Hacker Newsnew | past | comments | ask | show | jobs | submit | mobeigi's commentslogin

So TempleOS was ahead of its time!


I enjoyed the reference more than the story itself :)


I saw a recent post about only adopting packages a certain number of days post release (say +3 days, or +7 days) after. The idea is you never bring in fresh commits, only older ones. This would need dangerous or bad commits to be marked vulnerable too.

It means you skip supply chain attacks but may miss fresh vulnerability patches too.


You only miss supply chain attacks that are eager to begin exploiting. If everyone begins waiting a week to update dependencies, attackers just need to wait 2 weeks before actively using their attack vectors.


I'd very much like to learn more about this too, deserves its own blog post.


I've made the same exact SVN mistake. My first week in my first Software Engineering job, accidentally deleted trunk and my team lead had to scramble to fix my mistake.

I will always remember how he told me "Don't worry, it happens fairly often".


Been using Claude as a harness to OpenRouter for a while now. It's a nice setup if you don't mind API based billing.


I wish people wouldn't abuse the author of that project over this. Giving them the benefit of the doubt in that this was a mistake and not intentionally malicious, it feels really bad for hundreds if not thousands of people to send hate, insults, abuse to a single individual. Shame on the people who are doing that.


The only way you can consider this a mistake is by not having read the github comments here: https://github.com/notepad-plus-plus/notepad-plus-plus/issue...


I think you need to do a little more research before you give the poor, poor little author of 'that project' a pass.


Such a feel good post, thanks for sharing OP!


This was not on my bingo card. Not sure why eBay would take this personally. They've had a solid couple of years and there is room to grow. Gamestop on the other hand I'm not sure will exist in 10 years.


Valve's VACnet solution is definitely interesting. It uses AI, deep learning and is server side. It's hard to tell how effective that has been for them compared to traditional client side detection systems; I don't imagine they'll share any results.

The fact that it's completely hidden from cheat developers gives them a huge advantage though. In the past, any client side algorithm or detection method could be reversed engineered by cheat developers and patched before lunch time. Now they're working against Valve completely in the dark.


Which is a the power of not relying on obscurity. The server not sending you its complete source code is not any more obscure than a secret key.

Security through obscurity is about obfuscating easy-to-recover trivia thinking it buys you any margin, like the client-side anti-cheat handing attackers everything they need to defeat it while trying to then obfuscate that code.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: