Hacker News new | past | comments | ask | show | jobs | submit | nwellinghoff's comments login

Seems easy enough to do a quick fix for. Just add a option to maven that goes straight into compile and does nothing else. Would be good for local dev. However as we all know maven does much more than this and server side ci/cd process is what really slows your other team members down (if its slow)

You could have just done ssh reverse shell to a public jump server you control? Might have been easier.

They probably have ai that scans existing human written code and auto generates patches and fixes to improve performance or security. The 25% is just a top level stat with no real meaning without context.


Can’t believe people have not pointed out the biggest reason of them all. Its the most widely deployed desktop os across rich targets (corporations). A lot of time and investment goes into cracking it.


There are more computers running Linux on this earth by orders of magnitude.


>> Its the most widely deployed desktop os across rich targets

>There are more computers running Linux

You did not address the claim you replied to. Users get compromised, and users use windows desktop.

The number of DB clusters or whatever running *nix isn't relevant.


Users use Android phones which make use of a Linux kernel. There are far more Android phones then there are windows desktops. Also a phone often has far more sensitive data and is also privy to 2FA codes.

https://source.android.com/docs/core/architecture/kernel


Most of them are offering nothing more than an ssh or web service. Not really a great or fair comparison.

Linux on the desktop is the least secure option out of Windows and macOS, barring RHEL with it's SELinux policies which probably put it ahead of Windows and macOS as well.


> There are more computers running Linux on this earth by orders of magnitude.

Yes, but most of them aren't running GNU and have signed boot with no ability to disable it. Very shallow victory. Could turn into FreeBSD tomorrow, and very little ground would be lost.


You forgot servers.


That’s what they’re talking about?


And almost none of those bother doing things like checking driver signatures at all. You don't need to figure out hacks like "downgrading the OS to bypass signature validation logic" when you can `insmod` the moment you get admin/root permissions.

You could configure all manner of security settings on Linux, of course, but on most Linux distros they're all left unconfigured.


[flagged]


For a while apple had better security. Now it's more even, if you go by the 0day prices. There's not a lot of truly secure options unless you wanted to develop your own phone from the ground up.


GrapheneOS has been doing a lot of great work in the secure mobile OS space.


Yeah its a chilling effect where anything useful enough to get popular gets assumed to be compromised.

It seems unfalsifiable but it's also not unlikely.


How about iPhone in lockdown mode?


Wait until all those regulations requiring apple to allow different app stores come online and then we will see how secure iOS is. The day Joe Clicks-A-Lot can follow a link in some random pig butchering scam email then “legally” sideload and run whatever crazy weird goop happens to be at other end will really put things to the test.

Because letting Susie Easy-To-Phish install anything and everything on her iPhone is going to make things very… interesting.

That being said, Joe and Susie can already do that on android right?


Wow this thing has everything under the sun it. Anyone know the unit cost?


Man is that db-15 port on the back of that thing? Lol.

I want one of these just to be different and cool.

Btw the article website is so plastered with ads its totally unusable on mobile. Joke level bad.


For me I seem to have noticed that if you have thicker body hair you sure get bit less. My gf says “they like me”. No babe, just like me they like your shaved legs.

Seriously though. When they land on my hairy leg they are quickly detected and dispatched.


You also have to consider the material cost. RO membranes require continuous maintenance , are expensive, and generate a massive amount of brine waste water. So while having cheap energy definitely helps, there are many expensive problems with RO filtering at scale.


Wow this is wild and so counterintuitive. Basically totally free too. I hope its actually true!


Same question. Can someone chime in on how deploying this would be different from putting ssh behind wiregaurd? On first glance it looks like if you were ultra paranoid you could put this in front of wiregaurd and not even have to open up a udp port? Would that be an advantage to add a layer to secure wiregaurd against 0day?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: