********************************

A:「唔好咁灰啦。」

B:「真係好攰,仲好灰,灰過

Lady First 專欄 (33 - 34)

二月十四不是年三十


一年一度的情人節又快將來臨,你是否有一種死期到的感覺?特別是男人。

不能否認的是,許多女孩子都頗重視情人節的,早早準備好禮物,打算給男友驚喜,而禮物多是親手所造的,這才夠誠意嘛。

雖然,

A core principle of error and warning messages

Here is a core principle of how and when programs should show error andwarning messages of all sorts:

Error messages should only go to the people who can do somethingabout them.

This goes double for warning messages.

(Sometimes you don't have a choice, at least in theory; if your programsuffers a fatal error and you have nowhere else to log it, dumping it onthe user does some moderate amount of good. Maybe.)

There's two reasons to be careful where your error messages


無題

進入一個處境前需要準備意志。如果你有足夠的意志,你就可以履險如夷。反過來說,如果你能有足夠的迷幻,足夠自己發明所有甜美幻覺,同樣可以履險如夷。夢遊的人從不傷害自己。

人為什麼要進入那個幻境裡面,如果,他

非常準的測驗

https://w3.mecolor.com.tw/find.html

my type:
自覺紫色 + 潛質藍色 + 原生紫色
【困局型】
對於感情的渴望讓理性的頭腦陷入了困局之中。

希望自己美麗又具有智慧,能夠在人前展現優雅的自信。但是,受到同儕的影響,過於渴望豐

歌詩吧漫遊 GILI GULU 3





















Continue reading...

pHion 完全排毒綠粉的好處


打蛇


我之所以會看這電影,是因為某日聽收音機少爺占說看了此片很核突,然後無意中發現了DVD,於是就買來看。

這是一部我想像不到的核突電影,故事講80年三名非法入境者偷渡到香港時,被“打蛇集團”所捕,原來“打蛇”的

A problem with microtransactions

One corollary of Internet scale security is topoint out a lurking issue with microtransactions (one of the perennialInternet enthusiasms in some quarters). The problem is how you handleauthorizing microtransactions.

If you prompt the user every time they spend a cent, I think it's verylike that people will rapidly find this far too annoying and stop usingmicrotransactions at all. If you do not require the user to authorizetransactions you open yourself (and the user) up to attacks wherethe user's browser or other