Hacker Newsnew | past | comments | ask | show | jobs | submit | OvervCW's commentslogin

You cannot deny that telling the entire world about this vulnerability before it is patched won't cause a lot of abuse that would not have happened otherwise.

AFAICT it was a Linux kernel maintainer who first "told the entire world about the vulnerability" on 2026-03-31: https://git.kernel.org/pub/scm/linux/kernel/git/herbert/cryp...

The CVE was officially announced on 2026-04-22: https://lore.kernel.org/linux-cve-announce/2026042214-CVE-20...

Theori were simply the last team to publicly disclose the vulnerability on 2026-04-29, 37 days after reporting it to the vendor. They were simply more effective at communicating it, and they told you that you were vulnerable. That's why you're mad at them instead of the people who put the bug there in the first place, didn't bring its severity to your attention, and silently sat on the patch.


I do deny that, mostly because we’ve entered the time of automated vulnerability detection and abuse. A human need not be in the loop at all anymore.

But, even if I agreed with you, how do you propose they tell the patchers this that doesn’t tell the whole world?


Why not?

Any program on your computer can just run "sudo" to escalate itself.

The problem is not the passwordless sudo but running untrusted programs on your computer under your user. They don’t need sudo to steal your SSH keys or inject malicious code in your .bashrc.

That's exactly what I set out to do with my pet project :)

https://github.com/Overv/outrun


Yes, world class in causing human suffering.

https://www.youtube.com/watch?v=Q7pgDmR-pWg


>unless the label is something too low signal to predict

>Also, crashes are statistically rare events on arterial and local roads, so it can take years to accumulate sufficient data to establish a valid safety profile for a specific road segment.

That is exactly what this article is about.


I wouldn't be surprised if they did this to lower the support workload, since I have several 2.4Ghz devices that fail to connect to WiFi at all if I put both bands on the same SSID. I intentionally separated them for that reason and portable devices like phones know how to switch between multiple SSIDs based on signal strength anyway.


Vue can do progressive enhancement.


Yes, okay, some can. Vue, petite-vue, Alpine, ...


No, Hacker News is generally about technology and startup news, not businesses in general.


That's your opinion.


Mullvad at least is funded by their VPN subscriptions.


In my experience Chrome does not just load faster, but it also uses less memory than Firefox because of its more aggressive tab hibernation that is enabled by default.

On my laptop I had to switch from Firefox to Chrome because it kept filling up all of my RAM resulting in other applications crashing.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: