Congrats gaeld and team
The demo is very impressive!
disclaimer: I've known the founder for a while, as legitimate as it gets in deep tech, real years of research and engineering behind this, not vaporware
HN user
Congrats gaeld and team
The demo is very impressive!
disclaimer: I've known the founder for a while, as legitimate as it gets in deep tech, real years of research and engineering behind this, not vaporware
For monitoring I use and recommend UpDown.io, which doesn’t seem to be listed there.
It doesn't seem very well known, but I've been a happy user. Most of the others have become over-bloated with a shitty UI.
Nicholas Carlini, a researcher at Anthropic, orchestrated 16 parallel Claude agents to write a production C compiler in Rust.
To write a proof-of-concept C compiler, not a production-grade one...
Hard to take the article seriously after this
You misinterpreted the comment you are citing.
This non-determinism would not and did not cause replays to diverge (the PRNG seed was most likely stored and would reproduce exactly the same results).
Your AI powered comment is wrong. Le monde has been doing this for years. They have a series of articles about this. There is no "gap closing."
it cannot email your secret key to an attacker because of prompt injection etc.
Almost a month old, original source: https://cybernews.com/security/global-data-leak-exposes-bill...
and I've never seen any confirmation elsewhere
Looks like CyberNews have edited the article with more info since first I saw it, it used to look quite suspicious and untrustworthy, it now has more info. Still doesn't say exactly what a record is, or how many uniques there are.
You're getting downvoted because you didn't read the article.
It is specifically about cleaning up the data by removing these 3 and showing a clearer picture of acceleration without these 3 factors.
Great series of articles!
Wow. Maybe I'm missing something but it seems really weird to replace a tool with a rewrite that doesn't pass the test suite!
This comment[0] explains it.
The core bug seems to be that support for `date -r <file>` wasn't implemented at the time ubuntu integrated it [1, 2].
And the command silently accepted -r before and did nothing (!)
0: https://lwn.net/Articles/1043123/
Amazing they are still alive and kicking. Started using them with Windows 95 (different specific ones, same general concept)
These and Sysinternals (bought by Microsoft around 2006) were must have when I was still using Windows.
update your password, update your 2FA
should practice it for ENTER your password, ENTER your 2FA ;)
Still, I don’t understand how npmjs.help doesn’t immediately trigger red flags
1. it probably did for quite a few recipients, but that's never going to be 100% 2. not helped by the current practices of the industry in general, many domains in use, hard sometimes to know if it's legit or not (some actors are worse in this regard than others)
Either way, someone somewhere won't pay enough attention because they're tired, or stressed out, or they are just going through 100 emails, etc.
Indeed.
At least the crowd here should _know_ that TOTP doesn't do anything against phishing, and most of the critical infrastructure for code and other things support U2F so people should use it.
My apologies, somehow after all these years, I didn't know that (and first time I've done it)!
Yes! Here is the whitepaper (from 2017 I think), I read that and used it, it's excellent
https://karla.io/files/ichthyology-wp.pdf
At Stripe, rather than focusing on mitigating more basic attacks with phishing training, we decided to invest our time in preventing credential phishing entirely. We did this using a combination of Single Sign On (SSO), SSL client certificates, and Universal Second Factor (U2F)
Still would have done nothing in this case, as they pulled the correct email address he uses for npm from another source (public API I think?).
That's exactly why I said all the other "helpful" recommendations and warning signs people are using are never foolproof, and thus mostly useless given the scale at which phishing campaigns operate.
Great if it helps you in the general case, terrible if it lulls you into a sense of confidence when it's actually a phishing email using the right email address.
As for any of these cases, we do receive legitimate emails that require being logged in, Google or otherwise
The answer is simple: use your bookmarks/password manager/... to login yourself with a URL you control in another tab and come back to the email to click it
(and if it still asks for a login then, of course still don't do it)
In that case
1. You just requested it, I'm not saying to never click link on transactional emails you requested. You still need to click on those verify email links
2. It replaces entering your password, so you're not entering your password on a link from an email, which is the very wrong thing.
Besides the ecosystem issues, for the phishing part, I'll repost what I responded somewhere in the other related post, for awareness
---
I figure you aren't about to get fooled by phishing anytime soon, but based on some of your remarks and remarks of others, a PSA:
TRUSTING YOUR OWN SENSES to "check" that a domain is right, or an email is right, or the wording has some urgency or whatever is BOUND TO FAIL often enough.
I don't understand how most of the anti-phishing advice focuses on that, it's useless to borderline counter-productive.
What really helps against phishing :
1. NEVER EVER login from an email link. EVER. There are enough legit and phishing emails asking you to do this that it's basically impossible to tell one from the other. The only way to win is to not try.
2. U2F/Webauthn key as second factor is phishing-proof. TOTP is not.
That is all there is. Any other method, any other "indicator" helps but is error-prone, which means someone somewhere will get phished eventually. Particularly if stressed, tired, or in a hurry. It just happened to be you this time.
France and UK, from personal experience, whatsapp is big, especially for professional use, or friends/family groups.
Blue bubble isn't really a thing ever mentioned in France either, not enough iPhone market share.
I mostly agree and I do use one.
You only need read the whole thread however to see reasons why this would sometimes not be enough: sometimes the password manager does not auto-fill, so the user can think it's one of those cases, or they're on mobile and they don't have the extension there, or...
As a matter of fact, he does use one, that didn't save him, see: https://news.ycombinator.com/item?id=45175125
outside of the West
you probably mean outside of the USA, it's huge in Europe/UK
(which doesn't contradict your main point)
Hey, you're doing an exemplary response, transparent and fast, in what must be a very stressful situation!
I figure you aren't about to get fooled by phishing anytime soon, but based on some of your remarks and remarks of others, a PSA:
TRUSTING YOUR OWN SENSES to "check" that a domain is right, or an email is right, or the wording has some urgency or whatever is BOUND TO FAIL often enough.
I don't understand how most of the anti-phishing advice focuses on that, it's useless to borderline counter-productive.
What really helps against phishing :
1. NEVER EVER login from an email link. EVER. There are enough legit and phishing emails asking you to do this that it's basically impossible to tell one from the other. The only way to win is to not try.
2. U2F/Webauthn key as second factor is phishing-proof. TOTP is not.
That is all there is. Any other method, any other "indicator" helps but is error-prone, which means someone somewhere will get phished eventually. Particularly if stressed, tired, or in a hurry. It just happened to be you this time.
Good luck and well done again on the response!
There is NO reliable indicators
Completely agree. The only reliable way is to never use an email/SMS link to login, ever.
Happy for you, don't get me wrong, but your post is not particularly news, I'm guessing everyone on HN knows bare metal/VPS providers are cheaper than AWS/Azure/GCP.
And also lacking a bit in details:
- both technical (e.g. how are you dealing with upgrades or multi-data center fallback for your postgresql), and
- especially business, e.g. what's the total cost analysis including the supplemental labor cost to set this up but mostly to maintain it.
Maybe if you shared your scripts and your full cost analysis, that would be quite interesting.
Because you shouldn't use the simulator to calculate the EV, or said differently your n=1000000 is too small.
Assuming you used the first lottery example (Mega Millions), the EV is easy to calculate directly and is -$0.66/ticket, ie -33%
The jackpot is a whole $1 of that EV! Without it, the EV is -$1.75/ticket, ie -87%, which is closer to what you got in the simulation.
Besides missing the actual testing (!), the staged rollout (!), looks like they also weren't fuzzing this kernel driver that routinely takes instant worldwide updates. Oops.
Not really, that thread showed only superficial knowledge and analysis, far from hitting the nail on the head, for anyone used to assembly/reverse engineering. Then goes on to make provably wrong assumptions and comments. There is actually a null check (2 even!) just before trying the memory access. The root cause is likely trying to access an address that's coming from some uninitialized or wrongly initialized or non-deterministically initialized array.
What it did well was explaining the basics nicely for a wide audience who knows nothing about a crash dump or invalid memory access, which I guess made the post popular. Good enough for a general public explanation, but doesn't pass the bar for an actual technical one to any useful degree.
I humbly concur with Tavis' take
https://x.com/taviso/status/1814762302337654829
Here are some others for more technically correct details: - https://x.com/patrickwardle/status/1814343502886477857 - https://x.com/tweetingjose/status/1814785062266937588