Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dcsommer
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
121.
▲
by
dcsommer
4y ago
https://alexgaynor.net/2019/aug/12/introduction-to-memory-un...
122.
▲
by
dcsommer
4y ago
I appreciate the honesty in the FAQ. No thread safety and still some open questions about iterator invalidation. I look forward to seeing what they come up with! Borrow checker style "Aliasability XOR Mutability" does restrict a l
123.
▲
by
dcsommer
4y ago
Commit description should contain the command to generate the change. Your review the command plus spot check actual changes and CI signals.
124.
▲
by
dcsommer
4y ago
Interesting that despite tools like Splint, 70% of high severity security vulns, including in well staffed projects like Chrome and Windows, are due to memory unsafety. The false negatives of security analysis tools are significant and ar
125.
▲
by
dcsommer
4y ago
> ... the general Rust practice of panicking upon unexpected conditions What makes you say this? From the sample I've seen, Rust programs are far more diligent about handling errors (not panicking: either returning error or handling
126.
▲
by
dcsommer
4y ago
Decompilation. Reverse engineering. Network monitoring. Third-party attestations like https://research.nccgroup.com/wp-content/uploads/2021/10/NCC... . The lack of whistleblowers from within Meta itself.
127.
▲
by
dcsommer
4y ago
This. Be very careful implementing this paper's technique. It does NOT promote long-term sleep independence, which should be the goal. Crying before sleeping is not inherently bad. The objective function is not to greedily minimize c
128.
▲
by
dcsommer
4y ago
What's the weight difference? It's tragedy of the commons without controlling for weight.
129.
▲
by
dcsommer
4y ago
I would want to see an example of such a tool before comparing the two approaches or giving credit to Zig. As you admit in the other comment, even if such an "after the fact" tool can exist, still the net safety will be less. A co
130.
▲
by
dcsommer
4y ago
In my experience, APIs that throw rarely define all the exceptions that can come from it, especially transitively. I see exceptions as a failed (because undocumented, but still important for correctness) attempt at compromising between ha
131.
▲
by
dcsommer
4y ago
I think we have compatible views. Each layer of the software must decide it's requirements and handle errors appropriately per requirements. You're right I didn't articulate when to handle an issue locally vs. pass it up. I t
132.
▲
by
dcsommer
4y ago
I totally agree with de-emphasizing the old "recoverable" vs. "unrecoverable" dichotomy ( https://blog.burntsushi.net/unwrap/#what-about-recoverable-v... ). Every time I've heard programmers (esp
133.
▲
by
dcsommer
4y ago
Yes. Both large-scale farming and increased population in the southwest are bad ideas.
134.
▲
by
dcsommer
4y ago
Growth in California, especially Southern California, is misguided and trades near-term ethical wins (housing opportunity) for long-term ethical disaster (massive water shortages and consequent displacement). I recommend "Cadillac Dese
135.
▲
by
dcsommer
4y ago
QUIC is HTTP/3 more or less and solves the same problems, yes.
136.
▲
by
dcsommer
4y ago
The US has this concept of "black spots" too. However, they are ironically named "safety corridors." We get a nice sign [0] to mark the death zone and then traffic continues unabated. [0] https://www.oregonliv
137.
▲
by
dcsommer
4y ago
You could use a network traffic analyzer, Frida, or trust third party security audits that WhatsApp publishes like https://research.nccgroup.com/2021/10/27/public-report-whats...
138.
▲
by
dcsommer
4y ago
Sugar taxes are effective in decreasing consumption of sugary beverages. https://en.m.wikipedia.org/wiki/Sugary_drink_tax Progressive pricing of water for larger consumers helps alleviate impact on the poor.
139.
▲
by
dcsommer
4y ago
Are there any studies showing using 4chan, tumblr, or reddit has better mental health outcomes than non-anonymous social networks? I'm skeptical from my own experience.
140.
▲
by
dcsommer
4y ago
I think a lot of this applies to spoken communication, too. For instance, if you can't say it clearly and succinctly, you may be lacking clarity yourself and need to do more reflection before talking about it. Also, I like the perspect
141.
▲
by
dcsommer
5y ago
What alternatives to Technological Humanism are not antidotes? It sounds like you consider the anxiety of the age a/the major problem (I agree), but is there really only one solution? It seems like there are other possibilities worth
142.
▲
by
dcsommer
5y ago
Setting goals and requirements for code coverage via fuzzing (e.g. libFuzzer or AFL), where risky attack surfaces have stricter goals for coverage, is a great way to get ROI on your time spent securing C++ code.
143.
▲
by
dcsommer
5y ago
Agreed this would be a nice addition. https://docs.rs/bitmatch/latest/bitmatch/ works nicely but only for a single integer. https://internals.rust-lang.org/t/pre-rfc-binary-patterns/
144.
▲
by
dcsommer
5y ago
70% of high severity security bugs (including RCE) are due to memory unsafety. Not all, but most. It's been this way for~decades. https://news.ycombinator.com/item?id=19138602 https://www.zdnet.com/arti
145.
▲
by
dcsommer
5y ago
What about password managers? The browser built-in ones aren't always the best choice.
146.
▲
by
dcsommer
5y ago
Are you sure about the "CVE explosion"? From the CNA counting rules https://cve.mitre.org/cve/cna/rules.html#section_7_assignmen... : 7.2.4 If multiple products are affected by the same independently
147.
▲
by
dcsommer
5y ago
For those that are uncomfortable with this state of affairs, I recommend this presentation: "Quantifying Memory Unsafety and Reactions to It" https://www.youtube.com/watch?v=drfXNB6p6nI
148.
▲
by
dcsommer
5y ago
I recommend using `less <FILE>` <shift-F> rather than plain `tail -f <FILE>` because you can ctrl-c to stop the tailing and then search the text using /. You can then resume tailing again later with another <shift-
149.
▲
by
dcsommer
5y ago
There are some good thoughts concerning when to use a linked list here: https://rust-unofficial.github.io/too-many-lists/
150.
▲
by
dcsommer
5y ago
This kind of hyperbole is neither instructive nor accurate. What is the intended purpose of this comment?
More ›