Hacker News new | past | comments | ask | show | jobs | submit | 131hn's comments login

Claiming impostor syndrome is very different from having a crisis of confidence.


Is there a specific reason to make a distinction between the two products (copilot/chatgpt+) when in the end, they are using the same engine.. ?

It is confusing me a bit (chatgpt+ subscriber here)


Plenty of custom system prompts for co-pilot probably.


A french classic (but less impressive) Si mon tonton tond ton tonton, ton tonton sera tondu.

(If my uncle shave your uncle, your uncle will be shaved)


And for deutsch/german

Nach dem stutzen des Rhabarberbarbarabarbarbarenbarts geht der Rhabarberbarbarabarbarbarenbartbarbier meist mit den Rhabarberbarbarabarbarbaren in die Rhabarberbarbarabarbarbarenbartbarbierbierbar zu Rhabarberbarbarabarbarbarenbartbarbierbierbarbärbel um sie mit zur Rhabarberbarbarabar zu nehmen um mit etwas Rhabarberbarbarabarbarbarenbartbarbierbier von Rhabarberbarbaras herrlichem Rhabarberkuchen zu essen.

https://www.oezeps.at/wp-content/uploads/2011/10/Rabarberbar...



what makes you think docker swarm is abandonned ? The latest docker engine release (23.0) continue support it and add new features


A few years ago (2018?), I read somewhere - I think it was on Hacker News, even - that Docker/Moby was quietly dropping paid support for Swarm.

I've had a hard time finding much via hn.algolia.com to back this up, other than some discussions in mid-2018, though.


Android is what Gates had foreseen back then. I find his nightmare pretty relevant


If you have a teenager at home, make him read the story « Tibaldo and the Hole in the Calendar » about this event

https://www.amazon.com/Tibaldo-Hole-Calendar-Abner-Shimony/d...


The thesis french transcript of the tl;dr is written in verse/alexendrin.

Because, why not


excellent !


Forwarding the agent does not forward the keys, only a socket to the original server (agent)


Can't the server still pretend to be connecting to one of the specified hops? For example if -h 'allowed.com' is specified then in /etc/hosts/ wouldn't an entry to 127.0.0.1 allowed.com allow the local server to receive the key?


There’s no such thing as “receiving the key”. At best, you can coerce the forwarded agent to sign things w/ a key that it has. It will never give you the key itself; that isn’t part of the agent’s available behaviors.


Yup. And because SSH is a well-designed protocol, the signature needed to prove your identity is fresh (both sides pick large random values) each time, so even though SSH agent was over-used and securing it better is important, even today you cannot obtain enduring credentials from it. If I cut off your access to my SSH agent today, you can't authenticate to my servers tomorrow using what you learned.

This also has the benefit that the SSH agent can offer this capability on behalf of physical hardware that won't give up the keys either. My Yubico Security Key won't tell anybody (even me) my SSH private keys, but since SSH agent only offers to make signatures, it can proxy that work to the Security Key as necessary.

The Yubico product won't sign anything without a physical gesture (touching a glowing icon on the key) and so now if my laptop is sat unused on my desk while I eat lunch it's impossible for a remote system to use my credentials to sign in to another system, even if it's hostile, and it has somehow taken over control of my local machine's SSH client or I've unwisely authorised SSH agent forwarding, because it cannot cause the touch sensor to get touched.


It looks like the dns name is just a convenience; it actually looks up the associated host key and uses that, not the hostname. So the attacker would have the private keys for the destination to make use of it; I think?


If the originating host has added any of the agent's cached keys to ~/.ssh/authorized keys, then extracting the private key can be accomplished with:

    ssh origin cat ~/.ssh/id_ed25519


Which is the hole closed by this feature.


Iphone 7& 8, barelly usable since 2 months (ios 14.xx)


Did he put tape on the home button for us not to steal his fingerprints ?


Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: