Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
roca
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
91.
▲
by
roca
2y ago
It was removed in 2011.
92.
▲
by
roca
2y ago
It's actually: you say you want to live in a world where there are no ads, and therefore no ad-supported content. Well, with a little self-restraint you can live in that world right now. What, you don't like that world after all?
93.
▲
by
roca
2y ago
Then I think it's only fair for you to completely stop using ad-supported sites and services, right away. (Which will also mean that Firefox's treatment of ads will not affect you.)
94.
▲
by
roca
2y ago
> I don't think there can be a technical solution to this problem unless advertisers are forced by government regulations to behave, with very heavy fines for non-compliance. Indeed, but such regulation is much more likely to happen
95.
▲
by
roca
2y ago
The Linux kernel supports pretty powerful APIs for inspecting and managing processes, like ptrace and seccomp and /proc, from another userspace process. There is no comparable set of APIs for hypervisors, unless Xen has something maybe
96.
▲
by
roca
2y ago
The assumption here is that you're modifying the hypervisor itself. No-one expects to be able to bolt a record-replay tool onto a third-party hypervisor.
97.
▲
by
roca
2y ago
The interface between userspace processes and the kernel and CPU is pretty complicated. It's hard for me to tell whether it's more or less complicated than the interface between guests and the hypervisor (given most record and rep
98.
▲
by
roca
2y ago
My instinct is the same as yours, but I'm also well aware of the "grass is greener on the other side of the fence" cognitive bias :-). So without actually having written a record-and-replay hypervisor, I hesitate to judge.
99.
▲
by
roca
2y ago
Makes sense to me. I organise a lot of hiking trips and I frequently have dreams where one of my trips has gone wrong and I'm trying to cope. It's a cheap way to simulate a problematic situation.
100.
▲
by
roca
2y ago
I wonder if this inspired the VMWare VM record-and-replay functionality that came out in 2008. They discontinued it in 2011, but it's important to me because we used it at Mozilla to great effect and that made it easier for me to get M
101.
▲
by
roca
2y ago
Dotcom did absolutely nothing to "upset people with power". He was always just an obnoxious hustler trying to make money by obviously illegal means.
102.
▲
by
roca
2y ago
Charging a fee for using it is a bad idea because then people will delay using it until it's too late. That's why in New Zealand, at least, there is no fee for a rescue callouts in general.
103.
▲
by
roca
2y ago
Bounded model checking is not a silver bullet. If you want to prove it is, verify a Web browser and blog about it.
104.
▲
by
roca
2y ago
The two approaches are completely different. gdb singlesteps the program and, before each instruction, records the state of registers and memory that will be changed by that instruction --- an undo log. Then you can reverse-execute an instr
105.
▲
by
roca
2y ago
https://pernos.co/about/javascript/ is somewhat like that.
106.
▲
by
roca
2y ago
One option would be to combine chaos mode with a dynamic race detector to try to focus chaos mode on specific fine-grained races. Someone should try that as a research project. Not really the same thing as rr + TSAN. There's still the
107.
▲
by
roca
2y ago
Actually the gdb implementation predates rr, but (as an rr maintainer) I have to say that it is vastly inferior to rr. It's about 1000x slower than rr, and can't record across system calls or multiple threads or processes. It'
108.
▲
by
roca
2y ago
rr supports Aarch64 pretty well now.
109.
▲
by
roca
2y ago
It's far easier to hide malicious code in C or C++: just write some subtle undefined behavior that you can write an exploit against. Developers do that all the time even when they're not trying to be malicious. In Rust you'd
110.
▲
by
roca
2y ago
What I'm curious about: other than checkbox compliance, how does Crowdstrike convince companies to buy their product? Do they present evidence that their product is effective at protecting customers? Because certainly Crowdstrike custo
111.
▲
by
roca
2y ago
Sort of. They need to be sued into bankruptcy. Current shareholders get completely zeroed out; the company still exists, but is sold to the highest bidder with the proceeds paid out to affected customers. We need this so that every company
112.
▲
by
roca
2y ago
Crowdstrike was hacked by Russians?
113.
▲
by
roca
2y ago
It is nothing like FLoC.
114.
▲
by
roca
2y ago
Yeah, I thought exactly the same thing. If you didn't know what kind of person Elon is after the Thai cave diver incident in 2019, you weren't paying much attention.
115.
▲
by
roca
2y ago
They mean something like the minmax algorithm used in game engines.
116.
▲
by
roca
2y ago
And yet a few people are doing it. So yeah, it's advice to insane people.
117.
▲
by
roca
2y ago
Those are interesting points, but disabling the JIT doesn't really change anything unless it means you can forgo site isolation, and that would be a very risky bet. It may be that disabling the JIT is fine for users most of the time. H
118.
▲
by
roca
2y ago
I could be wrong but AFAIK Safari still doesn't have site isolation, so security-wise it's considerably weaker.
119.
▲
by
roca
2y ago
Indeed you can incrementally improve existing engines, and certainly that's what you would try to do if you wanted one of those specific features. But I didn't write the post because I want those features, I wrote it in the hope t
120.
▲
by
roca
2y ago
I guess one of my points is that layout algorithms are not really part of the "most basic" decisions anymore. Replacing layout algorithms is actually a lot less disruptive to the engine architecture than switching to site isolatio
More ›