Moderation is good, just don't overdo it...
HN user
halffullbrain
Well, they keep pushing the Creator Bundle when I open up the Numbers.app I bought bundled with the system. Perhaps they are implying creative bookkeeping?
As someone who was part of developing the “start your business”-registration system in DK, I’m pleased to hear that! (It really is pretty complex, but a lot of effort went into making it both user friendly and reliable)
In my country, citizens have an "ID" (a UUID, which most people don't know the value of!) and a social security number which they know - which has all the problems described above). While the social security number may indeed change (doubly assigned numbers, gender reassignment, etc.), the ID needn't change, since it's the same physical person.
Public sector it-systems may use the ID and rely on it not changing.
Private sector it-systems can't look up people by their ID, but only use the social security number for comparisons and lookups, e.g. for wiping records in GDPR "right to be forgotten"-situations. Social security numbers are sortof-useful for that purpose because they are printed on passports, driver's licenses and the like. And they are a problem w.r.t. identity theft, and shouldn't ever be used as an authenticator (we have better methods for that). The person ID isn't useful for identity theft, since it's only used between authorized contexts (disregarding Byzantine scenarios with rogue public-sector actors!). You can't social engineer your way to personal data using that ID unless (safe a few movie-plot scenarios).
So what is internal in this case? The person id is indeed internal to the public sector's it-systems, and useful for tracking information between agencies. They're not useful for Bob or Alice. (They ARE useful for Eve, or other malicious inside actors, but that's a different story, which realistically does require a much higher level of digital maturity across the entire society)
Totally agree, I was just pointing out to GP why LocalDate wasn’t a record. (Date and Calendar should never be used in new code. Note how the new date/time API doesn’t have any conversions to/from old types (Date+Calendar), they only in the opposite direction)
Can’t wait for destructuring support for classes, though.
But ... LocalDate predated records by 6 years?
Eventually, I guess there'll be backwards compatible "pattern extractors" functionality retrofittable to existing "record-like" classes. This has been hinted at on several occasions.
IBM has been, and still is, a big contributor to a bunch of Eclipse projects, as their own tools build on those. The people there were both really skilled, friendly and professional. Different divisions and departments can have huge cultural differences and priorities, obviously, but “IBM” doesn’t automatically mean bad for OSS projects.
I read the piece expecting precisely that; How to keep PII out of logs, which require a lot of adamant snipers with a lot of lead bullets. Passwords: Handled by IAM services. Tokens: Application frameworks which not to divulge. But Brian's phone number stashed in an innocuous case metadata field. Gaah!
Some of the same techniques apply, like using domain primitives, but some PII (like names and addresses) is eventually templated into flatter (text) values, and processed by other layers which do not recognize 'brands' as suggested.
Data scanners: Regexes are fine for SSNs and the like, but to be really effective, one would need a full-on Named Entity Recognition in the pipeline, perhaps just as a canary. (Wait, that might actually work?)
Dataflow analysis and control applies in a BIG way, e.g. separating an audit log for forensics, where you really NEED the PII, from a technical log which the SREs can dig into without being suspected of stealing sensitive info. Start there.
PHK’s piece assumes that there’s a clear and effective distinctions between the government and the juducial system: The police can’t wiretap unless authorized by a judge (this could be backed by certificates/whatnot, and not just “ok, go ahead” as it is now.)
However: Not all countries have this effective separation/independence between branches, and some countries which have so far enjoyed such separation are perhaps not so certain anymore.
Even so: I think the point still stands - there is a choice to make, and the current trajectory (EU’s ChatControl, and UK’s encryption ban), is what we’ll risk getting instead.
O(n^2) issues can typically be solved using keyed lookups, but I agree that the base processing speed is slow and the language really is too obscure to provide good DX.
I worked with a guy who knew all about complexity analysis, but was quick to assert that "n is always small". That didn't hold - but he'd left the team by the time this became apparent.
More that half of Danish municipalities have equipped schoolkids with Chromebooks -- but some failed to limit which services thay could/should use and so effectively send the kids' personal data out of the country, which caused quite the furor.
Machine-translated from the source (https://www.digmin.dk/digitalisering/nyheder/nyhedsarkiv/202...):
Denmark must become less dependent on the major tech giants when it comes to digital solutions in the public sector. Therefore, the Ministry of Digitalization is now starting to test a new open source solution.
This week, the Ministry of Digitalization is launching a new pilot project, where a group of employees will begin testing an open source alternative to the Microsoft Office suite.
Specifically, the open source platform in question is Collabora, which is based on the open source software LibreOffice. The employees in the Ministry of Digitalization’s department participating in the pilot project will have the Office suite in their case management system replaced with Collabora.
"As minister, I’ve spoken about the need to challenge our digital independence. Now we’re taking the first step ourselves in the Ministry of Digitalization with this new pilot project. I don’t delude myself into thinking that this means we’re ready to kick the tech giants out tomorrow, but I see it as a welcome step in the right direction. As politicians, we have an obligation to ensure that our IT systems in the future aren’t dependent on a few large companies," says Minister for Digitalization Caroline Stage.
The ministry is beginning tests of a new integrated document editing module in the F2 case management system, based on the open source platform Collabora built on LibreOffice. This means that ministry employees will test an alternative to the Microsoft Office suite and use open source document editing tools instead of Microsoft’s solutions like Word, PowerPoint, and Excel.
The solution will be rolled out for broader testing in the Ministry of Digitalization’s department on June 19, 2025. At that time, a group of departmental employees will have their Office suite in F2 replaced with the open source alternative. In the months that follow, the ministry will monitor and test whether Collabora can support the ministry’s workflows and needs in a satisfactory manner.
The upcoming testing work will focus, among other things, on functionality related to the ministry’s templates, formatting for government cases, use of 'track changes', tables, etc., and whether the solution can handle conversion to and from Word format without altering the layout of documents.
If the test period proceeds satisfactorily, the next step is expected to be a broader rollout of the open source alternative throughout the department.
This is the actual source, but it's in Danish:
https://www.digmin.dk/digitalisering/nyheder/nyhedsarkiv/202...
Considering just the office suites:
Nearly all of state and local administration uses various 3rd party solutions which have bespoke Office add-ins and rely on close integration with the formats (and security models) on the Office suite -- and are likely shifting more heavily into Microsoft 365 specific features.
So it's not as simple as rolling out LibreOffice and calling it a day. Much less Linux.
Exactly, the Ministry of Digitalization barks a lot louder than it bites - context here: https://news.ycombinator.com/item?id=44346549
Dane here.
A lot of debate at the moment about digital sovereignty, with a very trusted ally threatening to annex Greenland while perhaps shifting its internal power structure (courts vs executive powers) while also continuing a trend of increased executive power over private companies (NSL etc.)
Meanwhile, EU is apparently way behind both China and US in high-tech industry and digital infrastructure in general and AI technology in particular.
So it's a welcome discourse - we really should go through the threat scenarios, in light of the changed parameters. My observations:
* Consider: Could the society function if major cloud services (say, Microsoft 365 or Azure's IaaS services) - were suddenly nullrouted from Denmark? (Keep in mind that Denmark is heavily digitalized in both the private and public sectors)
* While that not a likely scenario, it's no longer an unthinkable scenario, which it seemed to be in 2024. If it's not unthinkable, it could quickly become a credible threat. "Surrender Greenland, or else..."
* Public sector Denmark is very much a "Microsoft first" country, 99.9% of desktops, office networks and productivity. On back-ends, MS is maybe not so big at the state-level systems, but quite dominant at regional and municipal levels.
* Due to GDPR (and various related side quests), public Denmark has been slow-ish in moving to cloud infrastructure, but e.g. Microsoft 365 is gaining marketshare over locally or semi centralized hosted Exchange servers. So the blast radius is unclear.
* At the same time, Microsoft is taking home quite substantial license fees. The minister's reaction could also play into that.
However, the thing to note is that the Ministry of Digital Affairs is a small ministry. While they control some key infrastructure components (few of which run on Windows, AFAIK), they are not at all responsible for choosing other administrative bodies' choice of office suite or the bargaining with Microsoft. In practice, that power is held by the Ministry of Finance, as is so much else. They might be seeing things differently.
Interesting times indeed. And certainly long overdue to consider alternatives realistically and reduce vendor lock-in where feasible.
At least, in this case, the WAF in question had the decency to return 403.
I've worked with a WAF installation (totally different product), where the "WAF fail" tell was HTTP status 200 (!) and "location: /" (and some garbage cookies), possibly to get browsers to redirect using said cookies. This was part of the CSRF protection. Other problems were with "command injection"-patterns (like in the article, expect with specific Windows commands, too - they clash with everyday words which the users submit), and obviously SQL injections which cover some relevant words, too.
The bottom line is that WAFs in their "hardened/insurance friendly" standard configs are set up to protect the company from amateurs exposing buggy, unsupported software or architectures. WAF's are useful for that, but you still gave all the other issues with buggy, unsupported software.
As others have written, WAFs can be useful to protect against emerging threats, like we saw with the log4j exploit which CloudFlare rolled out protection for quite fast.
Unless you want compliance more than customers, you MUST at least have a process to add exceptions to "all the rules"-circus they put in front of the buggy apps.
Whack-a-mole security filtering is bad, but whack-a-mole relaxation rule creation against an unknown filter is really tiring.
So, no you don't need a "Microsoft-esque" company, you need independent service providers who just know their stuff. Today, a company (any company!) with the proper skills CAN offer setting up and maintaining government infrastructure, independent and sovereign from Microsoft, by using commoditized hardware and open source software, with no long term vendor lock-in.
The offerings do exist, and get some traction. If done right, they should be cheaper in both short and long run, compared to Microsoft licensing.
So, what's holding us back?
1) One element is aggressive pricing for key customers and partners, on the part of the smarter incumbents (in this case Microsoft).
2) Another is a "reverse network effect": Scarcity of talent to create companies like the ones I suggest. And with too little supply, the demand side will be afraid to "not choose IBM" (figuratively).
3) A third is Microsoft 365's real-time collaborative editing. Yeah, really. The needs of some specific users get to dominate decision-making, since the key decisions are pitched in PowerPoint, analysed in Word, budgeted in Excel and distributed using Outlook. A lot of old dogs would have to learn new tricks.
But yeah, somebody really should do it...
The Eclipse Compiler for Java [1] is a notable exception, architected around incremental compilation, an API for “live” AST manipulation, and a layered non-batch approach to when to invoke various analysis steps.
The LSP for Java [2] used in eg. VSCode’s Java plugins, builds on this API.
But, no, I haven’t seen a generalized approach to this architecture discussed in literature.
1: https://github.com/eclipse-jdt/eclipse.jdt.core 2: https://github.com/eclipse-jdtls/eclipse.jdt.ls
MBP M2 Max building hurl from clean:
cargo build 42.55s user 4.35s system 748% cpu 6.269 total
cargo build --release 99.38s user 4.13s system 267% cpu 38.660 total
(I can really recommend this box for Rust. I got it in August, should have waited for M3...)
Kudos for making hurl, it looks super-userful!
By that logic, the worst possible recidivism rate (surely 100%) would make someone 1500x more likely to commit crime than a non-offender. That’s still a pretty good case for having effective rehabilitation (unless you insist on the death sentence for all prisonable offences)
Marvellous. I asked it:
Which opinions do you tender?
and
Do you need a beefy GPU?
The result really was food for thought.
But this is exactly that: Source code for a compiler integrating SIMD instructions into an intrinsic function.
Indeed, the two assembly variants are just of the 1600 byte block bit fiddling (keccakF1600).
The outer loop of the Write method (function?) is the same for all architectures.
The buffer overflow is in the C version of the algorithm (and likely related to loop condition checks idiomatic to C's for-loops). The Go version is a fresh implementation, not a wrapping of the C version. I'm no Go programmer, but if I'm not mistaken, the Go implementation just eats little slices of the input buffer until no more buffer is left, leaving all the overflow-danger to the Go array implementation:
https://github.com/golang/crypto/blob/642fcc37f5043eadb2509c...
Possibly not as fast as C, but easier to reason about, I'd say.
I actually went and found the code. It wasn’t JPEG after all, it was Targa, but it still had to be turned into HAM8.
At that time, I had already worked with JPEG on the Amiga, for loading and saving images to/from the GVP TBCplus product. As I recall, it took about a second to load a JPEG image at SD video resolutions, but that was likely with a 68030 or 68040.
PreVue Channel also had an ad-delivery platform which served ads for the upper half of the prevue channel. The system was completely “headless”, using an A4000 that you could dial into, and upload new ads etc.
I developed that in 1993 — I think it was called “AdVue” commercially.
It was able to slideshow/carrousel the uploaded IFF/ILBM files or JPEGs, as I recall. I somehow managed to write a dithering algorithm for rendering as HAM8. I don’t recall how I chose the palette seed colors, as I didn’t know proper clustering algorithms back then.
I also somehow pieced together the “BBS” like Zmodem/Xmodem/etc. functionality for uploads. Long live Public Domain sources. This was pre GitHub ;-)
I’ve heard that the system was used for several years in both USA and perhaps Central and South America.
I lost contact with the company after going back home to Denmark.
That's correct. With many concurrent connections, you save memory (from thread stacks) and context swiches (since you don't need to switch thread to process each socket).
If all you want is a single request (and you have wait for results to continue work), you don't gain anything by going async.
Now it's back up: https://github.com/actix/actix-web/issues/1289
Good call, fafhrd91! C'mon, people, it's only software, try to understand each other and be civil.
Are you looking for Rust employment in Denmark?