HNHacker News
TopNewBestAskShowJobs

numbsafari

5,625 karma · joined March 14, 2011

https://www.bainbridgehealth.com

The Gigazone™, MN | Philadelphia, PA

Emailers, you can call me "swilson" at my work domain.

submissionscomments
numbsafari··on Rsync replaced with openrsync on macOS Sequoia
I stopped treating Mac OS as a Unix and I started sleeping at night. It’s a great platform for running a Unix in a VM.
numbsafari··on A number of electric vehicle, battery factories are being canceled
Besides Tesla?
numbsafari··on Porting Tailscale to Plan 9
Many years ago a roommate and I had an HPUX machine running IE on HPUX just so we could forward X session to our FreeBSD and Linux desktops and not have to use our Windows machine for anything other than PC games.
numbsafari··on The surprisingly simple reason kids have imaginary friends
From the ass of Secret Dreams, comes Imaginary Friends.
numbsafari··on The surprisingly simple reason kids have imaginary friends
I grew up with six siblings on a cul-de-sac filled with other families with 3+ children (enough kids for two complete baseball teams) and had imaginary friends.
numbsafari··on We hacked Gemini's Python sandbox and leaked its source code (at least some)
You answered your own question.
numbsafari··on Multiple vulnerabilities in ingress-Nginx (Score 9.8)
No evidence, but the fact that the "IngressNightmare" PR piece was announced before there were even PRs created to fix this smells like the team at Wiz leaked this before it was really ready.

Whether the scores are legit or not, the fact that this was such a botched disclosure process is not a good look for the Kubernetes project, of which this is a part.

Edit: According to [1], the team at Wiz show a responsible disclosure timeline. Seems like the Kubernetes project's process didn't work so well. If Wiz is accurately reporting what happened in their blog, these fixes (or the plan for them) was available a month ago, despite seemingly not having working PRs until today, after the security announcement?

Again, I really appreciate the work of the team to ship this, but this isn't a good look for the Kubernetes project itself.

[1] https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabili...

numbsafari··on Apple shuffles AI executive ranks in bid to turn around Siri
> Putting too much trust on Eddy Cue

I've never understood the love for Eddy Cue. Apple pundits all seem to love him. Personally, I am really unimpressed by everything he's done. My understanding is he's been really good at negotiating big contracts.

I just don't think his execution or vision are exciting and, as you are hinting at, I don't think his moral compass points in the right direction. That said, despite some early pushback, my understanding is that Schiller was ultimately on-board with holding to the 30% cut.

numbsafari··on Evidence that Neanderthal and Homo sapiens engaged in cultural exchange
This is not true, as evidenced by the slave taking exhibited by nomadic peoples in North America. It was a pretty routine practice, well documented in history. Losers in battles would often be assimilated by the winner as slaves.
numbsafari··on Microsoft cancels leases for AI data centers, analyst says
This has nothing to do with supply/demand, and everything to do with geopolitics.
numbsafari··on Do Lake Names Reflect Their Properties?
I can assure you that "Jack The Horse Lake" in Northern MN absolutely reflects whatever you think that name implies.

https://www.google.com/maps/place/Jack+the+Horse+Lake/@47.61...

numbsafari··on Privacy Pass Authentication for Kagi Search
> This by default almost assumes a hostility towards the former group because their interests will of course be at odds with the interests of the latter group.

I would generally agree that that's the "default".

However, there are cases where two sides of a market need an intermediary with which they can both independently transact, and a net benefit of that interaction is felt on both sides. The key is to construct the solution such that the intermediary depends on the goodwill of both sides of the market.

I think Kagi is somewhat flipping the script. By "taking" data from publishers for free, they are then selling it to readers at a cost. However, there is a trade off. Kagi needs to make sure publishers continue to make their content available so that it can be searchable, or used in their Assistant product. In order to do that, they need to do the opposite of what Google is doing by trying to sequester traffic on Google.com: Kagi's best interest is to make sure that they provide good value to both sides.

Indeed, using the Assistant product, the way it is structured, I very often find myself clicking through to the referenced original sources and not just consuming the summarized content.

How this evolves over time, from a product design standpoint, will be interesting to watch.

numbsafari··on We are the "thin blue line" that is trying to keep the code high quality
> making it so hardware providers must maintain their drivers is a good start

How do you propose that happens?

numbsafari··on U.S. Government Disclosed 39 Zero-Day Vulnerabilities in 2023, First-Ever Report
NOBUS is a disaster. Knowingly leaving citizens unprotected is an absolute failure of government. Having a robust policy of identifying a resolving cybersecurity faults, and holding organizations accountable for patching and remediation is necessary if we are going to survive a real cyber “war”. We are absolutely unprepared.
numbsafari··on Anthropic: "Applicants should not use AI assistants"
These are the same people that insist we arm elementary school teachers and expect those teachers to someday pull the trigger on a child instead of having proper gun laws.

There is no irony.

numbsafari··on AstroForge selects target for “high risk, seat of the pants” asteroid mission
verY Common…
numbsafari··on Oracle Cloud deleting active user accounts without possibility for data recovery
Oracle is holding the door from the inside, smiling widely.
numbsafari··on Patient Monitor Contec CMS8000 Contains a Backdoor
The inverse of “defense in depth” is “flooding the zone”.
numbsafari··on Patient Monitor Contec CMS8000 Contains a Backdoor
> Contec Medical Systems Co., Ltd. (hereinafter referred to as CONTEC) focusing on research, manufacture and distribution of medical instruments, was founded in 1996 as a high-tech company. CONTEC locates in Economic & Technical Development Zone in Qinhuangdao covered an area of 125 acres and building area of over 100000 square meter, which is one of the largest bases for R & D and production of medical devices in China.

https://contechealth.com/pages/company-introduction

I doubt it.

numbsafari··on JavaScript Temporal is coming
Did you bother to look at it?

It has a single dependency, and that single dependency has no dependencies of its own.

So what is that dependency?

"temporal-spec"

And it looks like it comes from the same github repo. It basically looks like they broke out the API definitions so that they could be depended on by other potential implementations. This isn't atypical.

numbsafari··on It's official: Research has found that libraries make everything better
So, like, Kindle?
numbsafari··on Goodbye, Slopify
My wife continues to mourn the loss of Grooveshark and brings it up at least once a year. It was pretty amazing.
numbsafari··on Facebook ban on discussing Linux?
[flagged]
numbsafari··on A phishing attack involving g.co, Google's URL shortener
I don’t need a “verified” tag. No spoofed call should ever get through. Ever. When would I ever want a spoofed caller ID? Never.
numbsafari··on A phishing attack involving g.co, Google's URL shortener
> no incoming phone call can ever be trusted.

They can't. And they haven't been for a while. Spoofing phone calls is simply too easy, and nothing is being done to fix that, despite the fact that it puts so many of us at risk. It's not an insurmountable problem, technologically. It is literally a lack of will and outcry from ordinary people, despite how often this fact is used to abuse so many.

Credit Card companies have known this for a long time. My credit card company will call and say "do not call back to this number, call the number on the back of your card and use this reference number".

That should absolutely be the norm at this point.

numbsafari··on Divers recover Phoenician shipwreck that sank 2.6k years ago off coast of Spain
ahem... https://xkcd.com/356/
numbsafari··on Divers recover Phoenician shipwreck that sank 2.6k years ago off coast of Spain
Bring on the Sea Peoples (maybe)
numbsafari··on Supreme Court upholds TikTok ban, but Trump might offer lifeline
The interesting bits from the text[1], relative to the now flagged sibling

-----

(3) FOREIGN ADVERSARY CONTROLLED APPLICATION.—The term “foreign adversary controlled application” means a website, desktop application, mobile application, or augmented or immersive technology application that is operated, directly or indirectly (including through a parent company, subsidiary, or affiliate), by—

(A) any of—

(i) ByteDance, Ltd.;

(ii) TikTok;

(iii) a subsidiary of or a successor to an entity identified in clause (i) or (ii) that is controlled by a foreign adversary; or

(iv) an entity owned or controlled, directly or indirectly, by an entity identified in clause (i), (ii), or (iii); or

(B) a covered company that—

(i) is controlled by a foreign adversary; and

(ii) that is determined by the President to present a significant threat to the national security of the United States following the issuance of—

(I) a public notice proposing such determination; and

(II) a public report to Congress, submitted not less than 30 days before such determination, describing the specific national security concern involved and containing a classified annex and a description of what assets would need to be divested to execute a qualified divestiture.

-----

The way I read this is that Congress is bootstrapping the law with its own finding that ByteDance, Ltd/TikTok are Foreign Adversary Controlled Applications, but then, in (3)(B), the President is responsible for determining any other entities this law should cover given previously stated parameters (what they mean by "covered entity" here), using the procedure it then provides.

I believe that addresses the concern about this being a "Bill of Attainder".

Edit: Obviously IANAL, but it also doesn't appear that this issue of this being a Bill of Attainder was raised by TikTok, nor was it considered in this opinion. Perhaps they will do so in a separate action, or already have and it just hasn't made its way to the court(?), but if it were such a slam dunk defense, you think their expensive lawyers would have raised it.

[1]: https://www.congress.gov/bill/118th-congress/house-bill/7521...

numbsafari··on No Calls
At least you offer a pricing calculator.

When we are doing vendor research, we often dequeue or deprioritize vendors that do not have any kind of pricing available for the tier we require. Generally speaking, we assume things like volume discounts are available. Also, it's good to get a rough idea of what the delta between "Pro" and "Enterprise" happens to be. Not infrequently the reason that delta isn't available is because it's stupid orders of magnitude different.

If we know that up front, we know not to waste our time tire kicking with a demo account.

So, the middle ground you describes would seem, to me, to be the right place to be. Giving your pricing page a cursory glance, I would rank it pretty highly for the kind of "initial investigation" we might do.

I think from an entrepreneur standpoint, if I see a space with vendors with non-transparent pricing, I often think "there's an opportunity there".

numbsafari··on Diets high in advanced glycation end products promote insulin resistance
> Everything in moderation.
← PreviousPage 4 of 34Next →