Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
lrvick
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
91.
▲
by
lrvick
1mo ago
Well you of course want to sub-divide every application in user space either with gvisor or a hypervisor, like QubesOS. If someone pwns your personal browser they should pop out into an environment where nothing exists but that browser, wit
92.
▲
by
lrvick
1mo ago
On a modern Linux system you do not need sudo to compile software, install it, or even run it as an unprivileged system service in a User Namespace bound to port 22 (if you give your user the correct Linux Capabilities). The only thing you
93.
▲
by
lrvick
1mo ago
See my reply here: https://news.ycombinator.com/item?id=49504775
94.
▲
by
lrvick
1mo ago
For root filesystems I am recently favoring EROFS which is read only, fast, and can run from ram. On workstations I install almost all software to ~/.local as the home partition is writable. I also put all my systemd user units there,
95.
▲
by
lrvick
1mo ago
Arch at least mandates author signed packages which is unfortunately rare these days, but keys do not need to be on smartcards, and code review is not enforced. You compromise the right arch maintainer and you could do some real damage. Arc
96.
▲
by
lrvick
1mo ago
I love wikipedia for research. It is great that anon randos can help keep a common encyclopedia maintained with high accountability. If a mistake happens it is quickly corrected. But that trust model does not work with software. It is negli
97.
▲
by
lrvick
1mo ago
Sigh . Qubes had some great security design and implemented it the only way time/funds would allow: by cobbling together a lot of unfortunately very complex and broken things built for a different security model decades ago. Qubes is
98.
▲
by
lrvick
1mo ago
> Linux isn't like macOS, it doesn't have any kind of proper desktop sandboxing architecture that really works. As a QubesOS user, I beg to differ. Just because most Linux distros are negligent with sandboxing does not mean all
99.
▲
by
lrvick
1mo ago
Mac users always like to defend some of the things Apple legitimately got right over most Linux distros, but always ignore that supply chain security and standard package management security on Apple (Homebrew) is akin to giving a bunch of
100.
▲
by
lrvick
1mo ago
Rootless docker is even an officially supported install method.
101.
▲
by
lrvick
1mo ago
No popular Linux desktop, I would grant you. I use QubesOS and my own distro, stagex.
102.
▲
by
lrvick
1mo ago
Per my other comments, it does not really matter if you disable the sudo password or not. If you have a sudo binary at all you effectively are giving every user process root since malware can mask the sudo command and intercept the password
103.
▲
by
lrvick
1mo ago
I challenge anyone to name even one thing that requires sudo on a Linux desktop not better handled with systemd user units, Linux Capabilities, rootless docker, etc.
104.
▲
by
lrvick
1mo ago
There is. Simply do not install sudo and do not allow access to root at runtime. I am serious. There is absolutely nothing you cannot run unprivileged these days. Can even run sshd from a systemd user unit in your home folder, and even assi
105.
▲
by
lrvick
1mo ago
> You need root in order to overwrite sudo in the first place I think You just need write access to .bashrc or similar. > This is why I think it is a good idea to get a yubikey and use PAM to require a physical user presence check to
106.
▲
by
lrvick
1mo ago
Docker can be run rootless. It is so easy. No excuse for desktop distros to not do this by default. And that is why all major Linux distros are just as bad as Omarchy (Not recommending MacOS or Windows either as those are wildly worse)
107.
▲
by
lrvick
1mo ago
Homebrew is like giving a bunch of wikipedia randos remote shell access to your computer. There is no enforced code review policy. Any maintainer can make a commit under a pseudonym and merge their own code to main without review. Homebrew
108.
▲
by
lrvick
1mo ago
Because it is trivial for unprivileged malware to phish the password and escalate to root. No production system should ever ship with sudo.
109.
▲
by
lrvick
1mo ago
To be fair it is easy for malware to escalate to root on any major linux distro because sudo is completely security theater. Malware just need to put this in ~/.bashrc and wait: function sudo () { realsudo=$(which sudo) read
110.
▲
by
lrvick
1mo ago
Oh I think there is a substantial chance the internet completely breaks before we learn anything and try a sane approach on the rebuild.
111.
▲
by
lrvick
1mo ago
TDD is just one of many options. Personally I rapidly have LLMs rewrite code over and over until it is super easy for me to understand and exactly what I want, and then I generate tests to prevent regressions. Regardless, I run a security a
112.
▲
by
lrvick
1mo ago
We see it every day in the news with hacks that were, in every single case, completely preventable. That is had any competent security engineers been involved, with leadership willing to fund the cycles to do it right. "But we passed S
113.
▲
by
lrvick
1mo ago
I am the founder of the project. We accept every contribution that solves a problem, even drive-bys. Though they may often sit for a bit as we often merge in batches. If there is something missing, make a PR by all means. Ask any questions
114.
▲
by
lrvick
1mo ago
> Many are not doing any of that I do. Most people sucked at programming before AI and they still suck after it. Who cares what "many" do. We as individuals can demand higher bars from ourselves and our teams. AI can increase t
115.
▲
by
lrvick
1mo ago
> The prompts are not analogous to a higher level of abstraction in this way; they are analogous to JIRA tickets. Your first prompt could be instructions to guide creation of a spec, which leads to a test suite you personally validate, w
116.
▲
by
lrvick
1mo ago
I spend a ton of time mentoring Jrs in FOSS communities, but I confess as a startup founder myself I could simply not justify hiring anyone but self-directed seniors until we are profitable enough to set some money on fire for what would ef
117.
▲
by
lrvick
1mo ago
I use agents to build exactly what I want like I am pair programming with a jr engineer, and review every line of final output before I make a PR. I would have zero tolerance if anyone that did anything less in my orgs. Owning and understan
118.
▲
by
lrvick
1mo ago
> Except LLMs actually are making programmers dumber. And compilers made every software engineer worse at writing Assembly and better at skills higher up the stack. This will be no different.
119.
▲
by
lrvick
1mo ago
https://stagex.tools Always happy to train up new packagers and maintainers.
120.
▲
by
lrvick
1mo ago
Without bootstrapping and reproducibility, you are trusting -one- person to build and sign for everyone else, and hoping their device was not compromised at build time. Single point of failure. Without deterministic full source bootstrapped
More ›