Readit News logoReadit News
gz09 commented on Signal leaders warn agentic AI is an insecure, unreliable surveillance risk   coywolf.com/news/producti... · Posted by u/speckx
c-linkage · a month ago
It's pretty clear that the security models designed into operating systems never considered networked systems. Given that most operating systems were designed and deployed before the internet, this should not be a surprise.

Although one might consider it surprising that OS developers have not updated security models for this new reality, I would argue that no one wants to throw away their models due to 1) backward compatibility; and 2) the amount of work it would take to develop and market an entirely new operating system that is fully network aware.

Yes we have containers and VMs, but these are just kludges on top of existing systems to handle networks and tainted (in the Perl sense) data.

gz09 · a month ago
> It's pretty clear that the security models that were design into operating systems never truly considered networked systems

Andrew Tanenbaum developed the Amoeba operating system with those requirements in mind almost 40 years ago. There were plenty of others that did propose similar systems in the systems research community. It's not that we don't know how to do it just that the OS's that became mainstream didn't want to/need to/consider those requirements necessary/<insert any other potential reason I forgot>.

gz09 commented on Permission Systems for Enterprise That Scale   eliocapella.com/blog/perm... · Posted by u/eliocs
eliocs · 2 months ago
How would you achieve fast list queries of accessible resources with this approach?
gz09 · 2 months ago
feldera has a way to run ad-hoc/list queries on materialized views. Alternatively, you can send the result somewhere where you can query it.
gz09 commented on I spent a week without IPv4 (2023)   apalrd.net/posts/2023/net... · Posted by u/mahirsaid
mlangenberg · 2 months ago
> There are also still a lot of misconceptions from network administrators who are scared of or don’t properly understand IPv6

Enable IPv6 on a TP-Link Omada router (ER7212PC) and all internal services are exposed to the outside world as there is no default IPv6 deny-all rule and no IPv6 firewall. I get why some people are nervous.

gz09 · 2 months ago
I believe that was more a bug in the firmware that's been fixed for a while now.
gz09 commented on Dafny: Verification-Aware Programming Language   dafny.org/... · Posted by u/handfuloflight
dionian · 2 months ago
Reminds me of Eiffel, in a good way. Looks awesome. Is there anything close to this in Scala by chance?
gz09 · 2 months ago
It's similar in spirit, but in Dafny one can express much more complicated and complex invariants which get checked at build time -- compared to eiffel where pre/post conditions are checked at runtime (in dev builds mostly).
gz09 commented on Pricing Changes for GitHub Actions   resources.github.com/acti... · Posted by u/kevin-david
naikrovek · 2 months ago
Copilot uses other models, not (necessarily?) its own, so I’m not sure what you mean.
gz09 · 2 months ago
It does leverage various models, but

- github copilot PR reviews are subpar compared to what I've seen from other services: at least for our PRs they tend to be mostly an (expensive) grammar/spell-check

- given that it's github native you'd wish for a good integration with the platform but then when your org is behind a (github) IP whitelist things seem to break often

- network firewall for the agent doesn't seem to work properly

raised tickets for all these but given how well it works when it does, I might as well just migrate to another service

gz09 commented on Pricing Changes for GitHub Actions   resources.github.com/acti... · Posted by u/kevin-david
awestroke · 2 months ago
They still host all artefacts and logs for these self-hosted runs. Probably costs them a fair bit
gz09 · 2 months ago
They already charge for this separately (at least storage). Some compute cost may be justified but you'd wish that this change would come with some commitment of fixing bugs (many open for years) in their CI platform -- as opposed to investing all their resources in a (mostly inferior) LLM agent (copilot).
gz09 commented on     · Posted by u/mrideout
gz09 · 4 months ago
Probably there are good reasons for this (like avoiding chicken-egg/bootstrapping issues, circular dependencies etc.)
gz09 commented on Ask HN: Who is hiring? (October 2025)    · Posted by u/whoishiring
gz09 · 4 months ago
Feldera (https://feldera.com | REMOTE (US) | Full-Time

RELIABILITY AND PERFORMANCE ENGINEER: https://jobs.ashbyhq.com/feldera/709c14e4-1fa9-46b4-9ff8-078...

  - Strong background in systems engineering, performance testing, or site reliability engineering.
  - Fluency in Python and Linux fundamentals. Rust experience is a plus.
  - Experience with distributed systems and database concepts (consistency, fault tolerance, transactions).
  - Experience with CI/CD/Infrastructure as Code: GitHub Actions, Docker, Kubernetes.
  - Hands-on experience running large-scale and long-running workloads, preferably in a cloud-native environment.
  - Curiosity, rigor, and the ability to design experiments that simulate messy real-world conditions.
SOLUTION ENGINEER: https://jobs.ashbyhq.com/feldera/544aff74-263f-4749-a4d0-af0...

  - 5+ years experience in solution architect, customer engineering or solution engineering roles.
  - Strong background in distributed systems, databases, cloud infrastructure, and modern data platforms.
  - Experience with data-intensive systems in production (e.g., Kafka, Delta Lake, Iceberg, Kubernetes, monitoring/observability stacks).
  - Exceptional debugging and problem-solving skills, especially in customer-facing contexts.
  - Excellent communication skills, both for customer-facing and internal interactions.
  - Ability to write and maintain high-quality technical docs and playbooks.
https://jobs.ashbyhq.com/feldera

Feel free to email with your resume gz @ domain, put HN in subject.

u/gz09

KarmaCake day248December 4, 2013View Original