Hacker Newsnew | past | comments | ask | show | jobs | submit | spyc's commentslogin

The current implementation breaks semantics of functions with tail recursion from within loops: https://github.com/raaidrt/tacopy/issues/1


Potentially the movie itself is also or more of interest. The related thread is: https://news.ycombinator.com/item?id=45056377


Both implementations of doas for Linux have (the same) unfixed security issue:

- https://github.com/Duncaen/OpenDoas/issues/106

- https://github.com/slicer69/doas/issues/110

I have a hard time recommending doas over sudo on Linux when the issue has been fixed in sudo but not in doas.


Those should be closed WONTFIX. Neither doas nor sudo can protect you from the consequences of running untrusted code and must not attempt to do so because it adds needless complexity to safety-critical software.


Which distros still have TIOCSTI enabled in their kernel? I just checked for Arch and it's disabled.


Lost trust for sure. Who knows if Redis would be AGPL now if Valkey did not exist.


If anyone wonders what atop looks like at runtime or what it would be useful for, there's a video dedicated to the tool at https://www.youtube.com/watch?v=27AtCR5ftyM .


I'm reading "I can go into why another time." like "I don't have time" personally, not like "I am not allowed to say".


Then you are overlooking two things that provide important context: her previous behavior in similar circumstances of discovering bugs, and the opening sentence:

> My life as a mercenary sysadmin can be interesting.

To me this reads as "I was hired as a consutant for something that required a very restrictive NDA."


Hi! Three things:

- There is no commit with a SHA1 like that in atop Git history and what you shared is too long for a SHA1, it looks more like a SHA256. Did you share the right checksum? The only other way I can read this is that it's a SHA256 checksum of one of the past atop release tarballs or artifacts. I have not yet checked those.

- I have tried finding your tool Bismuth but all I find is things KDE and crypto currencies. Please share a link to the Bismuth that you are working on.

- You technically said that you are working on Bismuth /and/ found something, not that you found the bug /through/ Bismuth. Please clarify if and how that was the case.

Thank you!


- That SHA is just a proof marker so if it turns out we are correct we can prove we had it at that time

- Bismuth did indeed find the bug, our bug scanning feature in particular. Obviously we're going to sit on our hands until the maintainer gives the all clear but we'll write something up after this is all squared away

- https://www.bismuth.sh is our tool, we're still relatively new


pretty sure it's just a hash of some text they can reveal later, to prove that they had something at this point in time. not referring to any release or commit


This is exactly correct


I see, thanks!



Thank you!


Thanks for sharing that research!


"Quickly kill the process" is still a denial of service security problem.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: