Hacker Newsnew | past | comments | ask | show | jobs | submit | lol768's commentslogin

There are echoes of the incident that happened in 2023, here. There appears to be very little infrastructure in place to validate and reject bad data, without taking everything else down in a catastrophic failure.

https://archive.is/FBjl7


> Accrescent is the end goal for a secure and private app store but it's still in alpha

Note that nobody (new) can submit to it today; the developer console HTTP 503s and is only available to an allow-list of developers.


Accrescent has been quiet for a while, but had claimed in the past they would open the store up for new submissions again soon, it will perhaps happen by the end of the year. Its self-imposed requirements for this are to provide a better developer experience and more common app store features developers (should) expect. They recently announced they will be posting more about the progress made towards such goal, after the big announcements and releases of some months ago.

I'm more worried about the lack of a police to take apps down when it is very clear they should not be there. This is a present problem, presently solvable and that is not acknowledged despite the fact it harms the user.


They just made an announcement on their social the are gonna announce stuff more on their social.

Yes, and the UK's industry body - Rail Delivery Group - has thoroughly screwed up distribution of the timetable data for this trial... so no online retailers (with the exception of BR Fares) will be selling tickets for the operation. Hardly a fair trial.


Issues seems to be completely broken, just getting unicorns.

Interestingly the API still works for creating an issue (but webhooks weren't fired).


They've also started revoking previously valid tokens. I can no longer use RedReader with the API client I had created for this purpose.

The only winning move now is to start impersonating their app.


If you have a decent IDE, it'll offer you the ability to swap between the "old" and newer way of doing things when you encounter code written in one of the styles.

I can't say I've had any issues getting code using the new syntax through code review though. C# 14 has been out long enough that the team is familiar with much of it, and the IDE is helpful at reminding you to consider adopting new syntax. That aside though, the collection expression syntax is pretty familiar for anyone who's ever written e.g. JavaScript.


> Because Google has more resources to secure their browser

They've kneecapped ad-blockers, when ad networks are perhaps one of the biggest causes of malware installs/page hijacking/other unwanted behaviour. I'm not sure how you can consider Chrome remotely secure in this light.


My org (or rather, the org they pay to run their IT) blocked browser plugins with a security justification.

I find this incredibly amusing, and at a different point in my life I'd already be gone.

When you outsource IT, there are many, many misaligned incentives.


> I find this incredibly amusing, and at a different point in my life I'd already be gone.

How so? Bad actors buying existing extensions with large user bases then publishing a new version which does bad stuff is a pretty common pattern. It certainy seems like a reasonable concern for a corp IT department.


99% of security experts I know use ad blockers.

When there are unpatched browser vulnerabilities, attackers will use ad networks to inject attack code into reputable-but-ad-laden websites. And even when there aren't unpatched vulnerabilities out there, many ad networks will happily accept scam ads, ads that trick people into downloading malware, fake download buttons and suchlike.


> 99% of security experts I know use ad blockers.

But if they all use Chrome, wouldn't those be really weak ad blockers?


This is a common myth. I've used uBlock Origin Lite for months (a year?) and still see zero ads.

I'm extremely intolerant to ads, so I would leave Chrome if ad blocking stopped working.


Adblocking is an arms race. Google is handicapping adblocking progressively the fact that it doesn't take one day to achieve absolutely doesn't make it a myth. Adblocking is technically worse and the more locked down our environments are the easier it will be to kill or drastically reduce it.

If everyone had the same attitude this would probably already be the case.


> 99% of security experts I know use ad blockers.

100% of security experts I know find ads annoying and know ad blockers reduce how many they see.


Not GP, but I think the point was that no extensions => no ad blockers => major malware vehicle unlockable, short of disabling JS


Bingo.

I figure they had a switch they could toggle and they thought no further about the tradeoffs. Because their primary concern is their own liability, not what's best for the org their contract is with.


> My org (or rather, the org they pay to run their IT) blocked browser plugins with a security justification.

Same here, but only on Chrome. Firefox works fine.


Have they blocked vscode? I think any organisation that lets people use vscode, might just as well people do whatever they want.


Nope :)


Brave has ad-blocking built in and policies can be used to disable any unwanted features. With Chrome going user-hostile, it's a pretty great option.


Extensions are a much greater security risk than ads.


They didn’t take a decade plus to implement per-domain process isolation, for starters…


You can downvote the truth, but can’t reply to it.

Typical modern Mozilla fans, really.


Typical Hacker News posters.


Same, my Dad ordered it for me at the time; sits on my desk :-)


Yes; many (Alpine/Debian) containers in K8s on GKE for production rail ticketing infra in the UK.

There's not tons of noise being made because for the most part it all, Just Works and that's fairly boring. Perf, memory usage etc gets better every release. As an ecosystem, I'm pretty happy with it. I reach for other languages for smaller microservices.


> rail ticketing infra in the UK

You mean Raileasy? Or RDG too? (Just curious about the stack of the wider rail tech infra)


What's preventing you from using C# for smaller microservices? And what do you reach for?


Maybe startup time was a problem before AOT?


> The alternative would be that each school develop their own platform for this

I worked at a university which did exactly this, in the UK.

It was a bespoke platform which integrated incredibly well with the rest of the systems the university used because it was designed from the ground-up to meet the institution's needs, there were regular user groups involving academics to understand what features needed to be built/worked on etc. At one point it was all OSS on GitHub too, in case other universities could've found it useful. It handled plagiarism detection (integrating with Turnitin), marking, exam grids, coursework submissions and feedback, seminar allocations, personalised timetables & mitigating circumstances.

The in-house dev team was vastly cheaper than anything SaaS would've cost, as well. It also maintained software for on-campus parcel deliveries, online exams, opinion surveys, a mobile app for students/staff, the SSO system, the course catalogue, car parking permits, a content management system and more.


That sounds like a dream.

My (also UK-based) university has been working on a new student records management project for years that's been incredibly ill-fated. It's destined to replace all their current systems and the first module module was meant to launch last year, except it thoroughly failed testing and nobody has heard anything about it since.

No idea how long it'll take to pull through. I don't believe it's an in-house effort.


In-house bespoke software sounds reasonable, and multi-customer SaaS sounds reasonable, but outsourced bespoke software sounds like a complete dumpster fire:

End users who report problems:

* are ok with IT level 1 telling them IT level 3 is working on it with velocity appropriate to keep their jobs,

* are ok with IT level 1 telling them ${vendor_of_well-known_solution} is working on it with velocity appropriate for many customers, but

* are not ok with IT level 1 telling them ${vendor_of_bespoke_solutions} is working on it with velocity appropriate for one customer (if they even still exist).


This sounds like a great opportunity for students to gain hands on experience with real software engineering work as well.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: