They say it's opt-in but since they are capable of agreeing to this, I am just waiting until they hide this opt-in into the regular ToS when asking for a new model access...
HN user
rozumbrada
Not possible in case your clients are not stupid. Any company with SOC2 and <5 people is a red flag.
You might find auditors that would go along but any reasonable client will check your SOC2 report and quality of your auditors.
SOC2 requires tons of paperwork and management and separation of duties with also mandatory roles in your company - never feasible in a one man show.
I read this exact comment with I would say completely the same words several times in X and I would bet my money it's LLM generated by someone who has not even tried both the tools. This AI slop even in the site like this without direct monetisation implications from fake engagement is making me sick...
Finally... We had two days without large outage, I started to worry a little
This is why I go to hackernews every day <3
If you finally decided to support proper server-side middleware, why is there still a limitation for only one middleware function and not a chain of middleewares as every other sane server implementation offers?
The last hop showed in the BGP route is AS60068 (cdn77) which is a Czech company with global physical network. It does not mean the data are going through GB, it's not that easy.
I have no doubts that V8 has a rich test suites - including tests for the absolute value function.
But then a production optimized build apparently contains different code? This sounds to me like a system flaw
I believe in reality it's a bit more complicated
CDNs do not choose datacenters for users based on a geographic distance. The number one metric is latency but latency != physical distance. Second metric is optimizations of price of data transfer between peers and IXPs which results in very dynamic routing rules. Then consider also network/software hickups/maintanance and distribution of datacenters' load...
For people without Twitter/X account, this is a summary as a single post https://threadreaderapp.com/thread/1850658084491874555.html
Wow I hear for the first time that some TLD registrar would explicitelly allow zone transfer of the whole zone... talking about the Swedish TLD mentioned in the article.
This really works
dig @zonedata.iis.se se axfr
Could you apply here the Kerckhoffs's principle which says that security should not be based on secrecy? I know the original principle speaks about encryption but why should not it apply here aswell? Organisation should be secure by design and not by hoping nobody discovers all its assets. That being said maybe the mentioned Swedish approach to have the TLD zone public makes sense?
Could the act of publishing private keys to achieve a plausible deniablity actually backfire? If nobody is able to prove that the organisation sent the email, then the organisation is also not able to prove it. It works both ways. So imagine the organisation needs to prove an authenticity of some email because of a legal dispute. By publishing the private keys, it prevented itself from doing that