HN user

desdiv

4,685 karma
Posts67
Comments958
View on HN
news.samsung.com 4y ago

Samsung Introduces Exynos 2200 Processor with Xclipse GPU Powered by AMD RDNA 2

desdiv
4pts0
www.airforcemag.com 6y ago

US Air Force Starts F-15EX Buying Process

desdiv
2pts0
lkml.iu.edu 7y ago

KUnit: The Linux kernel unit testing framework from Google

desdiv
3pts0
github.com 7y ago

Kimurai – Modern Scraping Framework with Headless Chromium/Firefox and PhantomJS

desdiv
1pts0
github.com 7y ago

Ramses – A distributed system for rendering 3D content

desdiv
136pts25
blog.ubuntu.com 8y ago

Minimal Ubuntu, on Public Clouds and Docker Hub

desdiv
9pts1
blog.playframework.com 9y ago

Play Framework 2.6.0 released

desdiv
1pts0
www.cakesolutions.net 9y ago

What if I told you, Scala compiler can understand SQL queries?

desdiv
2pts0
github.com 9y ago

Westfield: Wayland for HTML5/JavaScript

desdiv
2pts0
www.anandtech.com 9y ago

Intel Xeon Scalable Processor Family: Skylake-SP Bronze, Silver, Gold, Platinum

desdiv
1pts0
animagraffs.com 9y ago

Supercharger vs. Turbo: An HTML5 Blend4web Demo

desdiv
1pts0
review.coreboot.org 9y ago

Lenovo ThinkPad X1 Carbon Now Supported by Coreboot

desdiv
4pts1
vimeo.com 9y ago

Extracting building height using OpenStreetMap and open LiDAR data (2014)

desdiv
1pts0
github.com 9y ago

Scalajs-react 1.0.0 Released

desdiv
2pts0
systev.com 9y ago

List of Programmable Wireless ICs and Modules

desdiv
4pts0
github.com 9y ago

OpenGL and Vulkan comparison on rendering a CAD scene using various techniques

desdiv
2pts0
github.com 9y ago

VK9: Direct3D 9 compatibility layer using Vulkan

desdiv
205pts83
people.debian.org 9y ago

Debian port for RISC-V 64-bit

desdiv
155pts47
www.muji.com 9y ago

MUJI Hut: A 9.1-sqm Minimalist Cabin

desdiv
101pts81
www.argenox.com 9y ago

A Developer’s Look at the BOx Bottle Opener (2016)

desdiv
2pts0
www.geomesa.org 9y ago

GeoMesa: Open-Source, Distributed, Spatio-Temporal Database

desdiv
2pts0
stackoverflow.com 9y ago

Why does HTML think “chucknorris” is a color?

desdiv
51pts12
www.anandtech.com 9y ago

Comparing Vulkan and DX12 API Overhead on 3DMark

desdiv
4pts0
github.com 9y ago

GAPID: Google Has a New Graphics Debugger for Vulkan and OpenGL ES

desdiv
1pts0
www.anandtech.com 9y ago

MSI Releases the 'VR One': A Backpack PC for VR from $1999

desdiv
1pts0
www.anandtech.com 9y ago

Now Shipping: AMD Radeon Pro WX Series

desdiv
4pts0
www.theverge.com 9y ago

Police arrest a hacker who allegedly DDoS attacked the 911 emergency call system

desdiv
2pts0
www.popularmechanics.com 9y ago

Two Dangerous Fault Lines Under San Francisco Are Connected, Study Finds

desdiv
8pts1
www.anandtech.com 9y ago

Samsung Foundry Announces 10nm SoC in Mass-Production

desdiv
90pts26
www.wsj.com 9y ago

Immigration Source Shifts to Asia from Mexico

desdiv
2pts0

For people who are having problem with the "hilton@domain.com" situation, consider using ROT13 or some other similar scheme (hilton becomes uvygba).

Other alternatives include:

1. shorten it so much that it's not revealing anymore (hil@domain.com)

2. use another language if you're multilingual (hiruton@domain.com for Japanese)

Many people reuse emails and passwords, so if such a victim sign up for scam.com, all of their other credentials were basically compromised too.

(Not saying that that's what's happening here. I initially suspected that amazon.jobs was a scam site; I think OP did too, hence the question.)

The point of this type of honeypots is to entice the blackhats to just take the crypto and walk away. Making it harder for them to walk away with the money would be counter-productive.

Old situation: blackhats sticks around for weeks or even months, exfiltrate data, blackmail, install crypto miners, etc.

With crypto honeypot: blackhats take the crypto and leaves.

With rigged crypto honeypots that are actually not redeemable:

on the hacker forums:

Guy A: "I tried to take the bitcoins from Corp A's honeypot wallet, but they broadcasted a high fee transaction and beat me to it."

Guy B: "Funny, same thing happened to me last week with Corp B's wallet."

Guy A: "Guess it's back to the old blackmail method then."

Sorry, I wasn't clear: I'm not advocating for any particular method. I was just trying to explain why Myth #1 remained so persistent for so long.

Method 1: salt and pepper, then cook immediately

Method 2: salt and pepper, let rest, then cook

Method 3: salting hours in advance, let it sit in the fridge, then cook

Obviously 3 > 2 > 1, but Method 3 wasn't done historically (by most cooks). Cooks either went with Method 1 or Method 2, and Method 2 "won" out in the end because people consistently noticed that it produced better results. Myth #1 was an incorrect explanation as to why Method 2 is better than Method 1.

There's a reason why Myth #1 is so persistent: the action itself works, just not for the reason advertised.

Most cooks who advocate for Myth #1 will salt and pepper the steak, then let it rest for 20-30 minutes. The salt draws out some of the moisture from the surface of the steak and leaves it behind on the resting surface. The less moisture that enters the pan means better browning.

From 2007:

A May SEC filing revealed Berkshire owned 10.5 million shares of Union Pacific unp and nearly 6.4 million shares of Norfolk Southern nsc.

Berkshire omitted those investments from a quarterly summary of its stock holdings filed earlier this month because the SEC allowed the company to keep them confidential, so it's not clear how much Union Pacific and Norfolk Southern stock Berkshire currently owns.

[1] https://abcnews.go.com/Business/story?id=3550477&page=1

Berkshire's 2022 ownership of UP (if it exists) is less than 1%.[2]

[2] https://money.cnn.com/quote/shareholders/shareholders.html?s...

Was there some notification of this change sent directly to all github users? I checked email and didn't find any references to the change from github.

Same here. No notification email as far as I can find. (Through this might depend on your notification settings? I have mine set to the minimal.)

Is there some other automated system to become aware of changes like this, other than stumbling upon a HN post?

Github offer the web changelog, their RSS changelog, and the Twitter account @GHchangelog. These three all relay the same information, and ironically all three missed announcing this important change. Instead they posted a blog post[0] which was not linked at all by the changelogs.

So to answer your question: you need to follow all updates on both https://github.blog/changelog AND https://github.blog.

[0] https://github.blog/2021-09-01-improving-git-protocol-securi...

You are honestly not allowed to put a letter in a friend/neighbour's letterbox?

Yes, that is correct. If you want to hand deliver a note to your nextdoor neighbor, their mailbox is off limits. The federal government views that mailbox as some sort of exclusive domain of the USPS. You can leave the note anywhere, other than their mailbox.

The text of the law is:

Whoever knowingly and willfully deposits any mailable matter such as statements of accounts, circulars, sale bills, or other like matter, on which no postage has been paid, in any letter box established, approved, or accepted by the Postal Service for the receipt or delivery of mail matter on any mail route with intent to avoid payment of lawful postage thereon, shall for each such offense be fined under this title.[1]

[1] https://www.law.cornell.edu/uscode/text/18/1725

(An interesting possibility would be to affix the correct USPS stamp on the note, void said stamp by crossing it out, then hand delivering the note into someone's mailbox. In that case the correct postage would have been paid, so maybe that might be legal? Not a lawyer, just pondering an interesting possibility out loud.)

I foresee two problems with that:

Problem 1:

If i is used multiple times inside the loop, then you might need to make a temporary variable for it, making it confusing:

for (size_t i_plus_one = size; i_plus_one > 0; i_plus_one--) {

size_t i = i_plus_one - 1;

f(i);

g(i);

h(i);

...

(The alternative is a bunch of i-1 all over the place, which is also confusing.)

Problem 2:

If operations inside the loop is short, then the extra "i-1" arithmetic could result in unacceptable performance penalties.

My understanding is that you cannot renounce citizenship on US soil.

I know nothing about this except 5 minutes of googling, but seems like USCIS does process renunciations on US soil:

Further attempts by prisoners to renounce under 1481(a)(6) continued to be stymied by a United States Citizenship and Immigration Services policy that applicants had to attend an in-person interview and demonstrate that they could leave the U.S. immediately upon approval of renunciation. [0]

Reading between the lines though, the process seems far harder than doing it aboard because you must demonstrate "intent to relinquish U.S. citizenship", meaning cutting off all US ties and establishing foreign ties, and that's hard to demonstrate when you're physically inside the US.

[0] https://en.wikipedia.org/wiki/Relinquishment_of_United_State...

The thought of a kidnapper inquiring about the child's social security number in the ransom note is pretty good dark humor. But I think the IRS has some restrictions on who you can claim as your dependent.

To claim someone as your dependent child, they must be either:

- Your son, daughter, stepchild, foster child, or a descendant (for example, your grandchild) of any of them; or

- Your brother, sister, half brother, half sister, stepbrother, stepsister, or a descendant (for example, your niece or nephew) of any of them.

To claim someone as your dependent relative, they must be either:

- Your child, stepchild, foster child, or a descendant of any of them (for example, your grandchild). (A legally adopted child is considered your child.)

- Your brother, sister, half brother, half sister, stepbrother, or stepsister.

- Your father, mother, grandparent, or other direct ancestor, but not foster parent.

- Your stepfather or stepmother.

- A son or daughter of your brother or sister.

- A son or daughter of your half brother or half sister.

- A brother or sister of your father or mother.

- Your son-in-law, daughter-in-law, father-in-law, mother-in-law, brother-in-law, or sister-in-law.

[0] https://www.irs.gov/publications/p501#en_US_2020_publink1000...

[1] https://www.irs.gov/publications/p501#en_US_2020_publink1000...

Tokyo's Metropolitan Police Department arrested the 32-year-old Ishii the same day and criminally charged him on suspicion of obtaining $154 million dollars following fraudulent money transfers from mid-May.

The private key seizure and the arrest happened on the same day (Dec 1).

I have no idea how this passed Coinbase's KYC limits, there must be much more to the story here.

He fraudulently opened a Coinbase business account for SA Reinsurance, a Sony Life subsidiary. The SA Reinsurance documents he submitted were legitimate, but he was not authorized to open such an account.

Two different replies to the same post both quoted the phrase "I've been on reddit for 14 years, trust me", so presumably that phrase had been in the original post, but has since been deleted via an edit.

This is my interpretation of their dilemma:

"We screwed up by spamming a lot of people. We like to apologize and fix our mistake. We currently have two options:

1. apologize by sending a second email. This second email will contain an apology and the phrase 'disregard the prior email'

2. apologize by some other method (e.g. this website)

Option #1 pro: reaches everyone we're previously spammed

Option #1 con: we will be spamming people a second time. If the first round of spamming puts us in legal/ethical jeopardy, then this second round of spamming could make it worst

We have not performed Option #1 yet. We do not know whether we should perform Option #1 or not. We are taking the temperature of the 'email operator community' to see whether we should performed Option #1 or not. If Option #1 gets the green-light then we'll do it ASAP."