Hacker Newsnew | past | comments | ask | show | jobs | submit | benregenspan's commentslogin

This seems like a really good example of Base CVSS scores not telling us much on their own.

For the Wordpress RCE (nominally CVSS 9.2), it looks like many standard deployments of WordPress would be affected, barring extra mitigations. But in the case of these Hugo ones (9.3), it looks like very specific circumstances (anti-mitigations, if you will) are needed. E.g. running arbitrary builds of untrusted user content without a sandbox; running it in a GitHub workflow against PRs from untrusted contributors, etc.


Parler was "ripped off the Internet" because it was delisted from app stores and dropped by AWS for violating their ToS due to having (If I remember correctly) approximately zero content moderation, which is not really compatible with the mainstream distribution model they wanted. The owners were not subjected to sanctions by a foreign government.


That part seems to qualify as an unsolved problem. But could anyone have taken the scanned data (or the GIF file) and used it to open a bank account in your friend's name? That seems like the main issue that is genuinely solved by correct implementation of this type of system.


Already today nobody can open a bank account in my name with just a picture of my passport, as the original would be required. My passport doesn't have any of the "eID/CAs/ZKP/PKI", so the question of "what exactly the addition of it solves" remains open.

My national ID card supposedly has some of it, the 17-year olds who want to pass as 18-year olds usually show a doctored gif file of their ID card, with a year of birth one or two years before the actual one; this works in ~98% of the cases.


Actually it does. Biometric passports (and IDs) have a chip which is read via NFC and the information the NFC provides is signed by a CA which is the government that issued the passport. ICAO compiles a database of public keys corresponding to each government (plus countries exchange their public keys via bilateral agreements). Unless somebody is doing purely visual inspection, any time a passport is scanned there's PKI involved to validate if the information is genuine.


None of that applies to my (non-biometric) passport, and we were talking about banks that don't have the passport-reading equipment to begin with.


Private entities get to use whatever name they want. In this case, there is the option to use the longstanding name that matches the one used by the other neighboring territory. Or to have a wait period after the name is changed unilaterally by executive order, because it'd be silly to change it back and forth. Or to put "a.k.a..." after it. Or to wait for the relevant government to update its own map and geographic names database first (https://edits.nationalmap.gov/apps/gaz-domestic/public/searc... is not yet updated as of now). Or to wait until local signage can be updated so it mostly matches the map (though I don't think Rochester will be in a rush to do this).


Being overly trained on comments in documentation could be one of the reasons why Claude models write frustrating comments (which often manifest as written justifications of how the code satisfies the prompt). A comment in a tutorial is going to be geared to explaining how the code relates back to the tutorial task or restating what the code does, rather than documenting the "why" of surprising code.


> Ben-Gvir is loathed by 90% of Israeli society...Trump still has 33% approval

Maybe that 90% number is for Tel Aviv. In national polls, they both have roughly the same approval rating.


I have a long-held feeling with Trump that his most ardent haters don't hate his specific policies, merely that he's so gauche about it, that he has no class.

I have no doubt that Ben-Gvir has a similar segment of haters in Israel. They want the same things, but they don't want to do it in the style of a leering hooligan fishing for a fistfight.


From what I can see, most people hate trump as a solid bloc. The fact that he, as every populist everywhere in past centuries, pointed out to some real problems but didn't do a squat about it when he came to power and in his case massively worsened the situation, is hard to escape from. He certainly didn't rise above other populists in this.

His form is just a tiny cherry on top of very big rotting cake. Make form smooth and underlying crap won't change a bit. Hating trump ain't emotional, purely rational approach is sufficient.


Definitively not a solid block. It's tempting to believe that, but no, John Bolton probably hates quite different things about Trump from you (and definitively from me). A lot of the opposition both outside the republican party and inside (such as it is), is probably entirely fine with bombing Iran for instance. Not mad he's bombing it, mad he's bungling it.


What specific policies? He's mostly impulsive, doing whatever comes to mind at any given moment, with no long-term consistency.

The one exception that comes to mind is his policy of flooding the country with untrained, unrestrained ICE agents, and I do not approve of that one.


> I have a long-held feeling with Trump that his most ardent haters don't hate his specific policies, merely that he's so gauche about it, that he has no class.

A bit of an extraordinary belief to hold, to be honest


I am not a lawyer, but this seems unlikely. Federal law prohibits "false advertisement" which is understood to include misleading advertisements. Regulators can and do restrict certain types of commercial speech, and this kind of restriction has survived First Amendment challenge.


> So if Elon decided to sell all his shares today (and likely destroy his companies in the process), he'd shoot to the top of the list? What's the point in that

It looks like the methodology involves subtracting the founder's entire net worth, so selling the shares would leave him in the same place.


Hmm you are right. But looking closer at the methodology, I find myself even more confused.

It seems the metric is something like "most successful stewards of shareholders' investments" which I guess is interesting. But now I'm tripped up on why the metric would only consider founders rather than CEOs more generally. Imagine Gates didn't start Microsoft, but instead became its CEO a month after some other founder started it and that founder sat on the beach in Hawaii while Gates did well, what he did. The founder would appear on this list but not Gates.

Edit: basically, all my intuitive "this doesn't make any sense" alarm bells are going off, but I think I need someone who really knows what they're talking about to help me understand exactly why, or what would be a more sensical version of this


There is a whole area of research on this. Prosecutors have significant discretion around charging and (suggested) sentence, and this allows bias to creep in. I've heard people debate the quality of specific research on the size of the bias, but not the mere idea that bias is possible at all.


I'd love for Google to figure out something comparable for the Drive API (currently it's not possible to grant read/write access to a single folder; you need to grant access to the entire drive!): https://issuetracker.google.com/issues/36760598?pli=1

I think the fact that the above issue has been open for a very long time is one indication of how difficult and sensitive this type of access control API is. The Google Drive API could be a proving ground for getting the UX right for this (including tricky details like how to manage persistent access to a folder with clear disclosure and user controls).


Is it really that complicated?

Why not just create per-domain browser-controlled folders (cert-linked?) that are abstracted into a simple read/write API via the browser (with subfolders allowed under that domain's root), disallow cross-domain access... and then build browser-mediated linking for use cases where you want to flow files from (non-domain) to (domain) to (non-domain)?

So essentially local storage with better integration with the actual filesystem, that's browser-controlled.

Allowing websites to have arbitrary (even user-approved) access directly to the real filesystem seems like a bad idea, when most use cases could be handled by a browser-mediated filesystem-like abstract view.


> Why not just create per-domain browser-controlled folders (cert-linked?) that are abstracted into a simple read/write API via the browser (with subfolders allowed under that domain's root), disallow cross-domain access

This part already exists, that's the "Origin-private file system".

> ...and then build browser-mediated linking for use cases where you want to flow files from (non-domain) to (domain) to (non-domain)?

That's pretty much what the directory picker is - or would have been. Apparently it doesn't satisfy the security worries of some.


Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: