If you want only that little description you can use `brew desc <formula>` as well.
HN user
D4AHNGM
Without going into the rest of your points, which seem bizarrely furious at a piece of software, nothing about Homebrew forces you to live inside `/usr/local`.
It is recommended, but if you want to run in `/opt/brew` or `~/brew` you'll get a warning some things may not work but that's it. There's no hard block, and the vast majority of core formulae can pour their bottles anywhere.
There's actually an `analytics` command that saves you even having to manually do this. `brew analytics --help` shows the options.
Thankfully, none of Homebrew's binaries are stored on GitHub.
Most of the changes committed to Homebrew are formulae-based; of the ~5600 contributors in Homebrew's lifetime only ~430 have contributed to the core code.
~/Library/Application Support/Google/Chrome/
~/Library/Google/GoogleSoftwareUpdate/
~/Library/Google/Google Chrome Brand.plist
~/Library/LaunchAgents/com.google.keystone.agent.plist
~/Library/Caches/Google
~/Library/Preferences/com.google.Chrome.plist
~/Library/Preferences/com.google.Keystone.Agent.plist
Nowhere outrageously surprising, really.Homebrew's creator hasn't been involved with Homebrew for nearly two years now.
Not sure why you're looking at Homebrew.
If you're feeling jumpy about binary packages, just set `HOMEBREW_BUILD_FROM_SOURCE="1"` in your shell profile.
Nobody's forcing binaries onto you.
Certain things are still being tested/rebuilt to work with the latest GCC.
Aye. The Debian compile rules for Jessie's OpenSSL include "no-ssl2 no-ssl3 no-ssl3-method" so it's just TLS1.0 onwards available.
Minor highlight: Debian 8 ships with an OpenSSL which has SSLv3 disabled at compile-time.
Checked Google Chrome prior to update, said it was vulnerable. Updated and now it isn't. Firefox 37 on OS X wasn't vulnerable apparently.
I noticed the rather pitifully empty donation bar last week, and made a mental node to chip in a little bit as soon as I could. Donated €5 today, and visited the website again just now and the donation bar is more than full, which is just incredible.
Werner's engagement on the mailing lists is awesome enough, let alone the software he writes. Genuinely glad for the guy that he's getting some of the financial support he needs.
If most of the UK didn't already think Cameron was an arse this could really damage his reputation.
Kinda weird you've implemented SSL/TLS everywhere except the home page. Surely that's not a deliberate omission?
Also, as much as I hate to be a pedant, spelling mistakes/missing words on the homepage look sloppy:
"The people in your life will feel better knowing they can expect an email from your after you’re gone."
"you canlog back"
Does OpenBSD ship zsh by default, out of interest?
Disclaimer: I heavily contribute to Homebrew.
Homebrew actually merged in 4 unique bash patches in 6 days after Shellshock broke as well, and forced all users to recompile to ensure that hole was closed on our end. The author of this article would have probably been best checking both MacPorts and Homebrew, and potentially Fink as well.
Am I misunderstanding what the author means by 'real release' in terms of OpenSSL? OpenSSL themselves pushed 0.9.8za and Apple later adopted it after a significant amount of nagging in the developer's forums on the issue.
Correct, but long-wave radar suffers terribly from noise, I believe. The difficulty is finding a tiny needle in the proverbial very busy, noisy haystack.
The F117 shootdown over Serbia had the advantage of having been able to tap the NATO radio network, and subsequently position their AA batteries according to that information. Even with that they only had a 20 second window or so to fire whilst the F117 had its bomb bay doors open.
I wonder if the B2 or F-22's radar profile is similarly expanded noticeably enough to stand out amongst the noise in long-wave radar during bombing runs. I doubt we'll known that with any certainty for 20+ years, if at all.
This is neat. I had no idea it existed. Forever in love with the power & simplicity of Ruby.
That's a nice simple little script. Thanks for sharing!
Well, that sucks. DuckDuckGo run a Tor exit enclave. I hope this doesn't put them off running an exit node, even if only to their own servers: https://duckduckgo.com/privacy
Homebrew has patched Bash for all 3 recently announced vulnerabilities, yes. The vulnerable bash will still be lurking on your system though, in /bin/bash and /bin/sh.
They do actually use Git a little. Both the OpenBSD & the Portable LibreSSL source code have mirrors on Github that are updated in sync with the CVS repository.
Whether that's because there's a demand to host the code on Github as well, or because they like Git, or a little of both is something I wouldn't presume to know.
It's nice to see the media digest and swallow this bull from the FBI & co without bothering to even chew it a little first. "Oh the FBI said something, IT MUST be true!".
All it requires is for someone to find that backdoor & its mechanism and that's it, they can exploit the backdoor designed for someone else for their own purposes. And if that someone doesn't have legitimate intentions, what then? Am I supposed to accept making my device that much less secure because the FBI or another state actor may one day decide I'm trouble? The chance of that backdoor being exploited by someone other than the FBI is considerably higher than the FBI ever using it themselves, and the FBI seem to be in lalaland on this.
This is a controversial opinion, but I am actually of the view that SSL is structurally unworkable against nation-state-level adversaries.
Seems like a pretty sensible opinion to me. The entire CA system is full of flaws that can be exploited by anyone with enough money, power or influence.
I recommend uBlock (https://github.com/gorhill/uBlock). Really lightweight, does the job perfectly.
Good lord, Yes. Disconnect, AdBlock, NoScript & a pretty hefty hosts file. I'll happily whitelist any site that:
1) Doesn't try and track the crap out of me. 2) Doesn't shove ads in my face. 3) Doesn't autoplay video/sound ads.
It doesn't seem like a huge amount to ask really, but the tracking is out of control in particular and just an enormous threat to privacy.
Interestingly, Sophos on OS X immediately identifies the .zip as Malware/Generic-Spyware and blocks access to it:
finspy_master.zip: Permission denied
I suspect most people linger and never bother creating an account. My own account is 103 days old, but I've been RSS subscribing to HN for about... 3 years? Maybe slightly longer.
I read a lot of what's being discussed on HN, but I barely participate.
Partly this is down to me fully accepting most of you know more about nearly everything than I do, and sometimes people can be a little unforgiving in reminding others of that. Partly because a lot of the time, I find I can get the information I want from a discussion by just through what others have discussed.