Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
notaplumber
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
notaplumber
6y ago
And it's just a port of the kernel wg(4) driver from OpenBSD, which was contributed by the Wireguard developers. It shipped in the OpenBSD 6.8 release in October. FreeBSD hasn't included it in a release yet. https://svn
32.
▲
by
notaplumber
6y ago
If you want a great firewall, try OpenBSD. That's where pf(4) came from, and is actually maintained. Not even FreeBSD has an up-to-date version. Also despite being the basis for the success of their product, and in their product name,
33.
▲
by
notaplumber
6y ago
Very recently as well. It's nice to see some rapid progress, certainly coming together. Good to hear the Ethernet is working on the M1 Mac Mini. Do you happen to know what device it is?
34.
▲
by
notaplumber
6y ago
Very few drivers have been written, beyond handling low-level SoC stuff. The ones that have been are explicitly mentioned in the linked article, stuff like USB which leverages existing Linux code. No keyboard, no trackpad, no GPU drivers (b
35.
▲
by
notaplumber
6y ago
So no then.
36.
▲
by
notaplumber
6y ago
Is it encrypted by default yet?
37.
▲
by
notaplumber
6y ago
KVM is the kernel virtualization module on Linux, QEMU handles the userland side support, all device emulation. The kvm binary on Linux is equivalent to running qemu-system-* with -enable-kvm. Newer versions of QEMU also support the '-
38.
▲
by
notaplumber
6y ago
This project is certainly covered under the Ancient UNIX licences. "Later, in January 2002, Caldera International (now SCO Group) relicensed (but has not made available) several versions under the four-clause BSD license." https:
39.
▲
by
notaplumber
6y ago
Another option might be pkgsrc, I'm sure someone's already looking at it. https://www.pkgsrc.org/
40.
▲
by
notaplumber
6y ago
File descriptor passing has been a common technique used in privilege separated design, used quite extensively in OpenBSD software. Other notable examples include Google's Chrome browser. It's quite telling how it's not menti
41.
▲
by
notaplumber
6y ago
AMDGPU It was significantly larger than the entire OpenBSD kernel sources. The dev/pci/drm directory ballooned to around ~130M. As of 6.8/-current, it's now 191M. It was under ~20M before May of 2019, prior to it first b
42.
▲
by
notaplumber
6y ago
Browsers having unfettered access to users files is something which should be mitigated against on all platforms, not fleshed out into an ill-conceived feature, it goes in complete contrary to browser sandboxing efforts in Chrome itself for
43.
▲
by
notaplumber
6y ago
Precisely. OpenBSD developers have committed John's diffs.
44.
▲
by
notaplumber
6y ago
Contributing to OpenBSD, not committing. He is not a committer.. yet.
45.
▲
by
notaplumber
6y ago
> I believe the best chance we have of doing that, is by gluing together the binary interfaces that've already achieved a decades-long consensus, and ignoring the APIs. Yeah, this isn't going to fly for OpenBSD, which doesn
46.
▲
by
notaplumber
6y ago
Sorry, poor choice of words I guess. I mean it's embedded within the filesystem. If you had root or serial access to the device, then you could probably very easily replace it, but at that point you could also just write the firmware a
47.
▲
by
notaplumber
6y ago
I think they were replying to me about the Linksys/Cisco routers, but it is similar in that the public key is contained on the filesystem and prevents flashing any firmware not signed with it. What's worse is they added this after
48.
▲
by
notaplumber
6y ago
At least a few models of Linksys/Cisco home routers I own had their firmware "encrypted" using GnuPG. They had the extension .gpg.img but could simply be decrypted with: $ gpg --output decrypted.img --decrypt <model><
49.
▲
by
notaplumber
6y ago
Nope. It's in the article. Just insert the key and ssh-add -K. I wouldn't be surprised if other SSH agents (e.g. Apple) added a UI to do this.
50.
▲
by
notaplumber
6y ago
You can, that's exactly what resident keys in this article is referring to. Once all of those platforms have a more recent OpenSSH, you can ssh-add -K to add keys to your SSH agent.
51.
▲
by
notaplumber
6y ago
You still do? EDIT: I see it now.
52.
▲
by
notaplumber
6y ago
This is simply not true. For a lot software you will get 1.3 automatically, for example mutt and irssi pick it up just fine. The existing APIs will work and LibreSSL will prefer TLS 1.3 over 1.2 if clients/servers support it. OpenSSL o
53.
▲
by
notaplumber
6y ago
To those wondering, LibreSSL has its own TLS 1.3 implementation. Client support shipped in LibreSSL 3.1.1. https://ftp.openbsd.org/pub/OpenBSD/LibreSSL/libressl-3.1.1-... https://www.openbsd.org&#x
54.
▲
by
notaplumber
6y ago
Yes. https://github.com/libressl-portable/portable/issues/595#iss...
55.
▲
by
notaplumber
6y ago
Saying something is pledged has a very specific meaning. And in this context, has no relevance to the discussion as none of the perl components in base make use of these bindings.
56.
▲
by
notaplumber
6y ago
No it's not. It has language bindings for pledge(2), which is different. There can be no one size fits all pledge for an interpreted language like perl, as programs can make arbitrary calls to anything they want. But those programs can
57.
▲
by
notaplumber
6y ago
Yeah, this confuses me. Gigabit is available in several places in North America. I had to check the date on the article.. posted 20 hours ago. Yep. Still confused.
58.
▲
by
notaplumber
6y ago
This type of separation would be better served with having multiple chrome user profiles. Like one for "work" and one for "home".
59.
▲
by
notaplumber
6y ago
Indeed, that part is accurate. It would be technically interesting if the tech demo was a part of UE5 source release. I'm not familiar if they've done that in the past.
60.
▲
by
notaplumber
6y ago
UE5 is not open source, it is shared source or "source available". Assuming it follows the model of UE4. https://en.wikipedia.org/wiki/Source-available_software
More ›