Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
akdev1l
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
akdev1l
5mo ago
You could still have this 1-click experience with another system. Like you could set some rule like “this vendor is approved for charges below $50”. We don’t need the legacy system for that. (I don’t know if any payment systems can do that
32.
▲
by
akdev1l
5mo ago
My biology teacher in school once tried to teach us that winds created by God. Not like spiritually or something but that God literally made the wind I guess. My “earth sciences” teacher also once tried to argue with me against the universa
33.
▲
by
akdev1l
5mo ago
As an anecdote, I provided fragnesia.c and the subsequent proposed patch to fix the issue and while it was not able to discover an entirely new vulnerability, I think it was able to find 2 new ways of exploiting the same underlying bug. Thi
34.
▲
by
akdev1l
5mo ago
The JVM has nothing to do with Android. There is no JVM running android apps. There was Dalvik VM at one point but now it’s just the Android Runtime.
35.
▲
by
akdev1l
5mo ago
A very comprehensive SELinux deployment for one. SELinux will stop any process in android from loading kernel modules, that’s not allowed. The android permission model as a whole is ultimately backed by SELinux.
36.
▲
by
akdev1l
5mo ago
The thing is that we could simply split those modules into separate packages No reason why you couldn’t just `dnf install -y kmod-rxrpc` if for whatever reason you need that.
37.
▲
by
akdev1l
5mo ago
interesting but in that case no point in keeping the x bit either and suid binaries should just be 4700 ?
38.
▲
by
akdev1l
5mo ago
F44 is safe as the kernel is greater than 6.18.22
39.
▲
by
akdev1l
5mo ago
Without read permissions you cannot execute the binary, that would not make any sense. To execute the binary it needs to be read from disk and loaded into memory. In fact if you have read permissions but not executable permissions on a spec
40.
▲
by
akdev1l
5mo ago
> you dont test exploit pocs on your daily driver. Do you just like making fake points and pretending other people said them?
41.
▲
by
akdev1l
5mo ago
what the blog says and what the code does are two different things. For all I know the blog itself is a honey pot. I need to know what the code does before I run it.
42.
▲
by
akdev1l
5mo ago
Disagree because to run the PoC you really ought to understand what it’s doing. And this code is not readable at all. It is failing at letting people confirm the exploit easily.
43.
▲
by
akdev1l
5mo ago
Agreed lmao the PoC itself looks like you’re getting attacked Which I guess is true but I would like to verify the attack is the intended one
44.
▲
by
akdev1l
5mo ago
You’d have to reinstall the su binary itself I guess
45.
▲
by
akdev1l
5mo ago
No, Android doesn’t have suid binaries to exploit like in the PoC
46.
▲
by
akdev1l
5mo ago
there’s barely any hacking here the guy found this through looking at the firmware but nmap -p 22 would have also found this So like the first thing you would do to attack the device I found an issue exactly like this on an ISP-provided rou
47.
▲
by
akdev1l
5mo ago
It was. Not anymore. See: layoffs.
48.
▲
by
akdev1l
5mo ago
Also Google has a whole YouTube inside of it
49.
▲
by
akdev1l
5mo ago
I am convinced Mark Zuckerberg does more harm than good for Facebook like literally they lucked out on the landing the business model early but it feels it has been in an ongoing decline and everything else they have tried has failed specta
50.
▲
by
akdev1l
6mo ago
It depends, you could have an application with something like FROM scratch COPY my-static-binary /my-static-binary ENTRYPOINT “/my-static-binary” Having multiple processes inside one container is a bit of an anti-pattern imo
51.
▲
by
akdev1l
6mo ago
Also Amazon definitely uses k8s for stuff. Teams are free to use EKS internally.
52.
▲
by
akdev1l
6mo ago
It’s good use for AI Have the model spit out example programs to study the API
53.
▲
by
akdev1l
6mo ago
> The driver can only provide a set of input coordinates to the applications. By default, the system will behave as if you've clicked at the point of a single touch, or mouse-button dragged when you single-finger drag. Yeah no. All
54.
▲
by
akdev1l
6mo ago
I think the author of the article is missing this point. When you actually work alongside people and everyone builds a similar mental model of the codebase then communication between humans is far more effective than LLMs. For random contri
55.
▲
by
akdev1l
6mo ago
There is a whole section on touchscreen annoyances from the Linux Surface project: https://github.com/linux-surface/linux-surface/wiki/Installa... > Any gesture functionality is dependent on the software y
56.
▲
by
akdev1l
6mo ago
>With Wayland, it's borderline identical. Come on lol. I have a couple steam decks and both are really clunky. Most applications are not built using GTK4 nor Qt6 for that matter. On my steam deck the keyboard never pops up by itself
57.
▲
by
akdev1l
6mo ago
It supports them via libinput. Everything around actually a Linux device with a touchscreen sucks. Like on-screen keyboard will be inconsistent depending on the framework of the app. comparing to iOS which was built from the ground up aroun
58.
▲
by
akdev1l
6mo ago
Yeah but then it will only use the certificate on the yubikey and not ask for a password so we’re back to 1FA
59.
▲
by
akdev1l
6mo ago
How does it compare to podman with crun-vm ?
60.
▲
by
akdev1l
6mo ago
Notably macOS cannot do this
More ›