HN user

lawl

4,104 karma
Posts43
Comments712
View on HN
github.com 4y ago

Noisetorch Possibly Compromised

lawl
6pts2
github.com 4y ago

Show HN: Ayy: decentralized Linux package management

lawl
2pts0
github.com 5y ago

NoiseTorch: Real-time noise suppression on Linux written in Go – v0.9 released

lawl
3pts0
github.com 8y ago

PlayStation4 4.55 BPF Race Condition Kernel Exploit Writeup

lawl
2pts0
mobile.twitter.com 8y ago

HTML injection in eclipse

lawl
1pts0
postmarketos.org 8y ago

219 days of postmarketOS

lawl
5pts0
postmarketos.org 8y ago

219 days of postmarketOS

lawl
4pts0
streaming.media.ccc.de 8y ago

34th Chaos Communication Congress Live Streams

lawl
282pts59
medium.com 8y ago

“Huge Dirty COW” (CVE-2017–1000405)

lawl
10pts1
motherboard.vice.com 8y ago

This Hip-Hop Track Has Better OPSEC Advice Than Most Guides Out There

lawl
1pts0
lkml.org 10y ago

Linus on compiler warnings and code reviews

lawl
168pts164
nakedsecurity.sophos.com 11y ago

Java updater to stop pushing Ask Toolbar, will foist Yahoo search on you instead

lawl
4pts0
bugzilla.redhat.com 11y ago

Systemd sends SIGKILL imediately after SIGTERM during shutdown

lawl
2pts4
www.youtube.com 11y ago

Robots Falling Down at Darpa Robotics Challenge

lawl
1pts0
marc.info 11y ago

“Blob-free OpenBSD kernel needed”

lawl
90pts74
www.vice.com 11y ago

We Asked a Color Vision Expert About the Color of That Dress

lawl
1pts0
github.com 11y ago

Teletext for Raspberry Pi

lawl
143pts22
hosted.ap.org 11y ago

Cuban youth build secret computer network despite Wi-Fi ban

lawl
2pts0
github.com 11y ago

No Multiline Strings in JS? Use a comment

lawl
4pts0
www.rabbitproto.com 12y ago

Rabbit Proto: Open source electronic prototyping for 3D printers

lawl
18pts4
github.com 12y ago

GOGS – GitHub clone written in Go

lawl
2pts0
social.technet.microsoft.com 12y ago

Today on all Windows XP computers stopped working Microsoft Antimalware Service

lawl
3pts0
kobeissl.org 12y ago

Secure connections can be easy and accessible

lawl
1pts0
blog.codinghorror.com 12y ago

Which Online Discussion Archetype Are You?

lawl
1pts0
arstechnica.com 12y ago

Mega opts for a reverse takeover so it can go public on NZ exchange

lawl
2pts0
en.wikipedia.org 12y ago

Qubes OS

lawl
2pts0
recode.net 12y ago

No, Google Didn't Just Buy $750 Million Worth of Lenovo Shares

lawl
5pts0
steamcommunity.com 12y ago

Steam Music

lawl
3pts0
javascript-puzzlers.herokuapp.com 12y ago

JavaScript Puzzlers or: do you really know JavaScript?

lawl
2pts0
yacy.net 12y ago

Decentralized Censorship Resistant Web Search

lawl
3pts0

mindustry allows you to still get the game on github, you just don't get steam integrations. i think that's pretty fair.

However, even if that wasn't the case i think it would be fine. If I contribute to a BSD licensed project, i shouldn't be mad if someone ends up selling my code.

So as long as the license permits it, I think it's generally fine. Otherwise, what's the point of the license?

Theyre pretty easy to DIY. Just look up a video on youtube of some kid doing it. Thats actually a lot more dangerous because now you run the risk of them doing it improperly and having batteries explode.

None of the things you need to DIY a vape can be controlled because its all common of the shelf stuff used for many things.

The only thing you can control is nicotine. And i can also order it from china, and the chinese always forget to label the concentration correctly or mention it at all.

So, i think this wont stop kids, but might stop adults from switching to vaping. Because nicotine free vaping is impossible to effectively ban, trivial to DIY. And the nicotine part that you can try to control (e.g. india does) is only really interesting to existing smokers, but also: chinese labeling.

Last but not least, i'm not sure i would have ever went and gotten a prescription. Probably not. The extremely low barrier of entry and ~100x cheaper were important factors for me.

I disagree.

I have dealt with bugs that were thought to be fixed a long time ago, only for them to mysteriously pop up again later. Ticket is created and the old ticket is linked.

It's really helpful to see what was done 2 years ago, including the attempted fix that is now still live in the code base but apparently doesn't work properly.

That said, as always, it's not black or white. There are definitely cases where it doesn't make sense, but I don't think you should call it 'totally worthless'.

Maybe I'm misunderstanding the intended scope of this engine, or I just ran into a bad result page, but:

https://beta.sayhello.so/search?q=Java+aot+compile

Does not seem to mention graal anywhere. (It's just a random test query that popped into my mind)

Asking a full question for a code snippet seems to work: https://beta.sayhello.so/search?q=How+do+I+sort+a+map+in+Jav...

How do you deal with licensing for these snippets though. Is that up to the user to verify?

Be honest - did you write an overcomplicated piece of code that was super hard to understand?

Not the person you asked but I have definitely done that. Usually writing overcomplicated code means you don't understand that particular domain/tech well enough and there may be no one else around to ask.

Half way in you realize you took the wrong approach. Now you have the difficult decision of sunk cost a fallacy here or not.

The correct answer may not be obvious, sunk cost isn't always a fallacy. I have definitely made wrong decisions here in the past and wrote bad code.

But sometimes the decision is ship something or nothing?

Funny, i was once in a project where i was asked to build some software. They asked if I can do it in a year. When I asked for requirements they deflected to scrum.

Probably the shittiest job I've ever had. Asked to build a system in a year with no pre-defined scope or requirements (which I complained about in advance). Told them I can build something in a year.

Of course they weren't happy about something because they wanted more. Told them to go fuck themselves.

Frankly, I should have seen it coming before the project started. Fixed budget, no requirements or scope should have been a giant red flag in hindsight.

I wonder what happened to that.

A Response 4 years ago

When people talk about "alt right pipeline", this is it, but casper isn't the perpetrator. He's the target.

Some of us were on imageboards when pools were being closed. I am sure there's a number of people that don't understand that 'glowies' isn't meant to be serious, but a reference to someone who also used to post on hackernews. But I can assure you, at least pre us politics, most got that it was just dark humor.

Just like I will not accept that pepe the frog is some hate symbol, I will not accept that image boards are an alt right pipeline. If there is such a thing, they're mostly quarantined to a politics board. Who cares? Dont look at it if it bothers you.

Sleep?

This may sound overly paranoid, but if they can intercept your deliveries they'll be able to snap a picture of your house key and have covert entry.

You'd probably need to barricade yourself in your bed room so that they cant get in without waking you up. Probably move the bed against the door so it can't be opened.

At some point this just degenerates into requiring unreasonable paranoia and opsec. And unless you have a specific goal to achieve, it may just not be worth it.

Plus airgaps against 0days. It's just purely very not fun I would assume.

Though if that’s a legitimate part of your threat model, you’re in a very difficult situation.

Its probably (close to) impossible to establish a trust anchor in that situation. That trust anchor being the untampered image. How do you secure that? Yes you can send it to trusted friends, but at that point that just means they're now fair game too. Its definitely not safe on your phone because 0days now definitely are part of your threat model too.

I think maybe if you make it your full time job, you might have a slim chance. But realistically you'd probably only manage that for a limited time.

I think people here are missing that the attacker here is actually LEA and crypto is Mega's legal defense. If you've ever looked at their crypto in a different way, you did it wrong, sorry.

This is true, I like apps that stay the same and just work.

The problem is that github encourages the exact opposite. Constant code churn, because if people see a project with last commit "2 years ago", they assume it's dead instead of just complete. Why do I know that? Because I have also caught myself doing that.

Vetting the Cargo 4 years ago

This feels like the equivalent of AdressSanitizer and similar tools for C. They fix a problem that shouldn't exist. At least not this extreme. C has the excuse of being old, Rust does not have that excuse. Using npm as an inspiration for cargo is just really sad.

Sandboxie (by default), does not restrict access to existing files in your user directory (or anywhere else).

It stops malware etc. From persisting because it catches writes. Basically it kind of mounts an overlayfs over your drive.

You can configure this differently, and iirc the paid donation version has an option to make your user directory private.

I agree that this probably isn't the best default, but that likeöy was a case of not rtfm'ing, andlnot misjudging the risk level. I was confused by this at first too.

Presumably market segmentation. You're only allowed VMs that dont feel like shit (i.e. have gpu accel) if you pay for enterprise vGPU shit. Can't have someone buy two of your GPUs to give one to a VM, obviously.

Amd changed their windows drivers to not output video if it detects its running in a VM. Nvidia went the other way and stopped doing so.

Both can/could be bypassed with some libvirtd xml magic, but still. Nvidia seem to slowly stop being assholes, AMD started already.

Download element.io, make an account somewhere. Matrix.org has a bridge for e.g. libera IRC, so you can use it like an IRC client with a free bouncer too for example.

Also since the protocol is http, a friend of mine lets his servers send him notifications about cronjobs by just curling an endpoint. Lots of things you can do with it.

IMHO it's good enough

Im a huge fan of matrix and use it daily. Just to make that clear upfront. If you read HN you should use it.

I don't think it's ready for non-technical people. The federation part still causes issues. Occassionally messages get stuck etc. I would not feel comfortable telling my mom to download element to text me.

I can just as well claim that ignoring startup with a small hot loop would unfairly favor a JIT compiler, since it ignores problems that would crop up in real world scenarios such as poor code locality.

Basically what you're suggesting would be the absolute best-case for JIT.