running multiple game servers in docker is a multi-tenant environment, because docker is not a serious security boundary unless you're applying significant kernel hardening to your kconfig to the tune of grsecurity patches or similar
HN user
logical_person
it's shocking how low-quality these issues are in a client that is otherwise 1000x more performant than the other options listed in the article
Prop 65 went great! Let's get a warning out for every game with peer to peer networking while we're at it.
p2o is pathetically low in comparison to other markets. is your experience limited to legitimate bug bounty programs like that?
before the popularity of ARM SoCs that contain everything on-die there were much fewer choices for vertically integrated devices. it's a different segment.
if you look at apple's vertically integrated devices, they chose a cryptography coprocessor that was not on die originally. with a key accessible only by both pieces of silicon's trusted execution environments, rather than the operating system directly, encrypted comms are established in a similar fashion as the TPM2.0 proposal.
encrypted sessions (and/or EK cert verification) without PIN are not much more then obfuscation
this is completely incorrect, encrypted sessions defeat TPM interposers when there is a factory burned-in processor side secret to use. lol at being just "obfuscation" because you can spend $5m to decap and fetch the key then put the processor back into working order for the attack.
that just requires a vertically integrated device instead of a consumer part-swappable PC.
do software cracks usually get posted to seclists? this is expected in the design of DRM...
But what this simple experiment demonstrates is that Llama 3 basically can't stop itself from spouting inane and abhorrent text if induced to do so. It lacks the ability to self-reflect, to analyze what it has said as it is saying it. That seems like a pretty big issue.
what? why? an LLM produces the next tokens based on the preceding tokens. nothing more. even a harvard student is confused about this?
200mb of data is not a large file, and chromium tabs have a memory limit of something ridiculously low so actual large 20-100gb datasets render this useless.
you're too kind replying to this
authenticated sessions are practically useless on anything but a fully integrated device, because there is no guarantee of the SRK's identity - MITM is still possible.
that's still less secure, though. without a TPM you have no guarantee of the underlying state of firmware on the device. this enables a persistent backdoor.
TPM with no PIN is practically bitlocker with no password. A high entropy PIN happens to solve this entire attack.
sorry but this is nonsensical, one site pushed malware so they all do? typical "security" person
wrong, loading drivers requires admin.
except the diagram shows several mobile blocks right above 40ghz, so what do you mean?
Super problematic that the HN mod team removed these posts by the author. His replies to this thread can likely be used to help ascertain the legitimacy of his claims, despite any rule-breaking they contained - let it be visible to the public.
Does anyone know how it performs on termbench? https://github.com/cmuratori/termbench
Thanks for the reply! I'm glad you're able to click the link and read the same table, which does not clarify what majors are categorized in these groups. Another user posted a category 11 link, for example, where CIS includes "word processing" degrees, while excluding CE & EE (but still, the table does not claim that their statistics under that grouping are category 11).
Do you work with a lot of software developers with word processing degrees?
The reference does not state what other majors are categorized under CIS, unless you've got a link?
CIS is not computer science.
This article is absurd, the statistics are entirely around "computer and information science" degrees - note this is NOT comp. sci. What software developers do any of us know with that major, lol? As if the # of software engineers in the job market is tied to that major at all (or any specific major, really)...
To say business tools and confidentiality are at odds with open source is comical at best. Some of us work on FOSS as a career. We still have to sign NDAs with customers, we still upstream patches to core components.
Throwing your toys out of the ring because business is business is why open source has a funding problem.
People that have never interacted with a freenode ircoper will believe everything they post.
the formation of Christel's corporation did effectively make her* the owner. any court would see a service she is involved in operating by his company's trademark, as belonging to that company. sad.
wow if you remove features from software it becomes more secure? nice!
vmswitch is configurable by the host. these VPN authors have no clue what they're doing, windows firewall rules should not in any case be applied to traffic coming from a VM. ridiculous.