Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rockdoe
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
rockdoe
4y ago
Isn't it more like that computing these flags is basically free in hardware? So might as well add support for it.
32.
▲
by
rockdoe
4y ago
Previously people pointed out that a lot of the extra M1 stuff (like TSO, x87 FP) is already standardized and/or has shipped in other ARM chips.
33.
▲
by
rockdoe
4y ago
I think the conclusions are a bit far fetched: "A generic Snapdragon ARM SoC, say, would deliver notably less performance in this specific scenario that is critically important to Mac users." The usage of these flags is NOT comm
34.
▲
by
rockdoe
4y ago
>intel nuc Gemini Lake chip? https://www.mozilla.org/en-US/firefox/106.0.5/releasenotes/
35.
▲
by
rockdoe
4y ago
Nothing forces you to write slow websites.
36.
▲
by
rockdoe
4y ago
They're literally saying Dolby and Fraunhofer are setting up this patent pool, so yes.
37.
▲
by
rockdoe
4y ago
This is the correct way to understand it. Dolby sells a bunch of codecs, and Fraunhofer sells USAC (which is basically Opus with some patented stuff added on). Their problem is that Opus serves many of those use cases for free. They can
38.
▲
by
rockdoe
4y ago
There are a LOT of commercial apps using Opus. Like Skype. It's more like - Opus' voice part IS Skype. Skype contributed all their patents, technologies and key engineers to the development of Opus.
39.
▲
by
rockdoe
4y ago
Alleged patents, or not even that, just an attempt to find some?
40.
▲
by
rockdoe
4y ago
Seems like it actually works similarly to the "old compatible path" described in the article: https://news.ycombinator.com/item?id=33153080
41.
▲
by
rockdoe
4y ago
The problem is that these are the locks in the memory allocator , so they cannot allocate any memory . Most high performance implementations don't need to operate under that limitation.
42.
▲
by
rockdoe
4y ago
I mean, SHA-3?
43.
▲
by
rockdoe
4y ago
Reminds me of "Your program shouldn't have bugs in it isn't an acceptable position to take for a debugger", from the rr folks. Unfortunately I can't find the source of the quote any more, but it stuck in my mind.
44.
▲
by
rockdoe
4y ago
Neither of these things are possible in a sandboxed browser: the syscalls are blocked, and the filesystem isn't (fully) accessible.
45.
▲
by
rockdoe
4y ago
On Linux the widgets are drawn by GTK and/or Qt, not Wayland. Also, the problem, I guess, is not just drawing (which could be done securely in a frame-buffer), but that you have to receive the events.
46.
▲
by
rockdoe
4y ago
My understanding is that same-old memory safety errors in C++ are still the main source of initial exploits for these browsers. Chromium has been looking at things like MiraclePtr, whereas Mozilla has been moving to Rust and RLBox (and Chro
47.
▲
by
rockdoe
4y ago
Firefox has also had this for over 5 years: https://www.mozilla.org/en-US/firefox/53.0a2/releasenotes/ The current mitigations seem to be doubling-down on getting rid of C++ memory safety errors (still t
48.
▲
by
rockdoe
4y ago
This is not correct - like the person you're responding to, you're mixing up security features. For one, Chrome predates Windows 8, where this mitigation was introduced, so it can't have supported it before it existed. I thin
49.
▲
by
rockdoe
4y ago
You can probably still have a meaningful bpf sandbox even without the setuid root helper (or user namespaces), but I'm not sure Chrome supports running that way (because it doesn't make much sense from a security tradeoff point of
50.
▲
by
rockdoe
4y ago
I mean in the rewards. A lot of those "desktop apps" have embedded "WebViews", if you know what I mean, which would effectively be running outdated Chrome versions, which would be easier to exploit than the real thing.
51.
▲
by
rockdoe
4y ago
Would the majority of the current "desktop" software actually being outdated Chromium/Electron/CEF stuff factor into this too?
52.
▲
by
rockdoe
4y ago
>I don't want FireFox or Chrome reading ~/.ssh or ~/.gnupg or any other directories in my home that it has no business reading. Both browsers already do this for the processes that are exposed to the internet. The software
53.
▲
by
rockdoe
4y ago
Unix applications run as a user, so it's not like they have that permission. Looking at that profile, it restricts write access to the home directory to only the Firefox profile and some config files. I guess that makes sense, but you&
54.
▲
by
rockdoe
4y ago
>It doesn't It does require one if your system doesn't support user namespaces. Some distros used to disable it, but they're getting rare these days.
55.
▲
by
rockdoe
5y ago
This isn't atypical for high performance network software, AFAIK. Single-thread with aio.
56.
▲
by
rockdoe
5y ago
I think the length of the explanation is due to the impact this had. Most Firefox bugs don't cause all Firefoxes everywhere to stop working simultaneously. That's quite the WTF and it's hard to understand how it is even possi
57.
▲
by
rockdoe
5y ago
Software shouldn't have bugs, got it. It should be written by bug-free programmers that foresee every possible failure mode (that they can never imagine happening, because they won't write bugs themselves).
58.
▲
by
rockdoe
5y ago
Not sure I'd consider a "CTO" to be the "lead dev". Definitely not in a bigger org.
59.
▲
by
rockdoe
5y ago
>Before Firefox went multi-process it handled package updates just fine No, the problem was just less common and things randomly stopped working or crashed instead of getting the warning page. In theory you can design the browser so it k
60.
▲
by
rockdoe
5y ago
Security updates for the browser, certificate checks (so you know it's the right website you're connecting to....) you can't get away from.
More ›