Hacker Newsnew | past | comments | ask | show | jobs | submit | processunknown's commentslogin

It seems more like a handrolled CodeQL

It's an agent system that basically embeds the core idea of CodeQL (Datalog extraction from codebases) and then allows a model to pose questions and answer them.

There is a giant list of reasons here https://grapheneos.org/faq#future-devices

id guess that most resolvers have a least recently used (LRU) policy


But they must still have a TTL, they can't just store stale records forever.


You're right, it's TTL not LRU. The authoritative server publishes a TTL with the record — "you may keep this for N seconds" — and when it's up the resolver has to ask again no matter how popular it is.

LRU does show up in resolvers, but as memory management: cache is full, evict the least recently used early. It can only make something disappear sooner than its TTL, never later.

It's time-based because there's no back-channel. An authoritative server has no idea who's holding a copy of its records, so it can't push an invalidation.


Yep, that's my mental model as well, thanks.


Bring back PB Crisps!


Dell did this too with their workstation laptops, Dell Pro Max 16 Plus. :/


Seems squarely in the "cost of doing business" category


Pay to play teeth


To an extent, though for significant (in monetary terms) violations of the law the teeth tend to pay for themselves (but do so by not fully compensating the people whose behalf they are supposedly acting on).

More problematically there are camouflaged sharp spines pointed primarily in the direction of poorer people, and people not advised by lawyers.

But none of that matters here when the damaged parties include the megacorps of the world.


Unfortunately, this is common for bug bounties.


+1 for qubes. with some effort you can get a really nice stack with segmented git, disposable coding agents, package cachers, firewalls, and network visibility.


It wouldnt be _that_ surprising since they committed widespread copyright violations building the models, plus the recent Apple IP theft...


Disclosing private repos against the owner's intent is a much more immediate and significant business risk than violating the license of open source code.

Maybe that shouldn't be the case, but it is.


This speaks to OpenAI's approach to things. But it doesn't speak to Microsoft and Microsoft would need to provide the access.


this might be relevant about microsoft.

Federal Cyber Experts Thought Microsoft’s Cloud Was “a Pile of Shit.” They Approved It Anyway:

https://www.propublica.org/article/microsoft-cloud-fedramp-c...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: