Hacker Newsnew | past | comments | ask | show | jobs | submit | Good4boothee's commentslogin

> but unless you're defending against some sort of denial of service attack, in practice it rarely matters.

That "rarely" contains most sites/webservices. Before programming languages started defending against it by applying randomization (and sometimes replacing degraded maps/buckets with treemaps) it was a real threat. I remember people were able to trigger DoS either by specially crafted query string params or HTTP headers. After all both are shoved into some kind of map by frameworks, before request is even passed to application code.


How does handling support tickets/bugs work with such approach? If LLM sometimes can't handle it - do I have to beg it to keep trying, as humans are no longer an viable fallback?

The way I've seen it work is basically pointing an agent directly to the ticket, or via a proxy description.

There's a good chance that if the agent cannot handle it, a human wouldn't be figuring it out either, without additional context. That context would be the sort of only-Joe-knows-how-it-works, so perhaps something worth addressing in any case.


> "But they can't possibly review every ad before publishing" they say.

That defense doesn't work either way as they (and Facebook) also reject manual reports from users.


Endless stream of "Your review was removed - place was closed down" is a interesting reward for reviewing places. I still wonder how can a beach just stop existing.

Will it ever work until a TPM like module is directly integrated into camera sensor? Older attempts of Nikon and Canon got broken, same had happened with C2PA implementation for Android - if it gets anywhere close to CPU it is insecure.

Yes, presumably there will be a cat and mouse game until the entire system including all peripherals has been brought into the trusted computing base, either physically or logically (usually with secured/authenticated communication). This has been the case for all applications of trusted computing.

Security is never a binary property, however, and can usually be better expressed in terms of how expensive it would be to subvert a given mechanism. "This image is either authentic or would have cost at least $x to fake" is already much more useful than nothing at all even without $x trending to infinity.


Main discussion at https://news.ycombinator.com/item?id=49437283

And I still can't go over how this title looks like draft version with placeholder, published a bit too fast. How could anyone thing a single letter is good choice for an company/service name?


> How could anyone thing a single letter is good choice for an company/service name

In this case, Musk is stuck being his 12 year old self and carrying a 30 year old obsession to use this very cool naming for his "everything company", after losing that name along with him leaving PayPal. He finally got the chance.


I am surprised they didn't rollback their change from 2019 when they included up to 5 private repos in free plan. Before that you had to pay to keep your code from being publicly visible.


Did it also give you a tip to "log in to your usual Wifi network"? I have a feeling all large corps let their heuristics run wild with little to none supervison.


That is a lot more Star Citizen players than I expected.

Also that Factorio chart is weird: https://steamdb.info/app/427520/charts/#max . I don't think I even saw another game with such steady player count. It is horizontal line after 1.0 to DLC release, and after DLC to present.


https://en.wikipedia.org/wiki/Ototoxic_medication#Other_exam... has some sources. Worth noting NSAIDs like aspirin are also listed there.


That’s a helpful reference. If accurate, the method of action here is simply nasal congestion (a common side effect).


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: