Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
usrbinbash
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
181.
▲
by
usrbinbash
2y ago
> Likewise, there was a time when server side website code had to be invoked via a httpd plugin or CGI, now every programming language will have several different web frameworks, each with their own HTTP listener and each needing to be c
182.
▲
by
usrbinbash
2y ago
> Also adding firewalling to SSH is hardly “kitchen sinking” sshd is a service. It may be one among dozens of other services running on a host. Now imagine for a moment, if EVERY service on the host took that approach. Every backend se
183.
▲
by
usrbinbash
2y ago
> but fail2ban is kind of a hacky pos. It's battle-tested for well over a decade, has accumulated 10.8k stars and 1.2k forks on github, so it seems to do something right no? Not to mention that even if it were otherwise, that's
184.
▲
by
usrbinbash
2y ago
Impatient about what exactly? fail2ban is battle tested for well over a decade. It is also an active project with regular updates: https://github.com/fail2ban/fail2ban/commits/master/
185.
▲
by
usrbinbash
2y ago
> There’s so many ways that can go wrong There are a lot of ways a builtin facility of one service can go wrong, especially if it ends up being active by default on a distro. `fail2ban` is common, well known, battle-tested. And its also
186.
▲
by
usrbinbash
2y ago
> what do you if you get mugged and you laptop and phone and keys are taken or stolen from you? or lost? My ssh keys are encrypted. They need a password, or they are worthless. Sure, I can mistype that password as well, but doing so has
187.
▲
by
usrbinbash
2y ago
> why should I install two separate pieces of software to handle the problem https://alanj.medium.com/do-one-thing-and-do-it-well-a-unix-...
188.
▲
by
usrbinbash
2y ago
How is baking this into sshd "better"? UNIX Philosophy: "Do one thing, and do it well". An encrypted remote shell protocol server should not be responsible for fending off attackers. That's the job of IDS and IPS da
189.
▲
by
usrbinbash
2y ago
I can, and am, using a locally running LLM with RAG on my personal wiki already. The difference between that and Recall: I decide what goes into the wiki.
190.
▲
by
usrbinbash
2y ago
> Why is MS pushing something so hard when nobody asked for it? Because they bet big on AI, and hardware suppliers bet big on AI-enabled hardware, and so they are trying to find use cases for it.
191.
▲
by
usrbinbash
2y ago
1. Browsing history doesn't show what the user is doing on the page. There is a big difference between logging "user visited his e-banking app", and logging his actual credentials as they are entered. 2. Browsing history watc
192.
▲
by
usrbinbash
2y ago
> So instead of looking, like the author of these new options, for ways to make life for the bad guys harder we do nothing? The thing is, we have tools to implement this without changing sshd's behavior. `fail2ban` et. al. exist for
193.
▲
by
usrbinbash
2y ago
> The security concerns apply regardless of Recall existing. Not quite. Because there is a world of difference between an attacker being able to grab information that is being entered or temporarily present, or permanently present and en
194.
▲
by
usrbinbash
2y ago
The problem is: As soon as a synthetic key is used by an EXTERNAL system, it stops being synthetic; for all intents and purposes it is now an integral part of the record, because if you change it, the external system may not be able to fi
195.
▲
by
usrbinbash
2y ago
> To what degree do they "influence" an election in our "reality"? - https://www.npr.org/2019/04/24/716374421/fact-check-russian-... - https://www.axios.com/2021&#x
196.
▲
by
usrbinbash
2y ago
> but what about crap daily newspapers that came in mass around 1900, then radio, then over-air television, then cable television? a) None of these were, first algorithmically, and then using machine learning, optimized to constantly gra
197.
▲
by
usrbinbash
2y ago
> I dream of a system that automatically captures and allows me to interact with and query against everything I do Well, I don't. For starters, because not everything I do generates relevant information for me. All those hours spent
198.
▲
by
usrbinbash
2y ago
Excuse me, when did password managers collect information about everything their users do on a massive scale?
199.
▲
by
usrbinbash
2y ago
> As Smith would say, "it's inevitable". To which I reply: sudo rm -rf /agents && echo "the only windows here are made of glass"
200.
▲
by
usrbinbash
2y ago
> But honestly, if somebody has this kind of access to your computer, they have access to your entire life anyway. Exactly. So please tell me why I would want to essentially allow something like this on my machine? As for the scifi-esque
201.
▲
by
usrbinbash
2y ago
> Your blog isn't a diary A blog is exactly what the one who writes it wants it to be.
202.
▲
by
usrbinbash
2y ago
> and revoke API keys sent over the unencrypted connection. Excuse me, short question: If I am not offering a non-TLS endpoint in the first place, and the client, for some reason, decides to take something that is literally called "
203.
▲
by
usrbinbash
2y ago
> Sodium ion batteries are mass produced at a comparable scale today Since we were talking about economic viability: "The global Lithium-ion Battery Market in terms of revenue was estimated to be worth $56.8 billion in 2023 and is
204.
▲
by
usrbinbash
2y ago
> Sodium ion batteries are doing just fine. Again, this discussion is about the as-is situation. If and when Na-ion enters mass production on a comparable scale, I will happily discuss it. > Negative energy prices at peak generation t
205.
▲
by
usrbinbash
2y ago
> Mining rates are growing quickly. https://www.weforum.org/agenda/2022/07/electric-vehicles-wor... > there are competing materials for new battery tech besides lithium And which of those are mass-produ
206.
▲
by
usrbinbash
2y ago
> But you can’t just turn a nuclear reactor on and off No, but I can regulate its output up and down. You don't have to turn a reactor off entirely, its output can be regulated up and down without shutting down completely. > and
207.
▲
by
usrbinbash
2y ago
> but I reckon as VR-wear becomes less clunky, stuff like this will be really useful. The thing is, I can already get a really good overview of the interior of the plane I'm gonna fly on, based on the actual textures and natural lig
208.
▲
by
usrbinbash
2y ago
And the point of this is...what exactly? That I can see the interior of a planes seating area? I can do that with a 5 second youtube search. And I can do it on my phone, without requiring any VR hardware.
209.
▲
by
usrbinbash
2y ago
And? Solar cannot do it, it's as simple as that, so the cost is irrelevant. > becoming exponentially cheaper "Exponentially" is very unlikely. It may become somewhat cheaper, at first, if supply increases. Which btw. is al
210.
▲
by
usrbinbash
2y ago
Pray tell, what is "unrealistic" about nuclear energy as an alternative? There are only 436 nuclear reactors in the world (for comparisons sake, there are more than 2400 coal power plants worldwide, and the US alone have more than
More ›