HNHacker News
TopNewBestAskShowJobs

TimWolla

2,996 karma · joined June 20, 2013

[ my public key: https://keybase.io/timwolla; my proof: https://keybase.io/timwolla/sigs/MWclLW9WYzVuQbvkZA3v4bdSRwlEhNxpGmt9zzpiVLg ]
submissionscomments
TimWolla··on The Database Inside Your Codebase
> Don't just quote some automated tool at people who very clearly experience something else.

I don't think that's a fair response to my comment when it was GP who specifically brought contrast into the discussion and even linked to a contrast checker that also checks two colors against the WCAG guidelines.

I wasn't I claiming that everyone is able to read it. I was just saying that according to the standard they themselves referenced it was fine. The fact that it actually was not fine for certain dark mode configurations is orthogonal to that and was not taken into account by both of us.

TimWolla··on The Database Inside Your Codebase
The contrast is fine, see: https://news.ycombinator.com/item?id=26160608
TimWolla··on The Database Inside Your Codebase
I found it perfectly readable and checked with Firefox' accessibility tools: The contrast of the main text is a 12.19 and thus meets the WCAG AAA standards for accessible text. [1] is the documentation Firefox links to.

[1] https://developer.mozilla.org/en-US/docs/Web/Accessibility/U...

TimWolla··on Securing my personal SSH infrastructure with Yubikeys
I'm being redirected to EFF if my 'Referer' includes news.ycombinator.com. Anyone else seeing this?

    $ curl -I 'https://www.dzombak.com/blog/2021/02/Securing-my-personal-SSH-infrastructure-with-Yubikeys.html' -H 'Referer: https://example.com'
    HTTP/1.1 200 OK
    *snip*

    $ curl -I 'https://www.dzombak.com/blog/2021/02/Securing-my-personal-SSH-infrastructure-with-Yubikeys.html' -H 'Referer: https://news.ycombinator.com/'
    HTTP/1.1 302 Moved Temporarily
    *snip*
    Location: https://supporters.eff.org/donate/join-eff-today
    *snip*
TimWolla··on Securing my personal SSH infrastructure with Yubikeys
It is possible to require confirmation before `ssh-add` allows to use a key. From `man ssh-add`:

     -c      Indicates that added identities should be subject to confirmation
             before being used for authentication.  Confirmation is performed
             by ssh-askpass(1).  Successful confirmation is signaled by a zero
             exit status from ssh-askpass(1), rather than text entered into
             the requester.
TimWolla··on Help users in Iran reconnect to Signal
I created an HAProxy configuration that should be equivalent to the nginx configuration within the Signal-TLS-Proxy repository:

https://gist.github.com/TimWolla/457c45dfccde26fc674dde4b3c7...

I could not test it with the Signal client yet, because the Beta is not yet available for me. However I verified that the nested TLS works using openssl and netcat.

TimWolla··on Replacing Dropbox in favor of DigitalOcean spaces
Hetzner is (one of) the largest German dedicated server providers.

They are DIN ISO/IEC 27001 certified: https://www.hetzner.com/unternehmen/zertifizierung. Of course if you only store encrypted data you don't really need this auditing.

TimWolla··on How WhatsApp works with other Facebook products
You can buy Threema within their store if you can't or don't want to use Google Play Services: https://shop.threema.ch/
TimWolla··on GitHub blocks entire company because one employee was in Iran
You might be able to regain access if you still have your SSH key: https://news.ycombinator.com/item?id=25648815
TimWolla··on GitHub blocks entire company because one employee was in Iran
They do: https://docs.github.com/en/free-pro-team@latest/github/authe...
TimWolla··on Ask HN: Is HN slow today?
I remember something about the database being a flat file / flat files. Is that (still) true? How are the two machines being synchronized?
TimWolla··on CVE Stuffing
See additional context in this issue in docker-library/memcached: https://github.com/docker-library/memcached/issues/63#issuec...

And this issue in my docker-adminer: https://github.com/TimWolla/docker-adminer/issues/89

TimWolla··on Adding Encrypted Group Calls to Signal
You can buy Threema from within their own shop: https://shop.threema.ch/. They support Bitcoin.
TimWolla··on Improving DNS Privacy with Oblivious DoH
> an actual run of the mill SOCKS proxy would have visibility of the user's queries and their identity, defeating the purpose of the design.

Why would it have visibility of the queries? If I send a TLS connection (containing my DoH query) through that SOCKS proxy, then the SOCKS proxy is unable to decrypt that TLS connection without breaking certificate verification and thus can't read my DoH query.

TimWolla··on Improving DNS Privacy with Oblivious DoH
Yes, I understand that. But I don't understand what ODoH does better than a run of the mill SOCKS proxy, such as Tor.
TimWolla··on Improving DNS Privacy with Oblivious DoH
So, having read the blog post from Cloudflare I don't understand why the proxy (needs to terminate|terminates) TLS.

I thought HTTPS proxying (or rather: Any TCP protocol) was a solved problem by the HTTP CONNECT verb or SOCKS proxies.

What am I missing?

TimWolla··on Improving DNS Privacy with Oblivious DoH
Probably better source, the blog post at Cloudflare: https://blog.cloudflare.com/oblivious-dns/

See also: https://news.ycombinator.com/item?id=25344220

TimWolla··on Feedback wanted: CORS for private networks (RFC1918)
> So I cannot access the box anymore at all?

My understanding is that you can access it directly. But you can't embed e.g. images or JavaScript from that server within a website running on a public IP address. I consider that a good thing.

TimWolla··on Slack stores browser cookies without user consent
You need to store some kind of state if you want to protect the form from CSRF attacks. You usually want to protect the form.
TimWolla··on New youtube-dl release: v2020.11.01.1
> The original author moved to gitlab and started GPG signing commits with his real GPG key.

Signed commits from them go back at least 1 year. So its not "started", but rather "continued" signing.

TimWolla··on 2020's fastest-rising tech jobs? Programming language PHP leads the way
PHP follows a consistent philosophy as well. The PHP functions are usually named after the C functions they wrap. And in fact: The MySQL C client library contains a function called mysql_real_escape_string.

see: https://dev.mysql.com/doc/c-api/8.0/en/mysql-real-escape-str...

TimWolla··on That company whose name used to contain HTML script tags Ltd
> I'm curious if that copied the text or the placeholders.

It copied the text.

TimWolla··on YouTube-dl is now part of GitHub/dmca.git
A hidden service uses 6 middle nodes, 3 for the server, 3 for the client.
TimWolla··on Dockerfile Security Best Practices
Monthly typically (and when important security updates are released): https://github.com/docker-library/official-images/pulls?q=is...
TimWolla··on A web of trust for NPM
According to https://en.wikipedia.org/wiki/Modulo_operation#In_programmin...:

- JavaScript is consistent with Java, PHP.

- Older C may behave as either Python or JavaScript.

- Modern C behaves like JavaScript.

So basically Python is the outlier here.

TimWolla··on Debian 10.6
Is it planned to move issue tracking to Salsa?

I enjoy filing bugs via email, because that does not require me to create an account and I need email notifications to become aware of updates anyway.

TimWolla··on Backing up data like the adult I supposedly am
Yes, you are correct. The script ends no later than 2:30 and then there's a delay of up to 1 hour.
TimWolla··on Backing up data like the adult I supposedly am
This works, but compared to using systemd it has the drawback that the range of possible times is anchored to the configured time in cron. The systemd timer example I gave causes the next cycle to start when the previous job finished.

So if it initially runs the script between 0:00 and 1:00 and the script takes 1.5 hours to finish then the next run will be between 1:30 and 2:30 the next day, instead of 0:00 and 1:00.

TimWolla··on Backing up data like the adult I supposedly am
It possibly makes the process unnecessarily slow. People tend to choose “round” numbers for their cronjobs. Probably most commonly minute 0 of a given hour for an hourly or daily job. Thus on e.g. 0:00 UTC there might be hundreds of clients running their backups.

I don't have a strict need to run my backups at a fixed point in time (e.g. within the night hours). By not hitting a hotspot I have a better chance of having a larger percentage of the targets bandwidth for my needs (both network as well as disk IO).

The random delay ensures that the job runs at a different point in time every day, with most of these points in time being expected to have a light load. If it accidentally hits a hotspot on one day it will be fine the next.

TimWolla··on Backing up data like the adult I supposedly am
I never used rclone, but I can tell you that a borg repository basically is a number of encrypted blobs of up to 500 MB size that are never going to be modified again (only created and deleted) + a few small metadata files. It rsyncs quite well.
← PreviousPage 4 of 11Next →