HN user

jzb

5,329 karma

Joe Brockmeier. Currently an editor and writer for LWN.

Posts51
Comments815
View on HN
lwn.net 2mo ago

A new era for memory-management maintainership

jzb
8pts0
lwn.net 1y ago

2024 Linux and free software timeline

jzb
2pts0
lwn.net 1y ago

Tim Peters returns to the Python community

jzb
4pts0
lwn.net 1y ago

A Zephyr-based camera trap for seagrass monitoring

jzb
3pts1
blog.archive.org 1y ago

End of Hachette vs. Internet Archive

jzb
23pts1
lwn.net 1y ago

"Opt-in" metrics planned for Fedora Workstation 42

jzb
2pts0
lwn.net 2y ago

Nix Alternatives and Spinoffs

jzb
4pts0
lwn.net 2y ago

Elevating CentOS 7 to a new life

jzb
2pts0
venturebeat.com 2y ago

Open source Apache Airflow 2.9 advances data orchestration as AI usage grows

jzb
1pts0
lwn.net 2y ago

Tridge returns to rsync

jzb
56pts7
linusakesson.net 2y ago

Vivaldi's Summer performed on Commodore-based instruments

jzb
1pts0
harshalpatil.substack.com 2y ago

My 5 Step Journey Towards Ergonomic and Fast Typing

jzb
1pts0
percona.community 2y ago

Dolphie, your real-time MySQL monitoring assistant

jzb
4pts0
almalinux.org 3y ago

Impact of RHEL Changes to AlmaLinux

jzb
86pts116
www.percona.com 3y ago

PostgreSQL Indexes Can Hurt You: Negative Effects and the Costs Involved

jzb
2pts0
www.linux-magazine.com 3y ago

System76 Teases In-House Built Laptop

jzb
11pts5
www.percona.com 3y ago

Upgrading to MySQL 8: Tools That Can Help

jzb
1pts0
seven.centos.org 11y ago

Running MariaDB, FreeIPA, and More with CentOS Containers

jzb
2pts0
cloudstack.org 13y ago

CloudStack Configuration Vulnerability Discovered

jzb
1pts0
www.itworld.com 14y ago

Nonprofit open source organizations booming

jzb
9pts0
www.readwriteweb.com 14y ago

Netflix: No, We Don't Advertise with Rush Limbaugh

jzb
1pts0
www.readwriteweb.com 14y ago

Private Clouds Shouldn't Mean Secret Pricing

jzb
5pts0
www.readwriteweb.com 14y ago

Red Hat Quietly Joins the OpenStack Effort

jzb
39pts5
www.readwriteweb.com 14y ago

OpenStack Looking to Drop Support for Hyper-V in Essex Release

jzb
16pts0
www.readwriteweb.com 14y ago

How Will Free Wikipedia Access Change Africa and the Middle East?

jzb
4pts1
www.readwriteweb.com 14y ago

What I Wish Wikipedia and Others Were Saying Today About SOPA/PIPA

jzb
183pts55
www.readwriteweb.com 14y ago

The Four Horsemen of the General Computing Apocalypse

jzb
7pts1
www.readwriteweb.com 14y ago

Missing the Point of WordPress Entirely

jzb
4pts0
www.readwriteweb.com 14y ago

After the Acquisition: Xmarks One Year Later

jzb
1pts0
www.geekmom.com 14y ago

Does It Feel Like Lego Bricks Just Keep Getting More Expensive?

jzb
1pts0

“Do we have a great poet who captures the American spirit, the American story, the American identity?”

No. There’s no singular “American identity” or story to capture. The U.S. has produced some amazing writers and storytellers who are, IMO, equal to the greats of other countries, but we have no collective identity that can be captured by a single person.

But if you put a gun to my head to identify one, I might argue for Steven Spielberg. If the U.S. has a Homer they’re not a poet or writer, they’re a filmmaker or TV producer.

The films he’s directed certainly capture big parts of the American mythologies, perhaps the largest of a single person.

Another option: Norman Lear. Maybe even more than Spielberg with All in the Family, Good Times, The Jeffersons, One Day at a Time… yeah. He definitely nailed a broad slice of American culture for a good chunk of time.

Good performance, not really a good movie. It was a bit of a letdown after parts I and II, but he was well cast. The writing wasn’t there: didn’t quite stick the landing.

Do you have stats on that?

I’m not sure piracy or AI training are really affecting book publishing dramatically. But if you have data, I’d be curious to see it. AI scraper bots are a total pain for online publishers and FOSS sites, but AFAIK they’re not really harming book publishing directly.

The consolidation of publishers and Amazon’s own practices are probably worse for authors than “piracy”.

Sorry if it sounded like it was only in Debian; that was not my intent. I tried to make clear that the Debian package maintainer and upstream maintainer were one and the same, and that the change was upstream first. That was the reason cited by the person who complained, that he didn't file a bug because the maintainer was the one who instituted the changes upstream.

There's an enormous imbalance between company and customer that you're ignoring, not to mention the difference between a private person and a company's very public personas who own said business.

If a company was sniffing around to learn my political views, that would be a bit intrusive, wouldn't it? I wouldn't expect the same level of anonymity if I were the CEO of a company like Mullvad. There's also a disparity between "I'm taking my business elsewhere, good luck without my $10 a month!" (or whatever Mullvad costs...) and "we've decided to not allow you to use this service".

How large a disparity is depends a lot on whether a company has a lock on a market. Generally, if a vendor in a crowded market decided to turn away customers who are XYZ voters (as an example) I'd be more apt to just comment on that as a business strategy than as a "how dare they, they must accept all customers!" Like, if you are one of 20 VPN providers and you think you can be successful by turning away customers.. well, OK. Good luck with that.

If it's a provider with a monopoly that's a bit different. I live in an area with only one choice of provider for electricity. So I don't think they should be allowed to refuse service to anybody who is paying their bill, even people I vehemently disagree with.

If the far-right parties they're supporting are similar to MAGA in the U.S., what they're doing is taking customer money and funneling it into a political effort to do just what you're describing - just in a different way. "We don't like groups X, Y, and Z, so we're going to fund a political effort to take their rights away by using government."

As I understand it, the Örebro party pushes for deporting immigrants and has a "Sweden belongs to the Swedes" policy that includes deportation for even those born in Sweden if their parents were born in, e.g., Somalia. So basically, "we don't like certain people, so we want to use customer money to force them out of our country". That really doesn't paint Mullvad as the victim, here.

A right to say something is not the same as the right to say (and do) something without being called out on it.

He has the right to do what he’s doing. Other people have the right to react and say “That sucks, it’s against my values, I no longer trust you or want to do business with you.”

The AirPods Effect 1 month ago

This is not new. AirPods are newish, but this is not new. People have been wearing headphones in public spaces since the Walkman, if not before, in large numbers. You can probably find opinion columns bemoaning this shortly after the introduction of the Walkman.

The difference is really volume, which is the case with a lot of problems related to AI/LLMs.

Humans have always submitted crappy code. LLMs, however, do so at a much faster rate. Even the most active lousy coder is not going to be capable of submitting anything like that volume of code to multiple projects.

Humans have always been capable of social engineering and trying to sneak in malicious code. However, it's possible that as agents get better that they can do so much faster. The missing component will be compromised accounts, I think -- how many aged accounts can attackers get hold of to turn loose with agents?

Long-lived FOSS projects have tons of people who've created accounts many years ago that might be easliy compromised, but have checked out of actively participating. It's not necessarily going to throw up a red flag if a "person" shows up after a hiatus and starts contributing again.

So, there's more to it than overwhelming a single maintainer -- it's the capability to conduct a bunch of these attacks in an automated fashion if attackers can get hold of compromised accounts.

(As an aside, it's concerning that a maintainer would be pestered into accepting a questionable PR like this. I expect, though, that there are quite a few overworked people who have taken on things like Anaconda and are being measured on how quickly they close PRs.)

ISTM this developer did people a favor: He’s shown a real-world vulnerability pattern in a way that didn’t do real harm.

Odds are he’s not the first to think of this, he absolutely won’t be the last. If your agents, CI/CD pipeline, or whatever are vulnerable to this, it’s time to fix that now before something truly nasty comes down the pike.

This is wonderful. I grew up watching WKRP and wanted to be Doctor Johnny Fever when I grew up. Managed to work in radio for a few years part-time, but by then DJing was “here’s a program sheet. Play these songs, exactly” - not the dream of being a DJ doing their own programming. I also realized why Johnny was always broke.

Still, very cool, and a little jealous of the on-air staff that get to work there.

This doesn’t sound like they’ll be weaning off it, though: it’ll be cold turkey. That’s going to let wealth holders pick up more property at depressed prices and drive down wages.

If they’re hosting network services, sure. I wouldn’t put vibe-coded software outside a home network, ever. But it seems low risk if people are just creating their own desktop software: especially since it’s less likely to be vulnerable to widespread malware.

(Note: I’m not an LLM fan, don’t vibe code myself at all. But I would be unconcerned about security for the kind of things I would create if I did start doing so.)

“There is no poverty of information.”

Quite the opposite, in fact. But there’s a difference between the information being present somewhere, and a reasonable way to get that information in front of people in an actionable form.

We’re drowning in “information,” at present. But the mass media narratives that are most readily available distort things quite a bit for a lot of reasons. (Ratings, owner bias/interference, format.)

It's only "necessary" if one accepts that the current way is the only way.

I'm not really sure what the point of encouraging new development is if the end result is "big company scoops it up and makes it shitty, but people get to enjoy it for a few brief moments before that happens."

Copy Fail 3 months ago

This is amazing. Page says it works on RHEL 14.3, which doesn’t exist. Current RHEL is 10.x, this must’ve been done in a TARDIS.

“I'd like to know how to avoid it.”

To paraphrase a popular quote from IBM: “Executives and MBAs can never be held accountable: therefore executives and MBAs must not be allowed to make decisions.”

Slightly less flippant: The only way to stop this is to stop letting companies like MSFT gobble up smaller companies. That doesn’t seem likely in the near future, though. Once the Borg assimilate something, it’s just a matter of time before it’s digested and drained of value.

In some ways it's as if the universe is conspiring to stop people traveling so much and burning so many fossil fuels. When COVID hit, we had severe curtailing of travel for a while. Now we have insanity fueling (heh) another disruption that may cause a even larger hit to travel. This story is about air fuel, but I'm sure that we'll be seeing similar effects at some point for cars, etc.

There’s a difference between intoxication and treating the chemical imbalance behind depression or anxiety. For one thing, treatments for anxiety only target the anxiety: they don’t impair the person the way that weed or alcohol does. (They can have other side effects, of course.)

Drugs for anxiety treatment do wear off, but not the same way that weed or alcohol does: something like Celexa takes a few weeks to build up in the system, and don’t lose effect 12-24 hours later if you miss a dose. I’m not sure how long you’d have to stop before it loses efficacy entirely.

I’m not Nancy Reagan, though: I would not advise people to self-medicate with booze or pot if they’re suffering from depression or anxiety, but I’m not going to preach at anybody who is doing so and thinks it’s working for them. I will say that I’ve seen that end badly, though. I can think of three people I’m close to who’ve tried it and have had problems with addiction: all of them are now sober and (I believe) on regular antidepressants.

Which goes back to the shame thing, really. Few people are willing to stand up and advocate for common sense laws because they don’t want to be associated with anything regarding sex. Politicians, whom are not generally noted for being averse to hiring sex workers, sure as hell don’t want to be advocating for them for fear of losing elections.

"Nobody in the middle of an existential war threatens to attack more - they just attack with everything they've got."

That sounds like a poor strategy. Expend all of your resources in one grand gesture rather than trying to push your enemy's internal factions to curtail or end the fighting?

Unlike the current US administration, Iran is playing a long game - one in which it has been isolated in many ways. Indiscriminate attacks on civilian targets is not going to win it many friends; putting pressure on the tech companies that have been buddying up to the administration and may have some sway, on the other hand, is a cheap strategy that could pay off. Iran understands that the only language that seems to matter with Trump's backers is profit; threaten that and you may have some success.

The fact that Iran has already done some damage to AWS data centers makes it seem likely they could do so again if they tried. I don't know for certain, I'm not a military intelligence expert, but the strategy of "throw the kitchen sink at it" seems like a sure loser.

"Iran has always lacked an ability to project power at a distance"

I'm curious what you're basing this on, since Iran has been supplying Russia with drones, etc. for much of the war in Ukraine and so far has launched attacks into Jordan, Iraq, Kuwait, Saudi Arabia, Bahrain, Qatar, the United Arab Emirates, Oman, and Cyprus since the US began its attacks.

Iran may not be able to strike at sites in the US, but it could certainly target data centers in the Middle East with some hope of success. I'm not at all confident the current administration has accurately assessed Iran's capabilities or has the ability to protect the assets of US-based companies (or US citizens) in that region.