Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
firebacon
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
firebacon
7y ago
Agreed; this is excellent news! A highly competent and principled government should be a considered a good thing regardless of where you stand on the whole "big tech" debate.
32.
▲
by
firebacon
7y ago
This makes sense, but it also implies that there is no actual backdoor in TFA. The code as shown in the article is not exploitable without assuming more (actually exploitable) bugs somwhere else in the callsite (which the article doesn'
33.
▲
by
firebacon
7y ago
But how does that result in a vulnerability? At best you can call the function with garbage input (negative number) and still receive a valid buffer from malloc, no? TFA calls this a "backdoor"; so how do you actually "get in
34.
▲
by
firebacon
7y ago
Agreed; the explanation does not clarify why the first snippet is considered "totally safe" and the second one is not. How does the second snippet introduce a new security issue? A negative value for num passed into the function
35.
▲
by
firebacon
7y ago
What does "mofo" mean here. Can you give us a rough estimate on the transaction rate you achieved with this setup? My own experience and all independent benchmarks I can find seem to indicate a limit of 100-1000TPS on reasonable h
36.
▲
by
firebacon
7y ago
The less flippant explanation is that SQLite can only handle a single writer at any time and when you try to access it with two concurrent writers (or a concurrent reader and writer in some modes) it will by default return a "BUSY&quo
37.
▲
by
firebacon
7y ago
It's hard to point those out without coming across as a hater, and because they might seem so obvious. Trying...: With the way transactions and durability work in SQLite, a normal setup will not do more than on the order of ~100 transa
38.
▲
by
firebacon
7y ago
My point was less about arguing which is more popular, but more that the same claim can equally be made for at least hundreds if not thousands of other software packages. Still, SQLite stands out to me as the only package I can recall that
39.
▲
by
firebacon
7y ago
They charge money for it... Note that I'm not saying all of the test suite should be open source. It's clearly a valid/cool business model and SQLite is, for a lot of use cases, an excellent piece of software that I have of
40.
▲
by
firebacon
7y ago
No, I'm referring to the second section. > MOST WIDELY DEPLOYED SOFTWARE MODULE OF ANY KIND? -- SQLite is probably one of the top five most deployed software modules of any description. Other libraries with similar reach include: zl
41.
▲
by
firebacon
7y ago
That completely depends on the chosen metric/definition though. For example, you could consider the most used database the one that handles the most queries per day. Not so clear who is the winner now. The claim that SQLite is one of t
42.
▲
by
firebacon
7y ago
About the well-tested bit: Per it's own documentation, SQLite has a massive test suite. [*Not all of] the test suite is actually open source though, so the overlap between commenters selling you on how well tested SQLite is and those t
43.
▲
by
firebacon
7y ago
[Edited] Two Generals does not apply since it deals with the problem of guaranteeing that two parties agree on the exact same consistent state after a finite amount of time/messages. MQTT's "exactly once" delivery is b
44.
▲
Half of England is owned by less than 1% of the population
(theguardian.com)
29 points
by
firebacon
7y ago
|
10 comments
45.
▲
by
firebacon
8y ago
> The calculation of accurate crash rates of this type depend on reliable counts or estimates of both airbag deployment crashes as well as the mileage travelled exposing vehicles to the risk of a crash. But after obtaining the formerly s
46.
▲
NHTSA’s Implausible Safety Claim for Tesla’s Autosteer Driver Assistance System [pdf]
(safetyresearch.net)
81 points
by
firebacon
8y ago
|
39 comments
47.
▲
by
firebacon
8y ago
> Not to forget, C++ template meta-programming was discovered by accident That's a bit of an uncharitable reading, no? For others that would like to make up their own mind: https://softwareengineering.stackexchange.com&#x
48.
▲
by
firebacon
8y ago
Technical details seem to matter though. Using the definition of "paying taxes" that TC seems to be using, you could have always paid your taxes using, for example, magic the gathering trading cards. You just need to find somebody
49.
▲
by
firebacon
8y ago
Seems like fake news. The state of ohio will not accept bitcoins -- they just "allow" you to pay your taxes using bitpay, which is a service that will convert your bitcoin to USD on the fly. How is this any different to what you c
50.
▲
by
firebacon
8y ago
Wow, so many negative comments here. I for one applaud the move -- a license like this has been needed for a long time. Slightly (un)related, but I don't understand why in a forum full of software developers it is the consensus that al
51.
▲
by
firebacon
8y ago
Very interesting! Is this kind of command capability (e.g. ability to modify memory contents) something that is usually only available on "non-critical" subsystems, or would you generally expect to also find it on critical compone
52.
▲
by
firebacon
8y ago
Thanks - that was exactly the kind of info I was looking for! Amazing that they had the ability to just run ad-hoc LISP on the spacecraft. It appears their method to ensure safety in the face of arbitrary code execution was to divide up t
53.
▲
by
firebacon
8y ago
Thanks for the reply! So what you're saying is that it's just a "normal" over-the-air software update. I.e. you add some new functionality and then do a full system test of all functions of the software before replacing
54.
▲
by
firebacon
8y ago
Remote updates -- where you replace a full (sub)system -- are one thing, since you can always run the normal software validation procedure on the new version of the software. So an OTA update of a system (even in flight) does not sound like
55.
▲
by
firebacon
8y ago
The part that I find the most intriguing is "corrections can be made on the fly". I can see how you would ensure reliability through proper requirements specification, a good software development process, separate independent impl
56.
▲
by
firebacon
8y ago
Off-topic, but do you actually run ad-hoc SparkSQL queries on the whole dataset sometimes? Are the logs actually stored as text files on disk? How long does such a query take and/or how many racks of machines do you need for that? Shou
57.
▲
by
firebacon
8y ago
Why would that help -- genuinely curious? Shouldn't a redis server already not be bound by the secondary storage I/O speed? I thought it was a main memory system with asynchronous commits to disk?
58.
▲
by
firebacon
8y ago
I would not consider setting an exit code to be a fancy feature, but I guess we are living on the bleeding edge here :) EDIT: I should have said explicitly in my initial comment that I knew about std::process::exit and panic!, but did not
59.
▲
by
firebacon
8y ago
Oh nice! Will start using that as soon as we get to 1.26 :) -- currently stuck on 1.24 (upgrading takes a bunch of work since we're building under openembedded/bitbake, so I wait until the new version hits the upstream layer)
60.
▲
by
firebacon
8y ago
We started using Iron, but later switched to just using hyper because that seemed easier and like a smaller API surface to target. I'm not really working on a web application so I need zero of the routing/web features of these fra
More ›