Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bennofs
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
22 ms
·
121.
▲
by
bennofs
8y ago
Why is a stack machine bad for security? The JVM also had sandboxed execution as a goal and also uses a stack machine. But perhaps the stack machine was choosen because it tends to produce smaller binaries (which is important for things you
122.
▲
by
bennofs
8y ago
Only if it uses proof of work.
123.
▲
by
bennofs
8y ago
Other dep managers could at least tell you about the conflict. Maybe that's what vgo needs, a way to specify a conflict bound so that any downstream user is notified if the depgraph has conflicts (ofc conflict bounds would only apply a
124.
▲
by
bennofs
8y ago
The equavilent in the unix world is gnome keyring (or any other Secret Service spec implementation) unlocked by a PAM module on login.
125.
▲
by
bennofs
8y ago
Pinning does not solve this. You still need a solver to generate new pin versions or update the pinned versions. Or do you manually pin/update each of the dependencies (including transitive ones)?
126.
▲
by
bennofs
8y ago
The thing that worries me about this line of thinking is that as far as I know, we don't know much about why SAT solvers tend to work well in practice. So if I ever happen to hit a problem that the solver cannot solve, all we can say i
127.
▲
by
bennofs
8y ago
Many of the "dynamically typed language" features can be had in statically typed languages as well: there are statically typed languages that have REPls for example. Your point about having higher productivity in the beginning and
128.
▲
by
bennofs
8y ago
I understand your point and I as an Emacs user I also considered moving to something less "heavy" quite a few times. But I am not convinced that something like you describe is actually possible to build and at the same time be les
129.
▲
by
bennofs
9y ago
The counter argument to that is if it causes user anger, then maybe it should not be enabled at all. Also, I am not sure about it adding no security without verified boot - a machine rebooting is something that can be noticed.
130.
▲
by
bennofs
9y ago
With green threads, I think you can have async io but with threads. When your current thread is making an async call, suspend the green thread (cheap) and yield back to the event loop. Threads are woken up when their async call finishes. Th
131.
▲
by
bennofs
9y ago
Welcome to open source maintainership
132.
▲
by
bennofs
9y ago
Are you using stock magit? I think a few of the GitHub integration plugins for example have performance issues, so it may not be Magit's fault but some of the other extension you're using.
133.
▲
by
bennofs
9y ago
What's the problem with matrix plus bridges? I am uniformed, so don't take this question to imply there are no problems
134.
▲
by
bennofs
9y ago
I am a Nix user, but one advantage that Bazel has is that it can do more fine-grained incremental rebuilding (nix as commonly used can only do per-project rebuilds). Also while there is some overlap, Nix usually relies on language-specific
135.
▲
by
bennofs
9y ago
yes, I am also experiencing this. But this is not unexpected: if you take this spectre PoC: https://github.com/crozone/SpectrePoC/blob/master/spectre.c then all that is doing is reading data from the sam
136.
▲
by
bennofs
9y ago
You can only read memory that is mapped in the address space of vulnerable processes with Spectre. Usually, that is only memory from the current process and maybe a small bit of shared memory (and code segments of shared libraries, but thos
137.
▲
by
bennofs
9y ago
I haven't tried it, but I would be very surprised if it yielded good results for go code. Go assembly, from what I've seen, looks very different from the assembly produced by a C compiler. In particular, the calling convention w
138.
▲
by
bennofs
9y ago
This looks really nice, but I think it will be hard to scale for larger binaries that contain significant amount of non-trivial algorithms (and not just copy-pasted stackoverflow answers). But this could still be useful the decompile indivi
139.
▲
by
bennofs
9y ago
Docker is a nice runtime, but you cannot reproduce the build of a docker container. What if you want to make a small change to the image? You need to rebuild it, but if it's years later, the versions of packages in the ubuntu repositor
140.
▲
by
bennofs
9y ago
> I don't think that there are any theoretical concerns about the ability to write a correct borrow checker, just practical issues with the current implementation not correctly handling certain cases. Is it really that trivial? When
141.
▲
by
bennofs
9y ago
Does this prove that the current borrowck rules are sufficient to catch all possible mistakes? For example, does it catch stuff like https://github.com/rust-lang/rust/issues/31287 or https://github
142.
▲
by
bennofs
9y ago
Note that only non-exported functions can be called directly. If you call a exported function, it has to go through the GOT to support redirection (LD_PRELOAD). There's a flag to disable that.
143.
▲
by
bennofs
9y ago
Wouldn't simply caching DNS SRV[1] records do that? 1: https://en.wikipedia.org/wiki/SRV_record
144.
▲
by
bennofs
9y ago
Yes, meltdown only works if the kernel is in the same address space. Also, the kernel maps the whole physical memory as part of its address space somewhere (kernel phyiscal map), so if you can read kernel memory, you can read all phyiscal m
145.
▲
by
bennofs
9y ago
The problem is that it bypasses sandboxes and isolation features... normally, JavaScript running in a VM in a sandbox in your browser cannot read all of your memory. With meltdown, that could be possible. Although for that scenario, you nee
146.
▲
by
bennofs
9y ago
I don't get this. Is caddy so hard to build from source that you'd pay 10$ for a binary? The source code is ASL licensed so allows commercial use.
147.
▲
by
bennofs
9y ago
If you combine index masking with a branch that should still be Ok. For example, if you do `if(idx > arrayLength) return undefined else array[idx & mask]` then the CPU can only predict "return undefined" or "array[idx
148.
▲
by
bennofs
9y ago
> non-turing-complete language like HTML I would be careful about that: It wouldn't suprise me if HTML with CSS (at least with all the new things like animations) is turing complete (it probably is).
149.
▲
by
bennofs
9y ago
Why does a spam system delete packages that have already been in use for quite some time? I could understand if it blocked some newly updated ones, but it seems like it has deleted already existing packages that also were used by other pack
150.
▲
by
bennofs
9y ago
Most package managers I know support Turing complete install hooks. How would a package manager detect what parts of those require/are safe to run with root?
More ›