Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
staticassertion
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
451.
▲
by
staticassertion
7mo ago
I don't really agree. Maybe I do, but I probably have mixed feelings about that at least. DoS is distinct because it's only considered a "security" issue due to arbitrary conversations that happened decades ago. There&#x
452.
▲
by
staticassertion
7mo ago
If the system "fails open" then it's not a DoS, it's a privilege escalation. What you're describing here is just a matter of threat modeling, which is up to you to perform and not a matter for CVEs. CVEs are local p
453.
▲
by
staticassertion
7mo ago
Part of the problem is that customers will scan your code with these tools and they won't accept "we never call that function" as an answer (and maybe that's rational if they can't verify that that's true). Thi
454.
▲
by
staticassertion
7mo ago
TBH I Think that DoS needs to stop being considered a vulnerability. It's an availability concern, and availability, despite being a part of CIA, is really more of a principle for security rather than the domain of security. In practic
455.
▲
by
staticassertion
7mo ago
It's strange to me that you read the word 'easily' as 'commonly', these are unrelated terms. But I suppose I am fine with saying that reports of death threats against users who use AI are quite common, certainly any
456.
▲
by
staticassertion
7mo ago
I actually do exercise. What I'm suggesting here is that there was never anyone helping me to build that habit forming, it has been entirely "self serve".
457.
▲
by
staticassertion
7mo ago
Yes, sorry, I think other posts are quite critical of yours so maybe you think this was me trying to be like "your post is bad". I think you're right (though I think that medication and therapy are often critical to help kick
458.
▲
by
staticassertion
7mo ago
I think this is true, but oof that's a heavy list. For one thing, food, alcohol, drugs, and stimulants, all have addictive properties that are almost certainly comorbid with depression. Dropping those is rough. Exercise is perhaps one
459.
▲
by
staticassertion
7mo ago
I mean, this is very obviously false. Literally everyone is not. Some people are, some people are absolutely condemning the use, some people use it just a bit, etc.
460.
▲
by
staticassertion
7mo ago
I'm surprised that you consider this hefty or find this surprising. I think you can just Google this and decide on what you consider "verified". There's quite a lot of "AI drama" out there that I'm sure yo
461.
▲
by
staticassertion
7mo ago
There is a massive difference between saying "I use AI" and what the author of this bot is doing. I personally talk very little about the topic because I have seen some pretty extreme responses. Some people may want to publicly st
462.
▲
by
staticassertion
7mo ago
I'll need you to be much more specific. I'm actually quite familiar with Rust, having worked with it since 2015, speaking at the first rustconf, having written in it professionally, having worked on a team that did vulnerability r
463.
▲
by
staticassertion
7mo ago
> Chromium is filled with sloppy and old code. Some of the source code (at least if dependencies are included) is more than 20 years old, and a lot of focus has been on performance, not security. Chromium is also some of the most highly
464.
▲
by
staticassertion
7mo ago
The ITW exploit has some sort of sandbox escape. My money is on a kernel exploit, but there are other options - universal XSS, IPC, etc. Kernel vuln is most likely by far imo. Chromium uses probably the single most advanced sandbox out ther
465.
▲
by
staticassertion
7mo ago
I'd bet that the sandbox escape is just in the underlying operating system kernel and therefor isn't a matter for Chromium to issue a CVE.
466.
▲
by
staticassertion
7mo ago
All mainstream package managers are built with zero forethought into security, as far as I can tell. I don't think any of them are any good at it at all, otherwise they wouldn't give arbitrary code execution with literally zero re
467.
▲
by
staticassertion
7mo ago
Nothing eliminates the risk but it is basically a best-in-class solution. If your primary concern is supply chain risk, there you go, best in class defense against it. If anything, what are you doing about supply chain for the existing code
468.
▲
by
staticassertion
7mo ago
> Don't we have a bunch of tools that should create memory-safish binaries by applying the same validation checks that memory-safe languages get for free purely from their design? No, we don't. All of the ones we have are heavi
469.
▲
by
staticassertion
7mo ago
Google already uses `cargo-vet` for rust dependencies.
470.
▲
by
staticassertion
7mo ago
I listen to multi-hour unsponsored content on Youtube almost exclusively.
471.
▲
by
staticassertion
7mo ago
Okay, well, they produce outputs that appear to be deceptive upon review. Who cares about the distinction in this context? The point is that your expectations of the model to produce some outputs in some way based on previous experiences wi
472.
▲
by
staticassertion
7mo ago
The "snark" of opening the PR vs the "snark" of people dox'ing the guy who opened it.
473.
▲
by
staticassertion
7mo ago
If something makes you 10x as effective and then you improve that thing by 4%...
474.
▲
by
staticassertion
7mo ago
But that is true of all sample sizes
475.
▲
by
staticassertion
7mo ago
Perhaps too meta or off topic but I thought it was funny that you thought their n was low and then cited a story about one person.
476.
▲
by
staticassertion
7mo ago
I feel like what you're saying is compatible. I'm not suggesting that things aren't top down or that you wouldn't have brand guidelines, that's actually exactly what I'm suggesting. I just mean that there is or
477.
▲
by
staticassertion
7mo ago
Marketing teams are constantly out of touch with the message they want to convey vs the message that gets conveyed. The creative team is usually not even talking to the other teams that would drive decisions like this - they almost exclusiv
478.
▲
by
staticassertion
7mo ago
I just want to clarify how extremely standard and often required it is to download and store your SOC2s and other such documents when going through compliance. You almost never can actually just link to a public pentest report or SOC2 etc
479.
▲
by
staticassertion
7mo ago
I really couldn't have been clearer. The implication was that Zed made a decision because of pressure from a VC. I said that they were vastly overestimating the pressure a VC can exert on an early stage company. You've then pointe
480.
▲
by
staticassertion
7mo ago
Oh, I sort of wondered if that was the case but I was really unsure based on the wording. Yeah, I have no idea.
More ›