For the best experience on desktop, install the Chrome extension to track your reading on news.ycombinator.com
Hacker Newsnew | past | comments | ask | show | jobs | submit | history | jadamson's commentsregister

> I wish we'd first fix women's rights and then extend their duties.

"We'll get around to it when some arbitrary measure is met, we promise"

This is the same thing you're criticising - using one injustice to justify another.


I don't have intentions to justify an injustice. I'm saying why should we try to make it even harder for a disadvantaged group? It does not help a single German man if women also have to comply to this law. Fixing women's rights on the other hand gives everybody the benefit of living in a society that is more fair. For me, that's a valuable goal.

You may claim not to have the intention, but materially, it's what you're doing.

Everyone doesn't get drafted at once. It stands to reason that drafting women would mean fewer men were needed.


Women vote, and pressure politicians into continuing a war that they will never have to fight themselves. Many such cases.

Can you show me a recent war in a democracy where women had greater percentage of supporting a war than men?

Setting aside arguments over biology, avoiding getting sent to war to be blown to pieces wouldn't be a "light" reason to consider claiming gender diversity.

SBGG has an exclusion carved out for people who share this opinion (not me).

https://www.gesetze-im-internet.de/sbgg/__9.html


Interesting, so they have to see the writing on the wall a couple of months in advance (plus processing time, presumably).

In case you missed it, according to the OP, the previous point release (1.82.7) is also compromised.


Yeah, that release has the base64 blob, but it didn't contain the pth file that auto triggers the malware on import.


The latest version with the the pth file doesn't require an import to trigger the exploit (just having the package installed is enough thanks to [1]).

The previous version triggers on `import litellm.proxy`

Again, all according to the issue OP.

[1] https://docs.python.org/3/library/site.html


Most his recent commits are small edits claiming responsibility on behalf of "teampcp", which was the group behind the recent Trivy compromise:

https://news.ycombinator.com/item?id=47475888


I was just wondering why the Trivy compromise hit only npm packages, thinking that bigger stuff should appear sooner or later. Here we go...


Little St. James


I don't understand your suggestion. If you're still showing one character after each character entered, what's changed?

What's the benefit of having a random character from a random set, instead of just a random character?


I think the idea is that each character overwrites the previous, so you're never showing the total length (apart from 0/1!)


Ah, and the characters are supposed to be an ASCII spinner.

I think if I was new to Linux that would confuse the life out of me :)


There's no persistent reveal of password length after you're finished typing. It reduces the length-reveal leak from anyone who eventually sees the terminal log to people who are actively over-the-shoulder as you type it.


If you can see 1 char from set of 4 you know the number of characters modulo 4. If the minimum length of a password is 6, and probably it is no longer than 12 characters, then you can narrow the length to 1 or 2 numbers. It is marginally better than asterisks of course, of course, but it is still confusing.


The original suggestion included randomizing the first character of the set, which removes this attack.


They mean to have a static single character on the screen and have it change with every keypress. For example, you type "a" and it shows /. You type "b" and it shows "|", etc.



Safari is the highest for 10 tabs but second-lowest for 20? This reads like AI slop, but even if it's not, it's definitely blogspam with no methodology.


in practice, I can have ~infinte tabs in Safari on my M1 MBP. I'll have multiple windows with hundreds of tabs open and I've never seen it stutter once.

It's actually enabling my worst tab-hoarding tendencies. In the Intel days I'd pay a performance price at some point and have to tend to my tabs, but now they just keep propagating....


It signifies that someone notable in the industry has recently died, in this case Tony Hoare [1]

[1] https://news.ycombinator.com/item?id=47324054


It very much is the same incident.


Apparently it is, my mistake. Surprisingly that the angle makes it appear so different.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search:

HN For You