HNHacker News
TopNewBestAskShowJobs

0zymandiass

191 karma · joined October 12, 2019

submissionscomments
0zymandiass··on Android 16 QPR1 is being pushed to the Android Open Source Project
I believe QPR includes security fixes as well, which should trigger the 4 month timer

Your comment seemed to imply that a source release would trigger a different timer than a binary release, which is explicitly covered as the same thing in the law - for both the 4 and 6 month timers.

0zymandiass··on Android 16 QPR1 is being pushed to the Android Open Source Project
You've explicitly quoted that source releases are not relevant:

> or, if the source code is not publicly released, after an update of the same operating system is released by the operating system provider

They have not released the source code, but they have released an update of their operating system on their reference Pixel hardware.

Therefore, all devices must update within 4 months of that Pixel release, regardless of source drops, per this law

0zymandiass··on Fedora change aims for 99% package reproducibility
If you'd bothered to read:

```This definition excludes signatures and some metadata and focuses solely on the payload of packaged files in a given RPM:

    A build is reproducible if given the same source code, build environment and build instructions, and metadata from the build artifacts, any party can recreate copies of the artifacts that are identical except for the signatures and parts of metadata.```
0zymandiass··on Infinite Git repos on Cloudflare workers
A branch doesn't use any more space than a commit... I'm curious what their complaint was with a large number of branches?

There are various repositories with 500k+ commits

0zymandiass··on LibreOffice 7.2 Community is strong on interoperability
Ironically, Microsoft Office also fails to render most of my ODP/ODT files correctly, which are open standards. One might infer it's by design...
0zymandiass··on Scalability, but at What Cost [pdf]
Reminds me of https://adamdrake.com/command-line-tools-can-be-235x-faster-...

Cluster computing can be useful, but until you're talking about petabytes of data, it probably isn't helping you

0zymandiass··on Hacking the Git Shell Prompt
It's far less interesting than finding an exploit in git-shell, which was how I read the headline :|
0zymandiass··on What If OpenDocument Used SQLite? (2014)
I'm sure they aren't perfect, but their test suite and extensive fuzz testing is far better than any XML or JSON parser I've ever seen

https://www.sqlite.org/testing.html

0zymandiass··on Let's talk about safety of Pinephone
If the conversation is

> Software engineering does not put safety first

I'm 100% agreed.

If the conversation is

> The PinePhone has less quality control than Android/iOS

It's patently false

I would parse the article as the second, as it's referring to a specific phone throughout

0zymandiass··on Let's talk about safety of Pinephone
The issue is they're heavily implying it's something specific to PinePhone. I just scrolled through the legal notices on an iPhone, and they all have the exact same wording. Small components, such as the graphics libraries, the kernel, health data, the web browser, etc...

(not to mention they're just plain wrong about the battery/thermal not having hardware-level limits)

0zymandiass··on AMD PSB Vendor Locks EPYC CPUs for Enhanced Security at a Cost
Ah. Yeah.

The motherboard just loads BIOS/UEFI into a predefined memory address and then starts the CPU

This is a pretty good explanation https://manybutfinite.com/post/how-computers-boot-up/

> In a multi-processor or multi-core system one CPU is dynamically chosen to be the bootstrap processor (BSP) that runs all of the BIOS and kernel initialization code

These days, the "bootstrap processor" is a separate core that your OS can't see. On Intel it's the IME (running Minix) and on AMD it's the PSP (ARM TrustZone)

0zymandiass··on AMD PSB Vendor Locks EPYC CPUs for Enhanced Security at a Cost
The CPU isn't what's compromised - this is protecting against a compromised motherboard
0zymandiass··on AMD PSB Vendor Locks EPYC CPUs for Enhanced Security at a Cost
There have been a couple in the wild, but they aren't super common.

They've become a bigger concern with UEFI since it has a massive attack surface compared to legacy BIOS.

For a processor sitting in AWS / Azure, they want guarantees, and they're the ones EPYCs are designed for.

The responsibility has to rest with the processor, since it's the only thing executing code prior to UEFI. What it's doing is validating that UEFI was cryptographically signed with the correct key prior to running any UEFI code. When it's first used, it is saving the key for the vendors UEFI implementation and won't allow it to proceed if the root signature ever changes (think something similar to root certs for HTTPS).

It's only relevant to Secure Encrypted Virtualization insofar as they are both implemented inside the PSP which is a separate ARM core that runs at a higher privilege level than the x86 cores (and is the core that actually initializes the x86 cores).

This is how all phones have worked for many years, but apparently it's now becoming a thing in servers too.

0zymandiass··on AMD PSB Vendor Locks EPYC CPUs for Enhanced Security at a Cost
BIOS (UEFI) level rootkits
0zymandiass··on AMD PSB Vendor Locks EPYC CPUs for Enhanced Security at a Cost
It's not necessarily just Dell, they're just the first to use the feature.

It also won't necessarily work in other Dell motherboards, just ones using the same key as the first.

It's strange Dell would blow the fuses by default, though.

0zymandiass··on Because of high unemployment benefits, businesses can't find summer workers
Fixed Headline:

Businesses don't have enough need for summer workers to pay them

0zymandiass··on Because of high unemployment benefits, businesses can't find summer workers
Not really.

If you had ubi, then you could still take those jobs for additional income for hobbies, travel, etc.

As it is right now, you're losing money by taking these jobs.

0zymandiass··on Siri, What Time Is It in London?
I don't know if it works there, but siri couldn't understand one of my contacts names

When it read back super incorrectly from an alias, I said something to the effect of "could you pronounce that correctly?" and it asked me to say it

Since then, it's understood that person's name. ¯\_(ツ)_/¯

It really needs to expose the option to train those easily

0zymandiass··on Systemd, ten years later: a historical and technical retrospective
It's dramatically simpler and more intuitive than what it replaced, so I'm super excited when someone comes up with something even better!
0zymandiass··on Apple Just Gave Millions Of Users A Reason To Quit Their iPhones
From the article, yes:

> I spoke with Verizon about the usage. They said it's getting categorized as audio and video streaming, but only because it's using network ports normally associated with those types of services.

0zymandiass··on Don't touch my clipboard
You're getting far enough into JS knowledge that I don't have.

Do you actually need clipboard events, or just dom.event.contextmenu.enabled for that?

0zymandiass··on Don't touch my clipboard
I don't suppose you've open sourced that somewhere?

My work has switched to iPhones, and I really miss NoScript when using Safari

0zymandiass··on Don't touch my clipboard
I can highlight and ctrl+c without issue in their Writer clone. Never tried any others.

I've only ever seen that setting fix sites that try to prevent you from copying.

0zymandiass··on Don't touch my clipboard
about:config -> dom.event.clipboardevents.enabled = false

You can't do it through a user agent, though

0zymandiass··on Divesting AdSense might help Google stave off worse regulatory action
I'm sure it's a large expense. However, they make more money from the data and market share they get from it.

Why else would they keep moving things out of AOSP and into their proprietary frameworks?

Same for Linux itself - however in that case, there isn't incentive to make it proprietary, because the companies are either making money from hardware sales or from support contracts.

0zymandiass··on My Favourite Git Commit
To me, at least, the issue with that commit message is the signal-to-noise ratio. There is a lot of exposition for each piece of information. I prefer a more declarative commit message. However, from the writing, I suspect this is just due to the committer not being a native English speaker.

e.g. the first paragraph doesn't lose any important information trimming it down to:

"After adding a test matching the contents of router_routes.conf, `bundle exec rake` fails with:

    ArgumentError:
        invalid byte sequence in US-ASCII
"

Realistically, it would have been a better commit message if they'd given the shortlog SHA where the test was added that exposed the bug rather than an explanation of what the test does.

"After adding test <testname> (08c3e17), `bundle exec rake` fails with:"

0zymandiass··on Amazon stops charitable donations via Amazon Smile if you turn off notifications
They don't want to support charities. They want to get people that want that to spend more money with them. They did the math, and the number of people that will say "no" to that permission is significantly smaller than the amount of money they make from forcing that permission in order to get them to give their scraps to charities.