Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ratorx
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
ratorx
9mo ago
Wha do you mean by “fixing this” or it being a design flaw? I agree with the point about sequential allocation, but that can also be solved by something like a linter. How do you achieve compatibility with old clients without allowing somet
32.
▲
by
ratorx
9mo ago
Not sure what GP had in mind, but I have a few reasons: Cherry picks are useful for fixing releases or adding changes without having to make an entirely new release. This is especially true for large monorepos which may have all sorts of ch
33.
▲
by
ratorx
1y ago
Google’s SRE STPA starts with a similar model. I haven’t read the external document, but my team went through this process internally and we considered the hazardous states and environmental triggers. https://sre.google/stpa
34.
▲
by
ratorx
1y ago
Hmm, I see what you mean, although technically this is still a 2 factor compromise (Google account password + 2FA code). Just having one or the other wouldn’t have done anything. The bigger issue is the contagion from compromising a set o
35.
▲
by
ratorx
1y ago
Gotcha, thanks for clarifying! And did you have passwords using chrome password manager as well (which were also compromised by the Google account access, and this is how they got access to e.g. Coinbase?), or did they get passwords through
36.
▲
by
ratorx
1y ago
But if you get access to the inbox, then you have a compromised device or the password via some other means right? Inbox access is a fairly big compromise, even without the 2FA codes.
37.
▲
by
ratorx
1y ago
I’m struggling to understand the chain of events, because the story starts midway. Is the claim that JUST the 2FA code was enough to pwn everything with no other vulnerabilities? If that’s the case, then that’s a way bigger problem. Or (giv
38.
▲
by
ratorx
1y ago
These don’t prevent censorship necessarily, they will give you a way to detect it at best. DNSSEC gives you the ability to verify the DNS response. It doesn’t protect against a straight up packet sniffer or ISP tampering, it just allows you
39.
▲
by
ratorx
1y ago
It does say that they collect this information in their “Data and Privacy Policy”. Specifically section 2.2 (Data Collected): https://quad9.net/privacy/policy/ Which policy are you referring to that implies they d
40.
▲
by
ratorx
1y ago
This might work for the types you create, but what about all the code written in the language that expects the “proper” structure? > Types either represent the data or not This definitely required, but is only really the first step. Wher
41.
▲
by
ratorx
1y ago
> requires fewer predictions to discover I don’t think that is implied. It was discovered first, but that doesn’t mean it is necessarily simpler or required less data to discover. Take Newton/Leibniz calculus for example as a clear
42.
▲
by
ratorx
1y ago
Being pedantic, even if you have to pay for a type of car, you still have no variance to expectation when you know what you are getting. I think that point was more about the variance in driving, driver etc rather than car type. Re: enshitt
43.
▲
by
ratorx
1y ago
Memory allocators can be simple. In fact it was an assignment for a course in the 2nd year of my CS degree to make an (almost) complete allocator. However it is typically always more complex to make production quality software, especially i
44.
▲
by
ratorx
1y ago
Flakes seem a lot more magic under the hood, whereas Niv is just providing the arguments to existing Nix functions. They need special handling for nested dependencies (“follows” is a bit weird and hard to discover). With Niv, everything is
45.
▲
by
ratorx
1y ago
I’m building a (small) monorepo with Niv. It is much easier to understand and use than flakes. Flakes are simpler to use directly for sure (eg from CLI), but if you actually want to use them as dependencies, it becomes way harder to underst
46.
▲
by
ratorx
1y ago
> absolute nonsense rhetoric Could you explain why you believe this? Bayesian models at the scale of modern LLMs are not commonly used because the equivalent techniques (like MCMC) are more expensive, which limits how big and useful the
47.
▲
by
ratorx
1y ago
In my opinion, Bayes is the more general approach. But the Frequentist approach can be simpler if your prior is uniform and you only care about the output, not the distribution. E.g. Neural Networks, where the computational cost makes model
48.
▲
by
ratorx
1y ago
Your example is flawed because the example has nothing to do with the difference between Bayesian and Frequentist inference, because neither approach is needed. In the same way that you don’t use Bayesian approach, you also have not done an
49.
▲
by
ratorx
1y ago
Are you implying that Bayesian doesn’t use basic probability theory or gives a different answer? To calculate the simplest possible conditional probability, you need to have defined probability first.
50.
▲
by
ratorx
1y ago
I think the vast majority of SRE problems are in the “side effects” category. But higher level than the hardware-level side effects of the computer that you might be imagining. The core problem is building a high enough fidelity model to si
51.
▲
by
ratorx
1y ago
I don’t think it’s quite that simple. Taken to the logical extreme, everything above pure machine code is “abstraction”, but I don’t expect AIs to produce good machine code any time soon. Even if you consider trainability (amount of code et
52.
▲
by
ratorx
1y ago
Small providers can also be hit with the same bullet (depending on the wording), it’s whether the laws can actually be enforced, which is a cat-and-mouse game the same way piracy generally is. They are still providing a digital service in t
53.
▲
by
ratorx
1y ago
In this case, that seems pretty accurate? Trump is indeed the one that started the trade war. External enemies are easier to unite against etc.
54.
▲
by
ratorx
1y ago
systemd just provides the feature to use a custom external application to configure a service based on a declarative spec, which podman uses to create actual systemd services from a declarative container spec. From the podman docs: > Pod
55.
▲
by
ratorx
1y ago
> the security aspect It’s not a systemd-specific thing, but systemd makes it relatively easy to drop privileges (like network in this case), whilst also allowing socket-activated services to be configured easily. You can probably achiev
56.
▲
by
ratorx
1y ago
Well you enforce this with types. That’s how every other language does it. By specifying that the type of the function has to be a sanitised string, it will reject unsanitised string with the type checker. > it has no way of knowing if i
57.
▲
by
ratorx
1y ago
template1 is a function that takes in a parameter evil (with a SanitisedString type that wraps a regular str) and returns the fully expanded str. It is implemented by just returning an f-string equivalent to the t-string in your example. Sa
58.
▲
by
ratorx
1y ago
Right, but it is possible to write a template -> string function that doesn’t sanitise and use it (or more realistically use the wrong one). Just as it’s possible to unsafely cast an unsafe string to a sanitised one and use it (rather
59.
▲
by
ratorx
1y ago
Added example to parent comment.
60.
▲
by
ratorx
1y ago
Added example to parent comment. This example still works, the entire f-string is sanitised (including whatever the value of name was). Assuming sqlstring is the sanitisation function. The “template” would be a separate function that return
More ›