Basic shell and command line tool use? Yes you can get those, if you stick to using those tools and not the GUI.
Working with the operating system and/or administration experience? Not as much, or will be OSX specific.
I work on a mac frequently and heavily use the shell. The generic things are easy and are the same on every system, you'll be able to pick them up anywhere. There are things that you won't be as exposed to on the mac that you would be on a different nix, as well as things that you could be exposed to, but probably wont unless you go digging.
with the permissions of that account was able to arbitrarily assign himself a large number of Bitcoins
Why the hell would any admin, let alone a former admin, have privileges to do that in a production system? (other than the unavoidable database admin account)
So its a bit unclear as to how, but it sounds like admins could create records of deposited money with no backing. Thats terrifying. I would understand if the privileges of that account exposed a yet-unseen sqli vulnerability, but that's not the way it reads. It sounds like this was a possibility Gox gave to the account.
Adoption will be slow, right now its just a playground of possibilties, but I think a slow ramp up of the userbase is more likely than the suprising amount of nay saying I've seen. I remember when Facebook was that thing I was getting an account on just to take a look around even though I'd never actually use it because all my friends were on MySpace.
>the attention paid to LulzSec — a litter of script kiddies with kindergarten knowledge of the basest forms of technological harassment since 90s AOL proggies — is disgusting. And pathetic. And dangerous.
Many of the things I've read in criticism of lulzsec is that the writer always considers themselves better, somehow above the techniques employed below themselves. They're writing lulzsec off like some snooty bankrobber who prefers elaborate oceans eleven style heists so much that they find the mere idea of breaking into an unlocked bank at night distasteful. They seem to gloss over the fact that lulzsec got results. Enough doors were unlocked at night that they caused a good shitstorm.
If you want to use them as a springboard for discussion on responsible disclosure, fine. Were they immature? Of course. Want to analyze what the coverage means for the current state of journalism be it tech-specific or not, blog or real news outlet? Good, go do that. But what I am sick of seeing, is the "Oh yeah, well, I could do that if I wanted to, I just don't want to." attitude. Fuck you buddy. What did you do to stop those widespread vulnerabilities from being exploited? Oh, nothing? So you're just miffed that the culture and collective ego you bought into was shaken? You deserve it.
>I worry that rapidly improving the web's ability to deploy applications will make it less suitable for reading and writing.
Will make it? It already has. The web as we know it is a fucking unfettered mess. We've just been jamming applications into a document format so hard for so long we're used to it. You are right though, its going to get a lot worse.
We need a new platform. We're probably not going to get one, the "web" is just going to expand to engulf every bit of functionality a new platform would have, but bring along over two decades worth of evolutionary cruft. I've resolved to just stay out of the way, not fight the inevitable.
No, we have people like you to thank. Standing on the sidelines bitching about the bad things that will happen in reaction to lulzsec instead of even attempting to prevent the gov't from doing them.
Way to suck the fun out of it :) -- I know, I just think a bitcoin exchange is an interesting concept, the kind of thing I would enjoy knowing my code was running in and got a little caught up bikeshedding in my mind how I'd secure a target like that.
I'd be down for that, it sounds like a fun project in an interesting domain and I was actually thinking about what building one would entail as I've been reading though the comments here.
That doesn't help anything other than dropbox's efforts to obtain new customers because they would be ill informed about the track record of the service.
>There is no way dropbox would be able to explain to them what happened without scaring them silly.
Opposed to who? People who do know what it means and should be scared silly but aren't because they've been beaten into submission by breach after breach after breach.
Pubkey auth connecting to openssh on freebsd to hippa- pci- sox- and sas 70- compliant storage with a warrant canary and you can give them a call to talk to the engineers (I have). Looking back dropbox feels like a fly by night in comparison.
I know. I didn't bring that up to accuse them of malice as far the DMCA part, I brought that up as an example that dropbox employees don't understand what their own internal tools do.
Last time the Dropbox security thing was in the news, regardless of your personal preference on what encryption keys dropbox should have been using, the issue and more importantly the way they handled it made me question their abilities. Then they sent a DMCA takedown notification notification to someone they were just trying to censor, and now they temporarily set their auth method to "allow any password".
They are showing us that they are technologically incompetent at managing their own systems. I don't know why anyone continues to do buisness with them for files they want any sort of privacy over.
I've moved to rsync.net. Its uglier, but at least they know what the fuck they're doing.