Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
corvad
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
61.
▲
by
corvad
5mo ago
Ah that makes more sense I was kind of confused by that.
62.
▲
by
corvad
5mo ago
AI right now feels like the go to for anything and everything that was tedious for humans to do or that took quite a bit of expense. What people seem to struggle to realize is that those exact things that they offload to AI are exactly what
63.
▲
by
corvad
5mo ago
Yes, agreed these are very different things. Also I'm not really sure the argument holds, there are plenty of AWS Command and Control hosted servers and AWS victims, is AWS to blame or blackmailing? The answer is a large no.
64.
▲
by
corvad
5mo ago
Many projects kind of take a different approach where for pull requests CI is not run until approvals from maintainers are given even for very simple jobs to avoid untrusted code running in ci.
65.
▲
by
corvad
5mo ago
At least my naive brain wonders if blocking force pushes to main would have stopped this as it is a setting in Github these days, unless I am misunderstanding the final attack vector since it seems it was force pushed.
66.
▲
by
corvad
5mo ago
Yes, but the exploit was with Github Actions not something that pnpm really prevented.
67.
▲
by
corvad
5mo ago
I'm not quite sure of what this really accomplishes, like is it just M.A.D.? Like at that point the creds have been stolen and the whole machine is toast.
68.
▲
by
corvad
5mo ago
It's always East 1... Jokes aside I don't understand how often east-1 is taken down compared to other regions. Like it should be pretty similar to other regions architecture wise.
69.
▲
by
corvad
5mo ago
I mean yeah, but the Pi Zero can also do TLS and much more complex tasks so I really don't understand why this is such a big "feat." It's a linux pc just running a webserver. Am I missing something here?
70.
▲
by
corvad
5mo ago
Some instances seem to be recovering. I wonder if a ransom was paid.
71.
▲
by
corvad
5mo ago
Just learned the defacement page was hosted from instructure's own aws bucket so seems pretty bad.
72.
▲
by
corvad
5mo ago
Once we hit 8h 45m SLA has been broken. https://uptime.is/99.9 https://www.instructure.com/trust-center/availability
73.
▲
by
corvad
5mo ago
The "Scheduled Maintenance" is just total B.S. and just honestly makes them look worse. Apparently according to their status pages this is what 99.996% uptime looks like. Pay attention lol.
74.
▲
by
corvad
5mo ago
Yeah like their page says "Scheduled Maintenance" which is total B.S. Talking to people at my university's IT side of things Canvas has said nothing to any clients.
75.
▲
by
corvad
5mo ago
Ransom paid?
76.
▲
by
corvad
5mo ago
I believe Canvas was also sold to private equity pretty recently too. https://www.instructure.com/press-release/instructure-to-be-...
77.
▲
by
corvad
5mo ago
Canvas is handling this terrible. No communication, no status updates, etc. Also looks pretty bad their whole platform was compromised and not a single real report for the breach that already had happened. Wonder how long it will take for S
78.
▲
by
corvad
5mo ago
Security through obscurity is bad. Security AND obscurity is fine. There's a very clear distinction here.
79.
▲
by
corvad
5mo ago
Yes, but also one less anything in a highly competitive industry is a bad thing overall. Not saying I think it's a good idea but I seem a grain of reasoning behind it however misleading it might be.
80.
▲
by
corvad
5mo ago
Agreed, a median would be a better indication.
81.
▲
by
corvad
5mo ago
I'm not sure that's even noble as by buying you would be a shareholder...
82.
▲
by
corvad
5mo ago
Yeah it honestly seems like an opportunity scam.
83.
▲
by
corvad
5mo ago
I get the idea but this seems very much something not credible, like who's behind it, what are the guarantees, etc.
84.
▲
by
corvad
5mo ago
The UI reminds me quite a bit like https://www.numworks.com/calculator/apps/
85.
▲
by
corvad
5mo ago
Agreed, this should really be the standard for marketing materials, no flashy promises, just cool technical and curious details.
86.
▲
by
corvad
5mo ago
I won't miss the nickel and diming that's for sure...
87.
▲
by
corvad
5mo ago
XZ Utils was a big example of this, the poor maintainer had to put up with toxic users and it led to supply chain compromise after a while.
88.
▲
by
corvad
5mo ago
My best guess is lack of resources and that they want to focus on the well known PR workflow instead of trying new things out of the gate. It's exactly that, it's a proven github workflow for better or for worse that most people a
89.
▲
by
corvad
5mo ago
This was an amazing read for me, so much so I bought the book and am enjoying reading it. It's quite an interesting read and I'm learning quite a bit more than I knew about the mission EFF stands for.
90.
▲
by
corvad
5mo ago
Warp didn't start out as AI, IIRC they started with auto completing terminals.
More ›