Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pilif
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
17 ms
·
151.
▲
by
pilif
4y ago
The first paragraph in the “Root Cause” section explains: that binary has access to a service that’s allowed to bypass SIP restrictions. It’s required to have those capabilities because this is what’s used by Apple to install their OS updat
152.
▲
by
pilif
4y ago
They will continue to use UIKit / AppKit for their own apps. They will just make it so that doing so will require a private entitlement. 3rd party apps will be restricted to SwiftUI. Apple is very much in the camp of maybe tolerating t
153.
▲
by
pilif
4y ago
When I decided to move away from self-hosted git ages ago and then from Jenkins to GA two years ago, reliability was a huge factor in my decision because Github, I supposed, would be much better at keeping their infrastructure running than
154.
▲
by
pilif
4y ago
I see two answers to this: 1) if something is legal wherever the purchase was made, then the credit card companies, as basic utilities, should be compelled to process the purchase. which would be the easiest for me to understand, but possib
155.
▲
by
pilif
4y ago
1. I know. I'm talking about API keys though - they do expire after 90 days. See https://tailscale.com/kb/1101/api/ 2. For API keys, expiration cannot be disabled.
156.
▲
by
pilif
4y ago
I don't understand Tailscale's pricing structure: On one end, the features they are adding make the most sense if every machine that should be accessible is running tailscale. Both the fine-grained ACL support and now this SSH thi
157.
▲
by
pilif
4y ago
A calendar app provides a much smaller attack surface than a browser. It can also perform good enough without the need for JIT compilation. As I said in my comment: I believe Safari and the underlying WebKit to be the most complex and most
158.
▲
by
pilif
4y ago
Apple thinks (and I'm inclined to agree) that no browser engine is safe enough to be on the platform but as there has to be at least one by necessity, they might as well reduce the attack surface by restricting it to a single one that&
159.
▲
by
pilif
4y ago
I don't think an audit will be able to even coming close to validate the security of a piece of software with the complexity of a browser. As it stands now, WebKit and the processes hosting it (Safari, WKWebView) are probably the most
160.
▲
by
pilif
4y ago
> The only reason they disallow Chromium and Mozilla is they want their users locked into their environment and they want to leverage that substantial locked-in user base to dictate terms That's one reason, but not the only re
161.
▲
by
pilif
4y ago
It would also allow to authenticate sudo without you knowing for as long as you sit next to your machine
162.
▲
Private Access Tokens: Eliminating CAPTCHAs on iPhones and Macs with Standards
(blog.cloudflare.com)
2 points
by
pilif
4y ago
|
0 comments
163.
▲
by
pilif
4y ago
I'm really giddy to see this being made use of by Docker / podman as the currently used QEMU based solution is slow as molasses. In our case, the moment the M1 Macs came out, I have re-built our development images on ARM, but ther
164.
▲
by
pilif
4y ago
I agree with most points, but OCSP stapling is independent of ACME and thus is perfectly doable with nginx and an externally obtained let’s encrypt certificate. That aside, for me the trade-off was different and I was willing to give up th
165.
▲
by
pilif
4y ago
it's my understanding that most distros by now have moved to have their stuff in /usr, though there might still be backwards compatibility symlinks of course.
166.
▲
by
pilif
4y ago
having the system mounted in its own sub directory rather than be spread over multiple directories (there's /usr/bin, /usr/share, /usr/lib, etc) has the advantage that a single read-only mount can mount th
167.
▲
by
pilif
4y ago
> Of course you could just copy the code, but then that increases LOC in my codebase that I'm responsible for. Once your company is owned by a supply chain attack or by an RCE in one of your dependencies, you will learn that you a
168.
▲
by
pilif
4y ago
This is 1.24.2 while the phone was connected to my charger over night https://i.imgur.com/hQU6Orz.jpg Tailscale app not force quit but also not connected
169.
▲
by
pilif
4y ago
About the battery usage: what I can’t explain is that there’s a lot of background energy usage on iOS when Tailscale is running even when it’s not connected. If this was about heart beating, I would expect that to only happen when the clien
170.
▲
by
pilif
4y ago
also, their iOS client still has abysmal background battery usage even when not connected. It has been more than a year now, so, yes, seeing them improve in such areas would be cool. But given the huge amount of money invested, pressure wil
171.
▲
by
pilif
4y ago
With such a huge investment comes the obligation to eventually pay it back. Is this another one of my favourite tools going the way of Dropbox, 1Password and all other companies that were formed around what should be a platform feature, whi
172.
▲
by
pilif
4y ago
You can, but unless you own that address you won’t be able to use the app as you’re expected to type a code sent to the provided address
173.
▲
by
pilif
4y ago
In my country there are plans that allow for multiple additional devices to be linked to an account. I wouldn’t have to pay anything extra for a 5G MacBook. Which of course makes total sense technically. Because for my mobile operator there
174.
▲
by
pilif
4y ago
It disconnects whenever the laptop enters sleep mode, it causes the phone to run very hot and consume lots of battery and, yes, it requires manual intervention before it can be used. I agree that overall these are probably small issues, but
175.
▲
by
pilif
4y ago
Bugs exist. No question. What does bother me is where you detect the bug. Is it at compile-time? Is it at run-time through a crash? or is it months later after you notice that many of your users seem to have January 1st 1970 as their birthd
176.
▲
by
pilif
4y ago
Only in theory. In practice even when IPv6 is in use, people have stateful firewalls that will drop unsolicited connection attempts. Compared to ipv4 where there is UPnP and NAT-PMP with widespread support in routers, there are protocols to
177.
▲
by
pilif
5y ago
yes, but google will be spared the bad press when this issue goes through the press again as it seems to happen every few years.
178.
▲
by
pilif
5y ago
> Is this another such risk vector? no because there are other CAs which offer support for the ACME protocol. That's the good thing about open standards.
179.
▲
by
pilif
5y ago
It is backwards compatible, so this tells me that they added an additional check to prevent certificates for such domains to be issued. I think this is a security measure that prevents people from getting certificates for homoglpyh domains.
180.
▲
by
pilif
5y ago
if regular ssh is available, nothing stops people from building pipes with tar on both ends. This will be integrated into additional tools (future "show HN - scp replacement written in $FANCY_LANGUAGE that works even when sftp is disab
More ›