Because whether you agree or not, sandbox is a necessary for banking app. No other app should ever be able to EASILY (emphasis on easily) perform arbitrary read on the banking app data.
- 0 Posts
- 30 Comments
Until web standard can agree to have device bound session, it won’t happen. Cookie stealer malware is just too dangerous to perform financial transaction. So maybe for read only stuff it is fine
bitfucker@programming.devto
Linux@lemmy.world•Linus Torvalds reaffirms that Linux is not "Anti-AI" & not a "Social Warrior" projectEnglish
0·2 months agoComing back here from another discussion, I do find it funny now that a legal entity can choose to not pay taxes but a human cannot avoid that in any reasonable way
bitfucker@programming.devto
Linux@lemmy.world•Linus Torvalds reaffirms that Linux is not "Anti-AI" & not a "Social Warrior" projectEnglish
1·2 months agoHmmm, I guess it depends on what you mean by capital. Because The Linux Foundation certainly has assets that they could donate to other FOSS project
bitfucker@programming.devto
Linux@lemmy.world•Linus Torvalds reaffirms that Linux is not "Anti-AI" & not a "Social Warrior" projectEnglish
3·2 months agoWhy? The proof that linux exists under capitalism already proves your point does not hold
bitfucker@programming.devto
Linux@lemmy.world•Linus Torvalds reaffirms that Linux is not "Anti-AI" & not a "Social Warrior" projectEnglish
2·2 months agoI’d say FOSS is not more political than paying taxes. FOSS is just another way of using the copyright law enforcement without which FOSS cannot exist. If no copyright law enforcement is in place, then the GPL license wouldn’t have power. So FOSS is just another way a law abiding citizen may use their rights/entitlement and perform their obligation with copyright law like how they have right/entitlement and obligation from taxes.
I only need ORM to have the flexibility of DSL table modeling for repeated fields. Think, createdAt, updatedAt, id (and the PK that comes with it), etc. After the migrations are written, I prefer to use a query builder
bitfucker@programming.devto
Technology@lemmy.world•Researchers find a way to reliably spot AI writingEnglish
2·2 months agoThat’s not how story writing works. Or any long form written art works for that matter. Try to ask any writer if they ever “write in their head” and publish those as a book as-is
bitfucker@programming.devto
Opensource@programming.dev•How to Be a Good Open Source Maintainer
7·2 months agoAlternatively, just do it sqlite style. Open source, closed development
bitfucker@programming.devto
Technology@lemmy.world•Anybody Who Thinks Orbital Data Centers are a Good Idea Is Suffering from AI Psychosis, Experts ArgueEnglish
2·2 months agoDamn, what’s the movie name again? With Tom Cruise cloned and all?
Edit: It was oblivion
I forgot where I got this, but it is from fediverse

Every *-git package also fetch it from the repo. The apt analogy is someone haven’t been maintaining the nixpkg and then it gets adopted by someone else. Now that someone else change the build script to be malware. So it is no fault of the upstream
I know where you’re coming from when you say they are different. But I disagree on that because at the end of the day you’re still trusting other people would not act maliciously or get their account compromised. The selection process doesn’t make it any more special as demonstrated by xz in my example.
Anyone can be an AUR submitter and maintainer. Act in good faith and never become an Arch maintainer. Someone can be an Arch maintainer and be good for a few years then something happened and their account got hacked or bad blood made them act rashly.
That’s precisely what I mean when I equate AUR maintainer to the distro maintainer. To the package management system, they are both trusted. Not in the sense of how special they are or how strongly you can trust one but not the other.
Yes, and that is no different than distro maintainer that maintains the infrastructure and package. Anyone can volunteer. That’s how xz is compromised. The point is that aurto trust models mimic those of other package managers. Trusting the authors implicitly trust the code. The only other special things from distro maintainer is their PGP signatures are required to perform release on the main repo. This is better because as I stated earlier, reviewing PKGBUILDS would encourage people to just skip it. Not everyone has the time for that. But when a maintainer changes? Aurto removes the package for you to perform that first trust again on the new maintainer. This is no different than if you update the arch keyring just more manual
Well, it is just like a distro maintainer account anyway. If the maintainer account is compromised then gg for the whole distro. That’s what happens with other supply chain attacks as well and yes, I do think we need a way to fix that without compromising on ease of usability
Yeah, use and promote
aurtoinstead. They require you to trust the maintainer and would remove the package from the local repo if the maintainer is changed
bitfucker@programming.devto
Opensource@programming.dev•First Look at Audacity 4: A Beautiful and Modern Revamp of the Audio Editor
51·3 months agoTantacrul, (I think) the lead of the Audacity (and also the guys that lead Muse Score) said that V4 is migrating everything first to QT. After that, they will start adding more features and also fix more backwards compatibility to the old engine (because V4 will also introduce new engine)
bitfucker@programming.devto
Opensource@programming.dev•What We're No Longer Seeing: AI and the Invisible Newcomer in Open Source
111·3 months agoGreat write up about the effect of LLM and first point of contact. It still needs to be said however that sometimes the question itself already has an answer and it is buried deep in the other noise. What we can do is make a place that like stackoverflow but without the toxicity
bitfucker@programming.devto
Opensource@programming.dev•A modernized, complete, self-contained TeX/LaTeX engine, powered by XeTeX and TeXLive.
21·3 months agoPlus one to this. I’m happy with typst but the op is asking for latex. Typst is an alternative to latex not another compiler



Photo is a word on its own tho so that also creates confusion if you shortened photography to photo. “Oh, I do photo for a living”.