To be honest, I think they missed the strongest argument in favor of Go: it compiles **fast**.
Even in the LLM age it's extremely important that LLMs can iterate on code quickly and a lightning fast compiler is the biggest factor in that.
https://t.co/6ws3A01wgX
Introducing acropalypse: a serious privacy vulnerability in the Google Pixel's inbuilt screenshot editing tool, Markup, enabling partial recovery of the original, unedited image data of a cropped and/or redacted screenshot. Huge thanks to @David3141593 for his help throughout!
Today I added support for sendmsg() and recvmsg() to my Blink virtual machine. Suddenly it's now able to run GUI programs. This might make it possible for us to run Linux desktop executables on other OSes and the web using WASM. https://t.co/ram0UF2Csf
Vendor: "Please have your DNS provider contact us."
Me: "I'm my DNS provider."
V: "No, the people who run the nameservers."
Me: "I run my nameserver."
V: "No not the data entry part, the people who actually provide the DNS service."
Me: "I do it. On a server."
V: "No, ...."
I wasn’t going to say anything, but since ZDNet has republished the AWS “Sustainability with Rust” blog post, a short thread about why that post is misleading (at best) about Go. 1/
How can we even start talking about supply chain security and sustainability if a maintainer publishing a bad npm package version breaks everyone instantly?
Stable, deterministic pinning is table stakes.
https://t.co/gKLZvr6UTW
🎆 Go 1.17.5 and 1.16.12 are released!
🔐 Security: Severe HTTP/2 server Denial of Service (CVE-2021-44716) and one more
📢 Announcement: https://t.co/qxS7t6CR6U
📦 Download: https://t.co/CuguaGpMGv
#golang
This log4j exploit = remote code execution in basically everything
Arbitrary code execution in iCloud, Twitter, Steam, CloudFlare, Amazon, Tesla, Baidu, Tencent
This may well be devastating 0day RCE exploit that has ever been dropped in all of history.
https://t.co/CeQNtSBpZV
You need random bytes. You call the platform API.
If that fails or is not available, you return an error, raise an exception, dump a core, I don't care. You DON'T implement a fallback.
It's only going to silently downgrade security or mask an incorrect use of the platform API.
While I wait for the GPU to churn through 2*26^11 possibilities, a brief recap of how we got here. It started when I noticed this bit of code in the @GitHubCopilot Visual Studio Code extension that detects naughty words in either the prompt or the suggestions.