HN user

weagle05

52 karma
Posts2
Comments20
View on HN
Nano Banana Pro 8 months ago

Gemini is all over the place for me. Nano Banana produces some great images. Today I asked Gemini to design a graphic based on the first sheet in a Google sheet. It produced a graphic with a summary of the data and a picture of a bed sheet. Nailed it.

For the first time in years I'm working somewhere that doesn't use JIRA or Trello and find myself without a Kanban system. I'm having serious withdrawals. I have limitations on using a non-approved IT system because I use customer data so I vibed a PWA Kanban system. Stores data in browser and only vanilla code. No external dependencies.

https://github.com/efriese/ikanban

I too would be interested to view these models. Coming from a rural background, people in my hometown still have gardens and hunt/fish. We're one, maybe two, generations removed from people producing most of their own food. I don't see how cities deal when they can't refrigerate food and the supply chain is interrupted.

I think we disagree on the bigger problem. In my view the bigger problem is the erosion of trust for open source. Over the last 10-ish years there has been a flood of research and marketing around open source software security. I wrote a white paper about it back in 2011. We know there are risks in open source and we know vulnerabilities are created both intentionally and accidentally. We also know open source maintainers are overworked and human. There will be mistakes and we must prepare for them. This is the reason why the fine folks at Sonatype, Snyk, and WhiteSource have jobs.

These grad students wanted to make a splash and went after one of the most important code bases on the planet. It stopped being an ethical problem when the kernel maintainers had to manually search for vulnerabilities. They are using hours that could be used elsewhere. The Linux Foundation is paying Greg Kroah-Hartman to solve this problem, so they have a financial loss due to the actions of these grad students. There's your civil liability. They "knowingly cause(d) the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer" so there's your criminal liability from the Computer Fraud and Abuse Act. There's probably criminal liability in the state where they live as well.

I'm giving you an upvote. Look around your house and count the number of linux kernels running. My count is 6 that I know about. I haven't seen the actual vulnerable code submitted to know how critical the vulnerabilities are but I believe these grad students are liable both civilly and criminally. Not advocating for mob justice but there needs to be more than a slap on the wrist. For those of us who live and breath software security everyday this is kind of a big deal.

I agree, I think they should be looking at criminal charges. This is the equivalent of getting a job at Ford on the assembly line and then damaging vehicles to see if anyone notices. I've been in software security for 13 years and the "Is Open Source Really Secure" question is so over done. We KNOW there is risk associated with open source.

This is not an absolute rule, but in general I see the path not being Y shaped but P shaped. Even if you stay technical you're going to end up managing something. Could be people, could be a process, could be creative, but your expertise is going to diverge away from writing code on a daily basis. I've been a consultant for about 12 years and even though I'm technical I still end up managing some stuff for clients.

The cheat sheet series is the best project at OWASP. I use them almost weekly when I reference vulnerabilities for developers. It's one of the main reasons I have a membership. If you feel the guidance is starting to get stale, take a few minutes to make an update and submit a pull request. I'm sure it will be appreciated.

"This is not 'espionage as usual,' even in the digital age. Instead, it represents an act of recklessness that created a serious technological vulnerability for the United States and the world. In effect, this is not just an attack on specific targets, but on the trust and reliability of the world’s critical infrastructure in order to advance one nation’s intelligence agency. " Mic drop

I also had this happen on my late 2013 MBP 15, it stayed on black screen for hours. I had an external monitor attached, so I was curious if that was affecting the update. I unplugged the monitor and then reset the laptop. It took at couple attempts, but the update resumed and I'm running Big Sur with no issues.

Now a real interesting article would be what appsec service would have the highest impact for $100? Obviously not pentest. Code review? Architecture analysis? At $100 none of it would be deep of course. I could find a lot more stuff of interest in 2 hours of code review compared to pentesting.

The whole thing is fubar. We're doing our public school's virtual school for our 3 elementary age children. I don't see how its sustainable. This age group cannot do school by themselves, so my wife and I are having to do school while also trying to keep our work going. My productivity is just going to be shot.

This is day one, but here's what I'm going to try this week: 1). Get up earlier. I'm going to try to be in front of my computer with coffee by 5:30am. I'm hoping I can log a couple solid hours of work before I have to punch in for school. 2). Long lunch for the kids. Their school schedule only gives them 50 minutes, but the school is going to have to deal with it. I'm going to do 90 minutes so I can try to focus on work while inhaling a sandwich or something. 3) Bourbon when the kids are sleep.

I really hope we can get a rhythm and my kids can pick up some study skills where we don't have to be so hands-on.