HNHacker News
TopNewBestAskShowJobs

pabs3

55,838 karma · joined May 4, 2018

https://bonedaddy.net/pabs3/

Hire me to work on open source projects! I've been working on and using open source for about 20 years, principally on the Debian project.

https://bonedaddy.net/pabs3/about/resume/ https://bonedaddy.net/pabs3/about/#other_pages https://bonedaddy.net/pabs3/log/ https://bonedaddy.net/pabs3/about/#contact

submissionscomments
pabs3··on Before GitHub
It was started by some French folks from Debian, so the latter is logical, and the former presumably because tech companies use their marketing budgets to sprinkle a few sponsorship dollars here and there.
pabs3··on Before GitHub
Some notes from ArchiveTeam about software archiving:

https://wiki.archiveteam.org/index.php/Category:Software_arc...

pabs3··on An Introduction to Meshtastic
And why MeshCore forked from Meshtastic:

https://blog.meshcore.io/2026/04/23/the-split

pabs3··on Hardening Firefox with Claude Mythos Preview
Which tool?
pabs3··on Carrot Disclosure: Forgejo
Yes, document.createElement is widely supported.
pabs3··on GitHub Actions is the weakest link
Better to treat it as a dependency still, but audit each new commit/release as it comes in, and pin to the exact last commit id that you verified.
pabs3··on GitHub Actions is the weakest link
How many people actually audit the code changes in their dependencies when updating them?
pabs3··on Carrot Disclosure: Forgejo
I wonder why they didn't change it to use DOM APIs instead. Related comment:

https://news.ycombinator.com/item?id=47945472

pabs3··on Carrot Disclosure: Forgejo
I note that the code that pull request 12283 is changing builds HTML via string concatenation/templates, which is a widespread source of XSS problems. Maybe it is time to for browsers and JavaScript runtimes/libraries to deprecate string based HTML building and require DOM based instead. The former is unsafe by design and the latter is a safe-by-construction approach.

Getting HTML building right is a pretty basic building block of web apps, Forgejo can't have great security practices if they aren't doing that. So I can easily imagine the OP is correct in their assessment of Forgejo code security.

pabs3··on An update on GitHub availability
git itself can push to multiple URLs btw:

https://stackoverflow.com/questions/849308/how-can-i-pull-pu...

pabs3··on When your digital life vanishes
IIRC you have to click "trust the device" on your iPhone and then it just works.
pabs3··on The West forgot how to make things, now it’s forgetting how to code
Reminds me of this post:

https://berthub.eu/articles/posts/how-tech-loses-out/

pabs3··on GnuPG – post-quantum crypto landing in mainline
IIRC the GnuPG folks do a lot of consulting and sell additional software:

https://gnupg.org/service.html https://gnupg.com/ https://g10code.com/

pabs3··on AGPLv3§74 Empowers Users to Thwart Badgeware Like OnlyOffice
FSF did the shame thing:

https://www.fsf.org/blogs/licensing/agpl-is-not-a-tool-for-t... https://lwn.net/Articles/1067771/

pabs3··on Why has there been so little progress on Alzheimer's disease?
> Alzheimers feels like something only old people get

https://en.wikipedia.org/wiki/Early-onset_Alzheimer%27s_dise...

pabs3··on Email could have been X.400 times better
The critical part of that quote "Like a car with no brakes or seatbelts."
pabs3··on Arch Linux Now Has a Bit-for-Bit Reproducible Docker Image
More info about Reproducible Builds here:

https://reproducible-builds.org/

Closely related is the Boostrappable Builds community:

https://bootstrappable.org/

pabs3··on Arch Linux Now Has a Bit-for-Bit Reproducible Docker Image
And spawned a cross-distro community working on this stuff:

https://reproducible-builds.org/

pabs3··on I don't want your PRs anymore
> why would anybody share anything

Before LLMs, it was cheaper in the long run; by upstreaming your patches you don't have to rebase them continually and sometimes the community will maintain the code for you. OTOH sometimes you might need to work on the code again though as other parts of the project evolve if the project is likely to throw out unmaintained code; this is especially true in the Linux kernel where internal APIs change constantly, but upstream maintenance is probably cheaper than continually backporting security fixes to your stable/LTS/SLTS or completely dead versions.

With LLMs the costs might be different but will still exist.

pabs3··on Windows 9x Subsystem for Linux
Here is a CLI for reading Mastodon instances, no account required.

https://github.com/jwilk/zygolophodon

I've been working on a WebExtension that calls out to zygolophodon and returns plain HTML to the browser. In the process of rebasing it over recent changes but here is the working webext-old branch:

https://github.com/jwilk/zygolophodon/compare/master...pabs3...

pabs3··on Binary Dependencies: Identifying the Hidden Packages We All Depend On
Does Gentoo use the Bootstrappable Builds process yet? ISTR someone was working on it.

Windows/macOS/etc are pretty irrelevant if you don't want to trust binaries, because most of them don't come with full source code. People who care about this stuff aren't even going to consider proprietary platforms.

In any scenario where you would do a full-source bootstrap, you would be reviewing the code for each step of the process, or deciding which reviews published using crev or similar are trustworthy enough for you.

https://news.ycombinator.com/item?id=47701394

pabs3··on Binary Dependencies: Identifying the Hidden Packages We All Depend On
Dependency detection is usually done during source code review for software packaging (like Debian), there it is relatively trivial; look at declared dependencies, search for language functionality that loads libraries or calls executables and mostly you will be done. Like dlopen for C or import for Python.

The Linux kernel has the IMA subsystem that is intended to prevent executing untrusted binaries, enroll all the hashes from your package manager, and then you will know where every executed binary came from. Or just verify the block device with dm-verity. Or both. I believe that similar functionality exists on Windows and some interpreters have support for asking the kernel to check if files can be executed before loading them.

https://ima-doc.readthedocs.io/en/latest/ https://www.kernel.org/doc/html/latest/admin-guide/device-ma...

The Bootstrappable Builds toolchain requires the use of machine code of course since CPUs only accept machine code, but that machine code is in hex numbers in a text file with comments and that form is considered the "source code" not "a binary", aka it is "the preferred form for modification" (the phrase used by the GPL). The human starting the bootstrap process has to review it is correct, enter it into the computer in some trustworthy way, and start it. Yes, the bootstrap process does go to unbelievably extraordinary measures :)

pabs3··on Amazon won't release Fire Sticks that support sideloading anymore
The SFC (the only GPL enforcers at the moment) disagree; they say that both GPLv2 and GPLv3 require the ability for users to install modified versions on their devices.

https://sfconservancy.org/blog/2021/mar/25/install-gplv2/ https://sfconservancy.org/blog/2021/jul/23/tivoization-and-t... https://events19.linuxfoundation.org/wp-content/uploads/2017...

pabs3··on Binary Dependencies: Identifying the Hidden Packages We All Depend On
Personally I like using Debian packages to keep track of source and binary dependencies.
pabs3··on Binary Dependencies: Identifying the Hidden Packages We All Depend On
Its possible to avoid all of those binaries (including the Linux kernel) and build from source instead.

https://bootstrappable.org/ https://lwn.net/Articles/983340/ https://github.com/fosslinux/live-bootstrap https://stagex.tools/

pabs3··on YouTube users get option to set their Shorts time limit to zero minutes
More similar ones here:

https://old.reddit.com/r/uBlockOrigin/wiki/solutions/youtube

pabs3··on YouTube users get option to set their Shorts time limit to zero minutes
This stuff can help a lot too:

https://old.reddit.com/r/uBlockOrigin/wiki/solutions/youtube

pabs3··on YouTube users get option to set their Shorts time limit to zero minutes
If you have uBlock Origin installed, the subreddit wiki for it has lots of options for blocking stuff on YouTube.

https://old.reddit.com/r/uBlockOrigin/wiki/solutions/youtube

pabs3··on Stealth signals are bypassing Iran’s internet blackout
http://tom7.org/harder/
pabs3··on Dependency cooldowns turn you into a free-rider
I prefer crev-dev for the review sharing thing:

https://github.com/crev-dev/

← PreviousPage 2 of 34Next →