Live data from Hacker News

Viewing profile — cyrnel

cyrnel

HN member
Joined
Sat, Jul 01, 2023, 10:54 PM UTC
HN karma
392
Public activity
92 items

About cyrnel

No profile information was provided.

Recent public activity

  1. comment
    Comment #45617769

    The response to that: https://andre.arko.net/2025/10/09/the-rubygems-security-inci...

  2. comment
    Comment #45455233

    Both are billion dollar companies, we as individuals have nothing in common with them. Enshittification happens due to market conditions that apply to small and large companies ali…

  3. comment
    Comment #45452150

    +1 for Node-RED. If we've learned anything from elasticsearch/redis/bitnami/and dozens of others, it should be "don't build important things on code that isn't enshittification-res…

  4. comment
    Comment #45367264

    I know, right? It's sycophancy. If you are actually against the policy and suspect a lot of people are too, then don't silence your employees by keeping their feedback isolated to …

  5. comment
    Comment #45270758

    Code signing, 2FA, and reducing dependencies are all incomplete solutions. What we need is fine-grained sandboxing, down to the function and type level. You will always be vulnerab…

  6. comment
    Comment #44978407

    It's true that we were all sold the lie of individual actions being the way to solve the climate crisis (recycling, turning off lights, etc.) But I think the conclusion is to try o…

  7. comment
    Comment #44946206

    The ideal situation would be building a society that believes everyone deserves to be fed, clothed, and housed regardless of their ability to make profitable things. Weird how poli…

  8. story
  9. comment
    Comment #43967875

    This seems to only address a few of the nine threats to the software supply chain, mainly "(D) External build parameters" and maybe the content-addressable storage addresses some o…

  10. comment
    Comment #43957294

    BNPL is only "good" if your definition of "good" is about GDP, market flexibility, high-performance index funds, and other things that have nothing to do with human happiness. I'll…

  11. comment
    Comment #43927971

    People have been running different levels of privileged code together on the same machine ever since the invention of virtual machines. We have lots of lightweight sandboxing techn…

  12. comment
    Comment #43927848

    Every action gets these permissions by default. The reason we know it had that permission is that the exploit code read from /proc/pid/mem to steal the secrets, which requires some…

  13. comment
    Comment #43925947

    This has some good advice, but I can't help but notice that none of this solves a core problem with the tj-actions/changed-files issue: The workflow had the CAP_SYS_PTRACE capabili…

  14. comment
    Comment #43860256

    Amazon really encourages valkey in the elasticache dashboard. There's a banner advertising lower prices and it's listed first in the dropdown when you go to create one. Default set…

  15. comment
    Comment #43727299

    I think this article describes the issue well: https://crankysec.com/blog/community/ > All the cybersecurity companies saying "We don't have anything to say about this situation." …

  16. comment
    Comment #43692108

    On its own, immutability isn't a complete solution to supply chain attacks. Software still needs to be updated and those updates could contain malware too. You need immutability an…

  17. comment
    Comment #43658135

    I've seen this more formalized as a triangle, with "functionality" being the third point: https://blog.c3l-security.com/2019/06/balancing-functionalit... You can get secure and eas…

  18. comment
    Comment #43434592

    The effort to replace US tech is not anything similar to the European tech industry. US technology has a hegemony because we were first to the party, our economy is larger, and our…

  19. comment
    Comment #43429484

    > you're going to personally be better off changing companies Job mobility for tech workers is a fluke of current economic conditions. If interest rates spike, or a recession happe…

  20. comment
    Comment #43429165

    There's no reason why tech unions can't have solidarity with other unionization efforts (and there are thousands of reason why we should have that solidarity). Us tech workers coul…

  21. comment
    Comment #43374050

    Thanks for the edit! In "incident response mode" every moment counts!

  22. comment
    Comment #43373052

    The advertising in this article is making it actively difficult to figure out how to remediate this issue. The "recovery steps" section just says "start our 14 day free trial". The…

  23. comment
    Comment #43310861

    I think declining an exit interview is bad advice for the exact same reason that venting during an exit interview is bad advice. Declining makes you look obstinate and can be used …

  24. comment
    Comment #43139903

    No discussion of language loss is complete without mentioning the hundreds of indigenous languages that were eradicated by force: > "Funded by the federal government and contracted…

  25. comment
    Comment #42899346

    There's not a lot of "breaking down" happening here. It's the same vague recommendations that can be found in the NSA's own documents, further reinforcing the gap between the guide…