Viewing profile — cyrnel
cyrnel
HN member- Joined
- Sat, Jul 01, 2023, 10:54 PM UTC
- HN karma
- 392
- Public activity
- 92 items
- HN profile
- View on Hacker News ↗
About cyrnel
No profile information was provided.
Recent public activity
-
comment
Comment #45617769
The response to that: https://andre.arko.net/2025/10/09/the-rubygems-security-inci...
-
comment
Comment #45455233
Both are billion dollar companies, we as individuals have nothing in common with them. Enshittification happens due to market conditions that apply to small and large companies ali…
-
comment
Comment #45452150
+1 for Node-RED. If we've learned anything from elasticsearch/redis/bitnami/and dozens of others, it should be "don't build important things on code that isn't enshittification-res…
-
comment
Comment #45367264
I know, right? It's sycophancy. If you are actually against the policy and suspect a lot of people are too, then don't silence your employees by keeping their feedback isolated to …
-
comment
Comment #45270758
Code signing, 2FA, and reducing dependencies are all incomplete solutions. What we need is fine-grained sandboxing, down to the function and type level. You will always be vulnerab…
-
comment
Comment #44978407
It's true that we were all sold the lie of individual actions being the way to solve the climate crisis (recycling, turning off lights, etc.) But I think the conclusion is to try o…
-
comment
Comment #44946206
The ideal situation would be building a society that believes everyone deserves to be fed, clothed, and housed regardless of their ability to make profitable things. Weird how poli…
- story
-
comment
Comment #43967875
This seems to only address a few of the nine threats to the software supply chain, mainly "(D) External build parameters" and maybe the content-addressable storage addresses some o…
-
comment
Comment #43957294
BNPL is only "good" if your definition of "good" is about GDP, market flexibility, high-performance index funds, and other things that have nothing to do with human happiness. I'll…
-
comment
Comment #43927971
People have been running different levels of privileged code together on the same machine ever since the invention of virtual machines. We have lots of lightweight sandboxing techn…
-
comment
Comment #43927848
Every action gets these permissions by default. The reason we know it had that permission is that the exploit code read from /proc/pid/mem to steal the secrets, which requires some…
-
comment
Comment #43925947
This has some good advice, but I can't help but notice that none of this solves a core problem with the tj-actions/changed-files issue: The workflow had the CAP_SYS_PTRACE capabili…
-
comment
Comment #43860256
Amazon really encourages valkey in the elasticache dashboard. There's a banner advertising lower prices and it's listed first in the dropdown when you go to create one. Default set…
-
comment
Comment #43727299
I think this article describes the issue well: https://crankysec.com/blog/community/ > All the cybersecurity companies saying "We don't have anything to say about this situation." …
-
comment
Comment #43692108
On its own, immutability isn't a complete solution to supply chain attacks. Software still needs to be updated and those updates could contain malware too. You need immutability an…
-
comment
Comment #43658135
I've seen this more formalized as a triangle, with "functionality" being the third point: https://blog.c3l-security.com/2019/06/balancing-functionalit... You can get secure and eas…
-
comment
Comment #43434592
The effort to replace US tech is not anything similar to the European tech industry. US technology has a hegemony because we were first to the party, our economy is larger, and our…
-
comment
Comment #43429484
> you're going to personally be better off changing companies Job mobility for tech workers is a fluke of current economic conditions. If interest rates spike, or a recession happe…
-
comment
Comment #43429165
There's no reason why tech unions can't have solidarity with other unionization efforts (and there are thousands of reason why we should have that solidarity). Us tech workers coul…
-
comment
Comment #43374050
Thanks for the edit! In "incident response mode" every moment counts!
-
comment
Comment #43373052
The advertising in this article is making it actively difficult to figure out how to remediate this issue. The "recovery steps" section just says "start our 14 day free trial". The…
-
comment
Comment #43310861
I think declining an exit interview is bad advice for the exact same reason that venting during an exit interview is bad advice. Declining makes you look obstinate and can be used …
-
comment
Comment #43139903
No discussion of language loss is complete without mentioning the hundreds of indigenous languages that were eradicated by force: > "Funded by the federal government and contracted…
-
comment
Comment #42899346
There's not a lot of "breaking down" happening here. It's the same vague recommendations that can be found in the NSA's own documents, further reinforcing the gap between the guide…