HN user

Xylakant

13,353 karma
Posts30
Comments3,881
View on HN
www.kdab.com 1y ago

Improvements to Mozilla's Searchfox Code Browser

Xylakant
2pts0
ferrous-systems.com 2y ago

Qualifying Rust Without Forking

Xylakant
7pts0
www.theguardian.com 3y ago

Elon Musk’s statements could be ‘deepfakes’, Tesla defence tell court

Xylakant
10pts0
status.cloud.google.com 3y ago

Multi-Zone failure in Google cloud: europeParis (Europe-west9)

Xylakant
16pts1
www.cybersecurity-insiders.com 3y ago

Cyber Attack on HaveIBeenPwned leaks email data to hackers

Xylakant
4pts3
www.bloomberg.com 6y ago

Germany Restricts Uber Citing Anti-Competitive Practices

Xylakant
4pts1
www.elastic.co 6y ago

Dear Search Guard Users #2, Including Amazon Elasticsearch Service, Open Distro

Xylakant
4pts0
www.meetup.com 6y ago

Meetup Payment Changes

Xylakant
41pts16
blog.cryptographyengineering.com 7y ago

Searchable encryption and the ever-expanding leakage function

Xylakant
3pts0
jacquesmattheij.com 9y ago

No politics please, we're hackers, too busy to improve the world

Xylakant
420pts274
www.businessinsider.de 9y ago

Elon Musk and Uber CEO Travis Kalhanick Joining Trump's Economic Advisory Team

Xylakant
3pts0
medium.com 10y ago

ImageMagic CVE-2016-3714

Xylakant
8pts1
the-digital-reader.com 11y ago

Adobe Is Spying on Users, Collecting Data on Their EBook Libraries

Xylakant
14pts0
docs.dpaq.de 11y ago

Uber banned germany-wide by preliminary injuction (german) [pdf]

Xylakant
3pts0
www.zeit.de 12y ago

Uber hit with preliminary injunction to stop service in Berlin

Xylakant
45pts63
thread.gmane.org 12y ago

Undisclosed hole in openssh on FreeBSD and Juniper?

Xylakant
48pts46
www4.mercedes-benz.com 12y ago

List of Open Source Licences in Mercedes Cars [pdf]

Xylakant
82pts59
www.kickstarter.com 12y ago

Public Safety Codes of the World: Stand Up For Safety

Xylakant
2pts0
www.linkedin.com 12y ago

Memo To The BuzzFeed Team

Xylakant
1pts0
netzpolitik.org 13y ago

Surveillance Contract between Telekom USA/VoiceStream and the FBI

Xylakant
2pts0
googleonlinesecurity.blogspot.de 13y ago

Google shortens disclosure timeline for vulnerabilities under active attack

Xylakant
3pts0
po-ru.com 13y ago

One does not simply … (Turbolinks edition)

Xylakant
2pts0
papers.ssrn.com 13y ago

Piracy and Movie Revenues: Evidence from Megaupload

Xylakant
1pts0
asquera.de 13y ago

ElasticSearch pre-flight checklist

Xylakant
64pts4
asquera.de 13y ago

Getting Bored Of The Rails Monotheism

Xylakant
3pts0
www.smh.com.au 13y ago

Drone finds dummy 'bushwalker' in world-first

Xylakant
3pts0
www.bluegraybox.com 14y ago

Picture Hanging (or a tale of junior developers)

Xylakant
3pts0
gist.github.com 14y ago

Hack your OSX

Xylakant
4pts0
issues.apache.org 14y ago

CouchDB uses SHA1 for entries in its _users db (will be fixed in 1.3)

Xylakant
1pts0
thedailywtf.com 15y ago

Release Management Done Right

Xylakant
5pts0

My Ankarsrum Assistent mixer has a detachable power cord with a standard C13 connector.

It seems to be possible, but it’s likely cheaper to have fixed connectors.

Quite to the contrary to what you write, many people pushing for Rust explicitly recommend to be very restrictive about touching existing, battle tested code and only rewrite it if you're substantially refactoring it anyways, or if it is a critical exposed piece of functionality - such as media codecs for example, which have a long history of being broken. The winning strategy that for example the google android team pursues is to not rewrite existing code, but write all new code in Rust, because real-world data shows that vulnerabilities in existing code follow a decay curve - most issues are detected in the early life of the code. That's the strategy that Firefox uses, too. (Though I'm curious about how LLMs change that equation because detecting errors in rarely used code path' seems to be what they're doing well)

And indeed, this is very much what Rust was designed to do with the ability to interface with existing C/C++ code in both directions. So this is the strategy that the designers of the language had in mind from the early days. It's a deliberate choice to offer this, and not an emergent property that was later discovered.

In any practical application there'll be a known set of errors and I'm generally fine merging code that has known deficiencies. But personally, I'd not condone merging anything that causes UB. It undermines such a fundamental guarantee of the language that it should be detected and eliminated. And bun certainly rises to the level of software where I'd expect that the project runs all available tooling to detect such cases. Especially if you LLM - code it. "Do not cause UB" should be part of the test harness.

3.4M Solar Panels 3 months ago

With a liquid cooler you could theoretically have the heat exchanger in a separate room or outside.

That doesn’t mean it’s unenforceable. You don’t need a permit to leave Germany to any country as long as your planned stay is shorter than 3 month. The only way this could be enforced is by checking if people are in country, that is in case of drafting them. The paragraph essentially ensures that any person that gets drafted needs to present themselves in person within 3 month of the draft notice.

I’m not convinced that Iran has damaged their relationship to the gulf states any more than the US and Israel have damaged theirs. The US has clearly demonstrated that they are willing to use their bases in an allied state to start a war of at least questionable legality that has the entirety predicted outcome of massively damaging the allies economy, possibly for decades to come. All the gulf states will soon re-evaluate their security relationship with the US. On the side, the US has also severely damaged NATO, to the point that NATO states have closed their air space to US planes involved in the war. On top of that, some European states have blocked flights transporting weapons for Israel. Not to mention the fact that Iran and the rest of the world has been demonstrated again that negotiations or agreements with the US do not mean anything. China will look appealing as a guarantor or peace soon to a lot of people.

I believe the long term damage this has caused in immeasurable and the only way to remedy this would be that both Israel and the US find some way to investigate who and why started this war - and possibly prosecuting any war crime that may have occurred.

Also, the EU needs to grow a spine, fast.

But alas, I have no hope of that happening. We’re all worse off for that.

The price of water has gone up for a multitude of factors. One of them is water savings in general, but not primarily because the sewage system requires regular flushes. The reason is that water gets paid per qubic meter and includes a fresh water and a waster water component. The assumption is that almost all fresh water you use ends up as waste water. Now, the grid has a very substantial fixed-price component that's largely independent from the actual current volume being used. Putting pipes in the ground and maintaining them there is an actual costly endeavour. If water use now drops, and the baseline cost remains stable, then it's entirely expected that the price per volume rises. It's simple math. The same baseline cost needs to be brought in via less volume.

This will also happen to people that use residential gas. As less and less people use residential gas, the maintenance of the gas network gets distributed among less and less customers.

The 'balcony power stations' are the same thing. They get subsidised, and you even get a fixed kWh price when pushing into the grid.

They are subsidized on purchase, but the price they get when pushing energy into the grid is by default fixed at 0. The network accepts the power, but there's no payment. It's also capped at 800W delivery, meaning that at peak power generation, you'd earn a whopping 5 cent an hour with the current subsidy for full scale solar power. So in practice, the only benefit owners have is that they draw less power from the net which is much more attractive because of the pricing structure. You can, optionally, register your balcony power station as a regular solar power plant, but then you're subject to a whole bunch of rules and regulations (for example you need a suitable elctricity meter etc.). This option is generally not attractive for such small power generations.

Fundamentally, though, the same issue as with the water and gas network exists with all localized (solar) power generation. If more and more people use the grid only as a backup, or for winter energy needs, then the overhead of maintaining the grid will have a larger cost contribution to the total cost of electricity.

There are no absolute rights, even in the charter of human rights, which is about as basic as it gets. The reality is that every right, if regarded as absolute, violates another fundamental right, if regarded as absolute.

Take for example Article 3 of the declaration of human rights:

Everyone has the right to life, liberty and security of person.

The article already has a collision set up in itself: You have the right to live in safety. But also, everyone has the right to live in liberty. If taken as an absolute, the right of liberty would prevent incarceration of dangerous individuals, violating the other individuals right to all life in safety.

Similarly, other fundamental rights get curtailed: The freedom of speech is in balance with the right to personal dignity of article one and other rights.

Not acknowledging that even fundamental human rights are in a tension with each other is just ignoring reality and will get you nowhere in a legal discussion.

The discussion is not which right is absolute, it is about how to balance the tension between the various rights. And different societies strike a different balance here.

Take for example the right to freedom and liberty. Lifelong imprisonment without parole as punishment is not a thing in Germany. There’s an instrument that allows the court to keep the perpetrator locked up in case the court considers the individual dangerous, but until 1998, this could not be retroactively be applied. There was a major legal upheaval with multiple rounds to the constitutional court to change that and it took until 2012/2013 to find a legal framework that wasn’t declared unconstitutional. To this day, however, Sicherheitsverwahrung is not a punishment, but a combination of therapy and ensuring the safety of society and it’s subject to regular checks if the conditions for the lockup still exist. The individuals are also not held in prisons, but in nicer facilities.

On the other hand, many US states still have the death penalty and are proud of it.

I can do that for my network - but the group is multiple kids that play from their home. I'm not going to teach all of those parents how to mess with their network. There's just way too many things that can go wrong. Also, won't work if the kid is traveling.

Yep, I agree. It's essentially impossible given the contraints. I'm mostly responding to a post that says "just run it on a VPN" with an example that just can't run on a VPN.

(3) would be easy to handle if DNS Cookies were sufficiently well supported because they solve reflection attacks and that's the most prominent. Rate limiting also helps.

At the moment I'm at selectively running the DNS server when the kids want to play because we're still at the supervised pre-planned play-session. And I hope that by the time they plan their own sessions, they've all moved on to a Switch 2.

Ok, why would I want to do that? Because when Microsoft bought Minecraft they decided to split the ecosystem into the Java Edition (everyone playing on a computer) and Bedrock Edition (Consoles, Tablets, ...) and cross-play is not possible on the official realms. That leaves out the option to just pay and rent a realm for the group.

So we're hosting our own minecraft server and a suitable connector for cross-play - and it's easy to join on tablets, computers and so on because there's a button that allows you to enter an address. But on the switch, Microsoft in its wisdom decided that there'd be no "join random server" button. But there are some official realm servers, and they just happen to host a lobby and the client understands some interface commands sent by the server (1). Some folks in the community devised a great hack - you just host a lobby yourself that presents a list of servers of your choice. But to do that, you need to bend the DNS entries of a few select hostnames that host the "official" lobbies so that they now point to your lobby. Which means you need to run a resolver that is capable of resolving all hostnames, because you need to set it in the switchs networking settings as the primary DNS server.

Now, there are people that run resolvers in the community and that might be one option, but I'm honestly a bit picky about who gets to see what hostnames my kids switch wants to resolve.

Whitelisting networks is impossible - it's residential internet.

The reason I'd be interested in running this behind a VPN is that I don't want to run an open resolver and become part of an amplification attack. (And sadly, the Switch 1 does not have a sufficiently modern DNS stack so that I can just enable DNS cookies and be done with it. The Switch 2 supports it).

Sorry if this sounds complicated. It's just hacks on hacks on hacks. But it works.

(1) judging from the looks and feel, this is actually implemented as a minecraft game interface and the client just treats that as a game server. It even reports the number of players hanging out in the lobby.

That assumes a device that can enter a VPN. I’d like to run a DNS server for a group of kids playing Minecraft on a switch. Since they’re not in the same (W)LAN, I can’t do it on the local network level. And the switch doesn’t have a VPN client.

There's really a wide range between "not looking after kids" and "watching them every second." Unlike the physical world, digital items allow kids to transition from a totally safe space to an unsafe space within seconds.

For example, I can have my kid do whatever he wants in his room. I know what's in there and while he may have the occasional stupid idea, it's all fundamentally safe.

But even a tablet breaks that barrier. It's entirely safe for him to listen to music and stories and I want him to be able to do that unsupervised. But solid control over content on Spotify isn't a thing. The catalog contains things that I consider not appropriate for him. And they've lately been adding vidoes to the feed and while I know he tries hard to resist, they deliberately push videos further and further up. So we're back to "I can turn on the story for you and you can listen.", which is super stupid and could be much better if I had solid controls that I can trust.

Yes, I know I can talk to him about not watching the videos. How can an 8 year old compete with the combined effort of the Spotify team paid to make him watch videos? That's just not feasible.

The problem is not that modern cars are somehow less reliable than old cars. They are much more reliable. But they’re also much less repairable without specialized equipment. You can with somewhat accessible technology repair almost all defects on a purely mechanical car. You cannot do the same for a modern car unless you happen to have a chip fab.

This looks a lot as if the facebook/jemalloc repo inserted a single commit 70 commits ago and then rebased the changes in the original repo on top. Because the commit SHAs for the changes pulled in change you see this result.

It's a perfectly not reasonable cookie banner. If you click on Details, you can see that they're not using marketing, statistics, or any other kind of cookies apart from the technically necessary. Which is great, but also means that they don't even need a banner. It could just go away.

My 95% bet is that the attacker just gained access to an account with suitable privileges and then went on to use existing automation. The fact that it’s intune is largely irrelevant - I’m not aware of any safeguards that any provider would implemen.

So the options here are MDM or no MDM and that’s a hard choice. No MDM means that you have to trust all people to get things as basic as FDE or a sane password policy right. No option to wipe or lock lost devices. No option to unlock devices where people forgot their password. Using an MDM means having a privileged attack vector into all machines.