• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 12:31
CEST 18:31
KST 01:31
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL19] Finals Recap: Standing Tall9HomeStory Cup 27 - Info & Preview18Classic wins Code S Season 2 (2025)16Code S RO4 & Finals Preview: herO, Rogue, Classic, GuMiho0TL Team Map Contest #5: Presented by Monster Energy6
Community News
Weekly Cups (June 30 - July 6): Classic Doubles2[BSL20] Non-Korean Championship 4x BSL + 4x China8Flash Announces Hiatus From ASL66Weekly Cups (June 23-29): Reynor in world title form?14FEL Cracov 2025 (July 27) - $8000 live event22
StarCraft 2
General
The SCII GOAT: A statistical Evaluation The GOAT ranking of GOAT rankings Weekly Cups (June 23-29): Reynor in world title form? Weekly Cups (June 30 - July 6): Classic Doubles Program: SC2 / XSplit / OBS Scene Switcher
Tourneys
RSL: Revival, a new crowdfunded tournament series FEL Cracov 2025 (July 27) - $8000 live event Sparkling Tuna Cup - Weekly Open Tournament WardiTV Mondays Korean Starcraft League Week 77
Strategy
How did i lose this ZvP, whats the proper response Simple Questions Simple Answers
Custom Maps
[UMS] Zillion Zerglings
External Content
Mutation # 481 Fear and Lava Mutation # 480 Moths to the Flame Mutation # 479 Worn Out Welcome Mutation # 478 Instant Karma
Brood War
General
Flash Announces Hiatus From ASL SC uni coach streams logging into betting site BW General Discussion BGH Auto Balance -> http://bghmmr.eu/ ASL20 Preliminary Maps
Tourneys
[BSL20] Grand Finals - Sunday 20:00 CET CSL Xiamen International Invitational [BSL20] Non-Korean Championship 4x BSL + 4x China The Casual Games of the Week Thread
Strategy
Simple Questions, Simple Answers I am doing this better than progamers do.
Other Games
General Games
Nintendo Switch Thread Stormgate/Frost Giant Megathread Path of Exile What do you want from future RTS games? Beyond All Reason
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread Vanilla Mini Mafia
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread Stop Killing Games - European Citizens Initiative Summer Games Done Quick 2024! Summer Games Done Quick 2025!
Fan Clubs
SKT1 Classic Fan Club! Maru Fan Club
Media & Entertainment
Anime Discussion Thread [Manga] One Piece [\m/] Heavy Metal Thread
Sports
Formula 1 Discussion 2024 - 2025 Football Thread NBA General Discussion TeamLiquid Health and Fitness Initiative For 2023 NHL Playoffs 2024
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List
Blogs
Culture Clash in Video Games…
TrAiDoS
from making sc maps to makin…
Husyelt
Blog #2
tankgirl
StarCraft improvement
iopq
Trip to the Zoo
micronesia
Customize Sidebar...

Website Feedback

Closed Threads



Active: 633 users

The Big Programming Thread - Page 1013

Forum Index > General Forum
Post a Reply
Prev 1 1011 1012 1013 1014 1015 1031 Next
Thread Rules
1. This is not a "do my homework for me" thread. If you have specific questions, ask, but don't post an assignment or homework problem and expect an exact solution.
2. No recruiting for your cockamamie projects (you won't replace facebook with 3 dudes you found on the internet and $20)
3. If you can't articulate why a language is bad, don't start slinging shit about it. Just remember that nothing is worse than making CSS IE6 compatible.
4. Use [code] tags to format code blocks.
Silvanel
Profile Blog Joined March 2003
Poland4725 Posts
Last Edited: 2019-11-27 21:01:08
November 27 2019 20:11 GMT
#20241
So i want the adress security topic i raised before. I want to deploy my website soon and I:
1. Decided to use one of the website hosting services like Heroku which should make it more secure (i think) than running my own server.
2. I have written my site in Django and have read and followed (to the degree i can understand them) the advices and best practices recomended by Django documentation (CSRF, XSS, SQL Injection, Hostheader validation, HTTPS)
3. I am making sure nothing valuable is stored in database and i will also ask users (which will be the people i know personally to only use passwords that wont compromise anything of value in any case)
4. I am requiring login to view my website and new users start as inactive (will require manual activation to login and see anything beyond home page).
5. I am following django deploy checklist

Also on the topic of protecting user credentials by not storing them as plain text doesnt Dajngo do that as default? I was under the impression it does.

Any comments/advices ???
Pathetic Greta hater.
Manit0u
Profile Blog Joined August 2004
Poland17243 Posts
November 28 2019 03:02 GMT
#20242
What encryption algorithm are you using to hash the passwords?
Time is precious. Waste it wisely.
tofucake
Profile Blog Joined October 2009
Hyrule19031 Posts
November 28 2019 04:03 GMT
#20243
I really hope it's argon2 and not SHA1 or something else like that....

If you're really into keeping things secure you can require mf2/2fa (whatever you want to call it) and disable things like security questions.

Heroku isn't inherently more secure, it's just a different way of hosting a website. If your application is insecure, it doesn't matter what your host is. PaaS like Heroku or AWS are more "secure" in terms of mitigating downtime and DDoS, but they won't do anything if there's a massive hole in your actual code somewhere. If you configure the firewalls/access rules properly, those types of hosts do mitigate some attacks, but not many.

If you want a truly secure server, you want to set up one which can only be accessed on 80 as a redirect to 443, and then configure a jump/bastion server for direct access. This is probably overkill for a non-commercial endeavor.

+ Show Spoiler [actually useless information] +
If you want an absolutely secure server you need to unplug it from the internet and require your users to go to the physical server to do anything, with you personally checking security and verifying identity prior to access.
Liquipediaasante sana squash banana
Silvanel
Profile Blog Joined March 2003
Poland4725 Posts
November 28 2019 07:24 GMT
#20244
Even the last solution (in spoiler) isnt 100% secure because You know people, a friend of mine from military told me how their secure cut-off from interent server was compromised by human stupidity and laziness. So no, i am not looking for total security just a reasonable one for hobby related low traffic site.
Pathetic Greta hater.
mahrgell
Profile Blog Joined December 2009
Germany3943 Posts
November 28 2019 07:47 GMT
#20245
On November 28 2019 16:24 Silvanel wrote:
Even the last solution (in spoiler) isnt 100% secure because You know people, a friend of mine from military told me how their secure cut-off from interent server was compromised by human stupidity and laziness. So no, i am not looking for total security just a reasonable one for hobby related low traffic site.


Reminds me of the story earlier this year where the plugged off computer system of a Ukrainian nuclear power plant had been connected to the net by employees to mine crypto currency...

https://www.zdnet.com/article/employees-connect-nuclear-plant-to-the-internet-so-they-can-mine-cryptocurrency/
broodmann
Profile Joined December 2011
604 Posts
November 28 2019 12:09 GMT
#20246
On November 28 2019 05:11 Silvanel wrote:
So i want the adress security topic i raised before. I want to deploy my website soon and I:
1. Decided to use one of the website hosting services like Heroku which should make it more secure (i think) than running my own server.
2. I have written my site in Django and have read and followed (to the degree i can understand them) the advices and best practices recomended by Django documentation (CSRF, XSS, SQL Injection, Hostheader validation, HTTPS)
3. I am making sure nothing valuable is stored in database and i will also ask users (which will be the people i know personally to only use passwords that wont compromise anything of value in any case)
4. I am requiring login to view my website and new users start as inactive (will require manual activation to login and see anything beyond home page).
5. I am following django deploy checklist

Also on the topic of protecting user credentials by not storing them as plain text doesnt Dajngo do that as default? I was under the impression it does.

Any comments/advices ???


Just hash+salt the passwords and then it should be fine. Heroku is a good option in many cases, add your enviornment-varibles in the heroku interface. I would use a secure/http-only/JWT cookie for authentication with a time-limit of something like 1 hour if you want to be super secure. If you want to go even further, something like Okta would be good.
Manit0u
Profile Blog Joined August 2004
Poland17243 Posts
Last Edited: 2019-11-28 18:58:07
November 28 2019 18:56 GMT
#20247
Geez, people. It's a hobby project for himself and a couple friends. Okta and such are overkill. Super secure stuff is also overkill (I totally hate credentials that expire too soon).

You'll be fine with basic stuff provided by Django (PBKDF2) but it's extremely easy to switch to something like bcrypt or Argon2 since Django has support for other algorithms out of the box but they require 3rd party libraries to be installed.

Just read this and adjust accordingly: https://docs.djangoproject.com/en/2.2/topics/auth/passwords/
Time is precious. Waste it wisely.
Silvanel
Profile Blog Joined March 2003
Poland4725 Posts
November 28 2019 20:06 GMT
#20248
Thanks for sugestions, i did switch to Argon2. I deploeyed my site--> its up and running. I run into some problems not present on testserver but that is expected i guess. I fixed some, need to fix some more. But that will have to wait. No its time to rest. Yay! I did it
Pathetic Greta hater.
tofucake
Profile Blog Joined October 2009
Hyrule19031 Posts
November 29 2019 05:03 GMT
#20249
The test server should be identical to prod so that you can catch errors before they happen. Sounds like you have something misconfigured
Liquipediaasante sana squash banana
Yurie
Profile Blog Joined August 2010
11806 Posts
November 29 2019 06:49 GMT
#20250
On November 29 2019 14:03 tofucake wrote:
The test server should be identical to prod so that you can catch errors before they happen. Sounds like you have something misconfigured


If you have something with high uptime demands you probably want a development server as well as a test server. Test server being used for acceptance tests while dev has the latest code you are working on for future changes.
Silvanel
Profile Blog Joined March 2003
Poland4725 Posts
November 29 2019 08:07 GMT
#20251
It should be identical be it isnt I had a problem with one security setting which run smoothly on localhost but started giving problems on production so i had to made changes on the fly. Anyway its something resembling closed beta right now so i will be fixing errors and stuff.

Thanks everyone for Your input.
Pathetic Greta hater.
tofucake
Profile Blog Joined October 2009
Hyrule19031 Posts
November 29 2019 16:40 GMT
#20252
Test is also sometimes called pre-prod. It should live in the same world as prod with the same configurations. Only dev should be local, and even then it should be running on the same containers or a VM configured the same as prod. Developing like this will reduce errors based on environment, and you can spin down test and dev when they aren't needed. It's a good habit to get into.
Liquipediaasante sana squash banana
Blitzkrieg0
Profile Blog Joined August 2010
United States13132 Posts
November 29 2019 16:56 GMT
#20253
On November 29 2019 17:07 Silvanel wrote:
It should be identical be it isnt I had a problem with one security setting which run smoothly on localhost but started giving problems on production so i had to made changes on the fly. Anyway its something resembling closed beta right now so i will be fixing errors and stuff.

Thanks everyone for Your input.


If the configurations are specific to that environment then it makes sense to do it directly. For bugs you can reproduce on your dev environment, you should fix them and then deploy them to your prod server. This makes it easier to document what went wrong and how it was fixed so that if it happens again in the future you have a record of it.

QA best name for your test or pre-prod environment.
I'll always be your shadow and veil your eyes from states of ain soph aur.
Manit0u
Profile Blog Joined August 2004
Poland17243 Posts
Last Edited: 2019-12-04 13:53:20
December 04 2019 13:52 GMT
#20254
I was amazed at how many of those I got wrong...

https://pixelastic.github.io/pokemonorbigdata/
Time is precious. Waste it wisely.
Excludos
Profile Blog Joined April 2010
Norway8053 Posts
December 04 2019 14:31 GMT
#20255
On December 04 2019 22:52 Manit0u wrote:
I was amazed at how many of those I got wrong...

https://pixelastic.github.io/pokemonorbigdata/


Omg I only got 52% right.. The shame overwhelms me
Silvanel
Profile Blog Joined March 2003
Poland4725 Posts
Last Edited: 2019-12-04 16:52:37
December 04 2019 16:50 GMT
#20256
I got 56% which is good i guess condering i never played pokemon or have anything to do with BigData, Anyway i used strategy "Noone would name pokemon like that" since pretty early i realized there are no rules to BigData naming, while some names obviously were too bad to be pokemon.
Pathetic Greta hater.
Excludos
Profile Blog Joined April 2010
Norway8053 Posts
December 04 2019 17:12 GMT
#20257
On December 05 2019 01:50 Silvanel wrote:
I got 56% which is good i guess condering i never played pokemon or have anything to do with BigData, Anyway i used strategy "Noone would name pokemon like that" since pretty early i realized there are no rules to BigData naming, while some names obviously were too bad to be pokemon.


That's just the thing, there's always a Pokemon named "that". I mean someone named a Pokemon Spoink. Not to mention they're about to introduce a literal apple as a Pokemon named "Applin". All bets are off.
enigmaticcam
Profile Blog Joined October 2010
United States280 Posts
December 04 2019 18:28 GMT
#20258
96%, only because I know my pokemon :D
emperorchampion
Profile Blog Joined December 2008
Canada9496 Posts
December 04 2019 21:08 GMT
#20259
67%
TRUEESPORTS || your days as a respected member of team liquid are over
zatic
Profile Blog Joined September 2007
Zurich15325 Posts
December 05 2019 08:27 GMT
#20260
I feel like a first year programmer ... Was stuck for almost 2 days because I had a whitespace trailing a URL I had to compute a hash on. Spent two days trying to find the error in my implementation of building the string to hash or the hashing function because the resulting hashes just would not match. And of course the software I am working with only has a console for debugging where I just couldn't see the stupid whitespace at the end of the URL.
ModeratorI know Teamliquid is known as a massive building
Prev 1 1011 1012 1013 1014 1015 1031 Next
Please log in or register to reply.
Live Events Refresh
RotterdaM Event
16:00
Rotti Stream Rumble 4k Edition
RotterdaM443
Liquipedia
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
mouzHeroMarine 762
RotterdaM 443
Hui .357
MaxPax 334
StarCraft: Brood War
Bisu 1941
EffOrt 1308
Flash 1304
Jaedong 1180
Hyuk 821
Stork 371
actioN 369
Soulkey 276
Soma 275
Snow 187
[ Show more ]
firebathero 175
Mind 98
JulyZerg 71
TY 69
sSak 64
Barracks 57
Sharp 50
JYJ46
Terrorterran 45
PianO 43
Rock 31
HiyA 21
Aegong 20
soO 16
yabsab 15
GoRush 11
Shine 8
IntoTheRainbow 7
Dota 2
Gorgc6615
qojqva3321
League of Legends
singsing2289
Dendi1253
Counter-Strike
fl0m1143
markeloff176
Super Smash Bros
Mew2King204
Other Games
hiko1544
Beastyqt844
ceh9366
Lowko307
crisheroes263
ArmadaUGS149
KnowMe140
Trikslyr62
Organizations
Other Games
gamesdonequick47269
StarCraft 2
angryscii 21
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 16 non-featured ]
StarCraft 2
• Reevou 7
• intothetv
• AfreecaTV YouTube
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• Michael_bg 2
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
League of Legends
• Nemesis6915
• TFBlade833
• Jankos802
Other Games
• Shiphtur316
Upcoming Events
Replay Cast
7h 30m
Sparkling Tuna Cup
17h 30m
WardiTV European League
23h 30m
MaNa vs sebesdes
Mixu vs Fjant
ByuN vs HeRoMaRinE
ShoWTimE vs goblin
Gerald vs Babymarine
Krystianer vs YoungYakov
PiGosaur Monday
1d 7h
The PondCast
1d 17h
WardiTV European League
1d 19h
Jumy vs NightPhoenix
Percival vs Nicoract
ArT vs HiGhDrA
MaxPax vs Harstem
Scarlett vs Shameless
SKillous vs uThermal
uThermal 2v2 Circuit
1d 23h
Replay Cast
2 days
RSL Revival
2 days
ByuN vs SHIN
Clem vs Reynor
Replay Cast
3 days
[ Show More ]
RSL Revival
3 days
Classic vs Cure
FEL
3 days
RSL Revival
4 days
FEL
4 days
FEL
4 days
BSL20 Non-Korean Champi…
5 days
Bonyth vs QiaoGege
Dewalt vs Fengzi
Hawk vs Zhanhun
Sziky vs Mihu
Mihu vs QiaoGege
Zhanhun vs Sziky
Fengzi vs Hawk
Sparkling Tuna Cup
5 days
RSL Revival
5 days
FEL
5 days
BSL20 Non-Korean Champi…
6 days
Bonyth vs Dewalt
QiaoGege vs Dewalt
Hawk vs Bonyth
Sziky vs Fengzi
Mihu vs Zhanhun
QiaoGege vs Zhanhun
Fengzi vs Mihu
Liquipedia Results

Completed

BSL Season 20
HSC XXVII
Heroes 10 EU

Ongoing

JPL Season 2
BSL 2v2 Season 3
Acropolis #3
KCM Race Survival 2025 Season 2
CSL 17: 2025 SUMMER
Copa Latinoamericana 4
Jiahua Invitational
Championship of Russia 2025
RSL Revival: Season 1
Murky Cup #2
BLAST.tv Austin Major 2025
ESL Impact League Season 7
IEM Dallas 2025
PGL Astana 2025
Asian Champions League '25
BLAST Rivals Spring 2025
MESA Nomadic Masters
CCT Season 2 Global Finals
IEM Melbourne 2025

Upcoming

2025 ACS Season 2: Qualifier
CSLPRO Last Chance 2025
CSL Xiamen Invitational
2025 ACS Season 2
CSLPRO Chat StarLAN 3
K-Championship
uThermal 2v2 Main Event
SEL Season 2 Championship
FEL Cracov 2025
Esports World Cup 2025
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
FISSURE Playground #1
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.