Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bennofs
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
61.
▲
by
bennofs
7y ago
Runc used by Docker actually does this. The reason is that you don't want /proc/self/exe to refer to any host path when spawning the container process (see https://blog.dragonsector.pl/2019/02/c
62.
▲
by
bennofs
7y ago
You need to consider that flying is still somewhat uncommon, if you consider the whole population on earth. From a quick search on google, less than 20 percent of the world's population took a plane in their entire lifetime.
63.
▲
by
bennofs
7y ago
On the other hand, it also seems implausible to me that the problem can be solved if everyone on the world would produce a few tones of carbon emissions each year by flying. So either flights need to become so expensive that they remain a p
64.
▲
by
bennofs
7y ago
Well, the rest of the code is also correct on its own though. If I tell the function to allocate X bytes, it should either fail or return a buffer that has space for X bytes. If the function returns less than X bytes if X happens to be a la
65.
▲
by
bennofs
7y ago
If you take (1 << 63) + 1 as size (which is a large negative int64), multiply that by 64 and you get 64. So it will call malloc(64) which will succeed. If other parts do the correct unsigned comparison then you have a heap overflow.
66.
▲
by
bennofs
7y ago
The negative number is multiplied by 64, so it can then underflow and become positive again.
67.
▲
by
bennofs
7y ago
I think the point is that most clients probably don't configure the ad-hoc network for you? Or do they?
68.
▲
by
bennofs
7y ago
What schema definition is there for JSON?
69.
▲
by
bennofs
7y ago
You can use Google maps navigation via a web browser
70.
▲
by
bennofs
7y ago
Then distribute it over more than one page.
71.
▲
by
bennofs
7y ago
Also, as I looked a little bit into Keybase I learned that they don't support any protocols that don't have public profile-like pages. So a pure messenger wouldn't be supported by Keybase.
72.
▲
by
bennofs
7y ago
I am not against CAs but even then, what tool do you use? Personal SSL certificates for signing? Except for s/mime I haven't seen this used anywhere
73.
▲
by
bennofs
7y ago
I understand that there are better tools for encryption, but is there anything that replaces the identity management of PGP? Having a standard format for sharing identities is necessary in my opinion. If I have a friend (with whom I alread
74.
▲
by
bennofs
7y ago
King - (Man + Woman) is the same as King - Man - Woman which is not the same as your second example at all.
75.
▲
by
bennofs
7y ago
That doesn't have to be a backdoor. Remember the wave of bugs caused by hardcoded secrets in Cisco hardware? Might just be some leftover debugging account or for service.
76.
▲
by
bennofs
7y ago
But using FCM is enforced by apps. If they would roll their own, no app would work.
77.
▲
by
bennofs
7y ago
What does encrypted/authenticated DNS gain you? If the application protocol is encrypted and authenticated like https then faking DNS responses just results in a connection that is closed immediately because authentication fails. Encry
78.
▲
by
bennofs
7y ago
I don't have a lot of experience with these, but I tested each of them a little bit and know mostly how they work. I believe that for small sites, the main aspect that differs between them is how peer discovery/name resolution is
79.
▲
by
bennofs
7y ago
But there is power to fuel, and I think the main problem with power-to-fuel is energy consumption of the process.
80.
▲
by
bennofs
7y ago
But solar can be much more decentralised than nuclear. So comparing single plants by power doesn't seem fair to me, at the very least you also need to compare costs.
81.
▲
by
bennofs
7y ago
The Argument is that it's bad for the market, as it makes it hard for competitors which aren't part of such a large company and hence need to make profit.
82.
▲
by
bennofs
7y ago
This just looks like it allows to bypass safety checks without marking the code as unsafe. But so do most of the bugs listed in https://github.com/rust-lang/rust/labels/I-unsound%20%F0%9F%... ? What makes this
83.
▲
by
bennofs
7y ago
I might not be your target user base, but that's exactly the opposite of what I would like as an user. I am already forced to update because the current version does not work correctly. Forcing UI/design/any major change (esp
84.
▲
by
bennofs
7y ago
URL parsers also have bugs (or at least don't all agree on one parsing if you rely on more than one parser). Just take a look at https://i.blackhat.com/us-18/Wed-August-8/us-18-Orange-Tsai-... for some fun ex
85.
▲
by
bennofs
7y ago
A big difference is that development of Android is done behind closed doors, whereas for Linux you can observe what is happening in public (discussions on the mailing lists for example). This means that it's essentially impossible to f
86.
▲
by
bennofs
8y ago
If packages are too small it can get hard to understand the code if your not familiar with the structure yet. Working from bottom to top level can work but might also be different because you are missing context for the low level packages t
87.
▲
by
bennofs
8y ago
The halting problem only tells you that there can be no algorithm to prove this automatically for any given program. It could still be the case that for all practically relevant programs there is a proof in each case that they are secure, e
88.
▲
by
bennofs
8y ago
> ... little more than a minor inconvenience of your time This is not entirely correct. I have seen recaptchas that simply deny access without giving any option to solve them when browsing with Tor. The message says something like: autom
89.
▲
by
bennofs
8y ago
Can audit be configured to only log file creation, not modification or access? Last time I didn't find a way to do that and I don't want to write a log file entry for every file access.
90.
▲
by
bennofs
8y ago
I've found secure scuttlebutt (www.scuttlebutt.nz) really impressive. By using public servers called pubs as meeting point they can ignore lots of issues like NAT punching and discovery. I don't like that it seems to be based on a
More ›