HN user

dralley

18,251 karma
Posts184
Comments3,615
View on HN
www.youtube.com 1mo ago

A Man Who Ran Putin's Hit Squad [video]

dralley
6pts0
access.redhat.com 1mo ago

Update on supply chain compromise of Red Hat cloud-services NPM packages

dralley
3pts0
access.redhat.com 1mo ago

RHSB-2026-006 Supply chain compromise of RedHat-cloud-services NPM packages

dralley
2pts0
theins.press 3mo ago

Russia's doping program is run by the same FSB team that poisoned Navalny

dralley
99pts90
lwn.net 3mo ago

A more efficient implementation of Shor's algorithm

dralley
1pts0
theins.press 4mo ago

How Russia's new elite hit squad was compromised by Google Translate

dralley
34pts6
www.youtube.com 4mo ago

I caught an Illegal Russian Spy [video]

dralley
2pts1
www.youtube.com 6mo ago

Ukraine After 4 Years of War [video]

dralley
3pts0
www.youtube.com 9mo ago

Russia's Spy Hotel – Unit 29155 [video]

dralley
3pts0
novayagazeta.eu 9mo ago

Four arrested as France thwarts assassination attempt on Russian Putin opponent

dralley
3pts0
www.themoscowtimes.com 9mo ago

France Arrests 4 Suspected of Assassination Plot Against Russian Dissident

dralley
3pts0
www.youtube.com 9mo ago

Russia's Secret War in Europe – Unit 29155 – Episode 4 [video]

dralley
10pts0
www.youtube.com 11mo ago

Getting Detained by a Government and Probably Blacklisted by Nvidia [video]

dralley
5pts0
www.propublica.org 11mo ago

Microsoft to stop using China-based teams to support Department of Defense

dralley
7pts0
www.thebulwark.com 1y ago

Marc Andreesen and the Billionaire Victims Club

dralley
61pts38
www.youtube.com 1y ago

The Plot to Kidnap and Assassinate Me [video]

dralley
5pts0
theins.press 1y ago

Hidden Bear: The GRU hackers of Russia's most notorious kill squad

dralley
5pts0
www.theguardian.com 1y ago

White House stunned as Hegseth inquiry brings up illegal wiretap claims

dralley
28pts2
chris-martin.org 1y ago

The Gang Has a Mid-Life Crisis

dralley
285pts282
www.youtube.com 1y ago

The Death of Affordable Computing – Tariffs Impact and Investigation [video]

dralley
12pts0
www.reuters.com 1y ago

Nikola founder Trevor Milton, convicted of fraud, granted full pardon by Trump

dralley
80pts32
www.independent.co.uk 1y ago

FAA workers threatened with firing if they 'impede' Musk's SpaceX federal deal

dralley
6pts0
theins.press 1y ago

Europe's most wanted man plotted my murder and that of my colleague

dralley
414pts258
news.sky.com 1y ago

Three people guilty of spying for Russia from Great Yarmouth seaside guesthouse

dralley
7pts3
www.politico.eu 1y ago

US satellite company Maxar reportedly cuts off Ukraine's access to imagery

dralley
64pts76
www.phoronix.com 1y ago

AMD Announces "Instella" Open-Source 3B Language Models

dralley
7pts0
www.nbcnews.com 1y ago

Treasury ends enforcement of business ownership database

dralley
12pts2
microsoft.github.io 1y ago

Project Mu – Rust Implementation of UEFI

dralley
4pts0
www.theregister.com 1y ago

Under Trump 2.0, Europe's dependence on US clouds back under the spotlight

dralley
6pts1
www.cnn.com 1y ago

Ukraine says Russia drone attack hits Chernobyl nuclear plant

dralley
22pts1

Most of those don't require fingerprints or photos. Those that require addresses, do so because they're literally billing and/or shipping items to you. And none of them is comparable to physically entering another country.

I, a US citizen, got fingerprinted by passport control in Austria 2 weeks ago, and they took a picture of my face and asked for personal details. That's pretty much how passport control works universally in any developed country, only the "how they get the information" changes. Sometimes they already have it and sometimes they ask for it.

Possible, yes. But it's not like it's terribly difficult to verify correct usage of "unsafe" that amounts to a basic function call to a C library. Trivial uses of unsafe are pretty innocuous.

Otherwise, it does not bode well for Rust code because any type safety glitch will be considered a vulnerability.

I mean, this is basically true. And it goes beyond type safety - there have been CVEs filed against the Rust stdlib for TOCTOU problems of a kind that the C++ stdlib is absolutely replete with (often the exact same ones in the exact same places, to the extent that comparable APIs exist) which ended up being fixed quickly in Rust and largely ignored in C++, if anyone bothered to file in the first place.

For sure does create headaches for those who need to categorize CVEs by impact, but on balance I don't think it's a bad thing for the ecosystem. Creating a culture that wants to fix soundness issues rather than mark them as WONTFIX with a line of documentation is a core principle and value proposition of Rust in the first place.

Quoting https://cor3ntin.github.io/posts/safety/

But the borrow checker is not what makes Rust safe. Rust is safe because it decides to put correctness first by default.

Rust is safe by culture.

Better to pay a penny to fix it today than a pound to deal with the fallout down the line.

Considering a substantial fraction of the commit history since then has been removing those instances of "unsafe" not all of are actually usages of "unsafe" (seems like there are a fair number of functions / types with unsafe in the name but not the signature), is that actually still true?

And if nothing else Rust forces you to document where they are, which isn't nothing.

How would that help? These are not general purpose, base system libraries, these are libraries specific to a product that uses them. Either you're not using them and hence they would not be installed in the first place, or you're using them because you have the product installed.

Though I would expect that Insights uses RPM packages to ship components and not the public NPM packages.

There are a number of compiler performance enhancements (and correctness improvements) that are being worked on that are kind of at a chokepoint behind some other piece of work. Unfortunately it's not that easy to discern what state they're in or how quickly they're making progress.

At some point though a lot of work will be able to start advancing at once, so long as people exist to do the work.

e.g. https://rust-lang.github.io/rust-project-goals/2026/parallel...

The existence of other influences does not diminish the fact that Trump is enamored with Putin (and most "strong man" dictators generally, but Putin in particular) and it does impact his foreign policy decisions and those of his administration (Hegseth straight up canceled weapons shipments to Ukraine for 2 weeks in the aftermath of the Oval Office meeting thinking it would please the boss).

Because that's exactly what it was. I agree with you, the puritanism around special effects doesn't make sense when there's plenty of high quality archival footage out there, and instead of using that or CGI to look similar, you do something that looks completely wrong.

Elite security researchers find bugs that fuzzers can’t largely by reasoning through the source code. This is effective, but time-consuming and bottlenecked on scarce human expertise. Computers were completely incapable of doing this a few months ago, and now they excel at it. We have many years of experience picking apart the work of the world’s best security researchers, and Mythos Preview is every bit as capable. So far we’ve found no category or complexity of vulnerability that humans can find that this model can’t.

From moral perspective, the same entities (UAE, Qatar) who have done the most to raise the profile of the I/P conflict with funds and media campaigns are directly funding and sending weapons to the parties responsible for the genocide in Sudan.

Which has much clearer properties of "genocide" than the I/P war, and killed 3 times as many people in the same timeframe despite having far more primitive and less powerful weaponry involved.

> In the first three days of the capture, at least 6,000 killings were documented. 4,400 inside the city. 1,600 more along escape routes. The UN writes explicitly that the actual death toll from the week-long offensive was “undoubtedly significantly higher”. The governor of Darfur spoke of 27,000 killed in the first three days alone. The Khartoum-based think tank Confluence Advisory estimated 100,000. The Yale Humanitarian Research Lab assessed that of the 250,000 civilians remaining in the city, nearly all had been killed, died, been displaced, or were in hiding.

> RSF fighters, according to survivor testimony, said things like “Is there anyone Zaghawa here? If we find Zaghawa, we will kill them all” and “We want to eliminate anything black from Darfur”. Men and boys under 50 were specifically targeted, killed or abducted. Women and girls of the Zaghawa and Fur communities were systematically raped, often in groups, sometimes for hours or days. Those perceived as Arab were often spared.”

The F-35 is cheaper than most of the 4th generation fighters on the market. Cheaper than Eurofighter, cheaper than Rafale, cheaper than Gripen.