Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
staticassertion
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
91.
▲
by
staticassertion
5mo ago
That seems literally borderline impossible.
92.
▲
by
staticassertion
5mo ago
https://duckduckgo.com/?q=LPE+security&ia=web wow
93.
▲
by
staticassertion
5mo ago
It was already known to attackers (or basically anyone watching) weeks ago when the patch hit the kernel but it wasn't communicated by upstream as a vuln (because Linus and Greg do not believe that vulnerabilities are conceptually rele
94.
▲
by
staticassertion
5mo ago
It's multi-faceted. Docs is part of it, but also, no one cares about security and they won't do literally anything to improve security if there's a papercut. Right now if I want to render untrusted content and if I use React
95.
▲
by
staticassertion
5mo ago
iframe sandboxing is wildly underleveraged. I think it's because it doesn't work well with "modern" app development - you need the ability to slice bits and pieces out yourself. I've been just using plain typescript
96.
▲
by
staticassertion
5mo ago
Typically you do things like this to either work in restricted envs (distroless) or to evade detection logic. It's not about bypassing a boundary, it's about getting things done in the env you have available.
97.
▲
by
staticassertion
5mo ago
I've had to remove any of the "knowledge" about me from any agent I use. "As a security engineer, blah blah blah" or "as a rust developer blah blah blah" even though my questions has nothing to do with tho
98.
▲
by
staticassertion
5mo ago
In my experience, you can tell them "Don't stop working on this until complete" and they'll go for an hour or more.
99.
▲
by
staticassertion
5mo ago
No it isn't. Confidentiality terms are the norm.
100.
▲
by
staticassertion
5mo ago
That's pretty much how every bounty works... obviously it's going to be at their discretion for an incomplete attempt.
101.
▲
by
staticassertion
5mo ago
This assumes that the tokens it outputs are a good description of the tool's behavior. That's not necessarily true though. For example, the LLM may be trained such that a lot of its input data is "LLMs often hallucinate"
102.
▲
by
staticassertion
5mo ago
I don't think there's a right answer, you need to sit down and try to think about these problems upfront. What will scaling look like? What decisions will you regret? Make the guesses you can, but don't ignore scale or perfor
103.
▲
by
staticassertion
5mo ago
Nix wraps your process in namespaces and seccomp?
104.
▲
by
staticassertion
5mo ago
There's one extra process that takes up a tiny bit of CPU and memory. For that, you get an immutable host, simple configuration, a minimal SBOM, a distributable set of your dependencies, x-platform for dev, etc.
105.
▲
by
staticassertion
5mo ago
This is why there's an endless cycle of shitty SaaS with slow APIs and high downtime. People keep thinking that scale is something you can just add later.
106.
▲
by
staticassertion
5mo ago
I'm not taking a side on whether a product should add telemetry. I'm rejecting the absurd notion that these suggestions are at all giving the same information.
107.
▲
by
staticassertion
5mo ago
Okay?
108.
▲
by
staticassertion
5mo ago
> On hardened targets and Firecracker specifically, here's a recent vulnerability found by "Anthropic": https://aws.amazon.com/security/security-bulletins/2026-015- ... Yep. It's notable that
109.
▲
by
staticassertion
5mo ago
You can set up a user forum if you'd like. If you think it will get you the same information that analytics will, you're obviously wrong.
110.
▲
by
staticassertion
5mo ago
Not really. (a) People hate responding to surveys and hate emails, you're more likely to lose users than to get data (b) there's no way you're surveying people's in a way that gets you information like "time spent
111.
▲
by
staticassertion
5mo ago
It's sort of hilarious to compare "talking to people" with analytics. I'm not defending Github here, but you can't possibly think that "talking to 1M customers" is viable.
112.
▲
by
staticassertion
5mo ago
I'm not sure I understand your question but I'll try to answer as best I can - also keep in mind that this is simply one view. The structure of the brain encodes information based on experience in the same way that the force of gr
113.
▲
by
staticassertion
5mo ago
So, my perspective on this is that the blog post doesn't motivate me very much. First of all, the constant framing around Mythos as being capable of tackling "hardened" targets is invalid to me. Or it heavily depends on what
114.
▲
by
staticassertion
5mo ago
> so the domain in which you can beat their performance Not in my experience.
115.
▲
by
staticassertion
5mo ago
They can't maintain the code so they are no longer going to maintain the code.
116.
▲
by
staticassertion
5mo ago
There are things that happen in the world that are external to us. We observe those things, and that observation is what I'm calling an experience. We can say things about the experience, but those words are not the experience. As to w
117.
▲
by
staticassertion
5mo ago
I really appreciate the links, this'll give me a lot to read about.
118.
▲
by
staticassertion
5mo ago
Sentences only have semantic meaning because you have experiences that they map to. The LLM isn't training on the experiences, just the characters. At least, that seems about right to me.
119.
▲
by
staticassertion
5mo ago
Is there any reason to believe that Grover's is as good as it gets? I'm on board here, and I think the article caveats that it's a matter of cost, priority, and assumptions. Cool, cool, I'm already using xaes-256-gcm. Bu
120.
▲
by
staticassertion
5mo ago
It's very typical to have a retainer / insurance to bring in "emergency" incident responders beyond your existing team. Not saying that's the case here but it wouldn't be surprising.
More ›