HNHacker News
TopNewBestAskShowJobs

Lex-2008

385 karma · joined January 15, 2019

http://alexey.shpakovsky.ru/
submissionscomments
Lex-2008··on Patch OpenSSL on November 1 to avoid “critical” security vulnerability
The globalsign atricle says:

> If you’re using version 1.1.1, this vulnerability doesn’t affect you

AFAIK, LibreSSL forked even before that - when OpenSSL was version 1.0 or 0.9 even. So likely not affected - unless a similar issue appeared there after the fork.

Lex-2008··on Show HN: Versioning Filesystem for SQLite
re: gzipping the db itself - yep, I tried and saw the same effect as you did: about half a size. I think it's because of indexes (I once played with sqlite3_analyzer[1] and on some databases it showed about half of disk space was used by indexes) and unused pages (all the space which can be vacuum'ed - again, size of some databases can be decreased almost twice by vacuum'ing).

[1]: https://www.sqlite.org/sqlanalyze.html

On the other side, indeed, text dump is likely not the most space-efficient way of storing raw DB data (compared to some binary one), so I wouldn't be surprised to find databases for which gzipped sql dump is bigger than (gzipped) database itself. I would even say that I'm surprised that it's not true for most databases :)

Lex-2008··on Show HN: Versioning Filesystem for SQLite
regarding multiple writes - I think hardest part would be to find an sqlite version where "read is a combination of all the files".

Speaking of multiple writers, I've recently heard about "BEGIN CONCURRENT" feature of SQLite [1] - currently it lives on its separate branch, but I hope they will eventually merge it to the main branch. Not sure if it can be used in your case, but worth mentioning anyway, I think.

[1]: https://www.sqlite.org/cgi/src/doc/begin-concurrent/doc/begi...

Lex-2008··on Show HN: Versioning Filesystem for SQLite
re: backup SQL dumps instead of db files - indeed! In my small experiment (SQL databases in a browser profile, [1]), simple `sqlite3 "$file" .dump | gzip >"$file.sql.gz"` decreased size of files to be backed up about 10 times!

I'm not sure how it compares to Borg's delta- and zstd-compression, though.

[1]: http://alexey.shpakovsky.ru/en/minimizing-size-of-browser-pr...

Lex-2008··on Day ahead electricity prices for EU
as sibling comment says, some numbers match those shown on https://www.nordpoolgroup.com/en/maps/#/nordic
Lex-2008··on 6 Raspberry Pis, 6 SSDs on a Mini ITX Motherboard
not OP, but I would start with filling disk space up to 100%, or creating zillions of empty files. In case of distributed filesystems - maybe removing one node (under heavy load preferably), or "cloning" nodes so they had same UUIDs (preferably nodes storing some data on them - to see if the data will be de-duplicated somehow).

Or just a disk with unreliable USB connection?

Lex-2008··on Let's Encrypt’s subscriber agreement changes on Sept 21
Sounds reasonable, but what if I lost the private key?

Speaking from personal experience: I received 7 emails from them, for various "tag" parts of my email (username+tag@server.example). Two of them - for when I was playing with Caddy server many years ago (well before COVID) - and its "auto-https" feature. There's no chance I still have these keys - I likely `rm -rf`'d whole caddy directory.

Lex-2008··on Botspam apocalypse
re: someone was unable to get past that captcha - this reminded me a story I heard back in ICQ times about some human who couldn't pass anti-bot question: "What planet do we live on?"
Lex-2008··on Hacker Typer
Nice! Also mentioned on reddit: https://old.reddit.com/r/itsaunixsystem/comments/amyahe/russ...
Lex-2008··on Hacker Typer
For those who haven't seen or don't remember it - one time (please let me know if there were more) when Hacker Typer got on TV: "They wanted to show me making games on TV, I couldn't resist!" imgur: https://imgur.com/lz7hOlC reddit: https://old.reddit.com/r/gifs/comments/1w862f/they_wanted_to... youtube: https://youtu.be/xnDwChRYB6Q?t=118
Lex-2008··on SQLite Internals: Pages and B-trees
Not OP, but I remember reading an interesting article about issues that simple write() might face: https://danluu.com/deconstruct-files/

And here's what SQLite does to ensure that in case of application or computer crash database contains either new or old data, but not their mix or some other garbage: https://sqlite.org/atomiccommit.html

Lex-2008··on SQLite 3.39.2
is it only me or does this site works only over plaintext http, while you gave an https link?
Lex-2008··on Plaintext HTTP in a Modern World
well, to be fair, https://zerossl.com/pricing/ has a "free" column :)

On the other page, https://zerossl.com/features/acme/ it looks like free acme certificates can have a wildcard records (*.example.com).

https://www.sslforfree.com/ claims they use zerossl and support wildcard records.

Also, one of others you mentioned also has a free acme option, but without mentioning wildcards: https://www.ssl.com/how-to/order-free-90-day-ssl-tls-certifi...

Lex-2008··on BootBASIC Interpreter in 512 Bytes
> Getting your computer to a usable or useful state without the help of another machine is something that we shouldn't have lost.

I once saw (and used) a similar feature on Mac: pressing some key combination during boot allowed you to wipe and reinstall OS from Internet. Not sure how exactly it was implemented, though, but I agree it would be cool if BIOS had a feature where you could type an URL to ISO and it would download and boot it.

Lex-2008··on Ask HN: Critique My Blog Design
re: whether the new version is actually an improvement - yes, I like new version more than the old one :)

While I agree that in new design headers are more recognizable as clickable links, I still find "Read more" link being useful (after reading the article paragraph).

Regarding adding name and photo - I think it's a personal taste :) Personally I don't feel a need to have them on the main blog page, but if you like it - please do, to give the blog a bit of personality. With name and photo the blog will probably feel more personal - written for those people who know you (either IRL or online). And without - the blog feels more like designed to be a thing by itself. Although note that it's my personal opinion, which might change tomorrow morning :)

Regarding tags - note that you can see "main page with tags" at https://incoherency.co.uk/blog2/tags/all.html :) Wonder how much heavier it makes the page look. Maybe hide it behind some "show tags" link?

Also check the <title> tag of the main page - I'm not sure if it was your intention to name the page "incoherency - ", but for me it looks kinda broken (something's missing on the right side of "-"), so maybe call it something like "incoherency - all posts"?

Lex-2008··on Ask HN: What do you use VMs for regularly?
Occasional gaming on my wife's work PC (in parallel as she's working there).

VMWare can provide DirectX 11 support for guest OS, and there are many kinds of gaming-friendly remote desktop applications to play remotely from my Linux laptop.

Originally inspired by this LTT video: <https://www.youtube.com/watch?v=-Mgnwn4twZE>, except that I wanted "work" system to have 100% of all resources when "gaming" one is not used (since it's started up only once in a few months). Hence, nothing as fancy as in video: "host" OS is the work system, and "guest" OS is booted up once in a few months for occasional gaming.

Lex-2008··on Map Data: False Assumptions
I'm not sure if your question is rhetoric, but somewhere I've read that some map providers show it depending on what country the user (website visitor) is in - so users in country A see the disputed territory as belonging to country A, users in country B see it as belonging to their country, and everyone else sees this territory as "disputed between A and B".

Governments of both A and B might have opposite demands from the same map-making company and threat it with legal consequences.

Also, in recent news: https://yandex.com/maps/ decided not to show country borders at all: https://techcrunch.com/2022/06/09/yandex-maps-no-borders/

Lex-2008··on Asking for a date of birth (2013)
oh wow, you don't even need to move your finger when entering digits - it's "one"s all along!
Lex-2008··on Ask HN: Is it still conceivable to remain an anonymous developer nowadays?
Daniel Stenberg, developer of very popular opensource library/utility curl, once received a threatening email:

https://daniel.haxx.se/blog/2021/02/19/i-will-slaughter-you/

SQLite developers were receiving phone calls in the middle of the night, so decided to change temporary files prefix:

https://github.com/mackyle/sqlite/blob/3cf493d/src/os.h#L52-...

In both cases, their libraries were used in some other software, which upset users.

Lex-2008··on Spam and Blogs = Trouble (2006)
same here, only with "email" field. For CSS-less humans, it even had a label: "please leave this field blank" :D
Lex-2008··on Kazakhstan president proposes reforms to limit his powers
re: Putin controlled Medvedev

Well, some people say that under Medvedev Russia was a bit friendlier with USA:

https://en.wikipedia.org/wiki/Russian_reset

I'm not sure that points highlighted in that article would happen if Putin was president (allowing U.S. forces fly over Russia, supporting Iran sanctions, reducing nuclear arsenals, U.S. dropping plan to build a missile defence shield in Eastern Europe).

Lex-2008··on Outline of benefits of Thorium over vanilla Chromium
I first parsed it as "21 years-old builds" and was wondering what kind of builds Chrome had 21 years ago.

Then I did some math and realized Chrome is just 14 years old. And 21 years ago, Firefox was called Mozilla, and IE6 was just released.

Lex-2008··on Running your own email is increasingly an artisanal choice, not a practical one
Re: [citation needed];

> Gmail obvious spam still #1 in the quarantine folders..

-- Michael Peddemors, President/CEO LinuxMagic Inc.

https://www.mail-archive.com/mailop@mailop.org/msg14526.html

Lex-2008··on Nextspace: a desktop environment that brings a NeXTSTEP look and feel to Linux
and in the "tiling WMs" camp there is subdivision into "dynamic" and "static" tiling window managers
Lex-2008··on Netlify Drop
> HTTPS is automatic

> Have you seen the little green locks on your browser? That means the site is safe and secure using HTTPS.

It's gray.

Not to be nitpicky - maybe it's just my OS theme (KDE Breeze Dark), but the HTTPS padlock is gray or dark-white in all three browsers I tested: Edge, Chrome, Firefox. Can anyone confirm?

Lex-2008··on WSL2 can now mount Linux ext4 disks directly
Sadly, that's yesterday news.

See here: https://security.stackexchange.com/a/249484

> ... a newly discovered ransomware variant exhibits the ability to detect and compromise partitions (including hidden partitions), a behavior not thought to have been seen before in ransomware.

with a link to original source:

https://www.fortinet.com/blog/threat-research/newly-discover...

quote from that link:

> At the time of discovery, FortiGuard Labs researchers believed the ransomware was seeking out partitions to find possible hidden partitions setup by systems administrators to hide backup files. But further analysis confirmed an even more advanced technique. The DarkSide Ransomware variant seeks out partitions on a multi-boot system to find additional files to encrypt.

Lex-2008··on Microsoft no longer signs Windows drivers for Process Hacker
do you mean you never received spam from @gmail.com? Lucky you!
Lex-2008··on Malwarebytes' privacy VPN is Mullvad in a shady trenchcoat
looks like geoIP database - for me it gives almost same data as https://www.ip2location.com/demo/
Lex-2008··on Why this Website is not, and may never be, HTTPS
Worth noting that at the same time, "they" weren't good enough at pushing new things that the same time. For example, all new compression methods work only over HTTPS (actually, this alone can be a reason to switch to HTTPS) - because they were incompatible with some HTTP proxies: https://bugs.chromium.org/p/chromium/issues/detail?id=14801

<rant> I'm actually looking forward for them to drop HTTP digest auth, because it's the only auth scheme which doesn't rely on sending shared secret over the wire with each request </rant>

Lex-2008··on Google developing own CPUs for Chromebook laptops
> all of them will be mutually incompatible, with own programming languages and data formats. The future looks bleak.

Server hardware had (still has somewhere): SPARC from Sun, PowerPC from IBM, HPPA from HP, etc... See for example list of supported architectures for Debian4: https://www.debian.org/releases/etch/hppa/ch02s01.html.en

But it feels like amd64 is winning today. Don't you think that eventually one of these architectures you're talking about (Google's, Apple's, Samsung's, CCP's) will win over others, one way or another?

← PreviousPage 3 of 7Next →