Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
facetube
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
31.
▲
by
facetube
8y ago
Yep. totally safe, someone on the internet said we should.
32.
▲
by
facetube
8y ago
One of the many practical vulnerabilities.
33.
▲
by
facetube
8y ago
The claim from daimenkatz was that transactions and MVCC are supported internally, but not externally. It's unclear to me if any of this is accurate. Here's the information that was offered: https://github.com/couc
34.
▲
by
facetube
8y ago
Multiple people. Please do your research before posting.
35.
▲
by
facetube
8y ago
You made a claim. Support it or withdraw it.
36.
▲
by
facetube
8y ago
So you have nothing to refute the available evidence. Thanks for the informative response. Don't make claims in public you can't support.
37.
▲
by
facetube
8y ago
That's why you'd use a cut-out: plausible deniability. Russia has attempted and/or carried out multiple hits on NATO soil in this exact manner, including one with a novel nerve agent.
38.
▲
by
facetube
8y ago
You have no evidence to support this.
39.
▲
by
facetube
8y ago
You have absolutely no evidence of this, and there have been multiple independent medical examinations and diagnoses.
40.
▲
by
facetube
8y ago
Easy enough to convert on the way out, using a mature database system without these performance flaws. The app got done and performed well, and we weren't at the mercy of an unresponsive community that leaves seven year old dependencie
41.
▲
by
facetube
8y ago
One of the stated goals on their Spidermonkey replacement issue (N.B. it still won't fix the view server protocol performance, but at least it'll be a modern engine) is "Get my C skills back out of the closet", and will
42.
▲
by
facetube
8y ago
> I‘ll give you no cite, sorry, because we discovered the effect during internal tests We discovered the issue in internal tests and reported it upstream where it was confirmed; there's nothing to discuss here. > BTW they may be
43.
▲
by
facetube
8y ago
What's your definition of huge?
44.
▲
by
facetube
8y ago
I suspect the bug bounties are much more about deterring the sale of exploits to bad actors than about recruiting employees.
45.
▲
by
facetube
8y ago
Correction: the library is too old for that specific CVE to be exploitable. There may be others, there may not be. I don't know – and that's actually the problem. The chief complaint here is that it's very hard to reason abou
46.
▲
by
facetube
8y ago
Also for balance: it's unclear if there are CVEs. There may not be any that are exploitable due to the age of the library (i.e. the bugs landed post-release). However, it's also very tricky to rule these out one by one, and the de
47.
▲
by
facetube
8y ago
Thanks a lot; this is super-helpful.
48.
▲
by
facetube
8y ago
Thanks for the clarification. Can I ask how the MVCC is implemented (e.g. WAL, MVTO, MVRC, etc.), or if there's documentation around that might give some additional insight?
49.
▲
by
facetube
8y ago
> Except CouchDB entire REST API, where nearly every endpoint streams result row by row I'm talking about the internals of couchjs. > As of security: wrong guess. Go compare number of critical CouchDB CVE I'm talking about S
50.
▲
by
facetube
8y ago
> Or you can use a query language mostly similar to what MongoDB uses Yes, provided you started on 2.0, as I specifically stated in a reply. > That's a feature. If they don't usually change together put them in a separate de
51.
▲
by
facetube
8y ago
Exponential population increase would certainly drive increased demand for water.
52.
▲
by
facetube
8y ago
From the point of view of a single cluster or node (ignoring replication for a moment), it just doesn't have any strong notion of transactions. There's no write-ahead log, no rollback, and no situation where you'd be able to
53.
▲
by
facetube
8y ago
For balance: there is a newer query/index system called Mango in Apache CouchDB 2.0+, that IIRC is internal and doesn't rely on any external view server. It wasn't in 1.7.1, though, so if you're coming from there, it&#
54.
▲
by
facetube
8y ago
He was right to abandon CouchDB. Here's my rationale: https://news.ycombinator.com/item?id=17116306
55.
▲
by
facetube
8y ago
Sorry, wasn't clear if you were talking about MVCC in a replication context or in a node-local context. It does the former, it definitely does not do the latter.
56.
▲
by
facetube
8y ago
It doesn't use real node-local/shard-local MVCC AFAICT. It's O_APPEND on flat files.
57.
▲
by
facetube
8y ago
God, where to start. Map/reduce views ("secondary indexes") are currently built by serializing JSON down a pipe to an external process called couchjs that links against a seven year old version of Mozilla Spidermonkey (1.8.5,
58.
▲
by
facetube
8y ago
> as of LAST NIGHT, there was a mention on 1password.com of using DropBox and other mechanisms for syncing vaults Below is exactly what the cited page said on February 1st – as far as I can tell, this post offers absolutely no support fo
59.
▲
by
facetube
8y ago
You wouldn't be fined. You'd be arrested and charged criminally, and likely spend the rest of your life in jail. The public does not understand and would happily hang you for being one of those evil hackers. The person who tells t
60.
▲
by
facetube
8y ago
Until the cops kick your door in on copyright infringement charges to "make an example" of someone. Don't think it can't happen.
More ›