Posts by icing@chaos.social
(DIR) Post #B66w5kyqlf8WeOck40 by icing@chaos.social
0 likes, 0 repeats
@ariadne unless you have an ACME client that can be configured with a fallback ACME provider.(but your point remains valid. the number of ACME CAs seems to be shrinking, LE being just too good)
(DIR) Post #B69ZQ15QscoSvIH3hI by icing@chaos.social
1 likes, 1 repeats
Apache httpd decided to close all ancient bug reports (I proposed this like a decade ago) and now I got 1044 mails in my inbox.Thanks?😅
(DIR) Post #B69aJDMQwjhkuyXxI0 by icing@chaos.social
0 likes, 0 repeats
@wolf480pl not that I know. In #curl you would make a PR with a new testcase, linking to an issue report.The closing when that passes is the easy part.
(DIR) Post #B6DBeVZwgfChHNlOT2 by icing@chaos.social
0 likes, 0 repeats
Details and timeline of the Ubuntu DoS attack and the „helpful hand“ of Cloudflare.https://www.flyingpenguin.com/can-someone-please-explain-whether-cloudflare-blackmailed-canonical/
(DIR) Post #B6JcVSoPT3PfnrCTKa by icing@chaos.social
1 likes, 0 repeats
First of all, *most* of FOSS security reports nowadays (that I see in #curl and #apache httpd) are non-threatening.They are edge cases under highly constructed preconditions. Yes, not impossible, but unlikely to be ever encountered.Before LLMs, no researcher would have invested the time to explore those scenarios. my guess.Yes, we fix them. But, they could also have been a bug report.💁🏻♂️
(DIR) Post #B6Rl7bH8npxXxD0wWe by icing@chaos.social
0 likes, 0 repeats
@ariadne Let‘s say it like this: if your primary motivation is money, you are not a ‚founder‘.
(DIR) Post #B6RlVtgO16zZzcPMxc by icing@chaos.social
0 likes, 0 repeats
@ariadne we can extend it to ‚money/fame‘ maybe?Edit: nvm, I am too fed up with the world rn to think about this. peace out.✌️
(DIR) Post #B6eGdI8ytj5aMRJArg by icing@chaos.social
1 likes, 2 repeats
‚Torvalds added, in the case of AI-discovered bugs, you need to keep in mind that just "because you found it with AI, 100 other people also found it with AI."‘There is nothing secret about a bug found by a model. If the software is a target, you can be sure that the bad guys are running continously prompts against it. Without token restrictions.As a maintainer, this is all hard to manage. But this is happening everywhere. It‘s not your job to save the world from stupidity, vanity and greed.
(DIR) Post #B6kKYY9dzFwuhJ7feK by icing@chaos.social
0 likes, 0 repeats
@ariadne if Azure ever figures out to serve http reliably, they‘d become…uhm…better than now, at least.💁🏻♂️
(DIR) Post #B6kM2XtvasawYLdf4C by icing@chaos.social
0 likes, 0 repeats
@ariadne there is a certain flavour of tech that never worked when I tried them.It used to be that when asking experts for help with these, you‘d get UI screenshots embedded in Excel files with scribbles of where to click. Which were almost uptodate.They don‘t do that anymore with Excel now, so it‘s harder to spot.😌
(DIR) Post #B6oavWgvy6bQieVm0u by icing@chaos.social
0 likes, 1 repeats
This is @samueloph being asked to revert to the pre-vibe rsync in Debiam. @ariadne plans to switch to openrsync in Alpine.Important decisions to be made here.It‘s about trust, not technology. rsync has earned trust over the years. Now it has increased changes using Claude with no second person reviewing.That people feel uneasy about this, for a tool that copies exabytes of important data every day, is very understandable.The LLM is the minor player here.https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138239
(DIR) Post #B6qcFr1uY6kBrLV4lM by icing@chaos.social
0 likes, 0 repeats
@bsdphkThanks for the insights.As @samueloph pointed out, the problems existed before LLMs entered the scene and your description confirms that.Until the FOSS funding problem gets solved (haha!), maybe openrsync is better for distributions.For someone who has invented the whole thing, this must suck though.@ariadne
(DIR) Post #B6v4dLpXm3vzOXY1DM by icing@chaos.social
0 likes, 0 repeats
@ariadne The dream where one no longer needs to *do* something. It is enough to *want* something.Back to being a toddler.🤱
(DIR) Post #B7Ru9IEN2QOiRYfiO8 by icing@chaos.social
0 likes, 0 repeats
@ariadne The models are good at figuring out inconsistencies in all code path possibilities.Threat model evaluations, not at all.
(DIR) Post #B8CjcTmPFPjWJVvaPQ by icing@chaos.social
0 likes, 0 repeats
@ariadne @sigmasternchen this is the future.
(DIR) Post #B8Ht3FwqEEgBq610E4 by icing@chaos.social
0 likes, 0 repeats
@ariadne I have bad news for you regarding Tokio Hotel.
(DIR) Post #B8MdmLMKRd4aDbNi9g by icing@chaos.social
0 likes, 0 repeats
@ariadne They are very good at bean counting PRs. Checking the stuff that makes human eyes glaze over.They, of course, have no idea if a PR is a good idea, sound design or propose alternate approaches.useful bean counters😌
(DIR) Post #B8aOuvfhEekDr0zoAK by icing@chaos.social
0 likes, 0 repeats
@ariadne do everything less, smell the roses.
(DIR) Post #B91MPNRAXY0XXpEYIy by icing@chaos.social
0 likes, 0 repeats
@ariadne Surely, a few visionairy, white, male people could tell people what to tell all the other people what to do to solve any and all problems.It‘s not that complicated.💁🏻♂️
(DIR) Post #B9tDJqElJvSc83NPAu by icing@chaos.social
0 likes, 0 repeats
@stux And the sun rises in the west!