Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
matrss
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
151.
▲
by
matrss
3y ago
> If the data is public and no login or personal/sensitive data is involved why do I need https? Do you care about if the data actually comes from your weather forecasting service and was not tampered with by a third party? Then you
152.
▲
by
matrss
3y ago
They make an (easily made) mistake on that page: the encrypted version of FTP is not SFTP, but FTPS. SFTP is an entirely different protocol based on SSH.
153.
▲
by
matrss
3y ago
ForgeFed sounds promising: https://forgefed.org/
154.
▲
by
matrss
3y ago
> Like tqdm (Python progressbar library) but as a Unix utility. FYI: tqdm can be used in a shell pipeline as well. It's documented (at least) in their readme: https://github.com/tqdm/tqdm#module
155.
▲
by
matrss
3y ago
> At the top, we have a not strictly POSIX compliant, multi-argument shebang: #!/usr/bin/env gsed -nE -f > It may break on some fringe UNIX implementations, but it is necessary for the system to work. I think I
156.
▲
by
matrss
3y ago
I just played a few matches on my phone and there seems to be some bug that can detect you as afk and loose you the game for no apparent reason (i.e. while making moves). It's really a good game otherwise.
157.
▲
by
matrss
3y ago
There is also nix-portable ( https://github.com/DavHau/nix-portable ), which is basically a drop-in replacement for normal nix that does everything required for no-root operation by itself when needed. Just put the singl
158.
▲
by
matrss
3y ago
Those still have the speed disadvantage of a phone camera and need more space than a compact document scanner, I'd imagine. I guess a ring light for my phone would be an improvement; using the builtin flash usually leads to very uneven
159.
▲
by
matrss
3y ago
I don't have an iPhone, but on Android there is the "Paperless Mobile" app ( https://github.com/astubenbord/paperless-mobile ), which can be used to scan as well. There are just some documents that I would
160.
▲
by
matrss
3y ago
I haven't been using it too much yet but I am really impressed by paperless-ngx so far. It just works(TM) and the auto-tagging functionality is surprisingly good, even with just a few documents in it. Does anyone have a good scanner re
161.
▲
by
matrss
3y ago
No, because a branch is a (re-assignable) name for some commit and cannot point at different commits while in the same repository at the same time. A "branch but at different commits" simply makes no sense. You can however create
162.
▲
by
matrss
3y ago
What is it missing? Using nix with nixpkgs you can pin all dependencies to a specific version identified by a hash value of that dependencies source code and dependencies, recursively building a dependency graph down to nixpkgs' bootst
163.
▲
by
matrss
3y ago
Nix ( https://nix.dev/ ) can provide all of this, although in a smarter way than just through dumping everything in the VCS. Some projects use it already to provide a reproducible development environment and if done right a c
164.
▲
by
matrss
3y ago
According to wikipedia they are both from 2005, although GNU Bazaar is indeed 12 days older.
165.
▲
by
matrss
3y ago
> However, I've long thought that motor vehicles should have some kind of black box that monitors various driving metrics such as how "smooth" the driving is. This could provide valuable data to insurance companies and the
166.
▲
by
matrss
3y ago
> And what kind of security do AppImages offer you? None and no one said that it does offer any kind of security. The criticism was entirely unrelated to that. On the other hand, flatpaks sandboxing is also severly limited by the fact th
167.
▲
by
matrss
3y ago
> All things considered, physical buttons and dials are probably easier and cheaper, because they don't require software updates! I am pretty sure there is a market for a dumb modern car, but no one is building it. I am thinking of
168.
▲
by
matrss
3y ago
I did not throw away any common-sense definitions. I never denied that the message is sent encrypted, i.e. is encrypted in transit. That is entirely irrelevant here though, since MS will be able to decrypt the message because they specifica
169.
▲
by
matrss
3y ago
I am really wondering how well Elixir with Nx would perform for computation heavy workloads on a HPC cluster. Architecturally, it isn't that dissimilar to MPI, which is often used in that field. It should be a lot more accessible tho
170.
▲
by
matrss
3y ago
Channels are, AFAIU, a reference to some point-in-time/commit/version of nixpkgs. They are exposed in the form of branches in the nixpkgs repository and used in some other places as well. A channel has a set of conditions that nee
171.
▲
by
matrss
3y ago
Nix is source-based. If you write your own "package definitions" you can distribute those in all the same ways you would use for source code, since they are source code. nixpkgs for example is a monorepo of many of those package d
172.
▲
by
matrss
3y ago
In addition to what was already said: systemd exposes (some of?) the same isolation features that are used by podman et al. to it's services as well. This can go as far as making the services software see only its state directory and n
173.
▲
by
matrss
3y ago
First of all, the article shows that it is indeed interceptable (although they didn't mention which additional steps, if any, were necessary to achieve that). And yes, the issue is obviously that it is send in a way that microsoft can
174.
▲
by
matrss
3y ago
What you are referring to is called an access token and has nothing to do with hashed passwords. A hashed password cannot be used directly to authenticate, otherwise it would not be a hashed password, but just a password (or access token, w
175.
▲
by
matrss
3y ago
Yes, it is literally encrypted in transit. This encryption, however, does not offer any value in protecting the user from microsoft stealing their credentials, because microsoft is the recipient of that encrypted message and is able to decr
176.
▲
by
matrss
3y ago
It would make it harder for them to impersonate their users and read all their mail. I would still be concerned that they want to run a rainbow table attack against it though. They should not steal user credentials at all, because it is sim
177.
▲
by
matrss
3y ago
It is not entirely clear to me from the article that this is the case. I'd assume that they had to at least install their MitM certificate into the OS's trust store to intercept that message. If not then this is indeed even worse.
178.
▲
by
matrss
3y ago
This shouldn't be just a fine. They exfiltrate a users credentials for another service without explicit consent and intercept a confidential communication channel between the user and their mail provider. This is straight up criminal b
179.
▲
by
matrss
3y ago
It is encrypted in transit, but Microsoft is on the receiving end of that transit and gets the plain text password. The encryption does nothing to prevent the third party, that is Microsoft, from impersonating the user and reading all their
180.
▲
by
matrss
3y ago
If I instruct fastmail or another provider to fetch mail from a different email provider on my behalf so that I have it in one place then that is a deliberate decision I make. If I connect to my mail provider via IMAP/SMTP from a local
More ›