@antirez Hijacking your post to share Tridgell's response https://t.co/5vPo0gWDi8
Also Tridge doesnt say, but EU CRA regulation (in effect from 2027) say you ship sw with unpatched CVE you go to court. See Spender commentary below (diff context but still relevant).
https://t.co/De1E5Dz1qD
@_GGhh_ Combine these three and if patching individual vulnerabilities is your way of avoiding exploitation, it looks like a mechanism to have downstreams send all the backports upstream just by virtue of auto-issuing CVEs.
@lcamtuf Hi Michał what did you change? I'm honestly studying/learning from these posts you make, I sort of got what the one from yesterday was about (with help), now I'm diffing I see some int literals are now long, pwrite count arg is 12 not 13, what else?
@lemielek@lcamtuf We live in a world where a dummy like me can take this little masterpiece in trolling and obfuscation, ask the llm to unfuck it, and pretend I understand it.
Michał: your job as shitposter has been replaced by AI. Rafał: should print hello world but prints bye world instead.
@TsengSR@antirez It was a mistake, an unintended breakage. Tridgell is trying something new, and surely course correcting. I'm not justifying it, but public opinion should tone the entitlement down. Acknowledge he's done more good than most before going full send on character assassination.
@antirez Ok ok I'm catching up. Seems like most commenters are unaware of Tridgell's caliber. Those who are, say "if not even Tridge can rein in the LLM, what chance do the rest of us have" which fairer point.
@antirez Yo Salvo, haven't checked HN, but you did, so: is ppl acknowledging "rsync author" is Andrew Tridgell, one of the giants of IT field?
Reversed BitKeeper prompting Linus to write Git, reversed SMB protocol and created Samba, I could go on. Headlines are like "some moron did this"
@spendergrsec Clear, receipts are there for all to see. CRA sprinkles a bit of that "share back" Linus couldn't get from GPL. Finally an explanation for the Linux CNA that makes sense. Wish I read it on LWN back in 2024, but hey better late than never. Always a pleasure, Brad. Until next time.
@spendergrsec Hi Brad, once again coming to you for informed opinions.
What do you make of https://t.co/YKaYP6IfJ9 "Documentation: security-bugs: explain what is and is not a security bug" (May 12)
Only gating scope for [email protected] or will influence Linux CNA too, one day maybe?
@spendergrsec Boy this whole thing looks like 7th grade negotiation: Gimme your lunch money or else.
Greg is effectively #2 in an org with 100's of mils, doesn't use them, pretends to be the homeless hacker worried his work is exploited by freeloaders.
Guess now I need to say "own opinions."
@spendergrsec Actually Brad thanks a million for mentioning CRA. I may have heard about CRA over the years but tuned it out and forgot (laws -> boring), but holy cow. CRA is 2024, Linux CNA is 2024. Greg made the CNA to get ahead of CRA didn't he? Am I a conspiracy nutjob to say that?
@mjbommar@spendergrsec I think I see your POV, like Brad explained, the doc says by decree some issues are not vulns. While other parties disagree on that triage.
My angle is more (distro POV), Linux CNA has been flooding us with nonsense CVEs, maybe they'll tune it down now? Hope so but unlikely
@antirez Giusto, DGX ha LPDDR5X che gli dà ~270 GB/s. Apple molto meglio. Ma se attacchi due DGX dice che hai RDMA veloce (100Gbe, forse 400).
Con Apple ho Thunderbolt (4-5) per la rete, numeri inferiori. Comunque mi hai convinto, meglio un nodo solo con 600-800 GB/s di banda di memoria.
@antirez Ciao Salvatore, spesso parli del chip Apple M3 Ultra (Mac Studio), che con $$$$ hai un bel 512GB di memoria.
Ma con ram-pocalypse Apple oggi ti vende massimo 96GB. Già erano scesi a 256GB. M5 Max è massimo 128G. Sbaglio?
Quasi meglio un two-pack di DGX, così ho 256GB.
@TanelPoder Oh! That is sweet sweet deal then! I could catch the discount, consume the content, then keep enjoying the updates once they're ready. Thanks Tanel for clarifying.
@spendergrsec Aware of who Greg his and how he operates (not a fan). You saying Eric Biggers is one of the good guys here. If you can please spell that part out for me. Do you mean https://t.co/wVwDk584K6 Thanks (srsly I'm trying to understand) (2/2)
@spendergrsec Hey Brad, don't hate me, I'm only a copypaste monkey working on distro kernel. Totally not involved in response to copyfail (well, "response"). Yet trying to make sense of this fuckfest. What will I tell my nephews when I'm old kinda thing. (1/2)