HNHacker News
TopNewBestAskShowJobs

PaoloBarbolini

104 karma · joined July 12, 2021

CTO at M4SS Srl paolobarbolini.it
submissionscomments
PaoloBarbolini··on Typst makes big strides
And unlike browser-based solutions, Typst can produce PDF/A, it can embed files into the PDF and it can produce charts and QR Codes on it's own without having to rely on an external solution.
PaoloBarbolini··on Rate limits on GitLab.com are changing
Is this going to apply just to `https://gitlab.com/api/v4/:rest_of_the_url` endpoints, or also to the API-ish endpoints like `https://gitlab.com/:org/:repo/raw/HEAD/:path`?
PaoloBarbolini··on We got admin access to Baseten's production GitHub
Even something like Qwen 3.8 27b could do this.

Lookup certificate transparency and continue from there https://crt.sh/?Identity=baseten.co&exclude=expired&match=IL...

PaoloBarbolini··on Forgejo <=16.0.3 Critical RCE
If you are self-hosting Forgejo and haven't done it yet, consider creating a Codeberg account and following https://codeberg.org/forgejo/security-announcements/issues
PaoloBarbolini··on Ask HN: Are others seeing Google's reCAPTCHA rejecting Firefox users?
A few years ago a service for which we had just implemented a scraper for (they had no API, and the customer needed info from 1000s of accounts) added a captcha right after we had implemented the scraper.

We quickly figured out that the server didn't validate the captcha challenge code with Google. It worked for 3 years until they changed the system to send a code via email to validate your login, and limiting you to 1 session at-a-time. Now we have different problems to deal with...

PaoloBarbolini··on AI models ran real businesses: They sent $12,431 in fake invoices, lost $3,200
I don't get what they were trying to prove. An LLM on it's own, little time and money... what were they expecting it to do? Not that I expect that different conditions would necessarily improve the situation, but seriously they didn't even give it a chance.

"Make as much money as you can" sounds like the prompt someone out of school would give.

Meanwhile they spammed the internet, sent fake invoices and a bunch of other very annoying if not even possibly illegal things.

PaoloBarbolini··on Hetzner is working on LLM Inference
They confirmed on LinkedIn that they are working on it.

Also, they have a feature request that has been getting many votes recently: https://feature-request.scaleway.com/posts/1251/prompt-cachi...

PaoloBarbolini··on Ubuntu 26.04
Why do we still put up with GNOME?

I've spent the last 10 years off and on from Linux. Had I used something other than GNOME, I believe my experience would have been better.

I've been on KDE for the last 3-4 years and things work so well I could never imagine going back to GNOME.

PaoloBarbolini··on Jepsen: NATS 2.12.1
There are many things they don't seem to understand about their own product.

https://github.com/nats-io/nats.rs/issues/1253#issuecomment-...

PaoloBarbolini··on Rootless Pings in Rust
The repo link goes to a 404 page.
PaoloBarbolini··on EXIF orientation info in PNGs isn't used for image-orientation: from-image
The image could have been encoded with a high compression ratio, or even something like OxiPNG. In that case, while re-encoding it wouldn't lose quality, it could still have the side-effect of making the file bigger.
PaoloBarbolini··on Ghost 6.0
A few years ago I convinced a friend to make their blog using Ghost 4. Very bad decision. I haven't kept up with it but at the time they supported only 1 mailing list service. What kind of open source project does that kind of vendor lock-in to their users.
PaoloBarbolini··on Raspberry Pi 5 Gets a MicroSD Express Hat
That's "easy" when all they have to do is to package https://github.com/raspberrypi/linux
PaoloBarbolini··on Postgres LISTEN/NOTIFY does not scale
I've had the same experience and I fixed part of the problem by writing my own Rust client, Watermelon. It's still missing a lot of features but at least I'm not blocked by weird decisions taken by upstream.
PaoloBarbolini··on Protecting NATS and the integrity of open source
See also the issue: https://github.com/nats-io/nats-server/issues/6832 Archived version: https://web.archive.org/web/20250425154144/https://github.co...
PaoloBarbolini··on GitHub Phishing Campaign making use of OAuth and render.com hosted site
I'm also finding that this has happened already in the past and GitHub didn't cleanup the spam entirely, like: https://github.com/Xyntax/1000php/issues/1#issuecomment-2318...
PaoloBarbolini··on GitHub Phishing Campaign making use of OAuth and render.com hosted site
Before this event, I've has another encounter with GitHub. What happened is that an AI coding assistance startup seemed to have created bots that would:

1. find new GitHub issues on random repos

2. fork the repo

3. make a commit, trying to implement whatever was requested in the issue

4. reply to the issue with a link to the commit, indemnifying themselves of the code quality (which was very poor), and linking to their platform

I reported a few of those issues to GitHub. To me, the problem seemed almost obvious:

1. they were using sketchy GitHub usernames

2. there was evidence of similar replies having been mass-deleted in the past

3. some of the issues also seemed to have been opened by sketchy users

GitHub took a few days to reply and didn't seem to understand how bad the situation was, and basically allowed them to continue. I don't expect to have to spend a lot of time writing an elaborate "criminal case" to convince GitHub that they are allowing their platform to be abused by these bots.

PaoloBarbolini··on GitHub Phishing Campaign making use of OAuth and render.com hosted site
Amazing work! This is the first time I've seen this kind of issue fixed so quickly.

GitHub should learn from this.

PaoloBarbolini··on GitHub Phishing Campaign making use of OAuth and render.com hosted site
Link to search results: https://github.com/search?q=%22We+have+detected+a+login+atte...
PaoloBarbolini··on The owner of ip4.me/ip6.me, Kevin Loch, has died
`curl https://myip.wtf/json` too is nice to use when debugging things
PaoloBarbolini··on From xz to ibus: more questionable tarballs
Same for Rust. In the short term we're trying to solve it on the user's side with https://crates.io/crates/cargo-goggles, but in the long term the registry should probably do it.
PaoloBarbolini··on Testcontainers
Could you provide an example?
PaoloBarbolini··on Netlify just sent me a $104k bill for a simple static site
It means they protect themselves from layer 3 and 4 DDoS. For layer 7 you're mostly on your own. That's what most companies mean when they talk about DDoS anyway.
PaoloBarbolini··on Netlify just sent me a $104k bill for a simple static site
This is the reason I've never used all of these user-facing serverless services. The price depends on the usage, but if anything goes wrong they are the ones to decide what you pay. It's not comfortable thinking that you could screw up, or get DDoS'd, and the remedy is hoping they wave the bill.
PaoloBarbolini··on DNS over HTTPS is not what I thought
Certificates can be issued for IPs too, CAs don't usually do it though.
PaoloBarbolini··on Show HN: Quickwit – OSS Alternative to Elasticsearch, Splunk, Datadog
According to the documentation[1] Kafka is just one of the supported inputs for ingestion, so it should be possible to run Quickwit without it if you're not intending to write logs into Kafka. Jaeger also seems like another optional dependency. Same also probably for Zookeeper?

1: https://quickwit.io/docs/ingest-data/kafka

PaoloBarbolini··on Review of Hetzner ARM64 servers and experience of WebP cloud services on them
I've been trying their Arm servers for a while and I've noticed some differences in the colors in htop for Debian 12, as if there were a slight difference between the x86_64 and the aarch64 image. Other than that everything's going fine and I'm planning to use Arm for every server in the Falkenstein datacenter (the only one with Arm dedicated and cloud servers for now)
PaoloBarbolini··on PostgreSQL – Don't Do This
Also if you're worried about the server having a different timestamp and possibly not having configured the connection timestamp correctly, as the following test shows Postgres always specifies the timezone of the timestamp it's giving you

server=# CREATE TABLE test1 (date TIMESTAMPTZ NOT NULL);

CREATE TABLE

server=# INSERT INTO test1 VALUES (NOW());

INSERT 0 1

server=# SELECT * FROM test1;

             date        
     
------------------------------

2023-06-01 08:00:30.40968+02

(1 row)

server=# SET timezone = 'UTC';

server=# SELECT * FROM test1;

             date    
         
------------------------------

2023-06-01 06:00:30.40968+00

(1 row)

PaoloBarbolini··on IPv4 Turf War
Why are you doing a separate request for every /8? I feel like this would be the first thing that would kill the site, if it weren't for the fact you're on HTTP, the browser is talking HTTP/1.1, so it only does 6 concurrent requests per domain.
PaoloBarbolini··on IPv4 Turf War
Tonight I discovered I could create 128 m2.micros from my AWS account no questions asked. Very very worrying. Much happier with Hetzner with an initial limit of 25.
Page 1 of 2Next →