HNHacker News
TopNewBestAskShowJobs

addingnumbers

844 karma · joined April 2, 2015

submissionscomments
addingnumbers··on Show HN: Killport – CLI tool to kill processes running on a specified port
grep isn't necessary at all here:

  lsof -s TCP:LISTEN -i :$port
addingnumbers··on Why do ships use “port” and “starboard” instead of “left” and “right?”
> The doors had to remain open and pointing away from the earth

It's the opposite. The orbiter usually kept it doors pointed toward Earth and the "bottom" tiles pointed away from Earth, and orbited with its engines pointed prograde. (Upside-down and backward relative to the atmospheric flight people are familiar with)

https://space.stackexchange.com/questions/12321/why-did-the-...

addingnumbers··on Making a Linux home server sleep on idle and wake on demand – the simple way
Proxy ARP would have the raspberry pi provide its own MAC address as the MAC for the server IP. All the traffic from the clients to the backup server would have to pass through the Pi's network interface for the duration of the session.

With this ARP stand-in, it provides the server's MAC to the client so subsequent traffic to the server doesn't need to pass through the Pi.

addingnumbers··on What is NMAP and how to use it? (2020)
The alerts tend to be geared more toward attempts to reach a secured system that isn't accessible to you.
addingnumbers··on Why ChatGPT and Bing Chat are so good at making things up
> Answer "I don't know" if you are not 95% certain they exist.

Technically, this could be read as == instead of >=, meaning it should answer "I don't know" when it is 99% or 100% certain...

addingnumbers··on Ubuntu stops shipping Flatpak by default
> All it takes to get rid of snaps forever is `sudo apt purge snapd`.

That's not enough. Some package could eventually drag it back in.

    $ apt show firefox
    Package: firefox
    ...
    Pre-Depends: debconf, snapd
If you really want to keep it off your system for good, you need something like this:

    $ cat /etc/apt/preferences.d/no-snapd
    Package: snapd
    Pin: release a=*
    Pin-Priority: -1
    $
addingnumbers··on So you've installed `fzf` – now what?
Add this to your login script:

  export FZF_DEFAULT_OPTS="--exact"
Or invoke it with one of these:

  fzf --exact
  fzf -e
Or if you start your search with a single quote ' it disables fuzz. (But maybe you already knew that, it sounds like you want the first option.)
addingnumbers··on So you've installed `fzf` – now what?
It returns non-zero exit codes when there are no matches or no selections made, so you can shorten that:

  fuzz() { file=$(fzf) && nvim "$file"; }
addingnumbers··on DNS0: The European public DNS that makes your internet safer
Won't recursing also spread your queries across multiple providers? And in the clear for deep packet inspectors to see, instead of encrypted?
addingnumbers··on HP bricking printers remotely if the client's credit card expires [video]
> In Gilbert and Sullivan's Pirates of Penzance, Frederick is indentured to a band of pirates until his 21st birthday.

That particular wording coming back around to bite him when it's pointed out that he was born on February 29th in a leap year...

addingnumbers··on ssh whoami.filippo.io
That's a petty interpretation, it's a big leap reading "don't send your unique identity to strange servers by default" as "never use private keys, always use passwords instead."

Nothing about that config snippet precludes using private keys for known servers.

addingnumbers··on Magic beans, Bahamian penthouses, old-fashioned fraud and other important SBF-in
That's all from the 1807 moralized version, the 1734 version doesn't have any golden eggs, goose, or harp. In the older version the giant swings a sword at him and dies himself instead by the protection of a magic ring Jack found on the way up. Then the giant's human servants appoint him king of the castle.
addingnumbers··on Cached Chrome Top Million Websites
> only including data from users who have turned on "Make searches and browsing better (Sends URLs of pages you visit to Google)"

One big problem there is that we don't know what percentage of users for whom "turned on" is a euphemism for "didn't notice."

addingnumbers··on Reasons a Raspberry Pi Belongs in Your Network Lab
I'm surprised they didn't recommend dnsmasq to begin with, it's a lot lighter on resources which could be important with low-end machines, and with DNS and DHCP services baked in to one process you don't need to worry about configuring hungrier services like dhcpd and BIND to read each other's state.

The only reason I'd recommend dhcpd/bind over dnsmasq for a small lab is if you are trying to familiarize yourself with the former pair for use in larger networks with more expansive requirements.

addingnumbers··on Mars helicopter Ingenuity soars higher than ever on 35th Red Planet flight
Well, that's convenient.

It looks like maybe Ingenuity's panel could use a little blast of nitrogen though:

https://www.nasa.gov/sites/default/files/styles/full_width_f...

addingnumbers··on Mars helicopter Ingenuity soars higher than ever on 35th Red Planet flight
Perseverance (the rover) has its own "Gaseous Dust Removal Tool (GDRT)" that puffs compressed nitrogen to remove dust from samples before analyzing them, not sure if it can turn that back around on its own panels though...
addingnumbers··on Before Google, there was the reference librarian
My grandmother's best friend was a librarian, so I got a lot of encouragement growing up to make use of library services.

I remember calling the local library dozens of times for school reports. The local library wasn't where my grandmother's friend worked, so I wasn't getting any preferential treatment. To them I was just another random eight-year-old ringing them up to ask questions.

They were always delightfully eager to help with obscure questions about geology and history and science, running off to grab books while I waited, slowly reading me facts and passages while I took notes. They'd set aside books for me to check out later in the week, with bookmarks already placed in the sections where they thought I'd be most interested.

As much as I love the instant access to information we have nowadays, I feel a sense of loss over kids missing out on that shared human sense of enthusiasm and encouragement from working with a person who enjoys feeding childrens' curiosity.

addingnumbers··on iOS allows DNS request to escape the VPN tunnel
They circumvent this by forcing certain traffic to circumvent your hardened WiFi by using the mobile network radios.
addingnumbers··on iOS allows DNS request to escape the VPN tunnel
> Also, aren't there proxies that you can setup that can inspect HTTPS connections (so long as you install the proxy's cert on your machine).

It's common for apps to prevent this with certificate pinning. They'll ignore the certs you've installed manually and will only connect to servers with certs signed by their in-house certificate authority.

addingnumbers··on Only Persistent LogIn
> If they have my authenticator app then they've already totally owned me anyway.

Seems like that is the problem they're trying to improve by using 3FA instead of 2FA.

addingnumbers··on Only Persistent LogIn
Seems like they're talking about RBA, risk-based authentication.
addingnumbers··on The IT Crowd US Pilot (2007) [video]
They completely undermined the first establishment of "have you tried turning it off an on again?"

The line doesn't land half as well without the entire 45 seconds (no exaggeration, I counted on the seek bar) of Roy licking his fingers and drinking tea while the phone rings first.

addingnumbers··on Uber investigating breach of its computer systems
> most websites/companies will quite happily let the impostor click a "Forgot password" link and get a SMS code to verify their identity

That's not 2FA. There is one single factor there, the SMS code.

SMS 2FA does not require you to have a 1FA backdoor, so you can't claim the latter is an inherent fault of the former.

For example, pairing "enter the SMS code" with "click the link we sent to your backup e-mail address" gets you a two-factor password recovery process.

That isn't the best or only method of 2FA password resets, it just comes to mind first because it's the last one I used and it is sufficient to prevent access via SIM hijacking alone.

addingnumbers··on Retirement of Amazon MOBI eBook file format
What about battery replacement?

Seems like no matter how good the display and build quality, all eBook readers are bound to stop holding a charge after 3-4 years. I feel like the ongoing availability of newly-produced replacement batteries and the difficulty of replacing them are the primary factors in choosing an ebook reader.

My 2015 Paperwhite barely lasts 20 minutes after I pull the charging cable, even back in 2018 it was down from two weeks to two days per charge.

It's not like you can avoid the problem by loading up on extra batteries. A replacement battery manufactured shortly after the reader is going to be as bad as the one that came installed by the time I need it.

All the other problems I worry about like responsiveness, display quality and defects apply early on when a refund or warranty replacement is a solution.

addingnumbers··on An incident impacting 5M accounts and private information on Twitter
"We are unable to determine if the vulnerability was exploited."

How hard they looked is not of any consequence if they can't tell it wasn't exploited.

addingnumbers··on Facebook Gave Police Teenager's DMs in Abortion Prosecution
> "why do I need anonymity if I'm not doing anything wrong"

These people didn't do anything wrong either:

"They Told Their Therapists Everything. Hackers Leaked It All"

A mental health startup built its business on easy-to-use technology. Patients joined in droves. Then came a catastrophic data breach.

https://www.wired.com/story/vastaamo-psychotherapy-patients-...

addingnumbers··on An incident impacting 5M accounts and private information on Twitter
That's why I referred to it as a psychological trick.

They should be open and forthcoming about their level of confidence, instead of using the least worrying language they can offer while remaining technically correct.

addingnumbers··on An incident impacting 5M accounts and private information on Twitter
It would be more honest to say "We aren't able to determine whether it was exploited" which could better brace potentially impacted users for the possibility they might be affected.

This is a relatively benign case but the same language is used in other breaches when people should be taking measures like freezing their credit or reviewing financial transactions.

addingnumbers··on Someone Is Trolling Celebs by Sending ETH from Tornado Cash
Don't know about Chappelle, but Fallon has his ethereum name service (ENS) address "Fallon.eth" in the "Name" field of his verified twitter account profile.
addingnumbers··on An incident impacting 5M accounts and private information on Twitter
"We have no evidence that this was exploited" is a standard psychological trick they pull in vulnerability announcements to give an unfounded impression that it hasn't been exploited.
Page 1 of 10Next →