HNHacker News
TopNewBestAskShowJobs

CAP_NET_ADMIN

822 karma · joined January 7, 2022

submissionscomments
CAP_NET_ADMIN··on C Course Online
Bulk of those blocked requests are to Launch Darkly, Datadog and Stripe.

I'd expect commenters on tech-oriented site to understand how uBlock Origin works... or at the very least how to check the browser console instead of fearmongering.

CAP_NET_ADMIN··on Sourcegraph went dark
My company looked into paying Sourcegraph many times in the past, but they were prohibtively expensive every time we checked.

It's 49 USD per user per month for Code Search, like what the hell man? It's more than twice as expensive as Github Enterprise. Almost twice the cost of Gitlab Premium.

At some point it was 100USD per month per dev, I also remember it being "Starts from 5k USD per year", you can find some quotes for that in old submissions regarding Sourcegraph going open, closed, open and closed again.

CAP_NET_ADMIN··on Sourcegraph went dark
I'd like to point to the previous episode in this YA drama series:

"Sourcegraph is no longer open source" by me, from last year

https://news.ycombinator.com/item?id=36584656

CAP_NET_ADMIN··on Linux Memory Overcommit (2007)
The truth is that if you're having issues with default overcommit configuration (namely overcommit_memory == 0 and overcommit_ratio == 50) your application probably sucks and you have to actually diagnose it and fix it.

"We run a pretty java-heavy environment, with multiple large JVMs configured per host. The problem is that the heap sizes have been getting larger, and we were running in an overcommitted situation and did not realize it. The JVMs would all start up and malloc() their large heaps, and then at some later time once enough of the heaps were actually used, the OOM killer would kick in and more or less randomly off one of our JVMs."

I know that 2007 may have been different times, but I'd argue that max heaps for all your JVMs running on a system probably shouldn't exceed around 88% of the total system memory. (percentage goes up as the total system memory goes up from 128GB -> 256GB -> 512GB)

CAP_NET_ADMIN··on Number of incidents affecting GitHub, Bitbucket, Gitlab and Jira is rising
Around 2021 a lot of higher-up people at my company pushed for moving from our local Gitlab instance (neatly hidden in our segmented VPN network) to the global one - because that's what all of the cool guys are doing.

I've resisted this, because I know that I can sleep peacefully at night when the inevitable monthly "GitLab Critical Patch Release" email comes.

CAP_NET_ADMIN··on Europe is in danger of regulating its tech market out of existence
Tech sector pretending that the regulations that worked in all the other sectors don't and won't apply to them or they will upend the human civilization.
CAP_NET_ADMIN··on Siblings miss crucial life-extending treatment because of CrowdStrike outage
I've personally trialed Crowdstrike for my company (around 30 people) and found it a buggy mess, especially on non-Windows platforms - after the trial was over we decided to not use it. However this is not the case for most companies, feds, auditors or both will force you to use this BS and there's absolutely nothing you can do.
CAP_NET_ADMIN··on Siblings miss crucial life-extending treatment because of CrowdStrike outage
Maybe try reading what happened during the Crowdstrike fiasco and then comment about it. Crowdstrike auto updates itself, the agent allows you to select update cadence, but this was an update to the "channel" files which auto update themselves a few times per day and you don't have any control over it.
CAP_NET_ADMIN··on EU Council has withdrawn the vote on Chat Control
I think it lacks /s at the end.
CAP_NET_ADMIN··on US prepares to exempt AUKUS nations from ITAR
I long for a few years of peace and prosperity, so that I won't have to read military, geopolitical and pandemic "experts" everywhere I look with half of them being agents of foreign interests.
CAP_NET_ADMIN··on Dehydrated: Letsencrypt/acme client implemented as a shell-script
I think the amount of alternative ACME clients is a testament to the absolute mess that certbot is.

Constant breakage unless you're using snaps on the most popular distributions. The CLI is absolutely idiotic and convoluted and the plugins do a lot of guess work without informing you, which results in some fun debugging. It's also a large pile of dependencies that take up space.

CAP_NET_ADMIN··on Why No IPv6?
No one wants to deal with IPv6 except for the almost religious crowd that creates an endless blogspam on how YOU should migrate to IPv6 because it's awesome!. The only interaction I had with dedicated IPv6 users was when I blocked an entire /48 from our app due to high abuse rates and got very angry email from the owner that I'm stifling the global progress.
CAP_NET_ADMIN··on Top Europe court chides Switzerland in landmark climate ruling
Please go on, reading stuff like this is always interesting for me, even if it concerns other countries.
CAP_NET_ADMIN··on Show HN: PostgreSQL index advisor
If you have some PostgreSQL performance issues, I'd recommend checking out PGAnalyze - they've offered a much more advanced index advisor for some time now.

My company is a paid customer since around 2020 and we are very satisfied, easily beats the Datadog's (which we use for the rest of our infra and apps) observability offering for PostgreSQL.

CAP_NET_ADMIN··on BCHS software stack: BSD, C, httpd, SQLite
I feel like interacting with the internet using C is nowadays as productive as changing your JS framework every other year.
CAP_NET_ADMIN··on SMTP Smuggling – Spoofing Emails Worldwide
For not properly disclosing this to Postfix maintainers, they earned themselves a bonk on the head.

I'm sick of this trend of successful attacks being basically free marketing, while successful defences and maintainers working long hours for free to keep open source software secure never receive any praise.

CAP_NET_ADMIN··on The debt problem is enormous, and the system for fixing it is broken
I feel like our monetary system as a way of balancing resources is failing, most of the debt nowadays doesn't really matter and doesn't represent what actually happens in the economy.
CAP_NET_ADMIN··on Stealthy Linux rootkit found in the wild after going undetected for 2 years
Corporate Ransomware attacks typically use 0-days and social engineering to achieve goals. No system is perfect, but a system in place is better than not having anything in place.

Things have changed in the last 10 years. Long gone are the days of only using signature databases.

https://attackevals.mitre-engenuity.org/results/enterprise?v...

CAP_NET_ADMIN··on Stealthy Linux rootkit found in the wild after going undetected for 2 years
Most of the currently used AV software contains heuristic/ML components that are able to gather and analyze various indicators of compromise. Without something like that running, you're basically tied to manual review of systems running at the moment. Making malware for such scenarios is basically making a Base64-encoded script in the language of your choice and then exploiting something(either the user or some software) to get it to execute.

I know, because I've been writing small malware toys and it got blasted by both Bitdefender and ESET.

CAP_NET_ADMIN··on Hetzner is terminating contracts with all users who had a Russian postal address
Good, maybe Hetzner IP ranges will become a little cleaner :)
CAP_NET_ADMIN··on Orca 2: Teaching Small Language Models How to Reason
LLMs can be trained on all the math books in the world, starting from the easiest to the most advanced, they can regurgitate them almost perfectly, yet they won't apply the concepts in those books to their actions. I'd count the ability to learn new concepts and methods, then being able to use them as "reasoning".
CAP_NET_ADMIN··on Server-side sandboxing: Containers and seccomp
Yep, can recommend systemd in this case, really easy to apply basic hardening to services that just works.
CAP_NET_ADMIN··on MariaDB ditches products and staff in restructure
I have 5 million users running on PostgreSQL, 3 dedicated servers (primary + 2 replicas), we use less than 190 connections, vanilla PostgreSQL and no things like pgbouncer.
CAP_NET_ADMIN··on Show HN: OpenStatus – Open-source monitoring with incident managements
In what ways is it better than Uptime Kuma which doesn't require a bunch of SaaS spaghetti to run and has much broader community support.

[1] https://github.com/louislam/uptime-kuma

CAP_NET_ADMIN··on Poland may seek extradition of Ukrainian Nazi WW2 veteran Hunka from Canada
Atrocities section on wikipedia is pretty thick

https://en.wikipedia.org/wiki/14th_Waffen_Grenadier_Division...

CAP_NET_ADMIN··on A Firefox-only minimap (2021)
I've been using Firefox for the past year due to some weird incompatibility between my GPU and Chrome's video decoding. It caused dropped frames and caused my YT quality to go down.

Haven't really noticed any issues on Firefox except the lack of actually good web translator.

-moz-element looks sweet, hope it comes to other browsers.

CAP_NET_ADMIN··on Sourcegraph is no longer open source
Just wanted to add that some simpler option of buying the license would be sweet, it tends to be much easier to get signed up for something that doesn't require contract and we can just use company credit card. Maybe it could be available while offering something akin to previous Free Enterprise (without new, cutting edge features) license but with higher seat limits? I don't know, just spitballing.

I like paying for things that I use and bring me value, but at the moment Sourcegraph is a hard sell due to high cost compared to small company size and being based outside of Western Europe and US.

CAP_NET_ADMIN··on Sourcegraph is no longer open source
Sourcegraph only provided non-OSS images and the build process was difficult and broken for a long time, the application itself was frequently broken in OSS version as well, searching issues for a few minutes brings up quite a few results. [1] [2] [3] [4]

It's no wonder, that the usage of OSS version was pretty low, when few were able to build it and even if they managed that, the resulting application was broken every few releases.

Both VS Code and Chromium are easy to build, due to their nature and popularity, they are available prebuilt from many sources. I would install "unofficial" Chromium build from my distribution's repository, I wouldn't keep my code in unofficial Sourcegraph build from some random person on Github. Comparing them is rather unfair, but there's another issue that stopped OSS adoption.

For a long time, official Sourcegraph Docker image came with a 10 seat free license, which suited many people and they weren't looking for alternatives like OSS build.

I would argue that announcing license change and closing of your product as a small block in change log file or when someone mentions the problem in Github Issues is not adequate for such a change.

Not using open-first principles, restricting the product by using enterprise only plugins, which others mentioned under this post, not providing open source builds and changing license without preceding announcement, while previously using open source terminology for some feel-good free marketing leaves a bitter taste. Especially with so many companies doing this right now due to interest rates.

https://github.com/sourcegraph/sourcegraph/issues/43231 https://github.com/sourcegraph/sourcegraph/issues/43203 https://github.com/sourcegraph/sourcegraph/issues/6790 https://github.com/sourcegraph/sourcegraph/issues/6783

CAP_NET_ADMIN··on Sourcegraph is no longer open source
Global code search across hundreds of repos even if they are hosted at different SCMs
CAP_NET_ADMIN··on Sourcegraph is no longer open source
It was 100USD per month per seat some time ago, with a high number of devs it may actually be beneficial to roll something on your own.
← PreviousPage 2 of 3Next →