Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
winstonwinston
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
winstonwinston
4d ago
Why makes no sense at all unless you are very naive trusting they would not jump straight to the endgame if it was possible with the technology available.
2.
▲
by
winstonwinston
5d ago
The sane way for encryption keys stored in hardware (secure enclave or tpm like) is to onboard user when the key is not derived from user password. Just like they do for FDE to export a recovery key and then you can adjust your expectations
3.
▲
by
winstonwinston
5d ago
But that’s not backup restore? I’m thinking Time Machine restore on a new Mac when old one is no longer working. Or when the old one had to be wiped and restored.
4.
▲
by
winstonwinston
5d ago
Maybe but this is unexpected if you need to restore from a backup..
5.
▲
by
winstonwinston
5d ago
Basically you add more radiators to keep water temperature low or you add a backup heating source such as typical electric water boiler that will be used only during very cold days to increase water temperature when heat pump cannot keep up
6.
▲
by
winstonwinston
6d ago
CERN wants x86-64-v1 binaries, not v2.
7.
▲
by
winstonwinston
6d ago
Alma and Rocky both require x86-64-v2 CPU as a minimum (same as RHEL 9). CERN want baseline x86-64-v1 which Debian provides.
8.
▲
by
winstonwinston
7d ago
Don’t they openly state that their product may cause IP issues but that is fine because they will take care of your legal problems caused by their product? In the end, it’s not them stealing, it’s the AI doing stealing. What kind of moral c
9.
▲
by
winstonwinston
7d ago
There is a common anti-pattern for heat pumps being installed in large houses. They are almost always more powerful than needed, just to be safe it will be enough, better safe than sorry. But overpowered heat pump will use significantly mor
10.
▲
by
winstonwinston
12d ago
> I prefer to run my own local recursive resolver. Used to be fine. I stopped doing it when average TTL dropped to 300 seconds and it takes far too long for my local recursor to get the answer >100ms, when 3rd party resolver delivers
11.
▲
by
winstonwinston
12d ago
When I run a mix of CF and Quad9 resolvers, Quad9 was consistently slower in response times when measured. But it didn’t make any perceivable difference in real usage.
12.
▲
by
winstonwinston
12d ago
A “swarm” and “hijacked” reads like DoS and spam at the very least, doubt any of those is legal in german law.
13.
▲
by
winstonwinston
13d ago
If they wanted air gapped environment they would’ve it. I mean, if you want to sabotage your trial by hard constraints you can do it, or you do not do it to see interesting results. They even said it that some constraints were disabled for
14.
▲
by
winstonwinston
13d ago
No memory ever wasted, consumes all of it. But this does not seem to be the case anymore. Today I see that eclipse IDE is more memory friendly than Chrome.
15.
▲
by
winstonwinston
15d ago
I can say that I have used pip only and it does a package manager job well, it just works. I’m not sure at what uv excel at but reading comments it seems uv is not only package manager but also venv manager.
16.
▲
by
winstonwinston
15d ago
Do these free HE assigned IPv6 prefix(es) just remain valid indefinitely even when not actually being used/routed?
17.
▲
by
winstonwinston
18d ago
What a fucked up reality when you need to point out that code contributor is responsible for their code.
18.
▲
by
winstonwinston
20d ago
Google has been sending some similar alerts long before Apple, those read something like "Government-backed attackers may be trying to steal your password".
19.
▲
by
winstonwinston
20d ago
`Cryptography` is not a Python stdlib: try: from cryptography import x509 from cryptography.hazmat.primitives import hashes from cryptography.x509.oid import NameOID except ImportError: # pragma: no cover sys.exit(&qu
20.
▲
by
winstonwinston
21d ago
I have no idea what you mean. It is no surprise that known unpatched CVEs will be exploited. Perhaps more effort should be put into shipping fixes faster than writing blogs about exploiting known issues.
21.
▲
by
winstonwinston
24d ago
You could just run multiple rsync processes using different src and dest paths to achieve multiple copy streams. Anyway this would not be likely much faster if rsync is run over encrypted SSH due to CPU performance, compared to unencrypted
22.
▲
by
winstonwinston
25d ago
Well, when I go look at the “victim repository”, to me that looks like manufactured persona with pointless vibe codes projects, a test playground so to speak. It does not appear that they actually let it target an actual persona/projec
23.
▲
by
winstonwinston
26d ago
Blog post is displayed for a moment and shortly after the post text is replaced with a cryptic error about regex parsing. I guess it has something to do with Safari javascript engine. Anyway, the current state of web development is so pathe
24.
▲
by
winstonwinston
27d ago
It would loose automagic? In a recent full discloure I was reading about a CVE of an LLM agent, the vendor installed a “secure sandbox VM” and then just shared a host’s filesystem read/write to the agent’s VM.
25.
▲
by
winstonwinston
1mo ago
> after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository. Unencrypted signing key. They just don’t care anymore.
26.
▲
by
winstonwinston
1mo ago
> It may be that the 662 MB used by the "Renderer" is shared between many Windows components, so killing that Weather app may not reclaim as much space as you may hope, instead, it would require killing every user of the compon
27.
▲
by
winstonwinston
1mo ago
You can’t be upset because they want to know the truth, seriously. When a project has concerns about generated code, it is for a reason.
28.
▲
by
winstonwinston
2mo ago
> I think we all know the answer to this: bad incentives. Better technology, worse food quality, more profit.
29.
▲
by
winstonwinston
2mo ago
The blog post is painfully vague. What usually happens when you publish a package on PyPI is that it will be downloaded tens of times shortly after uploading files by some 3rd-party automatic security scanners which then could “detonate” (i
30.
▲
by
winstonwinston
2mo ago
It’s the OneDrive installing new OneDrive Photos app. It happens on any Windows version, such as Server 2025 that has OneDrive installed. It isn’t limited to Windows 11.
More ›