Forgot your password?
typodupeerror

Comment Fake it till you make it (Score 1) 33

Even if the company has a crap product as long as they have a product they can keep taking money from investors and the CEOs can keep paying themselves out of that money. Maybe someday they will have a working product maybe they won't but either way the CEOs didn't have to have real jobs for quite some time.

Comment Re:I don't currently use Rust (Score 1) 168

UCS32 is certainly an option. It would probably turn me off from Rust entirely, though, at least for my current work. When your device only has a few KB of RAM, quadrupling the size of your strings would be really painful. I'm unhappy that my pointers and register-sized integers are each 8 bytes, so a slice consumes 16 bytes (pointer plus length), minimum. I hate it so much I might consider creating my own string type that only handles strings < 64kb in length, so I could use an 8-byte pointer and a two-byte length -- but ARM has pretty strict alignment requirements so the compiler would pad the u16 out to eight bytes anyway. And all of my strings are error messages which are seven-bit ASCII.

As for your abstracted version... note that in my code I not only don't have GC, I don't even have a heap... no dynamic allocation :-)

With Rust as-is, that means I don't actually have String, but I *do* have &str.

You can certainly argue that one language shouldn't try to address the requirements of tiny microcontrollers to servers with hundreds of GB of RAM... but it's actually really nice that it does.

I think letting programmers use a string as if it's a byte array is an unforced mistake and is out of step with the idea of Rust trying its best to prevent devs from writing bad code.

Rust doesn't try to prevent devs from writing bad code, it tries to prevent devs from writing unsafe code (i.e. code that can exhibit undefined behavior), and the approach to strings is safe. If you index a string at byte offsets, and try to use that data as a string and it's not valid UTF-8, your program panics in a safe, well-defined way :-D

Comment Re:I knew this would happen eventually (Score 1) 23

Because Russia and the US are incapable of compromising or suborning providers from elsewhere?

No, because Russia and the USA are inherently corrupted or corruptible. I could have mentioned China, but who in their right mind would use a Chinese VPN and expect any kind of functionality... My not mentioning others doesn't mean I endorse them per se. But indeed I don't think it's as easy for the USA government to get into Proton as it is to get into an American VPN service.

Perhaps not "as easy", but certainly not hard. Spend some time thinking about what kinds of covert and overt pressures might be brought to bear.

Aside: As an American, I think it's very sad that people lump the US and Russia together in this way. I think it's even sadder that I can't honestly argue that they're wrong. At most I can try to argue that there is still a significant difference of degree, if not kind, but it's not really worth making the argument because the degree of different is heading rapidly to zero. I deeply hope we can turn it around, and I'm doing what I can in that direction, but...

... they don't address the fact that you're still routing all of your traffic through someone else's server -- a server that tends to concentrate lots of potentially interesting traffic in one place, making it a much higher priority target than your typical ISP.

Okay, now I'm curious, so as a pro, please enlighten me what good their getting my true IP address does them, it's not like they can look into https data, right? Or do you just mean, it's a privacy issue if they can observe which servers one connects with?

The latter. I'm pretty confident that TLS is secure. The modern ciphersuites are tight and things like the certificate transparency log make it so that while the TLAs might be able to subvert the CA process, they can only do it in small-scale, tightly-scoped ways. If you are a personal target of interest of any national security agency, you're screwed. They absolutely can get into every aspect of a private citizen's life if they want to put some effort into it. But the transparency log means that if they attempted to do this in any kind of large-scale way it would be discovered and publicized, so the fact that we don't hear about it truly does mean that they're not doing TLS penetration at scale.

However, even if they can't get the content of the connections, they can see where you're connecting to, and when. That sort of traffic analysis provides a surprising amount of information, and it can be done at scale -- and using a third-party VPN generally makes it easier, not harder. Layering VPNs can help a lot. Done carefully, you can structure it so that someone would have to control all of the layered VPN servers in order to track your connections. Layering plus multiplexing (using multiple providers and picking different routes and exit nodes for every connection) could make it really hard.

And if you don't really believe that traffic analysis is a concern, then there's really no point to using a VPN at all (except for location shifting), because TLS really is quite secure. It's definitely silly to, for example, fire up a VPN before connecting to your bank while at a coffee shop or an airport, which is exactly the pitch that many VPN services make. "Be wary of untrusted networks" is their pitch, and it's stupid[*]. If you're concerned about your online activity being tracked it's the "trusted" networks you're on most of the time that are the point of concern for traffic analysis. And the "trusted network" that may be the biggest concern is your VPN provider.

[*] Note that it's not stupid to be frightened of untrusted networks, but kinds of risks that exist with untrusted networks are generally not mitigated by VPNs. The best solution to those risks is keeping your device patched up.

Comment Re:I don't currently use Rust (Score 1) 168

>> If C and C++ natively did UTF-8

> You mean, what Rust does.

Rust doesn't really do "native" UTF-8 any more than C does. Try getting a substring of characters 5 through 10 of a Rust String not knowing if some of the characters before the tenth are non-ASCII unicode codepoints.

I was a little surprised by how bad it is in that area. I know they're going for "As efficient as C", but cmon man, strings using byte indexing?

There are a few ways to do it. The most common is to use the chars() method, which gives you an iterator over characters. So, for your example, something like "s.chars().skip(5).take(5).collect()". If you really need to do heavy unicode text manipulation (e.g. you're writing a text editor or something), you probably want to use some of the available crates, e.g. unicode-segmentation.

Clearly, as you say, this isn't what a lot of people would consider full, native support for UTF-8. Really doing it right would impose a heavy runtime penalty on the vast majority of simple string usage that doesn't need it, so Rust compromised: If you have a &str or a String in Rust, you know that what it contains is valid UTF-8 -- which means that when you create one you're paying the validation penalty, even if you don't need it... however, the penalties scale in an unsurprising way. When you create a string from bytes, the validation is an O(n) operation, but you also have to copy the bytes, so it's already O(n). When you slice a string, the slice validation only has to check the first and last characters of the slice, so it's O(1), as you would expect slicing to be. You might not naively expect slicing to panic with a UTF-8 validation error, but you should expect that it might panic with a bounds-checking error so the fact that it might panic isn't surprising. And, of course, you can use the get() method to get Err() instead of a panic.

Full native UTF-8 support would be a lot heavier. Many common String operations would be O(n) rather than O(1) -- including indexing! The APIs would be quite confusing to people accustomed to C-style strings, too, another cost. So, Rust doesn't do that. Instead, if you want the length of a string in Unicode characters, you use s.chars().count(). If you want a substring with character offsets you use s.chars().skip(n).take(m).collect(), or similar. These operations do not look like they're O(1) which is good, because they're not. They're also not nearly as slow/heavy as they look.

Like most compromises, this one makes no one really happy, and many people will disagree that it's the right choice. But I don't really see a better option, do you? Keeping in mind that everything from device drivers and bare-metal microcontroller code to browsers and editors is included in the target space, and that having different wide and narrow string types has proven to be a bad idea.

Comment Re:Unintended consequences... (Score 2) 97

In USA, Aedes Aegypti is invasive and new, and it won't be missed. In most places in America, it's been here less than 30 years. Less than 5 years, where I live. I am confident that the ecology of 2026 is plenty compatible with the ecology of 2021.

If some obscure bird species that just moved in 5 years ago can't settle for eating the slower, bigger, less stealthy classical mosquito strains we'll have left, then it can fly back down to Central America where it recently came from.

Comment Re:I knew this would happen eventually (Score 1) 23

If the various intelligence and law enforcement agencies around the world don't own or at least have significant hooks into all of the major VPN service providers, someone should be fired for not doing their job.

I should have included organized crime syndicates in that list, though thanks to Google's TLS-all-the-things push traffic sniffing is less useful for stealing money, and criminals generally have less interest in spying on people by doing traffic analysis.

Comment Re:I knew this would happen eventually (Score 1) 23

.... they're just as likely to be a massive security and privacy risk. The problem is that they concentrate all of the traffic you'd most like to keep secret in one server, and depending on exactly how the system works, may require installing software on your local machine with ~root permissions. If the operator is malicious, this is a really dangerous combination.

So, use non Russian and non US providers.

Because Russia and the US are incapable of compromising or suborning providers from elsewhere?

Use open source clients / systems like OpenVPN. Use a VM or separate device (raspi etc) to connect to the VPN service. Install OpenWRT or something similar onto your router (and maintain it), to avoid becoming part of such botnets. Bonus: you can use the router to connect to the VPN service.

Those are all ways to avoid installing questionable software on your primary machine, which is good, but they don't address the fact that you're still routing all of your traffic through someone else's server -- a server that tends to concentrate lots of potentially interesting traffic in one place, making it a much higher priority target than your typical ISP.

If the various intelligence and law enforcement agencies around the world don't own or at least have significant hooks into all of the major VPN service providers, someone should be fired for not doing their job.

Comment Re:Damn republicans and their woke solar (Score 2) 90

The important thing is that all of the solar power remains in control of the same people who currently control our energy supply.

That's really what this is about. Power. Not electric power the power to tell you what to do by controlling whether you have electricity or not. Whether you can drive into work.

Comment Re:Slashdot: (Score 1) 105

The cause is that we are in a deep deep recession that is being masked by ridiculous amounts of AI spending and a news media that is dedicated to propping up this administration at least through the midterms.

There isn't a single serious economist who will tell you that we aren't in a recession if you take out AI spending and AI spending doesn't create jobs. The work is almost entirely automated except for a handful of highly specialized construction jobs that don't last very long and the typically are done by people brought in from out of state because they require specific skills that your average electrician or Carpenter doesn't have. Companies could of course train but fuck that give me give me give me that cheap labor.

Comment Bull fucking shit (Score 2) 105

You have not been able to get ahead in a company by schmoozing in a very long time. The way you get ahead and the way you have gotten ahead for the last two decades is you go to another company that pays you more than you come back to your old company with a higher salary and you keep bouncing from company to company. That's because companies stopped promoting from within and stopped training ages ago. They will only train you and give you new skills for a brief period of time during your new hire period so to move up that's what you need to do. That's exactly what my kid had to do in order to move up and it's why their income kept going up.

Networking doesn't work when companies randomly bring the ax down or hell the motherfucking chainsaw every few years when there's a blip in the stock price. You don't know who did not work with because you never know who is going to survive the next round of layoffs.

Comment Re:I use it (or it's mirrors everday). (Score 4, Interesting) 45

I like the idea of supporting creators to whatever extent I can. As an anime nerd I know that Blu-ray sales are the main metric whether a show gets another season or not. That and merchandise sales but I don't really have space to set up merch and I don't like buying it just to put it in a corner of a closet. Plus buying blu-rays gets me high quality video on a pressed disc that will more than likely outlive me.

I have no illusions though about how the people who make anime get treated. I know only a tiny fraction of the money I spend ever makes it into their pockets and more often than not they are run out of business repeatedly by rapacious corporations. So at the same time I don't really begrudge anyone who doesn't want to buy into that literally.

I think the correct solution is to buy the official release to support the creators but also change how you vote so that workers stop getting exploited. Worker exploitation is a political problem after all not an economic one.

Of course I have to live in the world the way it is now not the way I wanted to be so again if you're not buying blu-rays I don't be grudge you in the slightest. Although it's an anime fan like I said without the blue ray sales and the merch sales you're not going to get more of that show you like... And it really is the Blu-ray sales the drive the next season even more so than the merch a lot of times.

Slashdot Top Deals

Last yeer I kudn't spel Engineer. Now I are won.

Working...