Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
anyfoo
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
241.
▲
by
anyfoo
1y ago
That’s not the reason I don’t like it.
242.
▲
by
anyfoo
1y ago
Indeed I use my printer once every two months or so, as a very rough estimate. And then it’s usually for myself rather than for someone or something else. For example I sometimes (not always) like printing out papers to read them “offline
243.
▲
by
anyfoo
1y ago
I’m one of the people that don’t “get” Balatro. I do get how to play it (to a certain level at least), and I’ve certainly been drawn to a bunch of rogue-like games, some of which I still play (Into the Breach for example), but Balatro is ju
244.
▲
by
anyfoo
1y ago
I have not looked at this project, but my guess would be: x86 is a widely available platform that, because of its history and relentless compatibility, contains a lot of legacy interfaces that make implement a very simple, thin-layer and “D
245.
▲
by
anyfoo
1y ago
Very good design. Implements only the essential tasks an operator would need with concise and well-known mnemonics. I’m sure this will be immediately intuitive to anyone, with no potential for mistakes whatsoever.
246.
▲
by
anyfoo
1y ago
As someone from Munich, I often joke that if I fell unconscious and woke up in Vienna, it would take me a rather long time to figure out that I’m not in Munich.
247.
▲
by
anyfoo
1y ago
I grew up in Munich, so I’m heavily biased, but my impression is that people in Munich may appear somewhat cold/“grantlerig” on the outside, but when you actually interact on them on a personal level, they are extremely warm and welcom
248.
▲
by
anyfoo
1y ago
Does your solution do incremental backups at all? I have backups going back years, because through incremental backups each delta is not very large. Every once in a while things gets sparsed out, so that for example I have daily backups for
249.
▲
by
anyfoo
1y ago
You're right!
250.
▲
by
anyfoo
1y ago
COBOL has an almost-COME-FROM, its called “ALTER” and it changes the destination of a GO TO, but it’s “discouraged” nowadays.
251.
▲
by
anyfoo
1y ago
Not sure about regex. Its syntax is, by definition, regular . (Okay, most regex engines people use aren’t technically fully regular languages anymore, but that just makes things more convenient.)
252.
▲
by
anyfoo
1y ago
Gosh, after all those years I've only just realized the double meaning of "fruit flies". Thanks! Before that, I just thought it was more of a non sequitur, but still amusing. There was just something inherently funny about im
253.
▲
by
anyfoo
1y ago
Reading the paper further, there is this: However, the BTB provides partial target addresses [28], so the attacker only needs to branch to an address where the lower portion matches the desired kernel target. The upper bits of the BTB
254.
▲
by
anyfoo
1y ago
Again, I don't think I understood yet why the JS code needs to create actual pointers accessing arbitrary memory for the attack to work, instead of benignly passing down arbitrary integer values far enough into (say) the kernel and mis
255.
▲
by
anyfoo
1y ago
I am really an amateur when it comes to Spectre-like attacks, but do you strictly need a valid pointer pointing to the address? I thought you "just" need to mispredict into code that would use it as a pointer, even if that code
256.
▲
by
anyfoo
1y ago
Well that only depends on what gadgets happen to be available, doesn't it? Both C and JS get compiled down to machine code. I personally would not trust that you couldn't, in the most extreme case, get close enough to the kernel (
257.
▲
by
anyfoo
1y ago
This vulnerability is, in the worst case, about reading any memory in the system, not memory confined to any particular website, or to the browser at all, though?
258.
▲
by
anyfoo
1y ago
This seems to theorize an attack where you are interested in particularly data of the particularly visited website, and at the same time assuming that the attack would have to be carried out on the same website. The vulnerability however al
259.
▲
by
anyfoo
1y ago
Fair. Better than nothing.
260.
▲
by
anyfoo
1y ago
Hmm, I'm not sure why Same-Origin and injection attacks are prerequisite. Shouldn't it be sufficient to visit an arbitrary website through a link somewhere?
261.
▲
by
anyfoo
1y ago
I don't know. PL/SQL (which is separate from SQL) is effectively a general purpose language, and kind of a beast at that. I have not the faintest idea, but at least I wouldn't be surprised to see high enough precision timers,
262.
▲
by
anyfoo
1y ago
PL/SQL, not SQL. Whatever I knew about PL/SQL in the 90s and early 2000s I've forgotten, but I wouldn't be so certain that PL/SQL a) does not have precise enough timing primitives, and b) does not get JITed down int
263.
▲
by
anyfoo
1y ago
Do you mean overall or localized to branch prediction? Assuming all of that is true, you're talking about a 20-30% performance hit?
264.
▲
by
anyfoo
1y ago
A bit. I think we've shown time and time again that letting the compiler do what the CPU is doing doesn't work out, most recently with Itanium.
265.
▲
by
anyfoo
1y ago
Userspace processes can only read their own memory, or what has been shared with them.
266.
▲
by
anyfoo
1y ago
I don’t quite understand how that matters here. The researchers found a CPU vulnerability. They demonstrated it on a popular Linux distribution and LTS version, Ubuntu 24.04. They likely picked that to show that the attack is not purely the
267.
▲
by
anyfoo
1y ago
> If the timers draw from different distributions then it is going to be much harder. Again, I'm an amateur, but I think you just need to know that distribution, which I guess you usually do (open source vs. closed source barely m
268.
▲
by
anyfoo
1y ago
Yeah, as stated in a sibling answer, I misread your comment a little bit. It's true, on at least some classes of infrastructure boxes, you more or less "own all that is on the machine" anyway. But also note my caveat about da
269.
▲
by
anyfoo
1y ago
Awesome. I see you've made full use of Hedgehog as well.
270.
▲
by
anyfoo
1y ago
There is a difference. JS is turing complete, pure HTML is far from (as far as I'm aware). So HTML might (!) well be restricted enough to not be able to carry out such an attack. But I'd never state to definitively, as I don'
More ›