Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tetha
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
tetha
3mo ago
The terms I've learned to use is rather: Happiness, and Stressors. If you need your car to earn money, and you don't have the money or other resources to repair it if it breaks - that's a huge uncertainty and a huge source of
32.
▲
by
tetha
3mo ago
I watched a talk by her about this, and this post is missing half of the equation, which is really important: Having a wrong abstraction means you end up with a class/function/module with a huge amount of configurations through bo
33.
▲
by
tetha
3mo ago
The world needs more confusing positivity. "You are beautiful and wonderful - keep going! (unlike this systems security)"
34.
▲
by
tetha
3mo ago
I've started something similar in my life. Chris Boltendhal (Founder of Grave Digger) has been criticizing how streaming services had turned music into a wallpaper, and others have too. Something that's just there in the backgroun
35.
▲
by
tetha
3mo ago
As the old joke went, the easiest way to not have detected covid cases in the country is to stop testing. Very simple, very effective.
36.
▲
by
tetha
4mo ago
Starcraft is too tame. You need to use Dwarf Fortress there and we need to make those strategy guides worded more realistic. Avoid kids, cook cats, wonder how to avoid mood problems due to birth in combat, and zombie meese and camels are a
37.
▲
by
tetha
4mo ago
Regarding 1 and 2, my pity is mild if this requirement forced companies to follow principles of secure software development, configuration and deployment. Injecting stuff from deployment config is not hard. 3 is valid and can be tricky, as
38.
▲
by
tetha
4mo ago
So release the server code as OSS, data necessary to function & support community servers. Even in a crappy hard-to-support way, the community will usually figure out a way. IMO, the move from community servers over to matchmaking &
39.
▲
by
tetha
4mo ago
Also the APT and RPM world lets packages sit for a long time - those are called "testing" and "unstable" in the Debian world. It's slow, but it seems hard to move intentional exploits with short-term payoffs through
40.
▲
by
tetha
4mo ago
Also, from the customer side, people ask at the higher end, don't they? Beyond a certain level, it's more of a search and a quest than just browsing. So you mainly have to show that you have connections for certain things. Why doe
41.
▲
by
tetha
4mo ago
Women in a committed relationship can enter a medical situation that renders then unable to work for 6-9 months, + 2 - 3 years of leave afterwards. Men don't, that's just a month or two twice. It is illegal, and in my book also im
42.
▲
by
tetha
4mo ago
A friend of mine had an interesting point there. It was more on a personal note that either of us had a hard time spending money on nice things for ourselves. Like, do you need better headphones, do you need this, do you really need that? B
43.
▲
by
tetha
4mo ago
ETHOS is generally reserved for a certain type of error involving slab memory and complex logic though. Let's hope that reference is not too obscure...
44.
▲
by
tetha
4mo ago
Three deterministic Linux LPEs in a week, an LPE in BSD in execve (of all things...), nginx vulnerabilities, one or two new gnarly supply chain attacks. Linus noting that the linux-security mailing list is getting flooded with duplicated, A
45.
▲
by
tetha
4mo ago
"Molten" to me implies it is still liquid. Molten salt reactors, molten magma from a volcano, molten sand, molten steel, dipping something into molten cheese. All fluid. If I was to nitpick, "melted" is kind of inaccurat
46.
▲
by
tetha
5mo ago
But in a perfect world, the question would be: Is it reasonable to expect an outage by sending a few single TCP packet to a system? Or, were you flooding the system unreasonably? It is a huge security risk to treat systems as ancient eggshe
47.
▲
by
tetha
5mo ago
Yeah. And I do think that security research should have some regulation about it, but it should be more about responsible handling of the privileged access you gained, or a responsibility to disclose found vulnerabilities in private and
48.
▲
by
tetha
5mo ago
> There are times when this is good, there are times when actively trying introduce an improvement is the best way forward. A good senior is able to recognise when those times are. This is what I was thinking - I'd say the biggest s
49.
▲
by
tetha
5mo ago
How do you define flawless though? The CVEs here have their fair share of silly C problems, but also more rigid input validation and handling. These more rigid validations exclude stuff which may even be valid by the spec, but entirely prob
50.
▲
by
tetha
5mo ago
I've also grown somewhat sensitive to duplication, maybe to a painful level. But, the memmove-call from the AI writeup has duplication in there: memmove(args->begin_argv + extend, args->begin_argv + consume,
51.
▲
by
tetha
5mo ago
We at work are currently going through the kernel modules available on Debian by default and deactivating things, yes. And sorry, but I am ... frustrated by this. Why do my Debian 11 servers (currently upgrading, yes) have support for phone
52.
▲
by
tetha
5mo ago
> In the extreme I think there's a decent chance projects like Debian might have to radically overhaul or just shut down completely - the whole philosophy of slow and steady with old code just won't work. It may actually be the
53.
▲
by
tetha
5mo ago
Out of this dataset of 2-3 vulnerabilities, I'm noticing a pattern: All of those are in older and/or niche kernel modules. That raises two thoughts: Maybe the more regularly used kernel code has a lot of low-hanging security topic
54.
▲
by
tetha
5mo ago
I can't even imagine that scenario with the remoteness of burning man. Wacken got really bad a few years ago. Like, it's normal to rain here, and it's normal for cars to not get off campground, so a dozen of farmers or two ar
55.
▲
by
tetha
5mo ago
Monitor your disks to see if they grow full, and have an idea what your storage baseline should be. Storage in /var/lib/docker/overlay2 can also leak, even if you prune regularly.
56.
▲
by
tetha
5mo ago
It does. It's also very nice that this moves storage usage from /var/lib/docker over to /var/lib/containerd. Due to that, a careless installation of a few new dev-systems under the new docker version immed
57.
▲
by
tetha
5mo ago
SecuROM back in the day caused plenty of legitimately purchased copies to not work. You'd have a physical disc with the game on it from the store, and SecuROM decided it won't work on your computer for unknown, undebugable reasons
58.
▲
by
tetha
5mo ago
I also have a Dungeon Crawl: Stone Soup with my first 3 runes around somewhere. I'm aware I will probably lose it, but I'm also anxious to touch it. Maybe I should just get myself some good coffee tomorrow and get over with it. Bi
59.
▲
by
tetha
5mo ago
Do have way too much fun with EICAR: https://www.youtube.com/watch?v=cIcbAMO6sxo This guy put the EICAR test string into a barcode and started to scan it on various systems, with rather funny effects.
60.
▲
by
tetha
5mo ago
And a lot of these older tools are not meant to be fed untrusted, unvetted input. The patch shown there confused me for quite a bit. Or, more snarky: tee is also a huge security problem if you pipe untrusted input into `tee -a /etc
More ›