Hacker Newsnew | past | comments | ask | show | jobs | submit | throwaway02y's commentslogin

> life savings being stolen overnight.

Sounds like crypto to me.


Never experienced any freezes with tilix and I use it daily for years now. It's abandonware though.


It's still GTK 3 using VTE and so doing the drawing with Cairo. It (VTE) has a lot of optimizations that made sense when we didn't have working GPU drivers.

But for GTK 4, we can do things much differently and faster.


I'd love to use Wayland all the time, and we are almost there, but just so many quirks everywhere (especially with outdated Electron apps).


It really is nice once managed - it's hard to explain, but everything is very smooth. I would guess the display synchronization/mixed refresh rate support is to thank.

Some Electron-based things and Steam are the main holdouts I've noticed.

I suspect the Electron things at-large will be sorted out before Steam... they simply need to rebase while Valve has to modernize their libraries (ie: vgui)


Steam recently underwent a large GUI refresh, vgui has officially been retired.


That's just one I could name from memory - if you run 'xlsclients' you'll still see Steam isn't Wayland.

I was very hopeful that the redesign would be sufficient; it was not.

Thank you for the information, though - important to be current


> internal network is now accessible from anywhere !

If you exposed it willingly.


The point of the blog post is that this method is useful for attackers (as a so-called lolbin - trusted binary used in a malicious way).


I work with 500 idiots. Willingly and cluelessly are interchangeable.


Not nicely put, but not wrong. I had half an heart attack when that feature was rolled out, and the danger was split only between myself and a colleague. I can't even trust myself to not screw up. I needed another permanencied invocation of the principle of hope.


The industry is only going to keep making more idiots if they treat developers like this.


It kept producing more idiots when we didn't treat them like this and this is easier so fuck it.


Take their computer away.


Seems to be the goal of most "cybersecurity" types.


I thought their goal was collecting vendor certifications.


Ouch dude


It's a burn but it's accurate. Had three consultancies in (high end well known ones) and and two in house certified to their eyeballs professional cyber security experts in charge. All they did was tick a fuck load of boxes, run some scans, spend a lot of money and make it really hard for people.

Yet I managed to find a fully remote RCE and exploit it in 30 minutes after they did all this.

The industry is a fucking scam.


Confirming this experience, it is Security Theatre all the way down.


Sounds like it's time to make your own certification. :D


Management frowned at this suggestion.


Well said, this is why working solo can be beneficial: only one idiot to look out for. :)


That’s the idiot that can do the most damage!


Can confirm.


What do you do in your brain when you get something wrong?


Learn the concept better, not an exception to an incorrect rule. It seems like the model architecture just isn't good enough.


Sounds like learning irregular verb forms, or integration rules!


Hardcoding natural language rules doesn't work, we know that from decades of trying. Therefore hardcoding these natural language rules in the model wont work either, it will fail for the same reason, you can't encode enough rules to handle things as well as a human.


Are we arguing ChatGPT is not AGI? I can agree with that.

As for encoding enough rules to handle things as well as a human, what things? Humans don't work with infinite knowledge so there must be a set of rules (however large) that would be "enough".


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: