Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
akerl_
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
61.
▲
by
akerl_
2mo ago
The danger of using quotation marks around things that aren't quotes is that you can wildly misstate what somebody said and readers are left to ponder if you just don't understand or if you're willfully trying to misrepresent
62.
▲
by
akerl_
2mo ago
What is the good faith interpretation you’d suggest?
63.
▲
by
akerl_
2mo ago
Nobody is suggesting uncritical praise.
64.
▲
by
akerl_
2mo ago
This comment could make the same point and be even more effective if wasn't written as a snarky retort in violation of several of the guidelines of the site ( https://news.ycombinator.com/newsguidelines.html )
65.
▲
by
akerl_
3mo ago
Interesting. I’ve only used Maven-format repos once or twice and always via somebody’s preexisting CI tooling. Is there essentially a “draft” release that you can edit repeatedly before hitting “publish”? Is that draft release visible exter
66.
▲
by
akerl_
3mo ago
Generally each artifact in the release is atomic, as is (and was) the case here. You’ll never get served a partially uploaded wheel for amd64 Linux, but somebody could come back a year later and add a 2nd wheel to that release for a differe
67.
▲
by
akerl_
3mo ago
That’s exactly how individual artifacts are (and were) on PyPI. This change isn’t to artifact immutability, it’s to releases (collections of artifacts)
68.
▲
by
akerl_
3mo ago
No? Again, can you think of any packages managers that have a finalize step like you’re describing? All the package managers I’m aware of do one of two things: 1. You push once with everything baked in. 2. You push as many things as you wan
69.
▲
by
akerl_
3mo ago
Worth noting, because I think it’s confusing some folks on this comments page, that “file” here is “a wheel for a platform” or “a complete sdist”, not “each individual .py file in a release” You can’t go back later and add “evil.py” to a bu
70.
▲
by
akerl_
3mo ago
Are there any package managers that have that kind of publish/finalize flow? Every one I’m aware of works either as a one-shot (you have to submit everything in one push) or lets you keep adding new assets forever (other, obviously, th
71.
▲
by
akerl_
3mo ago
I wonder when Kalshi will start offering bets where one side doesn’t pay out until the end of the universe.
72.
▲
by
akerl_
3mo ago
This is a gnarly vuln but a top tier write-up.
73.
▲
by
akerl_
3mo ago
I'm scared of companies where SOC2 auditors are driving their security improvements. It's a bit like letting my toddler drive how I stock my pantry: surely by the end the pantry will be more full, but not really in the way I want.
74.
▲
by
akerl_
3mo ago
What about the other Lavabit users whose data he had handed over previously, before deciding to say no?
75.
▲
by
akerl_
3mo ago
Even setting aside that there are, in fact, many human and robot eyes staring hard at the firehose of published packages on popular registries, the whole argument feels like a false dichotomy. If you're going to "DYOR" or wha
76.
▲
by
akerl_
3mo ago
Agreed. Whenever we end up getting non-IKEA furniture I preemptively cringe as I open the instructions. The only time I’ve had a mistake building IKEA furniture was after opening both pieces of a combo shelf at once: there was a subtle but
77.
▲
by
akerl_
3mo ago
Are you saying that you don’t think that the GDPR text is written to apply outside of the EU, or that it does say that but it’s not relevant because it’s not viable for anybody to enforce that?
78.
▲
by
akerl_
3mo ago
Design changes are not part of the self certification process, they’re part of the type certification process, which has always been handled by the FAA.
79.
▲
by
akerl_
3mo ago
As has been noted in several of the comments, the crashes were a result of a faulty design, not aircraft failing to meet the design. The self-certification here wasn’t part of the chain of events that led to the crashes; it appears to have
80.
▲
by
akerl_
3mo ago
Not really in the way the media would have you believe. Like “I was scared for a couple minutes on a Friday morning until I saw the vendor status page” is orders of magnitude away from the bar here.
81.
▲
by
akerl_
3mo ago
What would your damages be? They’re not actually going to charge your credit card for 34 billion.
82.
▲
by
akerl_
3mo ago
https://health.aws.amazon.com/health/status Looks like this is a bug w/ S3
83.
▲
by
akerl_
3mo ago
Where are you seeing this? LLMs make it easier to do bulk data analysis / scale attack patterns, but I've not seen anything to suggest they're incentivizing people to do OSINT against random individuals to fire off targeted a
84.
▲
by
akerl_
3mo ago
How many people out there have attackers doing individualized research to identify services on their home LAN so they can chain a network attack with CVEs in their self-hosted service?
85.
▲
by
akerl_
3mo ago
Don’t worry, they got data from a whole 5000 people in Australia and 300 people in Afghanistan! I’m sure that’s generalizable to the whole country’s worth of 28 and 40 million, respectively.
86.
▲
by
akerl_
3mo ago
> Countries with fewer than 100 test-takers were excluded from the ranking due to limited sample size and are shown in gray on the map above. How generous of them.
87.
▲
by
akerl_
3mo ago
Your original link makes fairly clear how disingenuous it is to call the figures a national average: > Data from International IQ Test (IIT) are based on data from 1,352,763 participants worldwide who took the same IQ test on the website
88.
▲
by
akerl_
3mo ago
I don’t suppose this was related to the recent Netvue/Birdfy outage that they claimed was due to a registrar issue and lasted over a week?
89.
▲
by
akerl_
3mo ago
The reason this bug is unexpected is that the user is expecting to have to enter their password (because they expect the key to be wiped on suspend), and then _they are_ asked for their password. But there was a copy of the key elsewhere in
90.
▲
by
akerl_
3mo ago
Managing an Apple fleet is similarly fine, and that includes using any of the MDM tooling that also does key escrow on enterprise Filevault devices.
More ›