Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cyphar
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
61.
▲
by
cyphar
4mo ago
> Example: I post “fungame.com” on Show HN, you visit it, and in the background the JavaScript calls Facebook on your behalf (using your Facebook authentication cookie) and adds me as friend. Isn't that what CSRF protections are f
62.
▲
by
cyphar
4mo ago
The vast majority of Japanese and Mandarin speakers are also not in favour of replacing their current writing systems (which give them a link to thousands of years of their own history) in favour of simplified systems. I suspect it is the s
63.
▲
by
cyphar
4mo ago
Well, both give you 6 months of access. Out of interest I applied some time ago and (despite maintaining a few fairly important OSS projects) never got a response from them. Of the other maintainers I know, it seems to me that they decide w
64.
▲
by
cyphar
4mo ago
That already exists[1]. It looks like a joke but apparently they will accept your money to do it, which seems to cross the line of a joke. [1]: https://malus.sh/
65.
▲
by
cyphar
4mo ago
Yeah, 骨 is one but IMHO the best example is 返 -- it renders differently in every CJK locale.
66.
▲
by
cyphar
4mo ago
I'll be honest, I have always found the "trusted" publishing concept quite suspect -- the boiled-down argument is that developers are too incompetent to manage their own keys. Yes, there are obviously problems with storing pl
67.
▲
by
cyphar
4mo ago
> I'm being seen as a Luddite, blind to the advancement Note that the Luddite movement was actually not opposed to the technology itself, but how it would negatively impact workers' rights and textile quality[1]. Many Luddite
68.
▲
by
cyphar
4mo ago
> I’m willing to believe that there is some other code path that thinks that a path like "a/../b" is not allowable, and Claude saw that and wanted to enforce it, and then forgot about it when writing the rest of its
69.
▲
by
cyphar
4mo ago
> - There's a lovely comment in syscall.c:1660-1673 that's quite bad. It's handling strings that contain "/../" and such. If there's some actual contract that the function makes to its callers (an
70.
▲
by
cyphar
4mo ago
> Moxie's prediction tells us that we were "stuck trusting them forever" but er... nope, DigiNotar went bankrupt, StartCom exists only as some branding for the (now distrusted) Chinese company which bought it, and Symantec
71.
▲
by
cyphar
4mo ago
> Despite that, for some reason, these well funded criminal networks keep buying into these weird phone deals instead. I genuinely don't understand why, but they do. Given how many of them have been CIA honeypots, they must have am
72.
▲
by
cyphar
4mo ago
Well-funded criminal networks like the ones in the video you linked would have little issue if all e2ee chat apps disappeared tomorrow, they have enough money and operational incentives to pay someone to make custom encrypted chat apps (not
73.
▲
by
cyphar
4mo ago
> One of Web PKI's security holes is the fact that any CA can issue valid certs for any domain. The only official "mitigation" for that is voluntary and can be defeated. In case you were not aware, Moxie Marlinspike spoke
74.
▲
by
cyphar
4mo ago
Until they shut down the server, which will almost certainly be soon after the certificate expires.
75.
▲
by
cyphar
4mo ago
> The community didn’t need to independently invent godep, then glide, then govendor, then dep, before the core team finally shipped modules. That was just enthusiastic parallel exploration of a problem space that everyone agreed was a p
76.
▲
by
cyphar
4mo ago
There was also Helios 522 where one of the cabin attendants only managed to enter minutes before the engines flamed out, there is a strong argument if the door wasn't locked he could've entered earlier. And my understanding is tha
77.
▲
by
cyphar
5mo ago
They're almost certainly hoping for a Greater Fool.
78.
▲
by
cyphar
5mo ago
It's interesting how some ideas very quickly start popping up everywhere at once. One of my colleagues was working on adding support for fibers to systemd for some time (and the PR was merged a few days ago[1]!). From my understanding,
79.
▲
by
cyphar
5mo ago
> The cascade of AppArmor configs seemed to focus quite a bit on access to `/proc` and `/sys` so I think I mixed that up cgroups with my comments about memory access. Funnily enough that is a good example of how fickle AppArmor
80.
▲
by
cyphar
5mo ago
> If you've somehow bypassed AppArmor and cgroup mechanisms then any UID/GID remapping is irrelevant. At this point you're in a position to directly manage memory. Not really, user namespaces (despite all of the issues tha
81.
▲
by
cyphar
5mo ago
That doesn't actually do anything, connect(2) doesn't need write access to connect to a socket. If you think about it, if that did work then a socket with read-only permissions would be basically useless -- Docker uses HTTP for it
82.
▲
by
cyphar
5mo ago
1. The privilege check in question here is capable(CAP_NET_ADMIN), so it doesn't work in user namespaces. 2. Most sandboxes (including Docker and Podman) disable creating unprivileged user namespaces inside them via seccomp. In this mo
83.
▲
by
cyphar
5mo ago
No, that depends on the kind of privilege check. Some codepaths do ns_capable() (must have capability in owning namespace, reachable via unprivileged user namespaces), some do capable() (must have capability in host user namespace, not reac
84.
▲
by
cyphar
5mo ago
In common parlance, yes -- because there is no practical distinction. But in cases where something is just using the Linux kernel without GNU and other common userpand components (and there is a practical distinction) then it's definit
85.
▲
by
cyphar
5mo ago
The repo you linked works by replacing files that are being used by other privileged containers on the same system. That works for the Kubernetes case (I'm a little surprised they don't use static binaries for their own privileged
86.
▲
by
cyphar
5mo ago
> But splice is a more or less a generalization of sendfile Not really, splice(2) is actually more limited, it's an optimisation for reading and writing data between files and pipes without needing to make copies. sendfile(2) works
87.
▲
by
cyphar
8mo ago
While anyone can run a Tor node and register it as available, the tags that Tor relays get assigned and the list of relays is controlled by 9 consensus servers[1] that are run by different members the Tor project (in different countries). T
88.
▲
by
cyphar
8mo ago
There is a separate carve-out for breaking DRM for the purposes of "interoperability"[1], which (as far as I understand) is generally believed to include emulators. I also disagree more broadly with the initial moral indignation o
89.
▲
by
cyphar
8mo ago
That depends on the country. In Australia, there is an explicit carve-out in the Copyright Act to allow for backups of computer programs[1], and there is also a widely held belief (at least, according to the government) that backups of this
90.
▲
by
cyphar
8mo ago
> Piltdown was rejected 70 years ago, so hardly a current example Well of course it wasn't a current example -- to quote their original comment: > Quite frustrating how archeology swings over the years from "we'll bel
More ›