Notices by Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)
-
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 08:39:49 JST Haelwenn /элвэн/ :triskell: @piggo @georgia Probably both. -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 08:36:46 JST Haelwenn /элвэн/ :triskell: @georgia Also I guess inventor of that has no friends. -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 08:34:04 JST Haelwenn /элвэн/ :triskell: @sun Or for another example on glibc systems, CVE-2023-4911 (glibc ld.so GLIBC_TUNABLES) would still work against sudo-rs instead of sudo.
Meanwhile a Go reimplementation of sudo could end up fine if cgo isn't used. -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 08:14:54 JST Haelwenn /элвэн/ :triskell: @sun > it also doesn't solve logical vulnerabilities
I know, see the vulns Pleroma had, Erlang and Elixir are memory-safe. -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 08:12:43 JST Haelwenn /элвэн/ :triskell: @sun Sure but Rust Unsafe is basically Rust with few specific safety guarantees disabled.
Meanwhile issue with linking to C++/C/assembly/… is you do not have memory isolation, that's between processes.
For example Rust code linking to OpenSSL-Heartbleed is just as exploitable as C code would. -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 08:00:30 JST Haelwenn /элвэн/ :triskell: @coolboymew Put the most anti-christ one you can think off instead? :D -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 07:56:31 JST Haelwenn /элвэн/ :triskell: @sun Yeah in fact kind of fun that rust stdlib just links to the libc, rustc depends on LLVM (so C++) and cargo has quite a lot of dependencies in C and various kinds of assembly.
At least Go is more isolated there but for many years reference Go toolchain was in C. -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 07:48:51 JST Haelwenn /элвэн/ :triskell: @sun And presenting logic to apply instead of "trust me bro, you do (not) need this" in a very general manner. -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 07:46:38 JST Haelwenn /элвэн/ :triskell: @kaia Given the evangelion plugsuit… I don't think that's even official merch. -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 07:44:55 JST Haelwenn /элвэн/ :triskell: @sun Which is a dead argument because good luck quantifying software risks in such a broad manner, there's barely even have proper infra for communicating security issues to downstreams (like CVEs do) so stats would be seriously off.
Although I think you could say that not all software benefits from memory safety (like when there's little to no external input) and that all software benefits from taking dependency issues seriously. -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 07:26:04 JST Haelwenn /элвэн/ :triskell: @sun Well except memory safety is a language feature, not a programmer skill, although you do have to pick the right language for what you need.
While dependency issues how is that not a skill issue? -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 07:15:30 JST Haelwenn /элвэн/ :triskell: @kaia Imagine seeing this during the apocalypse. -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 06:12:47 JST Haelwenn /элвэн/ :triskell: @crowdagger Ah oui, les chaines d'email je connais. -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 06:11:31 JST Haelwenn /элвэн/ :triskell: @kaia Well consider that the actual 50 users of GnuSocial back in like 2014 actually had a use for !groups :D -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 05:53:11 JST Haelwenn /элвэн/ :triskell: tfw BlueSky StarterPacks just made me think of !groups…
bocchi cris for missing pleroma features (!groups).jpg
Gnu Social Veteran !groups (oh fugg).jpg -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 05:45:57 JST Haelwenn /элвэн/ :triskell: heh, ended up finding this
Hotel Mario CD-I - Hey You Get Off My Cloud -FGYGCoGBw.mkv -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 05:41:12 JST Haelwenn /элвэн/ :triskell: @chjara >implying DPRK has extra corn for popcorn -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 05:39:52 JST Haelwenn /элвэн/ :triskell: @novenary mario_cd-i_no.MOV -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 05:22:26 JST Haelwenn /элвэн/ :triskell: Which also means that one can diff from POSIX.1-2018:
https://hacktivis.me/tmp/posix-2018-2024-files.txt -
Embed this notice
Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 04-Dec-2024 05:03:39 JST Haelwenn /элвэн/ :triskell: \o/ POSIX.1-2024 available as archives: https://pubs.opengroup.org/onlinepubs/9799919799/download/