Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rainforest
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
rainforest
1mo ago
Are the headers not connected to that same filter net anyway?
2.
▲
by
rainforest
4mo ago
Note that the smart feed "feature" is Taboola-provided adware[0] so it's par for the course. It's beyond comprehension Lenovo would trash the brand by shipping it on flagships. [0] https://www.reddit.com/
3.
▲
by
rainforest
9mo ago
I'm quite surprised to see the need to debug a live server here. I'm of the belief that the need to repro a problem locally and using a debugger lead to better understanding. SSHing into boxen feels like a cowboy behaviour on a mo
4.
▲
by
rainforest
1y ago
Does it worry you at all that meat is ultimately made of whatever food the animal eats and processed into a litany of chemicals? I feel the UPF "debate" is just an appeal to nature, and calorie/nutrient density should be what
5.
▲
by
rainforest
1y ago
I had similar with my energy provider in the UK (Octopus). For one reason or another a regular payment bounced which automatically puts you on a "call daily until the debt is repaid" list. These calls come in on an unrecognised nu
6.
▲
by
rainforest
1y ago
I think Cloudflare WAF is a good product compared to other WAFs - by definition a WAF is intended to layer on validation that properly built applications should be doing, so it's sort of expected that it would reject valid potentially
7.
▲
by
rainforest
2y ago
Thanks, for the benefit of others the risk is that the devtools port has no Auth so is vulnerable to XSS. I would surmise that this will stop being a problem if you switch to using a unix socket for the CDP.
8.
▲
by
rainforest
2y ago
Could you go into a bit more detail about this? Why is exposing devtools to the agent a problem? What's the attack vector? That the agent might do something malicious to exfil saved passwords?
9.
▲
by
rainforest
2y ago
For a while the /join page was blocked by cloudflare WAF yesterday - I wonder if this is why.
10.
▲
by
rainforest
2y ago
The NHS does this calculus routinely using Quality Adjusted Life Years. Treatments that get more are favoured which is also how NICE decides what drugs the NHS should offer. There's obviously some utilitarianism in the decision to use
11.
▲
by
rainforest
2y ago
I would offer a counterpoint: most software in existence was written by not-software-professionals in Excel (most likely poorly). Within reason I think there is a rational basis for not having to involve software engineers for every project
12.
▲
by
rainforest
3y ago
Yes, if the key isn't in the TPM then it can't be sniffed. Secure boot would need to be enabled to protect against the threat model bitlocker is only good for here. Alternatively using a PIN would mean the key is only exposed once
13.
▲
by
rainforest
3y ago
A cow is in a sense a factory producing various proteins, fats, and carbs from grass. Does putting it into something "natural" reset it? I would imagine that red meat isn't a UPF by definition as it's only been through o
14.
▲
by
rainforest
4y ago
IIRC some of the Snowden leaks alleged that (at least at the time) domestic traffic couldn't be surveilled (but this was solved by mutual assistance across the Atlantic - the British would spy on US citizens and vice versa[1]). VPNs se
15.
▲
by
rainforest
5y ago
Most Kickstarter campaigns I get shown on FB are from third party services that just upload the Kickstarter breach list (my email is in it). Could that have happened to you?
16.
▲
by
rainforest
6y ago
The web extension honor system "security" model is broken because that extension that prints Hello at the top of the page might later be modified by a malicious actor to do something else [1]. [1] https://www.reviewgeek
17.
▲
by
rainforest
6y ago
Perhaps you don't have a change in the number of crackpots, but you have a decent chance the crackpots are now all saying the same thing. Misled voters in a democracy seems like a bad thing to me (this extends to the way mass media is
18.
▲
by
rainforest
6y ago
Sure Audio makes an ADAU1701 set of boards that looks similar. Parts Express seems to carry Dayton Audio branded versions. Can't say how well they work but a stack of IF board, DSP only, and Bluetooth programmer cost me around £50. Loo
19.
▲
by
rainforest
6y ago
Is there any potential for extending that limit? I work on a product that uses Fargate Spot as a kind-of lambda substitute to run longer-duration tasks consumed from SQS and being able to use lambda to do that would make life easier :)
20.
▲
by
rainforest
6y ago
> I don't understand why an entire elementary statistics pseudo-textbook is bolted on at the end, forming the entire back half of the text It's quite difficult to talk about empirical software engineering without discussing met
21.
▲
by
rainforest
6y ago
The permissions system seems to be granular with respect to whatever was selected - if you select a directory you have full access to everything in it. Theoretically the permission system requires explicit approval, but if you see the secur
22.
▲
by
rainforest
6y ago
It appears I could use this to ask a victim to "select your downloads folder" to save files to and then steal or overwrite any file in it.
23.
▲
by
rainforest
6y ago
Slack does this too. Slackbot sends you "getting started" tips by default, which led to me receiving an email to ensure I enable notifications. That email was sent out of office hours on a Friday evening too. I'm sure it wasn
24.
▲
by
rainforest
6y ago
Yes, if there was a library that eval'd unsanitised input the damage potential is the same. The practical difference is that it's a lot harder to assure code written in unsafe languages is free of defects like this since they mani
25.
▲
by
rainforest
6y ago
The exploit is against a vulnerable library (the actual input file is here: https://github.com/sola-st/wasm-binary-security/blob/master/... ) If you have a wasm application with vulnerabilities (e.g. in t
26.
▲
by
rainforest
6y ago
Gradle. I appreciate that it is a fast build system, and a lot of it does just work. When it doesn't just work it's a nightmare. The config language is completely opaque and undiscoverable (Kotlin might fix this, but I ran out of
27.
▲
by
rainforest
6y ago
I think the only way to do so would be to deny themselves the ability to push software to customers (speculating that this is how it was attacked), which itself is an attack vector. It basically seems impossible to do securely if you can&#x
28.
▲
by
rainforest
6y ago
Spam seems to be a growing problem too. If you follow (or even listen to) an artist, all someone needs to do is credit them on a song (or just squat on their name) for it to be eligible for Release Radar. There are weird pockets of the Spot
29.
▲
by
rainforest
6y ago
I suspect there's not much information in the individual blurred face, but I wonder if given enough examples you'd be able to determine if an unblurred face is the one in a sample of images with any level of confidence? You can do
30.
▲
by
rainforest
6y ago
How do you validate the predictions for the number of infected cases in May for scenarios that don't happen?
More ›