GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Tim Bray (timbray@cosocial.ca)'s status on Sunday, 21-Sep-2025 01:21:31 JST Tim Bray Tim Bray

    This is beautiful; pure poetry: https://obsidian.md/blog/less-is-safer/

    (Obsidian’s dependency-management philosophy.)

    I have a suggestion: If you have a project or repo that's getting popular, stop writing features for a few months and implement this instead.

    #softwaredevelopment #softwareengineering #0dependencies

    In conversation about 2 months ago from cosocial.ca permalink

    Attachments


    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Sunday, 21-Sep-2025 01:21:30 JST Paul Cantrell Paul Cantrell
      in reply to

      @timbray

      I do have to chuckle a bit when one of dependencies they list in their minimal, disciplined list is Electron — a behemoth of a black box with more complexity than some entire operating systems.

      In conversation about 2 months ago permalink
    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Sunday, 21-Sep-2025 02:03:09 JST Paul Cantrell Paul Cantrell
      in reply to
      • Dr. Juande Santander-Vela

      @juandesant @timbray
      I do agree to a large extent — or at least hope for it to be true! — but your sentiment suggests that •quality• of maintenance matters at least as much as the sheer •quantity• of dependencies.

      In conversation about 2 months ago permalink
    • Embed this notice
      Dr. Juande Santander-Vela (juandesant@mathstodon.xyz)'s status on Sunday, 21-Sep-2025 02:03:10 JST Dr. Juande Santander-Vela Dr. Juande Santander-Vela
      in reply to
      • Paul Cantrell

      @inthehands true, but that is indeed a large library, and that means it will only be updated consciously.

      /cc @timbray

      In conversation about 2 months ago permalink
    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Sunday, 21-Sep-2025 02:53:32 JST Paul Cantrell Paul Cantrell
      in reply to
      • Dr. Juande Santander-Vela

      @juandesant @timbray

      This set me off on a long train of thought, which I didn’t want to jam in your mentions but in case you’re interested: https://hachyderm.io/@inthehands/115237749357270051

      In conversation about 2 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Paul Cantrell (@inthehands@hachyderm.io)
        from Paul Cantrell
        Surfacing from replies (see context upthread). I’ve watched the pendulum swing back and forth multiple times in my career between “code reuse ftw!!” and “no dependencies!!” The one thing I can say with confidence is that both those extremes as dogma are ridiculous and costly. It’s all tradeoffs; you can’t escape the part where you think carefully and contextually. 1/ https://hachyderm.io/@inthehands/115237696859291899
    • Embed this notice
      jwz (jwz@mastodon.social)'s status on Sunday, 21-Sep-2025 03:45:57 JST jwz jwz
      in reply to
      • Paul Cantrell

      @inthehands @timbray It's important to stay bug-compatible with the WebP exploit du jour! https://jwz.org/b/ykEL

      In conversation about 2 months ago permalink

      Attachments


    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Sunday, 21-Sep-2025 03:45:57 JST Paul Cantrell Paul Cantrell
      in reply to
      • jwz

      @jwz

      Yuuuuuup.

      In conversation about 2 months ago permalink
    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Monday, 22-Sep-2025 05:05:35 JST Paul Cantrell Paul Cantrell
      in reply to
      • Shriram Krishnamurthi
      • Dr. Juande Santander-Vela

      @shriramk @juandesant @timbray
      I’m out of my depth here, and know nothing about OCAP systems applied to software. Can you say more? (Are we talking about out-of-control action plans here? Or is OCaps something else and I’m even more out of my depth than I think?)

      In conversation about 2 months ago permalink
    • Embed this notice
      Shriram Krishnamurthi (shriramk@mastodon.social)'s status on Monday, 22-Sep-2025 05:05:36 JST Shriram Krishnamurthi Shriram Krishnamurthi
      in reply to
      • Paul Cantrell
      • Dr. Juande Santander-Vela

      @inthehands
      But all this keeps pushing the issue back onto humans, and ignoring that there are technical solutions we can and should be implementing.

      POLA is a thing, and OCaps-type systems help us have our reuse cake along with our POLA confinement.

      I don't find the Obsidian post "beautiful" or "pure poetry"; I view it as a symptom of broken tools.
      @juandesant @timbray

      In conversation about 2 months ago permalink
    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Monday, 22-Sep-2025 05:31:15 JST Paul Cantrell Paul Cantrell
      in reply to
      • buherator

      @buherator @timbray
      Maybe? But if people are keeping sensitive data in their private Obsidian notebooks, exfiltration via a supply chain attack could be devastating.

      In conversation about 2 months ago permalink
    • Embed this notice
      buherator (buherator@infosec.place)'s status on Monday, 22-Sep-2025 05:31:16 JST buherator buherator
      in reply to
      • Paul Cantrell
      @inthehands @timbray my first thought too, but if electron is compromised obsidian would not be among our primary concerns (esp. because according to this policy they would likely not update before the incident is noticed). So I think electron is more of an attack surface problem than a supply chain one.
      In conversation about 2 months ago permalink
    • Embed this notice
      Shriram Krishnamurthi (shriramk@mastodon.social)'s status on Monday, 22-Sep-2025 06:11:08 JST Shriram Krishnamurthi Shriram Krishnamurthi
      in reply to
      • Paul Cantrell
      • Dr. Juande Santander-Vela

      @inthehands
      OCap = object capabilities
      Probably the best place to learn more is to follow pointers from here:
      http://www.erights.org/
      @juandesant @timbray

      In conversation about 2 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.erights.org
        Welcome to ERights.Org
    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Monday, 22-Sep-2025 06:11:08 JST Paul Cantrell Paul Cantrell
      in reply to
      • Shriram Krishnamurthi
      • Dr. Juande Santander-Vela

      @shriramk @juandesant @timbray ooooohh! Well, I was certainly barking up the wrong tree (and am still well out of my depth).

      I am always warm to any alternative to the current model of computing that starts with the assumption that every program should have privileges identical to the human who chose to install/run it.

      In conversation about 2 months ago permalink
    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Monday, 22-Sep-2025 11:13:37 JST Paul Cantrell Paul Cantrell
      in reply to
      • Shriram Krishnamurthi
      • Neil Madden
      • Dr. Juande Santander-Vela

      @shriramk @neilmadden @juandesant @timbray
      Wasn’t me. I’m still learning! It was here:

      In conversation about 2 months ago permalink
    • Embed this notice
      Shriram Krishnamurthi (shriramk@mastodon.social)'s status on Monday, 22-Sep-2025 11:13:38 JST Shriram Krishnamurthi Shriram Krishnamurthi
      in reply to
      • Paul Cantrell
      • Neil Madden
      • Dr. Juande Santander-Vela

      @neilmadden
      Also @inthehands just pointed me to this:

      https://justinpombrio.net/2021/12/26/preventing-log4j-with-capabilities.html

      @juandesant @timbray

      In conversation about 2 months ago permalink
    • Embed this notice
      Neil Madden (neilmadden@infosec.exchange)'s status on Monday, 22-Sep-2025 11:13:39 JST Neil Madden Neil Madden
      in reply to
      • Paul Cantrell
      • Shriram Krishnamurthi
      • Dr. Juande Santander-Vela

      @shriramk @inthehands @juandesant @timbray

      Kate Sills’ evergreen article is a great place to start, IMO:

      https://medium.com/agoric/pola-would-have-prevented-the-event-stream-incident-45653ecbda99

      In conversation about 2 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.