Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
i_think_so
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
i_think_so
5mo ago
I presume you work for astian.org yes? Then perhaps you can explain how a "mesh VPN" uses "secured end points". Also, the VPN link from your Wikipedia page is dead: https://en.wikipedia.org/wiki/Mid
32.
▲
by
i_think_so
5mo ago
https://en.wikipedia.org/w/index.php?title=Midori_%28web_bro... > programming language = originally in [[C (programming language)|C]] & GTK2, rewritten completely in [[Vala (programming language)|Vala]] &
33.
▲
by
i_think_so
5mo ago
I'm pretty sure this is the best idea I've ever heard of for this technology. You should build that tool and it should become mandatory throughout the tech world. Can we get some enabling legislation? A UN resolution perhaps?
34.
▲
by
i_think_so
5mo ago
> one team uses Copilot as autocomplete and calls it a day. Another team runs Claude Code in tight loops, with tests, reviews, and constant steering. A product owner suddenly prototypes real software instead of mocking screens in Figma.
35.
▲
by
i_think_so
5mo ago
"The uncanny valley of truth". That's a brilliant way of putting it. Thank you. > It's made worse buy its asymmetric nature: it takes seconds to generate pages of words and hours to figure out what is wrong with the
36.
▲
by
i_think_so
5mo ago
Duuuude. That is *deep*!
37.
▲
by
i_think_so
5mo ago
I was raised and educated well inside the Anglosphere (USA) and was also taught to write formally in that way. Do the people who say you sound like AI give you any specifics? Also, if you don't mind, what was your English education lik
38.
▲
by
i_think_so
5mo ago
When you say "we" you're talking about Twitter, right?
39.
▲
by
i_think_so
5mo ago
Oof. Now I has a sad. :(
40.
▲
by
i_think_so
5mo ago
Hmm. Now that you mention it, wasn't that part of what was happening in Neuromancer? The "encryption" (or whatever it was) kept changing so the attack had to respond by "evolving" to get in. Excuse me, I need to g
41.
▲
by
i_think_so
5mo ago
> I didn't enjoy it. Then it wasn't for you. No big whoop. > It wasted my thoughts as I stared at it, I think we have arrived at the kernel of the problem. :-) The rest of this comment is left as an exercise for the student
42.
▲
by
i_think_so
5mo ago
That's one idea. I have a different one. What if we...now hear me out....what if we didn't try to shoehorn a stupid and unworkable technological solution into this problem space and just...made parents responsible for their kids?
43.
▲
by
i_think_so
5mo ago
Well of course. What else did they expect kids were going to do? This whole idea was braindead from the start.
44.
▲
by
i_think_so
5mo ago
I am imagining some poor sod working for NSA TAO trying to hack a bespoke web microservice stack. He spends dozens of hours slaving away at the keyboard, skipping sleep and eating terrible meals at his desk, desperate to get RCE as quickly
45.
▲
by
i_think_so
5mo ago
Asking the real questions right here. ^ "Computer. Run program Riker omega six." <things happen>
46.
▲
by
i_think_so
5mo ago
Come on, bro. Why you gotta be like that? I mean, I'm a gwern fan, but...can't you just let people enjoy things?
47.
▲
by
i_think_so
5mo ago
Does he remind you of anyone? https://www.wired.com/story/jia-tan-xz-backdoor/
48.
▲
by
i_think_so
5mo ago
This. A billion times this. The community should be shouting from the rooftops that there is an intruder in the neighborhood. Maybe there's no malice intended and this is just a colossal pile of honest mistakes. Maybe this author is
49.
▲
by
i_think_so
5mo ago
Plenty of very thoughtful comments so far about copyright, community, developers who might not speak English as a first language, .... Very few people mentioning the obvious: MALICIOUS BINARY! Did we learn nothing from the xz malware fia
50.
▲
by
i_think_so
5mo ago
Speaking as someone who used to know absolutely nothing about the world of high finance, yes, it is too much to ask. Before I started paying attention to such things I wouldn't have known a single one of those terms to even begin googl
51.
▲
by
i_think_so
5mo ago
This very specific corner of the internet has no idea how your metaphor is supposed to work, which is why I like it so much.
52.
▲
by
i_think_so
5mo ago
It's not "trivial", and it costs dollars, not pennies for that many attack endpoints[1]. My firewalls scale much more cost effectively, especially when I coalesce individuals into netblocks. I don't think fail2ban pro
53.
▲
by
i_think_so
5mo ago
Could this be hacked to schedule upgrades to only happen when the user is not about to join a meeting in 5 minutes? "Yeah, uh, my local electric provider is burning coal 24/7 except at 9-10 pm on these 5 dates each year...."
54.
▲
by
i_think_so
5mo ago
> Security through obscurity isn't security. It could be a method to reduce noise, but by doing so, you also have less eyes to watch over. If you'd pay for a blackbox pentest, and the pentester doesn't find your OpenSSH se
55.
▲
by
i_think_so
5mo ago
Sounds like you are the poster child for moving ssh to a different port. :-) If I were you I would do that immediately. Then, once your logs become actually useful again, look at them. "Hmmm. There sure seem to be a lot of failed log
56.
▲
by
i_think_so
5mo ago
Good luck scanning 64k ports on a server that has a few randomly assigned fail2ban listeners.
57.
▲
by
i_think_so
5mo ago
> By reducing the noise in logs, it reduces the workload on the human or agent reviewing the logs. So, you can detect an attack in progress or respond to an attack before it gets out of hand. With SSH on a standard port, the harmful mali
58.
▲
by
i_think_so
5mo ago
> The problem with this argument is that you can justify an infinite amount of crap with it, the security equivalent of cockroach papers; which inevitably people ends up treating as real security. I almost missed the twist at the end bec
59.
▲
by
i_think_so
5mo ago
I have always replied to colleagues who poohpoohed "security through obscurity!" as if it was proof of ignorance or bad culture with "a password is just a string of obscure characters. ;-)" That's not a serious argu
60.
▲
by
i_think_so
5mo ago
Same thing as changing your ssh port to something random. It's a trade-off with the convenience of knowing that all of your servers are listening on port 22 and you won't need any customizations in scripts or whatnot. But there
More ›