

We have all evaluated the options. Most of us decided that sewing was in fact too extreme.


We have all evaluated the options. Most of us decided that sewing was in fact too extreme.


Not just the first hit in general but this also sounds likely to be a bait-and-switch. They will roll with that free 1TiB as long as they can for marketing and market capture. They have a few profit streams (ads, whales on bigger plans) to help cover those marketing costs. But most likely they will not be profitable and eventually will reduce/remove the free plan and try to upgrade as many users as possible to the paid plan (reducing costs and increasing revenue in one go).


Please explain what you mean and how this could be abused. What does “real” mean in this context? They both have the same code. It would probably help if you can provide a specific attack that could actually cause harm rather than just stating facts that have unclear risk.


It doesn’t mutate history. It just creates a new branch of history in their own fork. Just like any new commit would do.


I don’t understand. Why does having two commit IDs with the exact same code cause problems.
A green “Verified” badge on GitHub is supposed to mean that a trusted author signed it
The author did sign it. It is the exact same code.
An attacker can reissue the same signed code under a fresh ID that’s still verified to slip past.
To split past what? At best it seems that they would be able to have a different ID for the exact same code, which seems harmless? Slightly confusing at worst.
Nix also doesn’t use PGP signatures, it requires a separate hash of the resulting commit (the files with the .git directory stripped by default).


I’m a little confused by what this is saying. It seems that you can create a basically identical commit with a different signature and thus a different (hashed) ID.
So basically you can take a Signature S1 and produce a valid Signature S2 over the same data that is not identical.
This doesn’t seem like a very useful exploit primitive to me. Not nothing, but doesn’t seem like a big deal. I feel like I am misunderstanding something.


Yeah, carbon capture doesn’t math. I think the saying is that an ounce of prevention is worth a pound of cure.
The only reason why it is promoted is because the fossil fuel cartels push it as it moves the blame and focus from them to someone else’s problem. Then a bunch of garbage “carbon credit” companies start up and make a lot of noise while doing basically nothing. All the while they can keep pushing for fossil fuel projects because “it’s fine, carbon capture will solve it”.


Generally speaking it will be fine. SSH will also refuse keys with open permissions so you would notice if it was wide-open to other users of the device.
But you know if you are running random code or AI harnesses as that user it can be at risk. Or if you copy around the key all over the place it is more likely to leak. But generally speaking you are secure by default, just don’t do something dumb with the key and you’ll have no problems.


It sounds pretty reasonable. As long as you keep SSH patched and keep the key safe it should be quite locked down. Do double-check that password login isn’t allowed (or that all users have a very strong password).
One non-security note is be careful with rsync backup. Generally rsync isn’t considered a backup as any mistakes made in the source will be propagated to the “backup” on next sync. Although there are ways to use rsync to take good backups (like copying to a new directory for each backup).
Wow, the quality of that official video really looks like “maybe you just don’t care”. Why is all of the text weirdly pixelated, often not aligning to the lines and they couldn’t even bother to make it actually stroke out, just left to right wipe.


Why only streaming services? Why not target the volume of any ads within content that contains audio? While we are at it why not say that the add can’t be significantly more bright?


CSS != HTML
I don’t think there is any way to play audio from CSS.
But I mean it is open source, you could patch it to do whatever you want.
I built Chibichange to have a way to conveniently deliver changelogs to Dawarich users
Have you considered just posting a changelog to your blog? That would be much more convenient than every app I run pinging me in its own way by phoning home to its server.
It does say “I agree to pay the above total amount” so it is pretty clear.
Yes, on one hand every commit to nixpkgs needs review (to some degree) on the other hand there are far too many committers to nixpkgs.
There are also gaps such as the bots to auto-merge packages with maintainer approval, so a simple attack looks like this:
So nixpkgs is better than the AUR, but it isn’t great and unlike Arch has no separate official repos.


https://xkcd.com/1200/ comes to mind.
Games have no sandboxing anyways. They can access most of the data on the systems on which they run. Whether the game, crack or a HV crack makes little difference.
Sure, running a hypervisor or kernel level does allow them a bit more access, mostly around persistence. But I don’t think it is a huge difference to most people.
So IMHO you are already putting a lot of trust in any pirated software or crack, hypervisor bypasses are really just a small matter of degree. If you don’t trust the crack don’t run it. Easy as that. Or if you want robust protection run games on dedicated hardware with no personal information or in a dedicated untrusted gaming VM.
Because every three letter acronym means more than one thing. There are only 17 576 TLA so they are going to be heavily duplicated.
You should almost always spell out acronyms on the first use.
My wife’s last name was Wang. She was planning on taking her husband’s last name her whole life. Joke’s on her.
It’s not really though. They just used the screen from the pregnancy test and replaced all of the other hardware.
This advice feels like “Have you moved to the surface of the sun? Make sure to drink lots of water.” It’s not wrong, but also not particularly helpful. The only solution is to stop buying these things. Ideally take them back and get a refund if it isn’t too late.