Hacker Newsnew | past | comments | ask | show | jobs | submit | more wolfi1's commentslogin

there is a quote from Pauli about Dirac : 'There is no God and Dirac is his prophet' Heisenberg and Dirac had different opinions on the existence of a god and Pauli, asked for his opinion, had the former to say

There's a quote Atiyah has about spin geometry which he heard from his advisor Hodge, who had an office next to Dirac at Cambridge.

Only two people understand spinors: God, and Dirac. And Dirac's dead.


concerning backups, when it comes to disaster recovery you need a strategy for restoring as well, sometimes it's not only the data you would need but the systems as well

well, if you happen to be in a 'rm -Rf /' situation (which with agentic AI seems to be more often the case) to know how to operate in a chroot environment could be helpful

ah, those were the days, when compiling the kernel took about 12 hours, or the switch from COFF to elf - fun times indeed

Indeed.

I was a wuss and waited for a CD. I doged the 98 floppy install....


my first installation was a floppy installation (slackware), yeah that was an added bonus ;)

could xhost(1) help here?


I think the only possibility that comes to mind is creating an ebpf module that sandboxes all filesystem calls and trampolines all ld_open calls.

But then you would have to provide massive amounts of patched/"safe" variants of all kinds of shared libraries which is unfeasible.

But I mean in the xorg use case it would be possible to just provide your own library that fakes the expected returns and sends fake data to the sandboxed applications.

I did a similar thing with barrier (though using LD_PRELOAD, see [1]) on my debian system to force a different behavior.

Source: Am kind of experimenting with ebpf a lot for that use case. C ABIs and SO files are a mess though. A real messy mess.

[1] https://github.com/cookiengineer/barrier-disable-dpms


Not really - it's not sufficiently fine-grained and, besides, you need it to connect to X to display anything.

There were various attempts to improve this situation in the early 2010s, typically using Xnest or Xephyr in conjunction with other sandboxing techniques. I believe Qubes OS followed that approach but it was awkward, limited, had major performance problems, and yet never managed to fully prevent circumvention.

The fact is that the X model was never designed with these threats in mind.


> I believe Qubes OS followed that approach but it was awkward, limited, had major performance problems, and yet never managed to fully prevent circumvention.

Not sure what you are talking about. Qubes offers reliable protection with decent performance, unless you work with graphics. See also: https://news.ycombinator.com/item?id=49678250


but sandboxing would be quite useless


How so? If you can break out of a sandbox then by definition it is not a sandbox.

There are ways to force sandbox jail. For instance, giving processes only a partial view of the computer system. GoboLinux did this years ago via ViewFS (https://linuxphilia.blogspot.com/2009/07/gobolinux-is-linux-... search for ViewFS). There are many other similar solutions, some probably better.


X itself is the problem here, not the process attached to


You need to sandbox X11 which requires giving up X11 capabilities just like Wayland did.


production symptom? is this equivalent to "kidney disappointment"?


I hope one of them is Doctor Strangelove


ooh good call, I should fix that.


will Openai or Anthropic rename themselves to Skynet?


Nah. Collossus and Guardian.


not only in Sweden, in Germany and Switzerland as well. I guess it has the same origins in the trade unionist purchasing cooperatives at the turn of the century from the 19th to the 20th


At least in Germany, it's pronounced co-op, though. The stores got rebranded meanwhile. https://www.coop.de/coop/historie/


Italy, UK... Yep.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: