HNHacker News
TopNewBestAskShowJobs

TimWolla

2,996 karma · joined June 20, 2013

[ my public key: https://keybase.io/timwolla; my proof: https://keybase.io/timwolla/sigs/MWclLW9WYzVuQbvkZA3v4bdSRwlEhNxpGmt9zzpiVLg ]
submissionscomments
TimWolla··on HAProxy 2.0
For me it's the superior HTTP / header rewriting capabilities. With nginx you are more or less restricted to just adding headers the last time I looked into it.

Disclosure: I'm a community contributor to HAProxy and I help maintain the issue tracker on GitHub.

TimWolla··on I can see your local web servers
It does not only scan 3000. From the source code:

      const portsToTry = [
        80, 81, 88,
        3000, 3001, 3030, 3031, 3333,
        4000, 4001, 4040, 4041, 4444,
        5000, 5001, 5050, 5051, 5555,
        6000, 6001, 6060, 6061, 6666,
        7000, 7001, 7070, 7071, 7777,
        8000, 8001, 8080, 8081, 8888,
        9000, 9001, 9090, 9091, 9999,
      ];
TimWolla··on System Down: A systemd-journald exploit
systemd is not a syslog daemon either. systemd-journald is.
TimWolla··on Threema – Seriously secure messaging
I believe this is going to be fixed with Threema Safe: https://threema.ch/en/blog/posts/threema-safe-en. It is already rolled out for Android and iOS should be soon according to the blog.
TimWolla··on Slack closes account of an Iranian user living in Canada
Google for "Telegram Security" or "Telegram Moxie" to see why Telegram / mtproto might not be the best choice. This is repeatedly the topic on Hacker News as well.
TimWolla··on Download all of your GitHub data
It does not. This is what it looks like for me (files with number > 1 omitted for brevity):

    -rw-r--r-- 1 timwolla timwolla  499 Dec 19 19:31 attachments_000001.json
    -rw-r--r-- 1 timwolla timwolla  52K Dec 19 19:31 commit_comments_000001.json
    -rw-r--r-- 1 timwolla timwolla  72K Dec 19 19:31 issue_comments_000001.json
    -rw-r--r-- 1 timwolla timwolla  35K Dec 19 19:31 issue_events_000001.json
    -rw-r--r-- 1 timwolla timwolla  34K Dec 19 19:31 issues_000001.json
    -rw-r--r-- 1 timwolla timwolla  356 Dec 19 19:31 milestones_000001.json
    -rw-r--r-- 1 timwolla timwolla  22K Dec 19 19:31 projects_000001.json
    -rw-r--r-- 1 timwolla timwolla 4.4K Dec 19 19:31 protected_branches_000001.json
    -rw-r--r-- 1 timwolla timwolla  25K Dec 19 19:31 pull_request_review_comments_000001.json
    -rw-r--r-- 1 timwolla timwolla 4.3K Dec 19 19:31 pull_request_reviews_000001.json
    -rw-r--r-- 1 timwolla timwolla  51K Dec 19 19:31 pull_requests_000001.json
    -rw-r--r-- 1 timwolla timwolla 9.0K Dec 19 19:31 releases_000001.json
    -rw-r--r-- 1 timwolla timwolla  80K Dec 19 19:30 repositories_000001.json
    -rw-r--r-- 1 timwolla timwolla   75 Dec 19 19:31 schema.json
    -rw-r--r-- 1 timwolla timwolla  27K Dec 19 19:30 users_000001.json

    attachments:
    total 12K
    drwxr-xr-x 3 timwolla timwolla 4.0K Dec 19 19:31 ./
    drwxr-xr-x 5 timwolla timwolla 4.0K Dec 19 19:31 ../
    drwxr-xr-x 2 timwolla timwolla 4.0K Dec 19 19:31 c544f416-10c9-11e7-8337-82f88cac9fcd/

    releases:
    total 36K
    drwxr-xr-x 9 timwolla timwolla 4.0K Dec 19 19:31 ./
    drwxr-xr-x 5 timwolla timwolla 4.0K Dec 19 19:31 ../
    drwxr-xr-x 2 timwolla timwolla 4.0K Dec 19 19:31 5aa3a138-9c86-11e5-99bc-79a6c3e509eb/
    drwxr-xr-x 2 timwolla timwolla 4.0K Dec 19 19:31 …
    drwxr-xr-x 2 timwolla timwolla 4.0K Dec 19 19:31 dba26980-d9f1-11e8-8357-3f2750c60e51/

    repositories:
    total 12K
    drwxr-xr-x  3 timwolla timwolla 4.0K Dec 19 19:30 ./
    drwxr-xr-x  5 timwolla timwolla 4.0K Dec 19 19:31 ../
    drwxr-xr-x 41 timwolla timwolla 4.0K Dec 19 19:31 TimWolla/
TimWolla··on Git v2.20.0
You can use this PPA to get “bleeding edge” versions of git: https://launchpad.net/~git-core/+archive/ubuntu/ppa
TimWolla··on Ask HN: An app has access to my Google account, but access can't be revoked
I was able to solve the issue and revoke the access:

1. I modified the URL to add the `https://www.googleapis.com/auth/plus.login` scope.

2. This caused Google to re-ask me for approval, because I did not yet acknowledge the scope.

3. Afterwards the app appeared in my list of authorized apps.

4. I revoked access there.

5. I confirmed that access was revoked, when I tried to login back into the app Google asked me for approval.

TimWolla··on Hetzner removes traffic limitation for dedicated servers
Thank you for looking that up. Hardware usually does not fail from one day to the next, so to me it appears like your HDD monitoring was insufficient in the weeks / months leading the full crash.

It should have detected the disks going bad and allow you to request a replacement with 3 of 4 disks being good and then later a replacement of the second bad disk with 3 of 4 being good, no?

> I asked if they mean data lost on this single disk or the whole array, they said;

IMO this is the correct answer from Hetzner. They cannot know whether you run RAID 1 (which would be good), RAID 5 (which would have killed the array), RAID 6 (good) or RAID 10 (might or might not be good). Asking before replacing could possibly allow you to save data in case the disk is not completely dead, but rather has a bunch of faulty sectors only.

The only issue I personally see is the bad English. I am German like Hetzner and even I have issues understanding that grammar.

TimWolla··on Hetzner removes traffic limitation for dedicated servers
To be best of my knowledge the Flexipack is no longer required / available.
TimWolla··on Hetzner removes traffic limitation for dedicated servers
I'm afraid, I still don't understand. We are talking about a rented dedicated server here (not about some managed one), right?

> but once they have found the first

How did they find the HDD? As I said: They don't monitor your server. Did you request replacement of the HDD? If you request replacement of one disk, they swap one disk.

> Even if they are helping as a courtesy, they should test all the disks and do this right, before the customer continue.

How should that work? They remove all the HDDs from the server, put them into a different computer to run a test? That would be a privacy nightmare and add unnecessary downtime. I keep track of my HDD status (smartmontools, mdadm Events, ZFS Event Daemon). I know exactly what HDDs I want replaced. They just perform the actual, physical, replacement for me. And that is absolutely fine.

TimWolla··on Hetzner removes traffic limitation for dedicated servers
As the submitter of the link I cannot even downvote your comment, but something feels odd about it:

Hetzner provides unmanaged dedicated servers, thus you are the one responsible monitoring the hardware. The only thing Hetzner does is swapping HDDs you identify as faulty (you provide them the S/N of the faulty disk via the support form).

Personally I rent the super cheap Serverbörse servers for personal use. The HDDs in there are fairly old (as it's their older generation servers). Over the past 6 years I needed Hetzner to swap about 5 HDDs. When my server logged issues when accessing a disk, I requested a swap, they swapped it less than 30 minutes later and I started the rebuild of my RAID. All without issues.

> The first one was totally Hetzner's fault since they have failed to identify the faulty disks when they check the disks for it.

Did you mean to say that they removed an incorrect disk when you requested a swap? Or did you expect them to monitor the hardware for you?

TimWolla··on Hetzner removes traffic limitation for dedicated servers
Hetzner recently introduced the vSwitch feature. I believe it might be what you are searching for: https://wiki.hetzner.de/index.php/Vswitch/en
TimWolla··on Zoho.com CEO says domain with 40M users suspended for abuse complaint
I can highly recommend INWX. What I like about them is that the service they provide is domains only (I don't consider their web hosting offers [1] seriously). Thus no conflict of interest and resources are focused on a good domain service.

[1] https://www.inwx.de/en/hosting

TimWolla··on How I gained commit access to Homebrew in 30 minutes
While not OSS the Debian packages of Tarsnap are built and signed on an air-gapped machine: http://mail.tarsnap.com/tarsnap-alphatest/msg00033.html
TimWolla··on LIDL cancels SAP introduction after spending 500M Euro
As a native German speaker: The Google translation is fairly good: https://translate.google.de/translate?sl=de&tl=en&js=y&prev=...

The article is fairly thin on content, though. It barely contains more information than the Hacker News headline.

TimWolla··on Devuan ASCII 2.0.0 stable release
I am not aware of such a thing, but SystemD supports the "legacy" SysV init scripts out of the box. This feature is required for certain Debian packages, as not all of them ship with proper SystemD units, yet.

see: https://www.turnkeylinux.org/blog/debugging-systemd-sysv-ini... https://www.systutorials.com/docs/linux/man/8-systemd-sysv-g...

TimWolla··on Show HN: H-app-proxy – Application server inside haproxy
GitHub repository: https://github.com/TimWolla/h-app-roxy

Live demo: https://bl.duesterhus.eu/20180511/demo/DWhxJf2Gpt

Note that links expire after 60 seconds in the live demo. As stated at the bottom of the post: I don’t want to be liable for links pointing to nefarious content.

TimWolla··on Twitter urges users to change passwords after computer 'glitch'
Not GP, but KeePass user: I store my KeePass database on a small thumb drive (SanDisk Cruzer Fit), together with a copy of the KeePass executable. If I absolutely need to decrypt my password database on someone else's machine I can take the "secure" software from the USB and hope for the best. The USB also stores a copy of Truecrypt and a large Truecrypt container with backups of my encrypted private keys (PGP, SSH).
TimWolla··on ZFS on Linux: Unlistable and disappearing files
> but stretch-backports is on 0.7.6 (not sure when that happened exactly)

[2018-03-09] Accepted zfs-linux 0.7.6-1~bpo9+1 (source amd64 all) into stretch-backports (Aron Xu)

source: https://tracker.debian.org/pkg/zfs-linux

TimWolla··on Have I Been Pwned Is Now Partnering with 1Password
> Step 2 Enable 2 factor authentication and store the codes inside your 1Password account.

Doesn't storing the backup codes of 2-factor in your password safe where your first factors resides negate the whole "2 factors" thing?

Personally I write down the backup keys on a piece of physical paper.

TimWolla··on Lsofgraph – Convert lsof output to graph of processes, pipes, fifos and sockets
systemd-analyze(1) supports dot(1) output to plot dependencies between units:

Quoting from the man page:

    EXAMPLES FOR DOT
       Example 1. Plots all dependencies of any unit whose name starts with "avahi-daemon"

           $ systemd-analyze dot 'avahi-daemon.*' | dot -Tsvg > avahi.svg
                 $ eog avahi.svg

       Example 2. Plots the dependencies between all known target units

           systemd-analyze dot --to-pattern='*.target' --from-pattern='*.target' | dot -Tsvg > targets.svg
           $ eog targets.svg
TimWolla··on TLS 1.3 approved
> I guess e.g. Nginx could also insert an artificial header to mark requests received as 0-RTT, and frameworks like Django could use that header to require views be explicitly marked with a decorator to indicate support, or something like that

There is an Internet Draft for that [1]. It is co-authored by Willy Tarreau of haproxy and implemented within haproxy 1.8 [2].

[1] https://tools.ietf.org/id/draft-thomson-http-replay-01.html

[2] https://www.mail-archive.com/haproxy@formilux.org/msg28004.h... (Ctrl+F 'Early-Data') https://www.mail-archive.com/haproxy@formilux.org/msg27653.h... (Ctrl+F '0-RTT')

TimWolla··on February 28th DDoS Incident Report
There even is a dedicated homepage for that problem of providers not filtering their egress traffic: http://www.bcp38.info/index.php/Main_Page
TimWolla··on Signal Foundation
The swiss messenger Threema can be used fully pseudonymously, but is paid (Bitcoin available) and not open source: https://threema.ch/en
TimWolla··on Debian developer revisits FreeBSD after 20 years (2015)
(2015)
TimWolla··on Appropriate Uses for SQLite
It doesn't say "require". Possibly they are selecting the same information over and over again, instead of passing it along the different functions, because it is fast enough.
TimWolla··on Hetzner Cloud
See this on why they won't peer with Deutsche Telekom: https://news.ycombinator.com/item?id=10645577
TimWolla··on Hetzner Cloud
Yes. You can find Hetzner's ( ;) ) explanation here: https://wiki.hetzner.de/index.php/Microsoft_Blacklist/en.

It's the first link in the delisting section: http://go.microsoft.com/fwlink/?LinkID=614866&clcid

I also recommend signing up for SNDS.

TimWolla··on Hetzner Cloud
SEO is a black box, so there are no definite answers. It will affect load times (the 60ms) and that could have an effect on search engines.
← PreviousPage 6 of 11Next →