1,151 karma · joined September 28, 2020
Science is, and has always been, about adjusting our flawed, incomplete models as new evidence emerge. We shouldn't let our ill-informed preconceptions prevent humanity from moving forward.
If removing blood from the body takes forever chemicals with it and we have no practical way of filtering those chemicals out, then discarding the blood (yes, bloodletting) is the moral way to do it. Irrational and uneducated biases need not apply.
What's wrong with that? Git hooks are inherently dangerous (i.e. running arbitrary code) and should be something you opt into manually.
Besides, now that this security issue is patched, git devs should seek a proper solution to that doesn't break git and decrease security for everyone else.
Honestly, people haven't learned a single thing from Window's autorun days.
Wouldn't untrusted git hooks mean that git verify-* are useless since you're already running untrusted code?
I think this is a big mistake. Build environments use separate users for security purposes. It's insane to decrease security for everyone by requiring a single user to do everything because some of your users want to have fancy terminal prompts.
At the very least, let users configure this at a per-user level.
I think the only reason Google and their friends are doing this is to remain in control (how, when, if). They don't want to end up like the car industry.
I hope regulators don't fall for this trap.
Correction: NPM packages are routinely hacked.
I've been using linux packages for two decades, and not once have they been hacked (to my knowledge). I consider those packages to be infinity more secure than proprietary packages where I and others can't check what's running under the hood.
OSS being safe and secure is one of the primary reasons why I prefer open source to closed source software.
They declared something worked one way then silently changed how that thing works without properly announcing the change first and giving people enough time to adapt. Would you still be willing to make these excuses if your emails provider decided to do the same thing?
Even if it's their system, there's a limit where people would rightfully start to object.
Since I'm not really interested in using nightly or jumping through hoops, I'll just continue using kiwi which is able to support both my requirements just fine.
Thanks for the clarification though.
Mozilla was caught "studying" (read, spying) on a tiny portion of its user-base who have explicitly opted out of telemetry. The fact that most weren't spied upon doesn't mean that it didn't happen.
This is what I don't like about people who make misinformed statements on HN.
Firefox for android doesn't allow addons and F-droid Fennec doesn't seem to support them either.
The only browser on android that gives me full devtools and addon support is kiwi browser which has it's own skeletons to contend with: https://www.reddit.com/r/uBlockOrigin/comments/ppygw1/can_i_...
Life it too short to deal with malicious vendors.
How can you be so sure you got it right? How do you check for blind spots if you don't regularly expose yourself to opposing viewpoints?
I ask this because some of the best decisions I ever made were only possible after I considered the "other" side. Most of the time their views fail apart when subjected to scrutiny, but sometimes my view is the one that is found lacking.
I think fuzzing viewpoints with honest dialog is crucial for a healthy society.
I learned a lot of valuable things I wouldn't have otherwise had I used a tool like this.
Now that the steam deck is out, I'm glad I did.
1. How would this work for me as a user? Are web 3 "websites" (or whatever constitutes a service or company) not able to retain a copy of my data? Or phrased in another way, what prevents websites from also /owning/ my data?
2. How would this work for me as a service? Aside from my service's domain and internet address which are annoyingly hard to "own", what else is there to own that I don't already own?
I don't share hn's irrational hatred towards crypto so I'm not against joining whatever web3 is supposed to be (in principle) but I've yet to be shown a single benefit in doing so.
Give me a single clear benefit to using or offering a web3 service.
You refusing to transact with me isn't a war crime, but your line of thinking where normal citizen activities are similar to conscripts shooting at you can certainly lead to one.
It's one thing to target citizens who work on applications for the military, and another to target open source devs because they happen to be Russian. If you can't acknowledge this distinction then I'm afraid we have to agree to disagree.
Also please don't put words in my mouth. Strawmen will get us nowhere.
But most Russians affected by these aren't shooting back. They aren't conscripts or have anything to do with the war (doubly so now that sanctions are in effect).
Shooting at solders trying to hurt you is one thing, but that's not what's happening here.
You mean a full feature-complete devtools like what you'd find in the desktop version of firefox?!
If so, then it's a life saver. The only other browser that I'm aware of that offers full devtools on android is kiwi, but that browser force-disables ublock origin and other extensions on some sites.
I want to help others, but not at the risk of destroying my life.
This would allow global access to services in case of DNS outages, superfluous takedown requests, or anything in between.
Onion service support seems to be TBD, unfortunately.
That "crap" is something you brought up on your own. We're discussing unfair discriminatory pricing, not mating.