Hacker Newsnew | past | comments | ask | show | jobs | submit | gkbrk's commentslogin

Wine has better backwards-compatibility than Windows these days.

The Windows Compatibility Layer for Windows will be Wine someday.

It's always on The Pirate Bay. That's the streaming service everything is on.

The best advertisement for these companies would probably be running a public Polymarket account so everyone else can quickly check how accurate they are.

A monitor cannot install software on your computer by the way. It's Windows installing this software automatically (for some reason), so the blame should be on Microsoft.

Autorun of malware when you plugged in a USB drive was also a Windows issue, I'd classify this as the same security problem.


> A monitor cannot install software on your computer by the way.

I think everyone in the HN crowd knows that.

> the blame should be on Microsoft

No, they blame should ALSO be on Microsoft, they are the enablers.


> I think everyone in the HN crowd knows that.

I actually did not. I know there is some degree of two-way communication over HDMI/DP, and was curious if this was how the software was installed. I think discussing the technical details is a great use of the HN comment section.

(Wifi enabled display device -> HDMI -> Device) would be an incredibly interesting attack vector.


Monitor could also be USB-C which opens up the USB attack vectors.

“I think everyone in the HN crowd knows that.”

I would think everyone in the HN crowd would be aware of HEAC, the hdmi Ethernet channel, etc.

With full access to the hosts tcp/ip stack, we’d do well not to overlook the potential vectors for a monitor to install software on your computer… especially when the operating system is complicit.


Do any PC graphics cards support Ethernet over HDMI?

Ok, I don't use Windows and never will, so wasn't aware of this feature, and it would've been nice to have that context. Thought maaybe LG is exploiting a vuln in Windows via USB-C or over one of the niche HDMI features, but gathered it's not that.

> Autorun of malware when you plugged in a USB drive was also a Windows issue, I'd classify this as the same security problem.

Not really. AutoRun ran whatever was on the USB drive, with no oversight. This installs a driver from a company that's supposed to be reputable enough to get their driver signed by MS and pass validation. LG breached that trust here.


> that's supposed to be reputable enough to get their driver signed by MS and pass validation. LG breached that trust here.

I think you overestimated how reputable is enough.


Actually it frequently can, since a modern monitor is often on USB and in a position to impersonate a keyboard and/or mouse.

I wouldn't put it past most of these companies.


Not sure if it was an LLM hallucination, but I was looking for a wifi dongle for linux. Apparently some of them now present as an autorun usb disk until the driver they auto install sends some magic unlock handshake.

So, I avoided those.


The blame should be on Microsoft and LG, both.

So how is this malware?

[flagged]


Please do not blame the user.

You are describing 'the blame should be on Windows'.

The consequence of Windows having the blame is that one should not buy it.


that's funny; because my root cause analysis didn't show the user as the person making the decision to show themselves ads? did yours, or was the victim blaming intentional?

Not making the specific decision (showing ads) but making the general decision (giving power to Microsoft). Blaming customers for buying MS products is not really much different than blaming Trump voters for voting for him. In both cases risks were obvious beforehand.

> In both cases risks were obvious beforehand.

Not everyone is able to accurately predict the future from past patterns. They still deserve dignity and respect. Just because you were able to predict it easily doesn't make it possible for everyone.

The solution I'd like is instead of you making excuses for shitty behavior, instead maybe condemn the shitty behavior? You're allowed to say both, you can said I told you so, (to switching to not windows) while also being bothered when you see SWE at some company mistreat other people. You can complain about LG being abusive with the power they were given, while also offering alternative OS install instructions to that grandma who only wants to VC with her grandkids without being tricked into paying for trash-tier antivirus she doesn't need.


The word “victim” is honestly pretty funny in this context. Nothing really happened to anyone.

I wouldn't classify getting random malware as "nothing happening".

Because it spies on them and nags. But Windows itself already does that. LG could've done the same thing sans the mcafee popups and nobody would care, in fact Dell is probably doing that.

> But Windows itself already does that.

So once an person is victimized in this way, it becomes a free-for-all where future transgressions cease to matter?


Yep. Not free-for-all, but silently installed crap collecting metrics is well within their expectations.

So... When people expect to be harmed because they've been harmed before, then it's perfectly OK when they get harmed again.

Neato.


> Yep. Not free-for-all, but silently installed crap collecting metrics is well within their expectations.

I don't expect software engineers to build stuff like this. I expect humans to treat other humans with dignity and respect. In fact, it makes me extremely angry when I see people do it, or advocate that others should tolerate it.


I don't think they should tolerate it, but they do. 0 people are going to leave Windows because of this latest scandal, because the ones who care have already left. At some point I accepted that this doesn't matter to a lot of people, which is their right and choice, and if Linux wants to attract users, it has to do it by being easier to use besides just being more ethical.

The monitor should absolutely take the major part of the blame by being the source of the malware and poisoning the system for everyone else.

Ironically if Microsoft responded by just never signing LG software again, but kept this auto-install thing in, LG monitors would become the best to use with Windows.

its not the source though is it? its not like it's downloaded via the hdmi cable, it comes from Microsoft that offer the service of installing crap

now explain to the class who uploaded it to Windows Update service

The same server that's responsible for sanitizing garbage JS out of user content is also responsible for sending the Content-Security headers. Why would you trust it with one, but not the other? If it's buggy garbage it will also send the wrong headers.

This is a pretty good argument in the case of software written by a small team of experienced engineers. In that scenario, if the engineers don't have the nous to avoid the kinds of HTML injection vulnerabilities that might allow an attacker to inject their own JS code, then, as you say, they are probably also making lots of other mistakes.

A CSP is more valuable in a larger organization, where the codebase is always at risk of being modified by the organization's worst engineer.


All the codecrafters content is available on Github too, for free.


This I didn't know, thank you for that! "Build a selfhosted codecrafters" might be a fun meta "build an X"


But can you run it on their platform? NO, you need to run it on your own machine which takes a bit of work. And we have over 80 courses waaay over whatever codecrafters has


> you need to run it on your own machine

Isn't that the best part of codecrafters? Being able to just use your own text editor instead of a janky web based one which loses everything you typed on page refresh?


I'd rather have something I can tinker with on my own machine, thank you very much


You were right, and this comment stuck with me so I have decided to go ahead and implement it.

Every course now has a "work in your own editor" mode: you can download a zip with the starter code for every lesson plus a run_tests.sh that runs the full test suite locally. After that, you can push it to a public GitHub repo, we will judge it based on our grading system and internal tests


I respect your opinion too.


if you're learning code challenges you should probably learn how to run code locally.


You can't just say perchance.


It looks very natural, cheaper is better after all. Performance axis going up, and cheapness axis going up match each other.


gp's argument is that cheapness is a construct, derived from the real, and natural, cost parameter which most people are naturally accustomed to interpreting as increasing from left to right. cheapness would then replace the cost label, and feel natural. alas, this is not what we have here.


If your ISP cares, you need a better ISP.


There's no need to package it because ClickHouse is just a single binary.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: