Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mr_mitm
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
31.
▲
by
mr_mitm
2mo ago
Everybody can device an encryption algorithm that they can't break themselves. That is not sufficient.
32.
▲
by
mr_mitm
2mo ago
Yes it is, for many use cases. I'd argue the syntax is much simpler, more modern, and perhaps even more consistent (the fact that in TeX you can change the meaning of the escape symbol or the comment symbol is pure insanity IMHO). It c
33.
▲
by
mr_mitm
2mo ago
Fun fact: archive.is can even bypass a lot of hard paywalls and no one knows for sure how they do it. There's been at least on debate on HN with no clear conclusion: https://news.ycombinator.com/item?id=36060891 They p
34.
▲
by
mr_mitm
2mo ago
I just checked. The AI DJ showed me a suggested request button with the prompt "late afternoon reggae rock with Lorna Shore". That's like suggesting pickled fish with strawberry ice cream just because you happened to order bo
35.
▲
by
mr_mitm
2mo ago
You don't think they have a genuine interest in providing good recommendations? A good algorithm will hook viewers more than a bad one. For the algorithm to work, they need to know what you like, and perhaps why you like it.
36.
▲
by
mr_mitm
2mo ago
> most software in the world uses a basic hash like MD5 or SHA-256 rather than a key derivation function For passwords? Where do you get that information?
37.
▲
by
mr_mitm
2mo ago
The cookie disaster is thanks to the ePrivacy Directive, which came before GDPR: - https://www.edps.europa.eu/data-protection/our-work/subjects... - https://en.wikipedia.org/wiki/EPrivacy_Dire
38.
▲
by
mr_mitm
2mo ago
Plus, the fact that they call the posts "truths" (as in "the president truthed", "ads are sponsored truths") couldn't be more Orwellian.
39.
▲
by
mr_mitm
2mo ago
It's convenient for those who already use npm. You are almost always not forced to install npm. You can choose another packaging path (OP supports a multitude) or choose the less convenient path of building it yourself.
40.
▲
by
mr_mitm
2mo ago
So be it. Publicly disclose the vulnerability and stop doing business with them.
41.
▲
by
mr_mitm
2mo ago
My first one (That happened: Wine snobs) is already hilarious! Looks like LLMs are coming for comedians next.
42.
▲
by
mr_mitm
2mo ago
AFAIK felonies in Germany require "intent", not "criminal intent". The guy could have stopped earlier, right after testing the password. But he decided to use it to view data which didn't belong to him. I realize I&
43.
▲
by
mr_mitm
2mo ago
The term is insufficiently defined and has overloaded meaning. In the original sense of the word, i.e. creative use of technology? Debatable, and most techies would probably land on the "no" side of the debate. Is it illegal? Depe
44.
▲
by
mr_mitm
2mo ago
It's a reference to this infamous post: https://news.ycombinator.com/item?id=9224
45.
▲
by
mr_mitm
2mo ago
Which also makes it not obvious how to uninstall it. pip/npm/cargo etc have well known mechanisms for that. curl|sh is convenient for container images I guess.
46.
▲
by
mr_mitm
2mo ago
From the article: > “I had the projector set up outside and was waiting for the sun to set,” wrote one Facebook user in Colorado Springs, “but to my surprise I was simply living in the past. AI informed me the sunset had already happened
47.
▲
by
mr_mitm
2mo ago
Next up: "I didn't do a statistical analysis but the sample size seems small"
48.
▲
by
mr_mitm
2mo ago
And here I thought using open source client software is the only way I, the user, can guarantee E2EE of my data.
49.
▲
by
mr_mitm
2mo ago
> NONE of my agents have broken away from their tasks and then started to communicate to try to hack something. With all due respect, you also aren't evaluating brand new models that haven't been released.
50.
▲
by
mr_mitm
2mo ago
Go creates `~/go` by default. It's not even hidden. Unfortunately, saying it's not really used that much doesn't help with this.
51.
▲
by
mr_mitm
2mo ago
Surely e-mail is even more widely used?
52.
▲
by
mr_mitm
2mo ago
My impression is that it's the NodeJS, Go and Rust communities that don't care about XDG. This 11 year old, open issue is very symptomatic of this IMHO: https://github.com/rust-lang/cargo/issues/1734
53.
▲
by
mr_mitm
2mo ago
True, I guess you might as well evaluate each vulnerability yourself without the CVSS base score.
54.
▲
by
mr_mitm
2mo ago
> - Firstly, you quickly realise how irrelevant CVSS scores are Even if you factor in the environmental score? I realize it's a lot more work, but it basically allows you to tune the score to get any value you want.
55.
▲
by
mr_mitm
2mo ago
Here is a recent example. Currently unpatched in Debian stable. https://www.cve.org/CVERecord?id=CVE-2026-60002 As I understood this, a malicious server can change its host key somewhere during key exchange and trigger a us
56.
▲
by
mr_mitm
2mo ago
Have you ever tested this on a real corporate network?
57.
▲
by
mr_mitm
2mo ago
Yes
58.
▲
by
mr_mitm
2mo ago
Just FYI, it says "lack", not "luck"
59.
▲
by
mr_mitm
2mo ago
I, a German, went to Switzerland for vacation once. I talked to a Swiss guy about how I like Switzerland and all that. I told him how impressed I was with how organized everything is and how well everything works. The train system and publi
60.
▲
by
mr_mitm
2mo ago
The way I read the article was that cancer is caused by deficiencies in the body's repair mechanism. It appears as if some have a more robust mechanism than others, depending on genetics.
More ›