Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
cataflam
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
cataflam
4mo ago
Congrats gaeld and team The demo is very impressive! disclaimer: I've known the founder for a while, as legitimate as it gets in deep tech, real years of research and engineering behind this, not vaporware
2.
▲
by
cataflam
4mo ago
> For monitoring I use and recommend UpDown.io, which doesn’t seem to be listed there. It doesn't seem very well known, but I've been a happy user. Most of the others have become over-bloated with a shitty UI.
3.
▲
by
cataflam
4mo ago
> Nicholas Carlini, a researcher at Anthropic, orchestrated 16 parallel Claude agents to write a production C compiler in Rust. To write a proof-of-concept C compiler, not a production-grade one... Hard to take the article seriously afte
4.
▲
by
cataflam
5mo ago
You misinterpreted the comment you are citing. This non-determinism would not and did not cause replays to diverge (the PRNG seed was most likely stored and would reproduce exactly the same results).
5.
▲
by
cataflam
6mo ago
Your AI powered comment is wrong. Le monde has been doing this for years. They have a series of articles about this. There is no "gap closing."
6.
▲
by
cataflam
6mo ago
it cannot email your secret key to an attacker because of prompt injection etc.
7.
▲
by
cataflam
6mo ago
Almost a month old, original source: https://cybernews.com/security/global-data-leak-exposes-bill... and I've never seen any confirmation elsewhere Looks like CyberNews have edited the article with more info since
8.
▲
by
cataflam
7mo ago
You're getting downvoted because you didn't read the article. It is specifically about cleaning up the data by removing these 3 and showing a clearer picture of acceleration without these 3 factors.
9.
▲
by
cataflam
9mo ago
Great series of articles!
10.
▲
by
cataflam
10mo ago
Don't they? https://git.ffmpeg.org/gitweb/ffmpeg.git?a=search&h=HEAD&st=...
11.
▲
by
cataflam
11mo ago
Wow. Maybe I'm missing something but it seems really weird to replace a tool with a rewrite that doesn't pass the test suite!
12.
▲
by
cataflam
11mo ago
This comment[0] explains it. The core bug seems to be that support for `date -r <file>` wasn't implemented at the time ubuntu integrated it [1, 2]. And the command silently accepted -r before and did nothing (!) 0: https:/&
13.
▲
by
cataflam
1y ago
Amazing they are still alive and kicking. Started using them with Windows 95 (different specific ones, same general concept) These and Sysinternals (bought by Microsoft around 2006) were must have when I was still using Windows. https:
14.
▲
by
cataflam
1y ago
> update your password, update your 2FA should practice it for ENTER your password, ENTER your 2FA ;) > Still, I don’t understand how npmjs.help doesn’t immediately trigger red flags 1. it probably did for quite a few recipients, but
15.
▲
by
cataflam
1y ago
Indeed. At least the crowd here should _know_ that TOTP doesn't do anything against phishing, and most of the critical infrastructure for code and other things support U2F so people should use it.
16.
▲
by
cataflam
1y ago
My apologies, somehow after all these years, I didn't know that (and first time I've done it)!
17.
▲
by
cataflam
1y ago
Yes! Here is the whitepaper (from 2017 I think), I read that and used it, it's excellent https://karla.io/files/ichthyology-wp.pdf > At Stripe, rather than focusing on mitigating more basic attacks with phishin
18.
▲
by
cataflam
1y ago
Still would have done nothing in this case, as they pulled the correct email address he uses for npm from another source (public API I think?). That's exactly why I said all the other "helpful" recommendations and warning sig
19.
▲
by
cataflam
1y ago
As for any of these cases, we do receive legitimate emails that require being logged in, Google or otherwise The answer is simple: use your bookmarks/password manager/... to login yourself with a URL you control in another tab and
20.
▲
by
cataflam
1y ago
In that case 1. You just requested it, I'm not saying to never click link on transactional emails you requested. You still need to click on those verify email links 2. It replaces entering your password, so you're not entering you
21.
▲
by
cataflam
1y ago
Besides the ecosystem issues, for the phishing part, I'll repost what I responded somewhere in the other related post, for awareness --- I figure you aren't about to get fooled by phishing anytime soon, but based on some of your r
22.
▲
by
cataflam
1y ago
France and UK, from personal experience, whatsapp is big, especially for professional use, or friends/family groups. Blue bubble isn't really a thing ever mentioned in France either, not enough iPhone market share.
23.
▲
by
cataflam
1y ago
I mostly agree and I do use one. You only need read the whole thread however to see reasons why this would sometimes not be enough: sometimes the password manager does not auto-fill, so the user can think it's one of those cases, or th
24.
▲
by
cataflam
1y ago
> outside of the West you probably mean outside of the USA, it's huge in Europe/UK (which doesn't contradict your main point)
25.
▲
by
cataflam
1y ago
Hey, you're doing an exemplary response, transparent and fast, in what must be a very stressful situation! I figure you aren't about to get fooled by phishing anytime soon, but based on some of your remarks and remarks of others,
26.
▲
by
cataflam
1y ago
> There is NO reliable indicators Completely agree. The only reliable way is to never use an email/SMS link to login, ever.
27.
▲
by
cataflam
1y ago
Happy for you, don't get me wrong, but your post is not particularly news, I'm guessing everyone on HN knows bare metal/VPS providers are cheaper than AWS/Azure/GCP. And also lacking a bit in details: - both technic
28.
▲
by
cataflam
2y ago
Because you shouldn't use the simulator to calculate the EV, or said differently your n=1000000 is too small. Assuming you used the first lottery example (Mega Millions), the EV is easy to calculate directly and is -$0.66/ticket,
29.
▲
Humble Bundle: Software Architecture 2024 O'Reilly
(humblebundle.com)
3 points
by
cataflam
2y ago
|
0 comments
30.
▲
by
cataflam
2y ago
Besides missing the actual testing (!), the staged rollout (!), looks like they also weren't fuzzing this kernel driver that routinely takes instant worldwide updates. Oops.
More ›