Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Orygin
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
181.
▲
by
Orygin
11mo ago
Yet the GPL imposes requirements for me and we consider it free software. You are still free to train on the licensed work, BUT you must meet the requirements (just like the GPL), which would include making the model open source/weight
182.
▲
by
Orygin
11mo ago
Freedom 0 is not violated. GPL includes restrictions for how you can use the software, yet it's still open source. You can do whatever you want with the software, BUT you must do a few things. For GPL it's keeping the license, dis
183.
▲
by
Orygin
11mo ago
Great article but I don't really agree with their take on GPL regarding this paragraph: > The spirit of the GPL is to promote the free sharing and development of software [...] the reality is that they are proceeding in a different
184.
▲
by
Orygin
11mo ago
My next project will be released under a GPL-like license with exactly this condition added. If you train a model on this code, the model must be open source & open weights
185.
▲
by
Orygin
11mo ago
It's the same issue on big screens. I have a ultra wide 2k, and in full screen I only have 3 videos on the homepage.
186.
▲
by
Orygin
11mo ago
I tried playing GTAO when it was free, and oh boy. Loading for 10 minutes, arrive into the game and see you're not with your friends. So 10 more minutes to load into their server. Then you start a mission and 10 more minutes of loading
187.
▲
by
Orygin
11mo ago
Indeed that's what I remember too. So like I said, the risk is more not being able to download the games than the Steam DRM being there.
188.
▲
by
Orygin
11mo ago
They are as useless on linux as they are on Windows. How many cheaters on the latest games with Kernel AC?
189.
▲
by
Orygin
11mo ago
> This is a bug in the default config that is likely to result in RCE, it doesn’t get that much worse than this. Likely to get RCE? No. Not every UAF results in a RCE. Also, someone would have to find this and it's clearly not somet
190.
▲
by
Orygin
11mo ago
In the end, a report saying "fix this within 90 days or this gets public" for small-ish bugs like this is a kind of demand. Do this or this gets out and you'll have to make an express release to fix it anyway. I can understan
191.
▲
by
Orygin
11mo ago
> Anything besides rumors? AFAIK, there is absolutely zero official information beyond the rumor mill. If you count datamining as rumors, then no, nothing else. But the data mining is real data coming from valve so it's more than ju
192.
▲
by
Orygin
11mo ago
Yes (that's the point of a DRM), but like I said, the DRM is easily broken. Some games can also still use steam features when cracked (like joining lobbies, inviting friends, etc), and it's the same "crack" for every gam
193.
▲
by
Orygin
11mo ago
I totally agree with you, and I hope the status quo will change. But I'm still skeptical after the Steam Deck success where many games enabled anti cheat, but some did roll back like I said previously. Attestation could help, but I
194.
▲
by
Orygin
11mo ago
I mean, there are plenty of info available on the status of HL3 (code named HLX) and all point to it not being a VR title. Also I don't think ARM is really a thing for them, even now. They want to support running software on the headse
195.
▲
by
Orygin
11mo ago
If the DRM is enabled, the game does a simple "Is the game available in the user's library?" and steams says yes or no. If the game didn't have DRM enabled, no check is made. Copy the game folder elsewhere, without steam
196.
▲
by
Orygin
11mo ago
A 25 years old bug in software is not the same as a backdoor (not a bug, a full on backdoor..). The bug is so old if someone put it there intentionally, well congrats on the 25yo 0day. Meanwhile the XZ backdoor was 100% meant to be used. I
197.
▲
by
Orygin
11mo ago
We know, and the game devs know too. But Kernel anti cheat is not a solution but simply a marketing feature to make their users think they try. Just seeing all the gamers requesting a kernel AC for CS2, saying VAC does not work; but now the
198.
▲
by
Orygin
11mo ago
It affects console too, but watch game publishers disable linux support, blaming cheaters while producing graphs that don't support their arguments. While console packs and cheats are rampant, and their game servers even being hacked d
199.
▲
by
Orygin
11mo ago
HL3 is most likely not a VR game as Valve said they aren't working on a first party VR title (plus data mining seems to confirm). Plus they already have Alyx as the masterpiece, and it was already made with their own VR headset in mind
200.
▲
by
Orygin
11mo ago
The XZ backdoor is not a bug but a malicious payload inserted by malicious actors. The security vulnerability would immediately been used as it was created by attackers. This bug is almost certainly too obscure to be found and exploited in
201.
▲
by
Orygin
11mo ago
Why do you shit on it? This software is literally holding the near entirety of video transcoding *worldwide* on its shoulders.
202.
▲
by
Orygin
11mo ago
For OSS projects or commercial ones? I feel it's not the same when one has trillion in market cap and the other has a few unpaid maintainers.
203.
▲
by
Orygin
11mo ago
On the other hand, reporters giving a CVE a 10 for a bug in an obscure configuration option that is disabled by default in most deployments is bit over the top. I've seen security issues being reported as world ending, being there for
204.
▲
by
Orygin
11mo ago
It doesn't if you report lots of "security" issues (like this 25 years old bug) and give too little time to fix them. Nobody is against Google reporting bugs, but they use automatic AI to spam them and then expect a prompt fi
205.
▲
by
Orygin
11mo ago
Is it industry standard to run automatic AI tools and spam the upstream with bug reports? To then expect the bugs to be fixed within a 90 days is a bit much. It's not some lone report of an important bug, it's AI spam that put for
206.
▲
by
Orygin
11mo ago
He has none and has been trying to depict Audacity as a Russian malware vector for over a year now, but without providing any source.
207.
▲
by
Orygin
11mo ago
If you do reproducible builds for only the binary of the program and not what's around it I don't know if it makes any sense. Related software like the installation script should be checked too against the source. Otherwise that w
208.
▲
by
Orygin
11mo ago
I mean, you already are "executing a binary coming from Muse groups server" if you downloaded Audacity from their website. How is an auto update mechanism a backdoor? You have to accept a modal for it to run the downloaded binary.
209.
▲
by
Orygin
1y ago
Even worse, LLM hallucinations can be squatted to the same effect.
210.
▲
by
Orygin
1y ago
Wasn't the vulnerability triggered by a malicious script that was added silently to the tarball? Reproducible builds would have shown that the tarball is not the exact output of the build. Even though the malicious payload was already
More ›