HNHacker News
TopNewBestAskShowJobs

Thom2000

22 karma · joined December 5, 2022

submissionscomments
Thom2000··on Tail-Call Interpreters in Rust – Jimmy Ostler
> (If the author reads this, my name changed from Noel to Neal at some point. I don't really mind though; my name is a bit unusual and I've been called all sorts of things.)

I think it'd be good to update the about page with that info: https://noelwelsh.com/landing/about/

Thom2000··on Oracle cut its Always Free ARM limits to 2 OCPU / 12GB, enforced Aug 18
> Your free server will likely have a blacklisted ip address. > > Oracle is exceptionally frustrating to use in the first place. Pay the 5$ a month and use AWS or Digital Ocean

Funny thing that you mention this because according to Xenedra it's my DO IP that's blacklisted (even though I have it for years with no bad activities) but the free Oracle one is fine.

I was quite surprised by that.

Thom2000··on TLS certificates for internal services done right
Yep. Especially with non-wildcard certs this leaks all service names (privacy concern).
Thom2000··on TLS certificates for internal services done right
Sadly most tools still doesn't support it: https://github.com/cert-manager/cert-manager/issues/8373#iss...

And then the issue is protecting the private key of the issuer and monitoring certificates (it's a good idea to do that anyway).

Thom2000··on Nitpicking the shell history scene in 'Tron: Legacy'
> The artist, JT Nimoy, was an Emacs user but still thought it would be fun to set up a dichotomy--some fun details on this blog

I don't see any details about setting up a dichotomy in that article (just that the author was a happy Emacs user). Or maybe that was in that HN meetup you mention?

Thom2000··on GitHub is sinking
Github still doesn't support SHA-256 git repos (https://github.com/orgs/community/discussions/12490) even though their competitors (Gitlab, Codeberg) have that for ages now.
Thom2000··on SSH certificates: the better SSH experience
Sadly services such as Github don't support these so it's mostly good for internal infrastructure.
Thom2000··on Building a Transparent Keyserver
> PGP supports RSA. That's enough reason to avoid it.

I hate to break the narrative but age also supports RSA, for SSH compat:

https://man.archlinux.org/man/age.1#SSH_keys

Thom2000··on Building a Transparent Keyserver
I wonder if they think of a deeper integration of this into the age binary. Currently the invocation looks extremely ugly:

    age -r $(go run filippo.io/torchwood/cmd/age-keylookup@main joe@example.com)
Thom2000··on Show HN: Firm, a text-based work management system
> My biggest hurdle was getting it to export to a nice looking PDF that could be emailed or printed later.

If you can export to structured data such as JSON, I guess Typst would be a perfect fit for that job.

Thom2000··on Pwning the Nix ecosystem
Exactly!

Bearer tokens should be replaced with schemes based on signing and the private keys should never be directly exposed (if they are there's no difference between them and a bearer token). Signing agents do just that. Github's API is based on HTTP but mutual TLS authentication with a signing agent should be sufficient.

Thom2000··on Working pipe operator today in pure JavaScript
FWIW it's possible to run readme examples automatically add part of tests: https://github.com/parallaxsecond/rust-cryptoki/blob/main/cr...
Thom2000··on Modern messaging: Running your own XMPP server
You don't need any third party modules and can proxy based on ALPN (https://wiki.xmpp.org/web/Tech_pages/XEP-0368#nginx) thus running everything on port 443. Note that ALPN is not encrypted AFAIK but public wifi services don't care.
Thom2000··on NSA and IETF: Can an attacker purchase standardization of weakened cryptography?
It's hard to answer your question without repeating the arguments made in the post itself.

Are you implying that djb blew the matter out of proportion?

Thom2000··on Modern CI is too complex and misdirected (2021)
I've used dynamic pipelines. They work quite well, with two caveats: now your build process is two step and slower. And there are implementation bugs on Gitlab's side: https://gitlab.com/groups/gitlab-org/-/epics/8205

FWIW Github also allows creating CI definitions dynamically.

Thom2000··on Comptime.ts: compile-time expressions for TypeScript
Interesting. I've never seen the import-with syntax, though and it's hard to find any documentation on it. Is this a syntax extension?
Thom2000··on C++26 Reflections adventures and compile-time UML
Sadly, Rust proc macros operate on tokens and any serious macro implementation needs third-party crates.

Compile-time reflection, with good, built in API, akin to C# Roslyn would be a real boon.

Thom2000··on JSON5 – JSON for Humans
"comment" may be relevant to the object. Maybe using "_" for the whole object comment would be safer?
Thom2000··on Engineering with Enclaves
That clarifies some matters - thanks!
Thom2000··on Engineering with Enclaves
It seems like everything you have described could be done with TPM: creating a signing key for TLS mutual authentication (against the secret store) with policy that allows using that key only if system configuration did not change (PCR values stay consistent). Additionally TPMs allow remote attestation (via quotes and endorsement keys).

So I'm wondering what's the advantage of Nitro Enclaves? Better out of the box tooling?