Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
arcfour
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
121.
▲
by
arcfour
5mo ago
I don't think it's unreasonable to imagine that Alibaba is allowed to scrape the wider internet, or that some research institution is and then Alibaba got data from them. What is perhaps more surprising is that the data was not sc
122.
▲
by
arcfour
5mo ago
It seems to me that an organization dedicated to stopping hate groups also funding those same hate groups (which, I might add, it relies upon for its continued existence/relevance) is fairly problematic.
123.
▲
by
arcfour
5mo ago
It is debatable what thoughts and feelings went into the music of Wesley Willis, of "Whip The Llama's Ass" fame, despite him being human.
124.
▲
by
arcfour
5mo ago
It's unfortunate that this does not include which versions of the kernel are vulnerable/patched, especially since this is a builtin module which cannot be easily removed with rmmod... I was wondering if I was vulnerable running Fe
125.
▲
by
arcfour
5mo ago
LPE is a very well-known acronym within the security community, it's not purely academic or obscure or anything. I agree that it would be a good idea to define it explicitly when writing for a broader audience, but I don't think i
126.
▲
by
arcfour
5mo ago
Closing the PR without providing feedback beyond "needs further discussion" does not engender said further discussion.
127.
▲
by
arcfour
5mo ago
JitHub. ("Please don't sue us.")
128.
▲
by
arcfour
5mo ago
I've seen plenty of servers in companies configured to allow sudoers to run a restricted subset of binaries as root, usually without a password. Some of them were GTFObins that the admins were not aware of until I reached out to let th
129.
▲
by
arcfour
5mo ago
Maybe sudoers is configured to allow you to run base64 as root. Why would someone do this? No idea. But if you are in such a situation, now you know how to bypass the intended permissions and read any file on the system. Or maybe you give C
130.
▲
by
arcfour
5mo ago
I don't know why everything has to be so polarized these days. You can use LLMs without it making you an idiot or delusional or psychotic or something. Are there issues with them? Of course. Are there people and organizations that rely
131.
▲
by
arcfour
5mo ago
Most extant email readers support such a limited subset of CSS that nobody is likely to send emails with anything beyond very basic CSS though, unless your reader gains a ton of traction I suppose.
132.
▲
by
arcfour
5mo ago
Huh. I consider cyan to be blue, but it turns out it's made by mixing equal parts of blue and green light on an RGB display. I guess that makes sense thinking about it now since it's not a deep blue, and there's obviously no
133.
▲
by
arcfour
5mo ago
I mean, I have to imagine the type of people that even know about Framework's products, let alone those that have interest in buying them, are overwhelmingly likely to be the type of people that use Linux, not Windows. Not to pooh-pooh
134.
▲
by
arcfour
5mo ago
The correct link for the first one (Jan 2017 SSL certs) is https://news.ycombinator.com/item?id=13377214 (currently it points right here, to this story) :-)
135.
▲
by
arcfour
5mo ago
I haven't had that experience at all with them before. I also don't put much stock in one off experiences from someone who is admittedly not in a situation that almost anyone else, much less someone registering their domains throu
136.
▲
by
arcfour
5mo ago
CloudFlare since they sell domains at cost and have really good DNS infrastructure with some free protection features. If the TLD isn't supported by them for registration then I'd just use their nameservers. Or Route53 if you'
137.
▲
by
arcfour
5mo ago
When you frame it that way, all human output ever is derivative.
138.
▲
by
arcfour
6mo ago
While I certainly relate to some of your points, and I'm not an AI maximalist by any means, a few thoughts: > You join a meeting with a coworker. Your coworker has enabled an AI tool to automatically take notes and summarize the mee
139.
▲
by
arcfour
6mo ago
Perhaps I'm ignorant, but isn't the idea that you can do it faster than brute force? If the results are statistically identical to guessing then it seems like you've just built a Rube Goldberg contraption.
140.
▲
by
arcfour
6mo ago
They wouldn't be classed as vulnerabilities then, since, you know, there is no vulnerability. Unless you have evidence that most of these issues are unexploitable, but I would be surprised to hear that they were considered vulnerabilit
141.
▲
by
arcfour
6mo ago
I wouldn't describe myself as an AI maximalist at all. I just don't believe the false dichotomy of you either produce "vulnerable vibe coded AI slop running on a managed service" or "pure handcrafted code running on
142.
▲
by
arcfour
6mo ago
Embrace the suck.
143.
▲
by
arcfour
6mo ago
Vercel runs on AWS.
144.
▲
by
arcfour
6mo ago
That's why I wrote my own compiler and coreutils. Can't trust some shit written by GNU developers 30 years ago. And my own kernel. Can't trust some shit written by a Finnish dude 30 years ago. And my own UEFI firmware. Defini
145.
▲
by
arcfour
6mo ago
Pfft, just grab a teletype and run lpr -P ttyUSB0 ai_generated_report.txt ;-)
146.
▲
by
arcfour
6mo ago
I know the best way to solve a problem with corruption and lack of transparency: involve the government! Nobody could ever pay off a politician . Surely that would only work in our favor.
147.
▲
by
arcfour
6mo ago
What would this privilege look like that is meaningfully different from SYSTEM while being properly protected from/able to deal with malware that has an LPE?
148.
▲
by
arcfour
6mo ago
CloudFlare has supported it since 2023: https://blog.cloudflare.com/announcing-encrypted-client-hell... Firefox has had it enabled by default since version 119: https://support.mozilla.org/en-US/kb/
149.
▲
by
arcfour
6mo ago
A building collapse and a poorly built website UI are completely different in terms of actual risk.
150.
▲
by
arcfour
6mo ago
Sure, I should have said geolocation element, since the original API still exists and is used: https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/...
More ›