Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Seirdy
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
121.
▲
by
Seirdy
5y ago
You should probably add noexecstack to your ldflags. I also only use -fstack-protector-strong and -fcf-protection as a fallback in case -fstack-protector-all and -fcf-protection=full cause crashes. I listed some more in https://n
122.
▲
by
Seirdy
5y ago
Yes, fvisibility=hidden is a great addition; combined with LTO and a Clang toolchain, you can also add fsanitize=cfi. The CFI sanitizer adds a 1% perf penalty for a significant exploit mitigation. It complements -fcf-protection=full nicely.
123.
▲
by
Seirdy
5y ago
> For one thing, convection to a website via one of those protocols first, and then a header informs the client that it can reconnect via QUIC/HTTP3. Nit: new SVCB DNS records can serve the same purpose as Alt-Svc HTTP headers befor
124.
▲
by
Seirdy
5y ago
Another project in this vein is the Tildeverse, a group of pubnix servers that provide web/gopher/gemini hosting, preinstalled utilities (e.g. an IRC client, development toolchains, common $EDITORs), and services (mail hosting, BB
125.
▲
by
Seirdy
5y ago
> I hope you realize this doesn't make sense. Would minsign2 be able to read minsign1? For an end user, they will need to know even more out of band information about the signature they want to verify. "Signify 2" would be
126.
▲
by
Seirdy
5y ago
> Strong identity and long lived keys are a requirement. Perfect forward secrecy does not make sense in a world were I want to prove that all things signed by me are in fact signed by me. If I generated a new key, how do I distribute tha
127.
▲
by
Seirdy
5y ago
> In the Keyoxide case we are only doing signing so that is the only part of the OpenPGP standard that would be applicable. The problem is that PGP does a lot of stuff besides signing too; this is bad design, and is one in a long list of
128.
▲
by
Seirdy
5y ago
PGP is bloated and complex, trying to be the Swiss Army Chainsaw of encryption and verification. It lacks modern features of encryption tools such as channel binding (which opens whole categories of exploits) and perfect forward secrecy (in
129.
▲
by
Seirdy
5y ago
The purpose of a permissive license is to encourage proprietary derivatives that come with intellectual property restrictions, EULAs, SaaS with vendor lock-in, etc. The purpose of a copyleft license is to encourage derivatives that don'
130.
▲
by
Seirdy
5y ago
There are...a lot of good reasons to keep the mitigations enabled. All nontrivial software has bugs, and hardening measures can keep some of the worst ones in check. Frankly, the Linux desktop needs more of this, not less. That being sa
131.
▲
by
Seirdy
5y ago
I wasn't aware that MATE was still on X; that's good info to know.
132.
▲
by
Seirdy
5y ago
I was referring to the fact that OpenGL is becoming a second class citizen among the silicon giants, with more attention being drawn to Vulcan/Metal/etc. Now that sway supports a Vulcan backend, it won't be left in the dust s
133.
▲
by
Seirdy
5y ago
Qubes devs are in my experience the most vocal X detractors. They had to work around X's inherent lack of isolation by using a Xen mechanism. The equivalent would be putting a wooden chest in a safe to show that wooden chests are sec
134.
▲
by
Seirdy
5y ago
> Why does it have to be? What do we get for this cost? The only things in which I would find a modern Linux better than a 90s Linux are full UTF-8 support, modern crypto and hardware drivers availability. A lot of exploit mitigations, e
135.
▲
by
Seirdy
5y ago
Xdotool and xsel have had Wayland equivalents for years: see ydotool/wtype and wl-clipboard. The reason why major orgs have had to push for Wayland is the same as the reasons they had to push for HTTPS and TLSv1.2, unique passwords, ke
136.
▲
by
Seirdy
5y ago
I am only familiar with ARMv7 and later, which come with graphics chips optimized for for something different than what X was built for. In my own tests and from others who have tried the same, DWM & Co were noticeably slower; I'd
137.
▲
by
Seirdy
5y ago
Debian 10, Debian 11, OpenSUSE, Fedora, RHEL 8, Ubuntu, and others ship GNOME on Wayland by default right now. It receives better support than the X version. KDE upstream is also Wayland by default which is reflected in the KDE version of O
138.
▲
by
Seirdy
5y ago
If you try scrolling in a web browser, especially fast scrolling in small increments, you're likely to experience screen tearing or other problems in the "smoothness". Compositors are included by default on most X desktop env
139.
▲
by
Seirdy
5y ago
> Zero cases in the wild Follow along this post and you'll end up with one case in the wild all by yourself on your own machine: https://theinvisiblethings.blogspot.com/2011/04/linux-securi... Xace was des
140.
▲
by
Seirdy
5y ago
ARM chips did not exist in the early 90s, and compositors weren't the norm either. Current integrated graphics processors are optimized for a very different landscape. A typical X setup also includes a compositor to mitigate screen tea
141.
▲
by
Seirdy
5y ago
> hey, you lose copy-paste, screenshots, xdotool and most of the apps you used before. Wayland has had working screenshots, screen recording, clipboard functionality for text and arbitrary mimetypes, etc. for years on wlroots, GNOME, and
142.
▲
by
Seirdy
5y ago
1. Wayland does support remote execution; see waypipe for an example. 2. X11 does lack critical features that lots of users need: GUI isolation (a very basic security measure that's otherwise been standard practice for decades), mixed
143.
▲
by
Seirdy
5y ago
Fedora, Ubuntu, OpenSUSE, RHEL/Rocky, and Debian all have their default desktops on Wayland. Both GNOME and KDE have already switched and will keep legacy X around for compatibility purposes for another few years. On the more minimal s
144.
▲
by
Seirdy
5y ago
The biggest reason is security. X offers no GUI isolation. This is a basic mitigation that should have been the norm a decade or two ago. Advanced mixed DPI also comes to mind. Another is performance: Sway easily outperforms DWM/i3
145.
▲
by
Seirdy
5y ago
KDE hasn't used WebKit for many years. KDE uses QtWebEngine, which is based on the Chromium Embedded Framework.
146.
▲
by
Seirdy
5y ago
I wasn't referring to the installation medium, but the base image typically used for setting up servers/chroots/containers.
147.
▲
by
Seirdy
5y ago
The Fedora base image does not include which. The base image is what's used in the standard OCI Fedora container, some Flatpak work, and some other things. Arch also doesn't include "which", nor do some arch-based distro
148.
▲
by
Seirdy
5y ago
You're free to do this, but be aware that you'll then need to be aware of where your scripts will and won't run. I regularly use Fedora, Alpine Linux, Void, Debian, and OpenBSD. Void uses dash as its default shell, Debian use
149.
▲
by
Seirdy
5y ago
You should be using ShellCheck or an equivalent linter on your shell scripts in POSIX mode if you want them to be portable; in POSIX mode it warns when using "which" instead of "command -v", and I think it also warns whe
150.
▲
by
Seirdy
5y ago
Moving away from standards won't make it any easier to diversify our operating system choices. Standards compliance is what allows alternatives to be usable with existing software. A lack of alternatives simply means that not enough st
More ›