Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
csirac2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
23 ms
·
181.
▲
by
csirac2
12y ago
I dare you to tell my why lxc-docker silently fails to start at boot in jessie. Without a single shred of clue in any log, no matter what logging options are turned up - at least with a shell script I can add some echo/exit/touch
182.
▲
by
csirac2
12y ago
What prompted me to reply was when you said "Regardless, it doesn't matter. It's simply ignorant to bitch about this, when the NSA literally intercepts all of this and exploits or introduces exploits into the software you use
183.
▲
by
csirac2
12y ago
Is this where we are now? Patting Apple & friends on the back for sneaking in just a little bit more data scrapage, because surely the only people who think they have a choice are just idiots? I'd rather be an idiot who gets angry
184.
▲
by
csirac2
12y ago
True. The real problem is if you use a hash that's not designed for protecting passwords and can be computed at a rate of millions/billions per second on commodity hardware - versus s-crypt & friends which should only allow fo
185.
▲
by
csirac2
12y ago
It seems extremely light on actual science. It's been a couple of years since I worked with biologists but dealing with false positives with this type of thing (well, GeneChips anyway), specifying suitable probe sets, getting the exper
186.
▲
by
csirac2
12y ago
I'd say the reasoning is that you then have to trust there are no privesc/bypass opportunities in your environment. Trusting that all your dbus/pulseaudio/network-manager/cups/fuse/display manager & fr
187.
▲
by
csirac2
12y ago
From what I've been hearing they seem to already have big customers using it. I wonder if it'll ever be available to individuals and small businesses. It's pretty cool in that it appears to have some tripwire-esque stuff so t
188.
▲
by
csirac2
12y ago
Not just apps, it even routes physical USB devices to specific VMs, which potentially mitigates BadUSB type attacks against the dom0. And I really appreciate that they've tried to solve XDMCP weaknesses.
189.
▲
by
csirac2
12y ago
I was under the impression they would continue to use the existing channels of obtaining DHCP logs from ISPs as before (i.e. subpoenas), but the changes were aimed at some ISPs not retaining more than eg. last 7 days logs, or last 30 days&#
190.
▲
by
csirac2
12y ago
I spent four years mostly on perl 2009-2012, and again briefly last year. The performance of any non-trivial perl web app is laughably bad when you run as CGI. I've never run prod systems without psgi or mod_fcgid.
191.
▲
by
csirac2
12y ago
Not all the time, I must admit - but when I'm blindly poking my phone or it's just grabbed out of my pocket, some part of the screen (that for me is the most likely part) makes the swipe prompt disappear and is replaced with the p
192.
▲
by
csirac2
12y ago
I agree with most of your post. His attitude toward keyscript users is less than inspiring. But I still try - yesterday I spent 4 hours tweaking my VM builds against debian sid; by the end I had found a way to segfault systemctl, filed a bu
193.
▲
by
csirac2
12y ago
But wait a minute - didn't risky.biz' Patrick Gray originally report that the AFP clarified that the "Metadata retention" amounts to merely formalizing the retention of DHCP logs? I mean, there's heaps of shitty thi
194.
▲
by
csirac2
12y ago
Obviously, a strong passcode is a must. But that's a big ask not just for the obvious reason, but also because the Nexus 5 is the first phone I've ever owned which demands that I unlock it first before I can access the UI to cance
195.
▲
by
csirac2
12y ago
Sounds like it was a fun journey. Don't forget to figure out how to make ccache work in your cross-compiler toolchain... it doesn't always speed things up that much (I have some projects that seem to spend more time linking than c
196.
▲
by
csirac2
12y ago
This is a great article. Just this year I've become partially involved in hardware design again after some years now doing mostly just software - it's amazing how cheap fab options are these days! I recently got a few quotes for c
197.
▲
by
csirac2
12y ago
1) Since the mid-90s Apache and similar http servers have offered fastcgi as a way of communicating with processes with sockets. So you can understand why hearing you single out apache to "use a more secure IPC like sockets" detra
198.
▲
by
csirac2
12y ago
There's a lot of Apache hate here but I have to wonder if you've actually used it. Anyone stuck running cgi stuff with apache invariably goes to fastcgi or mod_fcgid for performance reasons, which already uses a unix domain socket
199.
▲
by
csirac2
12y ago
Where in the CGI spec does it say anybody has to eval anything?
200.
▲
by
csirac2
12y ago
Your response sounds like blaming the world's oldest webserver for being the world's oldest webserver. CGI sucks, but telling the 1990s to go home and not come back until it has a secure mechanism of IPC just isn't helpful: t
201.
▲
by
csirac2
12y ago
Only for amd64 though, ctrl+f for "4.3-9.1": http://ftp.debian.org/debian/pool/main/b/bash/
202.
▲
by
csirac2
12y ago
There's netlist files for schematics, but they're a bit raw to do by hand... Each PCB design package has its own programming language, here's an example of what you can do with Eagle's ULP: http://irq5.io/
203.
▲
by
csirac2
12y ago
Agree, I'm 80% software these days but ~8 years ago I discovered Eagle and found it was a huge relief at the time coming from Protel (now Altium). I've been getting my feet wet again; perhaps Altium has fixed the UX which drove me
204.
▲
by
csirac2
12y ago
(em)debian provides nearly enough of what I need most of the time. The trigger for going to a ARM chroot is when I can't get build dependencies installed properly on an amd64 host. Either that or the thing I'm compiling just isn&#
205.
▲
by
csirac2
12y ago
They've got a lot of idiosyncrasies at the moment, some of it working around the fact ADD some/directory/ could never be cached (so my build scripts maintain some.directory.tar.gz and those are ADDed instead), but I really sh
206.
▲
by
csirac2
12y ago
I (or rather, jenkins) builds all my software in it, I don't actually use it for containerizing final applications. In a nutshell, for me the value is in trivial repeatability. I can reproduce the entire build toolchain, test environme
207.
▲
by
csirac2
12y ago
There have been at least a few kernel privesc vulnerabilities, for example, which have apparently been mitigated successfully with SELinux (I assume that the SELinux policies prevent the necessary pre-conditions of the exploit being met, li
208.
▲
by
csirac2
12y ago
Assume an environment where VMs are already used for rough isolation... If we wanted to further lock down VM guests (and hosts for that matter), and SELinux is too cumbersome - does AppArmor or grsecurity strike a significantly better balan
209.
▲
by
csirac2
12y ago
This is perhaps the wrong place to discuss, but reading Noah's piece you just linked seems just a little narrow-minded... Given the struggles I see to recruit and retain contributors (who overwhelmingly $work to 17:30 and take school h
210.
▲
by
csirac2
12y ago
I'm a fan of btrfs, but it's too easy to crash btrfs send/receive. Slowly, it gets better and better though.
More ›