The history and endurance of vi is impressive. I never thought I would be using the same editor today that I started using in the mid 90s because it was more l33t.
The comments about LLM contributed code seems like a specific axe to grind that otherwise detracts from a nice history lesson.
The appeal of GraphQL is that it eliminates the need for a BFF and easily solves service meshing. Over fetching is more of a component design problem than a performance issue.
It’s how a lot of code is being generated by owners of small startups with minimal engineering engagement. PMs are producing full walking skeletons of designs that used to take a week to polish to that fidelity.
By installing MDM you’re effectively chaining your security to the security of the MDM. The MDM gives you the ability to install arbitrary code via a blessed backdoor. There’s no reason currently not to suspect that anything said on that phone (signal or not) is compromised.
They used an internal fork delivered via MDM. There are no guarantees that Signal can make about the software running on those phones and per the reports it’s a lot of phones.
This is currently my bet. This looks like something I would set up— state actors are not in my threat list. But, I’m usually being paid to protect the employer not the employee.
This is so frightening. I worked in corporate security, and that was occasionally a leaking ship, but this wouldn’t even fly with our engineers even if we wanted their message history. This is negligence.
But tl;dr anything said on those phones is assumed to be compromised until proven otherwise by time or a whole lot of very interesting security verifications. So far the evidence that this is a very large leak looks probable based on the evidence presented.
Yeah, I was shocked to see this buried. If the allegations are verified this could be a huge leak on what a number of people were led to believe is a secure by default platform. It turns out when you can’t trust the CI/CD pipe those guarantees go out the window.
Installing Signal using this method provides none of the guarantees Signal can normally provide by being an open verifiable application. It not only opens you up to state actors, but also IT folks like us. This is very much tech news. It helps explain why MDM is both critically important for businesses and terrible for security.
This news story has been strange for me for awhile because on one hand NO our public officials should not be using Signal, but it isn’t because Signal is a bad technology choice. Signal is great. It’s probably the most useable service that’s verifiably secure.
Is meilisearch ready for production workloads? I would love to use some of the feature set, but is the only option for HA running multiple instances and keeping them in sync?
I’m certainly guilty of using one of these hosted cli tools in a pinch (crontab I can’t quit you), but adding an LLM in the mix just adds more complexity. Getting a few of these tools under your fingers is probably way easier than building an app to try and figure it out for you.
The comments about LLM contributed code seems like a specific axe to grind that otherwise detracts from a nice history lesson.