Hacker Newsnew | past | comments | ask | show | jobs | submit | foul's commentslogin

Then they start to use their "well-earned" money to bend the world to their worldview, but "it's their right!". Of the people you bring up, i've been affected just by Musk (his endeavours are a net contributor for global warming), I'm still suspecting you should get fucked with your freely expressed opinion.

It has its share of vulnerabilities but flaws in core are rarer, more (a lot more) (i swear to god a LLM would be better) in the modules ecosystem. Also like most CMSes they are still vulnerable to what i call the "webapp bug" (you install this blob on a hosting that should not be aware of what you dump on there and allows you to run a php file on any subdir, while with a CMS, whatever you use, only a very limited number of files should be allowed to be reached, executed or even included in any php call).

All I remember with Joomla! is that it was really, really susceptible to the “plugin we use is abandoned and not updated and the new version of core is completely incompatible” causing everyone to run various out of date packages with stupid security layered on top. Web application firewalls are an abomination.

Ahahah I remember to have patched themes for clients by hand, years ago. A different time, where a core team would for whatever reason leave security holes around to be sure you need three frameworks around their pile of dung code.

pearcmd and register_argc_argv are just examples. get_page_template was unsanitized in some themes, that's the flaw, you could then combine it with one of a million unauthorized file upload in wordpress plugins to try and eval code. An attacker would like to use upload + this chain of requires (instead of just uploading a php) because of hardened configuration and the pwn can go unnoticed in the logs.

Also, with pearcmd (if you can get to that, there's no open_basedir) and containers a novice sysadmin will publish insecure sites.


How are things going with V btw? In the past i've seen some bad press about this programming language.

It was nice to use when I tried to dabble with it.


My understanding:

- The bad press was because the initial public release on GitHub did not implement most of the things seemed like they're implemented, (Rust like memory safety etc.)

- Over time it actually saw contributions from a lot of people and is kind of decent now, be it not as polished as Go, Rust, D etc.

- It is super easy to use, so kind of attracts an audience.


The bad press was because after some people tried to call them out for not shipping features that were claimed in the release, those people were banned from further contribution/commenting on github.

Only one person, who said "V must die", was banned.

And the lead dev would come into any thread on HN or Reddit and argue with people.

Ouch. That's definitely worse than I assumed.

Disagree with the first point. A lot of the so-called "bad press" came very directly from competitors. To the extent that it looked like they were trying to snuff out a rising new language or were arguably engaging in slander, because it seemingly was a threat to the popularity of their own creations.

Any just released language (talking about when it came out back in 2019), is not going to be polished. That should be common sense. I've never seen a first release alpha of any language be polished or not have have things in a state of partial implementation. 0.1 is not 1.0.

> Over time it actually saw contributions from a lot of people and is kind of decent now

True. At present, they have 846 contributors and over 2,300 forks on GitHub.

> It is super easy to use, so kind of attracts an audience.

Agree. Ease of use is one of its attractive features. Very much geared towards getting people started, even newbies to programming, and doing useful things.


It still compiles in 0.5s:

https://www.youtube.com/watch?v=vV-mzTDUpAI

10k+ bugs fixed, only ~40 open github issues.


Hi Alexander, cool! Will return to dabble with it.

That's such an outlandish idea! What made you suspect this? (sarcasm)

I do use AI but whenever I use it from third person view or diff POV ,it feels like very dumb to use

Meta should just close. It's like wanting to change CEO for the dioxin factory.


Maybe they should rebrand again. It took a few renames to get the stink off of Blackwater (private military contractor).


Closing sale! 50%+ Off Sale on data for the majority of humans on Earth!


The idea of that data ending up in new undetermined hands may-or-may-not be a worse thing, but it reminds me of this bit from Making Money, by Terry Pratchett:

> 'Vetinari, are we to believe that you knowingly put the most important bank in the city into the charge of a known bank robber?'

> [...] 'Should he have left it in the hands of unknown bank robbers?'


Is your username a reference to Terr_ _________?


I don't understand the question/joke.


Terry Pratchett sorry


Ah no, that'd be kinda —ing presumptuous of me.


  >Like, how could two-way links work? I mean, they can't, obviously? Links go 
  >around text, so they have to live on a document. The author here mentions spam, 
  >but there's a far simpler structural problem that making links two-way means 
  >the links have to be stored... say it with me folks, as a stream of annotations 
  >on top of the underlying text! Links would go "on top of" your document, 
  >linking word 153 of paragraph 4 of document A onto word 96 of paragraph 13 of 
  >document B.
  >
  >But what happens if document B changes? Then it's going to have invalid 
  >backlinks! Well, it does work, because in Xanadu... all the documents you write 
  >would be transclusions of a "permascroll". Everything you ever write goes in 
  >the permascroll and then your Xanadu client would transparently publish a 
  >transclusion of your edited document. So "word 96 of paragraph 13 of document 
  >B" somehow gains actual referential integrity across changes to the document.
If I recall correctly, the site you browse in hypotetical Xanadu-land has to mirror the reference (for transclusions) and get downloaded back (for two-ways links). Payments and that levy system are there because without some freedom to copy content you get dead links with extra steps.


> it seems fairly clear that A/I was providing services to organizations listed as Terrorist Organizations by the US, UK, and Canada.

It isn't fairly clear, there's no due process, there are no proofs or clues, only Trump's and Shideler's word on that.


Anyone from a nation that signed the Statute of Rome. Guess what, USA not only hasn't joined the ICJ but has historical laws in place that will make them intervene even with military force to free a US citizen in the hands of the ICJ.


That isn't how the Statute of Rome works. The Statute of Rome applies to things done on the territory of signatories.

So if a US person has operated in the territory of a signatory, and committed something suspected to be a covered crime, and there is no US attempt to prosecute them, they can be prosecuted.

The US militarily can't intervene. They don't have the capacity to fight the Dutch, or French or the like, and the political cost of attacking other NATO countries is of course enormous-- it would be the end of the US as a superpower and lead to an actual EU-US war which would probably last for decades. There's a reason the US Servicemen Protection Act has an out, that it doesn't require any action. Think of it, not as a real policy, but as a dog making sure there's a fence between it and another dog before it starts barking.


*ICC(International Criminal Court aka Hague established 1998/2002) not the ICJ(International Court of Justice aka World Court established 1946) they are different entities , hence the Hague Invasion Act from the US.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: