Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
chc4
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
chc4
2y ago
Your PDS webmaster has a signing key for your repo, because they for all intents and purposes are you. That's the trust structure of how PDS' are setup. If you don't trust someone else to modify your repo don't give th
62.
▲
by
chc4
2y ago
If you are syncing data from another PDS, there is no way to verify that posts have an accurate date, unless you have some central ledger which is antithetical to allowing self-hosting and being distributed.
63.
▲
by
chc4
2y ago
I've wanted to play around with a color ePaper watch for a while, including debating buying an old Pebble Time, so this seems like a great excuse to pull the trigger. For people who have developed apps for them in the past, does everyo
64.
▲
by
chc4
2y ago
It sounds like the hypervisor extensions are more like one-shot payloads, which probably have much less attack surface than normal kernel modules that are exposing new functionality to userspace.
65.
▲
by
chc4
2y ago
A lot of speedruns will not only use specific versions of online patchable games, but old games will have players use specifically Japanese or European physical copies for the same reason: there are glitches that are only present on the Ja
66.
▲
by
chc4
2y ago
Microcorruption is basically just a Zachtronics game, if you squint, which I always thought was a fun framing. Reading the blog posts about Starfighter/Stockfighter definitely made me think of video game style exploits, too, if not the
67.
▲
by
chc4
2y ago
Yeah, there's definitely shades. I think for most games the people who find glitches and drive forward this kind of research usually aren't actually that good of runners themselves. But for TAS runs, where there isn't as much
68.
▲
Speedrunners are vulnerability researchers, they just don't know it yet
(zetier.com)
365 points
by
chc4
2y ago
|
88 comments
69.
▲
by
chc4
2y ago
That's a very cute feature! Thinking about it in terms of thunks makes it pretty understandable to me.
70.
▲
by
chc4
2y ago
> GDB has an extensible, modern C++ codebase with literal decades of hard earned knowledge baked into it. I literally laughed outloud at this. Have you ever actually opened a GDB source file? It is, as a whole, extremely poor quality cod
71.
▲
by
chc4
2y ago
Reverse engineering C# is extremely different from C++ binaries.
72.
▲
by
chc4
2y ago
They aren't clean room. They go based off of disassembly, which doesn't have the same legal defense as true clean room reimplementations. Game hackers have folklore-esque beliefs about the legality of things like this that aren&#x
73.
▲
by
chc4
2y ago
What does that even mean? Relays not being able to arbitrarily edit posts is by design, and why PDS updates like posts are signed by their authors. That's a strength, not a weakness. The mechanism for spam filtering is the same as any
74.
▲
by
chc4
2y ago
CPython merged[0] an experimental JIT compiler into mainline based on the author's previous paper, Copy-and-Patch 0: https://peps.python.org/pep-0744/
75.
▲
by
chc4
2y ago
CHIPS was signed into law in August 2022. The yearly inflation rate for 2023 was 4.12%. Inflation, especially in the wake of the COVID-19 pandemic, was caused by an extremely large amount of different issues and chalking 9% inflation up to
76.
▲
by
chc4
2y ago
Good news! You just described how Bluesky works
77.
▲
by
chc4
2y ago
Anthropic and AI alignment research isn't about making AI that are DnD-style "good alignment", but making AI that have outcomes that are aligned with the goals that the designers intended for them. The chatbot AI model and go
78.
▲
by
chc4
2y ago
I wrote (some) of a Lua interpreter in Rust, which runs PUC Lua 5.1 dumped bytecodes. Now I'm rewrite it all because I want to do type specialization: I'm implementing "Simple and Effective Type Check Removal through Lazy Bas
79.
▲
by
chc4
2y ago
You can mount volumes in your Docker containers: what I usually do is mount my host source directory over the container's source directory, so that changes are immediately visible inside the container, and then hot reloading in e.g. Fl
80.
▲
by
chc4
2y ago
Years ago I had a similar train of thought: Zendesk is used by a ton of companies for their support site, and back then HTTPOnly cookies and javascript site isolation were much less of a thing. I found an XSS bug on Zendesk, which also tran
81.
▲
by
chc4
2y ago
It was one of the worst movies I've ever seen, IMO. It came across like a combination of a high school shakespeare parody and someone retelling The Fountainhead from memory but if they read it five years ago. The story was nonsensical,
82.
▲
by
chc4
2y ago
Love2D has Android support. It's surprisingly easy to setup: https://github.com/love2d/love-android
83.
▲
by
chc4
2y ago
Ghidra embeds Python scripting via Jython, which is stuck on Python 2. Switching to GraalPy would allow Python 3 scripting. Any other Java programs that want a scripting engine could use it as well.
84.
▲
by
chc4
2y ago
Was it very shocking when you woke up today and found yourself transported from the year 2000, when Moore's Law still held?
85.
▲
by
chc4
2y ago
I'm under the impression Intel's 3D XPoint/Optane memory was based off the same process used for memristors.
86.
▲
by
chc4
2y ago
That's not really how out-of-order execution in CPUs work. The address doesn't have to be fully computed X cycles before a load in order to be filled. Loads are filled as their dependencies are computed: requiring an additional op
87.
▲
by
chc4
2y ago
You opt-in to any of the top byte masking schemes via prctl on Linux. It's fully forward compatible, in that programs that don't enable it will continue to work like normal. Additionally, Linux won't map memory at addresses h
88.
▲
by
chc4
2y ago
> Currently, ARM is the only major vendor with support for TBI is not true. Intel and AMD both have variants of TBI on their chips, called Linear Address Masking and Upper Address Ignore respectively. It's a bit of a mess, unfortuna
89.
▲
by
chc4
2y ago
I'm under the impression enclave keys have been extracted before, and Intel was able to mitigate by essentially publishing a key revocation update that made models with the extracted keys not be trusted for remote attestation. Is that
90.
▲
by
chc4
2y ago
The point of a JIT is to optimize code that is, roughly, the largest percentage of program time. Most programs follow a power distribution where there is some very important code that is ran a lot, with a lot of code that isn't ran ver
More ›