Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
chha
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
chha
11mo ago
Been a while since I looked into this, but afaik Maven Central is run by Sonatype, which happens to be one of the major players for systems related to Supply Chain Security. From what I remember (a few years old, things may have changed) th
32.
▲
US spy satellites built by SpaceX send signals in the "wrong direction"
(arstechnica.com)
17 points
by
chha
11mo ago
|
2 comments
33.
▲
Mark Zuckerberg's illegal school drove his neighbors crazy
(wired.com)
2 points
by
chha
11mo ago
|
0 comments
34.
▲
OWASP Top:10 2025 RC1
(owasp.org)
2 points
by
chha
11mo ago
|
0 comments
35.
▲
by
chha
1y ago
It depends. If they simply ignore the ruling, my guess is that whatever trade agreements are in place have a mechanism for escalating such violations so that an Israeli court can enforce the order. I also take for granted that it depends a
36.
▲
NSO permanently barred from targeting WhatsApp users with Pegasus spyware
(arstechnica.com)
7 points
by
chha
1y ago
|
2 comments
37.
▲
by
chha
1y ago
Similar to the Shai Hulud attack, but with more sofisticated C2 (blockchain, Google Calendar). It also uses Unicode characters to hide source code in IDEs, harvests ecosystem credentials to infect and publish new versions of packages you ha
38.
▲
GlassWorm, Self-Propagating Worm Using Invisible Code Hits OpenVSX and VSCode
(koi.ai)
3 points
by
chha
1y ago
|
4 comments
39.
▲
Widespread Supply Chain Compromise Impacting NPM Ecosystem
(cisa.gov)
1 points
by
chha
1y ago
|
0 comments
40.
▲
Anti-vaccine groups melt down over RFK Jr. linking autism to Tylenol
(arstechnica.com)
9 points
by
chha
1y ago
|
6 comments
41.
▲
Aikido Safe Chain
(npmjs.com)
1 points
by
chha
1y ago
|
0 comments
42.
▲
Live updates: Shai-hulud, the most dangerous NPM breach in history
(koi.security)
46 points
by
chha
1y ago
|
3 comments
43.
▲
by
chha
1y ago
There could, this would essentially be in the form of a standard library. That would work until someone decides they don't like the form/naming conventions/architecture/ideology/lack of ideology/whatever else a
44.
▲
Celebrating 50 Years of the Rocky Horror Picture Show
(arstechnica.com)
7 points
by
chha
1y ago
|
0 comments
45.
▲
American musical satirist Tom Lehrer dies at 97
(bbc.com)
2 points
by
chha
1y ago
|
0 comments
46.
▲
Supply-chain attacks on open source software are getting out of hand
(arstechnica.com)
3 points
by
chha
1y ago
|
0 comments
47.
▲
by
chha
1y ago
Fines are based on a number of things; the type of data (PII or Article-9-PII), number of people affected, amount of data, previous violations, and as far as I know also the country issuing the fine. 6.5M might be a small fine by some stand
48.
▲
by
chha
1y ago
It doesn't say audited environments as such, but you are required to use secure environments that you control as a basis. What "secure" means can always be discussed, but in general it depends on what data you process and wha
49.
▲
by
chha
1y ago
> Deliberately extracting personal data into un-audited environments without good reason (eg printing a label for shipping), should be punished with GDPR-style global turnover-based penalties and jail for those responsible. There already
50.
▲
by
chha
1y ago
Sorry for that, guess I'm just too used to the common misconception some people have that the GDPR doesn't apply if a company isn't established in the EU. In this case 23andMe is on the Data Privacy Framework list, so they ha
51.
▲
by
chha
1y ago
Sure they can. GDPR article 2 (2) says: «This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related
52.
▲
by
chha
1y ago
Absolutely. A bunch of them also predated the www, or started just when the www was gaining popularity, meaning that information on possible products might be more limited than it is today. Some have narrow use-cases, and some might have st
53.
▲
Afghans relocated to UK under secret scheme after data leak
(theguardian.com)
3 points
by
chha
1y ago
|
0 comments
54.
▲
by
chha
1y ago
The AI Act classifies systems depending on their capabilities and their intended use, and the risk that they pose on the people using or being exposed to them. If a tool ends up being classified as a high-risk AI system or as a model with s
55.
▲
Browser extensions turn nearly 1M browsers into website-scraping bots
(arstechnica.com)
34 points
by
chha
1y ago
|
15 comments
56.
▲
The Crazy Ant Strike Team XIII – Tales from the Atoll
(talesfromtheatoll.wordpress.com)
3 points
by
chha
1y ago
|
0 comments
57.
▲
RFK Jr.'s CDC panel ditches some flu shots based on anti-vaccine junk data
(arstechnica.com)
11 points
by
chha
1y ago
|
2 comments
58.
▲
by
chha
1y ago
"I think this is the quickest way of clearing my overdraft" That statement from Michael Eavis (founder of the festival) kind of hits home with a recent story from The Independent in how bands are settling for less, or even paying
59.
▲
by
chha
1y ago
Even though this doesn't apply to enterprise customers, I'm just waiting for European customers to wake up and realize that ChatGPT isn't compatible with the GDPR today. And if the court suddenly decides that enterprise custo
60.
▲
by
chha
1y ago
Translated story: https://www-nrk-no.translate.goog/norge/dnb-navnet-misbrukt-... One of the biggest Norwegian banks were used as a cover for a scam in Portugal, involving 2500 ad posters distributed by advertising com
More ›