Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
arcfour
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
151.
▲
by
arcfour
6mo ago
Opt in features are a great way to increase user frustration and confusion. See the whole new geolocation API they had to make for browsers since people would perma-deny it reflexively and then complain that geolocation features weren'
152.
▲
by
arcfour
6mo ago
As a user, I really don't care about the supposed purity or correctness of a website's tech stack. When I click "back" I want to go back to what I think the previous page was.
153.
▲
by
arcfour
6mo ago
Well, I guess you'll always live in a land of division and spite, always angry yourself, and the "others" always angry back at you, squabbling forever while things slowly get worse. I hope you enjoy the bed you've made f
154.
▲
by
arcfour
6mo ago
Does it really matter who is more violent? The fact of the matter is both sides do have a nonzero amount of crazy/violent people and both sides could treat the other with more respect instead of furthering division. You will notice I
155.
▲
by
arcfour
6mo ago
"The other side are where all of the bad guys and crazy violent lunatics are. The side I align with is the only sensible one; we would never do anything like that." This sort of thinking causes extremism and division. It only pe
156.
▲
by
arcfour
6mo ago
Begone, AI spambot.
157.
▲
by
arcfour
6mo ago
And yet many people assume malice by default and are unhappy as a result in this day and age. It's unfortunate.
158.
▲
by
arcfour
6mo ago
You can also use SB with your own keys (or even just hashes)...just because Microsoft is the default included with most commercially sold PCs—since most people use Windows on their PCs—doesn't mean SB is controlled by them. You can rem
159.
▲
by
arcfour
6mo ago
Citation for what? The existence of bootkits? Petya/NotPetya, Alureon, Carberp/Rovnix, Gapz, LoJax (firmware rootkit!). All of these attacks would be thwarted by SB (and in Petya's case, simply having UEFI enabled at all, sin
160.
▲
by
arcfour
6mo ago
I (the commenter you responded to) am a security engineer by trade and I'm arguing that SB is useful. I'm not sure if the parent commenter is or isn't a security person but my interactions with other people in the security fi
161.
▲
by
arcfour
6mo ago
So everyday users should be vulnerable to bootkits and kernel-mode malware...why, exactly? That is useful security. The fact that people do not pursue this type of malware very frequently is an effect of SB proliferation. If it were not the
162.
▲
by
arcfour
6mo ago
The attacker does this when the drive is already unlocked & the OS is running. Backdooring your kernel is much, much more difficult to recover from than a typical user-mode malware infection.
163.
▲
by
arcfour
6mo ago
I run Linux with Secure Boot and I don't feel locked out of any media, applications, or websites. My mom uses Secure Boot with Windows and doesn't know or care that it's enabled at all.
164.
▲
by
arcfour
6mo ago
> anyone that cared enough about that specific vector just put their bootloader on a removable media. FDE wasn't somehow enabled by secure boot. Sure, but an attacker could still overwrite your kernel which your untouched bootloader
165.
▲
by
arcfour
6mo ago
But...it doesn't restrict user freedom. If the user wishes to do so, they can disable SB.
166.
▲
by
arcfour
6mo ago
I strongly disagree on the Secure Boot front. It's necessary for FDE to have any sort of practical security, it reduces malicious/vulnerable driver abuse (making it nontrivial), bootkits are a security nightmare and would otherwis
167.
▲
by
arcfour
6mo ago
Their rationale provided for that is safety-based, not infrastructure-based.
168.
▲
by
arcfour
6mo ago
The best part is the comment ranting about how the Wii's CPU is so fundamentally different, and then: > The Wii uses a PowerPC 750CL processor - an evolution of the PowerPC 750CXe that was used in G3 iBooks and some G3 iMacs. Hilari
169.
▲
by
arcfour
6mo ago
Money pays for infrastructure. It doesn't will infrastructure that doesn't exist into existence.
170.
▲
by
arcfour
6mo ago
You can't stop accepting new customers unless you're fine with killing your potential future customer base. That's a ridiculous suggestion. Either your current customers or your potential future customers are going to be unha
171.
▲
by
arcfour
6mo ago
In order to get to space, you must first be capable of flight through the atmosphere. That should be apparent to anyone even then because the atmosphere is in between space and the ground. Regardless of whether spaceflight is still 1000 or
172.
▲
by
arcfour
6mo ago
> I'm not even sure we're any closer to AGI than we were before LLMs. I mean this is very obviously untrue. It'd be like saying we aren't any closer to space flight after watching a demonstration of the Wright Flyer.
173.
▲
by
arcfour
6mo ago
Are you saying that by providing a globally available service, they're engaging in vendor lock-in, because otherwise you'd have to build your own globally available and distributed service...? ...yeah? But if you wanted to run Wor
174.
▲
by
arcfour
6mo ago
Workerd (the platform for Workers) is open source though? You could run your own? And people do run their own, at least according to Cloudflare.
175.
▲
by
arcfour
6mo ago
I introspect all the time. I just disagree with you so I have thin skin? Lol. I think it's transformative. I also think that it's a net positive for society. I lastly think that using freely available, public information is totall
176.
▲
by
arcfour
6mo ago
You're perfectly free to scrape the web yourself and train your own model. You're not free to let Anthropic do that work for you, because they don't want you to, because it cost them a lot of time and money and secret sauce p
177.
▲
by
arcfour
6mo ago
It is exceedingly obvious that the goal here is to catch at least 75-80% of negative sentiment and not to be exhaustive and pedantic and think of every possible way someone could express themselves.
178.
▲
by
arcfour
6mo ago
It prompts for transitive dependencies, too. I have never had workerd as a direct dependency of any project of mine but I get prompted to approve its postinstall script whenever I install cloudflare's wrangler package (since workerd ne
179.
▲
by
arcfour
6mo ago
The prompt would be to approve the new malicious package (plain-crypto-js)'s scripts, too, which could tip users off that something was fishy. If they were used to approving one for axios and the attackers had just overwrote axios'
180.
▲
by
arcfour
6mo ago
PNPM makes you approve postinstall scripts instead of running them by default, which helps a lot. Whenever I see a prompt to run a postinstall script, unless I know the package normally has one & what it does, I go look it up before app
More ›