Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
roblabla
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
91.
▲
by
roblabla
2y ago
> It's not clear to me they are so different but maybe I am not "sufficiently smart". They're different because linux promises "eBPF are safe and cannot crash the kernel", and failed to deliver on that, whil
92.
▲
by
roblabla
2y ago
It's possible CS can do better, of course. But it's just wrong to blame them for the Linux crashes - they're not the ones that introduced buggy code and broke their users. RHEL/Linux did.
93.
▲
by
roblabla
2y ago
There's a simple thing microsoft could do to avoid this, that doesn't require anything too crazy. EDRs work in kernel-land because that's the only place you can place yourself to block certain things, like process creation, d
94.
▲
by
roblabla
2y ago
> From my understanding the CS driver lives in the kernel space and parses configs/applications downloaded in the user space. Hence the system even does a BSOD. That's my understanding as well, but not quite the same as > ex
95.
▲
by
roblabla
2y ago
Again: this is not a kernel module. eBPF probes are meant to be Compile Once, Run Everywhere, that's their whole point! https://facebookmicrosites.github.io/bpf/blog/2020/02/19/bpf... If you ex
96.
▲
by
roblabla
2y ago
Unless you have a source, you should really avoid spreading misinfo here. CrowdStrike doesn't have kernel-level ACE. It has a buggy configuration parser, and they pushed a corrupted config that triggered those buggy codepath in the par
97.
▲
by
roblabla
2y ago
Yeah, the fact that Windows requires kernel-level access to be able to do EDR stuff is really unfortunate. MacOS has been very successful with their userspace EndpointSecurity Framework for this purpose. On the other hand, Linux is similarl
98.
▲
by
roblabla
2y ago
@watt there's a big difference here. eBPF is a bytecode that is interpreted in the kernel, with the explicit goal to allow writing code that executes at the kernel-level in a safe way. Any kernel panic (again, short of pid1 kills) is c
99.
▲
by
roblabla
2y ago
1.An eBPF probe is not a kernel module. An eBPF probe should never cause kernel panics. 2. RHEL didn't provide beta kernels before very recently, as far as I can tell. 3. Even if you caught an error then, you're still at the mercy
100.
▲
by
roblabla
2y ago
Yes, and? They probably do test their software on RHEL. But how are they supposed to prevent a bug in a newly released kernel update? You can't test your software on future updates that aren't out yet. If RHEL breaks some core fun
101.
▲
by
roblabla
2y ago
Do you have a source for this? It's the first time I hear of this. From what I've understood (perhaps wrongly), the error came from the CrowdStrike driver (csagent.sys) having bugs in their configuration parser that could cause it
102.
▲
by
roblabla
2y ago
This is some very poor journalism. The linux issues are so, so very different from the windows BSOD issue. The redhat kernel panics were caused by a bug in the kernel ebpf implementation, likely a regression introduced by a rhel-specific pa
103.
▲
by
roblabla
2y ago
Highly suggest trying orion browser on iOS. It supports webextensions, so you can install ublock origin.
104.
▲
by
roblabla
2y ago
> the advertisers could simply block Firefox en-masse and survive And why would firefox users care about advertisers blocking firefox? Oh noes, ads aren’t showing up in my browser!
105.
▲
by
roblabla
2y ago
> A camera should be by definition running on dedicated camera firmware, and nothing else. Says who? There's no intrinsic reason a camera couldn't run with an Android OS. In fact, there's a lot of good reasons why you woul
106.
▲
by
roblabla
2y ago
Where'd you get $195/yr? EV certs are usually around $400/yr last I checked. In that sense, $10+$5/mo is a _huge_ discount.
107.
▲
by
roblabla
2y ago
If you're OK with unsupported means, there are ways of bypassing that limit. See https://khronokernel.com/macos/2023/08/08/AS-VM.html .
108.
▲
by
roblabla
2y ago
Do you also audit the sources of the programs installed by that install.sh? Do you make sure the binaries and sources match? If not, why? What makes the shell script so special that it must be audited with care, but the binaries are fine?
109.
▲
by
roblabla
2y ago
no, it doesn't? It changes your publicly visible IP. Your GPS data still shows you in the original location. Your wifi localisation and 5g antennas would still be in the original location. It'd also be _trivially easy_ for the OS
110.
▲
by
roblabla
2y ago
I mean, worse case scenario, your phone just locks (I assume to the lockscreen, where you have to re-enter your pin). It doesn't seem like such a big problem?
111.
▲
by
roblabla
2y ago
I had the same problem. I had to long press the download button and open in a new tab for it to do anything. It then showed the popup saying I needed to allow installation of the app in the settings before long-pressing download again.
112.
▲
by
roblabla
2y ago
> Congress has avoided the responsibility of passing new harsher antitrust legislation that simply skips the lawsuits and goes straight to fines. How would that work? Do you have some example of proposed legislation around this?
113.
▲
by
roblabla
3y ago
Dolphin ships with a bunch of keys in the source code[0]. So do almost every other emulators for any console from 6/7th gen consoles (ps3, xbox360, gamecube), see delroth's post on the matter here[1]. It's really not that sim
114.
▲
by
roblabla
3y ago
call it what it is: random bullshit.
115.
▲
by
roblabla
3y ago
If you want to codesign and notarize your binary from linux, you can also use rcodesign[0]! I've been using it in production for about a year, and it's been working great so far. [0]: https://gregoryszorc.com/docs&
116.
▲
by
roblabla
3y ago
That's a weird take given bash doesn't have _any_ dependency management. At least with XonSH you get something? Also, I'm not sure what issues you're hinting at - my experience with python dep management is that, althoug
117.
▲
by
roblabla
3y ago
> There's nowhere in the GPLv3 that says that (then again, that sentence doesn't imply there is) It does, commonly called the anti-tivoization clause. Here's the text: > “Installation Information” for a User Product mea
118.
▲
by
roblabla
3y ago
Actually, BitTorrent v2 (as specified in BEP 52) has per-file hash trees, so it supports sharing a swarm if the same file is shared between different torrents. Not a whole lot of torrents use it though.
119.
▲
by
roblabla
3y ago
They also got the contributors of the extensions repository. Tachiyomi had one big monorepo where most of the extensions were being developed. So it'd be pretty easy to get the list of extensions contributors.
120.
▲
A supply chain attack on PyTorch
(johnstawinski.com)
463 points
by
roblabla
3y ago
|
101 comments
More ›