Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
muricula
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
muricula
4y ago
Why do you think the choice of programming language will change the usage of a browser or its engine?
62.
▲
by
muricula
4y ago
Has this been fuzz tested? Fuzz testing is one of the best ways of discovering security vulnerabilities in C code, and tools like libfuzzer and asan or AFL make it easier than ever.
63.
▲
by
muricula
4y ago
Some folks may be interested in the Armv9 Scalable Matrix Extensions which appear to do something very very similar. https://community.arm.com/arm-community-blogs/b/architecture...
64.
▲
by
muricula
4y ago
At a glance, the debugger user interface looks much nicer than gdb's terminal ui. How tightly coupled is the debugger interface to the emulator/debugger engine? How much work would it be to plug in a different debugger, say lldb o
65.
▲
by
muricula
4y ago
Why would x86 L1 be limited by the page size? The cache works at 128 byte granularity. If it's too big it might increase tlb pressure I suppose, but it makes sense that increases in L1 would be best accompanied by increases in tlb size
66.
▲
by
muricula
4y ago
If you're going to port it to a different architecture, do arm64 or risc-v. Don't waste your time learning about the quirks of a processor lineage which has compatibility with features meant to solve problems from the 70s, like se
67.
▲
by
muricula
4y ago
> Has corporate America never had layoffs? Anyone who entered the tech industry in past decade+ has never experienced layoffs at this scale before. Young techies have experienced good times and high salaries. And the transition was quick
68.
▲
by
muricula
4y ago
Re the http endpoint, that's well and good, it just requires serialization and deserialization to a different protocol at the endpoint, which the docs led me to believe you wanted to avoid. There is probably an opportunity here to do i
69.
▲
by
muricula
4y ago
How does the runtime manage different levels of trust between clients? How does the language grapple with code injection vulnerabilities? If I want to be able to receive data from an untrusted entity, but not code, how do I make sure they&#
70.
▲
by
muricula
4y ago
Spectre does not require changing the CPU's microcode. You just need to be able to run native code or even javascript. https://security.googleblog.com/2021/03/a-spectre-proof-of-c... https://leaky.
71.
▲
by
muricula
4y ago
Wannacry used the exploit from EternalBlue to create one of the most famous ransomware worms in recent memory, and wasn't the only malware to leverage that one exploit: https://arstechnica.com/information-technology
72.
▲
by
muricula
4y ago
There are two parts to making chips: architecture (design) and process (how it's manufactured). Intel does both but eg Apple only does design and outsources manufacturing to other companies. There are lots of different chips ranging fr
73.
▲
by
muricula
4y ago
Iran gets trotted out as a strawman in these arguments, but its government is really quite democratic compared to many US allies which have the mere trappings of democracy painted on a dictatorship. Iran has an elected president, and a parl
74.
▲
by
muricula
4y ago
Like your internet service provider you already have??
75.
▲
by
muricula
4y ago
The article says whether a language runtime like v8 is a stronger security boundary than a hypervisor is a matter of debate, however v8 has boatloads of CVEs and the further isolation of browser sandboxes has been a driving factor in OS dev
76.
▲
by
muricula
4y ago
Seems fake. The image in the header appears to have been passed around the internet and reused, but may originate here in 2013: https://web.archive.org/web/20130912050353/http://www.pastho...
77.
▲
by
muricula
4y ago
I'm fairly sure that checkm8 doesn't affect apple silicon macs.
78.
▲
by
muricula
4y ago
Process and architecture are mostly independent. Node process is determined by the physical manufacturing. Architecture is determined by the design templated on during manufacturing. You could make an arm core on an intel process (which I t
79.
▲
by
muricula
4y ago
To quote the last sentence of the article: > Other major figures in the case settled years ago, including the builder and the owner of the private lockups and their companies, in payouts totaling about $25 million.
80.
▲
by
muricula
4y ago
PAC (pointer signing) & Branch Target Identification are not available on 32 bit arm chips, and judging by the assembly in the blog post the Titan M is a 32 bit chip.
81.
▲
by
muricula
4y ago
In a sense, finding security bugs is a very specialized QA sub-discipline, which often requires a far deeper understanding about security than many QA engineers or developers possess. However, there is also a part of that organization which
82.
▲
by
muricula
4y ago
Everything you said about memory space & bandwidth is 100% on point. However: arm arch 32 has 14 general purpose registers (including the link register). arm arch 64 has 31 general purpose registers (also including the link register). I
83.
▲
by
muricula
4y ago
yup :P
84.
▲
by
muricula
4y ago
What is this language's approach to memory safety? Does it guarantee there can never be out of bounds accesses, use after frees, double frees, or other memory corruption errors? Anything which talks to attackers over the internet is a
85.
▲
by
muricula
4y ago
A zero day bug in the pdf parser or javascript engine of your browser. Such bugs are common enough that the North Korean military is believed to use them to gather intelligence and for theft, but also are rare enough that they're going
86.
▲
by
muricula
4y ago
I have debugged the kernels of Windows, Linux and now iOS using internal tools. Windbg generally works, and is far superior to the equivalent tools for other kernels. Like vim it has a baroque syntax and a steep learning curve, but it also
87.
▲
by
muricula
4y ago
That's what the ios sandbox provides. Heck, the tools arm64 gives you to isolate VMs are awfully similar to the tools they give you to isolate processes. VM escapes aren't too different than sandbox escapes. Encrypted memory isn&#
88.
▲
by
muricula
4y ago
Oregon House is actually in California: https://en.wikipedia.org/wiki/Oregon_House,_California It's a confusing name.
89.
▲
by
muricula
4y ago
visual studio online is what it was called internally, the marketing may have changed. It's okay, and is what was/probably still is used at MS internally to develop windows.
90.
▲
by
muricula
5y ago
Here's an internal ABI doc which escaped Redmond at one point: http://www.openrce.org/articles/files/jangrayhood.pdf I believe there were other ABI docs but the official version of that was what I was given.
More ›