* Posts by Steve Holdoway

9 publicly visible posts • joined 29 Jun 2007

Hide the keyboard – it's the only way to keep this software running

Steve Holdoway

Back in the day DEC support suggested that the cause of random shutdowns could be alpha particles released when opening brown cardboard boxes.

Well at least they brightened our day.

Fancy trying the granddaddy of Windows NT for free? Now's your chance

Steve Holdoway

Happy days!

Except for the sys$qiow calls from C.

Gold-7 exit

Tearoff of Nottingham: University to lose chunk of IT dept to outsourcing

Steve Holdoway

Re: Seriously....

No... CCC is Cripps Computing Centre not Cloud Cloud Cloud..

Customer satisfaction is our highest priority… OK, maybe second-highest… or third...

Steve Holdoway

Re: Close 'em down...

Shut her down Clancy she's pumpin mud. From HP's of the 1980's... HPE I think.

Your WordPress and Drupal installs are probably obsolete

Steve Holdoway

Re: Challenge to keep up to date

Re wordfence... stores loads of stuff in the database. Only way to clear down is to set the option and disable/enable it. The alternative is to wonder why your site runs like a dog...

Manic malware Mayhem spreads through Linux, FreeBSD web servers

Steve Holdoway

Hmmm...

Every CMS known to man requires a space writeable by the web server / server side scripts. As such, owning all files by another user will only protect *part* of your docroot, and as such all you're really providing is 'security through obscurity'. If you're not using a CMS, then you can further lock down your docroot by making files ( and directories! ) immutable, which is as far as possible a completely secure solution.

Some cron jobs *must* run as the damon user. A specific example: Magento re-index creates a lock file for each index as it works on it, which ends up owned by the user running the process ( assuming they had permission to overwrite it in the first place ). This will prohibit the interactive run of a reindex from the CMS backend as the file can't be recreated by the daemon ( yes there's a million and one ways around this, but I'm making a point! ).

Chroot jails are also provably insecure... if you're this bothered about security, then you need to separate via VMs, or the new lightweight altrnative, docker, which I'm desperately trying to find time to investigate further. All other alternatives lull you into a false sense of security to some level.

I agree 100% on the chmod 777 thing though, anyone who writes this has no concept of *nix file permissions. Any software install instructions containing this requirement prompts me to delete it immediately, and be very circumspect on any other software from the same author.

Fifty, fired and fretful: Three chaps stare down CAREER MORTALITY

Steve Holdoway

DIY

All you need Is a virtual presence. Website, computer and a decent Internet connection and you're away. No more commute, work your own hours... Well, it's not that simple, but it's an alternative to throw into the mix.

Nobody need know how old you are if you don't want them to.

Microsoft lets slip Visual Studio 2008

Steve Holdoway

my link is so unreliable that...

I'm using

wget -c http://go.microsoft.com/fwlink/?LinkId=104679

off linux to get it. Go figure!

Nokia restructuring from strength for mobile internet

Steve Holdoway

time warp?

He wants to do this by when: 2004???