Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
outloudvi
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
outloudvi
6d ago
I agree with the opinion that people should treasure every moment, and live as if they only have 100 days of life, that is: to have fun, to try things, to explore anything they are interested in etc.. The LLM horror, no matter unfake or not
2.
▲
by
outloudvi
12d ago
If people want to apply this mechanism, it shall be not much of a hassle for writers of most (modern) programming languages, as they mostly have some `src/` directory (maybe also some `tests/`) that contains all source codes for a
3.
▲
by
outloudvi
2mo ago
Went through the comment page and found this comment that explains well on most of the popular opinions. Thank you, hennell!
4.
▲
by
outloudvi
2mo ago
I agree cooldown is not harmful in general. What I intended to say is that people (mostly) only know a security company is not trustable because they once failed to detect a malware package, and the reason people know a package is malware i
5.
▲
by
outloudvi
2mo ago
I agree that LLM does not (and believe it never) fully replace researchers, but it produces artifacts (e.g. writeups, PoCs) at a cheaper price. That makes me think LLM impacts human researchers' rewards, but now I realized the result
6.
▲
by
outloudvi
2mo ago
After reading the comments I now agree a short-length cooldown (maybe 1 or 3 days) is beneficial, given the following assumptions: - Independent security companies are scanning the packages (be careful if the project is depending on some no
7.
▲
by
outloudvi
2mo ago
Sorry! That's 100% on me failing to make the analogy understood. Shall have thought about that... but I'm playing too many Unity games recently.
8.
▲
by
outloudvi
2mo ago
Thanks for your explanation on the definition of "security theater"! > But if it turns out they can’t serve as the cooldown vanguard, then we have great evidence that they shouldn’t be trusted at all. If they cannot serve as th
9.
▲
by
outloudvi
2mo ago
I applaud you if you do setup automated security scanners, without counting on external security groups or individuals (that doesn't have a security contract with your company). This post is based on an assumption from what I see (I wo
10.
▲
by
outloudvi
2mo ago
> The idea of not moving quickly to new software versions has been around for decades. There are COBOL users and CentOS 6 users. They aren't affected by this issue. They might need to face another set of issues like vulnerability ba
11.
▲
by
outloudvi
2mo ago
I think it's great if people actually use LLM for the analysis. I did mention it in the solution part in the post: > Run LLM-assisted audit on vendored code.
12.
▲
by
outloudvi
2mo ago
I also believe sandboxing will get more and more important. There might be some trade-off on user experience or convenience, but given the security enhancement and (LLM agent's) freedom I think it will be well worth it.
13.
▲
by
outloudvi
2mo ago
I do appreciate these security companies a lot (for example, Snyk), but I feel it hard to believe this is sustainable. Especially in the current world where LLM is devaluing security researchers' work. If they cannot get enough fiat or
14.
▲
NPM's release cooldown is security theater
(blog.outv.im)
44 points
by
outloudvi
2mo ago
|
75 comments
15.
▲
by
outloudvi
2mo ago
May I put some contents against GCP's AUP in my repo, wait for Grok Build to upload them, and report the bucket to Google?
16.
▲
by
outloudvi
4mo ago
> Sadly, the RDS kernel module this requires is only default on Arch Linux among the common distributions we tested. Sir, what do you mean by "Sadly"? I know your write-ups are mostly for marketing, but please don't expose
17.
▲
by
outloudvi
5mo ago
The article speaks well but the situation for coding is more severe. Shells are not needed once they are not in needed. Code does not: customer need is always there. Before forgotting how to code, The West will first get round up by their o
18.
▲
by
outloudvi
7mo ago
These companys don't care about the reputation of their domains anymore at the moment they start to send spams. However, email senders (SendGrid, Mailgun etc.) care about the reputation of their IP addresses.
19.
▲
by
outloudvi
7mo ago
I usually check the "Received" header and report to the email service provider. Once in a while I receive a response saying the case is properly handled. These providers are the only ones that care about their reputation and thus
20.
▲
by
outloudvi
7mo ago
> Is there good public discussion on root expiration? Haven't seen a specific one but I guess the most relavant public discussion on root CA-led device bricking issues might have occurred around the time when DST Root CA X3 (natural
21.
▲
I cannot curl https://example.com (on some distros)
(blog.outv.im)
15 points
by
outloudvi
7mo ago
|
2 comments
22.
▲
by
outloudvi
9mo ago
While the style and headline seems like Hacker News, the usernames seem increasingly alike Slashdot.
23.
▲
Email spammer forgets to BCC, triggering reply-all storm (mainly from UBC)
(mk.outv.im)
2 points
by
outloudvi
10mo ago
|
0 comments
24.
▲
by
outloudvi
11mo ago
I'm worried about the situation when Dark Patterns are not widely recognized enough as a malicious practice for users. Half a month ago I see someone on Twitter defending its own product design as "transparent and nothing hidden&q
25.
▲
by
outloudvi
1y ago
Vercel has a fairly generous free quota and a non-negligible high pricing scheme - I think people still remember https://service-markup.vercel.app/ . For the crawl problem, I want to wait and see whether robots.txt is prove
26.
▲
by
outloudvi
3y ago
The reveal.js slide itself probably isn't the best way for readers. The reveal.js project actually provides a PDF export feature which can be more helpful. Anyway, it's an asahilina.net page, not a cve.mitre.org page. That domain
27.
▲
Reddit is working on adopting the Matrix standard for Chats
(twitter.com)
10 points
by
outloudvi
4y ago
|
0 comments
28.
▲
by
outloudvi
4y ago
Isn't it against at least the law somewhere?
29.
▲
by
outloudvi
4y ago
1. Anything beyond control may cause problems. For the security part: add SRI to whatever you care about, please. 2. Could we, in 2022, get rid of the troublesome Referer?
30.
▲
by
outloudvi
4y ago
Would a double SHA256 hash make it securer?
More ›