https://react.dev/blog/2025/12/03/critical-security-vulnerab...
Privately Disclosed: Nov 29 Fix pushed: Dec 1 Publicly disclosed: Dec 3
HN user
[ my public key: https://keybase.io/akshetpandey; my proof: https://keybase.io/akshetpandey/sigs/AcLwTDYvWbR9A4BYlBh0nfwxDxnj3RII_jTajYx_3wY ]
https://react.dev/blog/2025/12/03/critical-security-vulnerab...
Privately Disclosed: Nov 29 Fix pushed: Dec 1 Publicly disclosed: Dec 3
https://www.dnsperf.com/#!dns-resolvers
Last 30 days, 8.8.8.8 has 99.99% uptime vs 1.1.1.1 has 99.09%
NPOs still need to be financially sustainable/viable. They still need to pay their employees and pay their vendors.
The wiki link says otherwise. Silver and gold are <40% reflective in visible, while aluminium is ~90%, neither of that is enough. Reflectivity goes down very quickly as metals heat up.
The article's result is large than that
This isn't real. This is a scam video for crypto.
I see it there
Its fairly common to embed canary trap into message to find out who the leeker is. Not saying this memo had one, but its generally no longer safe to just show redacted messages without compromising the source.
This scams are very common and fairly easy to detected even without contacting the person.
I have been looking at apartments since november and finally found a place in January, and this is the third apartment I have rented in SF over the last 5 years. I believe this one would have been caught by point 2.
Detecting a SF craigslist rental scam:
1. Is it too good to be true? Its a scam. What's too good to be true you ask? Check other listings, especially on something like rentSFnow, or the many other property management company to get a baseline price range.
2. Reverse image search the images and if it comes from a house listing on redfin or some other website to buy/sell houses, its a scam.
3. Does it mention a management company? Check their website, if the apartment is not listed there, its a scam. If they don't have a website, its a scam. Does the building/apartment's google maps or yelp not link to the management company website? Its a scam.
4. Are the pictures really good/professional looking? It MAY be a scam.
5. Does the listing provide no/very little info about the apartment/roommates? Its a scam.
6. Look for listings for the same apartment on alternate sites like apartments.com/hotpad/zillow/trulia. Don't find another listing for the same place? Its a scam, with a minor chance that the owner may not be technically adept, in which case look at the pictures, if they are good, its a scam.
7. Are there multiple postings on the same day/close by with different titles but same content? Its a scam.
If it passes all of these, it may still be a scam, reach out and proceed with caution.
If after reaching out, they ask for deposit before seeing the place, its a scam. If they ask you to sign up on any website, it may be a scam. If the sign up requires credit card/bank account or sensitive personal info, its DEFINITELY A SCAM.
Ignore most things they tell you, the only thing you should care about is actually checking the place out and making sure it works for you in person.
Even if they let you see the place, IT MAY BE A SCAM. Proceed with caution and make sure the person actually own the place/has the right to rent the apartment.
Its mostly higher bandwidth from being closer to source. Latency is definitely improved but so is bandwidth if you are in peered in the same exchange. Peek bandwidth is going to be much higher, especially if you are pulling/pushing north of 10G.
Basing this solely as a person from India and not some research background,
In the small minority of hacker rank study set, I would say that women are just as much encouraged or frankly expected to be in STEM as men. Although I am fairly certain that this observation will quickly disappear and will be heavily male dominated on a larger percentage of the population.
Really, looking at the actual hacker rank source, it seems like their sample set is really tiny and heavily biased.
Presumably because the gap exists in the current system, and the current system is optimized for the current scoring function. Changing the scoring function will cause the system to rebalance into a new steady state.
Although, there is no clear reason why the new steady state would not be female dominant or evenly split, but if I were to take a bet, I would bet that the new scoring function will still hold existing bias because the problem starts much earlier.
Modern 3D graphics has a lot of facets, a good resource as well as engine for PBR rendering is filament and is documented here: https://google.github.io/filament/Filament.html
That just the fire stick, or the netflix firestick app or your network. That isn't netflix's infrastructure problem. Netflix is the most reliable of netflix/hulu/hbo.
Try a higher end streaming devices that wired to your router
Its the domain name they use for their servers. Its generally a good practice to have a dns name that maps to a particular server apart form the website its supposed to be serving for administrative purposes.
Try this:
dig google.com
;; ANSWER SECTION:
google.com. 299 IN A 172.217.164.110
nslookup 172.217.164.110
Non-authoritative answer:
110.164.217.172.in-addr.arpa name = sfo03s18-in-f14.1e100.net.
That seems to deal with anti-circumvention provisions and not copyright provision and not with infringing on trademark/copyright as the GGGGP (white-flame) seems to be pointing to.
IANAL, but the two things seem related, why is GP being down voted? From just a reading of the wiki pages without much law knowledge it does seem like sega would win today? What I am getting wrong?
Which is basically what a blockchain is... Just that instead of a cryptographically append-only acyclic directed graph, its a cryptographically append-only linked list.
Because this way you have a public ledger that can't be mutated without notifying the public. Not everything that blockchain gives is for the trust distributed use case. For that fact, proof of work is the only thing that is purely there because bitcoin's blockchain needs a distributed trust system.
To further support your point, if you switch to a pane that does require the padlock and then switch back, the padlock is gone. Looks like someone forgot to set the padlock bar to invisible on that perf plane. It's a minor UI glitch, nothing to see here.
5 mins on amazon will find you what you are looking for. There are a whole bunch of feature phone and basic carrier/prepaid phones out there. Some of them will also do usb tethering but its a bit difficult to actually set up since it needs obscure drivers. You can also go for the higher end blackberry which still keeps physical keys and runs full blown android.
Even sold by Amazon: Blackberry: https://www.amazon.com/dp/B00DGYW83E TracPhone: https://www.amazon.com/dp/B01M3VI4Q6 TracPhone: https://smile.amazon.com/dp/B01L2DE1G2
What is he supposed to do?
His initial reaction when he thought he was under attack was fine and the second reaction was immature and lacked empathy but he was likely facing an unexpected problem that he couldn't figure out how to handle but very soon got on the right track.
Those servers and bandwidth aren't free. Bandwidth to tier three countries is actually more expensive.
Advertising revenue is basically non-existent for tier three countries, conversion rates and LTV is super low, ltv for the group of user that are using his service for whatsapp will be in the range of 1-5 Rs, ~(1-8 cents).
He will eventually have to block these countries again if he can't figure out a way to indirectly monetize these users. Or he will run out of money and the servers go down.
The best thing for these users would be if he can figure out a way to make it sustainable, and that means to monetize these users.
Some researchers had independently create and demonstrated working PoC based on the linux patches they saw which read kernel memory from user space. At that point it was already public.
After that its all about PR and getting people prepared for the magnitude and impact early.
Also to let people know that patches that were already available can be used (restarting GCP/AWS instances, SPI on chrome).
4,5 and 6 don't need to time the attack.
I am not really sure how/if zero copy may/may not solve this problem.
If this bug only allows reading kernel pages, zero copy may actually help if the unprivileged user can't read your pages, but from the small amount of available description it looks like it can read any page, but kernel pages are more interesting because thats a ring lower and which is why all the focus is on that.
I am fairly certain there is more protection against being able to read memory owned by process on a lower ring level so zero copy may be a bad idea for security critical data.
And based on the disclosure that google published, looks like any memory can be read
I can think of a few ways to get privilege escalation if you already have rce as unprivileged user:
1. Read the root ssh private key from the openssh deamons kernel pages maintaining the crypto context and ssh into the system
2. Read a sudo auth key generated for someone using sudo and then use that to run code as a root user
3. Read the users password's whenever a session manager asks the users to reauth
4. If running in AWS/GCP inside a container/vm meant to run untrusted code, read the cloud provider private keys and get control on account
5. RCE to ROP powered privilege escalation exploit seems reasonable...
6. Rowhammer a known kernel address (since you can now read kernel memory) to flip some bits to give you root
Also remember running JS is basically RCE if you can read outside the browser sandbox, ads just became much more dangerous...
Conversion on android has gone up, along with users on high-end android devices. At the same time CPI on iOS has gone up.
Speculation: iOS users may be running into app fatigue and just don't want to install new apps anymore.
Sorry should have clarified, I am taking about freemium apps , both subscriptions and IAPs. Don't have data on paid apps.
Also I am talking about app that are well monetized and advertised so you have an level comparison instead of chart positions giving and sustaining a significant lead on one platform just by some fluke.
Hard part in this case is not the actual build code or even the CI runners, its actually maintaining a mac server farm for your builds. None of the major cloud providers have mac hardware options.
Buddybuild and very few other CI systems have iOS and Android support.
Not a reasonable replacement as maintaining your own mac servers is non-trivial and all the major cloud providers don't have mac as hardware options.
Not a reasonable replacement as maintaining your own mac servers is non-trivial and all the major cloud providers don't have mac as hardware options.