HNHacker News
TopNewBestAskShowJobs

TurningCanadian

303 karma · joined May 12, 2013

submissionscomments
TurningCanadian··on Problems with “graceful shutdown” in Kubernetes (2019)
Check out

https://kubernetes.github.io/ingress-nginx/user-guide/nginx-...

if you're running nginx. Consider setting it to true instead of the default (false)

---

By default the NGINX ingress controller uses a list of all endpoints (Pod IP/port) in the NGINX upstream configuration.

The nginx.ingress.kubernetes.io/service-upstream annotation disables that behavior and instead uses a single upstream in NGINX, the service's Cluster IP and port.

This can be desirable for things like zero-downtime deployments .

TurningCanadian··on Justice Department Issues Web Accessibility Guidance Under the ADA
It's pretty similar to opening a physical store and not making the entrance accessible.
TurningCanadian··on Google Domains is out of beta
They have raised prices a number of times though. That can be its own challenge, and something you don't experience with AWS.

https://www.reddit.com/r/kubernetes/comments/fdgblk/google_g...

https://cloud.google.com/storage/pricing-announce

TurningCanadian··on WebGPU – All of the cores, none of the canvas
Couldn't you make the same argument about being able to perform computation on the CPU?
TurningCanadian··on Outlook just asked me if I want to upgrade to bigger ads
Each origin has its own cache, so it doesn't matter if you load your fonts from the same place as some other site -- they won't be shared.

https://andydavies.me/blog/2018/09/06/safari-caching-and-3rd...

https://www.zdnet.com/article/chromes-new-cache-partitioning...

https://arstechnica.com/gadgets/2020/12/firefox-v85-will-imp...

TurningCanadian··on Privacy Sandbox on Android
They're lumped together correctly. If you allow bluetooth access, the nearby bluetooth MAC addresses could be used to identify your location with near-GPS precision.
TurningCanadian··on Names of Canada truck convoy donors leaked after reported hack
First, vaccines do inhibit transmission. They're not perfect, and the protection begins to wane after a few months, but to say that they don't inhibit transmission is false.

Further, the vaccines have consistently significantly reduced hospitalization, and most Canadian hospitals continue to be stretched with a long backlog. The continued strain from COVID hospitalizations continues to impact others. Freedom has always been limited when it interferes with the rights of others, (in this case timely access to healthcare) and borders have always had stricter rules than normal life within a country.

We're in a gray area here, granted. Ideally ones' own health choices would not impact others, and hospitals would be back to normal, but the restrictions are not nonsense.

TurningCanadian··on AirPods don't “just work”
I believe the audio quality degradation when using the mic is a limitation of Bluetooth bandwidth. It switches to a different profile capable of sending and receiving audio instead of only receiving.
TurningCanadian··on We're migrating many of our servers from Linux to FreeBSD
Pick any given feature and a FS may or not support it well. RAID56 did have a major update, but still has the write hole and isn't recommended for production.

I think the point still stands though. There has been lots of stabilization work done to BTRFS, and anyone using production-recommended features should consider the filesystem stable.

TurningCanadian··on We're migrating many of our servers from Linux to FreeBSD
"Btrfs is great in its intentions but still not as stable as it should be after all these years of development." may have been true years ago, but doesn't seem to be anymore.
TurningCanadian··on Goodbye CSS Modules, Hello TailwindCSS
Looks like CSS variables in CSS Modules would've achieved the same thing but is more verbose.
TurningCanadian··on Trevor Moore has died
The local sexpot, right? RIP.

https://twitter.com/itrevormoore/status/1413167188886786049?...

TurningCanadian··on Atlantic Ocean currents weaken, signalling big weather changes: study
Let's say the weather gets better in one place due to climate change. Isn't that nice. You have that on the one hand.

On the other hand, there are big risks inherent to change. You don't get to pick just the good parts of climate change. Spitballing here: risks to food stability from droughts, fires, etc. Some areas no longer economically support farming. Other areas open up but aren't as productive, so food is a bigger part of your budget and might be subject to disruption. Political risks: displaced people start eyeing the habitable places and find ways to make life miserabile unless they're let in. Costs of the disruption while everyone tries to adapt weigh on the economy and make the products/services you take for granted today more expensive or unavailable. Your children (or others that you care about) will have to deal with even worse. And things don't stop getting worse until greenhouse gas emissions are dealt with.

The mentality of looking at the silver lining while ignoring the rest is wrong on so many obvious levels.

TurningCanadian··on The Push for a “PBS for the Internet”
If the US government paid $1 in total to PBS, would you be surprised that PBS couldn't provide its service for free? The US pays about 4% of what the UK pays per capita for public broadcasting.

https://site-cbc.radio-canada.ca/documents/impact-and-accoun...

Members, corporate underwriting, and distribution fees each provide a bigger percentage of its revenue than the federal government https://publiceditor.bento-live.pbs.org/publiceditor/blogs/p...

TurningCanadian··on Mozilla rolls out DoH to Canadian users of Firefox
I didn't realize that Fedora dropped that proposal https://pagure.io/fesco/issue/1511

May have been related to IPv6? Not sure.

I remember trying it out at the time (https://fedoraproject.org/wiki/Changes/Default_Local_DNS_Res...) and not running in to issues

TurningCanadian··on Apple's “iCloud Private Relay” broke risk based authentication
The company challenging her beyond the normal experience is forced to because until she logs in, she is indistinguishable from an attacker. That's the price she's paying for perfect privacy.

They're not doing it because they want to annoy anonymous users; they're doing it because they're not getting any signal that they can trust this connection. That's the price you pay for removing reputation, and no number of Apple Relay users can change that. Website operators can't simply start trusting completely anonymous connections simply because there are a lot of them.

That's why I say Apple should be communicating this to users: there's a price to pay for anonymity. You may see more captchas, you may get challenged with 2FA more often, etc. Not to mention, you might be making it easier for actual criminals to hide amongst the other traffic.

When she logged in, the privacy issue becomes moot of course, yes. At that point her credential can be trusted the same way as before.

TurningCanadian··on Apple's “iCloud Private Relay” broke risk based authentication
How would that alternative way of proving their unmaliciousness/identity not be a reinvention of the peephole?
TurningCanadian··on Apple's “iCloud Private Relay” broke risk based authentication
In the Apple Relay case, the person is deliberately making it impossible for me to determine who they are. It isn't a problem with my peephole.

If there is a problem with my peephole, I'm still not trusting the person at the door until I can check it out and fix it.

TurningCanadian··on Apple's “iCloud Private Relay” broke risk based authentication
It comes back to reputation. In the real world, we build up a reputation and people can choose to trust us based on it. That also means that they get to know us. I personally like being able to interact with people that I've built up a positive relationship with. Why doesn't that carry over to the virtual world though?

I think everyone's view is tinted by the over-collection of data that some companies are doing. A real-life analogy would be having someone record everything that you do. We've come to accept that to an extent when going into stores, but probably wouldn't hang out with a friend that did that. I don't think the best solution to that is to put a bag over yourself and change your voice so that you're anonymous but still hang out with that friend -- I think it's to tell your friend that you don't want to be recorded. If some service is recording you too invasively, don't do business with them. If you don't know who is recording you, get your government to pass a law like GDPR.

If you want to live in a world without reputation, there will be drawbacks. Attackers will be indistinguishable from regular users, so you have to treat regular users as if they could be attackers; you can't have a tiered approach. The person banned for posting threats (or worse) or otherwise misbehaving on a message platform will be indistinguishable from a new account. The brute force attack will be indistinguishable from the legitimate user. Etc.

To throw out the whole concept of reputation so that you can be perfectly anonymous seems like the wrong solution to the problem.

TurningCanadian··on Apple's “iCloud Private Relay” broke risk based authentication
Why would my visitor be surprised that I'm suspicious though? They're choosing to be suspicious.

Another analogy I could make is someone that is blocking their caller ID. Should they be surprised that fewer people will take their call? They're lumping themselves in with spammers.

I think Apple -- and anonymizing proxy/VPN services in general -- should be communicating that to their customers.

TurningCanadian··on Apple's “iCloud Private Relay” broke risk based authentication
Did it actually break risk based authentication though? Sure, legitimate users will be using Apple's Relay, but what's stopping attackers from using it? If the users of the service are choosing to be indistinguishable from attackers, then that's on them.

I think of it like reputation in real life. If you come knocking on my door, and I can see and recognize you, I'll open it. If you cover up my peephole or hide yourself so that I can't recognize you, why would I even let you know I'm home? Even if you tell me who you are, shouldn't I be worried that someone is impersonating you?

At the very least I'd expect users from anonymizing IPs to have to jump through some extra hoops like captcha and 2FA.

TurningCanadian··on Don't just shorten your URL, make it suspicious and frightening (2010)
X-Powered-By: PHP/5.5.9-1ubuntu4.11

yikes!

TurningCanadian··on Few people know that Google voluntarily removes some search results
They can block any traffic that they can't decode
TurningCanadian··on Few people know that Google voluntarily removes some search results
I wouldn't say it's all or nothing. Several of the more regressive countries already demand access to decryption keys. The government gets easy access to the data but it's still hard for the non-state bad guys to intercept.
TurningCanadian··on Microsoft support page says Windows 10 “retirement date” is 2025
IE11 support was tied to Windows 10, so now we finally have an official EOL for it. (though I don't see that mentioned in the article)
TurningCanadian··on GraphQL Conf. 2021
You need to turn on useGETForHashedQueries. I don't know why it's not the default. Combine that with the @cacheControl directive for automatic cache-control headers.
TurningCanadian··on How Intuitive Are Macs Really?
Not on Linux
TurningCanadian··on How Intuitive Are Macs Really?
It's not even great for programming these days. Docker on Linux or even Windows is a walk in the park compared to the horror show of slowness (https://github.com/docker/roadmap/issues/7) and missing features that it is on Mac.
TurningCanadian··on Ask HN: What do you think will come after Kubernetes?
It sounds like you're describing Kubernetes. It already does container and volume management that way. All that's left is to continue building on top of it so that it can provision managed services like storage buckets and databases.
TurningCanadian··on Why we switched from Webpack to Vite
For people already on webpack, there's esbuild-loader (https://github.com/privatenumber/esbuild-loader)
← PreviousPage 3 of 5Next →