Live data from Hacker News

Viewing profile — insanitybit

insanitybit

HN member
Joined
Fri, Sep 16, 2022, 4:57 AM UTC
HN karma
4,589
Public activity
1,874 items

About insanitybit

Mastodon: https://infosec.exchange/@insanitybit Github: https://github.com/insanitybit

Rapid7 -> Dropbox -> Grapl -> Datadog

Recent public activity

  1. comment
    Comment #49219465

    It's not that companies won't pay for it, it's that it is banned . Legal teams at these companies set the policy.

  2. comment
    Comment #49219459

    The issue is that AGPL is flatly banned at many companies, so now any company that even wants to test this database out is going to have to seek a contract, which they won't.

  3. comment
    Comment #49219409

    People have rapidly adopted far less tested databases when the dbs have claimed to solve real problems.

  4. comment
  5. comment
    Comment #49212496

    Sure, that seems reasonable enough. I'm pretty skeptical that it will happen, but it's not like it's impossible.

  6. comment
    Comment #49196218

    I'm not debating you at all. I'm asking what the model looks like since you've stated (and I've agreed) that a language model wouldn't work. I think it would make sense to explain …

  7. comment
    Comment #49192364

    And I'm asking you to describe the model.

  8. comment
    Comment #49192250

    It's unclear what you are talking about then. Because the idea of training "ciphertext -> plaintext" for language models is absolutely bonkers, so what are you suggesting?

  9. comment
    Comment #49191454

    I'm referring to the first selection process.

  10. comment
    Comment #49189960

    How much am I expected to charitably interpret the joke? They said "only", I'm taking it at face value because it's obviously intended to be commentary and the obvious implication …

  11. comment
    Comment #49186092

    > No way to prevent this says only package manager where this regularly happens "only"

  12. comment
    Comment #49185174

    Only if the jury believes in nullification, which isn't common. The jury is instructed to follow the law. The selection process asks "even if you think they were right, if it's aga…

  13. comment
    Comment #49185057

    That axiom is clearly false. AI can interact with external systems, which means it is not just compressed knowledge - it has the ability to access new information.

  14. comment
    Comment #49174152

    left-pad is totally irrelevant to this conversation.

  15. comment
    Comment #49174137

    Yes, it has nothing to do with the design of npm (relative to similar languages/ repositories) and everything to do with the popularity.

  16. comment
    Comment #49174129

    I just don't think that this is that unique to javascript, it's absolutely not about npm, and I don't think that this is well supported as a relevant feature that leads to these at…

  17. comment
    Comment #49172659

    Yeah, my point is just that other package managers aren't in a great spot. NPM even lets you separate out "publish" and "release" now where you can publish to the registry but you …

  18. comment
    Comment #49172258

    No build script control though.

  19. comment
    Comment #49172194

    162k vs millions. That's not even getting into package update velocity, authorship, the totally divergent goals, etc. I just think it's utterly pointless to compare.

  20. comment
    Comment #49171904

    Debian's scale for package distribution is tiny and explicitly curated by maintainers. Everything funnels through Debian. The goals are completely different. Debian packages what's…

  21. comment
    Comment #49171879

    I think that's barely meaningful. Which of the compromised packages would have been part of any reasonable stdlib?

  22. comment
    Comment #49171260

    Ruby is worse. crates.io is arguably worse.

  23. comment
    Comment #49171250

    I don't consider these comparable in any way that's worthwhile. The scale and goals are completely different.

  24. comment
    Comment #49171245

    Arguably crates.io is worse. NPM has cooldowns and has for a while, it has had Trusted Publishing for longer, it has human-approved releases that separate CI/CD from actual publish…

  25. comment
    Comment #49171234

    Yep, I'd recommend it.