Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pilif
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
61.
▲
by
pilif
2y ago
I get that this is a super low level API, but yet, my expectation about an API that parses a buffer with length to a number and which has a specific enum for error cases as its return type would be that when asked to parse "9not a numb
62.
▲
by
pilif
2y ago
how can this be the ~5th iteration of a very wide-spread use-case and still contain a footgun? The API looks like it's following best-practice, with a specific result type that also contains specific error information and yet, that
63.
▲
by
pilif
2y ago
What an amazing article. And what amazing analysis of this 30 years old blob. This was super enjoyable to read. My only tiny gripe is that with the first quirk the author who insists that his implementation is bug for bug compatible lists t
64.
▲
by
pilif
2y ago
And not just that - also dependencies of dependencies. You have $FRAMEWORK using $BUILD_SYSTEM and depending on $NODE_VERSION which is running on $OS_VERSION in $ARCHITECTURE. Eventually, there will be a security flaw in $OS_VERSION which w
65.
▲
by
pilif
2y ago
I'm coming out of reading this a bit dismayed as I really thought that the `if let` (to use the swift conventions) pattern would finally be a good and reliable solution for these silent errors. And at the same time, reading the code in
66.
▲
by
pilif
2y ago
> We're in the process of operationalizing an opt-in to this technique oh the jargon > We're making progress by the minute I better hope you do.
67.
▲
by
pilif
2y ago
I think conversion rate and support cost associated with 2FA-OTP are worse enough for SMS to still be worth it, especially as a phone number also gives you a good marketing ability and a reasonably unique identifier for a user. If not, ever
68.
▲
by
pilif
2y ago
If I were to serve a targeted exploit like this, I would certainly hide it in the binary and have the binary determine whether it's running in the targeted environment and then run the payload. It's much, much easier to hide a mal
69.
▲
by
pilif
2y ago
True, but where's the difference between downloading a binary and executing it vs. downloading a script and executing that which will then download a binary and execute it? In both cases, you trust the publisher and in both cases the p
70.
▲
by
pilif
2y ago
Of the three distros I know to more detailed extents, Debian, Arch and RedHat, none of those make it easy to install and keep updated a third-party package through the built-in package manager. In all cases, signatures and repositories need
71.
▲
by
pilif
2y ago
I'm not OP, but here's my two qualms with using Sublime Merge for blame: * it doesn't do a good enough job following renames (in cases where you would need to use `--follow` to `git log`. `git gui blame` does. * while there i
72.
▲
by
pilif
2y ago
Sublime Merge is cough sublimely good at performing 3-way merges. I don't like it as much as a generic git frontend (nothing beats the command line once you're used to it, but for 3-way merges, it's absolutely perfect and I
73.
▲
by
pilif
2y ago
Called it: https://old.reddit.com/r/apple/comments/1c8vkid/idos_is_hope...
74.
▲
by
pilif
2y ago
Given the sandboxing and the security architecture of iOS, my conjecture is that apps could be perfectly safe even in light of the use of undocumented APIs (calls to which can be and are obfuscated even in today's setup) and accidental
75.
▲
by
pilif
2y ago
The problem is that a JIT implies that you can load arbitrary binary code into memory and execute it. This means that your app can load arbitrary updates from the server and execute them, for example based on some purchase not made in the A
76.
▲
by
pilif
2y ago
Would they? Apple Pay and Google pay are just proxies for the actual cards, so if a play does not accept a type of card, that will also be true for the virtual card presented by Apple Pay. I agree about PayPal, but they charge their own fee
77.
▲
by
pilif
2y ago
Checking the box is not enough. You also need to provide an API key for iTerm do be able to do any kind of uploads to OpenAI. If your auditor does not believe that with the checkbox unchecked and no API key provided, iTerm will not talk to
78.
▲
by
pilif
3y ago
That's my first point though. If you only take into account what is currently known about the backdoor, unless you are a linux distro building a liblzma debian or RPM package, you are not vulnerable to the backdoor. So I believe, given
79.
▲
by
pilif
3y ago
That's my second point. Just checking for version <= 5.6.0 is not safe either and is exactly what the original article has done. But if all you use as the basis of the vulnerability analysis is the version constraint and what we cur
80.
▲
by
pilif
3y ago
no. We have to assume any commit of the threat actor to have been malicious. Given that 5.4 contains code by the threat actor, it's not safe to claim to not be vulnerable. Not vulnerable to this specific backdoor, sure. But I don'
81.
▲
by
pilif
3y ago
While this is great news, in my opinion, given the facts surrounding this backdoor, I think this article is misguided due to two reasons: 1. the scope of the known backdoor is very constrained to only be inserted into native OS packages. As
82.
▲
by
pilif
3y ago
Can you point to a source of this? I think this was true in the past but isn't any longer. YouTube Premium is more expensive through iOS for example. What's not allowed is telling the users that it's available for cheaper in
83.
▲
by
pilif
3y ago
The control reflects how the equivalent of checkboxes look on mobile devices in native apps. So this is a great way to get to use the same control as the rest of the OS uses without having to implement it yourself in CSS and JS. This means
84.
▲
by
pilif
3y ago
One of the features of IPv6 is address autoconfiguration, obviating the need for a central authority like DHCP on v4. However, that only works with a /64 prefix and given that larger sites might want to have multiple subnets, that’s wh
85.
▲
by
pilif
3y ago
By keeping the whole WAL. The incremental backup would be just the WAL segments excluding the base backup. With this new feature, the WAL segments you need to store are much, much smaller.
86.
▲
by
pilif
3y ago
> why isn’t being a customer also considered parody I'm pretty sure you can claim that in a court. However, making an offline appointment with a hitman and then making them an offer and even making a first down payment for the servi
87.
▲
by
pilif
3y ago
According to the article, in this case it was a (pretty obvious) parody website and the webmaster called law enforcement on their own.
88.
▲
by
pilif
3y ago
This is very timely for me. Only two weeks ago, I learned that the bouncycastle Java FTP client library refuses to talk to servers that run with custom dh_params and I was wondering why because my intuition told me that custom parameters sh
89.
▲
by
pilif
3y ago
I guess adoption of browsers capable of displaying JPEG-XL as part of the overall browser landscape
90.
▲
by
pilif
3y ago
To be fair: that’s an old version (v6 vs v11). Given that win 3.11 doesn’t change, you can expect the old version to keep running too
More ›