HNHacker News
TopNewBestAskShowJobs

_hyn3

1,857 karma · joined March 15, 2012

submissionscomments
_hyn3··on AWS says it can't restore some data from mideast facilities struck by Iran
This is not exactly a nuanced view either and claiming that someone needs to discuss a personal issue with their clergy doesn't reduce the temperature or elevate the discourse.

This was not "a free attack". The goal was and is preventing the world's leading terror organization from acquiring nuclear weapons, especially when they already have the missiles to carry them. It's just a bad situation and the decisions are difficult. Even now, the IRGC continues attacking their erstwhile allies. Those would likely be nukes if they'd had them.

_hyn3··on Congressional Ratification of President Trump's Corporatism
$27B across 30 large, highly valued companies? Is it a "principle of the thing" or does Mr. Paul believe that this actually moves the needle? All of these seem nat'l security adjacent.
_hyn3··on Migrate from Datadog to Grafana
"Meanwhile Datadog keeps billing, and morale tanks halfway through" bottish/llmish (?), but truer words never spoken.
_hyn3··on It's hard to justify buying a Framework 12
I said movies. As in, the movie theater. I cancelled Netflix years ago.
_hyn3··on GrapheneOS Speech Services version 2 released
Check out FUTO keyboard with the larger 250 MB model
_hyn3··on The newest Instagram “exploit” is the goofiest I've seen
> someone invited a whole mailing list

IIRC, LinkedIn would email everyone in your "address book" (or anything else it could find) back in the day.

_hyn3··on A 10 year old Xeon is all you need
You're right - the article says 'CPU: Intel Xeon E5-2620 v4 @ 2.10 GHz' but also says DDR3. And the specs page for that CPU (https://www.intel.com/content/www/us/en/products/sku/92986/i...) clearly says the 2620 v4 is DDR4.

E5 CPUs have their supported RAM right on the Intel ARK pages, but short version:

E5-xxxxx v1 and v2 are all DDR3

E5-xxxxx v3 and v4 are all DDR4

Not sure why Intel didn't just cut new model numbers instead of keeping them all as "e5"

More concrete example for E5-2660 (great processor) showing v1 and v2 support DDR3, while v3 and v4, DDR4 (again, different motherboards)

DDR3 v1: https://www.intel.com/content/www/us/en/products/sku/64584/i...

DDR3 v2: https://www.intel.com/content/www/us/en/products/sku/75272/i...

DDR4 v3: https://www.intel.com/content/www/us/en/products/sku/81706/i...

DDR4 v4: https://www.intel.com/content/www/us/en/products/sku/91772/i...

This also means that you need to know the processor your motherboard supports (or, easier, probably RAM) before putting in an order to upgrade the processor. (These processors are incredibly cheap, less than $10 for something that might have cost literally thousands ten years ago, so worthwhile to spend a few minutes and pick out your favorite based on cores, watts, Ghz, etc.)

(Another commenter says that there are some motherboards that accept v3/v4 but also can run slower DDR3 RAM. That's new to me and quite cool - DDR3 is extremely cheap, even now. I did find these motherboards on aliexpress, too: https://www.aliexpress.us/w/wholesale-XD3-motherboard.html?s... and one clearly says v3/v4 cpu's with DDR3 RAM. That could be very useful although memory speeds are slower since CPU performance can be boosted with v3/v4.)

v1: https://www.intel.com/content/www/us/en/ark/products/series/...

v2: https://www.intel.com/content/www/us/en/ark/products/series/...

v3: https://www.intel.com/content/www/us/en/ark/products/series/...

v4: https://www.intel.com/content/www/us/en/ark/products/series/...

_hyn3··on It's hard to justify buying a Framework 12
Yeah, or a Macbook Neo! No need to disparage other people's use cases.
_hyn3··on It's hard to justify buying a Framework 12
Only if you are solely an Apple user, because it's literally not a problem anywhere else. I've taken tons of photos of movies with my Pixels.
_hyn3··on 2026 HIPAA Security Rule Update
If SOC2 relies on competent auditors (and you're right, it does), than it is an ineffective standard (and it mostly is).
_hyn3··on SSH certificates: the better SSH experience
Touche.. actually a good point, but actually those are two different situations. With one, I'm accessing a website and trusting that the certificate is signed by someone I trust; so the trust in my browser certificates (which include certificates from hundreds of certificate authorities all over the world, any one of which could be compromised, robbed, or controlled by an adversarial person or even government) is extended to the site that I'm visiting. To say this is weak sauce rather understates how bad this actually is. (To paraphrase Churchill, this is the worst possible design, except for all the rest.)

With the other, I'm logging into a server for the first time (and I could simply deploy the same trusted host key to all my ssh servers via an autoscaling configuration or whatever). I think it's debatable if TOFU is worse or better than your (granted clever) metaphor.

(to those who'd recommend userify, yes - great for the client login issue and definitely increases security, but to parent's point, TOFU is still needed unless you want to distribute host pubkeys)

_hyn3··on Benchmarks for Golang SQLite Drivers
Excellent evaluation. From reading the code, it appears that the units for the numbers column is usually milliseconds (ms)

It also looks like squinn is the clear leader for most but not all of the benchmarks.

Even though it's "not scientific", is still very useful as a baseline - thanks for taking this effort and publishing your results!

Also taking a look at monibot.io , looks cool

_hyn3··on Building Bluesky comments for my blog
How is this different from any other self hosted solution; you've still got to manage spam yourself. Might as well go self hosted.
_hyn3··on US reportedly forcing TSMC to buy 49% stake in Intel to secure tariff relief
What would TSMC do if they couldn't sell chips to the USA? It cuts both ways, like most trade negotiations.
_hyn3··on Why I no longer have an old-school cert on my HTTPS site
"We now have another confirmation on Twitter that remote code is executed and a glimpse into what the script is... it appears to be benign."

https://github.com/acmesh-official/acme.sh/issues/4659

It was not. Don't use acme.sh.

_hyn3··on SMS 2FA is not just insecure, it's also hostile to mountain people
Trying removing consent to receive text messages on that number, or that it's only a land line and only phone calls are accepted.

You might even try to block incoming SMS. In fact, you might also try a forward with Twilio or free Google voice number, since a lot of SMS TOTP refuse to with with those numbers :)

I've even had success removing my phone number entirely from certain types of accounts, but sometimes I had to deliberately break the account (eBay) and then it tries to get you to confirm on each login which you can sometimes bypass by changing the URL or clicking the company logo.

Be sure to have strong security in other ways; strong, non repeated passwords.

But this is truly insane. Large banks don't even offer the option of TOTP but instead require far more insecure SMS. Maybe they'll offer RSA dongles, because they never bothered to remember when they all got completely leaked ten years ago or how they accepted $10M to completely compromise their constants.

What can you say, large enterprises are behind the security eight ball, as always! It's a tale as old as time.

https://www.wired.com/story/the-full-story-of-the-stunning-r...

https://www.theverge.com/2013/12/20/5231006/nsa-paid-10-mill...

_hyn3··on Whistleblower details how DOGE may have taken sensitive NLRB data
> President isn't CEO

The President is literally the Chief Executive officer in the United States.

https://people.howstuffworks.com/president4.htm

> Laws and budgets are set by Congress

That's correct, under Article 1, but the President does not have to spend every dime that was allocated.

> EOs do not have the force of law

"Both executive orders and proclamations have the force of law, much like regulations issued by federal agencies"

https://www.americanbar.org/groups/public_education/publicat...

You seem to underestimate the power that is vested in the office of the President as the Chief Executive.

> have been invalidated by courts

As have many, many legislatively-passed laws; this is simply checks-and-balances and allows the judiciary to act on other laws (which originate from Congress) and regulations (which originate from the Executive Branch).

_hyn3··on Whistleblower details how DOGE may have taken sensitive NLRB data
Those darn hackers. They probably hang out and get their news... someplace.
_hyn3··on Whistleblower details how DOGE may have taken sensitive NLRB data
If the CEO of your company empowers a team to audit your work, would you 'resist'?

And this Chief Executive was elected by the majority of the country, specifically to take these actions that he'd clearly stated he would take.

The resistance is actually the violation of federal law. It's no different from contempt of court; within the President's domain, he has a huge amount of power. The President can also modify existing policy (regulations) at any time and literally make new laws (Executive Orders have the force of law) as long as they don't conflict with current law, as well as overturning previous President's Executive Orders.

Of course, then the shoe will be on the other food someday, too, just as it was when Biden took over from Trump and then they switched places again.

As President Obama said, "I've got a pen, and I've got a phone."

https://www.npr.org/2014/01/20/263766043/wielding-a-pen-and-...

_hyn3··on JSLinux
Willy Tarreau - creator of HA Proxy
_hyn3··on Owning my own data, part 1: Integrating a self-hosted calendar solution
"Would be nice if you use your.. financial stability of a Google job to build an open-source protocol"

Well, sure, it'd be nice if we could all spend our time building things to give away for free, but it's just not always possible. Life happens and people shouldn't have to explain or apologize for it.

_hyn3··on Open-sourcing OpenPubkey SSH (OPKSSH): integrating single sign-on with SSH
How does this compare to Userify's plain-jane SSH key technique?

That agent (Python, single-file https://github.com/userify/shim) sticks with decentralized regular keys and only centralizes the control plane, which seems to be more reliable in case your auth server goes offline - you can still login to your servers (obviously no new users or updates to existing keys). It just automates user and sudo configuration using things like adduser and /etc/sudoers.d. (It also actively kills user sessions and removes the user account when they're deleted, which is great for when you're walking someone out in case they have cron-jobs or a long-running tmux session with a revenge script.)

This project looks powerful but with a lot of heavy dependencies, which seem like an increased surface area (like Userify's Active Directory integration, but at least that's optional)

_hyn3··on The Future Is Niri
# for floating windows

default_floating_border none

# make sure pavucontrol is floated; use xprop (cli) to get window title/class/etc

for_window [class="Pavucontrol"] floating enable, resize set height 512, opacity 0.3

# https://faq.i3wm.org/question/61/forcing-windows-as-always-f...

_hyn3··on Microsoft begins turning off uBlock Origin and other extensions in Edge
Also Brave.. just not sure when or if someone will breaking fork chromium.
_hyn3··on Trapped in the dark for 35 hours – Red Sea dive-boat survivors tell of escapes
Not at 1atm. The air was pressurized.
_hyn3··on Australia: Kids under 16 to be banned from social media after Senate passes laws
Runs smack into the Rule of Lenity.
_hyn3··on Australia: Kids under 16 to be banned from social media after Senate passes laws
What is the acceptance criteria for this test case?
_hyn3··on Teens learn a new conspiracy theory every week on social media
I appreciate this; it's a good point.
_hyn3··on Teens learn a new conspiracy theory every week on social media
At least until such 'food and drug' agency was inevitably overwhelmed by lobbyists, patent royalties, and a revolving door between industry and government. Then it'd be worse than nothing at all.
_hyn3··on Teens learn a new conspiracy theory every week on social media
> About 80% of teens who use social media say they see content about conspiracy theories in their online feeds

Where conspiracy theory means what, exactly? Did they define this term for the teens (or even just for the survey)? Why is 'disinformation' (itself undefined) conflated with the hilariously ambiguous 'conspiracy theory'?

It's really just a terribly weak article, and the source "study" doesn't look much better. It really looks like it is a study set forth to push a particular agenda with "numbers".

Too many people confuse data with science, and perhaps that is what schools should actually be teaching; probably when they teach statistics, which all students should take. Pseudo-science like "critical thinking" can't really be taught, but actual science can.

Page 1 of 9Next →