2,001 karma · joined September 11, 2014
New project: https://supplywarden.com
Unless you use a text editor without any coding capabilities, your IDE should show you which values you can pass. The alternative is to have more methods, I guess?
> why can't I just pass 20 or 20_000 or something
20 what? Milliseconds? Seconds? Minutes? While I wouldn't write the full Duration.ofSeconds(20) (you can save the "Duration."), I don't understand how one could prefer a version that makes you guess the unit.
> proxy(ProxySelector.of(new InetSocketAddress("proxy.example.com", 80))), geez that's complex
Yes it is, can't add anything here. There's a tradeoff between "do the simple thing" and "make all things possible", and Java chooses the second here.
> .authenticator(Authenticator.getDefault()), why not just pass bearer token or something?
Because this Authenticator is meant for prompting a user interactively. I concur that this is very confusing, but if you want a Bearer token, just set the header.
But even if there were some "ethical reason" to do this, I don't think Gitea is the right project to play up as a victim. Their homepage [2] doesn't mention that Gitea itself is a fork either. Their Readme does, but is this so much better?
[1]: https://forgejo.org/2022-12-15-hello-forgejo/ [2]: https://about.gitea.com/
- you don't know "who" you hit. The case in TFA is still rather simple (just send the "hack" as the response), but you will still most likely hit some residential proxy and nuke some random person instead of the responsible actor - (this is not too related to TFA but a point in discussions about hack-backs on a state-actor level) unless you're doing a very simple "attack", you need to have some sort of vuln ready to perform any kind of hack-back. Which leaves the ethical dilemma that actors are now motivated to keep vulnerabilities available, thus making the world more unsafe. And once you have used your vulnerability, your "enemy" probably knows it as well.
What about security researchers scanning for their research? What about scanners that notify you?
(she worked and lobbied for the gas sector before joining the current government)
60 min delay: 25% (or 100% if you abort your travel) 120 min delay: 50% Furthermore, your ticket is usually unlocked for all trains in case of delay, not just the one you booked. So you can find alternatives and maybe even upgrade (you won't have a seat reservation though).
There's also up to 120€ for overnight-stay or other forms of transportation in select cases (when you won't be able to reach your destination before some time)
Of course, this went exactly as you'd think. However, since 2021, you can get a gambling license in all of Germany.
Fun fact: Since it's illegal to gamble with a non-licensed provider, using international platforms like polymarket can get you in trouble.
It has some compound words. But including too many of them would quickly get out of hand
Or less snarky: it's simply harder to steal something or defraud someone in meatspace than in the Internet, so less protection should be necessary.
> Boot images should be Dm-verity protected EROFS images
Maybe I'm misunderstanding you - I gather that you think the boot images are distributed as OCI images? That's not the case, bootc is more about building the image, updating it and the overall structure. Booting an image built with bootc does not involve any container infrastructure (unless you start services that depend on containers, I guess - but that's deep in userspace). There's technically nothing preventing this from using verified read-only images.
I can definitely confirm that this is a common thing. But I think this is a "small org"-problem more than a "European business"-problem. Apparently, the company has somewhere between 500 and 1000 employees (I couldn't find good data, sadly). With a size like this, the "support" is probably outsourced (meaning they don't know anything), there are maybe 100 engineers (probably less) and the mailing is either done via a third-party or set up by an Admin that left three years ago.
Without any basis, I will speculate that you will notice this more in Europe because there is simply no company at the size of Stripe or similar.
I have no idea if the number is actually a lot shrug but it's surely different than cars on a planet's surface
The capture process sounds much more complicated than necessary. There are emulators that can capture the output as APNG/GIF/... If you really want to make sure that you have every frame, a good emulator also supports manual frame stepping without having to use the debugger.