Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
winstonwinston
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
winstonwinston
2mo ago
The blog post is painfully vague. What usually happens when you publish a package on PyPI is that it will be downloaded tens of times shortly after uploading files by some 3rd-party automatic security scanners which then could “detonate” (i
32.
▲
by
winstonwinston
2mo ago
It’s the OneDrive installing new OneDrive Photos app. It happens on any Windows version, such as Server 2025 that has OneDrive installed. It isn’t limited to Windows 11.
33.
▲
by
winstonwinston
2mo ago
Realistically spoofed address (unauthenticated email) will be treated as spam and it’ll be implicitly quarantined or rejected as such by many well-known mail receivers. You can make this an explicit “reject” by publishing DMARC policy for y
34.
▲
by
winstonwinston
2mo ago
To be fair, it’s used by only those who choose to use horrendous “mta-sts” instead of DNS-based Authentication of Named Entities (DANE). I might add that if you want to enforce SMTP TLS, you can do just that without mta-sts or DANE.
35.
▲
by
winstonwinston
2mo ago
Hash pinning (already) works, and this change is all about when you as a PyPI user do not use hash pinning for installing releases, when you pin just release version for example. The release consists of one sdist and zero or more wheels. Un
36.
▲
by
winstonwinston
2mo ago
> "Our model is powerful enough to commit multiple felonies (and we can't stop it)" is "marketing," I suppose. Well this bad publicity (if that’s how you want to frame it) certainly captured everyone’s attention.
37.
▲
by
winstonwinston
2mo ago
Using strong password as you suggested is a solved problem for your use case, but that is not universal. Passkeys provide universal security for all. Also PIN or biometrics verification to access passkey from device bound TPM or security en
38.
▲
by
winstonwinston
2mo ago
> How can I do that, if Passkeys are the only option to log in? It is not feasible to remove password login or some other recovery login method. > If I can just use a password to log into a website without Passkeys, then Passkey is us
39.
▲
by
winstonwinston
2mo ago
For starters they (those who submit) should not hide the fact. If they do, it is quite obvious to spot LLM generated code for anyone competent.
40.
▲
by
winstonwinston
2mo ago
Quick search shows this in Wordpress: > WordPress database access abstraction class. class wpdb {} So this is some sort of ORM provided. $results = $wpdb->get_results( "SELECT * FROM {$wpdb->prefix}options WHERE opt
41.
▲
by
winstonwinston
2mo ago
In Europe too, for Sd via DVB-C/T2. It is however non-existent for OTT.
42.
▲
by
winstonwinston
2mo ago
Microsoft can remove device driver crapware from being distributed via windows update if you can get their attention on this.
43.
▲
by
winstonwinston
3mo ago
Apple earned some trust unlike openai.
44.
▲
by
winstonwinston
3mo ago
They want to allow forwarders (such as mailing lists) to modify signed messages all while keeping the original signed author email address. It is meant to replace ARC which is now deprecated. You can now verify who changed what and when but
45.
▲
by
winstonwinston
3mo ago
> Finally, one aspect to consider is that many mail servers reject mail when the Envelope From domain has no MX or A/AAAA records. When the Envelope From domain and From domain are identical, this may reduce the number of relevant c
46.
▲
by
winstonwinston
3mo ago
I did but where is fun in that. When I got involved in infosec community decades ago, veterans told me then, I should always investigate for myself, not just reading someones reports, they were right. That’s why I suggested it, because you
47.
▲
by
winstonwinston
3mo ago
Yes, and I have 250GB Evo Samsung with similar stats, of same age and power on time.
48.
▲
by
winstonwinston
3mo ago
> Is this a theory or did you test this yourself? This is just a pointer for exercise you could do if you are interested. I can’t tell what is the actual HME vulnerability they claim to exist.
49.
▲
by
winstonwinston
3mo ago
> Sure, that's possible, but I doubt it and I was also unable to trigger such behavior. An oversized message is bounced directly by the receiving SMTP server. > So the theory now has to be that possible to sneak something past th
50.
▲
by
winstonwinston
3mo ago
Even when it rewrites message envelope and headers, the actual message body of an NDR (nondelivery report) can disclose original address information. Because the NDR is generated by the receiver server, the HideMyEmail does not have influen
51.
▲
by
winstonwinston
3mo ago
I was using FDK AAC encoder, I didn’t know Apple encoder was available for systems other than Apple. Though I have once compared AAC FDK to Apple AAC at 192kbps, and couldn’t tell the difference, while the old FFmpeg AAC encoder fall apart
52.
▲
by
winstonwinston
3mo ago
This model looks pretty good on paper based on what it claims: up to 6.1 COP and is able to reach water temp of 59C. If it is able to deliver that would be news. So far models popular around where I live are all up to ~5.1 COP and are actua
53.
▲
by
winstonwinston
3mo ago
When it is about paying money for a commercial service I think it is valid point to vote with your wallet. Otherwise if it was a free service, it would not really matter as the whole VPN provider industry is dubious and comes down to the sa
54.
▲
by
winstonwinston
3mo ago
> Apparently RHEL will even refuse to install a 2023 signed shim if the firmware lacks the certificate for it. Why is that? RHEL own blog post described that RHEL is distributing dual signed shim by both 2011 and 2023 certificates, so th
55.
▲
by
winstonwinston
3mo ago
Yes but chrome is not from MAS. I have none MAS apps installed because they are simply not available via MAS.
56.
▲
by
winstonwinston
3mo ago
Though there is a difference what store apps and non-store apps can do. I think is about store apps which are “sandboxed” and have to use public api to request then access information which non-store apps can access without.
57.
▲
by
winstonwinston
3mo ago
Windows 11 is not free software. Apple macOS, iOS, ipadOS all support HEVC and Dolby because Apple pays licensing costs, likewise Microsoft should do the same for Windows users, it is not free OS.
58.
▲
by
winstonwinston
3mo ago
Unless users complain it’s not going to happen. Somehow SPA (Single-page application) consume memory as much as operating system.
59.
▲
by
winstonwinston
3mo ago
Technically every domain is a ‘ghost’ domain until TTL expires and NS RRs are usually cached for very long.
60.
▲
by
winstonwinston
4mo ago
The posted page said that finding logic bugs of this kind requires ‘understanding’ which LLM cannot.
More ›