• 0 Posts
  • 26 Comments
Joined 1 year ago
cake
Cake day: June 27th, 2023

help-circle







  • Coming from the UK generation that grew up during the decimalisation process, and therefore being equally comfortable with both systems, imperial measures are far less intuitive than metric. Don’t mistake simply being being used to something as it being intuitive.

    We use a base 10 numeric system because that’s how many fingers & thumbs we have. Having a system of weights and measures based on that decimal system, is far more intuitive than a system that scales up through orders of distance using different scaling factors at ever order, is so unintuitive as to be absurd.


  • Is having a consistent domain language across the board important? Yes, obviously it’s a huge benefit in communication and in maintainability.

    Is not following that convention, in and of itself, a huge problem? Probably not, so long as the primary parties understand the differences between separate aspects (such as the database using a different word order), although the documentation needs to explain this.

    Is not being able to get an agreement on a consistent domain language that everyone will follow a problem for development? Yes. Huge. Crippling. It reeks of poor, indecisive management at the top project level, and petty interdepartmental squabbling all the way down. It’s a huge red flag as to a company’s ability to deliver. It’s not that difficult a thing to get agreement on or to enforce, as it’s entirely visible. If a project can’t do that, it’s not going to be able to do the things that are actually difficult.






  • But if they don’t know they have to knock “shave and a haircut” first, your job gets a lot easier and you’re dealing with a lot fewer nuisance password promptings.

    Very good explanation. And the benefits are even greater, because there is absolutely no response until the entire secret knock is correctly used, the random guy trying to get in doesn’t even know if there’s anyone at that address. (In fact, set up correctly, they won’t even know if there’s really a door there or not)


  • If you want to go down that path, a password is only security by obscurity.

    Port knocking is an extra layer of security, and one that can stop attackers from ever knowing your private server even exists. A random scanner won’t even see any open ports.

    Always bear in mind that any random guy advising people not to use port knocking may be doing it with malicious intent. I’m sure there’s someone out there advising that random passwords are a waste of time, and everyone should just use monkey123.