HN user

akerl_

13,134 karma

akerl.org

me@lesaker.org

Posts217
Comments3,007
View on HN
letsencrypt.org 1mo ago

A Post-Quantum Future for Let's Encrypt

akerl_
4pts0
www.microsoft.com 1mo ago

Microsoft: Protecting customers through Coordinated Vulnerability Disclosure

akerl_
3pts1
www.wiz.io 4mo ago

Trivy Compromised by Supply Chain Attack

akerl_
4pts1
www.popehat.com 5mo ago

We Should Talk About the Morality of Political Violence

akerl_
9pts0
github.com 3y ago

Opt-Into Better Default Headers

akerl_
2pts0
www.theverge.com 4y ago

Tesla pulled its latest ‘Full Self Driving’ beta after testers complained

akerl_
63pts154
successfulsoftware.net 7y ago

How to notarize your software on MacOS

akerl_
1pts0
rachelbythebay.com 8y ago

Exfiltration, correctness, and the race to market

akerl_
5pts0
rachelbythebay.com 8y ago

Patch runs ed, and ed can run anything

akerl_
490pts147
www.intelligence.senate.gov 9y ago

James Comey's Senate Statement Regarding Trump [pdf]

akerl_
2pts0
groups.google.com 9y ago

Vault-ssh-helper critical security vulnerability

akerl_
1pts0
www.kickstarter.com 9y ago

Update on the HydraDock situation

akerl_
6pts0
aphyr.com 9y ago

Serializability, linearizability, and locality

akerl_
2pts0
www.brendangregg.com 10y ago

Linux 4.5 perf folded format

akerl_
3pts0
fortune.com 10y ago

Slack Beefs Up Executive Ranks

akerl_
1pts0
www.ebaytechblog.com 10y ago

Packaging for Performance

akerl_
2pts0
aphyr.com 10y ago

Jepsen: RethinkDB 2.1.5

akerl_
379pts27
jvns.ca 10y ago

Surviving meetings while remote

akerl_
3pts0
labs.spotify.com 10y ago

A 101 on 1:1s

akerl_
2pts0
github.com 10y ago

How the Services team uses GitHub

akerl_
1pts0
hmarco.org 10y ago

Grub2 Authentication 0-Day

akerl_
15pts1
lists.gnupg.org 10y ago

GnuPG 2.1.10 released

akerl_
4pts0
www.atlassian.com 10y ago

Stash is now called Bitbucket Server

akerl_
2pts0
blog.cloudflare.com 10y ago

HTTP/2 is here. Goodbye SPDY? Not quite yet

akerl_
267pts69
mta.openssl.org 10y ago

Forthcoming OpenSSL releases – moderate severity security fixes

akerl_
2pts0
blog.circleci.com 10y ago

CircleCI: Announcing the Inner Circle: Our New Beta Testing Program

akerl_
1pts0
engineering.tumblr.com 10y ago

Data Lasso

akerl_
1pts0
kamalmarhubi.com 10y ago

Using strace to figure out how Git push over SSH works

akerl_
13pts1
blog.getsidecar.com 10y ago

Sidecar closes an $8M series B round

akerl_
1pts0
www.ansible.com 10y ago

Ansible Tower 2.4 Now Available

akerl_
2pts0

I'm scared of companies where SOC2 auditors are driving their security improvements. It's a bit like letting my toddler drive how I stock my pantry: surely by the end the pantry will be more full, but not really in the way I want.

Even setting aside that there are, in fact, many human and robot eyes staring hard at the firehose of published packages on popular registries, the whole argument feels like a false dichotomy.

If you're going to "DYOR" or whatever, having your automated dependency management on a cooldown timer seems like a snazzy way to smoothly provide a window for all your fancy dependency validation to happen.

Agreed. Whenever we end up getting non-IKEA furniture I preemptively cringe as I open the instructions.

The only time I’ve had a mistake building IKEA furniture was after opening both pieces of a combo shelf at once: there was a subtle but relevant distinction between the crossbars that was not obvious from the instructions, because ordinarily you wouldn’t have pieces from another shelf to confuse with each other.

As has been noted in several of the comments, the crashes were a result of a faulty design, not aircraft failing to meet the design.

The self-certification here wasn’t part of the chain of events that led to the crashes; it appears to have been related to other issues the FAA uncovered as a side effect of their investigation.

Where are you seeing this? LLMs make it easier to do bulk data analysis / scale attack patterns, but I've not seen anything to suggest they're incentivizing people to do OSINT against random individuals to fire off targeted attacks on home LANs.

The juice isn't really worth the squeeze for the token spend any more than it was worth the human energy.

Your original link makes fairly clear how disingenuous it is to call the figures a national average:

Data from International IQ Test (IIT) are based on data from 1,352,763 participants worldwide who took the same IQ test on the website.

Becker’s estimates are categorized by source. T = value is based upon actual test results from said country. E = value is a best-guess estimate based upon measured values of nearby countries.

Opening up the actual paper from Becker they're citing is basically a wandering tour where they try to find whatever numbers do exist and then math their way out of the fact that the sample sizes are small and the tests are different everywhere.

Various entities have performed IQ tests on people in many nations. But taking that and trying to flip it to say we've derived average national IQ is junk science.

Free the Icons 23 days ago

We've managed to make the entire corpus of open source software but the thing that's a "Hard Problem" that nobody can find a way to do is making the icons look good?

It's almost like it's not a technical challenge, it's that getting good looking icons would require a unified userbase, and Apple has that but Linux does not.

It just feels a bit like you've decided to solve the hardest possible side quest first.

Everything else on your roadmap could have been built and shipped in the universe that exists, and then if down the road it's working, you could have aimed for your own TLD.

Instead you're putting the TLD first and any of the actual functionality that end users might want afterwards.

I think it's clear at this point that the allegations don't worry them. They tried debunking them by pointing out that the overwhelming majority of these are separate daemons that are entirely optional, can be packaged separately, and don't affect anybody who doesn't want to use them. The people raging against systemd didn't feel obligated to take those facts into account.

So they're just doing their own thing, and the distro landscape seems a clear indication that their own thing looks pretty compelling to basically every distro with any meaningful market share.

People may as well make the pitch that Linux is "taking over everything".