Hacker Newsnew | past | comments | ask | show | jobs | submit | engcoach's commentslogin

Fuck the government

What about people who have eaten extensive quantities (and variations) of vegetarian Indian food but still crave meat? It's not a matter of exposure, it's also a matter of taste.

Old Apple wasn't run by ex-Microsoft and ex-consultancy MBAs... a serious cultural rot has set in and the much of the "bottom up" component powering much of the innovation is nothing but smoldering coals.

The golden goose is dead.


Allies shouldn't align with their block's primary geopolitical enemies...


I'd term it "theopolitical" more than "geopolitical"... which is both more ominous and closer to the truth IMHO. One particular dusty-book-infused worldview, for example, can cite an order of magnitude more xenophobic and violent passages directed towards specifically-named outsider-followers of certain other dusty-book-infused worldviews than all the others, for example.


Eh. I can see how MAGAing it up to 11 might lead to some shifting of those blocks in a complicated world.


Israel has entered the chat.


Honestly, the US doesn't need Türkiye. Europe does.


Rare earths are vital for military equipment. This action is coming from a country that NATO has trusted with its best technology and they continue to flirt with both Russia and China, NATO's primary threats.


"Trusted with its best technology"

No. The US kicked NATO member Türkiye out of the F-35 program and denied them F-16 upgrades for a long time[1]. And the EU has denied Türkiye membership supposedly because they're not fully part of Europe (among other issues) while courting Georgia which is farther east. Türkiye is treated as a frenemy by the west. Good on them for making their own way.

[1] https://balkaneu.com/turkeys-f-16-deal-stalls-as-focus-shift...


> among other issues

Those words are doing some heavy lifting. The EU cares more about their commitment to democracy, and their dubious economic policies. The last thing the EU needs is another Hungary.


My instinct is that there are a lot of a potentially good reasons not to let them into the EU, and maybe even ones for kicking them out of NATO, but "they want to sell their minerals to other countries" doesn't strike me as a reasonable gripe in terms of NATO at least.


Is the danger here token replay? It's using Bearer tokens, so it's not sending a password over:

<https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Aut...>

Threats section for Bearer tokens: <https://datatracker.ietf.org/doc/html/rfc6750#section-5.2>

Does OAuth reuse tokens across domains? If not, doesn't this just mean it is requesting an auth token for ghrc (the "fake" domain) but it can't access any auth tokens for ghcr (the real domain)?


Blog author (and OCI maintainer) here. The request to get a bearer token sends the password or PAT using the basic auth header, base64 encoded, but otherwise clear-text. That's the request the www-authenticate header is triggering. Once the token is received, the registry uses that to verify access, and that eventually expires. But the attacker isn't getting the token, they are requesting the credentials that would be used to acquire a bearer auth token.


Without a fee, people would make new accounts and circumvent distribution restrictions.


The fee could be less and have a similar deterrent on the type of activity you describe. The real question isn't what Apple is gaining from this fee, but what they are losing.

Apple's $99 fee is annoying and feels like a waste of time and one more thing to manage.

The paid ADC program has kept me from sharing projects with other developers who would have otherwise been able to contribute (but they aren't paid devs because they'd rather have a year of Costco hotdogs than pay Apple to help me with my app for a week)


Quit


It only takes a spouse with a personality disorder and a divorce to change the calculus.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: