Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dgl
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
91.
▲
by
dgl
3y ago
If you’re wanting to save money though something with say an Intel i5-6500T (6th Generation Core) the ‘T’ meaning it’s a low power (throttled) part is worth considering. They are surprisingly close in performance to an N100: https:/&#
92.
▲
by
dgl
3y ago
Actually, I got it wrong, too many vulnerabilities in flight. They did fix it: https://github.com/openbsd/src/commit/375ccafb2eb77de6cf240e...
93.
▲
by
dgl
3y ago
It does. Try grep -i
94.
▲
by
dgl
3y ago
See my reply in the thread: https://www.openwall.com/lists/oss-security/2023/10/20/2 — not all terminals get this right.
95.
▲
by
dgl
3y ago
Cute, I found a similar issue in OpenBSD's tar as mentioned, I didn't share the exploit before but basically a long filename does it. Something like: https://gist.github.com/dgl/355840320535bf8ef8b70f2e0722bf6
96.
▲
by
dgl
3y ago
(Author here.) If there's any takeaway from this, while the worst part is the terminal bugs; I'd like people to be aware that any tool dealing with text (command lines, potentially even websites) should consider sanitizing control
97.
▲
by
dgl
3y ago
Sixel isn't state of the art, see https://sw.kovidgoyal.net/kitty/graphics-protocol/
98.
▲
by
dgl
3y ago
Some terminals can do tricks like this, some terminal authors care about performance, e.g. https://codeberg.org/dnkl/foot/src/branch/master/doc/benchma... In general you're better off usin
99.
▲
by
dgl
3y ago
(Author here.) I agree the only correct way C1 controls can work is encoded within UTF-8 data, else nothing works. The context is escaping C0 control characters is simple, you look for a single byte and filter it as you need. C1 controls wh
100.
▲
by
dgl
3y ago
Thanks, I will see about adding that. As I wrote before CVEs it is hard to find details. I've also noticed Google is missing quite a lot of historical things lately.
101.
▲
by
dgl
3y ago
That's still only best effort, for example it will depend on the terminal but it doesn't reset things like xterm's control keys send escape sequences property, so: printf "\e]4;1;?\a\e[>4;2m" In xterm+fish
102.
▲
by
dgl
3y ago
(Author here.) Unsure how fish can fully protect from this, as if you run "cat" in fish, then it isn't between you and the terminal anymore? Or do you mean fish should do a reset before displaying each prompt? If I run the pr
103.
▲
by
dgl
3y ago
(Author of the original paper here.) Bracketed paste mode is good and ideally it just works(tm) and therefore people don't need to know about it. It does just work in recent versions bash (readline) and Zsh. Unfortunately there is stil
104.
▲
by
dgl
3y ago
Glad to have helped.
105.
▲
by
dgl
3y ago
I have an X1 Nano too, because I want to run Linux and it is less hassle than Asahi Linux (currently, I wouldn't be surprised if that changes). Agree on the portability, it's great, but Lenovo still only offer 16GB RAM, the CPU is
106.
▲
ANSI Terminal security in 2023 and finding 10 CVEs
(dgl.cx)
3 points
by
dgl
3y ago
|
0 comments
107.
▲
The Terminal Escapes: Engineering unexpected execution from command lines
(gresearch.com)
9 points
by
dgl
3y ago
|
0 comments
108.
▲
by
dgl
3y ago
pf on OpenBSD does it fine.
109.
▲
by
dgl
3y ago
“udp” in this context means unprivileged data gram, not UDP the protocol. For some reason go uses the confusing “udp” name in parts of its API. The docs for this kind of socket seem to only exist on the kernel commit: https://lwn
110.
▲
by
dgl
3y ago
In general once you’re connecting over SSH the connection itself is always in raw mode and then the remote host deals with its pty normally (which can be in line or raw mode). Terminals with special shell integrations usually need them ins
111.
▲
by
dgl
3y ago
Thanks! No need for a /ip, just doing: $ curl ip.wtf ... will do the right thing, or if your user-agent isn't curl send a header of "Accept: text/plain" and you'll get the plain text version (see https:/&
112.
▲
by
dgl
3y ago
A long time ago I spent a bit too long debugging something to later find out the "source port" that displays isn't right! It's still not right! I obviously fixed this by making my own site ( https://ip.wtf ).
113.
▲
by
dgl
3y ago
> I wonder if it could be brought to macos (would be a huge undertaking though since there are SO many differences between Linux and modern macs). That sounds like trying to recreate what Microsoft did with WSL1*, which is an emulation l
114.
▲
by
dgl
3y ago
It appears it blocks you if you send an X-Forwarded-For header, but if you happen to be behind a proxy which sends one, you'll find you can't access it... Rather broken HTTP behaviour.
115.
▲
by
dgl
3y ago
Same; I made a ~/bin/telnet that does: #!/bin/sh nc -v "$1" "${2:-23}" Obviously it doesn't do the telnet protocol when run on port 23 (note the real telnet client disables the telne
116.
▲
by
dgl
3y ago
10baseT would imply a hub, but 10base2 is “thinnet” (because the cable was thinner than the previous standard) where a coax cable runs between all devices on the segment, with no central device connecting them together. https://e
117.
▲
by
dgl
4y ago
It sounds like it's pretty much the final step; the toolchain will be fully reproducible on 1.21: https://go.dev/cl/454836 The CL description describes the changes, then: "Combined, these four changes (along
118.
▲
by
dgl
4y ago
Section 13 of the AGPL v3: "Notwithstanding any other provision of this License, if you modify the Program, your modified version must prominently offer all users interacting with it remotely through a computer network (if your v
119.
▲
by
dgl
4y ago
It's AGPL licensed which for a proxy is a strange choice. They have an unanswered question for months on what it might mean: https://github.com/sozu-proxy/sozu/issues/764 Without an answer to that if you
120.
▲
by
dgl
4y ago
https://bugs.launchpad.net/bugs/1966800 looks like a potentially related Ubuntu bug, although the underlying bug is in systemd. The commit that fixed it was in 2021: https://github.com/systemd/syst
More ›