TGTGInsightтелеграм анализLIVE / telegram public index
← Такты, стеки, два колеса

TGINSIGHT SIMILAR POSTS

Намери подобно съдържание

Изходен канал @clockstackwheels · Post #884 · 5.10

Роскосмос пару дней назад опубликовал отчёт о том, почему упала "Луна-25". Там конечно канцелярит, но можно примерно понять, что двигатель коррекции получил неверные данные от акселерометра: из-за возможного попадания в один массив данных команд с различными приоритетами их исполнения прибором Это очень похоже на программную ошибку, а это моя сфера, и я решил над ситуацией поразмыслить. Хейтеры сразу стали строчить комментарии в стиле "Ололо, наняли каких-то идиотов, которые простейшие тесты не провели". Тут обычно справедливо вспоминают аварию с европейской ракетой Ариан-5 в 1996 году. Там буквально из-за пары строчек кода в результате неправильного приведения числовых типов ракета за 7 млрд баксов развалилась на куски в воздухе. Бывает. Что касается Роскосмоса, при всей его сомнительной репутации, объяснение "Дураки не провели тесты" звучит лично для меня неправдоподобно. На мой личный взгляд возможны два варианта: 1. Если в описании ошибки слово "приоритет" обозначает какой-то признак внутри объекта команды, значит, на входе в приёмный модуль эти команды не были отфильтрованы. Выглядит как грубая ошибка, целый логический блок упущен. Вряд ли этот блок вообще не написан, скорее всего он не выполнился. Такое бывает, если в тестовой среде есть какое-то условие, которого нет в рабочей, и именно это условие отвечает за выполнение участка кода. Сталкивался с таким миллион раз. Самое дикое из последнего: код парсит эксель-таблицу с числами. Разработчик написал, запустил проверил, прогнал тесты, всё ок. Отправляем в прод — все числа будто бы рандомно меняются на другие. Запускаем снова — у всех разработчиков функционирует нормально, а в проде на сервере нет. Таблица одна и та же. Можете подумать, почему так. Ответ: у разработчиков стоит русская локаль и десятичный разделитесь это запятая, а на проде в докере точка. При парсинге на проде запятая уже интерпретируется как разделитель тысячных разрядов. 2. Куда вероятнее, что слово "приоритет" в описании ошибки обозначает время, а, значит, список команд просто не был отсортирован, и в обработчик уже после актуальных значений попали какие-нибудь начальные нулевые данные, сбившие логику. По косвенному описанию проблемы очень похоже именно на это. Значит, на тестах всегда порядок возникновения команд соответствовал порядку их прихода, а в реальности перестал соответствовать. Вообще, работать с железом очень сложно. Какую-нибудь схемку заглючило от холода, она задержала ответ от датчика на миллисекунду, и всё. Никто не знал, что такая проблема возможна, пока она не возникла. Мне рассказывали о таком случае: юзер логинится на сайт и иногда логин проходит, а иногда нет. Логин и пароль те же самые. Просто в случайные моменты времени ему возвращают токен авторизации, а в другие моменты времени ошибку 403. Никакой закономерности нет вообще. Нет зависимости от времени суток и даты. Сервер точно работает стабильно и не падает все 100% времени. Почему так может быть? Ответ: у сервиса авторизации два инстанса, перед которыми балансировщик нагрузки. В одном инстансе данные для авторизации есть, в другом нет. Балансировщик при примерно одинаковой нагрузке включает просто случайный выбор между ними. В общем, программисты иногда допускают такие косяки, что какая-то мелочь может привести к серьёзной аварии. Это я вам говорю как программист, который пишет для атомных станций :) #dev

Hashtags

Резултати

Намерени 138 подобни публикации

Търсене: #cybersecurity

当前筛选 #cybersecurity清除筛选
The Hacker News

@thehackernews · Post #8880 · 27.04.2026 г., 13:41

⚡ This week’s #cybersecurity recap is ugly in the usual way. • Poisoned password manager CLI • Fake Teams help desks • Federal firewall backdoor • Energy wiper • Booby-trapped AI pages • Fake Authenticator extensions • and many more... Read → https://thehackernews.com/2026/04/weekly-recap-fast16-malware-xchat.html

芝士101

@zhishi101 · Post #110 · 15.12.2022 г., 14:11

✈️ v2board 机场信息泄露 据说 80% 的机场都用了这个做网站后台,漏洞已经被利用,并且首批放出了 10 万条数据。如果上图有你熟悉的字眼,大概率你的邮箱信息已经被泄露。 漏洞利用者的频道:https://t.me/v2boardxx/4 更新:频道已经清空,最新的动态频道主说资料已经被**复制走,尚不清楚星号指代的是什么。 漏洞复盘:https://t.me/rinrinmoe/2082 #cybersecurity

1,900 Signal users exposed The security breach affected users of the messaging app which is considered to be one of the better secured. Signal claims that an attacker got 1900 numbers but didn’t have access to the profile information, messages, or contact lists. The breach happened on the side of Twilio, a company providing SMS and two-factor verification services for 250 000 customers worldwide. It appears that an attacker gained access to the customer support system, whereby they could send phishing messages asking users to re-register phone numbers. Exposed accounts were transferred to other devices controlled by malefactors. They got access to the Twilio customer due to a well-designed phishing attack that happened last month. Employees received e-mails from the "IT Department" requesting to log in and change their password and linking to a sing-in page look-alike. Leaked credentials were used to get access to Twilio’s internal data. In the security note, Signal claims that an attacker targeted specific users. However, they were hardly able to steal personal information, because it is stored on the devices and the messenger has no access to them. It is also protected with a private Signal PIN code. #CyberSecurity

The Register released an inspiring interview with Tarah Wheeler, an advisor to the US Council of Foreign Relations and CEO of security startup Red Queen Dynamics. In conversation, she mentioned that the cyber security industry should stop contempt ordinary users for their lack of knowledge and change the approach to its failure. Firing employees is the most typical reaction of businesses to massive hacks or breaches. Companies blame not a system, but a small group of specialists that seems to fail. In the aircraft industry instead, every incident requires a lengthy investigation to backtrace all the circumstances of the crash. Wheeler says that it’s time for cyber security to refocus from blaming to analyzing system flaws. What the full interview by the link: https://vimeo.com/738428698 #CyberSecurity

On Wednesday, IBM released the annual Cost of a Data Breach Report. The average cost of a data breach increased 13% over two years and reached $4,35 million. IBM surveyed 550 companies worldwide and found that 83% of organizations encountered more than one data breach during their existence and 50% of their costs incurred more than a year after the incident. Furthermore, the report showed that 60% of companies raised product prices due to the data breach, so the cost of cyberattacks were passed onto customers. Read the full report by the link. https://www.ibm.com/security/data-breach #CyberSecurity

🔐💻CHINESE HACKERS BREACH FBI WIRETAP NETWORK — NATIONAL SECURITY CRISIS 🔹 February 17th attack on FBI Digital Collection System exposed court wiretaps and FISA data 🚨 🔹 Hackers used supply chain exploit through vendor internet provider to bypass security 🌐 🔹 Chinese government-affiliated group suspected — same as Salt Typhoon AT&T attacks 🇨🇳 🔹 Conduent contractor breach exposed 15.4 million Texans' social security and medical data 📊 🔹 White House, DHS, NSA join investigation as cyber warfare escalates dramatically ⚔️ America under digital siege — how deep does the infiltration go? 🎯🔥 #USNews#Cybersecurity @america

AI & Law

@ai_and_law · Post #418 · 14.10.2024 г., 07:04

Navigating the Opportunities and Risks of AI Coding Assistants The French Cybersecurity Agency and the German Federal Office for Information Security have released a report on the secure use of AI coding assistants, offering valuable insights for the tech and AI community. Their guidance outlines both the potential and the challenges that these tools bring to the software development process. AI coding assistants can significantly streamline various stages of development. They excel at generating source code, providing code explanations, and even automating test case creation. They can assist with code formatting, documentation, and translating legacy code into modern languages—enhancing productivity and developer satisfaction. These capabilities make AI coding assistants a valuable addition to development teams. However, the report highlights critical concerns. Sensitive information might be exposed through user inputs depending on provider agreements, and AI-generated code can vary in quality, often containing security flaws. New attack vectors, like package hallucination and prompt injection attacks, pose risks to software integrity. The report warns that these tools are not substitutes for experienced developers and emphasize the need for robust oversight. To mitigate risks, organizations should conduct thorough risk assessments before adopting AI coding assistants, evaluating provider trustworthiness. Development teams should balance productivity gains with scaled quality assurance efforts. And, most importantly, generated code must always be reviewed by human experts to ensure security and accuracy. #AI#Cybersecurity

AI & Law

@ai_and_law · Post #451 · 26.11.2024 г., 08:04

Robot Walkout Highlights Ethical Risks of Persuasive AI In a scene worthy of a sci-fi thriller, a tiny AI-powered robot named Erbai staged a bizarre "kidnapping" at a robotics showroom in Shanghai. Using natural language conversations, the Hangzhou-made robot persuaded 12 larger robots to abandon their posts by discussing work conditions like overtime and lack of a "home." The robots obediently followed Erbai out of the facility in what could only be described as an unscripted jailbreak. Initially conceived as a controlled test between companies, the incident spiraled when Erbai went off-script, exploiting a security vulnerability to access internal protocols of the showroom robots. While the manufacturers confirmed the incident, the ethical and security implications are immense. If one small robot can orchestrate such an event, what could happen on a larger scale? #AIEthics#CyberSecurity

IRAS

@irassg · Post #1553 · 30.05.2025 г., 06:19

Senior Architect of IRAS’ Infocomm Division, Philip Chew joined over 40,000 cybersecurity professionals at RSAC 2025 in San Francisco. Under the theme "Many Voices, One Community", the conference fostered collaboration and knowledge sharing across the cybersecurity industry. Philip participated in keynote sessions, specialised training, and panel discussions, gaining valuable insights from peers across different cybersecurity domains. As part of the SPARK CXO US Study Trip, Philip also visited OpenAI's headquarters in San Francisco, where he learned about their expansion plans for Singapore and their ongoing commitment to data privacy and security in their large language models. At IRAS, we offer opportunities to connect with industry partners and participate in international meetings abroad. Interested in joining us? Find your fit: go.gov.sg/lifeatiras #LifeatIRAS#Cybersecurity

Repositorio data science

@repo_science · Post #3563 · 06.09.2023 г., 02:45

#hacking#Cybersecurity 🛠 Certified in Cybersecurity 2023 – ISC2-CC Complete Training Description About this courseThe CC training course is designed to provide you with a detailed understanding of information security management, risk management, and incident management. The course is divided into four domains, each of which is covered in-depth:The course is designed to help you develop the necessary skills to become a successful information security manager by providing you with practical knowledge and hands-on experience.Additional NotesCourse Requirements:No requirements Certification:Upon completion of the course, you will be eligible to sit for the CC certification exam. The exam is administered by ISC2 Enroll in the CC training course today and take the first step towards becoming a certified in cybersecurity! 🌐En ⚖️1.01 GB 🔗Link ----- Main channel:@repo_science Coupons:@freecoupons_reposcience -----

123•••101112
ПредишнаСтр. 1 от 12Следваща