Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
stusmall
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
91.
▲
by
stusmall
2y ago
Unless you hangout and get beers with her on the weekend, calling her Elizabeth might be a bit informal
92.
▲
by
stusmall
2y ago
The actix crate is deprecated. I looked on their site and repo and couldn't find an official announcement of deprecation but here is a link to what the lead said when I reached out with questions a few months ago: https://d
93.
▲
by
stusmall
2y ago
In this thread you can really tell who gets blocked on twitter a lot and are upset about it.
94.
▲
by
stusmall
2y ago
I remember I was screen sharing while troubleshooting something at a new job. I hadn't really set up my mac, and most everything was still defaults until I got a working build/deploy. One of the founding engineers said "You s
95.
▲
Mobile and Edge Solutions with MongoDB and Ditto
(mongodb.com)
4 points
by
stusmall
2y ago
|
1 comments
96.
▲
by
stusmall
2y ago
Yes. Default deny application firewalls are really powerful tool. It really can take the wind out of large classes of exploits. They can't phone home to exfil data or get follow up command. It isn't something I'd recommend
97.
▲
by
stusmall
2y ago
Yup. My configs can be found here: https://github.com/stusmall/nixos I tend to put all the random grab bags rules needed for basic functionality in the opensnitch.nix module. If a package needed rules it gets a modul
98.
▲
by
stusmall
2y ago
This is what finally got me over to NixOS. In the past when I've used application firewalls its a lot of set up that often breaks on updates changing paths or I have to redo it all whenever I move to a new computer. Just tons and ton
99.
▲
by
stusmall
2y ago
Respect to them for not naming names, that's the classy move, but I wouldn't blame them if they did.
100.
▲
by
stusmall
2y ago
They normally aren't serving from webservices but from subsidized CDNs.
101.
▲
by
stusmall
2y ago
>I know you're writing in agreement, but it sounds like your changelog is an intermediary step, and I don't understand why it's needed? To fill in the gaps from lazy commit messages? It's about the audience. * Commit
102.
▲
by
stusmall
2y ago
I've been recently working on the process to improve this at my day job. A coworker made a point to make very clear distinction between change logs and release notes, and its made a huge difference in how I approach and think about th
103.
▲
by
stusmall
2y ago
Their point is that the result changes depending on the request. It isn't a concern about the SRI hash not getting checked, it is that you can't realistically know the what you expect in advance.
104.
▲
by
stusmall
2y ago
Oooft. I didn't realize it's one that dynamically changes it's content.
105.
▲
by
stusmall
2y ago
I'm surprised there is no mention of subresource integrity in the article. It's a low effort, high quality mitigation for almost any JS packages hosted by a CDN. EDIT: Oh, it's because they are selling something. I don'
106.
▲
by
stusmall
2y ago
In the same way a lot of the other rules on that list are. How are they going to know you are familiar with the code you are committing? How are they going to know it is tested? Sometimes rules are established to set up a common community
107.
▲
by
stusmall
2y ago
It's definitely older than that. I remember implementing it at an old job. That device ran 4.4 and was later upgraded to 5. I know we had it in our 5 builds but I can't remember about the KitKat builds.
108.
▲
by
stusmall
2y ago
What a business card
109.
▲
by
stusmall
2y ago
It is their guess at what is happening without proof. That is the definition of a theory. It is about two entities secretly working together to do something harmful. That's a conspiracy. So... I mean... yeah. The comment is a perfe
110.
▲
by
stusmall
2y ago
So this didn't seem right at first glance. NPR just not covering a primary contest, and especially one as important as Iowa, seems wrong. I was curious and went to check. Sanders didn't even win Iowa.
111.
▲
by
stusmall
2y ago
If you were a direct employee of the government, went out and spoke publicly about your organization, in your official capacity, using confidential internal information when told you needed approval before hand, would you expect it to go di
112.
▲
by
stusmall
2y ago
You should scroll through more articles by the author of the linked post. His focus is on the media and ethics. He very regularly goes after NPR and member stations and airs dirty laundry. It isn't a reflexive thing. It's centr
113.
▲
by
stusmall
2y ago
Asking for a source isn't "blowing the disinformation whistle". It is a healthy thing. We should be skeptical about what we read on anonymous forums. Curiosity to know more and attempts to vet information is a good thing.
114.
▲
by
stusmall
2y ago
A lot of employers have this. This isn't that strange. You might have the same. I've had to run open source work past employers when it's similar to the company's domain.
115.
▲
by
stusmall
2y ago
If my college degree was focused only on technologies that were popular at the time, it would be worth significantly less today. Instead it focused on the concepts and theory that are timeless. When picking an architecture to teach on the
116.
▲
by
stusmall
2y ago
I know it isn't the point you are trying to make, but I can't think of a better way to re-enforce OP's point of "mediocrity will be even more available" than a mid-00s style, pop country song about eating hamburgers
117.
▲
by
stusmall
3y ago
Nix might even make it worse. xz made it into unstable and it is part of stdenv. This means almost every package needs to be rebuilt which takes forever and limits the speed in which it can be reverted. They still have 5.6.1 in unstabl
118.
▲
by
stusmall
3y ago
As I understand it warrant canaries are controversial in the legal community or at least were last I looked. Some of the questions you are exactly what they've asked. I don't know if any of the theories have been properly tested
119.
▲
by
stusmall
3y ago
I was really surprised to see that commit message. I wonder if they had that cleared? I'm guessing the committer didn't fully understand the concept.
120.
▲
by
stusmall
3y ago
The idea behind a canary is while they can tell you to keep it confidential, they can't compel your speech to lie and say you've never cooperated. Adding a wink wink nod nod code word defeats the idea.
More ›