Adding 'https://www.surveillancewatch.io/noise-anim.gif' to your favourite rule-based adblocker fixes this.
HN user
roddux
The stupid dancing fuzz filter across the entire website renders the content almost completely illegible, and is a struggle to read. Shame.
Rather than seeking an impossible ideal (>2 people who agree on what 'good' code is)-- instead read ALL sorts of code. This will then help you learn to distinguish between what is good and not good, and what makes it so. Simplicity, clarity, and lack of surprise come to mind as concepts for 'good'. Others will have different ideas.
Looking at a local privilege escalation (on some systems) that works due to a logic bug in readline, when used with SUID programs.
Find a new provider that won't randomly shaft you for spurious reasons.
Solana really seems like the most interesting Layer-1 chain outside of Ethereum... lots of cool tech.
Archive/no paywall: https://archive.ph/Uxssq
I love the look of this, but haven't been able to find any information about latency... It seems to be a local network solution? Light on details about how it works, short of reading source.
LaTeX for music? nice!
Nobody is arguing that users having a 1-2 week patch window is a bad thing. However, this frankly seems incompatible with open-source projects. Silently patching issues does not work in practice; it frequently leads to missed fixes, misapplied patches and other incompatibility woes. The situation with backports and LTS releases showcases this well— the only truly well-supported kernel is latest. Everything else is a patchwork of best-effort fixes, not all of which may have been applied correctly. Brad Spengler of grsecurity fame talks frequently about this (primarily via Twitter): https://twitter.com/spendergrsec
Don't know why your other comment got downvoted. Silently patching bugs has left many LTS kernels vulnerable to old bugs, because they weren't tagged as security fixes. Also leads to other issues..: https://grsecurity.net/the_life_of_a_bad_security_fix
See also: https://twitter.com/spendergrsec
Is it a rule that all NFT art must be algorithmically generated and look like shit? Jesus wept.
I am quite interested in your setup! Have you written at all about how you use this, day to day, or perhaps made a screencast? I would be very keen to watch it.
I am a huge fan of integrated environments. I often find the promise of extendability in Linux is unfilfilled by components that do not interop without a lot of manual effort.
Readable version: https://archive.is/GXIeZ
So when can we expect ThisEstonianDoesNotExist?
Article is pretty light on details; but I don't think much is public yet. I think the big question is, will Windows turn into a subscription-based OS?
If anyone else was curious about HarmonyOS, don't bother..:
Unveiled on 9 August 2019, Huawei initially stated that it would be an independently-developed, microkernel-based, distributed OS, and "completely different from Android and iOS",[1] but it was later discovered that HarmonyOS was actually a derivative of Android.
Looks like an interesting prototype. The problem is, though, is it just a funky UI on top of Webkit/Blink and V8? There's no real innovation under the hood, here - although some of the GUI features look nice.
Something you won't gather from skim-reading the headline is that this is that the author has also created a tool, Fickling: https://github.com/trailofbits/fickling - to aid in playing around with pickle files.
From the article: [Fickling] can help you reverse engineer, test, and even create malicious pickle files.
Months of dedicated research, utilising a wealth of knowledge that comes from spending a not-insignificant portion of your career researching such bugs.
ignoring the security best practices of other systems programming languages
Can you please expand on this point?
You should add the late Terry Davis to your list, or if that area interests you, read up on his work: https://en.wikipedia.org/wiki/TempleOS
Is it possible to verify that you cannot access said system, though? How would that even be done? In most scenarios I can imagine you're still rely on the server telling you something about itself... which it can lie about.
The potential application is hinted at with the slide "OSS-Fuzz@Home". Akin to the SETI@Home* mass-distributed computing project, this has the potential to scale in a HUGE way. Anyone with a web browser could simply load the fuzzer and contribute cycles... No need for any big downloads, any installs, special software, configuration or anything! Just visit a page and you're golden.
I wonder if Google will actually build on this. It's a great idea.
Of all places I thought I'd see that channel recommended, HN is close to last on the list. That guy puts up some really great stuff.
Good, hopefully it hurts the porn industry as a whole.
I've been following these since maybe 2016? I don't remember when they started. It's striking to note that for as long as I recall, HGST still holds the crown of lowest annualised failure rate across the board.
Input the backup code as the 2FA text code, that's normally how the process works IME.