Hacker Newsnew | past | comments | ask | show | jobs | submit | auscompgeek's commentslogin

As a developer or security researcher, you're able to download and run GitHub Enterprise Server. I'm not sure having access to the full source code makes a meaningful difference for most of GitHub's surface area, given it's largely Ruby.


LLMs can't really parse compiled code to find exploits, maybe code in scripting languages (python, js, etc) even if minified. So I don't quite agree with you, having access to the source can definitely help find exploits even in pre-LLM days.


Also, the Github enterprise code is "obfuscated" but it uses a trivially reversible method just meant to be a minor roadblock. After you get past that you get the full ruby source code, no minification or anything.

For a while the key was literally:

> This obfuscation is intended to discourage GitHub Enterprise customers from making modifications to the VM. We know this 'encryption' is easily broken.


Pretty much everyone disagrees with you, especially when you add in decompiler tools to the LLM.


how to say you haven't tried llms since 2023 without saying it, that's quite literally one of the things they excel at


In theory eStargz layers should be amenable to CDC.


It feels that way, but eStargz is still only addressable as a single layer, or range of one.


From what I can gather it is the exact same vulnerability.


In isolation sure. But in context with the other points it makes it look like "they" refers to Microsoft in all the dot points.


describe is also the command you can use to edit the commit message of the change you're currently drafting. In jj there's no staging area, every modification to the working tree immediately gets integrated into the current commit. (This means if you have no diff in your working tree, you're actually on an empty commit.)


Depending on what NPU you have yes.


It was definitely a relatively well known problem with the 2019 MBP on the internet at some point. I found a Reddit thread linking to a news article about this. https://www.reddit.com/r/mac/comments/vi3grj/you_should_char...

It was so much of a problem that at work we added a check that you were charging from the right ports to our internal doctor script (think like `brew doctor`).


I help out with an emulation community. Any time anyone with a 2019 MBP comes in with issues, I stop them from giving any more details and just have them check this first.

99% of the time it works 100% of the time.


I think you may be confusing Agent Client Protocol with Agent Communication Protocol.


At the very least schools should be billed for the frivolous police callouts. Who knows, maybe then the school might change their tune.


I would've considered signing up if scrolling on your website didn't make my modern flagship phone drop frames.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: