HNHacker News
TopNewBestAskShowJobs

AtNightWeCode

457 karma · joined March 29, 2021

At a dark place
submissionscomments
AtNightWeCode··on XZ backdoor story – Initial analysis
Difficult but not impossible. Some of the malware and ransomeware stuff is also created by experts.
AtNightWeCode··on XZ backdoor story – Initial analysis
I think it is a professional attempt. It does not have to be a goverment. There are other cyber criminals.
AtNightWeCode··on Spotify demonetizes all tracks under 1k streams
No small artists cares about this at all. Grow up.
AtNightWeCode··on Spotify demonetizes all tracks under 1k streams
The 1k streams limit will probably only financially effect "artists" that spams the platform with new tracks. It is not like it will make any difference for real artists.
AtNightWeCode··on Reflections on Distrusting xz
The history. Every time something like this attack happens people think they can read the complete git history in the repo.
AtNightWeCode··on Reflections on Distrusting xz
People think git is immutable. It is not.
AtNightWeCode··on Xzbot: Notes, honeypot, and exploit demo for the xz backdoor
My guess is that a ransomware group is behind this. Even if the backdoor had gone into production servers it would have been found fairly quickly if used at some scale.
AtNightWeCode··on Xz: A microcosm of the interactions in open source projects
Humans can always be compromised. This specific case can only be solved by improved tooling, workflows, visibility, runtime environments and so on.
AtNightWeCode··on Type Inference Was a Mistake
Maybe write the types in the actual files and let the editors optimize it away instead of having it as a language feature. I don't want to see or write all the types in my daily work but when reviewing other peoples code I would like to have them.
AtNightWeCode··on Backdoor in upstream xz/liblzma leading to SSH server compromise
Maybe one can get the code from here. New commits being added it seems.

https://git.tukaani.org/

AtNightWeCode··on Someone has been attempting to DDoS us for weeks and we do nothing
Those numbers in the screenshot from Cloudflare represents requests to Cloudflare, not requests to the origin. It includes cache hits.
AtNightWeCode··on The race to replace Redis
I was of course talking about a managed service. And the problem with deleting data exists in several Azure producs like Cosmos DB, Table storage, App Insights and so on.
AtNightWeCode··on The race to replace Redis
It should be a simple task to add that command and it is widely used. It sounds more like a business decision to not add it. It is not unusual that cloud providers make it difficult to delete data for various reasons.
AtNightWeCode··on The race to replace Redis
To not support the FLUSHALL command suggests that Azure is the goal with the project.
AtNightWeCode··on Recent 'MFA Bombing' Attacks Targeting Apple Users
Rate limiting per user is mostly a thing of the past. You set other rate limits and various rules and then get the rate limit per user for free.
AtNightWeCode··on ZenHammer: Rowhammer attacks on AMD Zen-based platforms
Some of these exploits can be used in a browser. They leave no trace. So it is hard to tell how much these exploits have been used in the past and how likely a wider attack will happen in the future.

Some of these exploits have been used in targeted attacks towards end users so the risk is not 0.

AtNightWeCode··on Regex character "$" doesn't mean "end-of-string"
There are many differences between implementations of regex. To name a few. Lookbehind, atomic groups, named capturing groups, recursion, timeouts and my favorite interop problem, unicode.
AtNightWeCode··on Regex character "$" doesn't mean "end-of-string"
I fail to add carriage return to the test string on that site. Which I guess would be an issue on Windows.
AtNightWeCode··on Inside the Massive Alleged AT&T Data Breach
I have not really thought this through but maybe there could be a forced requirement to add a watermark to the data when storing sensitive PII.

Hackers could then use the watermark to prove the authenticity of the data and users could use it to check if their data have been breached.

AtNightWeCode··on On clock faces, 4 is Expressed as IIII, not IV
My guess is that IIII was used before IV in various cases. So maybe a mistake or to reduce confusion.
AtNightWeCode··on Swedish data brokers claim journalists' legal protection to evade EU law
A thing not mentioned in the article is that most of the example data is also available directly from the authorities. Not as easily accessed perhaps. However, these services also keep data not available like old convictions. There are other lawsuits regarding that.
AtNightWeCode··on Maybe Functions
So what I meant is that you see the exact same maybe pattern in many projects but instead of returning null there is a guard that throws an exception. I agree with the solution.
AtNightWeCode··on Maybe Functions
I am for exceptions but it should not be used for basic control flow. Many techs will treat all exceptions as errors.
AtNightWeCode··on A simple dice game shines a bit of light on the psychology of regret
People think they are being tricked is my guess. But also in general, people like to stick to what they have committed to. I think this has more to do with culture than regret.
AtNightWeCode··on Meta outage
SSO in Cloudflare also seems to have problems.
AtNightWeCode··on Ask HN: How can I learn about performance optimization?
The difficult thing is to benchmark the software correctly and evaluate the impact of a change. Most of the examples on the Internet are useless micro-optimizations. I evaluated a program some time ago that did several speed tricks. But the reason it was slow was because it reread a file on each iteration in a loop.
AtNightWeCode··on Netlify just sent me a $104k bill for a simple static site
Workers run before the cache so I would avoid this for static sites. One can use workers for dynamic routes on a static site though.
AtNightWeCode··on Netlify just sent me a $104k bill for a simple static site
You typically can't replace Netlify with Cloudflare. You need something like Github actions with some storage, S3 or something and then one can put Cloudflare in front of it all for caching, DDOS protection and so on.
AtNightWeCode··on Institutions try to preserve the problem to which they are the solution
Something I have noticed along the same line is that the importance of actions within a company is mapped from the work roles people have, not from the work to be done.
AtNightWeCode··on Almost every infrastructure decision I endorse or regret
In your case it sounds more viable to move to VMs instead of RDS, which some cloud providers also recommend.
← PreviousPage 8 of 34Next →