Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
codethief
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
codethief
1mo ago
> First, a TUI is usable with only the keyboard. Is it? Many TUIs these days don't allow me to configure my usual key bindings for moving my cursor within input fields. Meanwhile, GTK offers (used to offer) a way to customize key bi
32.
▲
by
codethief
1mo ago
This was what stood out to me, too! And this: > Packfiles are the fundamental building block of Git storage and Git networking. (emphasis mine) > His approach was storing the objects in a distributed hash table. This was only possi
33.
▲
Agentic Engineering at Zalando: A Snapshot
(engineering.zalando.com)
3 points
by
codethief
1mo ago
|
0 comments
34.
▲
by
codethief
1mo ago
Ah yes, so if I understand correctly, you're referring to the fact that, e.g., on Linux a typical Secure Boot setup will verify the kernel (if at all) but not the rootfs. Yes, that's of course a huge issue (as is mutability of the
35.
▲
by
codethief
1mo ago
Agreed, I was excited about this until I found To get started, sign in with Vercel: fx login in the README on Github.
36.
▲
by
codethief
1mo ago
> The approach used by desktop operating systems with TPMs is awful and makes security worse in a lot of ways rather than better. It's not at all the same thing, similarly to how what the desktop world calls secure boot is not a ser
37.
▲
by
codethief
1mo ago
Sure, the form of the function being maximized will usually depend on the environment.
38.
▲
by
codethief
1mo ago
> It maybe can be, but what is the maxima that is being solved for exactly? Survival rate/reproduction rate/rate of genes being spread?
39.
▲
by
codethief
1mo ago
Yes, though since it's a "micro" VM, it shouldn't take up nearly as many resources as a regular VM. Some hypervisors also implement memory ballooning to not take up memory that's not being used, but I'm not sur
40.
▲
by
codethief
2mo ago
Exactly! As I've argued here on HN before, such an "LLM in a box" might end up being serviced/upgraded once or twice a year by a company very similar to the one servicing the coffee machine at the office. In contrast to
41.
▲
by
codethief
2mo ago
While I agree that a proprietary solution is not great and personally I'd avoid it, too, I am getting https://news.ycombinator.com/item?id=9224 vibes. :-)
42.
▲
by
codethief
2mo ago
As the sibling said, Docker Sandbox is not based on standard Docker containers. It spawns micro VMs.
43.
▲
by
codethief
2mo ago
This is not really an alternative if you care about the security of your host system. Docker Sandbox uses micro VMs for a reasons.
44.
▲
by
codethief
2mo ago
Bubblewrap is not nearly as secure as a proper VM.
45.
▲
by
codethief
2mo ago
It is supported on Linux… https://docs.docker.com/ai/sandboxes/#get-started has instructions for Ubuntu.
46.
▲
by
codethief
2mo ago
> So what "sandboxing" does this add that is not already present in Docker Docker Sandbox spawns a micro VM, not a standard container isolated by host kernel mechanisms (Linux namespaces etc.)
47.
▲
by
codethief
2mo ago
> supports acceleration with WHP On Windows 11, too? At least for hardware virtualization in VMWare one would have to disable Windows Device Guard & Credential Guard for that.
48.
▲
by
codethief
2mo ago
> Does anyone have a better alternative? Not necessarily better but OpenSandbox[0] by Alibaba seems similar. [0]: https://github.com/alibaba/OpenSandbox
49.
▲
by
codethief
2mo ago
Do you mean like Docker has supported for years…? (Just configure krun as Docker's OCI runtime.) Obviously, there's a reason why Docker released Docker Sandbox as a separate product: - Barely anyone bothers to configure Docker
50.
▲
by
codethief
2mo ago
Yes, you can run Podman with different OCI runtimes, in the same way as you can run Docker with different OCI runtimes, and some of these OCI runtimes are microVM-based. This is not what the person I was responding to is doing, though. As f
51.
▲
by
codethief
2mo ago
That's not correct. Virtio devices have different security properties and many of them expose the host system to considerable risks. Using containerization on the host is one way to limit the latter. See e.g. https://github.
52.
▲
by
codethief
2mo ago
I'm afraid I don't want my sandboxes to live in the cloud, though. :-)
53.
▲
by
codethief
2mo ago
To everyone sharing their favorite container-based sandboxing solution: Docker Sandbox does not use containers for isolation. It spawns the workload in a libkrun-based micro VM, which has vastly different security properties.
54.
▲
by
codethief
2mo ago
Yes, pretty much, except for one detail: > That runs the codex OCI in a qemu microvm. AFAIU it's actually the other way around: krun spawns a libkrun-based (not QEMU-based) VM inside a crun container. Source: https://gith
55.
▲
by
codethief
2mo ago
> exactly this This is nowhere near "exactly this". Docker Sandboxes uses micro VMs, you just use regular containers which have completely different security properties.
56.
▲
by
codethief
2mo ago
In my experience it's mostly the UX/DX where Gondolin is lacking. For instance, I don't want to set up a JavaScript project every single time I need a sandbox. Instead, I just want to place a config file somewhere in my repo
57.
▲
by
codethief
2mo ago
Agreed, bad posture (not just neck but in general) can cause both tinnitus and RSI-like symptoms in my experience and I have been able to tackle both with proper exercising. Where I don't agree is the following: > Turns out the proc
58.
▲
by
codethief
2mo ago
I came here to ask this, as well! Where does that tension come from and the relief one feels after cracking? People keep saying it's built-up gas but that doesn't really explain why we feel so much relief after cracking. (Not just
59.
▲
by
codethief
2mo ago
> They seem optimally designed to ensure that you'll have glare on your screen no matter how you position it in any kind of well lit environment. At work we have dozens of curved monitors by Dell. Not once have I seen glare on them.
60.
▲
by
codethief
2mo ago
Yesterday[0] I learned that supernovae can be driven by Kevin-Helmholtz instabilities, so when I saw the title I was already getting worried. :) [0]: https://news.ycombinator.com/item?id=49198503
More ›