Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bjackman
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
91.
▲
by
bjackman
4mo ago
Yeah I actually advocate for dropping to assembly quite a lot in BPF: - portability isn't a concern - BPF ASM syntax is quite readable - it can often let you write simpler code by directly doing what the verifier needs instead of danci
92.
▲
by
bjackman
5mo ago
FWIW uBlock Origin for Firefox on Android works fine here.
93.
▲
by
bjackman
5mo ago
I think his agenda here is to point out that your probability distribution for AI outcomes should be broad (what you said), but most importantly: this means you must take seriously the possibility that we are gonna get superintelligence qui
94.
▲
by
bjackman
5mo ago
> similar to a macOS experience but built on a standard Linux foundation. From a security perspective, this cannot exist. MacOS is fundamentally superior to classical GNU/Linux distros. Android/ChromeOS are the only Linux syste
95.
▲
by
bjackman
5mo ago
It's very common, I believe all the Big Tech firms have you write code. I think the example from my story was the only one I've had where I had to _read_ code. (I have heard of people doing "code review interviews" thoug
96.
▲
by
bjackman
5mo ago
I once had a job interview where they wanted to evaluate my C knowledge. They showed me a printout of some pointer arithmetic and said spot the bug. (It may actually have been the old puzzle where it turns out that /* is always a comme
97.
▲
by
bjackman
5mo ago
Yes that is what i mean, anyone can do it technically, but they are gonna have to build a slightly crappy OS in order to do it. But still, better multiple slightly crappy OSs instead of just one (plus Apple).
98.
▲
by
bjackman
5mo ago
There is a fundamental tension here though - suppose DMA or something requires that online providers recognise reCAPTCHAs from non-Google-attested OS builds. What OSs can they safely trust? Only ones that are difficult for fraudsters to use
99.
▲
by
bjackman
5mo ago
Linux does actually have a proper embargo process. But, you're correct that in this case it wouldn't usually have been followed anyway. Bugs like this are fixed multiple times a week, anyone with basic kernel knowledge can see tha
100.
▲
by
bjackman
5mo ago
Updating your kernel isn't good enough, it never was. Native unsandboxed execution == root. Only thing that's new is some people started making websites for their LPEs. https://github.com/google/security-resea
101.
▲
by
bjackman
5mo ago
Well, there's still value in users and namespaces! Just, it's not a strong security boundary. Also even if it's not strong, it doesn't mean it's entirely worthless. You can't rely on it, but it's usually f
102.
▲
by
bjackman
5mo ago
Look at kCTF results. Look at the CVE database. Most of those UAFs are LPE. Many of the OOBs and many of the race conditions too. These are fixed in Linus' master but you are running an old kernel. Then look at the KASAN reports on the
103.
▲
by
bjackman
5mo ago
Yes but what I'm saying is that copy.fail is a minor detail in this scenario. If you are running Ninja Forums you need to run it in its own VM so that if it gets compromised _you don't care if it has uid=0_. You need to do that r
104.
▲
by
bjackman
5mo ago
Yeah you need native code execution, and if you have AF_ALG access there is clearly no sandboxing in place. At that point it's game over on Linux, there are too many bugs. Even if you fix all the known ones in the current kernel, by th
105.
▲
by
bjackman
5mo ago
It's not RCE it's an LPE in an obscure corner of the kernel attack surface that no sensible application depends on. They are absolutely a dime a dozen. Even just in AF_ALG there have been several such vulns fixed in 2026 already.
106.
▲
by
bjackman
5mo ago
If you can access AF_ALG on a server you don't need to do shenanigans like that. It's much easier to just find another bug and exploit that one instead. The copy.fail website is very silly, it is not a special bug. If anyone gets
107.
▲
by
bjackman
6mo ago
99% is usually the best you can do. So you can only layer multiple defences together, this makes sense as one layer to me. I have an issue with security layers that are inherently nondeterministic. You can't really reason strongly abou
108.
▲
by
bjackman
6mo ago
Not just with human lives but with staggering amounts of economic growth. In a globalised system there's absolutely no way the stimulation of war pays for the destruction and disruption.
109.
▲
by
bjackman
6mo ago
> And to agree with others on this thread, the folks who push for war should 100% be required to participate in them and lead from the front I agree but I don't think it goes far enough. Leading from the front of the best equipped m
110.
▲
by
bjackman
6mo ago
You can use a reverse proxy and still have working app auth, I have set this up via Authelia with the OIDC Jellyfin plugin. However: - This is EVEN MORE complex than "just" a reverse proxy. - I'm not really sure it wins much
111.
▲
by
bjackman
6mo ago
Damn that's interesting I have not run into that at all after about 4 years. Maybe it's just that my site is extremely dumb? I forked an "ultra minimal" theme and deleted most of its code. So perhaps I just use such a ti
112.
▲
by
bjackman
6mo ago
Ha, I had a similar story with Jekyll but my build wasn't containerised. At some point it stopped being compatible with the latest [something. Ruby? Gems? I don't care, just build my fucking HTML templates please] so I just migrat
113.
▲
by
bjackman
6mo ago
Nice work! Really low frame rate on Firefox on Android (pixel 10), might be something worth checking.
114.
▲
by
bjackman
6mo ago
To me this was just the cherry on top though, there's a huge list of such correlations that seem wildly unsurprising.
115.
▲
by
bjackman
6mo ago
The article itself acknowledges that the headline is bullshit: > The change isn't about the core operating system becoming resource-hungry. Instead, it reflects the way people use computers today—multiple browser tabs, web apps, and
116.
▲
by
bjackman
6mo ago
If this really works there would seem to be a lot of alpha in running the expensive model in something like caveman mode, and then "decompressing" into normal mode with a cheap model. I don't think it would be fundamentally v
117.
▲
by
bjackman
6mo ago
Don't think those people need robots? I don't think the next bracket up from me does their own laundry today.
118.
▲
by
bjackman
6mo ago
Trust me, plenty of millionaires are doing their laundry in a shared Waschküche in Zürich! Current Chinese dev bots cost like $15k. Vapourware startups are claiming they'll ship their humanoid robot product at $20k. I'd pay that i
119.
▲
by
bjackman
6mo ago
IIUC dexterity is gonna be the bottleneck. There was actually a post on here a few months back where someone claiming robotics expertise posted exactly what you asked for: a list of things they didn't think robots were close to being a
120.
▲
by
bjackman
6mo ago
I wonder if we'll start to see gimmicks in home appliances for taking advantage of variable prices. Like for EV charging I assume it's a basic requirement, you simply wouldn't buy a car that didn't let you adjust the cha
More ›