Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
drvdevd
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
27 ms
·
541.
▲
by
drvdevd
10y ago
Interesting take. When I first read this article I admit to buying in to the sensationalism a bit -- but I'll have to agree with you that The Darknet really hasn't changed this situation significantly, rather it's just introd
542.
▲
by
drvdevd
10y ago
Thanks for this! I didn't realize (or had forgotten) LUKS had been ported to Dragonfly. Also you touch upon my #1 frustration with APFS without really knowing anything about it: simple portability.
543.
▲
by
drvdevd
10y ago
Actually, perhaps this doesn't address all your points, but I share the sentiment about VM snapshots "feeling" quite similar, in fact I experience it every day as I run ZFS as a root filesystem within VMware. The real gain
544.
▲
by
drvdevd
10y ago
I think the number one legitimate concern I can see, after just reading this for the nth time, is the trustworthiness of C++ compilers, which I believe was not so great in the early 90s. Now, I have no evidence to back this up (yet), but I&
545.
▲
by
drvdevd
10y ago
Or perhaps the more obvious: you try to disallow 'npm install' in some limited environment but allow other npm commands?
546.
▲
by
drvdevd
10y ago
Yes, I agree and also thought of shell aliases when I read this. On top of that there's an argument forming somewhere in my mind that this also sets a bad security precedent in the long term... although I can't put my finger on
547.
▲
by
drvdevd
10y ago
It seems like a losing battle though. Small embedded cameras are becoming too widespread and you can't put tape on all of them. I think looking forward it's not unreasonable to rely on software controlled switches to minimize this
548.
▲
by
drvdevd
11y ago
You've made one of the most compelling points I've seen in this discussion so far. Really - why mix an application security mechanism into the transport layer? DDoS attacks will happen whether Tor is blocked or not. Add to this so
549.
▲
by
drvdevd
11y ago
And here you've hit upon what would actually be interesting: the open sourcing of Windows itself, open sourcing of Hyper-V, etc. This is a 'nice to have' addition to Windows for sure. But it really does nothing to make Window
550.
▲
by
drvdevd
11y ago
Regarding the path of least resistance for developers eventually, hopefully, perhaps traversing NAT will prove to be a bigger pain for the average developer than just using IPv6.
551.
▲
by
drvdevd
11y ago
Agreed. I had to navigate away quickly. Which is a shame because the article was interesting.
552.
▲
by
drvdevd
11y ago
Not exactly disagreeing with you but for a long time now the web has been our primary path to most forms of code execution hasn't it? I mean if you count HTTP as the web in addition to browsers?
553.
▲
by
drvdevd
11y ago
This line stood out to me (especially after reading the protocol explanation points from a manufacturer just above): "I’m baffled as to why such a well-known brand as Foscam would enable P2P communications on a product that is primaril
554.
▲
by
drvdevd
11y ago
If you're in the email marketing business having to create and test email templates, this could actually be a very practical exercise and a team building game at the same time, I think. These bugs are a serious pain point sometimes f
555.
▲
by
drvdevd
11y ago
You beat me to this! Awesome!
556.
▲
by
drvdevd
11y ago
Immediately upon reading 'csrutil disable' I thought of 'setenforce 0' and the fact that this is usually the first measure taken to deal with SELinux by many users, usually against better judgement. However this, like SE
557.
▲
by
drvdevd
12y ago
Yeah when I read the post, I kept thinking about the fact that there are a number of areas in which the just plain interested individual could focus their efforts to achieve the same general feeling of depth the author had back then. And
558.
▲
by
drvdevd
12y ago
It does seem to me that the author has unfortunately encountered a more negative interpretation of the meme. Personally I've read the original RGWIB essay and took away a couple interpretations. First, a simpler implementation is gen
559.
▲
by
drvdevd
12y ago
This is very interesting work. Thanks for publishing it. One thought experiment for you (which perhaps you've discussed already): could an attacker potentially influence and predict the state of patched software on the target system, i
560.
▲
by
drvdevd
12y ago
Yes. This point also highlights the distinction between interactive shell and system shell. You probably want a bunch of featutes in your interactive shell. You probably want a small, readable code base in your system shell. These two goals
561.
▲
by
drvdevd
12y ago
Also, what could the U.S. government do when this knowledge is so widespread and in so many forms at this point? Take down notices to github? Cease and desist orders to Linus Torvalds? The encryption cat is out of the bag to a certain degre
562.
▲
by
drvdevd
12y ago
> This Golden Key idea is one of those classic "I'm just an idea man, I don't have to figure out the nitty gritty details!" claims. Most definitely. And even the way it was proposed at the end of the original WaPo e
563.
▲
by
drvdevd
12y ago
True. Even shells that are written with security in mind are bound to have some similar bugs, though perhaps not as easy to discover or exploit. I think the bash bugs have exposed some general flaws in the way we continue to trust input bot
564.
▲
by
drvdevd
12y ago
One of the most interesting outcomes of recent internet scale, headline creating bugs, such as heartbleed and shellshock, is what I think I'm going to start calling the "bugfud" effect. This could be either a combination of
565.
▲
by
drvdevd
12y ago
I think you cannot really say who has the bug in this case, from this point of view. The problem is that in order to blame one component (e.g. Apache) over another like bash, you would have to have a "rigorous" spec of the entire
566.
▲
by
drvdevd
12y ago
Think of it this way: this doesn't just affect webservers. It affects most unpatched bash instances. The vector of attack is through environment variables in bash. You could argue that 90% of the worlds' PHP servers will probably
567.
▲
by
drvdevd
12y ago
Thanks for sharing this! I've already encountered some skepticism as to the severity of the bug so information like this is very helpful.
568.
▲
by
drvdevd
12y ago
I already code for a living and thus my github often goes dormant for months or even years. I also code on my free time too and many of the projects I might contribute to for free (important to stress that), or otherwise become involved i
569.
▲
by
drvdevd
12y ago
This is great. Thanks!
570.
▲
by
drvdevd
12y ago
I find the concept of "digital detox" in this situation to be interesting. The Hacker News reader in me wants to say, "But you're missing an opportunity to watch the watcher." I understand most abuse shelters aren&#
More ›