Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
SahAssar
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
211.
▲
by
SahAssar
11mo ago
Nobody in this thread has provided anything that would lead me to believe that any government can easily buy RCE on any OS . Read the quote again: > Any government can get RCE on any OS with the change in their couch
212.
▲
by
SahAssar
11mo ago
Come on, you said: > Any government can get RCE on any OS with the change in their couch If you were extremely hyperbolic for effect that's fine, that's why I asked if you actually believed that, but what you are saying now is
213.
▲
by
SahAssar
11mo ago
I work in security. I know all of the above. But the parent said that " any government can by RCE on any OS ", that is not at all the same as saying that it is plausible that a few of the more advanced countries probably have
214.
▲
by
SahAssar
11mo ago
Finding a vulnerability is not at all the same as "RCE on any OS". Vulnerabilities are common, the ones that have the impact implied are not.
215.
▲
by
SahAssar
11mo ago
It really hasn't to the scale that you imply. Why hasn't ukraine and russia both used this to completely shut down each others infrastructure? Why isn't russia just hacking all the ukrainian COTS drones? Why hasn't anyon
216.
▲
by
SahAssar
11mo ago
> [1]: https://opzero.ru/en/prices/ Those are the prices that they are buying for, they do not indicate at all that these are common or how large the market is for RCE on any OS . > [2]: https://
217.
▲
by
SahAssar
11mo ago
> Any government can get RCE on any OS with the change in their couch. Do you really believe that? That seems extremely implausible based on just simple observations like all governments using COTS OS for military/intelligence work
218.
▲
by
SahAssar
11mo ago
A supported way would imply guarantees of compatibility and stability. These sort of perfs in user.js or about:config are clearly labeled as not having those guarantees and therefore "unsupported". As someone who extensively custo
219.
▲
by
SahAssar
11mo ago
https://archive.ph/GjrnB
220.
▲
by
SahAssar
11mo ago
It sorta was, even before jsx: https://en.wikipedia.org/wiki/ECMAScript_for_XML
221.
▲
by
SahAssar
11mo ago
From that article: > However, after further appeal in another court, hiQ was found to be in breach of LinkedIn's terms, and there was a settlement. So why would the same not apply here?
222.
▲
by
SahAssar
11mo ago
Tabular data? Tables have a purpose, it's just that people misused them for layout purposes.
223.
▲
by
SahAssar
1y ago
> More context: https://chatgpt.com/share/68f82df3-74f0-8012-9bfe-de89a4e75e... Are you using chatgpt to factcheck what chatgpt does on your computer?
224.
▲
by
SahAssar
1y ago
"Store data persistently" implies "it can be looked up" since if you cannot look it up it is impossible to know if it is stored persistently. The "efficiently" part can be considered a separate problem though.
225.
▲
by
SahAssar
1y ago
> Experts recommend What experts? For what scenarios specifically? When do they consider time-of-creation to be sensitive?
226.
▲
by
SahAssar
1y ago
Seems like its chromeOS only for now.
227.
▲
by
SahAssar
1y ago
Cloudflare does not allow you to use other nameservers. That makes them a bad registrar since they forbid using a different service for a unrelated thing.
228.
▲
by
SahAssar
1y ago
> And makes me wonder if this is gonna cause more pushback regarding the rust in the kernel movement. Does this have anything at all to do with the kernel?
229.
▲
by
SahAssar
1y ago
In my experience deliverability to gmail is not that hard if you configure stuff correctly. You need a clean IP and domain, rDNS and the usual email stuff like DKIM, DMARC, SPF, but not much else. Also not sure why you would choose OpenBSD
230.
▲
by
SahAssar
1y ago
My experience is pretty much the opposite. Bad support for common APIs like S3, terrible support for terraform/opentofu, none/lackluster help in support or github issues.
231.
▲
by
SahAssar
1y ago
That is not my experience at all. Using a pretty fresh IP and domain I get pretty good deliverability as long as I have proper rDNS and all the other normal steps (like DKIM, etc.)
232.
▲
by
SahAssar
1y ago
I don't think that is true for email or xmpp. Could you please explain?
233.
▲
by
SahAssar
1y ago
Why bring up Gentoo at all?
234.
▲
by
SahAssar
1y ago
Doesn't seem to work for me on desktop chrome or firefox (linux), dragging the movie does nothing.
235.
▲
by
SahAssar
1y ago
Android does not use what we normally call a linux userspace. iOS is not at all linux based, although it is UNIX-like.
236.
▲
by
SahAssar
1y ago
Android is a modified/patched linux kernel with a different userspace.
237.
▲
by
SahAssar
1y ago
You can, but a lot of people lack the discipline to do so correctly. I'd prefer them to use corp.paypal.com, but as a security guy it's easier to just get them a separate domain and let them have their less-secured stuff completel
238.
▲
by
SahAssar
1y ago
There is a standard solution, it works well. What is still being worked on is portability, but if you are securing your most important stuff (banking, email) then passkeys are definitely workable without portability since if you switch ecos
239.
▲
by
SahAssar
1y ago
Do you work for bunnyCDN? This sounds more like a sales pitch than a honest recommendation.
240.
▲
by
SahAssar
1y ago
These sort of articles should definitely mention webauthn/passkeys. It's the only solution that actually solves these (including phising) problems.
More ›