Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
0x0
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
61.
▲
by
0x0
3y ago
> What? How does load on the system affect correctness? Seen this happen quite often with code that is not multi-thread safe, especially in languages like c# and java, such as using a static class property for data that should be request
62.
▲
by
0x0
3y ago
There's been plenty of flaws in the app sandbox, but without the ability to execute arbitrary code they are often much much more difficult to exploit since you won't be able to invoke the particular system call or function you wan
63.
▲
by
0x0
3y ago
Browsers that bring their own javascript engine will likely also need to support JIT in order to be able to compete with Safari on performace. Doing JIT on iOS requires a special entitlement grant from Apple in order to map memory pages as
64.
▲
by
0x0
3y ago
Answer: Don't use storyboards.
65.
▲
by
0x0
3y ago
I think you meant "in theory" instead of "in practice" :)
66.
▲
by
0x0
3y ago
Sure it does. I'm still dealing with the fallout of old projects built with old webpack which uses md4 (as a file name cache buster only!) which is gone in recent nodejs+openssl binaries.
67.
▲
by
0x0
3y ago
Yes but you could refuse to deliver whatever the sender is paying for. I mean you need to wait for 6 confirmations or whatever anyway before "approving" the payment transaction.
68.
▲
by
0x0
3y ago
One bitcoin is very much distinguishable from another bitcoin as they can be traced through transactions and wallets, with the outcome that some bitcoins might be rejected by recipients that are uncomfortable with certain source wallets or
69.
▲
by
0x0
3y ago
Pretty sure that's a different thing just to prevent tcp/ip connections to other devices on your local subnet after you have already joined a wifi.
70.
▲
by
0x0
3y ago
Sucks that it requires iCloud Keychain enabled, and also removing your appleid from any legacy macs and iphones. Wish they explained the reasons for this, because I'm having a hard time seeing one.
71.
▲
by
0x0
3y ago
The comment about code signing perhaps being a blocked for third party sdk/library deduplication doesn't seem to also consider the fairplay DRM on iOS apps. As far as I know, the code (.text) segment of all iOS app store binaries
72.
▲
Debian 12.3 image release delayed for data corruption
(lists.debian.org)
8 points
by
0x0
3y ago
|
0 comments
73.
▲
by
0x0
3y ago
I wouldn't be surprised if they in fact do have a list of serial numbers for all the mac, ios, tvos devices they have ever sold, linked with some corresponding device-unique public key data?
74.
▲
by
0x0
3y ago
The moment you have a contact from any other country than your own, you'll quickly learn that green = huge carrier fees and blue = free texting that even works on wifi with data roaming off. Quadruply so for group chats.
75.
▲
by
0x0
3y ago
Strange error, why does it say "illegal instruction at ffffffff" but then the dump shows CS:EIP as 71a3:000056e5? Shouldn't the EIP part be :ffffffff or what am I missing?
76.
▲
by
0x0
3y ago
They should have put labels in front of and after the string bytes, then most assemblers would evaluate "(labelafter - labelbefore)" to a constant integer giving the length as needed. No need for a runtime sub instruction either,
77.
▲
by
0x0
3y ago
It's because newer versions of rsync switched license to GPL3 (from GPL2), and apparently Apple is not touching that with a ten foot pole. It's also why the included bash is frozen in time (and probably why they switched to zsh as
78.
▲
Looney Tunables: Local Privilege Escalation in the glibc's ld.so (CVE-2023-4911)
(openwall.com)
4 points
by
0x0
3y ago
|
0 comments
79.
▲
by
0x0
3y ago
At least running an .exe should be somewhat obvious to computer literate people. When I saw those signed applet dialog prompts, even as a developer it was not obvious to me that it also meant granting unsandboxed x86 code execution to a .dl
80.
▲
by
0x0
3y ago
Wild. So any other website could then do the same thing as you, accessing the hardware key and all...? Did anyone stop to think maybe this wouldn't be the best way to expose a hardware key? I mean, if you care about security at all, wh
81.
▲
by
0x0
3y ago
According to wikipedia, bitly started in 2008 and was in fact twitter's default url shortener in 2009, at which point Gaddafi was very much still in charge.
82.
▲
by
0x0
3y ago
I mean I'm sure there were a million exploits that would bypass even the check and prompt, but that doesn't change the fact that it's pretty crazy that native code execution was part of the design with just one small incompre
83.
▲
by
0x0
3y ago
Was it even an exploit? I seem to recall reading something about code-signed applets being allowed to load native dlls by design. Which is crazy, one single "trust signature" dialog prompt from infecting a system with malware...
84.
▲
by
0x0
3y ago
macOS 10.15.6 had a showstopper kernel zpool memory leak if you used virtualization software to run windows VMs, requiring multiple reboots per day in order to stay in place. It was an absolute dealbreaker for productivity as a developer wh
85.
▲
by
0x0
3y ago
Care to elaborate?
86.
▲
by
0x0
3y ago
I think the most interesting thing about this post is the pointer to https://rome.baulab.info/ which talks about surgically editing an LLM. Without knowing much about LLMs except that they consist of gigabytes of "weig
87.
▲
by
0x0
3y ago
I ended up having to pay(!) to re-enable middle clicking after magicprefs stopped working at some point in the macos upgrade race. I bought this. https://middleclick.app/
88.
▲
by
0x0
3y ago
You can have includeIf sections in your .gitconfig that applies only to things within a certain directory. So you if you create top level directories in your $HOME for your various identities, all you need to do is to make sure you are clon
89.
▲
by
0x0
3y ago
But it's not a random pseudo-reseller? The one github comment from "the founder of Quantum CA" seems to say they are also the creator of HiCA, which is the entity that was exploiting the 0day in acme.sh. And the crt.sh link s
90.
▲
by
0x0
3y ago
I find it troubling that a root CA (ssl.com) is apparently OK with lending their name in a business relationship with an actor that is actively exploiting an acme.sh 0day.
More ›