I'm scared of companies where SOC2 auditors are driving their security improvements. It's a bit like letting my toddler drive how I stock my pantry: surely by the end the pantry will be more full, but not really in the way I want.
HN user
akerl_
akerl.org
me@lesaker.org
What about the other Lavabit users whose data he had handed over previously, before deciding to say no?
Even setting aside that there are, in fact, many human and robot eyes staring hard at the firehose of published packages on popular registries, the whole argument feels like a false dichotomy.
If you're going to "DYOR" or whatever, having your automated dependency management on a cooldown timer seems like a snazzy way to smoothly provide a window for all your fancy dependency validation to happen.
Agreed. Whenever we end up getting non-IKEA furniture I preemptively cringe as I open the instructions.
The only time I’ve had a mistake building IKEA furniture was after opening both pieces of a combo shelf at once: there was a subtle but relevant distinction between the crossbars that was not obvious from the instructions, because ordinarily you wouldn’t have pieces from another shelf to confuse with each other.
Are you saying that you don’t think that the GDPR text is written to apply outside of the EU, or that it does say that but it’s not relevant because it’s not viable for anybody to enforce that?
Design changes are not part of the self certification process, they’re part of the type certification process, which has always been handled by the FAA.
As has been noted in several of the comments, the crashes were a result of a faulty design, not aircraft failing to meet the design.
The self-certification here wasn’t part of the chain of events that led to the crashes; it appears to have been related to other issues the FAA uncovered as a side effect of their investigation.
Not really in the way the media would have you believe.
Like “I was scared for a couple minutes on a Friday morning until I saw the vendor status page” is orders of magnitude away from the bar here.
What would your damages be? They’re not actually going to charge your credit card for 34 billion.
https://health.aws.amazon.com/health/status
Looks like this is a bug w/ S3
Where are you seeing this? LLMs make it easier to do bulk data analysis / scale attack patterns, but I've not seen anything to suggest they're incentivizing people to do OSINT against random individuals to fire off targeted attacks on home LANs.
The juice isn't really worth the squeeze for the token spend any more than it was worth the human energy.
How many people out there have attackers doing individualized research to identify services on their home LAN so they can chain a network attack with CVEs in their self-hosted service?
Don’t worry, they got data from a whole 5000 people in Australia and 300 people in Afghanistan!
I’m sure that’s generalizable to the whole country’s worth of 28 and 40 million, respectively.
Countries with fewer than 100 test-takers were excluded from the ranking due to limited sample size and are shown in gray on the map above.
How generous of them.
Your original link makes fairly clear how disingenuous it is to call the figures a national average:
Data from International IQ Test (IIT) are based on data from 1,352,763 participants worldwide who took the same IQ test on the website.
Becker’s estimates are categorized by source. T = value is based upon actual test results from said country. E = value is a best-guess estimate based upon measured values of nearby countries.
Opening up the actual paper from Becker they're citing is basically a wandering tour where they try to find whatever numbers do exist and then math their way out of the fact that the sample sizes are small and the tests are different everywhere.
Various entities have performed IQ tests on people in many nations. But taking that and trying to flip it to say we've derived average national IQ is junk science.
I don’t suppose this was related to the recent Netvue/Birdfy outage that they claimed was due to a registrar issue and lasted over a week?
The reason this bug is unexpected is that the user is expecting to have to enter their password (because they expect the key to be wiped on suspend), and then _they are_ asked for their password. But there was a copy of the key elsewhere in kernel memory that was never cleared.
Managing an Apple fleet is similarly fine, and that includes using any of the MDM tooling that also does key escrow on enterprise Filevault devices.
I recently heard that a trip to Popeye's for a family of 3 recently cost $68 in Florida.
Does it?
We've managed to make the entire corpus of open source software but the thing that's a "Hard Problem" that nobody can find a way to do is making the icons look good?
It's almost like it's not a technical challenge, it's that getting good looking icons would require a unified userbase, and Apple has that but Linux does not.
I mean sure, but if you started talking about google.com as a subdomain, real humans would correctly look at you funny.
Are you working on the not-TLD parts in parallel? If you don't get the TLD, do you plan to launch on a more traditional domain?
The marketing stuff makes it look like the TLD is your main focus.
It just feels a bit like you've decided to solve the hardest possible side quest first.
Everything else on your roadmap could have been built and shipped in the universe that exists, and then if down the road it's working, you could have aimed for your own TLD.
Instead you're putting the TLD first and any of the actual functionality that end users might want afterwards.
What is the premise for being able to do "one person, one subdomain" that isn't a privacy/security nightmare?
Is the point of the site to build reputation, or to share opinions and discuss topics?
I'm saying you're driving backwards down the highway, and you're asking how you can read the signs better because they all look blank.
It seems impossible that you know the problem is real but don’t know who the right people are to tell about it.
How did you decide what to build without knowing who you’d be building it for?
You think that users having to find and download software from the Internet at large is both similar to the AUR model and has preferable handling of these issues?
Can you elaborate?
I think it's clear at this point that the allegations don't worry them. They tried debunking them by pointing out that the overwhelming majority of these are separate daemons that are entirely optional, can be packaged separately, and don't affect anybody who doesn't want to use them. The people raging against systemd didn't feel obligated to take those facts into account.
So they're just doing their own thing, and the distro landscape seems a clear indication that their own thing looks pretty compelling to basically every distro with any meaningful market share.
People may as well make the pitch that Linux is "taking over everything".