Computer
Google Will Let Friends Help You Recover an Account
Read more of this story at Slashdot.
Reddit Cofounder Says 'Much of the Internet is Now Dead'
Read more of this story at Slashdot.
US Falls Out of Top 10 on List of the World's Most Powerful Passports
Read more of this story at Slashdot.
Government Told To Prepare For 2C Warming By 2050
Read more of this story at Slashdot.
Almost 70% of US Adults Would Be Deemed Obese Based on New Definition, Study Finds
Read more of this story at Slashdot.
The Numbers Six and Seven Are Making Life Hell for Math Teachers
Read more of this story at Slashdot.
New MacBook Pro Does Not Include a Charger in the Box in Europe
Read more of this story at Slashdot.
Nearly 40% of Kids Under 2 Years Old Interact With Smartphones, According To Their Parents
Read more of this story at Slashdot.
Japan Asks OpenAI To Stop Sora 2 From Infringing on 'Irreplaceable Treasures' Anime and Manga
Read more of this story at Slashdot.
Apple's Tim Cook Promises To Boost China Investment
Read more of this story at Slashdot.
Apple's New MacBook Pro Delivers 24-Hour Battery Life and Faster AI Processing
Read more of this story at Slashdot.
US News Outlets Refuse To Sign New Pentagon Rules To Report Only Official Information
Read more of this story at Slashdot.
FSF Announces the LibrePhone Project
Read more of this story at Slashdot.
Common Yeast Can Survive Martian Conditions
Read more of this story at Slashdot.
A Refreshing Change
Dear Third-Party API Support,
You're probably wondering how and why your authorization server has been getting hammered every single day for more than 4 years. It was me. It was us—the company I work for, I mean. Let me explain.
I’m an Anonymous developer at Initech. We have this one mission-critical system which was placed in production by the developer who created it, and then abandoned. Due to its instability, it received frequent patches, but no developer ever claimed ownership. No one ever took on the task of fixing its numerous underlying design flaws.
About 6 months ago, I was put in charge of this thing and told to fix it. There was no way I could do it on my own; I begged management for help and got 2 more developers on board. After we'd released our first major rewrite and fix, there were still a few lingering issues that seemed unrelated to our code. So I began investigating the cause.
This system has 10+ microservices which are connected like meatballs buried deep within a bowl of spaghetti that completely obscures what those meatballs are even doing. Untangling this code has been a chore in and of itself. Within the 3 microservices dedicated to automated tasks, I found a lot of random functionality ... and then I found this!
See, our system extracts data from your API. It takes the refresh token, requests a new access token, and saves it to our database. Our refresh token to this system is only valid for 24 hours; as soon as we get access, we download the data. Before we download the data, we ensure we have a valid access token by refreshing it.
One of our microservice's pointless jobs was to refresh the access token every 5, 15, and 30 minutes for 22 of the 24 hours we had access to it. It was on a job timer, so it just kept going. Every single consent for that day kept getting refreshed, over and over.
Your auditing tools must not have revealed us as the culprit, otherwise we should've heard about this much sooner. You've probably wasted countless hours of your lives sifting through log files with a legion of angry managers breathing down your necks. I’m writing to let you know we killed the thing. You won’t get spammed again on our watch. May this bring you some closure.
Sincerely,
A Developer Who Still Cares
[Advertisement] Keep the plebs out of prod. Restrict NuGet feed privileges with ProGet. Learn more.'Save Our Signs' Preservation Project Launches Archive of 10,000 National Park Signs
Read more of this story at Slashdot.
DOJ Seizes $15 Billion In Bitcoin From Massive 'Pig Butchering' Scam Based In Cambodia
Read more of this story at Slashdot.
Secure Boot Bypass Risk Threatens Nearly 200,000 Linux Framework Laptops
Read more of this story at Slashdot.
NordVPN Embraces Open Source By Releasing Its Linux GUI On GitHub
Read more of this story at Slashdot.
Google Announces $15 Billion Investment In AI Hub In India
Read more of this story at Slashdot.