Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Foxboron
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
91.
▲
by
Foxboron
2y ago
BUS interposers are trivially defeated with encrypted sessions and a PIN. Bitlocker is traditionally the implementation susceptible for this attack, but for that I'll just defer to Chris Fenner. https://www.dlp.rip/tpm-
92.
▲
by
Foxboron
2y ago
A lot of Linux distributions has moved away from the dbus implementation that was merged into systemd to the `dbus-broker` project which has an optional dependency on systemd. So the answer is "yes", alternative projects exists.
93.
▲
TPM Performance:(
(stiankri.substack.com)
5 points
by
Foxboron
2y ago
|
0 comments
94.
▲
by
Foxboron
2y ago
Got served carbonated gammel dansk from this tap, and tortured by "När man festar festar man" on repeat for 6 days during Chaos Communication Camp. 10/10, no notes. Would do again.
95.
▲
by
Foxboron
2y ago
For fun, https://aur.archlinux.org is a single git repository with each package represented as their own namespace. An mirror for the `aur.git` repository can be found on Github. https://github.com/archlinux/
96.
▲
by
Foxboron
2y ago
Matthew was shitting on systemd and pulling no shots. Poettering calling Matthew a scriptkiddie is mild. He did call me a "facist weenie" with no clear reason why beyond me pushing back on their grand claims.
97.
▲
by
Foxboron
2y ago
They have blocked me so I can't read their tweets.
98.
▲
by
Foxboron
2y ago
I think it's worth pointing out that all demonstrations of this issue either needs yama to be disabled for `ptrace` to work (this is what reptyr does under the hood), or you need to be part of the parent process to abuse the tty termin
99.
▲
by
Foxboron
2y ago
Bro, you should really take the hint soon.
100.
▲
Why No IPv6?
(whynoipv6.com)
66 points
by
Foxboron
2y ago
|
176 comments
101.
▲
by
Foxboron
3y ago
I think we are talking past each other. I'm just trying to clear up a misconception on how nix works, not anything about the docker portion of what you have written.
102.
▲
by
Foxboron
3y ago
>It's content addressable, just what are you addressing? In the case of Nix it's addressed by the input. Not the content of the build. It's an important distinction and one Nix also makes. https://nixos.org&#x
103.
▲
by
Foxboron
3y ago
Nix is not content addressable though, the hashes is based off on the derivation files which are equal to the lock files you would find in other package managers. > The thing it provides is the toolchain of dependencies that are reproduc
104.
▲
by
Foxboron
3y ago
> We don't need to be looking for such contrived examples actually, nixpkgs track the packages that fail to reproduce for much more trivial reasons. There aren't many of them, but they exist Less than a couple of thousand packa
105.
▲
by
Foxboron
3y ago
> Nixpkgs focuses on reproducible builds, that means that for the same inputs, you always are going to get the same binary output. This is a common misconception, nixpkgs only really supports "repeatable builds" and "repro
106.
▲
by
Foxboron
3y ago
Parts of this seems dated. I'm pretty sure the entropy changes suggested doesn't really add anything after the recent (~2 years ago) rework of `/dev/random` in the kernel. It doesn't mention `systemd-homed` which m
107.
▲
by
Foxboron
3y ago
This doesn't help at all as you need to coordinate so-name rebuilds across multiple architectures. This implies you need to some way to orchestrate a staging repository and have building do rebuilds towards this repo interactively unti
108.
▲
by
Foxboron
3y ago
It's all part of the same problem domain; How do we rearchitecture the release process of Arch so we can support multiple architectures. The amount of people that understand this problem domain, have the time+energy to work on it and i
109.
▲
A re-introduction to mkosi – A Tool for Generating OS Images
(0pointer.net)
2 points
by
Foxboron
3y ago
|
0 comments
110.
▲
by
Foxboron
3y ago
There has been patches floating around to support this for quite a while. One example here: https://github.com/sandsmark/vlc-chromecast-subtitles
111.
▲
Stream to Chromecast with resolved, vlc and bash
(linderud.dev)
82 points
by
Foxboron
3y ago
|
35 comments
112.
▲
by
Foxboron
3y ago
CCC is a political organization.
113.
▲
by
Foxboron
3y ago
That is not great. Currently this makes the barrier of entry for new people to contribute to projects using gitlab quite a lot higher. There is also a huge volunteer cost here where we have to manually make accounts.
114.
▲
by
Foxboron
3y ago
A lot of effort is spent on packaging the stuff we need for our own infrastructure so we can run it in prod. Gitlab is one of these exceptions but generally it's been working well for us.
115.
▲
by
Foxboron
3y ago
Here is a post of the git migration to Gitlab on their tech blog written by Levente Polyak (Arch project leader). https://about.gitlab.com/blog/2023/09/11/migrating-arch-linu... Mentioning it as it never
116.
▲
by
Foxboron
3y ago
We do. The infrastructure is obviously open-source as well. Ansible role for gitlab: https://gitlab.archlinux.org/archlinux/infrastructure/-/tree... Gitlab playbook: https://gitlab.archlinux.org&#x
117.
▲
Arch Linux bugtracker migration to Gitlab completed
(archlinux.org)
120 points
by
Foxboron
3y ago
|
71 comments
118.
▲
by
Foxboron
3y ago
There is no limit to the password. Usinging a 4 digit numeric PIN is just easier to remember, and because of the bruteforce resistance it doesn't decrease the security.
119.
▲
by
Foxboron
3y ago
AUR is unsupported, and the fact that nixpkgs decides to support everything is for them to decide. Reaching for reproducible builds support in Arch is a more attainable goal than for nixpkgs. Properly maintaing 80k packages without regres
120.
▲
by
Foxboron
3y ago
It's unclear at the moment because of the limited testing (minimal ISO and a Gnome ISO) vs Arch/Debian/Guix rebuilding entire package repositories.
More ›