Hacker Newsnew | past | comments | ask | show | jobs | submit | fidget's commentslogin

Yeah, we really should rewrite the kernel.


Err, that is not an excuse. That just leads to the question of why there is a second kernel metastasizing in userspace.


Was already done, many times. Device drivers is the issue it never took off.


That's GRSecurity for you


Man, I've got some horrible news about your CPU.



There are other bad things about ssh. Tofu sucks balls and ssh users are far too comfortable with it.


Had to look it up. https://en.wikipedia.org/wiki/Trust_on_first_use

What would you replace it with?


Signed keys. Here's an example of how to do it from Digital Ocean: https://www.digitalocean.com/community/tutorials/how-to-crea...


Well, feel free to come up with a better solution. 3rd party trust roots are way worse.


The server key can be signed by a trusted authority, no need to trust on first use.


Doesn't particularly make a difference, given that this issue is about users not upgrading (for whatever reason) their windows XP installations. Would the exploit having being disclosed by the NSA or by someone else have changed the fact that these users would not have upgraded and gotten a patch?


Can I have my cake and eat it too?

People should keep systems under their responsibility up to date.

And people should disclose security vulnerabilities.


Um, a LOT of drivers broke on the change from XP to Vista.

If you controlled a piece of hardware, you may not have had a choice to upgrade.

The lesson is that closed-source is anathema to a good security policy.


His arms and influence is also changed the way I view conflict between states.


It's not strongly coupled beyond requiring that the wrapper implement a `Cause() error` method. I don't really think that could ever be considered strong coupling


So short it


Exactly, they are still at almost $20B in quarterly ad revenue. Facebook is their only competitor because of its captive and mobile audience. Plus they are already diversifying with more bets on the cloud plus things like Waymo, etc.

Edit: misquoted data thinking it was yearly not quarterly.


More like nearly $80 billion in yearly ad revenue. $20 billion is their profit.


Please let me know where you work, so I can avoid any product potentially produced by you.


Are you suggesting that you had a concurrency bug that was solvable without changing your entire storage layer? Heresy..


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: