Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pilif
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
121.
▲
by
pilif
4y ago
The type of malware secure boot protects against can be made completely undetectable by the running OS and can be made to persist a full wipe.
122.
▲
by
pilif
4y ago
Secure Boot is designed to help with malware compromising boot code that runs before the OS gets to run and thus has the ability to hide itself from OS and everything running on it while also able to intercept everything an OS is doing. Giv
123.
▲
by
pilif
4y ago
Using this method requires admin rights though, but that’s probably for the better as running code of unknown provenance is probably a privilege of a machine’s owner
124.
▲
by
pilif
4y ago
From experience I can tell you that such a setup is very brittle and will fail the moment the one employee of that customer who knows about this is on vacation or working at a different place. The only thing that works reliably is a proper
125.
▲
by
pilif
4y ago
I'd say it's autocorrect at work. I'm really starting to believe that autocorrect is leaving society with worse written works than if we just kept the actual typos present. Most of the typos are just that whereas most of the
126.
▲
by
pilif
4y ago
Yes. A point release added an API to do this better and Apple has contributed a PR to OBS to make use of the new API: https://news.ycombinator.com/item?id=30112595
127.
▲
by
pilif
4y ago
The other big advantage over just being a gui is that it Scans the filesystem ahead of time and keeps the data across your navigation into directories. du will have to rescan as you traverse down the tree
128.
▲
by
pilif
4y ago
The question was about not using any of the built-in capabilities because they require the use of an app on a connected device which the poster thinks would be a distraction for their kid. The answer offers some options that will work witho
129.
▲
by
pilif
4y ago
... which is why I never understood why this is the convention rather than int* x, y. Does somebody know?
130.
▲
by
pilif
4y ago
While I could probably have done the first part myself, the moment the author went and updated the min API level to avoid the nagging pop up, I was seriously impressed and decided this was submission-worthy
131.
▲
Be 64-Bit to Ride This Ferry
(medium.com)
2 points
by
pilif
4y ago
|
1 comments
132.
▲
by
pilif
4y ago
I'm aware of that and those computers do not need to use any of these features. But if you're a FOSS project, why should you be advocating for security features to not exist if they provide value for a significant part of their us
133.
▲
by
pilif
4y ago
> you can't have one without the other, AFAIK, secure boot can be disabled, both in the BIOS and in the Kernel. In some machines that's not be the case due to contracts with Microsoft, but those already can't run Linux in
134.
▲
by
pilif
4y ago
If you were responsible for the security of your enterprise network, would you vehemently fight for your user's rights to run the ransomware executable they just get sent over email?
135.
▲
by
pilif
4y ago
If I was responsible for a large enough fleet of machines in my enterprise and I would have to deal with 100s of users of various technical knowledge while at the same time being blamed for the eventual ransomware attack, I would absolutely
136.
▲
by
pilif
4y ago
> They were on thin ice adding remote management (SSH) out of nowhere to what was supposed to be a VPN replacement. Now sysadmins and security have to deal with users randomly shooting files around between devices. historical note: Taild
137.
▲
by
pilif
4y ago
if we're talking about zsh history settings, I also recommend setopt SHARE_HISTORY HIST_IGNORE_DUPS SHARE_HISTORY will cause zsh to write to the history file after every command which means that two shells running in parallel won'
138.
▲
by
pilif
4y ago
I think you misunderstood my tale. I'm running a SaaS business and one of our customers users had this issue when they were interacting with the site because that end user's proxy server was arbitrary altering AJAX requests made b
139.
▲
by
pilif
4y ago
My favourite issue caused by a corporate firewall was when it altered an AJAX request to replace a specific combination of digits (in a long product ID) by asterisks. Turns out that a substring of that product ID matched the client company&
140.
▲
by
pilif
4y ago
Yep. That paragraph made me pause and consider that maybe OP is the victim of some compromised device running on their network. If two independent sites believe you are a bot, you or something at your address just might be.
141.
▲
by
pilif
4y ago
Apple has supported GNSS since the iPhone 8/X generation in 2017. This is about L5 GPS which I'm not sure how well this is supported in general ATM as its pretty new
142.
▲
by
pilif
4y ago
The fix is to clean the stems with alcohol. That will get rid of the corrosion building on the contacts. Also, as a preventative measure, before putting them in the case, make absolutely sure they are dry. As a runner, mine tend to get swea
143.
▲
by
pilif
4y ago
That was a nasty one, but then again, my recommendation would still be to use `pg_repack` over reindex concurrently because that one also gets you concurrent clustering and that one was not affected by this bug. I'm not downplaying the
144.
▲
by
pilif
4y ago
it was in the 2012/2013 time frame, so I can't find the relevant release note any more, but it was reliably returning wrong results for a specific sub query pattern. Not all of them were broken, but the broken one was returning wr
145.
▲
by
pilif
4y ago
To give some anecdata: I have been bitten twice by going to a .0 release with Postgres, once by index corruption and once by some subqueries returning wrong results in some cases. I have since decided to always wait for a .1 with Postgres b
146.
▲
by
pilif
4y ago
> down to the level of not over complicating their menus to be fair, their mobile UX has plenty of warts and behaviors that don't match platform expectations and are confusing (like what happens when you tap on any of the listed m
147.
▲
by
pilif
4y ago
not really. By banning the whole /64 prefix, you get the same effect that you got from banning a single IPv4 address.
148.
▲
by
pilif
4y ago
That's the root of the issue. The service is meant to be used by a system component but didn't or couldn't check whether that was actually true and the failure to check properly was overlooked in the security review. There&#x
149.
▲
by
pilif
4y ago
a git repo is practically a blockchain. Fixing this will require how git treats signatures, but no additional parallel architecture needs to be created.
150.
▲
by
pilif
4y ago
They have something under Settings > SSH and GPG keys where you can enable Vigilant mode. While that still allows pushing unsigned commits, it will flag them with a warning batch. I had this on for a while, but unfortunately as some open
More ›