HN user

wlkr

1,338 karma

ヽ(`⌒´)ノ

Posts77
Comments172
View on HN
www.theregister.com 1mo ago

Nottingham Uni says student records raided after ShinyHunters claims cyberattack

wlkr
2pts0
www.youtube.com 2mo ago

Leaked plan to end US elections points to WW3. Stephen Fry [video]

wlkr
7pts1
shop.m5stack.com 3mo ago

M5Stack CardputerZero – Pocket Raspberry Pi Computer for Hackers

wlkr
2pts1
phel-lang.org 8mo ago

Phel: A Functional Lisp Dialect for PHP Developers

wlkr
2pts1
interestingengineering.com 8mo ago

Matrix collapses: Mathematics proves universe cannot be a computer simulation

wlkr
3pts0
www.gamingonlinux.com 1y ago

Ubuntu 25.04 upgrades halted due to Kubuntu users getting a broken desktop

wlkr
5pts0
www.newscientist.com 1y ago

Odds of asteroid 2024 YR4 hitting Earth in 2032 have reached new high

wlkr
20pts8
github.com 1y ago

Quip: A Clojure game engine built using Quil

wlkr
4pts0
medium.com 1y ago

Software Process Improvement, Simplified

wlkr
1pts0
news.sky.com 1y ago

Share trading app Freetrade to pull out of Swedish market

wlkr
1pts0
github.com 2y ago

tech.ml.dataset: A Clojure high performance data processing system

wlkr
3pts0
www.notion.so 2y ago

Notion: Upcoming changes coming to our Plus plan

wlkr
1pts0
www.privateinternetaccess.com 2y ago

Private Internet Access Transparency Report Q1 2024

wlkr
3pts1
www.privateinternetaccess.com 2y ago

Private Internet Access: Independent Limited Assurance Report (2024) [pdf]

wlkr
2pts1
www.computerweekly.com 2y ago

Fujitsu bosses knew about Post Office Horizon IT flaws, says insider (2021)

wlkr
13pts8
www.openrightsgroup.org 2y ago

ORG warns of threat to privacy and free speech as Online Safety Bill is passed

wlkr
23pts0
old.reddit.com 2y ago

Samsung Notes does not run on non-Galaxy Book Laptops anymore

wlkr
1pts1
rss.org.uk 2y ago

Statistical issues in investigation of suspected medical misconduct (2022) [pdf]

wlkr
1pts0
www.thefire.org 3y ago

Do the cops suing Afroman after raiding his home have a case?

wlkr
91pts19
www.newarab.com 3y ago

For the sixth year, Algeria blocks internet to prevent cheating during exams

wlkr
77pts66
hackaday.com 3y ago

Flipper Zero “Smoking” a Smart Meter Is a Bad Look for Hardware Hackers

wlkr
3pts1
appsource.microsoft.com 3y ago

Excel Labs, a Microsoft Garage Project

wlkr
104pts50
www.theregister.com 3y ago

Elon Musk's Neuralink probed over pathogen transport

wlkr
5pts0
www.themeateater.com 3y ago

The Wyoming corner crossing case

wlkr
101pts74
arstechnica.com 3y ago

UK authorities have arrested a teenager linked to GTA VI leak

wlkr
5pts1
www.chess.com 3y ago

Chess.com Prices Are Changing for New Premium Members on Sept. 1

wlkr
1pts0
old.reddit.com 4y ago

PEP 8: Why is the character limit 79 and not 80?

wlkr
2pts0
www.sciencealert.com 4y ago

Brain implant translates paralyzed man's thoughts into text with 94% accuracy

wlkr
449pts211
worldchess.com 5y ago

Fide Online Arena Now Has an iOS App. Hmmm

wlkr
1pts0
uk.reuters.com 5y ago

As the Arctic's attractions mount, Greenland is a security black hole

wlkr
1pts0

At this point I would very much like to get off Mr Bones' Wild Ride but I fear this is going to continue to happen because, from my own exploration at least, a large number of commercial detection strategies are directed at the repo/device/developer level when loading/using a package.

This seems analogous to how we tackle email spam and general malware. It means that there is almost always a target valuable enough for bad actors to continue trying. However, unlike email (mostly...), package managers are centralised authorities (and anything out-of-band is surely the developers problem?).

My ill-informed feeling is that we might need to change the culture of lazy versioning with rapid releases and focus on stable, deeply scanned versions at registries. There will be some effect of volume and scale so I could be off, but it still seems telling that this impacts high-churn languages more often.

I don't know, I would love a comprehensive article that explores the landscape right now.

I didn't say it was necessarily more credible, although I understand that was mentioned further up.

Personally I found the article (not the tweets) much more useful to understand the context of all this, as someone very out of the loop. Certianly more useful to me than a long list of very specific, in my option largely LLM output, points about a codebase I'm entirely unfamiliar with with claims that seem to need a legal team and court case to be meaningful. Slop is somewhat unfair and I'm happy to be disagreed with.

This might just be the frequency illusion at play, but there seem to have been a number of high-profile supply chain attacks of late in major packages. There are several articles on the first few pages of HN right now with different cases.

Looking back ten years to `left-pad`, are there more successful attacks now than ever? I would suspect so, and surely the value of a successful attack has also increased, so are we actually getting better as a broad community at detecting them before package release? It's a complex space, and commercial software houses should do better, but it seems that whilst there are some excellent commercial products (e.g. CI scan tools), generally accessible, idiot friendly tooling is somewhat lacking for projects which start as hobby/amateur code but end up being a dependency in many other projects.

I've cross-posted my comment from the current SAP supply chain attack thread [0].

[0] https://news.ycombinator.com/item?id=47964003

This might just be the frequency illusion at play, but there seem to have been a number of high-profile supply chain attacks of late in major packages. There are several articles on the first few pages of HN right now with different cases.

Looking back ten years to `left-pad`, are there more successful attacks now than ever? I would suspect so, and surely the value of a successful attack has also increased, so are we actually getting better as a broad community at detecting them before package release? It's a complex space, and commercial software houses should do better, but it seems that whilst there are some excellent commercial products (e.g. CI scan tools), generally accessible, idiot friendly tooling is somewhat lacking for projects which start as hobby/amateur code but end up being a dependency in many other projects.

Hopefully this doesn't seem like advertising - I'm not affiliated with the project in any way. I just particularly enjoy playing with cyberdecks [1] and stumbled upon this while browsing. I continue to have a lot of fun with the uConsole and SDR, but I've long wanted a Cardputer with a bit more oomph. I should add, if anyone is interested in a uConsole, brace yourself for the shipping times... [2].

[1] https://www.reddit.com/r/cyberDeck/

[2] https://www.reddit.com/r/ClockworkPi/comments/1fk893z/shippi...

I'm very interested to see how some VPN providers react to this. For a zero logs VPN provider, if such a thing can really exist, how big of a problem is this? Presumably many customers pay with a debit/credit card already so there's some PII on file? Usage remains the same? Surely savvy people can just use their existing VPN to buy a VPN from outside the UK.

Of course, we're sliding quite rapidly down that slippery slope here so I'm sure logging and easier government tracking would be next. The justifications will get weaker and even more lacking in supporting evidence for their implementation.

Thanks for responding, and, especially recognising the name, thanks for all your work on the Clojure ecosystem! To answer the question, for me personally, it would be largely full-stack web and data science tooling, but that's just me. I was moreso thinking out loud about the posted project and highlighting libraries that could be semi-official or strongly recommended by the community. The Clojure community offers many different libraries that, on the surface, are similar, even if each addresses a particular set of concerns. For a lowly idiot like me without enough time to spend writing code in Clojure, I'd love to just be directed to those used by the experts and have solid backing and anticipated longevity - 'gold star' libraries.

Perhaps a bit cynical, but it seems that as Microsoft continue to shove ads in absolutely everywhere and track everything they possibly can, Apple are content to be just marginally better rather than actually having meaningfully higher standards. Of course, it's business as usual, but we are boiling the frog for the next generation by tolerating it.

It would be helpful to see some additional stats, like the number of issues and the last update. Of course, these are only heuristics, but they are still helpful to see. It's often pointed out that one of the great things about Clojure is that the libraries generally don't need updating that often because the language is pretty stable. However, quite often I do find that libraries have a number of long open issues or depend on outdated, sometimes insecure, versions of Java libraries. I realise that I'm complaining about free code, so 'fork it and contribute' is a valid response, but at the risk of further fragmentation and yet another library that exists for just a short period.

Separately, I do wish Clojure would adopt a bit more of an opinionated way of doing things and coalesce around some solid core/common libraries that the official docs could point to. This year, Clojure didn't make it into the named languages list on the Stack Overflow developer survey (1.2% in 2024). It's clear that it's not all that popular, even though there's some commercial backing and a friendly community, and there just aren't enough developers to support a myriad of different ways of doing things. I do feel there needs to be a focus on getting beginners in, and that means helping them to do things easily.

This is a good article, but in my opinion overlooks changes to the existing display accessibility features as a result of liquid glass (although I appreciate it can't cover absolutely everything). I enable high contrast in light mode (along with some other tweaks, like clearer button indicators). Unfortunately, this is quite a bit worse for me in Tahoe. I'm hoping it improves with future updates but it's annoying. I'm otherwise neutral to slightly negative on liquid glass so far.

Apache ECharts 1 year ago

This looks great, thanks! I didn't come across this this in my search but I'll definitely try it out.

Apache ECharts 1 year ago

Funny seeing this here with your comment, as I was exploring using ECharts for a project recently to work exactly with HTMX from a Clojure backend. I eventually settled on Chart.js as I found that for my use case, I wanted the charts to more easily fit their dynamically sized container, which isn’t quite as simple with ECharts and Vega. I also didn't need particularly complex plots. Nevertheless, this is a nice project! There remain some open challenges with web-based visualisation libraries more generally around responsive design and accessibility, but we’ve come a long way.