Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
neerdowell
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
neerdowell
10y ago
They're likely referring to Solaris Zones and FreeBSD Jails.
32.
▲
by
neerdowell
10y ago
> It fails in a poorly set up chroot, not any old chroot. It fails for any program that calls chroot(2) and chroots to a location that hasn't had /dev/urandom constructed, which is... almost every program that sandboxes
33.
▲
by
neerdowell
10y ago
/dev/urandom isn't reliable; it fails in a chroot, if file handles are exhausted, etc.
34.
▲
by
neerdowell
10y ago
I wonder how many of the 18 also disagree with her views on Israel (and how many of the 33, in the interests of curiosity).
35.
▲
by
neerdowell
11y ago
Software has to play nice and not request WX pages. If they do, the OS does as its asked. See also, Theo de Raadt's recent comment on why OSes can't enforce W^X on userland (yet): https://marc.info/?l=openbsd-misc&
36.
▲
by
neerdowell
11y ago
Whisper System's announcement of this: https://whispersystems.org/blog/whatsapp-complete/
37.
▲
by
neerdowell
11y ago
OpenBSD's malloc(3) implementation is found in sys/kern/kern_malloc.c, and OpenBSD's malloc(9) implementation is found in lib/libc/stdlib/malloc.c
38.
▲
by
neerdowell
11y ago
uBlock Origin is a fork of uBlock by the original developer of uBlock. They are essentially the same addon except uBlock Origin has more features and is more actively maintained (development of uBlock pretty much stopped after the fork).
39.
▲
by
neerdowell
11y ago
> or including proprietary services (e.g. Pocket) forcing the creation of the Icecat fork. Your timeline is off by about a decade. IceCat was first released in 2008 and the GNUzilla project has existed since 2005. Firefox added Pocket
40.
▲
by
neerdowell
11y ago
That traffic is from IPredator's relay, which is currently the top exit node by consensus ( https://globe.torproject.org/#/top10 ). There are less than 50 relays in Australia and none of them come close to IPredator
41.
▲
Firefox performance regressions
(marc.info)
2 points
by
neerdowell
11y ago
|
0 comments
42.
▲
by
neerdowell
11y ago
Does nissan.com meet the criteria for the sort of thing you're writing about?
43.
▲
by
neerdowell
11y ago
"currently maintained" seems to imply that this is a recent thing, so just to point out, millert has been maintaining sudo since before 1994.
44.
▲
by
neerdowell
11y ago
> the worst generator you can think of Decrementing the seed by 1 with each call[0], which is a standards-compliant rand implementation. Although it looks like a standards-compliant Math.random() implementation isn't allowed to be
45.
▲
by
neerdowell
11y ago
Chrome meets their criteria too, when bundled with other software, example: https://i.imgur.com/MakuHWC.png It deceptively claims to increase web speeds, piggybacks on CCleaner's installation, doesn't inform the u
46.
▲
by
neerdowell
11y ago
`tar -xf` is not "explicitly asking" for gzip. `tar -zxf` is "explicitly asking" for gzip. I don't really care what vim does, that's a different argument. There have been many vulnerabilities in gzip, and in ta
47.
▲
by
neerdowell
11y ago
It tells you how it's compressed and how to decompress it if it knows how. OpenBSD's tar doesn't support xz so it can't help there, but does support gzip so it suggests using -z. Not letting untrusted input automatically
48.
▲
by
neerdowell
11y ago
And many implementations don't behave that way.
49.
▲
by
neerdowell
11y ago
Correct, on OpenBSD: $ tar -xf foo.tar.xz tar: End of archive volume 1 reached tar: input compressed with xz $ tar -xf foo.tar.gz tar: End of
50.
▲
by
neerdowell
11y ago
> I'm not defending or apologizing for OpenSSL (or any project), but your rationale isn't consistent, seemingly only trying to evoke an emotional response. The GP is pointing out that LibreSSL has avoided the 5 vulnerabilitie
51.
▲
by
neerdowell
11y ago
> That script is FOSS; you can see exactly what it wants to do. Any method of automatically renewing certificates, regardless of what script it used, is going to require the privileges needed to alter the certificate file. The only way
52.
▲
by
neerdowell
11y ago
With the practicality of something that only worked on Debian systems aside... > Between Let's Encrypt and StartCom ... What do we have? StartCom doesn't allow their free certificates to be used for commercial purposes and w
53.
▲
by
neerdowell
11y ago
> Is it that they think the OpenBSD source layout is hard to understand OpenBSD's source tree layout is almost the same as FreeBSD's. In both trees the source for the various CLI tools lives in src/bin/, src/sb
54.
▲
by
neerdowell
11y ago
> I know of no website that contains user-uploaded pictures that allows SVGs Wikipedia.