HN user

febusravenga

172 karma
Posts0
Comments104
View on HN
No posts found.

If you're telling dirty jokes, there are many flavors and those ive' mentioned are not special.

This is example. There are _bad_/_hard_/_dark_ jokes about women, grandmas, blacks, whites, east-asia. They have place - unless you're harming someone they are _ok_ for situation.

But only for situation. When recorded, stored and reheard years after it's not longer that situation. By recording, you're basically extending every private situation to infinity.

People in private situation, in close groups behave in ways they consider private - they cross boundaries, they "challenge" authorities/boundaries and it's ok.

It's not ok to take this freedom by assuming you can't say anything controversial in any setting.

Its not about saying illegal things. It's mostly about saying things that can get you canceled in future in future culture.

Dark jokes and strong opinions are example - you something filthy - let's say dark Holocaust/Nazi joke but funny in situation In group that accept it and it's ok. But if it's recorded, it'll stay forever and will surface in most unexpected moment, like job interview or some other screening by gov/corpos.

Don't say that dirty jokes should be punished in future if in given situation they were received as ok and only later someone else, not in situation is going to judge it

always been simple: to help you ask anything on your mind

No, it was to search. Search within resources that are external to Google. Like index in library.

(stating the obvious). Starting article like this - that is with attempt to rewrite history - is very sad.

This is GitHub FU.

Key issue here is cache poisoning, that is feature/bug that exist in utility functions/actions provided by Github.

Even if there was misconfiguration on tanstack side, then root cause is on. GH for even allowing insecure workflows to interfere with secure ones.

Here people are trying to fix defaults - not to write cache in insecure context -> https://github.com/actions/cache/issues/1756

(even if sufficiely smart attacker would find the key somewhere and skip this kind of prodection, not sure where but write-allowing-key it must exist somewhere in runtime if actions/cache can us it)

Someone else on this thread:

On GitLab even if you set the same cache key it will not cross between unprotected and protected runs.

This is a critical insight: SLSA provenance confirms which pipeline produced the artifact, not whether the pipeline was behaving as intended. A compromised build step can produce a validly-attested but malicious package.

They basically confirm that this whole provenance only proves origin. That origin was broken/flawed and was coerced to do something bad. (?)

Again, untrusted workflows can't write anywhere - cache poisoning was they key problem. If cache would be clean, release build/run would be clean too.

I think biggest concern here was cache poisoning.

Well, one of simplest mitigation is that `pull_request_target` jobs shouldn't have access to write to cache, they can read for performance, but not write.

To extrapolate rule, the `pull_request_target` shouldn't have any ways to invoke external side effects.

In most strict scenario, they shouldn't have access to network at all ... or only to GET <safeUrl> - where safeUrls are somehow vetted previously on main, derived from yarn.locks and similar manifests. Pita to setup, no wonder nobody does that.

I can only juggle 3, but I prefer clubs. Balls are so boring they are so small and not spectacular. Clubs on the other hand, man they are rotating. Once, twice, treetimes, backwards. I believe that if someone stuck at this basic level of juggling 3 balls, he should try clubs - at least for me it's pure satisfaction watching these rotating in various variants before.

Stop Sloppypasta 4 months ago

In my company, overuse of LLm and sloppy pasta is feature of those that you can't fire.

For me it destroyed company as aligned group of people, at C level, it's just bazaar of drones throwing AI slow at each other.

Good to hear, some countries already have some privacy laws protecting is from this type of products. Anyone has share more specifics about those laws, how's that they are effective in this case (unlike GDPR which is annoying and usually toothless).

Exactly. I don't know how about "big design houses" like Apple, but in my small shop designers _only_ care about static screen stories. They don't care how user will click those icons, how focus will work, how any dynamic aspects of complex UI works.

In past it was "given" by desktop env, now it's all rebuilt in material or other design but without any advanced behavior, it only "looks good on static screen".

Using this stuff well is a deep topic. These things can be applied in so many different ways, and to so many different projects. The best asset you can develop is an intuition

You're basically saying that using LLMs is like using magic. Telling people to use intuition is basically telling that i don't know how it works and why, but works for me sometimes.

That's why we programmers hate it - we have safe space where there's no intuition - namely programming languages & runtimes with deterministic behavior. And we're shoehorned back into mess of magic/intuition and wishfullthinking.

(yes, i try llm, i have some results, i'm frustrated mostly by people AI-slopping _everything_ around me)

Interesting observation and I have to relate - today I've measured ice thickness with classic stainless caliper - -3 celsius was enough for it to immediately glue to ice it was even barely wet.

Working such temperatures must be real hazard to skin, anything metal will glue to it immediately.

Well, I think that it depends on perspective and motivations.

Kissing asses/politics can be treated as skill used for different purposes. Imagine your ambition is to build bridge, skyscraper or fancy opera house.

To be chosen as the one for such projects, you must play many games including politics.

(I assume good intentions, selfish ones are possible too, but are they worth discussing?)

Koralm Railway 7 months ago

they just had shitty railroad

The terrain is just hard railroad had do huge detour on this section

Look at map: https://mapy.com/en/turisticka?x=15.0703419&y=46.7076432&z=1...

Passes in those mountains are only ~1200m above valley level (~1650 abs). Yeah, perfectly ok to run railroad there.

Your autobahn climbs 600m on this section (to 1050m absolute) - it's way to high for railway to be effective.