HNHacker News
TopNewBestAskShowJobs

anemic

303 karma · joined November 10, 2011

submissionscomments
anemic··on Xiaomi Mimo 2.6 live post-training dashboard
Bottom of the page says "Open is what we value."
anemic··on Los Puesteros, solitary men who look after ranches and livestock in Patagonia
They probably all are former software developers. I would imagine the waitlist is very long
anemic··on Turning Claude Code into my best design partner
I too recently discovered this workflow and I'm blown by it. The key IMHO is first to give claude as low requirements as possible and let it's plan mode roam freely. Writing a reporting for sales metrics? "Ultrathink relevant sales metrics" and it will give you a lot to start ranking which you want, maybe add some that are missing. Then create a new directory for this feature and ask it to write the plan to a file. Then proceed to create an implementation plan, ask it to find all the relevant data from the database and write how to query it. Then finally let it implement it and write tests and end user documentation. And send it to QA.

Need sales forecasting? This used to be an enterprise feature that 10 years ago would have needed a large team to implement correctly. Claude implements a docker container in one afternoon.

It really changes how I see software now. Before there were NDAs and intellectual property and companies too great care not to leak their source code.

Now things have changed, have a complex ERP system that took 20 years to develop? Well, claude can re-implement it in a flash. And write documentation and tests for it. Maybe it doesn't work quite that well yet, but things are moving fast.

anemic··on Root shell on a credit card terminal
I once had the (dis)pleasure of working with these Yomani terminals. I got a development unit (with red text "DO NOT PAY" on the side). I plugged it in my home internet which has a public ip with dhcp just to get it quickly online and keep it out of my internal home network. The next day I got a call from my ISP saying I had a compromised machine in my network with malware. I was like WTF?! and they gave me the mac address and it was the Yomani terminal! I promptply unplugged it from the network and started investigating. Indeed, this development unit had a telnet(!) port open and root login without password was possible. So, having a wide open telnet port on a public ip and it's just a matter of minutes until someone uploads a generic arm malware onto it. I returned the terminal to the vendor with explanation but never got a followup. Lesson learned: never attach anything to public internet, even if it looks secure.

I guess Atos Worldline really doesn't like root passwords.

anemic··on Intel lost the Sony Playstation business to AMD
Maybe the deal went south because Intel wanted it to be called Playstation 6 with Intel Integrated Graphics.

And with a sticker on the front, of course.

anemic··on ‘All of Sony Systems’ Allegedly Hacked by New Ransomware Group
Due to the previous hacks they have successully reduced the number of files they have.
anemic··on Ask HN: How do I manage the profit of a successful website?
How about donating to charity? If you don't need the money, there are people in the world who are struggling to get clean water.

Spend some time to verify that your money goes to a good cause and not to scammers.

You could start by donating to a local sports team to buy equipment to those who can't afford if, for example. Then go see their games to see what you've accomplished.

anemic··on Upgrading the soldered-on RAM of a Dell XPS13 7390 laptop
I did not know dentists offer such a service but i'm still a bit hesitant to ask at my next checkup.
anemic··on Extreme Ironing
Extreme ironing used to be fun sport but when Rowenta started sponsoring the UK team in the championships it's now only "commercial sponsorship and exploitation"

http://www.ntk.net/2002/09/13/?l=92#l

anemic··on Russian Spy Ship Yantar Loitering Near Trans-Atlantic Internet Cables
They could also insert some kind of remote detonation device so the cables can be cut in case of war.

Tapping the cables is so last season, everyone knows about it and should use encryption.

anemic··on North Dakota needed to hire Latvians to manage an ancient state computer system
> North Dakota's unemployment insurance mainframe computer, similar to the 1980s system seen here

The image is actually HPE C7000 blade server chassis introduced in 2006

https://en.wikipedia.org/wiki/HPE_BladeSystem

anemic··on GitHub was down
Protip:

Always have an extra customer, like the flowershop downstairs. Let her borrow your wifi in exchange for some office flowers. Now she is technically your customer.

When your shit goes down and nothing works you can still write "some of our customers are experiencing issues" in the statuspage as the flowershop still has wifi (hopefully).

anemic··on An analysis of the Lego City deep space rocket
It could be decoy program to hide development of an intercontinental ballistic missile?

I haven't seen any LEGO centrifuges in stores. Those could have been hoarded by someone to encrich LEGO uranium?

anemic··on “100 spies” will monitor all SMS and email that goes in and out of Norway
My personal belief is that they dont. Best they could achieve is trapping the ISP's sending mail server in Norway before the mail is encrypted but there is no capability to decrypt SSL without obtaining the keys.

They could still store metadata like sending IP address, timestamp etc.

Using foreign webmail via HTTPS would not be intercepted in any possible way. Unless they get support from the service provider in question. I think the service providers you mention will comply with law enforcement and give out your data. But those are isolated cases and mass data required by intelligence services is a different thing. National security letters are only for US Govt use and other governments have no access.

I also think legislation like this is years late now that about every protocol has encrypted variants and they don't get any meaningful results compared to the money spent.

anemic··on Estonia sues Gemalto for €152M over ID card flaws
Well, there was this revelation that NSA had the 'Gemalto network wide open'. After week long investigation Gemalto denied any breach, leading to situation where you could either believe NSA or Gemalto.

https://www.wired.com/2015/02/gemalto-confirms-hacked-insist...

anemic··on 15 Years of SparkFun
Company that produces instruction manuals like the Heaterizer XL3000 can't be bad!

https://www.sparkfun.com/datasheets/Tools/SFE-Heaterizer-Ins...

anemic··on GitHub mirror compromise incident report
Also the type of the malicious content (rm -fr /*) is "easy" to spot in which I mean there are no rootkits or remote exploitable flaws added.

Not very nice to be a victim of that but at least there is no doubt whether you're vulnerable or not.

The timeline also suggests that the malicious content was made after the break-in and not planned beforehand?

anemic··on What's the Deepest Hole Ever Dug?
Thanks for this, reading the article made me curious about this too.

The folks at Cards Against Humanity () didn't get too close to the record. They also ran out of funding like most of the projects mentioned in the article...

https://www.theguardian.com/technology/2016/nov/28/cards-aga...

anemic··on Earliest images of the moon were better than people realised
I really liked how they used the apparently intact equipment inside the McDonalds like the price signage to show their images.

That's no moon!

https://www.flickr.com/photos/agentmouthwashfanclubpresident...

anemic··on Gas Pump Skimmers
Most interesting part is that they managed to get the hex dump of the software. Quick glance shows there are no copyright texts in it, bummer!

I'm not an expert in PIC assembly but it seems there is very little code and there are no obvious code paths, like a switch..case like construct for processing the serial commands. Lots of I/O and not much more. Most likely they are not decoding the magstripe data in PIC but just get the decoded data and store it.

anemic··on Timescale, an open-source time-series SQL database for PostgreSQL
Can this be queried with Grafana or some other visualization tool?
anemic··on UpCloud+Kontena – all Suomi (Finnish) love
I just made a switch from Kube to Kontena last week. I had constant trouble with etcd cluster and so far Kontena seems solid and was much faster to set up for production. I'm running 6-8 nodes so kube always felt like it was a little too much for me.

I noticed the same thing about FAQ, I had all those working in my kubernetes setup.

anemic··on A quick look at the Ikea Trådfri lighting platform
FAQ here http://www.ikea.com/gb/en/customer-service/smart-lighting-su...

says no API access in the first version but IKEA is working towards an open system.

anemic··on Kubernetes the Hard Way
ansible/puppet/chef is the way to go. Single line of DSL is worth 1000 lines of text on a blog, imho.
anemic··on Kubernetes the Hard Way
Spot on! Once you get everything running you're so exhausted documenting it by writing a blog post is not on your mind, sleeping for a week is...
anemic··on Kubernetes the Hard Way
That is perfectly fine if it suits your use case! I have to deal with industry certifications and unfortunately using a ad-hoc certificate authority is not an option or running in insecure ports.

Also I was setting it up on coreos and baremetal servers. It should be possible to run pods in google container engine or similar very easily, but would there be any fun in that?

anemic··on Kubernetes the Hard Way
Lots of good information here but it is still not enough for a production setup IMHO.

There is a great need of good source of production setups. In open source software this seems to be the secret that no one is willing to reveal. I tried to setup a kubernetes cluster from scratch a while ago and soon I was browsing the source code for answers. Openstack is the same, you need to understand a lot about the inner workings before you can even attempt to setup something for production.

There is always a simple "this shell script starts your own <name your tech here> cluster in vagrant" but it is still not a production setup.

And even if this article is the "hard way" it describes:

> This is being done for ease of use. In production you should strongly consider generating individual TLS certificates for each component."

And it does not mention that the crucial part is the common name field in the certificate maps to the user name that is the magic information that I once needed.

I sincerely appreciate this article but production setup is still a long learning experience away.

anemic··on Santa Claus Confirms NSA Attack on Naughty or Nice Database
as you seem to have some inside information can you share some details about the database schema: is naughty field not null or nullable? what about indexing a table on a boolean column?
anemic··on Demoralize Your Teams Quickly and Efficiently with Micromanagement (2010)
After talking with several managers who tend to micromanage I've noticed that they like to play strategy games on their free time where it's also possible to micromanage. Good example is Civilization where they always like to manage every single detail of their cities whereas I just want to leave that to the computer AI.
anemic··on Computer, Respond to This Email
advertising becomes scary when this service tries to suggest responses like "Yes, let's have a meeting tomorrow and why not enjoy a refreshing glass of ice-cold Dr.Pepper together!". But if not, I'm not that worried about the ad revenue aspect.
Page 1 of 3Next →