Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
taviso
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
taviso
2y ago
I think they're talking about the cp example, doesn't seem like it would handle filenames with spaces! Super neat project, btw!
32.
▲
by
taviso
2y ago
Super cool, I didn't know about this - too bad it's not archived. I did know about a different game for 1-2-3, I even managed to track down original media and get it working in Linux! https://lock.cmpxchg8b.com/doo
33.
▲
by
taviso
2y ago
I dunno, I think Debian are being wise here. A while ago KeePassXC published a glowing audit report, but the report just ignored the scary stuff -- i.e. the things being disabled here like browser integration. I took a quick look, and thoug
34.
▲
by
taviso
2y ago
> Testing cannot be used to prove that a flaw doesn't exist, only that it does. FWIW, I wrote a similar blog post about a different encryption bug that really seemed like it should have been found by fuzzing, and had 100% coverage
35.
▲
by
taviso
3y ago
I think I feel the same way, lag has never occurred to me when using xterm -- and I use the heavier features like translations and sixels day-to-day. Maybe it's just the Athena widget style that is making people dismiss it, because it&
36.
▲
by
taviso
3y ago
The issue here is that the vendor did release patches, but then tried to hide that they fixed a vulnerability. This is usually called "silent patching", and it's controversial. As with any disclosure discussion, there are
37.
▲
by
taviso
3y ago
Here are some examples! https://github.com/taviso/ctypes.sh/blob/master/test/select.... https://github.com/taviso/ctypes.sh/blob/master/test/poll.sh Yes, it
38.
▲
by
taviso
3y ago
They should have used my (dumb?) library, ctypes.sh: https://github.com/taviso/ctypes.sh Then they can access libm, poll(), select() and so on from bash :)
39.
▲
Hiew Hex Editor
(lock.cmpxchg8b.com)
194 points
by
taviso
3y ago
|
47 comments
40.
▲
by
taviso
3y ago
The group selection the spammers target seems really strange, alt.comp.freeware is another example. Not sure I understand what they're trying to achieve. (I tried to raise the issue internally, fwiw).
41.
▲
by
taviso
3y ago
I've been reading through vintage computer magazines in my spare time - this is from Unix Review, February 1986 issue. I was just struck with how this could almost be talking about GPT-4 or copilot, 40 years ago! The technology must ha
42.
▲
Artificial Inroads: Science gets down to business (1986) [pdf]
(lock.cmpxchg8b.com)
11 points
by
taviso
3y ago
|
2 comments
43.
▲
Hacking the Timex m851
(lock.cmpxchg8b.com)
313 points
by
taviso
3y ago
|
82 comments
44.
▲
by
taviso
3y ago
Yes, exactly... :) You can also create callbacks (i.e. function pointers to bash code) that you can pass to qsort() or bsearch()... or pthread_create? That last one was a joke, I mean, you probably could but I don't know what would hap
45.
▲
by
taviso
3y ago
It's a funny trick, but you could probably also use setjmp and longjmp with ctypes.sh :-) https://github.com/taviso/ctypes.sh
46.
▲
by
taviso
3y ago
I'm not really sure, cpu and bandwidth utilization were fine. Memory usage was high, but not oom high. It continued serving over http just fine, perhaps there was some automated rate limiting by my provider. I'll have to debug whe
47.
▲
by
taviso
3y ago
Yes. It was unexpected, but good. Not a complaint.
48.
▲
by
taviso
3y ago
An msr is a "model specific register", a chicken bit can configure cpu features. They don't persist across a reboot, so you can't break anything. You can undo what you just did without a reboot, just use `... & ~(1 &
49.
▲
by
taviso
3y ago
welp, that's unfortunate indeed. It's a single-core 128 MB VPS, which seemed fine for my boring static html articles. I guess I underestimated the interest.
50.
▲
by
taviso
3y ago
123 was indeed ported to UNIX, I have that working as well! https://github.com/taviso/123elf (Although it was more likely procalc - a popular low-end lotus clone) I'm also working on porting dBase IV, another popu
51.
▲
by
taviso
3y ago
A text editor and a word processor are different things. There are things you can do very easily in a word processor that are difficult in a text editor, and vice versa. I actually wrote a FAQ about this! https://github.com/
52.
▲
by
taviso
3y ago
If you're looking for a more full-featured terminal word processor, you could take a look at wpunix! https://github.com/taviso/wpunix
53.
▲
by
taviso
4y ago
I'm still a daily gmane user, thankfully you're mistaken and it's still alive and well, just nntp only (news.gmane.io)! I honestly don't know what I would do if it did die, it's such a large part of how I use the in
54.
▲
by
taviso
4y ago
I remember watching someone insert a credit-card sized SIM into a StarTAC when I was a kid. It blew my mind, it looked like a Star Trek communicator.
55.
▲
AMD Zen2 ymm registers rolling back
(lkml.org)
277 points
by
taviso
4y ago
|
130 comments
56.
▲
by
taviso
4y ago
It's still useful on non-simple compilers when mixing inline assembly and c, for example `register __m128 foo asm("ymm7")`. I realize that's a gnu extension - but it's super useful!
57.
▲
by
taviso
4y ago
The attack here was that if you get tricked into giving a phishing site your password and Web USB access to your U2F key and then you press your U2F key, then the attacker can bypass the 2FA. I highly doubt this ever happened in real li
58.
▲
by
taviso
4y ago
Do you think you might have argued against the internet when it was being deployed? It sure opened the door to a lot of scams, and was far from a perfect solution. Yet it does seem to have had a net positive effect. Maybe that can be true o
59.
▲
by
taviso
4y ago
Web USB can realistically improve security for billions of people globally. It will improve security for me and my family, and we're all humans. Sure, it's not a magic a wand that solves all problems, or makes malware disappear. I
60.
▲
by
taviso
4y ago
I think I need to see some data to back up your claim that Web USB makes socially engineering "catastrophically worse". Web USB is deployed today for a billion users, and yet attackers still seem to prefer malware or walking victi
More ›