Hacker Newsnew | past | comments | ask | show | jobs | submit | gh02t's commentslogin

A complication is that AUR doesn't publish packages, it's more like FreeBSD ports in that they are the build scripts for packages and the user builds the package on their local machine. Building an AUR PKGBUILD inherently runs arbitrary code on the user machine, and that code is controlled by the maintainer of the AUR package.

So you have to scan an arbitrary bash script and determine if it pulls malware, or build the package server side in a sandbox and scan it (and some AUR scripts wrap proprietary software blobs the user is supposed to provide e.g. MATLAB, which makes those impossible to build server side). It's a very big extra layer that malware deployments can hide in.


https://dnschecker.org/ip-blacklist-checker.php is pretty handy for checking if you're on any of the major blocklists.

There's really two ways, the other is to manage your own CA. But it seems like every browser/piece of software/etc out there is hell bent on making that as difficult as possible. It'd also be nice if it was easier to scope a certificate authority to a specific domain, but support for that is pretty patchy which is functionally the same as no support at all. And that's not to mention software that ignores the system certificate store. Or how tedious and nonstandardized it can be to get a trusted certificate store in a Docker container in cases where you have services that need to trust each other. Or how annoying it is to install your own trusted CA on devices (though, step-cli does help a lot at least on normal computers... phones however...). On and on and on, the barriers to what should be the obvious solution are extremely high.


If scoping were actually viable, public CAs could also sign your private intermediate CA with a name constraint and it would be trusted everywhere.


Pfsense or OPNsense can handle ~5 gbps routing/firewall on a low power AMD or Intel embedded chip. My now old Pfsense box I got off Aliexpress can comfortably handle 2.5 gbps on an ancient Celeron J4125 running around 10W total. 10+ gbps is feasible on a reasonable power budget with higher end hardware, though it starts to get more expensive.


Damnnnnn that's cool but ouch. I know you're really buying the whole platform and capability and flight-worthy certification but $2K for what is basically a wifi dongle still makes my head spin.


General aviation is for billionaires with how expensive it is.

It’s sad as a regular person that I could never be able to afford to fly. Even in a 75 year old piece of garbage with a carburetor


Linus Tech Tips did a video a few days ago where they built a DIY Steam box for the same price. What they came up with was a decent improvement on the GPU but not a massive upgrade. Kinda suggests Valve isn't necessarily selling them at a loss but the margins are probably near zero.


Wasn’t it also like 4x the size?


It was still small enough to be relevant but yes. The level of integration Valve can do with the steam box probably actually lowers the total cost for them a bit versus just comparing against individual component cost, so it buys them a bit of margin but probably not a ton in today's market.

It was also missing the ability to wake from the controller, I wonder if we will see that become a feature on other gaming Linux distros? I'm not super clear on why that isn't already possible.


Idk man. The thing they built looked gigantic and wouldn’t fit in a tv console at all.


To be fair, "boffin" usually implies someone has relevant (usually scientific) expertise, but nerd doesn't. Henry Legg has the relevant credentials to give weight to his claims, he's not just some random basement nerd.


Never went away, Linux is now the primary target platform for OpenZFS (which is basically synonymous with ZFS these days). TrueNAS/iXSystems (probably the main commercial company using ZFS) moved from FreeBSD to Linux. Major new features like pool expansion have been added after years of requests. Etc., it's a good time for ZFS on Linux.

There ARE licensing issues related to shipping it compiled into the kernel, but you can install it as a kernel module on every mainline distro nowadays which is functionally the same from a user perspective.


Still sucks that you need to verify if your kernel update is compatible with the external module.


I've bought a good bit of 10Gtek stuff over the years. Not sure to what extent they actually are designing their products vs. just acting as a reseller (I think the latter), but either way everything I've bought from them has been quality kit that lasted for years, at a great price.


Oh man, tasks isn't compatible yet? Thanks for mentioning that, I guess I'll wait a bit to upgrade.


Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: