HNHacker News
TopNewBestAskShowJobs

8organicbits

7,215 karma · joined June 10, 2020

Hello!

https://alexsci.com/blog/

https://indieweb.social/@robalex

Feel free to reach out on email if our interests align: robert [at] robalexdev (dot) com

Statements are my own and do not represent the positions or opinions of my employer/client.

submissionscomments
8organicbits··on Show HN: Canary – Monitor any URL for changes, get AI-powered intelligence
Why GitHub Actions?
8organicbits··on Ask HN: What's the Deal with Forward Deployed Engineers?
Are you sure you're offering a competitive salary?
8organicbits··on Abusing Customizable Selects
Would changing your usercontent.css or uBlock Origin filter to set all select appearance attributes to auto help? There are some challenges, like the custom style could hide elements, but I think that should give fall-back equivilent styling.
8organicbits··on Apple's intentional crippling of Mobile Safari
Notifications struck me as odd. I aggressively disable notifications in my apps because they are often just ads or engagement focused. But as a developer, it would be cool to have a way to notify an iOS user other than building a native app and paying the iOS tax. There's a bunch of utility apps not getting built because of this limitation.
8organicbits··on The “small web” is bigger than you might think
I know kagi doesn't do it, but it is possible to specify language in the feed (xml:lang) such that a feed reader can filter languages the user doesn't understand out of multi-language feeds. One challenge is that lots of bloggers forget to add that tag.
8organicbits··on The “small web” is bigger than you might think
Very cool.

Crawling related sites for tags could work (open graph tags on the website are another good source). I'm wary of mixing data across contexts though. A blog and a Mastodon profile may intend to present a different face to the world or could discuss different topics.

8organicbits··on Kagi Small Web
I think the problem is that it's hard to curate feeds in a language you don't understand. I've been building an uncurated index of OPML blogrolls, with no language restriction. The OPML blogrolls are curated by their owners, so someone decided they met some inclusion criteria, but the overall list is uncurated.

https://alexsci.com/rss-blogroll-network/

8organicbits··on Cert Authorities Check for DNSSEC from Today
Can you not check the RFCs?
8organicbits··on The “small web” is bigger than you might think
Reminds me of https://notes.pault.ag/tpl/
8organicbits··on The “small web” is bigger than you might think
The tag cloud part may be a challenge. Web feeds don't always tag their content.

I have a blog filter that does something similar (https://alexsci.com/rss-blogroll-network/discover/), but the UI I ended up with isn't great and too many things are uncategorized.

8organicbits··on The “small web” is bigger than you might think
One objection I have to the kagi smallweb approach is the avoidance of infrequently updated sites. Some of my favorite blogs post very rarely; but when they post it's a great read. When I discover a great new blog that hasn't been updated in years I'm excited to add it to my feed reader, because it's a really good signal that when they publish again it will be worth reading.
8organicbits··on The “small web” is bigger than you might think
Is there a good free-but-subscriber-only solution for blogs? It seems like a contradiction, but in practice it may be manageable.
8organicbits··on Bucketsquatting is finally dead
I think you are hung up on the word "leak".

Putting a secret subdomain in a DNS query shares it with the recursive resolver, who's privacy policy may permit them to share it with others. This is a common practice and attackers have access to the aggregated datasets. You are correct that third-party web servers or CDN could share your HTTP path, but I am not aware of any examples and most privacy policies should prohibit them from doing so. If your web server provider or CDN do this, change providers. DNS recursive resolvers are chosen client side, so you can't always choose which one handles the query. Even privacy-focused DNS recursive resolvers share anonymized query data. They remove the source IP address, since it's PII, but still "leak" the secret subdomain.

Any time you send secret data such that it travels to an attacker visible dataset it is vulnerable to attack. I call that a leak but we can use a different term.

8organicbits··on Bucketsquatting is (finally) dead
There's a lot of online documentation about passive DNS. Here's one example

> Passive DNS is a historical database of how domains have resolved to IP addresses over time, collected from recursive DNS servers around the world. It has been an industry-standard tool for more than a decade.

> Spamhaus’ Passive DNS cluster handles more than 200 million DNS records per hour and stores hundreds of billions of records per month, providing you with access to a vast lake of threat intelligence data.

https://www.spamhaus.com/resource-center/what-is-passive-dns...

8organicbits··on Bucketsquatting is (finally) dead
No man-in-the-middle is needed, DNS queries are often collected into large datasets which can be analyzed by threat hunters or attackers. Check out passive DNS https://www.spamhaus.com/resource-center/what-is-passive-dns...

You'd need to check the privacy policy of your DNS provider to know if they share the data with anyone else. I've commonly seen source IP address consider as PII, but not the content of the query. Cloudflare's DNS, for example, shares queries with APNIC for research purposes. https://developers.cloudflare.com/1.1.1.1/privacy/public-dns... Other providers share much more broadly.

8organicbits··on Bucketsquatting is (finally) dead
Ah you're right, they are always wildcard certs. I think I was mis-remembering https://news.ycombinator.com/item?id=15826906, which guesses names based on CT logs.

In either case, the subdomain you use in DNS requests are not private. Attackers can collect those from passive DNS logs or in other ways.

8organicbits··on Bucketsquatting is (finally) dead
~As far as I know, bucket names are public via certificate transparency logs.~ There are tools for collecting those names. Besides you'd leak the subdomain to (typically) unencrypted DNS when you do a lookup and maybe via SNI.

Edit: crossout incorrect info

8organicbits··on Show HN: s@: decentralized social networking over static sites
These days people are fearful of their work ending up in LLM training datasets. A private, but static hosted website is on a lot of people's minds. Most social networks have privacy setting these days, which feels like a missing feature of standard, static blogs.
8organicbits··on Show HN: s@: decentralized social networking over static sites
That should scale pretty well. The HTTP fetch of posts/index.json could use conditional get requests to avoid downloading the body when there are no changes. Static files are dirt cheap to serve.
8organicbits··on Redox OS has adopted a Certificate of Origin policy and a strict no-LLM policy
The commit you listed was merged upstream.

https://github.com/zigimg/zigimg/pull/313

8organicbits··on The death of social media is the renaissance of RSS (2025)
You don't need to explain RSS any more than you need to explain SMTP or HTTP. A product that uses RSS could gain traction without the user ever knowing it uses RSS. Products like Google Reader prove that is possible.
8organicbits··on Ask HN: What Are You Working On? (March 2026)
I made a web-based speaking clock: https://alexsci.com/time-at-the-tone/

I had been doing lots of time-based work for a blog post and ended up annoyed that so many clocks around me were visually out of sync. Especially my microwave and oven clocks. Using the tool I got them synced up beyond what I could perceive.

8organicbits··on Put the zip code first
There's a few messages it can show:

      const msgs = [
        `Yes, we know ${country} exists. We're very proud of you.<br><br>This site is about US address forms — the ones that make <em>Americans</em> scroll past Turkmenistan 200 times a year. You have your own postal code problems. We believe in you.`,
        `We see you're visiting from ${country}. Welcome. We regret to inform you that this rant is specifically about American address forms, which are — and we cannot stress this enough — <em>unbelievably bad</em>.<br><br>Your country probably has its own postal code horrors. We'd love to hear about them: <a href='mailto:shame@zipcodefirst.com'>shame@zipcodefirst.com</a>`,
        `Hello from across the pond (or whichever body of water separates us from ${country}). This is a US ZIP code website. We are aware that other countries exist. We just have 160 million addresses and a 50-state dropdown to be mad about first.<br><br>Your frustrations are valid. Your postal codes are also useful. Put them first too.`
      ];
8organicbits··on UUID package coming to Go standard library
Have you seen UUIDv3/v5 used there though? I've seen lots of md5 historically and sha variants recently, but not the UUID approach.
8organicbits··on UUID package coming to Go standard library
It can be, but you should prefer UUIDv4 if you do that. One problem is that UUIDv8 does not promise uniqueness.

> UUIDv8's uniqueness will be implementation specific and MUST NOT be assumed.

Here's a spec compliant UUIDv8 implementation I made that doesn't produce unique IDs: https://github.com/robalexdev/uuidv8-xkcd-221

So, given a spec-compliant UUIDv4 you can assume it is unique, but you'd need out-of-band information to make the same assumption about a UUIDv8.

I wrote much more in a blog post: https://alexsci.com/blog/uuid-oops/

8organicbits··on UUID package coming to Go standard library
The question evaluates different skills when you solve it in Java. If you allowed XML, you'd see Java candidates reach for the standard library, as it has a built-in XML parser. Using plain text responses was a good fix, as the candidate can focus on concurrency, networking, and error handling, which is probably what you were trying to assess.
8organicbits··on Boy I was wrong about the Fediverse
> mastodon feeds are prone to shameless promotions, scams, and attention whoring

My mastodon feed contains only the users I follow. If they post unwanted things I unfollow them. Mastodon doesn't force you to see content from people you don't follow.

The sfba trending list has engagement-bait, but you shouldn't look there (on any social media site) if you don't want that sort of content.

8organicbits··on Boy I was wrong about the Fediverse
If you don't want to choose, install the official mastodon app. It should direct you to create an account on mastodon.social, unless you go out of your way to pick something different.

I suspect the sign up flow has changed since you last tried.

8organicbits··on UUID package coming to Go standard library
You're talking about the hash-based UUIDv3/v5? I haven't found examples of those being used, but I'm curious.

Using MD5 or 122 bits of a SHA1 hash seems questionable now that both algorithms have known collisions. Using 122 bits of a SHA2/3 seems pretty limited too. Maybe if you've got trusted inputs?

8organicbits··on UUID package coming to Go standard library
No, UUIDv8 offers 122 bits for vendor specific or experimental use cases. If you fill those bits randomly, you get the same amount of randomness as a v4. The spec is explicit that it does not replace v4 for random data use case.

> To be clear, UUIDv8 is not a replacement for UUIDv4 (Section 5.4) where all 122 extra bits are filled with random data.

https://www.rfc-editor.org/rfc/rfc9562.html#section-5.8-2

← PreviousPage 4 of 34Next →