Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cyphar
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
181.
▲
by
cyphar
1y ago
Go was sold as a "systems language" for a long time, and a lot of people deciding on what language to use in the 2010s made decisions based on that bit of advertising. Rust filled the same niche at around the same time so it'
182.
▲
by
cyphar
1y ago
I do get your point, but in this particular case, it's a quote from Office Space (1999) and while the movie is a comedy, I don't think it's fair to say that it was specifically a joke about or making light of sexual violenc
183.
▲
by
cyphar
1y ago
> I've seen at least a paper trying to bolt-on such a feature on golang but it's way too convoluted. A friend of mine has been working on [1] which is a less computer-sciency solution to the problem for Go modules that doesn&#x
184.
▲
by
cyphar
1y ago
I think there are a handful of cases where it is a nice-to-have and would be sad if it was removed in a hypothetical Go 2. Making a utility wrapper struct that overrides a method or adds new helper methods while keeping the rest of the inte
185.
▲
by
cyphar
1y ago
It also assumes that people who are "good" at the standard code review process (which is tuned for reviewing code written by humans with some level of domain experience and thus finding human-looking mistakes) will be able to tran
186.
▲
by
cyphar
1y ago
I looked at it again and the story is more complicated -- user_access_begin() is actually just a memory barrier on x86 and so doesn't take mmap_sem like I thought. It looks like each get_user() independently checks that the pointer is
187.
▲
by
cyphar
1y ago
I completely agree. You are infinitely more likely to get implicated in some widespread attack due to bugs in GitHub Actions or your automated release scripts than have your local machine's local build and signing infrastructure attack
188.
▲
by
cyphar
1y ago
The kernel doesn't give you SIGSEGV in that case -- you will usually just get -EFAULT. All user pointer accesses are scoped with user_access_begin() and user_access_end() (or something equivalent) which stops the block of data from bei
189.
▲
by
cyphar
1y ago
I think the five-dollar-wrench attack has a similar risk profile to a maintainer introducing a security flaw (intentionally or not) -- unless you are actively auditing the code of your dependencies you are ultimately trusting the upstream m
190.
▲
by
cyphar
1y ago
To be clear, I'm not at all a DANE advocate -- I agree with you wholeheartedly. Even if all of those problems with DANE were magically resolved it would still be an administrative nightmare to manage (especially in a world with short c
191.
▲
by
cyphar
1y ago
While multiple authors' signatures would be nice, a lot of these kinds of attacks would be solved if there was any signature verification being done of the commits, tags, or generated artefacts at all . People like to complain about
192.
▲
by
cyphar
1y ago
You forgot "Take a deep breath. Don't make mistakes. An old lady will die if you misplace a div."
193.
▲
by
cyphar
1y ago
Well sure, that is the argument behind short-lived certs but the current standard (47 days or less) is still fairly long if you think about a targeted attack. You can't refresh your certificates every 2 minutes but you can set the DNS
194.
▲
by
cyphar
1y ago
If the DNS entries for the certificates have a very short TTLs (i.e., 2 minutes) then you wouldn't need explicit revocation infrastructure. It would probably take more than 2 minutes for CRLs or OSCP changes to propagate anyway. (I
195.
▲
by
cyphar
1y ago
You could store the certificate hashes in DNS (i.e., use DANE instead of the CA PKI) and so a MITM on the actual connection wouldn't succeed.
196.
▲
by
cyphar
1y ago
> This may be true in principle but has a very low chance of happening in practice, because there is no current plausible transition path, so it's really just a theoretical debate. Well, DANE exists and provides an obvious transitio
197.
▲
by
cyphar
1y ago
If DNS was presumed secure (i.e., secure against MITM at all points in the chain) you could just stuff the public key into a DNS record (a-la DANE) and remove the need for PKI. I'm saying there would be no need for CAs -- you could jus
198.
▲
by
cyphar
1y ago
If DNS was presumed secure (i.e., secure against MITM at all points in the chain) you could just stuff the public key into a DNS record (a-la DANE) and remove the need for PKI. There would be no need for the authentication provided by CAs,
199.
▲
by
cyphar
1y ago
The server is written in Elixir. https://news.ycombinator.com/item?id=45253390
200.
▲
by
cyphar
1y ago
Because one of the main things TLS is intended to defend against is malicious / MITM'd DNS servers? If DNS was trustworthy then the entirety of TLS PKI would be entirely redundant...
201.
▲
by
cyphar
1y ago
Their point is that if the money held in reserve are proceeds from criminal activity, it is possible for the assets to be seized or frozen by the feds (which would render them no longer backed 1-to-1 even if they were before then). The text
202.
▲
by
cyphar
1y ago
I went through a Japanese ePUB novel I happened to have on hand (the Japanese translation of 1984) and 65% of the bytes are ASCII bytes. So in this case UTF-16 would end up resulting in something like 53% more bytes (going by napkin math).
203.
▲
by
cyphar
1y ago
I disagree, but I think this is a question that could only be answered in court (and probably over several court cases). The end-stage result of your argument would be that copyleft licenses are practically unenforceable because if you just
204.
▲
by
cyphar
1y ago
UTF-16 is absolutely not easier to work with. The vast majority of bugs I remember having to fix that were directly related to encoding were related to surrogate pairs. I suspect most programs do not handle them correctly because they come
205.
▲
by
cyphar
1y ago
Note that the Linux syscall exemption is actually not the license of the entirety of Linux, because most code contributed to Linux is under the standard GPLv2. It's just a red herring -- there is no need for such an exemption because t
206.
▲
by
cyphar
1y ago
I see what you're getting at, but on the other hand there is also a difference between APIs that are intended for use by third parties that are just "regular usage of the program" and internal functions that are being exposed
207.
▲
by
cyphar
1y ago
Sure, that is the point of the original point of the article after all. I was speaking about the problem in general (I suspect most Rust projects--if not most projects in general--with this setup do not have patents). It also requires activ
208.
▲
by
cyphar
1y ago
The FSF considers linking to be a definite example of derived works in general, but I don't believe they consider lack of linking to prove that something isn't a derived work. The goal of the GPL is to flip draconian copyright m
209.
▲
by
cyphar
1y ago
The short answer is copyright law and jurisprudence. The whole purpose of copyleft is to flip draconian copyright regimes over and make them protect users instead, so the GPL generally has the most maximalist stance allowed by copyright law
210.
▲
by
cyphar
1y ago
This is being worked on (they call it AnyRaid), the work is being sponsored by HexOS[1]. [1]: https://hexos.com/blog/introducing-zfs-anyraid-sponsored-by-...
More ›