I think the customer got hacked some other way, and the hacker just wrote to the .htaccess file AFTER hacking the site. Probably the .htaccess is a quick and easy way of taking over the website.
enjo is absolutely right. I regularly require inspiration in order to solve difficult problems. This inspiration generally never happens when sitting in front of a computer screen - most of my ideas come when I am walking, swimming, cycling, etc.
Certainly there are many dull development jobs that require no inspiration or even much thinking - I worked in many of them before I got bored to death and started my own business.
If you are in one of those dead-end jobs, you're not the kind of person that enjo is talking about.
Just checked my servers, and not infected (but neither even have libkeyutils, so I don't think I'm vulnerable to this).
After being burned in the past, I always install iptables and block incoming connections. Plus I only allow ssh access to certain ip addresses. This means that even in the worst case if a vulnerability lets a rootkit get installed, there isn't much they can do after that.
Speaking as someone who has actually been suicidal, it does seem pretty clear that he was depressed. From his blog posts it seems that he typically had a lot of stress-related health symptoms over the years, including depression. It seems that he simply tried to do too much, got burned out as a result, and couldn't/wouldn't talk about it to anyone. Not all depression fits nicely into the 'clinical depression' pigeonhole.
If you read Aaron's blog, you'll see he posted about his illnesses back in 2007. From his account, it sounds like he suffered from burnout/CFS (chronic fatigue syndrome). I would suspect that his 'flu' 2 weeks before his death might have been a CFS/burnout episode. Severe depression can be a symptom, and suicide is usually the end-result if you don't know what's happening.
I know this because I suffered from burnout and CFS myself, and had severe depression, and I did quite a bit of research to figure out what was happening.
The bottom line is that people like Aaron and myself who have a high capacity for working incredibly hard also tend to suffer from burnout which can lead to CFS and severe depression. The mistake Aaron made is that you CANNOT push through it. The other mistake he made was hiding it from other people.
My own solution is to have two different passwords for everything - one for banking and credit cards, another for crap like twitter/linkedin. I haven't changed my passwords for years (no point really, as you're likely to have the breaking as soon as they get your password).
I think there are risks with all solutions to the password problem.
Yes, I agree...it's just spam. I certainly would never respond to this spammy crap. In fact I now never respond to any company spamming me, because in general they tend to be evil in other ways and provide a crappy service. If I want something, I'll do my own research.
Who cares if the html is crufty as long as it works. I use table layouts quite often, and if you look at the source of stackoverflow they use tables too.
What I would like to see are a few functionality tweaks to make HN more useful. The main ones that come to mind are: increasing the timeout before you get an 'unknown or expired link' and optionally emailing you when someone replies to one of your comments.
Yes, I know - that is the whole point of the article. What I meant is that they don't generally have a free team version. It would be better perhaps to have a limited free version for everyone, and then charge educators if they want a more advanced version rather than giving them the crown jewels for free. Just my opinion based on selling a similar offering to this market for over 15 years.
Not sure this is such a good idea. I operate a similar business and most of our profit comes from educational customers. Universities have massive budgets and a few thousand dollars is peanuts to them. School boards also tend to have large budgets, although it tends to be cyclical.
I think the best option is to have a free, limited version and then offer more features for a price. I notice that lucidchart doesn't have any free version for teams.
My own experience is the same. Our facebook page has over 2000 likes, our twitter feed has about 360 followers, but we only have 19 people following us on google+ (even though we've been on there for a year, post all the same things on google+ and promote our g+ page as much if not more than the others).
On a personal note none of my friends uses google+ (only my wife). They pretty much all use facebook.
No, not exactly. Perhaps I didn't word it correctly. A crime has been committed using the user's internet connection, so in most civilized countries (i.e. places I would like to live in), that means the police have the legal and moral right to investigate that crime. Until proven otherwise, the 'tor' user is a suspect - watch a few episodes of CSI if you want to get a rough idea how it works.
It's up to the user to prove that the child porn isn't on his computer. As someone pointed out earlier, you could just download a bunch of child porn with a tor exit node running on your computer and say it was someone else.
The big difference is ISPs keep track of users' ip addresses and they give that information to the police when they get a warrant. tor doesn't keep that information, so basically the exit node is all that the police have. The trail stops at the person running the tor node. Likely the police won't find the actual perv here, but you can't blame them for trying.