Anyone using or been trying out Radicle recently?
HN user
pamcake
Yes you should. It will come naturally if you go down the road of separating code from data and properly isolating dev and prod environments, applying principle of least privilege as you do.
.env files for creds are a convenience for dev and testing. They were never supposed to be used for security or carried around with sensitive stuff inside. None of this is new.
The answer is the same: You give it either read-only or its own copy separate from the one you care about.
The requested feature wouldn't be a robust solution here either for the same reasons.
Besides, have you noticed the amount of other amateur-hour bugs anf jank in Codex going for weeks or months without proper resolution? Given that, why would you want and trust their solution here over alternatives, specifically?
It's not their problem to solve. Don't give it access to sensitive files on the first place.
Are those things you are personally struggling with (if you are considering quitting open source contribitions wholesale: don't let this make you) or is this a showcase of rationalization?
You can test this locally yourself with mitmproxy, opensnitch, or whatever.
You can try building the (supposedly) open-source apps you use from source.
Everyone opining here should MitM themselves every now and then. If not for your own security then maybe to make sure you're not participating in psyop when opining online and resharing hearsay or old truisms.
Obviously playing Kasparov on the board requires more planning ability than managing a McDonald's
Not obvious and in fact I think the opposite is way more likely. Chess is well-defined and self-contained in a way that managing a restaurant with fleshy customers never will be.
At what point did/does it start feeling naive to trust the integrity and output of Github Actions on general? Does it feel unlikely that an attacker would be able to get a foothold in that infrastructure?
I really hope this pushes users (here: devs and maintainers) to decrease their reliance on Microsoft and especially stop outsourcing security to them.
Migrate off vscode already.
What of it?
You are not responding to the debunking of your "Value doesn't have anything to do with utility" claim.
The only relevant thing I can see here is that yes, the volume is too low to provide any sense of untracability for the scenario discussed. It might for paying your VPN subscription.
Guess: 30B MOA with 3B active
In this case it does. You can't funnel huge amounts through a coin with usually small volume and market cap and expect any sense of anonymity or privacy. The delta makes it obvious. It would probably be visible via movements on markets too.
For smaller amounts this is not a problem for the same coin and network.
Your volume might support $10k but not $10m.
I put together these annotated slides from my five minute lightning talk at PyCon US 2026
Is there a video or audio of this talk?
This kind of post really shouldn't require client-side js — from third-party domain — to read...
static markdown version: https://raw.githubusercontent.com/ze3tar/ze3tar.github.io/9d...
I don't understand this choice at all. What do you base your trust on here?
I'm announcing the release of the 6.12.86 kernel.
All users of the 6.12 kernel series must upgrade.
Alternative readable rendering: https://www.terrygodier.com/the-boring-internet/ascii
Another good introduction, full-nonsense: http://landoflisp.com/
Konform Browser
Mullvad Browser
Tor Browser for those occasions
Obscurity isn't security but it can support security. Until it doesn't.
I think I agree. But at the same time we have strength in numbers and people will find something close to what they want and fork off that.
So I think the same thesis holds for audiences of 10-100 and 100-1000.
A cambrian explosion of software.
It transformed. Same name, different browser.
Recently did a personal roundup of firefox forks and ended up with Mullvad Browser, with Tor Browser on the side. Main factors being security and release latencies. Since a month or so also running Konform on the side after seeing it on Show.
Three months for a utility tool like this is nothing to panic in comments about.
The agent harness needs different sandbox(es) with different privileges. Nothing here supports not containing its access. It's a mistake to think and talk about "the sandbox" in the way the article does.
Video games is one thing. Roblox is something else.
Look, if they namedrop specific distros in their announcement (marketing) blog post as affected, I think a heads-up before publishing that is appropriate and expected.
I don't think they would have gotten as much flame if it weren't for how the RHEL 14 mention and such were put.
This is a security company with a professional(?) communications department banking on pointing fingers at distro maintainers. We are not talking about solo security researchers or academics here.
s/your/a
You may not want to be doing this at the edge.