Hacker Newsnew | past | comments | ask | show | jobs | submit | joshrw's commentslogin

Hello, have you heard of the Snowden revelations? What OP was referring to are called bugdoors.


I'm very concerned about bugdoors and very grateful to Snowden, but I don't remember a specific example of a software bugdoor that was disclosed there or identified as such as a result of his revelations. Do you have an example? I don't think the Dual-EC DRBG counts here.


This happened later than Snowden, but is an example of an unsettling revelation.

A bug has existed for many years in Apple devices, until a few years ago, when it has been discovered accidentally by some victims, which has forced Apple to fix it, after several CVEs where assigned to it and associated software bugs.

The bug consisted that some secret test registers, which allowed a complete bypass of all memory protection, were left accessible after production. Thus knowledgeable attackers could take control remotely of an iPhone, for many years, in a completely undetectable way, by sending an invisible message, which then exploited some bugs in Apple system libraries to gain privileged access to the secret test registers, which were then used for complete access to any hardware, including stored files, video camera and microphone.

This backdoor was discovered only because some victims became suspicious due to unexpectedly high Internet traffic originating from their iPhone, which was recorded by an external firewall.

This was discussed on HN after its discovery.

It is hard to believe that such a mistake like forgetting to disable the test registers after production could have happened and it also would have never been discovered for many years, without some Apple insider intentionally doing it.

Moreover, the unknown attackers who have exploited the backdoor for many years had complete knowledge about the secret test registers, which is likely to have been provided by an Apple insider, perhaps the same who has ensured that they remain accessible.

Hopefully, the backdoor has been created only by some lower-rank employee, and it was not created with the knowledge of the management, due to some request from a TLA. It is unknown whether the backdoor has been open in all Apple devices, or only in those sold in certain markets.

When the backdoor was discovered, it was used to spy on some Russians, so some US agency or one from Israel were among the possible exploiters of it (this was before the current war).


Doublespeak


Then it needs to do context compacting, otherwise the results become garbage


Happening very often lately


and we all know why


Because they're moving it to Azure and doing it far too quickly, not taking care to avoid availability issues


It wasn't the migration to Azure that completely borked their PR UI.


Could be.

Or could be that the recent 12 months of 100x increase in code and activity is more than they had planned for when they last did capacity planning.

Vibe-coders, many of them here, often boast about the insane amount of KLoC/hour they can generate and merge.


I've seen this take in another GitHub thread, but are there any stats confirming this? As far as I know a lot of Github stats are publicly available, and can be queried via Clickhouse.


There may be other problems but as someone who's somehow ended up integrating Git into a service twice in my career without even trying that hard to find a reason (it turns out it's weirdly handy in quite a few situations, god I wish it were implemented as a library and not a pile of Perl and shit, and yes I know about libgit2) and has looked into some of Git's and Gitlab's posts about their architectures over the years though the lens of having fought a few of the same beasts, an Azure migration was very obviously going to make things worse.


yeah, ai slop rush

everyone builds off vibes and moves fast! like no, if you are a mature company you don't need to move fast, in fact you need to move slow

the only thing that can kill e.g. github is if they move fast and break things like they do recently


Weapons of mass destruction, as usual.


Always have been.


I prefer using a VPS instead of an old laptop. 2 improvements I’d recommend:

1. Use tmux to keep sessions alive

2. Launch Claude Code using the —-dangerously-skip-permissions flag to avoid annoying pauses in execution

It’s like having a team of full-time interns running in the cloud building your software


There's always Stripe Atlas, which would give you a US-based business Stripe account, but for solopreneurs I'd recommend Paddle or Gumroad.


Thank you so much! Gumroad is exactly what I was looking for. I didn't even bother researching them after I saw that they weren't recommend by https://opensubscriptionplatforms.com but that was silly because it's almost exactly what I wanted. I'm more than happy to take the hit of not being able to export customers fully if it means not having to jump through weird loopholes to get money in my bank account at the end of the day!


The chilling effects it will have on free speech should not be discounted, though. Despite the patchy enforcement and relatively small fines, people will self-censor rather than risk saying anything "illegal".


That's... the point of the bill. People will stop seeing their participation in online hate-speech as a viable use of their time.


They actually do a bit further down the page: http://dotorgdoesntmeancredible.org/misguidedinstruction.htm...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: