Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
intern4tional
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
intern4tional
1mo ago
The requirement for hardware security keys ties the use of these models even tighter to a specific identity. This will limit ability to scale or share the model.
2.
▲
by
intern4tional
2mo ago
Interesting article but doesn't seem to understand how security teams work or even how to address a threat outside of an brittle easily bypassed response. The initial report was investigated and resolved, with the removal of specific r
3.
▲
Arene Base
(github.com)
2 points
by
intern4tional
4mo ago
|
2 comments
4.
▲
by
intern4tional
4mo ago
arene_base provides low level C++ facilities to help development of safety critical software in compliance with Woven by Toyota's C++ development best practices.
5.
▲
by
intern4tional
8mo ago
You misunderstand. Ben is a random engineer, he is definitely not the proper point of contact. FOSS compliance is serious, so if this is real, do escalate it.
6.
▲
by
intern4tional
8mo ago
Correct, that was my intent - Ben isn't the proper channel as he is just an engineer responding to comments here. Stuff like this is serious and so should be escalated. Compliance with FOSS licenses isn't a joke.
7.
▲
by
intern4tional
8mo ago
Nothing. This isn't something that is even tracked. AI usage is obviously encouraged but HR has far better things to do than go gather this kind of data. Internally, depending on what product is being worked on teams will have differ
8.
▲
by
intern4tional
8mo ago
Assuming this is real and you have the authority to share your work from previous location; you should reach out and contact Microsoft Legal directly. A random engineer on Hacker News is not the proper channel. Link: https://www.
9.
▲
by
intern4tional
2y ago
QNX is heavily used in industries where functional safety or particular high assurance models are required. Sure FreeRTOS has a SafeRTOS mode, but its not sufficiently functional for a modern ADAS stack or complex robotics systems. QNX is
10.
▲
by
intern4tional
2y ago
He was freed in 2020: https://arstechnica.com/tech-policy/2020/02/man-who-refused-...
11.
▲
by
intern4tional
2y ago
https://web.archive.org/web/20061023112233/http://software.s... "Microsoft made both changes in response to antitrust concerns from the European Commission. Led by Symantec, the world's largest
12.
▲
by
intern4tional
2y ago
Windows does have the ability to have sovereign builds (and has had this since 2016?), but the capability wasn't present when the decision was made (in 2006). Windows build is complex and tightly coupled with performance testing, tele
13.
▲
by
intern4tional
2y ago
Industry forum was external, MS did not start that. I do not know enough to properly answer on the concrete reasons why, only that it was external. Sorry.
14.
▲
by
intern4tional
2y ago
As someone that worked at MS, on a team that worked directly on this issue (among other things) some years ago, MS did figure out better solutions and did discuss it with industry. MS has an entire forum for discussing these things with ind
15.
▲
by
intern4tional
2y ago
Here's an actual compliant at MS to the EU from an anti-malware vendor: https://www.techtarget.com/searchsecurity/news/450420491/Mic... This is and has been a thing for quite some time. Windows is a hig
16.
▲
by
intern4tional
2y ago
There is basis for that assertion. Via Google: https://www.techtarget.com/searchsecurity/news/450420491/Mic... (Also via myself, as I was at MS when we wanted to make this change and the EU said no.)
17.
▲
by
intern4tional
2y ago
So the grandparent poster has a fundamental misunderstanding of how Windows works, and why CrowdStrike has a kernel driver in the first place. Microsoft has long desired to kick AV vendors out of kernel space and has even attempted to do so
18.
▲
by
intern4tional
2y ago
I think returning results in a timely manner is more than an acceptable assumption. The poster clearly thought about search in terms of the existing Google search functionality which is near instantaneous. Usability matters to the average e
19.
▲
by
intern4tional
2y ago
This makes it something that the average person cannot do; you're suggesting something that already requires more time and resources than 75% of the population has access to. If you're serious about this than go talk to a non-tech
20.
▲
by
intern4tional
3y ago
I don’t disagree with this either, I just didn’t think of it when I put my response in. Naming and shaming does work.
21.
▲
by
intern4tional
3y ago
Of course, but it that’s good in most cases as then you don’t get an overreaction. The right people will read it (Chattr.ai’s customers) and respond . Right now everyone looks at it and some CISO will overreact and make everyone go check t
22.
▲
by
intern4tional
3y ago
Title: I pwned Chattr.ai via Firebase misconfiguration That’s what you should call it. It explains to readers what’s going on without over sensationalism. That isn’t too long either.
23.
▲
by
intern4tional
3y ago
No, as company employee is directly tied to and the responsibility of the company. These companies are responsible for their employees behavior and data but they are not responsible for nor legally liable for (in most cases, some exceptions
24.
▲
by
intern4tional
3y ago
This isn’t owning fast food chains; rather compromising some AI startup that has some of them as a customer. Title is misleading.
25.
▲
by
intern4tional
3y ago
So this is mostly a solved problem at other OEMs, and I do not know how Ford does it. I know that other OEMs do variant testing, have complex SILS (software in the loop) test systems so that all potential failure scenarios are tested in sof
26.
▲
by
intern4tional
3y ago
I think there is one other unaccounted aspect that the article doesn't acknowledge. I've never seen a SRE lead go to prison for an outage, but as of late a few CISOs have been charged, convicted, and sentenced to prison for failin
27.
▲
by
intern4tional
3y ago
Likely not their code. OTA is generally developed by tier 1, so this is probably a bug in the tier 1's code. (Samsung, Panasonic, Sony, etc are common tier 1s in this space.)
28.
▲
by
intern4tional
3y ago
So, this will be my last response to this thread as I think it's run it's course. > voluntary standards aren't standards Most of the worlds standards work this way. They are standards, and it is up to various legislative
29.
▲
by
intern4tional
3y ago
> Tesla being non-compliant is precisely my point: they get away with that because they don't have to open up their code to scrutiny. This is an inaccurate assumption. ASIL compliance is something that you can publicly state, and T
30.
▲
by
intern4tional
3y ago
This comment chain appears to have a fundamental misconception of what constitutes safe and what does not. Automotive standards and automotive coding standards approach safety in a different way than most people think (and given your commen
More ›