Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

On the other side of the coin, all these things would make sysadmins absolutely loathe you.

- You have 20-30 specialized applications which aren't package based stored in an application share mounted at /app with the convention /app/name/version or something but then this tool hardcodes itself to /opt/name.

- Using nonstandard ports doesn't make you more secure against someone who's specifically targeting you, but it absolutely stops automated attacks and logspam. What do you mean you can't change the port?!?

- Because there's no such thing as a secure internal network. All sites go through the hardened proxy.

- Invest? Nobody is going to pay for certs for internal services and who wants to set up a reverse proxy If you can't use an internal CA that's just poor form.

- That's a new one for me. I assume because they have a single shared database for all of their apps.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: