Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
xign
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
xign
3y ago
That's definitely true. And a lot of times it could be a random open source project that is under the radar and rarely thought about. E.g. The Great Suspender Chrome extension which was sold to an unknown buyer which later turned it to
32.
▲
by
xign
3y ago
I don't think it's strange to be honest. Like, if you make your code available under a permissive license like BSD, it's… permissive. Companies don't have a moral or ethical or legal obligation to contribute back. AWS sa
33.
▲
by
xign
3y ago
Pretty much. I think it's the whole virtue signaling and intellectual hand wavy dishonesty that really bugs me about these companies. They want to have the cake and eat it too. Do companies like Apple say macOS is open source (I mean t
34.
▲
by
xign
3y ago
> The vast majority of the users don't need to do anything, and if they change [to any upcoming fork], it's for ideological, not licensing (concrete), reasons. This is simply not true. Most normal users are not directly affec
35.
▲
by
xign
3y ago
I'm not confused about it. I never said Collin is legally liable to help. I'm talking about societal obligations here. Just because you do something for free doesn't mean your actions don't have consequences.
36.
▲
by
xign
3y ago
Jia Tan is absolute a possible real name. Most people commenting on this topic aren't even Chinese native speakers lol. Each pinyin can map to a lot of different Chinese characters because they are missing the tone of the character any
37.
▲
by
xign
3y ago
The stealing part is related because in this case, his project is "stealing" (or injecting a backdoor"). Does that make the analogy clearer? To be exact, he didn't do it specifically, but the non-profit is usually locked
38.
▲
by
xign
3y ago
I think in a centralized environment (workplace), it could be argued that immediately triggering all the build failures and having good hygiene in cleaning them up is actually not a bad thing. It really depends on how that's set up. An
39.
▲
by
xign
3y ago
I'm sorry but no. If you are responsible for the worst backdoor in recent computing history (which is probably a criminal act in nature), then you do have a responsibility to explain what went down. Maybe he can take a couple days to w
40.
▲
by
xign
3y ago
There are a lot of bad to terrible takes here, ranging from hindsight 20/20 to borderline discriminatory: 3. The issue here has more to do with the generated tarball doesn't match source. You (i.e. distro owners) should be able to
41.
▲
by
xign
3y ago
That's not what the above commenter said. This may be your interpretation but the above commenter is essentially saying "don't work with Chinese-sounding developers" and is the completely wrong take here. Jia Tan may or
42.
▲
by
xign
3y ago
I don't think it's crazy for a maintainer to Google the person a bit, and if there is no positive match, ask the other person for at least a little bit of detail about themselves, like where they live (country/city), who th
43.
▲
by
xign
3y ago
IFUNC is arguably not the real issue. IFUNC was used to create a function that will be called on library load (since you need a resolver function to decide which function to map in). There are other ways to create "callback on library
44.
▲
by
xign
3y ago
"Jia Tan" was not a contributor, but a maintainer of the project. The key point here is that this is a multi-year project of infiltrating the xz project and gaining commit access. In a large tech company (including ones I have w
45.
▲
by
xign
3y ago
FWIW Metal is actually easier to use than Vulkan in my opinion, as Vulkan is kind of designed to be super flexible and doesn't have as much niceties in it. Either way, OpenGL was simply too high level to be exposed as the direct API of
46.
▲
by
xign
3y ago
I mean, GitHub is still by far the most open source friendly repository hosting service by orders of magnitude. I wish we have code search back for anonymous GitHub use as well, but the simple fact is there isn't another service that
47.
▲
by
xign
3y ago
Even if your open source code is on GitLab they can still be used to train Copilot. Most permissive license allows you to train AI models using them. Any license that forbids AI training would not be considered "open source" under
48.
▲
by
xign
3y ago
To be fair, GitHub still has vast majority of features available as public anonymous API end points other than code search. It's just that they are rate-limited a lot more aggressively. And making a GitHub account is free and not terri
49.
▲
by
xign
3y ago
What's not technical about it? It tells you what the new advancements in the M3/A17 GPUs are, what you should look out for, and how you can take advantage of them. It provides enough information so you can understand what technica
50.
▲
by
xign
3y ago
Wow, I'm impressed by your numbers. Because mine is 0%… :( It's really disheartening when you try to file proper bug reports, with proper reproduction steps, my own investigative work and more details of it, etc. Then… silent. As
51.
▲
by
xign
3y ago
Yes and no. If you are making a macOS app and want to distribute your own binary (meaning not via the App Store), you are basically doing everything yourself and not using Apple's network. You still have to get a developer account be
52.
▲
by
xign
3y ago
Yeah, he kind of seems like the only guy who cares as someone looking from the outside. There are a lot of technology details where you need to dig up some random Apple Developer forum post from him just because Apple sucks at documenting s
53.
▲
by
xign
3y ago
Stepping back, I kind of feel like Google is abusing their power. Seems like they literally print money by issuing new TLDs every other month or so, for doing… not much. Are people really asking for these TLDs, like .zip and .mov? Some of t
54.
▲
by
xign
3y ago
Websites are still super relevant, especially for more serious / professional usages, or in random circles like gaming (since PC gaming is a thing that refuses to die). Domains are still the primary way you get to control your web pres
55.
▲
by
xign
3y ago
Can you explain what you mean by "patch stack"? I can roughly guess what you meant but not sure. Do you mean rebasing changes while to preserving the diffs of what you were reviewing? (I find that essentially no Git service I have
56.
▲
by
xign
3y ago
Those are two separate things though. C is more vulnerable than Rust, but either way we should properly sandbox our applications even if they are written in a memory-safe language like Rust (which is not infallable, it's just safer). O
57.
▲
by
xign
3y ago
That blog post is talking about something else though. He's saying that the CVE system does not do a good job and allows for people who drums up severity for drama. That is just a generic issue he has with the procedure. You can have s
58.
▲
by
xign
3y ago
I don't think the comment above you is a valid perspective considering that it does not appear to be a 0-day vulnerability and there is no evidence of it being used in the wild. The information he provided is IMO not enough to craft an
59.
▲
by
xign
3y ago
Fair enough, but it was never a problem because most software like Terraform would not have been open source to begin with in the good old days. So in a way yes, what you said is true, but I don't think the takeaway is "open sourc
60.
▲
by
xign
3y ago
WebKit already added support for it if I remember correctly. It's just not on Safari so to speak since it uses the macOS stack for this, so it needs the OS itself to adopt it, but Apple was clearly interested in it. And web browsers ar
More ›