HNHacker News
TopNewBestAskShowJobs

AtNightWeCode

457 karma · joined March 29, 2021

At a dark place
submissionscomments
AtNightWeCode··on Cloudflare API, dashboard, tunnels down
You and all the others did not get it did you. The size of the outcry corresponds to the user base. If you fked something up that was really used at scale this thread would have exploded.
AtNightWeCode··on Okta's stock plunges after security breach
I wonder what was really achieved when we left basic auth with sessions and moved to web tokens. None of these jwt services handles logouts as far as I know. It is just a more complex way of doing just about the same thing.
AtNightWeCode··on Encrypted traffic interception on Hetzner and Linode targeting Jabber service
The way that certbot works with let's encrypt the only surprise is that this does not occur more often. We have monitoring on several certs used for TLS. We should probably add an alert if an A-record changes as well.

I assume the root cause is DNS tricks.

AtNightWeCode··on Is POSIX really outdated?
Posix is actually pretty terrible. It is funny how Linux people still defend it. My criticism.

Inflexible. Poor ACL management. All this recursive bs that I still can't wrap my head around. User groups, not a flat hierarchy? Poor observability.

Windows is terrible in many ways but with files and in comparison to Posix Windows actually got it right.

EDIT: I did not mention the article. It is silly to compare S3 to Posix. However. Azure and other cloud providers that did offer Posix storage have dropped those offerings.

AtNightWeCode··on The largest DDoS attack to date, peaking above 398M rps
If this is true than the design is problematic. What makes it even worse is that cancellation of requests typically does not work in cloud environments. It is a bit laughable that Azure for instance recommend the use of cancellation tokens but in reality you never get them for web requests.
AtNightWeCode··on The largest DDoS attack to date, peaking above 398M rps
This is just Google bs. There is no way in hell they can't mitigate anything at the edge of this nature. If this was a real problem it most likely originated from within GCP. The article does not even state where the traffic comes from.

EDIT: Ok, so this was a 0-day issue. Then it all makes more sense. Sorry.

AtNightWeCode··on Microsoft CEO testifies that Google’s power in search is ubiquitous
I think most corps allows known bots. To allow all traffic to a major site is not possible.

The problem is bigger the other way around I would say. That Google, AWS, Azure and so on use the same AS numbers for private and public cloud. It is not easy to detect if it really is the Google bot or some low-lifes performing DOS-attacks from GCP. Many attacks, especially state sponsored attacks, comes from trusted clouds.

AtNightWeCode··on 0-days exploited by commercial surveillance vendor in Egypt
I don't get it. If it is over http then you can play around with anything in a proxy. You have no TLS tunnel so it is not encrypted. It is by design.
AtNightWeCode··on The Bogus CVE Problem
It is not just a CVE problem. Many sec standards feels really random and difficult to work with. You can get better scores on some of these sec scans if you open up some ports in the firewall.
AtNightWeCode··on Snowden leak: Cavium networking hardware may contain NSA backdoor
At the end of the day. We need cryptography that is understandable. There is absolutely zero need for the complexity in this field that exists today.

And we need something better than just private keys.

AtNightWeCode··on Results of technical investigations for Storm-0558 key acquisition
Is the key a certificate? Then it might be installed on all Service Fabric clusters. There is overall something fishy with X.509 handling in Azure.
AtNightWeCode··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Maybe it is the price model. It should state what type of security updates are included and for how long these are for free and what the expected cost after that is. I think a problem is that you buy a thing and not a thing and a service.
AtNightWeCode··on Microsoft had three staff at Australian data centre campus when Azure went out
I straight out think MS lied when they said this was an .au only issue. We had a surge of rouge traffic from MS during this issue and we are pretty much on the other side of the globe.
AtNightWeCode··on The worst programmer I know
Metrics. I used to work on a team with skills in agile development. The process was evaluated at every retro and everything was tweaked. One member of the team however continued to put tasks into states that was not even in our agile board. Meaning. You could not drag a task into that state. You had to set it. Turned out that the idiot CTO used an unknown report to evaluate staff. One metric was putting a task into a specific state no longer used by our team. The idiot CTO had told his favorite pet dev about this metric.

Too bad I quit before the CTO, CEO and most of the board members got fired. Would have enjoyed sitting there and going. Yes, yes, yes.

AtNightWeCode··on ChatGPT user sessions are down 29% since May
Have no time. Rework this. This is flawed in many ways.
AtNightWeCode··on Accessible Palette: stop using HSL for color systems (2021)
I created a game editor some years ago that had several HSL alternatives including one contrast corrected bar and two different light/shadow corrected bars. I used it mostly the other way around though. Creating suggestive backgrounds with many colors but with low contrast between them.
AtNightWeCode··on Changing my relationship with GitHub Copilot
I quit using GC since it adds cognitive load and because it lures one into incorrect solutions. I always try to have a single focus when I work. I don't even like having multiple screens for the same reason. I do use AI for coding sometimes but then that tool is my main focus.
AtNightWeCode··on Hackers can get your IP through Skype by just sending a link, no click required
Most chat programs have solved this by using a proxy. The downside of this is that the proxy may be blocked. There should be a more generic and safe way to deal with link previews.
AtNightWeCode··on Imminent Death of ChatGPT [and Generative AI] Is Greatly Exaggerated
I think a problem with AI is that it is used so much by people that don't really know a field. Like middle management. I heard those fools claiming that a complete IT project took a couple of minutes to do with ChatGPT. The same crazy people that said 5 years ago that all devs will be replaced by low-code by some years ago. Incompetent people will use AI the most. That is a risk.

There is no death of ChatGPT in sight. Even if the UX was a bit of a hoax to begin with. It would be if some of the other models beat it.

AtNightWeCode··on OpenTF announces fork of Terraform
What is the problem with BSL? Is it that the code is still available but you have to run their binaries? Honest question.
AtNightWeCode··on A good measurement culture where numbers don’t replace common sense
Overall this is my standpoint too. But it depends on how KPIs are set. I think it is more destroying to not have any general directions at all.
AtNightWeCode··on Node.js 20.6.0 will include built-in support for .env files
Envs are not process secure. Files are. Ram disks exists.
AtNightWeCode··on Node.js 20.6.0 will include built-in support for .env files
Environment variables should never be used. This was a known security hole already in the last century. Several OS solved this by config files that comes with file permissions. The correct solution on Linux and Windows at least. And still people use envs.
AtNightWeCode··on AI bots are now better than humans at decoding CAPTCHAs
Delete all captchas everywhere. While at it. Delete all challenges. I am tired of wasting time into all this bs. If we did put the same amount of time into real solutions like rate-limiting and actually making endpoints secure there would be no problem to begin with.
AtNightWeCode··on Htmx is part of the GitHub Accelerator
Before I break my neck completely. Htmx is still JS? No?
AtNightWeCode··on The OpenTF Manifesto
The fantastic cost of running TF in the cloud is painful. Several years ago it was very clear that it would be difficult for HC to survive once they became a company registered at stock markets.
AtNightWeCode··on The OpenTF Manifesto
This is perhaps the most incorrect post you will ever find on HN. I am not a huge fan of Terraform. However, TF is made for infra not config. There are several tools out there to manage config like Salt, Ansible and so on.
AtNightWeCode··on Firefox finally outperforming Google Chrome in SunSpider
Some years ago it was common that some sites did not work or was slow in FF. I can't remember that I've had that problem for years. Good work by the FF team regardless of these benchmarks.
AtNightWeCode··on Show HN: LLMs can generate valid JSON 100% of the time
"" valid!
AtNightWeCode··on Backward Compatibility, Go 1.21, and Go 2
Could some of the genius down-voting argue for the reason why Google needs both of these more or less dying langs?
← PreviousPage 10 of 34Next →