Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kbwt
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
91.
▲
by
kbwt
9y ago
> php,ruby, python or modern javascript But do you really understand those? Do you have a complete mental model of how they work down to the fundamentals? For C and even C++, I can confidently say YES.
92.
▲
by
kbwt
9y ago
> forums Every single forum I frequented "back in the days" (ca. 2004, vBulletin-style) is gone. These were forums that hosted intense/focused technical discussions, in a way that just doesn't seem to exist anymore, w
93.
▲
by
kbwt
9y ago
But then we're not comparing the same thing. If you were trying to learn manual memory management, type declarations, linkers, cross-compilation and packaging in 2018, would that really be any easier than in 1998?
94.
▲
by
kbwt
9y ago
The consensus seems to be that those types of skills do not belong in a Higher Learning institution. In Germany, the saying is "You do not need a Computer to study CS", although it sounds wrong in English because CS literally cont
95.
▲
by
kbwt
9y ago
> 'Technische Universität' That's just what the Universities which focus more on STEM as opposed to Literature/Law/Psychology call themselves.
96.
▲
by
kbwt
9y ago
The communication ends up being such a bottleneck that your senior devs might as well do the 10% writing. Incidentally also the reason why outsourcing software doesn't work if you're trying to do anything innovative.
97.
▲
Intel Software Development Emulator
(software.intel.com)
2 points
by
kbwt
9y ago
|
0 comments
98.
▲
by
kbwt
9y ago
> Return pointer to stack object (more common than you might think!) Maybe when you're still learning how to program. A combination of valgrind/sanitizers will catch all of these mistakes. The same class of mistakes can also be
99.
▲
by
kbwt
9y ago
This is the call stack I'm looking at: #0 https://cs.chromium.org/chromium/src/components/url_pattern_... #1 https://cs.chromium.org/chromium/src/components/url_pattern_...
100.
▲
by
kbwt
9y ago
Now I'm half tempted to serve up ads from a path in the form '/a{n}b/\d+' with sufficiently large n to bring the O(mn) std::string::find subpattern matcher to a crawl when it encounters my harmless 'src="&
101.
▲
by
kbwt
9y ago
> because they have to make up the revenue. I see this all the time when justifying bad business practices. How about you stop doing what you're doing if it isn't profitable?
102.
▲
by
kbwt
9y ago
They are defined behavior in Java, but not in C++. Things still get extremely complicated[1] if you use them in Java, so I would treat them as undefined behavior regardless and ban them from any Java code base. Note that Java has some impli
103.
▲
by
kbwt
9y ago
I actually disagree. High-level knowledge without later filling in the gaps leads to cargo-cult software engineering. If people get lost in the details, they are not prepared to fully understand the big picture.
104.
▲
by
kbwt
9y ago
> Please don't say "don't use C". We all agree on that . I wouldn't be so sure John Nagle agrees with such a blanket statement.
105.
▲
by
kbwt
9y ago
Less than 1/3 the price of the equivalent Linode and DO offerings at 2GB.
106.
▲
Free peer-to-peer code interview practice
(pramp.com)
1 points
by
kbwt
9y ago
|
0 comments
107.
▲
by
kbwt
9y ago
It seems to be a common confusion in the EU. A lot of people refer to CS as IT where I live.
108.
▲
by
kbwt
9y ago
I wouldn't be so sure lower level code necessarily has more vulnerabilities. It's certainly easier to find the vulnerabilities because the attack vectors are well-known. Software written in higher level languages is often less wid
109.
▲
by
kbwt
9y ago
It's not the indirect jumps that concern me but all the conditional branches, such as loop conditions.
110.
▲
Linode not to patch cross-VM memory reads before next week
(blog.linode.com)
1 points
by
kbwt
9y ago
|
0 comments
111.
▲
by
kbwt
9y ago
Translation: Only closes some low-hanging attack vectors.
112.
▲
by
kbwt
9y ago
Read up on the "out of bounds" and "indirect branch" variants. Spectre doesn't have much to do with mode switches.
113.
▲
by
kbwt
9y ago
> Note that the insertion of LFENCE must be done judiciously; if it is used too liberally, performance may be significantly compromised. Wow, as if we could press some magic button and it would pinpoint all the places where a branch cond
114.
▲
by
kbwt
9y ago
That is not an effective mitigation.
115.
▲
by
kbwt
9y ago
> The resolution of performance.now() will be reduced to 20µs. That will reduce the data rate of this particular covert channel, not prevent the attack altogether. Even adding random noise would not rule out the attack.
116.
▲
by
kbwt
9y ago
> Resolved by software / OS updates to be made available by system vendors and manufacturers. Not unless you update every piece of code running on your machine to insert an lfence following every branch on attacker-controlled data.
117.
▲
by
kbwt
9y ago
The papers take a while to get to the point. I nearly fell asleep re-reading the same statements until they got to the point: speculative execution of buffer overflows. Could have been said more concisely. Sadly, this seems to be the norm w
118.
▲
by
kbwt
9y ago
> this is impossible. I wouldn't be so sure. > pump and dump it forever That doesn't work.
119.
▲
by
kbwt
9y ago
Could also be worth 100x less.
120.
▲
by
kbwt
9y ago
Karnaugh maps are often made out as something special, but it's nothing more than a graphical brute-force method. Thus, useful for pen-and-paper up to 5-6 bit logic functions but no better than exhaustive testing for a computer. There
More ›