Preferences

tkinom
Joined 484 karma
tkinom.lee@gmail.com

  1. Can we design something like virustotal setup? (https://en.wikipedia.org/wiki/VirusTotal)

    NPM setup similar dl_files_security_sigs.db .database for all downloaded files from npm in all offline install? List all versions, latest mod date, multiple latest crypto signatures (shar256, etc) and have been reviewed by multiple security org/researchers, auto flag if any contents are not pure clear/clean txt...

    If it detects anything (file date, size, crypto sigs) < N days and have not been thru M="enough" security reviews, the npm system will automatically raise a security flag and stop the install and auto trigger security review on those files.

    With proper (default secure) setup, any new version of npm downloads (code, config, scripts) will auto trigger stop download and flagged for global security review by multiple folks/orgs.

    When/if this setup available as NPM default, would it stop similar compromise from happen to NPM again? Can anyone think of anyway to hack around this?

  2. As Dr. Ian Malcolm said it: “Your scientists were so preoccupied with whether they could, they didn’t stop to think if they should.”
  3. About right, did it two years ago with 2 Sockets, 128Cores (64 core per socket), 256 Threads 2 Epyc Motherboard with 1TB DDR4. Build Kernel < 90 seconds. Should be faster nowadays....
  4. Another idea for them: Walkatron for NFTs token for "....." causes....
  5. RPi+ Yolo can do real time object recognition of cluster Tank, Trucks, BMP from orbit.

    A service with real time streams of those objects + GPS data info directly from starlink for a select sets locations should worth a lot for DOD, NATO, Ukraine. DOD and NATO would likely flip the bill for everything need to build such system.

  6. Love to see a container environment that can monitor Monitor and log all outgoing network connection requests.... Monitor and log all critical file/directory access such as /etc/*

    With such container, we can catch the compromised supply-chain attach easily, right?

    Does anyone know such container exist?

  7. There should be some post post-processing algorithms that can remove/clean hex elements, right?
  8. Got Honda Clarity PHEV since 2018. Loving it so far. It is 48 miles E range. I need ~36 for round trip daily commute. Charging at work is free. I remember only fuel up only 3 times in 2019 with the 7 gallon gas tank. Normal fuel up is 5-6 gallon only as it has a very small tank. But the Hybrid range is supposed to be 350 miles.

    I also just installed solar at home. I expect the next family car would also be PHEV suv to replace the 16 years old minivan. Other than long trip, I don't expect to use gas much, maybe just once a week to oil up the engine for a few minutes.

  9. Fog of war.
  10. I have written time series logging db with sqlite believe that approach has following advantages:

       System performance scales well with latest SSD HW.
          As compare to cloud base approach that is limited by network/cloud speed.
    
       One can store logs per day / week / year in separate db files as needed.  
    
       Backup of small db files for last few days/weeks are trivial with rsync.
    
    
    
    Love to hear other pro/con arguments from folks who use Timescale type approach.
  11. One can easily cut the zip-tie, search and re-zip it again, right?
  12. Start by tracing exist open source Intel/AMD driver in linux:

       Can be for old laptop (T420, etc with Intel GPU/Driver.) 
       Use FTRACE in kernel. 
       Setup ebpf trace for GPU acitivies.
       Write some doc/blog/medium pages on the process and show off your works.
       Understand, document and improve some opensource GPU API related utilities
       Understand and document interaction between GPU/GUI App and OpenSource driver.
    
    
    
    In term of jobs: AMD has 289 opening for intern positions: https://jobs.amd.com/go/Internships-&-Co-op-Opportunities/25... A lot of them are graphic related.
  13. Love to see compiler benchmark (compile firefox, chrome) on this vs system with EPYC 64C/128T or 128C/256T.
  14. Name the project "SETI@PI"?
  15. Religion can help? - I have a Mormon co-worker. They have 8 kids. Move whole family to Japan. Told me that every time they came home to US they took a row in the wide body Jet.
  16. I love the fact they can convince VC to spend $80mil to try this.

    20 year ago, most of space experts probably laugh at SpaceX for even trying to reuse the rocket by landing it back on earth vertically.

  17. Old Programming Languages never die, they just fade away.
  18. For anyone who like to hack legally and ethically, check out https://www.hackerone.com/. If you're very good at hacking devices, software, networks, etc, companies will pay bounties for the vulnerabilities you find thru HackerOne.

    Looks like they paid out millions in bounty in 2020:

        https://www.zdnet.com/article/hackerones-2020-top-10-public-bug-bounty-programs/
  19. Commander BGP (aka DATA) entered the "sleep" command. The faceborgs found they can't enter building, connect to the collectives or take over the Galaxy.

This user hasn’t submitted anything.

Keyboard Shortcuts

Story Lists

j
Next story
k
Previous story
Shift+j
Last story
Shift+k
First story
o Enter
Go to story URL
c
Go to comments
u
Go to author

Navigation

Shift+t
Go to top stories
Shift+n
Go to new stories
Shift+b
Go to best stories
Shift+a
Go to Ask HN
Shift+s
Go to Show HN

Miscellaneous

?
Show this modal