Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cyphar
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
211.
▲
by
cyphar
1y ago
Great, but Unlicense doesn't grant patent rights so you have the exact same problem as MIT (actually it's even worse because Unlicense explicitly states that it is only concerned with copyrights multiple times).
212.
▲
by
cyphar
1y ago
Sure, if you have a patent. If you don't and the patent shield is intended more as pre-emptive protection then MPLv2 or GPLv3 are better.
213.
▲
by
cyphar
1y ago
If you do this, you need to have a very explicit policy for contributors to say they are contributing under both licenses, though this is something you need to have anyway if you are licensing under Apache 2.0 (a contributor could theoret
214.
▲
by
cyphar
1y ago
I re-read the text again and it's even worse than the Facebook one -- the entire license terminates in reaction to any litigation, not just patent litigation. Hypothetically, a former employee suing Supabase for violation of workers&
215.
▲
by
cyphar
1y ago
You need to read the text more carefully -- the license terminates for any litigation against Supabase at all. Hypothetically, a former employee of Supabase suing them for some employee rights violation would no longer be allowed to use t
216.
▲
by
cyphar
1y ago
A common issue with open source patent licenses is that they cannot grant blanket patent rights from contributors without some limitation around modifications, as it would allow someone to trivially render all of contributors' patents
217.
▲
by
cyphar
1y ago
MPLv2 has a stronger version of this (I also personally prefer it in general to Apache-2.0 if you can't stomach GPLv3).
218.
▲
by
cyphar
1y ago
The whole patents kerfuffle with Facebook was about a larger issue with their patent grant. Critically the issue was that it practically stopped you from suing Facebook for any patent issues (not just those granted for React, which would
219.
▲
by
cyphar
1y ago
The handle solution is definitely better (which is why I mentioned pidfds -- I actually think it might be possible to do this today with SIG_IGN and PIDFD_GET_INFO but it's a little hacky) but Unix only had pids and most descendants on
220.
▲
by
cyphar
1y ago
I agree, but I really wonder where on earth they find these people.
221.
▲
by
cyphar
1y ago
If only, it would've been an honour to get phished by Mitnick. Rest in peace...
222.
▲
by
cyphar
1y ago
A few years ago our annual corporate phishing training was initiated by an email sent from a random address asking us to log in with our internal credentials on a random website. A week later some executive pushing the training emailed the
223.
▲
by
cyphar
1y ago
> v29.0 will have support for nftables. It'll be marked as experimental in the first few releases to allow us to change anything without worrying about backward compatibility. It would've been nice to at least link to the EPIC[
224.
▲
by
cyphar
1y ago
> This is not my area of expertise but this is omitting that user namespaces tend to drastically increase the attack surface (despite what some vendors say). Configuring user namespaces for the container to improve containment = very go
225.
▲
by
cyphar
1y ago
On the other hand, process managers care about the exit signal of child processes and the most straightforward way is to keep around a zombie that just contains that information and ensures the only identifier available to userspace at the
226.
▲
by
cyphar
1y ago
> There needs to be a point where enough is enough, and locking down devices so that you cannot install programs nor practically use custom operating systems on them anymore is way past that line. That is to say, banks are not the only e
227.
▲
by
cyphar
1y ago
And much easier to copy elsewhere or memorise (not that I would recommend the latter).
228.
▲
by
cyphar
1y ago
Unfortunately, this kind of thinking leads to insane situations such as the South Korean banking cartel which requires users to install several pieces of "security software"[1] which make your computer more vulnerable to securit
229.
▲
by
cyphar
1y ago
Presumably they're referring to Google's plans to roll out developer signing requirements for all apps[1], which will affect F-Droid-installed apps. [1]: https://news.ycombinator.com/item?id=45017028
230.
▲
by
cyphar
1y ago
Code reviews (especially internal ones) generally assume that the person writing the original code has an idea of what they are doing and are designed to catch mistakes that humans might make. Just because they probably work to improve code
231.
▲
by
cyphar
1y ago
Maybe I'm the outlier here, but I think intentionally torrenting millions of books and taking great pains to try to avoid linking the activity to your company is far beyond something as "trivial" as ignoring robots.txt. This
232.
▲
by
cyphar
1y ago
Ah, so the NSA defence then -- "it's not bulk collection because it only counts as collection when we look at it".
233.
▲
by
cyphar
1y ago
Which part of this comment: > Maybe the article is dumbing it down too much, but the conclusion seems unsurprising. Why shouldn't a single unknotting do double-duty in some cases? is them "explicitly stat[ing] they might be mis
234.
▲
by
cyphar
1y ago
No, the point is to stop Amercian technology companies from providing technology to Russian entities. From the perspective of sanction laws, accepting patches (or arguably even replying to emails) from sanctioned entities is effectively pro
235.
▲
by
cyphar
1y ago
0) They do. 1) They could just adapt MPL-2.0, which provides GPLv2+ compatibility while still providing the same patent grants. 2) The upgrade is chosen by downstream users. The OpenZFS project could ask individual contributiors to choose t
236.
▲
by
cyphar
1y ago
Even the smallest nations have the legal right to permanently incarcerate, strip you of your assets or even murder you if you are in their sphere of influence. I would hope you'd agree those are not powers that we should grant to large
237.
▲
by
cyphar
1y ago
Oracle is the license steward for CDDL, they have the right to release CDDL-2.0 and make it GPL-compatible which users would then be allowed to chose to use. Mozilla did the same thing with MPL-2.0 (CDDL was based on MPL-1.0), though the de
238.
▲
by
cyphar
1y ago
The Software Freedom Conservancy did a legal analysis and concluded that the incompatibility comes from both sides[1]. This also applies to the pre-2.0 MPL that CDDL was based on. A lot of people focus on the fact that the CDDL allows binar
239.
▲
by
cyphar
1y ago
Yes, the trust model for TLS is broken and the handful of attempts made to fix it (Moxie's "Convergence" project from 2011[1], for instance) haven't born fruit. However, in a security context "takes some effort"
240.
▲
by
cyphar
1y ago
You're replying to the bcachefs author, I expect his response will be fairly obvious. ;)
More ›