HN user

D4AHNGM

37 karma
Posts3
Comments48
View on HN

Without going into the rest of your points, which seem bizarrely furious at a piece of software, nothing about Homebrew forces you to live inside `/usr/local`.

It is recommended, but if you want to run in `/opt/brew` or `~/brew` you'll get a warning some things may not work but that's it. There's no hard block, and the vast majority of core formulae can pour their bottles anywhere.

  ~/Library/Application Support/Google/Chrome/
  ~/Library/Google/GoogleSoftwareUpdate/
  ~/Library/Google/Google Chrome Brand.plist
  ~/Library/LaunchAgents/com.google.keystone.agent.plist
  ~/Library/Caches/Google
  ~/Library/Preferences/com.google.Chrome.plist
  ~/Library/Preferences/com.google.Keystone.Agent.plist
Nowhere outrageously surprising, really.

I noticed the rather pitifully empty donation bar last week, and made a mental node to chip in a little bit as soon as I could. Donated €5 today, and visited the website again just now and the donation bar is more than full, which is just incredible.

Werner's engagement on the mailing lists is awesome enough, let alone the software he writes. Genuinely glad for the guy that he's getting some of the financial support he needs.

Kinda weird you've implemented SSL/TLS everywhere except the home page. Surely that's not a deliberate omission?

Also, as much as I hate to be a pedant, spelling mistakes/missing words on the homepage look sloppy:

"The people in your life will feel better knowing they can expect an email from your after you’re gone."

"you canlog back"

Disclaimer: I heavily contribute to Homebrew.

Homebrew actually merged in 4 unique bash patches in 6 days after Shellshock broke as well, and forced all users to recompile to ensure that hole was closed on our end. The author of this article would have probably been best checking both MacPorts and Homebrew, and potentially Fink as well.

Correct, but long-wave radar suffers terribly from noise, I believe. The difficulty is finding a tiny needle in the proverbial very busy, noisy haystack.

The F117 shootdown over Serbia had the advantage of having been able to tap the NATO radio network, and subsequently position their AA batteries according to that information. Even with that they only had a 20 second window or so to fire whilst the F117 had its bomb bay doors open.

I wonder if the B2 or F-22's radar profile is similarly expanded noticeably enough to stand out amongst the noise in long-wave radar during bombing runs. I doubt we'll known that with any certainty for 20+ years, if at all.

Homebrew has patched Bash for all 3 recently announced vulnerabilities, yes. The vulnerable bash will still be lurking on your system though, in /bin/bash and /bin/sh.

They do actually use Git a little. Both the OpenBSD & the Portable LibreSSL source code have mirrors on Github that are updated in sync with the CVS repository.

Whether that's because there's a demand to host the code on Github as well, or because they like Git, or a little of both is something I wouldn't presume to know.

It's nice to see the media digest and swallow this bull from the FBI & co without bothering to even chew it a little first. "Oh the FBI said something, IT MUST be true!".

All it requires is for someone to find that backdoor & its mechanism and that's it, they can exploit the backdoor designed for someone else for their own purposes. And if that someone doesn't have legitimate intentions, what then? Am I supposed to accept making my device that much less secure because the FBI or another state actor may one day decide I'm trouble? The chance of that backdoor being exploited by someone other than the FBI is considerably higher than the FBI ever using it themselves, and the FBI seem to be in lalaland on this.

This is a controversial opinion, but I am actually of the view that SSL is structurally unworkable against nation-state-level adversaries.

Seems like a pretty sensible opinion to me. The entire CA system is full of flaws that can be exploited by anyone with enough money, power or influence.

Good lord, Yes. Disconnect, AdBlock, NoScript & a pretty hefty hosts file. I'll happily whitelist any site that:

1) Doesn't try and track the crap out of me. 2) Doesn't shove ads in my face. 3) Doesn't autoplay video/sound ads.

It doesn't seem like a huge amount to ask really, but the tracking is out of control in particular and just an enormous threat to privacy.

I suspect most people linger and never bother creating an account. My own account is 103 days old, but I've been RSS subscribing to HN for about... 3 years? Maybe slightly longer.

I read a lot of what's being discussed on HN, but I barely participate.

Partly this is down to me fully accepting most of you know more about nearly everything than I do, and sometimes people can be a little unforgiving in reminding others of that. Partly because a lot of the time, I find I can get the information I want from a discussion by just through what others have discussed.