Viewing profile — terom
terom
HN member- Joined
- Thu, Feb 04, 2016, 10:56 AM UTC
- HN karma
- 1,678
- Public activity
- 253 items
- HN profile
- View on Hacker News ↗
About terom
Recent public activity
-
comment
Comment #47573442
https://x.com/telegram/status/2038069726316834994 Telegram claims that exploitation of the vulnerability is blocked by server-side validation of stickers
-
comment
Comment #46304679
I haven't seen a serialization exception, but I have run into plenty of footguns with YAML (ref GitHub Actions). The DSL semantics can be weird with when things like params/env exp…
-
comment
Comment #46302401
Working with Jenkins CasC, JobDSL and declarative pipelines, I'm not sure where the million times comes from. Sure, there are some annoying parts, and GHA has the social network fo…
-
comment
Comment #46159590
downdetectorsdowndetector.com does not load the results as part of the HTML, nor does it do any API requests to retrieve the status. Instead, the obfuscated javascript code contain…
-
comment
Comment #45709333
re-search :D
-
comment
Comment #44548533
Also with additional control difficulty due to reduced hydraulic pressure. > On the Boeing 767, the control surfaces are so large that the pilots cannot move them with muscle power…
-
comment
Comment #44262518
From the Cloudflare incident: > Cloudflare’s critical Workers KV service went offline due to an outage of a 3rd party service that is a key dependency. As a result, certain Cloudfl…
-
comment
Comment #44050703
Based on [1] it seems like one `management.endpoints.web.exposure.include=*` is enough to expose everything including the heapdump endpoint on the public HTTP API without authentic…
-
comment
Comment #43910474
Going a bit further, it seems like there's a grain of truth here, HTTP/2 has a stream priority dependency mechanism [1] and this report [2] from Imperva describes an actual Depende…
-
comment
Comment #43910146
The git commit hashes in the diff are interesting: 1a2b3c4..d4e5f6a I think my wetware pattern-matching brain spots a pattern there.
-
comment
Comment #43820990
Portugal has an even bigger relative drop in load, from 5852MW at 11:00 hours -> 613MW at 13:00 hours - these seem like 1 hour averages. [1] https://transparency.entsoe.eu/load-dom…
-
comment
Comment #43820635
That graph doesn't seem to make a very clear distinction between historical, real-time and predicted values... I think the event happened at 12:30 local time or so. There seems to …
-
comment
Comment #43820442
It looks like the Iberian peninsula is relatively isolated from the rest of the CESA synchronous grid, with only 2% cross-border capacity compared to local generation. [1] There's …
-
comment
Comment #43536786
https://news.ycombinator.com/item?id=43486945 related
-
comment
Comment #43491356
Yeah, you have to move it off-planet to achieve an actual security boundary. In our threat model the upper bound on the useful lifetime of the system is limited by the light-distan…
-
comment
Comment #43206013
Yeah, and that makes sense in the context of an acceptable use policy for Mozilla services that are not your use of the Firefox browser. But the same AUP for the services is now ex…
-
comment
Comment #43205510
Wait, Mozilla is banning the use of their Firefox browser for porn? That's going to hurt adoption. What's with the mixup of their browser and services policies? [1] Your use of Fir…
-
comment
Comment #43169381
It's fascinating that we've built a system that has expended perhaps several million dollars of engineering, legal and admin etc time over the issue of a single letter not being ca…
-
comment
Comment #41748811
These are technically kinda crazy, because they use a normal schuko plug (with male pins) to output power. It allows loading the circuit with a higher total ampacity than the circu…
-
comment
Comment #41678603
Renewing the certificates seems technically pointless, but some organizations/federations require it. Rotating the keys would make some sense, but just swapping the cert for a new …
-
comment
Comment #41007968
The title seems incorrect, per Comment#10 https://bugzilla.mozilla.org/show_bug.cgi?id=1877388#c10 all missued certificates were eventually revoked > 2024-01-22 > 08:25 The error m…
-
comment
Comment #41007753
https://old.reddit.com/r/crowdstrike/comments/1e6vmkf/bsod_e... quotes the CrowdStrike advisory verbatim, which has timestamps of 04:09 UTC for the problematic version and 05:27 fo…
-
comment
Comment #41006890
"post-processing step" aka regex? :) HN comments from a green username citing a friend who knows someone aren't the greatest source, but this sounds so believeable
-
comment
Comment #41006371
https://azure.status.microsoft/en-us/status/history/ doesn't seem to have links to the individual incidents. Some reports claim the Azure / Microsoft 365 outages were related to cr…
-
comment
Comment #41006311
Reboot harder. > Update as of 10:30 UTC on 19 July 2024: We have received reports of successful recovery from some customers attempting multiple Virtual Machine restart operations …