> I wish Python had static builds! while unusual in the "python world", there are more or less well supported ways: https://www.askpython.com/python/examples/compiling-applicat... i'm sure go will support dynamic…
They suck to maintain. I love the fact that you can just update one single openssl lib and all installed apps use the updated version after a restart. Static builds have their legitimate use-cases so maybe change that…
https://textualize.io for python isn't bad either. (In case you don't like static builds like me.)
> where the maintainers of F-Droid can intervene and prevent an update to an app from reaching users if it's deemed to be malicious That sounds like a feature you want when using FOSS. Imagine distros wouldn't have been…
That's not true tho. f-droid supports (true) https://f-droid.org/en/docs/Reproducible_Builds/ for quite some time now. Those are signed by both, f-droid and the author.
Hm f-droid provides privacy friendly https://fdroid.gitlab.io/metrics/ for some time now. I'm not sure what sort of "control" they have over the Play Store compared to f-droid, but I'd rather have a trusted 3rd party do…
yep. android 13
Hence "hack". It needs keys for administration but at a first glance, I see no reason why a git-anon user couldn't be part of gitolite's git user.
ledger-cli is rock solid but it lacks a decent TUI. Really all I want is an 80s TUI accounting app that "just works" as ledger does but with a menu driven interface with keyboard shortcut support. Modern stuff like…
For a single author you don't necessarily need any server at all. A cloud directory or zip files work well. But gitolite is so easy to setup & maintain, it's not a big difference and for r/w-access management within…
not sure how lightweight any of these are, but https://gitolite.com/gitolite/ just needs git and ssh deployed. And it works like a charm.
I bet in the majority of cases, there's no need to pressure for merging. In a big company it's much easier to slip it in. Code seemingly less relevant for security is often not reviewed by a lot of people. Also, often…
I kinda miss the curiosity show. It was a bit more science leaning but got kids to awe just the same way.
> it enabled it in the first place it took roughly two years including social engineering. I'd say the same approach is much easier in a big software company.
> where no auditor ever looks Well, software supply chains are a thing. "where no auditor ever is paid to look" would be more correct.
There's a gazillion nice python SSGs but when it comes to advanced stuff like responsive imagrs, i18n or js optimization, you always have to add it yourself. It seems most of these never became fit for use for some…
I loved etherpad but it was a pain to host back then. I'd love to have something similar that's lightweight and not serverside node.js
Not sure. In Germany there's an ongoing debate for extending conprehensive schools [1] across all ages. It's a complex topic but the general gist of supporters is, that pupils profit from each other. (e.g. Bad ones get…
You're basically saying the system is obsolete when society reaches a point, where it needs no more mediocre generalists and only excellent specialists. I wouldn't be so pessimistic.
> Whizzkids will educate themselves Only those you see becoming one. You never hear of all the "Einsteins" who never leave the patents office because they never got inspired for some passion or various other stupid…
now if we just teach those tools to kids instead of turning them into spreadsheet office robots, that would be great.
also nothing in linux will ever just give some cryptic hex code error or crash report. It's either crashdump or nice error message. If not I just increase loglevel to find the actual problem.
> At least one RCE, admittedly with a non-default fail2ban config and a somewhat unlikely attack chain: you had to manipulate answers from a whois server. Sure, it increases attack surface (like any additional piece of…
fail2ban is fine for effectively slowing brute-force attacks for services that can't by themselves or where significant complexity would be needed. it's easy to setup and can stop multi stage attacks that generate…
> Printer manufacturers also don't thing like this at this point, what are they gonna do? Not provide windows drivers?
> I wish Python had static builds! while unusual in the "python world", there are more or less well supported ways: https://www.askpython.com/python/examples/compiling-applicat... i'm sure go will support dynamic…
They suck to maintain. I love the fact that you can just update one single openssl lib and all installed apps use the updated version after a restart. Static builds have their legitimate use-cases so maybe change that…
https://textualize.io for python isn't bad either. (In case you don't like static builds like me.)
> where the maintainers of F-Droid can intervene and prevent an update to an app from reaching users if it's deemed to be malicious That sounds like a feature you want when using FOSS. Imagine distros wouldn't have been…
That's not true tho. f-droid supports (true) https://f-droid.org/en/docs/Reproducible_Builds/ for quite some time now. Those are signed by both, f-droid and the author.
Hm f-droid provides privacy friendly https://fdroid.gitlab.io/metrics/ for some time now. I'm not sure what sort of "control" they have over the Play Store compared to f-droid, but I'd rather have a trusted 3rd party do…
yep. android 13
Hence "hack". It needs keys for administration but at a first glance, I see no reason why a git-anon user couldn't be part of gitolite's git user.
ledger-cli is rock solid but it lacks a decent TUI. Really all I want is an 80s TUI accounting app that "just works" as ledger does but with a menu driven interface with keyboard shortcut support. Modern stuff like…
For a single author you don't necessarily need any server at all. A cloud directory or zip files work well. But gitolite is so easy to setup & maintain, it's not a big difference and for r/w-access management within…
not sure how lightweight any of these are, but https://gitolite.com/gitolite/ just needs git and ssh deployed. And it works like a charm.
I bet in the majority of cases, there's no need to pressure for merging. In a big company it's much easier to slip it in. Code seemingly less relevant for security is often not reviewed by a lot of people. Also, often…
I kinda miss the curiosity show. It was a bit more science leaning but got kids to awe just the same way.
> it enabled it in the first place it took roughly two years including social engineering. I'd say the same approach is much easier in a big software company.
> where no auditor ever looks Well, software supply chains are a thing. "where no auditor ever is paid to look" would be more correct.
There's a gazillion nice python SSGs but when it comes to advanced stuff like responsive imagrs, i18n or js optimization, you always have to add it yourself. It seems most of these never became fit for use for some…
I loved etherpad but it was a pain to host back then. I'd love to have something similar that's lightweight and not serverside node.js
Not sure. In Germany there's an ongoing debate for extending conprehensive schools [1] across all ages. It's a complex topic but the general gist of supporters is, that pupils profit from each other. (e.g. Bad ones get…
You're basically saying the system is obsolete when society reaches a point, where it needs no more mediocre generalists and only excellent specialists. I wouldn't be so pessimistic.
> Whizzkids will educate themselves Only those you see becoming one. You never hear of all the "Einsteins" who never leave the patents office because they never got inspired for some passion or various other stupid…
now if we just teach those tools to kids instead of turning them into spreadsheet office robots, that would be great.
also nothing in linux will ever just give some cryptic hex code error or crash report. It's either crashdump or nice error message. If not I just increase loglevel to find the actual problem.
> At least one RCE, admittedly with a non-default fail2ban config and a somewhat unlikely attack chain: you had to manipulate answers from a whois server. Sure, it increases attack surface (like any additional piece of…
fail2ban is fine for effectively slowing brute-force attacks for services that can't by themselves or where significant complexity would be needed. it's easy to setup and can stop multi stage attacks that generate…
> Printer manufacturers also don't thing like this at this point, what are they gonna do? Not provide windows drivers?