Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
saurik
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
91.
▲
by
saurik
11mo ago
At the top click "share" and then select the "long link". http://archive.today/2023.11.30-020758/https://www.theverge....
92.
▲
by
saurik
11mo ago
I just wish the default way people used archive.is was to generate their long form link instead of their short link, as, if the site ever goes down, all of the links people have posted where they don't change the setting and thereby pa
93.
▲
by
saurik
11mo ago
The socket should also not have a timeout.
94.
▲
by
saurik
11mo ago
How does the timeout help? Expose the lack of progress to the user and give them a way to give up; if they choose to walk away, then you stop. The only timeout should be in the head of a human that can make real decisions about how long too
95.
▲
by
saurik
11mo ago
Which is what the provider themselves have, by definition. The people who run these services are literally sitting next to the box day in and day out... this isn't "provably" anything. You can trust them not to take advantage
96.
▲
by
saurik
11mo ago
Yes: "provably" private... unless you have $1000 for a logic analyzer and a steady hand to solder together a fake DDR module. https://news.ycombinator.com/item?id=45746753
97.
▲
by
saurik
11mo ago
The existing WebTransport API implemented in all browsers actually supports you providing the fingerprint of a certificate that can be self-signed.
98.
▲
by
saurik
11mo ago
Yeah... it has felt kind of ridiculous over the years how many times I have tracked some but I was experiencing down to a timeout someone added in the code for a project I was working with, and I have come to the conclusion over the years t
99.
▲
by
saurik
11mo ago
If it sucked why didn't you just abort?
100.
▲
by
saurik
11mo ago
I think the modifications here are the "original work" in question. Like, I would be wanting to save the thing I spent a lot of time myself working on -- the edits to the photos -- in their "original format": the way Lig
101.
▲
by
saurik
1y ago
This is very similar (and maybe even the same thing) to some recent work (published earlier this year) by the people at Ritual AI on attacking attempts to obfuscate LLM inference (which leads to the design for their defense against this, wh
102.
▲
by
saurik
1y ago
The input isn't the training data, the input is the prompt.
103.
▲
by
saurik
1y ago
If I have my hardware under lock and key in my house, this lets me only trust the CPU vendor and not the software stack running on my computer when I try to verify that it is running exactly the workload that I intended. With a third party,
104.
▲
by
saurik
1y ago
If you can rely on truth being represented as 1 (or 3, fwiw) the same bitwise operations work fine.
105.
▲
by
saurik
1y ago
They don't require key rotation, though, merely certificate busy work; if they wanted key rotation they could try to add some mechanism for it, but I've been using the same key for over a decade now.
106.
▲
by
saurik
1y ago
> Its weird to me to see capitalists not wanting to accept payments for goods. Even the most hardcore capitalists refuse to take our money for their services, insisting on giving away free websites--some which don't even have any au
107.
▲
by
saurik
1y ago
I presume this FFI goes in both directions; some APIs really want the value of a boolean to be 1 while others really want it to be "all 1s"/0xfff.../-1 because, internally, someone decided to do something silly and compa
108.
▲
by
saurik
1y ago
> Look at Apple, their software game is mediocre now because of that culture, but they're at the top of their hardware game because instead of outsourcing and acquiring, they built in-house. Apple acquired Touch ID (AuthenTec) in 20
109.
▲
by
saurik
1y ago
At best this just makes them a patsy, which isn't actually better; but it, also becomes pretty clear if you pay more attention and dig into this (watch some of their interviews, etc.) that they actually DO care about the license, and a
110.
▲
by
saurik
1y ago
> When a company uses acquisition as a strategy to develop features, it is stagnating. At least it's past it's peak. I feel like you might just be ignoring tons of acquisitions... back in 2004, Goole went on a spree and acquire
111.
▲
by
saurik
1y ago
One way to correct this misalignment is to give the bounty platform a cut of the bounty. This is how Immunifi works, and I've so far not heard anyone unhappy with communicating with them (though, I of course will not be at all shocked
112.
▲
by
saurik
1y ago
This wording isn't as useful as it comes across at first, as the issue itself is often two-sided. Steve Jobs--one of the defining users of these phrases in tech--saying that it is important to exert his puritan values on everyone to pr
113.
▲
by
saurik
1y ago
While those are all "filesystems", they are also (internally) alternatives to MD RAID; like, you could run zfs on top of MD RAID, but it feels like a waste of zfs (and the same largely goes for btrfs and bcachefs). It thereby is
114.
▲
by
saurik
1y ago
So... one can, on a filesystem that is mirrored using MD RAID, from userspace, and with no special permissions (as it seems O_DIRECT does not require any), create a standard-looking file that has two different possible contents, depending f
115.
▲
by
saurik
1y ago
Well, I wouldn't say I have a beefy car or a beefy sword: there's some historical bit of linguistic connection that seems to have caused people to describe a server with the adjective "beefy", rather than "powerful&
116.
▲
by
saurik
1y ago
It's been a decade now, I guess, since Charlie Miller figured out how to hack into Jeep Grand Cherokees and remotely disable the brakes. https://www.wired.com/2015/07/hackers-remotely-kill-jeep-hig...
117.
▲
by
saurik
1y ago
That's a lot of people...
118.
▲
by
saurik
1y ago
So, the other standard that relates to this is Signed HTTP Exchanges (which, I only, just now, learned that Cloudflare I guess decided to, also just now, withdraw support of, lol), and I think when you fit all of these together, and look at
119.
▲
by
saurik
1y ago
<3 FWIW, I know Hacker News discussions often go stale after a bit and later responses might never be seen, and I don't really have time until later tonight to work on this (I used up my minutes earlier frantically reading this arti
120.
▲
by
saurik
1y ago
1) It seems strange that this spec isn't an extension of the previous cache manifest mechanism, which was very similar and served a very similar purpose: it listed all of the URLs of your web app, so they could all be pre-downloaded...
More ›