HNHacker News
TopNewBestAskShowJobs

TimWolla

2,996 karma · joined June 20, 2013

[ my public key: https://keybase.io/timwolla; my proof: https://keybase.io/timwolla/sigs/MWclLW9WYzVuQbvkZA3v4bdSRwlEhNxpGmt9zzpiVLg ]
submissionscomments
TimWolla··on Hetzner Apple Mac Mini Offering
> The customer forum requires a login to access

It's not just a login. You need to actually be a customer. I consider that a good thing, because it allows me (and Hetzner) to speak more freely compared to a fully public forum. That's also why I just linked to the forum instead of quoting.

> and unfortunately is often in German.

That's true. The majority of the active user|customer base is German (I am myself) and thus communicating in German is the obvious choice. I've seen a few English-speaking folks participating by using a translator of choice to read the threads and then simply responding in English. I think it works well enough, as virtually every German understands English. Especially a German running servers.

TimWolla··on Hetzner Apple Mac Mini Offering
SSH by default according to Hetzner's customer forum [1].

[1] https://forum.hetzner.com/index.php?thread/28493/&postID=280...

TimWolla··on Please stop closing forums and moving people to Discord
> If your email client doesn’t do that, perhaps you need a better email client.

Which email client does?

TimWolla··on Improving Git protocol security on GitHub
> You can't authenticate over HTTPS anymore

You can, just no longer using username and password. Instead you must use an access token.

TimWolla··on How does Google Authenticator work?
One reason might be that those characters would include letters. A digits-only code is much easier to type, e.g. using a restricted keypad, such as a phone.
TimWolla··on Debian 11 “Bullseye” Released
> My first time doing a Debian upgrade and it’s not a great experience compared to CentOS

My understanding was that CentOS does not even support upgrades between major versions, is that not true?

FWIW: I successfully upgraded 3 machines of mine yesterday. 2 Hetzner Cloud VMs, 1 dedicated server at Hetzner. I've never had any major issues during Debian upgrades since I've been doing them ~10 years ago. One time I hit a kernel bug [1] with my configuration, but that would also have happened without the upgrade.

[1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931574

TimWolla··on IPv4 pricing
> You don't leak anything as the link doesn't seem to be accessible publicly (at least for me).

Yes, the forum requires registration and is open for customers only. That's why I said that I hope I don't leak anything (by saying that this topic was discussed in their (private) forum).

TimWolla··on IPv4 pricing
> For security reasons, I’d much prefer to get them without one (I disable the interface and firewall it 100% anyway), but it’s not an option to get a virtual machine without the public IPv4 address.

I agree and hopefully without leaking anything: This is also an request within their customer forum [1].

[1] https://forum.hetzner.com/index.php?thread/28220/&postID=277...

TimWolla··on IPv4 pricing
The pricing change is only about additional IP addresses for a single machine. Each machine will still come with one IPv4 included for "free":

> Our dedicated root servers will continue to include one free main IP; there will be no change here.

TimWolla··on IPv4 pricing
You can assign a Unique Local Address [1] subnet to Docker. Unique Local Addresses are the IPv6 equivalent of 192.168/16, 10/8, ...

Docker's documentation explains how to assign an IPv6 subnet to Docker: https://docs.docker.com/config/daemon/ipv6/ and https://docs.docker.com/network/bridge/#use-ipv6

You then can lookup a container's IPv6 address using 'docker inspect' and then directly connect to it from your host.

[1] https://en.wikipedia.org/wiki/Unique_local_address

TimWolla··on Akamai Edge DNS was down
Unbound has a 'serve-expired' option: https://nlnetlabs.nl/documentation/unbound/unbound.conf/#ser...
TimWolla··on Rust and Load Balancers
(2019)
TimWolla··on Public Suffix List
> Getting a domain listed is pretty hard.

I disagree. I've made two PRs [1] to that list to add domains where we assign subdomains to mutually non-trusting parties to ensure proper cookie security for these.

Both times the turn-around times were less than a week. In my first PR I even made a small mistake, because I did not read the instructions correctly. I promptly corrected it (< 5 minutes later) and the maintainer then merged my PR like 2 minutes later.

However we properly researched what the PSL does for us and what it does not before filing the PR. Also the domains do not hold anything other than customer data (similar to github.io).

[1] https://github.com/publicsuffix/list/pulls?q=is%3Apr+author%...

TimWolla··on Things I wish Git had: Commit groups
A rebase always creates a new hash, because the commit hash is a hash over the contents of the commit. This contents include, among others, the parent commit(s) and the time of committing (which in case of a rebase will be different than the time of authoring).
TimWolla··on “Please don't waste maintainers' time on your KPI grabbing patches”
> ("Borken" is a city in Germany, that's my only association with it )

Being German myself it's also the plural of "Borke" (i.e. the "bark" of a tree): https://de.wikipedia.org/wiki/Borke

TimWolla··on “Please don't waste maintainers' time on your KPI grabbing patches”
> they tried to fix "borken" to "broken" and the maintainer was not happy […] this does come down to not being familiar with this particular bit of slang - but they push back and argue a bit which doesn't help

I did not know "borken" either, but I am aware of "borked" and "broken". Based on that email thread someone else already attempted to fix this in the past.

Maybe it's an indication that the so-called "joke" is not actually funny and it should be adjusted to either "borked" or "broken" to not cause others to send the same fix?

TimWolla··on New GitHub Issues Beta
Thanks. I missed that list item, because it did not have a corresponding screenshot / screencast.
TimWolla··on New GitHub Issues Beta
I find it interesting that it sometimes shows my very own repositories (or repositories of one of my organizations) within the 'Explore repositories' section on the dashboard. As if I didn't know those repositories yet.
TimWolla··on New GitHub Issues Beta
I'm more interested in GitHub's Issue Forms (as an evolution of Issue Templates): https://twitter.com/frenck/status/1355620350176976901

Does anyone know what the status of these is?

TimWolla··on ZFS fans, rejoice – RAIDz expansion will be a thing soon
> If tomorrow SnapRAID stops working, I can replace just that component with something else without affecting the rest of the system.

Can you actually? If some layer of that storage stack stops working then you can no longer access your existing data, because all these layers need to work correctly to correctly reassemble the data read from disk.

TimWolla··on 2021.06.08 Certificate Lifetime Incident
There is another incident report in Bugzilla referenced in Let's Encrypt's: https://bugzilla.mozilla.org/show_bug.cgi?id=1715455#c1 references https://bugzilla.mozilla.org/show_bug.cgi?id=1708965

KIR S.A. is another CA that issued certificates with the same one second issue (1 year + 1 second instead of 1 year) and reported that one month ago.

TimWolla··on Changes to Docker Hub Autobuilds
Too bad. IMO the big benefit of automated builds was that Docker Hub was linked the source repository and showed the original Dockerfile, so that one was able to more easily verify what exactly a Docker image contains (provided one trusts Docker to correctly build these automated builds).
TimWolla··on HAProxy 2.4
Disclosure: Community contributor to HAProxy, I help maintain HAProxy's issue tracker.

HAProxy is virtually unusable as a file server, but really shines as a reverse proxy. One of the main reasons I almost always deploy HAProxy in tandem with (stock) nginx is the superior HTTP rewriting / configuration. See also my comment back on HAProxy 2.0: https://news.ycombinator.com/item?id=20198232

HAProxy's configuration is a procedural style configuration. The HTTP rules (e.g. adding or deleting headers) are processed in order if their condition matches. (Stock) nginx has a declarative configuration which makes it hard for me to understand which options apply when and the inheritance by nesting different blocks is sometimes very confusing. One example would be an `add_header` in a `location` completely overriding (instead of extending) an `add_header` in a `server`. So if I want to put e.g. HSTS into the server to apply to the full host and also want to add headers for different paths, then I need to duplicate the HSTS stuff.

TimWolla··on Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea
The WebAuthn API can register a resident key on the YubiKey. This will basically store the username, private key and domain on the YubiKey. The website then can later request authentication based off a resident key. This will cause your web browser to query the YubiKey for resident keys of the website. You then can select the resident key with the correct username and will be logged in based on strong cryptography without needing to enter your password or username. Depending on your YubiKey configuration you might need to enter your YubiKey pin for this to work. See the screenshot in this comment on a GitHub issue: https://github.com/keepassxreboot/keepassxc/issues/3560#issu...

The website will need to support this of course. Also the amount of storage available for resident keys on the YubiKey is limited.

TimWolla··on Cloudflare’s CAPTCHA replacement with FIDO2/WebAuthn is a bad idea
> For instance, Yubi Key 5 supports up to 25 keys

This is for resident keys. A YubiKey 5 supports an infinite number of non-resident WebAuthn keys, because the returned key handle will simply be the private key encrypted with a master key stored on the YubiKey. For authentication the service will send the stored key handle back to the YubiKey which then can decrypt it and use the decrypted private key to sign the challenge.

TimWolla··on OpenSSL Security Advisory
This is the fix for the LibreSSL issue [1]: https://github.com/libressl-portable/openbsd/commit/5f00b800...

This is the fix for the OpenSSL issue: https://github.com/openssl/openssl/commit/02b1636fe3db274497...

They don't appear to be related to me. One is a UAF, the other is a NULL pointer dereference.

[1] The LibreSSL issue was found by HAProxy's continuous integration pipeline: https://github.com/haproxy/haproxy/issues/1115. Disclosure: I'm a community contributor of HAProxy, I help maintain the issue tracker and I took part in debugging the issue.

TimWolla··on Suez canal blocked by a massive ship
Looking at GP's foto again I believe the name of the ship they photographed ends with a 'G'. But I also realized my mistake with mixing up the ship's name with the company name.
TimWolla··on Suez canal blocked by a massive ship
That's another ship. The tweet is about "Ever Given", not "Evergreen".

Edit: Comparing with https://en.wikipedia.org/wiki/List_of_largest_container_ship... it might or might not have been the ship. Evergreen is the name of the company: https://en.wikipedia.org/wiki/Evergreen_Marine

TimWolla··on Fish Shell 3.2
You can use `psub` for process substitution, e.g. to compare two sorted files:

    diff -u (sort a |psub) (sort b |psub)
TimWolla··on The Database Inside Your Codebase
I was not telling anyone that they must be able to see this properly. I was saying that I was able to see this properly and I was saying that according to an established standard it should be as readable as it gets.

Sure, the standard might be lacking, but then the standard should be fixed. As a website author you need something to refer to when you don't experience these issues yourself.

← PreviousPage 3 of 11Next →