Hacker Newsnew | past | comments | ask | show | jobs | submit | zdw's commentslogin

> You cannot offer a taxi service in a car that is not fit for the road, and then just shrug when it crashes a people get hurt.

The problem is that there's no overt way to tell whether the "car" (code) you're looking at is someone's experimental go-kart made by lashing a motor to a few boards, or a well tested and security analyzed commercial product, without explicitly doing those processes on your own.

The problem is all the go-kart hobbyists who make moderately popular go-kart designs end up being asked for all sorts of commercial territory requirements.

The people on the consuming end think "reliability is their job!" and try to force all their requirements and obligations onto the go-kart makers, which usually doesn't end well.


> The problem is that there's no overt way to tell whether the "car" (code) you're looking at is someone's experimental go-kart made by lashing a motor to a few boards, or a well tested and security analyzed commercial product, without explicitly doing those processes on your own.

Yes you can, companies just don't like the answer.

To run with that analogy, if you are setting up that taxi company, will you build your fleet by picking up free gokarts around the neighborhood, or by purchasing cars from a known manufacturer who has gone through crash testing etc?

Not particularly different for software. If you need certified quality, you need to pay the providers fairly substantial amounts of money for that.


Important security packages should be audited by 3rd party researchers and their results shared. For example https://github.com/RustCrypto/RSA?tab=readme-ov-file

If you’re using a security package and it isn’t either a shim over an existing API (eg porting a C-library to a non-C language) or it fails to provide evidence of independent audits, then steer clear or it.

Most other domains are generally much easier for the developer to audit.

However I will say in an age of AI, it will become much easier than it already is to inadvertently pull bad packages.


One could have different tiers of repository for different levels of trust.

In arch Linux, I trust the base repositories more than AUR.


LG sells a DualUp monitor that is 2560x2880, same size as two 2560x1440 displays stacked on top of each other: https://www.lg.com/us/monitors/lg-28mq780-b-dualup-monitor

Yep, though what I would want is the width and height swapped. You can rotate the monitor, but then the subpixel layout isn’t good for text.

If you ever visit Taliesin in Wisconsin (which has a pretty bland), you should also visit the nearby House on the Rock which is a fascinating and very weird collection of esoteric and kitschy items.

The contrast in attitudes and aesthetics between the two is incredibly stark, and it's very interesting to see the reactions of visitors to each location.


Remember that Wright told HotR owner/designer Alex Jordon that he wouldn't hire him to design a chicken coop. You are correct; both should be visited. However, get ready for monotony at HotR. Room after room after room of Jordan's curiosity collection.

This is, by far, one of the weirdest places I've ever visited. Tonal whiplash is an understatement.

-> which [is?] pretty bland

That's a shame to hear, as Taliesin West in Arizona is very fascinating and interesting, but rather poorly curated and run.


My bad on the typo.

The Tallesin 1 hour or so tour is definitely interesting to look at from a historical and design perspective, but definitely "art project" not "good engineering" given the poorly supported balconies, the continually leaky roof, and if you're over 6 feet tall you might hit your head in places.


100% that's actually what we found missing/were disappointed in from the Taliesin West "self-guided" audio tour was it was more social/artistic approach of his architectural style, and not at all on the actual architecture and it's effects.

The 88k multi-chip cache/MMU architecture is fascinating, especially how it could be designed with a single cache chip, or a split I/D cache across two or more different chips.


The 99xx chips have two CPU dies, and one cache die is on each CPU die.


The 3D V-Cache sits underneath only one of the CCDs. See https://en.wikipedia.org/wiki/Ryzen#Ryzen_9000.


That's what's different about this one. "Enter the Ryzen 9 9950X3D2 Dual Edition, a mouthful of a chip that includes 64MB of 3D V-Cache on both processor dies, without the hybrid arrangement that has defined the other chips up until now."


Did you forget which thread we are on?


Oh heh, I thought they were asking about the X3D. My bad ><.




Seeing what China next door has done with solar and batteries, I wonder if they'll do an electric end-run around oil, similarly to some places in Africa.


There are another ~3k devices on the OpenWRT table of hardware that would fall into this category: https://toh.openwrt.org/


This is "Open Hardware" which usually means open PCB or chip schematics, so people can modify or extend the board. OpenWRT is "Open Software that runs on closed hardware".

After checking a couple, Kind of seems like a lot of boards on this "open hardware" list might not actually be open hardware?

Here's an example of what open hardware is supposed to be: https://github.com/greatscottgadgets/ubertooth/tree/master/h...


by open, we mean that you can flash your own firmware. - but yes, we will need to check manualy each device/board or improve the Claude Opus prompt to make sure that it's doing a very good research when extracting these devices


Yeah, that OnePlus phone is defo the very opposite of open hardware...


If one's looking for an actual open hardware smartphone: https://source.puri.sm/Librem5/hw/l5-schematic


Given that a large portion of the population has a HD or higher quality camera in their pocket most of the time these days, most cryptid style conspiracies seem pretty well debunked at this point.


Mandatory XKCD.[1]

[1] https://xkcd.com/1235/


If the phenomenon is itself intelligent..


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: