HN user

cuillevel3

308 karma
Posts0
Comments180
View on HN
No posts found.

"The vulnerable Github Agentic Workflow Noma Labs discovered was configured to:

* Trigger the workflow on issues.assigned events in GitHub * Read the issue Title and Body * Post a comment in response using the add-comment tool * Run with read access to other repositories (public and private) in the organization "

Self inflicted damage, I think. So what is their claim, that gh-aw's "Safe output gate" and "Threat detection" didn't stop the workflow?

Totally agree there and they actually talk about that in the post:

Finally: we’re painfully aware that none of the Matrix clients available today provide a full drop-in replacement for Discord yet. All the ingredients are there, and the initial goal for the project was always to provide a decentralised, secure, open platform where communities and organisations could communicate together. However, the reality is that the team at Element who originally created Matrix have had to focus on providing deployments for the public sector (see here or here) to be able to pay developers working on Matrix. Some of the key features expected by Discord users have yet to be prioritised (game streaming, push-to-talk, voice channels, custom emoji, extensible presence, richer hierarchical moderation, etc).

For everyone not reading the post:

Practically speaking, that means that people and organisations running a Matrix server with open registration must verify the ages of users in countries which require it. Last summer we announced a series of changes to the terms and conditions of the Matrix.org homeserver instance, to ensure UK-based users are handled in alignment with the UK’s Online Safety Act (OSA).

At least you can self-host matrix and messages are end to end encrypted, unlike IRC.

Distros are struggling with the amount of packages they have to maintain and update regularly. That's one of the main reasons why languages built their own ecosystems in the first place. It became popular with CPAN and Maven and took off with Ruby gems.

Linux distros can't even provide all the apps users want, that's why freshmeat existed and we have linuxbrew, flatpak, Ubuntu multiverse, PPA, third party Debian repositories, the openSUSE Buildservice, the AUR, ...

There is no community that has the capacity to audit and support multiple branches of libraries.

The permanent library was strange. Not very transparent what happened there. I am still shocked they did not invest in the original idea (tag and archive web page), but instead tried to build another content stream with recommended articles and such.

I paid for Mozillla Pocket Premium and they canceled their product within a few months, did not properly open-source the server, did not export my "permanent library" and refunded 6$. As the websites in the "permanent library" are partially offline, that data is now lost. No thanks, not buying again.

I totally agree.

  A forever home for your collection. Pocket becomes your permanent library—so even if a page you've saved is taken down, you'll still have a copy of it in Pocket
That's what I paid for. I trusted in Mozilla being open and allowing me to take my data with me. This is worse than Google?

These protests are organized by conservative organizations. They represent the big farms and the export industry. I'm not sure why the "World Socialist Website" thinks this is some grass root resistance to austerity politics.

The coalition in Berlin will stop at nothing to suppress this movement and defend the bankrupt capitalist social system against any opposition.

Actually, the government already gave into some of the demands of the protesting, subsidies-receiving land owners.

But well, maybe that's because the "World Socialist Website" has their own Putin-politics to push:

This is underlined by the brutality with which it is fuelling the punitive war against Russia in Ukraine, supporting the genocide against Palestinians in Gaza

Well, when Ubuntu was first released 18 years ago, it was the first big distribution without any open ports in the default installation and no root password. Of course there were hardening guides for Debian, which you could use to shut down the fingerd daemon and the ftp server and get rid of the global administrator account. Linux distributions had so many remotely exploitable bugs, that whole books were written about them. (Windows was still worse)

Other distros slowly started to adapt the "secure by default" policy and came up with different approaches. OpenSUSE for example still uses the root password for sudo. The patch to /etc/sudoers is massive.

I wouldn't expect sudo to behave the same across distros, there is a lot of history to it.

What most of these articles don't get, is how unpopular nuclear was among Germans. It was not just the Greens party, the rejection was more wide and in the end a majority.

Nuclear power financing, accidents, storage and disposal discussions fueled major civil unrest for decades.

Also most of the Russian gas is used in the heavy industries, you can't simply switch those factories to electrical heating. As for electrical heating of households, yeah that was a thing until maybe the eighties? Nobody does that anymore. Not sure our power grid, which is being decentralized, could handle that?

Start Self Hosting 4 years ago

What exactly is self-hosting? Are you just running services in isolation?

Updates come from a central place, I guess. With some appliances, there is integrated federation, "cloud" access? Those can still comprise you.

Do you share hosting with your family and friends? Are they still "self-hosted", or are you their provider?

Never tried it, but you should be able to copy `StandardKeyBinding.dict` to your library, convert it to XML and edit keybindings directly.

I also like 'Spectacle' to move windows around.

Just a side note, your idea of art is a bit naive. Take for example the work done by Christo and Jeanne-Claude, citing wikipedia:

Their work was typically large, visually impressive, and controversial, often taking years and sometimes decades of careful preparation – including technical solutions, political negotiation, permitting and environmental approval, hearings and public persuasion.

Maybe not WhatsApp's security, but privacy invasive business models are definitely a privacy concern for their users.

Facebook should have done the right thing from the start. The conditons were clear.

The regulator has also ordered the messaging service to bring its processing into compliance by taking a range of specified remedial actions.

Now users also have to spend tax money on litigation. Fines need to be harder.

IPv4 pricing 5 years ago

You don't live in a major city I guess? Most providers in Germany do offer 200-1000mbit downstream.

IPv6 is also common. In case of DS-Lite you don't even get your own IPv4 anymore.