HNHacker News
TopNewBestAskShowJobs

Jnr

1,192 karma · joined March 14, 2018

submissionscomments
Jnr··on I don't like passkeys
I am even more surprised about the multiple down-votes for this comment just because I like some feature. Must be a bunch of grumpy old keyboard warriors on this thread. 0__o
Jnr··on I don't like passkeys
Surprised to see so much hate towards passkeys. I absolutely love them when I can use them with Bitwarden and my own SSO. Sucks when I am limited to hardware tokens like yubikeys.
Jnr··on CrowdSec Source Code Leak
Not sure what you implemented.

They provide several IP blacklists. None of those seem to be false positives. You can also add custom 3rd party blocklists.

They also provide several different rulesets. It is up to you to choose which ones to use and fine tune. LLMs can be very helpful with that.

And there are 3rd party dashboards and tools that help you manage it more easily.

I use the free version as a simple WAF on multiple servers and it blocks a lot of bots. It did require some initial finetuning though.

Are there any better open source solutions?

Jnr··on Leaving Linux
I have been on the same Arch installation for 10+ years and the previous install on a different device was also ~8 years old. Could have just transferred files over and be done about it but I wanted to refresh my knowledge. :)
Jnr··on Cloud in a Bottle: making self-hosting accessible to everyone
Kubernetes supports multiple pluggable container runtimes per node. Can be quite useful when requiring some virtualization or running certain docker-in-docker scenarios for CI/CD workers. Maybe it can be done with Docker as well these days, but with kubernetes it is out of the box support.

Perhaps you could manually set up some VLANs and set up Docker networking to use those, but that has to be custom setup, none of that is a standard feature of Docker.

So instead of having to reinvent the wheel for each of those problems, you can just take kubernetes instead. And while it is a lot to learn, LLMs can make it a lot easier to do. For years I was running docker-compose stacks for self hosted things, but I replaced that once LLM agents became a bit less stupid. :)

Jnr··on Cloud in a Bottle: making self-hosting accessible to everyone
Having separate bare server for each service would become quite expensive.
Jnr··on Cloud in a Bottle: making self-hosting accessible to everyone
Yes, kubernetes makes it much easier to configure proper firewall through network policies.

Docker has networks but there is no good options to limit it beyond those and it is extremely basic and basically leaves everything open between your proxy and app.

Jnr··on Cloud in a Bottle: making self-hosting accessible to everyone
In the age of LLM agents, still going for Docker/Podmam on anything besides local development box seems like a weird choice.

Docker has poor tooling for network level security between the containers, has issues with different runtimes per container, etc.

It is just a bit primitive if you want to expose multiple services to the internet on the same server. One of those apps will get compromised and then all the others will follow.

If you want a decent self hosted server, ask your frontier LLM agent of choice to configure kubernetes (on something like k3s) with mandatory userns mapping so nothing runs as root on the host, default deny firewall so inter-container communication is as locked down as possible, and if your router supports, set up VLANs so none of the containers can access your other devices on the LAN. Use something like backrest to handle backups, alertmanager and Grafana for monitoring, Keel for auto updates. Also consider separating ingress for public and internal services and use Tailscale with split DNS to acces the internal entrypoint. Set up Crowdsec as WAF and subscribe to their free blocklists to filter out bots. Ask it to set this all up using Ansible, so it can be maintained.

While this would be extremely time consuming to set up and maintain by hand, an agent can do and test it in a few hours.

Jnr··on Apple introduces M6 and M5 Ultra
Because it still doesn't fully support all of the hardware on M1. I know it because I used Asahi while I had M1. Now I have M4 for work and it doesn't support Asahi at all.

I just use Linux PC as much as possible instead. And that 4$ M4 is just a fancy presentation computer I use when I travel.

Personally I would spend thousands on an actually great Linux laptop, but there are still none around.

Jnr··on Building a backyard office, the build and cost breakdown
I bought my first minisplit ~4 years ago since none of the contractors were available in the hot summer. I bought the tools as well (vacuum pump, manifold, pipe cutters, etc.).

It cost me ~650$ total.

The next time I bought a minisplit (3.5kW one), I already had the tools and it cost me only 450$. A proper one meant for use during harsh winter would probably costs a bit more though, at around 1000$.

So I have set up a few of them for my family and friends so far. The units come pre-charged with gas for ~5M of ducts, there is nothing hard to set them up.

I also set up ESP32 controllers so I could attach them to Home Assistant, bypassing any Chinese cloud apps, etc.

Jnr··on Claude Code May–August 2026 weekly limits promotion
With how bad Opus 5 and how expensive and limited Fable is, I would not be surprised.
Jnr··on Ask HN: Alternatives to GitHub
I did and then rolled back. Gitea is far ahead in CI/CD features, which is the main thing I want from my own git forge. And they also seem to keep adding more meaningful features, not just refactoring to keep some federation thing working.
Jnr··on LG to ban residential proxies from smart TV apps
I block known DoH servers on my lan and forward all dns requests to my dns server.
Jnr··on HomeLab #1: MikroTik as a Home Router
There is a safe mode built in. If you enable it and you loose connection to the router due to some misconfiguration, it will reset within 15 minutes to the point of where you started the safe mode session. Also if you mess up the IP layer, there is a chance that you can still connect and configure RouterOS through their WinBox program using the mac address.
Jnr··on HomeLab #1: MikroTik as a Home Router
It should be doable by most software engineers. They did teach some basic CCNA course in the university as part of computer science studies and the concepts taught there should help a lot with configuring any router, including RouterOS. It could also be helpful to watch some guides on routing and firewall on Linux, since RouterOS is just Linux with a very specific UI on top.
Jnr··on HomeLab #1: MikroTik as a Home Router
I just got a backup ISP at home and connected fiber directly to Mikoritk using SFP dongle instead of the box provided by ISP.

Scripts on RouterOS handle network checks for failover, DNS updates, etc.

I got that Mikrotik home router 10 years ago and it is still performing great and handles most of the use cases without issues.

Jnr··on Zig Creator Calls Spade a Spade, Anthropic Blows Smoke
I saw an estimate of around 160k $ somewhere in HN comments about the rewrite.
Jnr··on Why developers are ditching GitHub for Codeberg and self-hosting alternatives
I similarly have been using Gitea for some years. I use it as my main forge and mirror to Github for discoverability and community reports and contributions.

For public projects I have workflows that can publish and push containers to both Gitea and Github.

Jnr··on Better Auth is joining Vercel
How so? I am using their open source software, what have I missed?
Jnr··on Better Auth is joining Vercel
> "features that business care about"

I don't see companies using open source lining up to support the developers. Good for developers to come up with some monetization strategies to keep their software alive.

Jnr··on Better Auth is joining Vercel
From what I remember, next-auth is kind of dead and Better Auth developers have been maintaining security of next-auth for some time now. (or was it Vercel that did the maintaining?)

Better Auth is the go-to solution for many people using Nextjs, so it makes sense that Vercel puts some effort in maintaining it.

I have never had issues running Nextjs in regular containers, it is just a good open source solution, I don't see why it would be any different with Better Auth.

Jnr··on FUTO Swipe – A new swipe typing model
Can we please get this for iPhone? Their keyboard is extremely imprecise, I have to go back and correct each sentence.
Jnr··on WWDC 2026: Apple is Folding
Nothing new about it. It is a thin laptop, similar to Macbook Air which they have had for many many years.
Jnr··on WWDC 2026: Apple is Folding
Perhaps Apple is also running out of ideas.
Jnr··on London's Free Roof Terraces
Last time I was in London for a day, I simply reserved a table at one of the restaurants at Sky Garden and got in without any queues. Maybe I booked it on the previous evening, but not much earlier than that.
Jnr··on Flatpak Will Depend on Systemd
I doubt that. But they clearly thought that people should have a choice. And it is great. But fractured community using different tools for the same task makes slower progress. Each approach has its positives and negatives. I think it is great that we have wayland and systemd. It will eventually lead to something greater in the future.
Jnr··on Flatpak Will Depend on Systemd
When it comes to incorrect profiles, I suggest making a pull request to alsa-project/alsa-ucm-conf with correct configuration. I had similar issue with my audio interface a couple years ago but it was quickly merged and now it works better than on Windows or macOS.

Before that I did have custom config, it was not that hard to set up, there are great examples and explanations on Arch wiki: https://wiki.archlinux.org/title/PipeWire

Jnr··on Flatpak Will Depend on Systemd
Like wayland?

Where none of the desktop environments offer the same feature set. And the more compositors there are the harder it is for apps to use those new protocols, and guaranteeing a ton of bug reports from users using an unsupported compositor. That just hinders Linux desktop app development.

Jnr··on Flatpak Will Depend on Systemd
I think it came from the necessity for rapid integrations between different parts of the OS. And if it is handled as a single project it takes less time to improve it, since you don't have to align with 10 different projects and their release cycles.
Jnr··on Flatpak Will Depend on Systemd
> after all it has replaced GRUB.

With unified kernel images there is no need for grub or any other bootloader anymore. And UKI simplifies boot configuration and helps improving security in some aspects.

Page 1 of 18Next →