Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
arbll
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
arbll
11mo ago
It used to be 100% runtime-level and it was the golden age of browser exploits. Each of your tabs are now a separate process that the OS sandboxes. They can only access a specific API over IPC for anything that goes beyond js/rendering
32.
▲
by
arbll
11mo ago
It's fine for this project since google is probably not in the business of triggering exploits in yt-dlp users but please do not use deno sandboxing as a your main security measure to execute untrusted code . Runtime-level sandboxing
33.
▲
by
arbll
11mo ago
I'm assuming it's the render engine that is in pure CSS. You could display a static map in CSS but things like the tools to modify the terrain definitely need JS.
34.
▲
by
arbll
11mo ago
It is based on the impact on Datadog's customers, not on synthetic queries / pings
35.
▲
by
arbll
1y ago
A single region that is a SPOF for global AWS services*
36.
▲
by
arbll
1y ago
To avoid operating a database by yourself and dealing with incidents, backups, replicas, failovers, etc... You can use cheap commoditised S3-like storage and run your application statelessly. If you have access to a database that is well ma
37.
▲
by
arbll
1y ago
well at least it's consistent
38.
▲
by
arbll
1y ago
I never said it was a poor choice in this specific context but propagating the idea that Deno's sandboxing is safe and "basically the same security as chrome" is wrong and can easily do damage the next time someone that has r
39.
▲
by
arbll
1y ago
Identical to Chrome except the part where Chrome uses os-level sandboxing on top. V8 exploits are common, Deno sandboxing by itself is not a good idea if you are executing arbitrary code.
40.
▲
by
arbll
1y ago
Chrome does not rely exclusively on V8's security or else it would routinely get exploited (See v8 CVEs if you don't believe me). The hard part of browser exploitation today is escaping from the os-level sandbox put on the process
41.
▲
by
arbll
1y ago
Deno is a V8 wrapper, the same JS engine as Chrome. Vulnerabilities are very common there, not necessarily because it's poorly designed but more because there's massive financial incentives in findings them. This plus what you men
42.
▲
by
arbll
1y ago
I wonder if we're going to see JS runtime fingerprinting attempt from google now
43.
▲
by
arbll
1y ago
The sandboxing features of Deno also seem to have played a role in that choice. I wouldn't overly trust that as a security layer but it's better than nothing.
44.
▲
by
arbll
1y ago
One anecdote => All Ethereum’s cryptographers are a fraud => All crypto is a fraud You're deducing a lot from this one quote lol
45.
▲
by
arbll
1y ago
this type of exploits are goldmines for attackers, it means they have a window of a few month to years to turn any basic access into root. It doesn't have to be a super complex exploit chain, anyone running wordpress botnets it going t
46.
▲
by
arbll
1y ago
Situational but if you're in default configurations it's comparable. Both will need some form of unknown vuln. It boils down to wether you trust more the linux namespacing logic and container runtime glue or the hypervisor logic.
47.
▲
by
arbll
1y ago
Don't know much about SecureBlue but Kicksecure isn't comparable to Qubes at all. It's a hardened distro, not a way to isolate workloads through virtualisation. Depending on what you're trying to achieve they can both fi
48.
▲
by
arbll
1y ago
I think it will also try to influence what you like to maximize engagement unfortunately...
49.
▲
by
arbll
1y ago
Anything outside of what we can observe will always be based on faith anyway. We'll probably never understand what's "before" the big bang, wether it make sense to ask that question or why something exists rather than no
50.
▲
by
arbll
1y ago
At t=0 or "before" none
51.
▲
by
arbll
1y ago
I mean if a malware is root and altering your memory it's not like you're in a position where this check is meaningful haha
52.
▲
by
arbll
1y ago
This seem completely unrelated to the goal of OP's library ?
53.
▲
by
arbll
1y ago
No this is an S3-compatible client, minio is an S3-compatible backend
54.
▲
by
arbll
1y ago
Ah yes I'm going to disable DoH and go from trusting a central entity to trusting another central entity and everyone else on the wire. Article is a bunch of strong opinion with nothing to back them.
55.
▲
by
arbll
1y ago
For me the main reasons to pick Go in those context are cross-compilation, static binaries and more subjectively better productivity. You can very quickly get an MVP running and distribute it knowing it will work everywhere.
56.
▲
by
arbll
1y ago
IMO "easy/medium" coding questions have their place. I run quite a lot of interviews and I have many many "seniors" from known techn companies that can't do exercises that are glorified reverse for loops. The i
57.
▲
by
arbll
1y ago
Any complex software is going to be a collection of files, not a single static binary.
58.
▲
by
arbll
1y ago
- Stablecoin as an output requires BuyMeACoffe to implement KYC - Stablecoin as input adds a lot of friction on the donor with KYC again Crypto is just massive overhead for everyone in its current state
59.
▲
by
arbll
2y ago
A scenario where as an attacker: - You have raw access to the DB - You don't have enough privileges to get something more valuable than crashing the DB - You don't care to get noticed/caught Does sound pretty unlikely
60.
▲
by
arbll
2y ago
well good luck finding a buyer, there's very little practical use for a DoS on a service that is usually not exposed to the public internet
More ›