Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
danieldk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
46 ms
·
421.
▲
by
danieldk
7y ago
Why are the macOS and Windows versions are unsigned?
422.
▲
by
danieldk
7y ago
If The Qt Company discontinued the FOSS version of Qt, the Qt framework would become available under the BSD license, and there would no longer be a contributor licence agreement allowing a company to sell the work of another company. But
423.
▲
by
danieldk
7y ago
For instance, you could run your package manager across all containers to see if they have packages with known CVEs. Or manage the filesystems of all containers on the system (the usefulness of this is only clear with filesystems like ZFS
424.
▲
by
danieldk
7y ago
I just like fresh bread without all the work ;). With a good bread machine, you only have to mix the ingredients (or purchase a nice mix) and the machine does the work for you. Ours never failed baking a good bread (except for the one tim
425.
▲
by
danieldk
7y ago
If we had 10x as many ventilators, and 100x as much protective equipment, this would be less dangerous. Only up to some point, then you run out of specialized personnel who know how to properly treat each patient (including controlling sa
426.
▲
by
danieldk
7y ago
That was not broken. What was broken was origin validation in Safari. There is a difference between a vulnerability in the OS permissions system (which this was not) to control mic/camera permissions and a vulnerability in an applica
427.
▲
by
danieldk
7y ago
Me neither, but I also wonder how many non-expert users actually know that it is available. There is the initial dialog about Siri when setting up a Mac. After that, it is not that prominent. Moreover, it's a bit embarrassing to use in
428.
▲
by
danieldk
7y ago
The problem is that otherwise "Hey Siri" wouldn't work on (newer) Macs. Still, you can use something like Micro Snitch to track webcam/mic use. Also, in macOS Catalina (I don't remember if this was the case in prior
429.
▲
by
danieldk
7y ago
Also, the Mic is disconnected in hardware when you close the lid: https://support.apple.com/guide/security/hardware-microphone...
430.
▲
by
danieldk
7y ago
There is also Micro Snitch from the makers of Little Snitch: https://obdev.at/products/microsnitch/index.html
431.
▲
by
danieldk
7y ago
I think subscriptions will be terrible for vendors in the end as well. First, because they have to compete with the likes of Office 365, which offers an Office Suite, 1TB cloud storage, and 60 Skype minutes (at least the used to) for little
432.
▲
by
danieldk
7y ago
but neither do the maintenance costs. That depends. On macOS the churn is high. But there are probably a lot of Windows applications from the nineties that still run unmodified.
433.
▲
by
danieldk
7y ago
Do JetBrains products still work if the company would go out of business or decided to undo the perpetual license? (I haven't upgraded my license since they switched to the subscription model.) [1] [1] It would probably be difficult co
434.
▲
by
danieldk
7y ago
I agree, that would be awesome!
435.
▲
by
danieldk
7y ago
I like their products and Omnigraffle in particular, though they still seemed to have old-school high pricing. I guess they have done their market research and concluded that lowering the prices does not add enough users. I like OmniGraff
436.
▲
by
danieldk
7y ago
Indeed, data outside the application folder usually consists of a preferences plist and saved application state. Of course, there could be caches as well, which could take up a fair amount of disk space. But I think the primary argumentatio
437.
▲
by
danieldk
7y ago
Developers can distribute .app's inside of .zip files, and many do, but this can result in users just running the .app inside of their downloads folder. And then this causes problems if they ever decide to clean out their Downloads fo
438.
▲
by
danieldk
7y ago
I never understood why Apple still supports the pkg format. It seems a half-baked leftover from the 2000s and even then I was already surprised that there is no way to uninstall things through the macOS GUI. I am not sure if this has change
439.
▲
by
danieldk
7y ago
The point is that downloading a key from a website does not prove that the key belongs to that organization. If the server is compromised, the attacker could replace the public key and TLS would not barf at it. Your reactions perfectly unde
440.
▲
by
danieldk
7y ago
This is nonsense. A malicious Linux application can exfiltrate all the data in your home directory. Taking over the OS is not hard either, just run a keystroke logger or put a rogue sudo in the user's path. Of course, this does not app
441.
▲
by
danieldk
7y ago
Maybe there are local dynamics at play (we are in a city in The Netherlands). But my wife has been doing the grocery shopping (since I don't have a driver's license). We would normally shop every day, but she is now going every 3-
442.
▲
by
danieldk
7y ago
It is interesting that Fedora Silverblue wasn't mentioned in the discussion at all. It aims for having an immutable root filesystem with transactional updates. Like Fedora, it uses SELinux to isolate processes with security policies. I
443.
▲
by
danieldk
7y ago
Why no mention of firejail or similar tools? They do mention bubblewrap in the sandbox-app-launcher section.
444.
▲
by
danieldk
7y ago
That's still not an OS issue. No amount of clever programming will help if people are that determined to do something dumb. And yet, a malicious iOS cannot typically take over the OS, other applications, or exfiltrate data from other
445.
▲
by
danieldk
7y ago
This doesn't seem like a "desktop Linux security" problem. It is a desktop Linux security problem, because people will want to install applications that are not available in a distribution. So, you should provide a mechanis
446.
▲
by
danieldk
7y ago
I also remember when I first started with Arch, which at that time had unsigned packages. Very much at the urging of Arch maintainers not to, people are using package managers to install stuff from AUR, where literally anyone can upload P
447.
▲
by
danieldk
7y ago
Agreed, I don't really see the problem. It's not like Catalina is bugging you over and over again with permissions. The first time you start e.g. Skype, it will request access to the mic and camera, you either allow it or deny it,
448.
▲
by
danieldk
7y ago
Packages have signatures on Linux. They're validated during install rather than execution, but validating them on execution wouldn't cause meaningful problems as long as the device owner can install additional signing keys. How
449.
▲
by
danieldk
7y ago
Things like apparmor can work well because the author or distributor of a package knows that it shouldn't ever do a particular thing, so if it attempts to, that is a bug and it should be refused. The user shouldn't even have to b
450.
▲
by
danieldk
7y ago
Yes which is very useful in videoconferencing. We don't want to run Microsoft Teams or Skype elevated. In macOS, applications do not have permission to capture the screen, control the mouse pointer, use the mic, use the camera, etc.
More ›