Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
flaminHotSpeedo
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
flaminHotSpeedo
3mo ago
I was under the impression the purpose of that is to give an LLM a cheap (in terms of context window) understanding of a repo, and not at all for the benefit of humans? Whether that's effective is another matter, even if the LLM genera
2.
▲
by
flaminHotSpeedo
3mo ago
I haven't personally tried, so I can't say for certain, but Lambda has publicly stated they run on bare metal EC2 instances, presumably the supply of whatever instance types they use should be fairly healthy
3.
▲
by
flaminHotSpeedo
3mo ago
Most mature and/or security conscious providers don't consider containers to be a secure isolation boundary (with Microsoft being a notable exception, though it's unclear whether that's a failure of internal policy or in
4.
▲
by
flaminHotSpeedo
4mo ago
I wasn't expecting a peer reviewed study, but I certainly was expecting more from that title
5.
▲
by
flaminHotSpeedo
5mo ago
What makes you say that? The article is pretty clear that they had the llm working in a staging environment, then it decided to use some other creds it found which (unbeknownst to the author) had broad access to their prod environment.
6.
▲
by
flaminHotSpeedo
6mo ago
I wish there was a mechanism to force shitty, bloated companies that have been mismanaged into a nosedive to divest "culturally valuable" IP early. I enjoyed the early ghost recon and rainbow 6 games, but I don't even bother
7.
▲
by
flaminHotSpeedo
6mo ago
350 was late last year. The text at the top of the linked page says prices are up about 30% over the past month. Directly prior to the war starting the price was about 470
8.
▲
by
flaminHotSpeedo
7mo ago
> My opinion is that both should be liable in a case like this. I totally agree, but if I went after every company I felt to be incompetent to the point of criminal negligence I'd be up to my eyeballs in lawsuits just over password
9.
▲
by
flaminHotSpeedo
7mo ago
That's fair, if your domain is erroneously put on the block list, Google should be liable for the consequences. But my point is that any knock on effects like domain suspension, email deliver-ability, etc. stem from 3rd parties misusin
10.
▲
by
flaminHotSpeedo
7mo ago
Self censorship requires a threat or risk of detriment if the party doesn't self censor, right? Where is that here? What Radix does has no impact on Google, and I don't see how Google would be incentivized to pressure Radix. So I
11.
▲
by
flaminHotSpeedo
7mo ago
Theoretically, the easiest way is to use a sub address (more commonly/colloquially known as email aliases or plus addresses, they're described in RFC 5233). You should be able to add a separator character (usually a plus, sometime
12.
▲
by
flaminHotSpeedo
7mo ago
You might want to review the commenting guidelines, notably the first few. Like you mention, big tech gravitates to a handful of tech hubs across the US, which drives up salaries for every company in the area. Which is more data suggesting
13.
▲
by
flaminHotSpeedo
7mo ago
I think there's a fundamental misunderstanding where executives mistake software engineering for "code monkey with a fancy inflated title" And coding agents are making that disconnect painfully obvious
14.
▲
by
flaminHotSpeedo
7mo ago
I question their data if their p90 value is $211k I recognize that not everyone makes big tech money, but that's somewhere between entry and mid level at anywhere that can conceivably be called big tech
15.
▲
by
flaminHotSpeedo
9mo ago
Are you thinking of the Missouri department of education's teacher directory website? https://krebsonsecurity.com/2022/02/report-missouri-governor... Luckily someone eventually talked sense into the governor,
16.
▲
by
flaminHotSpeedo
9mo ago
Actually, it's really important to me to have a network of atomic clocks available to verify the times I clock in and out, I want to make sure I get paid for an accurate duration of time down to the nanosecond
17.
▲
by
flaminHotSpeedo
9mo ago
> 103 drivers (41.9%) overall tested positive for THC, with yearly rates ranging from 25.7% to 48.9%. The statistics for this seem suspect at best, I'll believe it once it's peer reviewed
18.
▲
by
flaminHotSpeedo
9mo ago
> Researchers analyzed coroner records from Montgomery County in Ohio from January 2019 to September 2024, focusing on 246 deceased drivers who were tested for THC following a fatal crash. This paper would need to go into way more detail
19.
▲
by
flaminHotSpeedo
9mo ago
Yeah, in some (rare) situations physical isolation is a more appropriate level of security. Or if you want to land somewhere in between, you can use VM's with single tenant NUMA nodes. But for a typical case, VM's are the bare min
20.
▲
by
flaminHotSpeedo
9mo ago
Containers are never a security boundary. If you configure them correctly, avoid all the footguns, and pray that there's no container escape vulnerabilities that affect "correctly" configured containers then they can be a cru
21.
▲
by
flaminHotSpeedo
9mo ago
That's entirely incorrect. For starters, they didn't get unlucky. They made a choice to use the same system they knew was sketchy (which they almost certainly knew was sketchy even before 11/18) And on top of that, Cloudflare
22.
▲
by
flaminHotSpeedo
9mo ago
There was another deployment system available. The progressive one used to roll out the initial change, which presumably rolls back sanely too.
23.
▲
by
flaminHotSpeedo
10mo ago
Do you have a public source about an embargo period for this one? I wasn't able to find one
24.
▲
by
flaminHotSpeedo
10mo ago
Like the other poster said, roll back should be the right answer the vast majority of the time. But it's also important to recognize that roll forward should be a replacement for the deployment you decided not to roll back, not a paral
25.
▲
by
flaminHotSpeedo
10mo ago
To clarify, I'm not trying to imply that I definitely wouldn't have made the same decision, or that cowboy decisions aren't ever the right call. However, this preliminary report doesn't really justify the decision to use
26.
▲
by
flaminHotSpeedo
10mo ago
They kinda buried the lede there, 28% failure rate for 100% of customers isn't the same as 100% failure rate for 28% of customers
27.
▲
by
flaminHotSpeedo
10mo ago
What's the culture like at Cloudflare re: ops/deployment safety? They saw errors related to a deployment, and because it was related to a security issue instead of rolling it back they decided to make another deployment with globa
28.
▲
by
flaminHotSpeedo
10mo ago
My understanding of the contemporary argument against publicly traded companies, though I'm not completely convinced of them personally, are that the fiduciary obligations inevitably drive those bad behaviors, and/or that sharehol
29.
▲
by
flaminHotSpeedo
11mo ago
That's what I was getting at, though I wasn't sure if my perceptions matched the general consensus (which it seems they do). If a manufacturer has been broadly considered as unreliable for the past 20-40 years (JK's came out
30.
▲
by
flaminHotSpeedo
11mo ago
Out of curiosity, what do you mean by Jeep riding on their reputation? Based on everything I've seen and heard, Jeep's reputation is for unreliable vehicles that are increasingly difficult to repair. This seems pretty on-brand for
More ›