

Delayed replies to a single internal endpoint triggered a latent retry bug in VS Code that amplified traffic by approximately 10x and caused delayed recovery for the Copilot Token Service.
So you DDOS’d yourself. Nice job.


Delayed replies to a single internal endpoint triggered a latent retry bug in VS Code that amplified traffic by approximately 10x and caused delayed recovery for the Copilot Token Service.
So you DDOS’d yourself. Nice job.
Xbox One Series X or S
I think there’s a bit of confusion due to Microsoft’s insane naming conventions. These consoles exist:
OP is talking about (2).
Technically there has been an exploit found:
But it might be only for (1) and it’s not clear if there’s a practical way to use it yet.


Not OP but I was a pretty competent C/C++/C# programmer first. Lisp and Haskell both totally changed how I thing about programming. I’ve used all the other languages you listed and I don’t think any of them have a unique philosophy to offer, except maybe rust for the memory model.
Lisp teaches you how flexible programming languages should be. Haskell teaches you about things like higher kinded types, and exposes you to loads of cool category theory stuff. Other languages can probably accomplish these goals, but I don’t think any of the alternatives you listed could.


Neither because they probably aren’t stupid:
<PackageReference Include="Duende.IdentityModel.OidcClient" Version="6.0.1" />


Because it wasn’t obvious to me from the article, and I was trying to figure out whose sovereign tech fund it is:
The Sovereign Tech Agency is financed by the German Federal Ministry for Digital Transformation and Government Modernisation and is a subsidiary of SPRIND, the Federal Agency for Disruptive Innovation.


It should be possible to use a distributed web of trust for this.


For me the scariest thing someone could do on my pc is exfiltrate all the data from my home directory which is readable by my user account.
Maybe I’m misunderstanding you, but that’s harm to me without root access.
Well that was fucking dark. Good read though


Still team Emacs. We’re a team because we use elisp, not because of something trivial like how our text editors work.


This is a good article because it immediately made me feel stupid for not knowing about O_PATH.
I really need to figure out a better sandboxing method for shells. It’s crazy to be things where my keys, browser data, shell history are all accessible.
I do try to use firejail where possible, but it’s quite cumbersome. Every so often I look for tools to help with this, but everything is oriented around making a specific program (e.g. Firefox, steam) work.


Yeah, I’d say for information, certainly, but there are other ways you could be valuable. A dev on a popular open source project might be very valuable for executing supply chain attacks.


First of all, fuck them.
Secondly, thank you for working on this app. I know Roku is a bit of a liability, and I’ll eventually have to move to something open source, but it’s been my main media player for a couple of years and I’ve been very happy with it. o7
You can audit the code but something like:
The rate of commits and new features seems rather high for a single person working by themselves
Is a huge problem in itself IMO. It implies there’s no real human oversight of the project.
That’s the scary thing. It can easily create more code than it can understand, and do it faster than human understanding can keep up with.


Yes, and you can do the same thing to your child’s non-root account. The point of the California law is to allow admins (parents) to do that.


Furthermore, a peer review process is planned, through which the consortium members will mutually check and certify their operating systems and smartphone or tablet models. “This is intended to create transparency and replace trust with traceability.”
Still doesn’t sound very open.
I should be able to tell my bank to only trust devices running an OS signed by the grapheneos key, and more importantly I should be able to tell them to trust an OS signed by my key.
Edit: I don’t mean to shit on this too hard. It might be the best next step.


That’s true, but as a maintainer you could encourage those helpful maintainers to triage issues from regular users.
I think the real benefit would come from taking a user’s reputation into account across projects.
At the end of the day you can’t have low effort pull requests, and expect maintainers to look at everything. It’s the same spam problem as in any other domain.
Uh okay.