HNHacker News
TopNewBestAskShowJobs

biturd

626 karma · joined July 13, 2010

submissionscomments
biturd··on Mitro is Shutting Down on August 31st
Even @twittereng replied saying "welcome to the flock" so indeed they were acquired/aquihired by twitters.
biturd··on Show HN: Potbox – A premium cannabis subscription club
How will they ship this? It is probably a big crime to commercially mail pot across state lines that have not legalized and decriminalized it.
biturd··on Project Fi Review: Cell Service from Google
Yes, of course, it's a basic cell phone still. Many buy them, drop 20 bucks on it, pull it apart and make a nice GPS tracker insead of paying $800 for a "professional" work truck positional monitoring system.

Edit: spelling

biturd··on Own-Mailbox, the first 100% confidential mailbox
So basically, once you add the relay, you have made the devices most compelling feature no longer a feature.
biturd··on Own-Mailbox, the first 100% confidential mailbox
You certainly should check. As I'm sure you are aware, some RBL's areole aggressive than others. Some are down-right draconian, and some are more like a whitelist in that they leverage grey listing so any outbound mail is given a few good points in it's total possible spam score.

I ran a medium email ( late 90's ) mail server system on a dedicated 100mb/s line, on an older dual cpu Power Mac actually, but I pulled out all the GUI and tried to run it mostly as a server using the client OS and only the CLI, making it more like running FreeBSD or openBSD I suspect.

I got a /24 IP range out of Comcast which I think helped as it was a previously never used /24, or at least not in use long enough that it had fallen out of RBL's

I'm sure you are aware of the sites that checks your IP against all 200+ or so mainstream RBL's.

There are a few RBL's that block Comcast business as well as all cellular ranges and quite a bit more. I found RBL's to be more trouble than worth.

Ideally, you are dropping the connection at the very beginning, just after the EHLO/HELO., highly efficient, perhaps marginally more efficient CPU-wise than greylisting. Fail2Ban is probably your best friend. Do it closer to the network if possible.

The above, versus pushing the message through various spam filtering, address validation, and other measures. There's heavy CPU usage post greylisting, greylisting is great, but waiting that 5-15 minutes for the retry is too long, most users don't use a password manager. Their password manager is "forgot your password". Insane, but that's how I watch all my friends do it. They learned not to re-use passwords, but now they rely on third party email to send forgot password messages. At least people can tell which are not hashing/+salting their credentials. Though I doubt most blink an eye at a raw password in an email. Clients have email me their credit card data. I tell them delete their debt message, then dived 15 minutes doing tech support to help them locate the credit card sent email.

I was far too often adding whitelist entries, making certain clients ignore greylisting or drop down to 30 seconds, for which I saw no increase in spam. It's the retry value on the server that's set too high/long. Not to mention the 10% or so of older email servers that don't support greylisting so never retry. A clear RFC violation, but these are proprietary systems and not made with greylisting in mind. You could achieve it with a proxy running greylisting or ASSP if you want a full proxy with web admin and essentially a full MTA in a proxy all in one file of many tens of thousands of perl code. No version control, crazy version numbers, and I think still on SFNet ( Source Forge )

At some point you realize you have added aol, yahoo, gmail, etc., all the big guys, they need whitelisting because their IP ranges are huge, and ever changing. Keeping on top of which IP's they are publishing as public MTA based IP's, you can build a solid whitelistable IP range, but they change often enough it's not feasible. A SAAS that checked all this would be nice but latency may be too much. Less than the 5-30 minutes of greylisting though.

AOL fully ignores greylisting last I looked. Not to mention DNS TTL's are/were ignored. Sucked to set my MX TTL to 300 seconds, wait the 8 hours for my default DNS expiry, switch my DNS, and then wait 2 weeks for DNS proposition with aol. Not to mention all the paperwork that needs filling out to get into their MTA whitelist program which kicks your sending threshold up by a percentage so it's not a true whitelist. I had to renegotiate every time we added another 5000 to our outbound, it would flag me and I could see all the aol messages stuck in my outgoing queue. Two weeks was longer than my greylisting time, messages bounced because aol saw no server at the other end. I had to keep a "gateway" running, basically I set up a secondary MX to sit there and deal with the aol 2 week DNS propagation to happen.

Finally I gave up and added an external SMTP only machine in a colo. small machine, under 100.00 a month, all it did was SMTP. Deliverability was significantly better after that but ruined the notion of securing my data at my location. But it is relatively ephemeral in that its just SMTP, the data sends instantly, unless it hits greylisting servers or other things that initiate a SMTP retry. That leaves messages and retry logs on the remote server out of my control physically.

Most don't answer postmaster@ or abuse@ which are RFC. Some even bounce meaning they don't even have those addresses available. Having a support/postmaster/abuse @ address that you certainly should check. As I'm sure you are aware, some RBL's are more aggressive than others. Some are down-right draconian, and some are more like a whitelist in that they leverage grey listing so any outbound mail is given a few good points in it's total possible span score.

I ran a medium email server system on a dedicated 100mb/s line, on an older Power Mac actually, but I Pulled out all the GUI and tried to run it mostly as a server using client OS and only the CLI, making it more like running FreeBSD or openBSD I suspect. Added 2x SATA cards and an additional CPU to speed things up. IMAP is purely I/O limited and I wanted and had everyone in IMAP. but IMAP needs a few horses behind it, I wish SSD's were where they are now back in the 90's. That would have been great. I moved my 4GB IMAP account into pure ram disc. It was pretty amazing. Millisecond loading of a mailbox with push enabled in milliseconds to load many tens of thousands of messages and attachments.

I got a /24 out of Comcast which I think helped as it was a previously never used /24, or at least not in use long enough that it had fallen out of RBL's

I'm sure you are aware of the sites that check your IP against all 200+ or so mainstream RBL's.

There are a few RBL's that block Comcast business as well as all cellular ranges and quite a bit more. I found RBL's to be more trouble than they are worth. Good in theory and a great thing to run your own local RBL as it's such a nice way to manage it, through DNS. Want to whitelist or block, just add a DNS entry after reversing the IP. Simple, immediate, understandable.

Ideally, you are dropping the connection at the very beginning just after the EHLO/HELO. Versus pushing the message through various spam filtering, address validation, and other measures. There's heavy CPU usage post greylisting, greylisting is great, but wIting that 5-15 minutes for the retry is too long, most users don't use a password manager. Their password manager is the "I forgot my password" mechanism.

I was far too often adding whitelist entries, making certain clients ignore greylisting or drop down to 30 seconds, for which I saw no increase in spam. It's the return value on the severe that's set too high/long.

Eventually I ran out of granularity per user to set things how I wanted. Setting up a server for a subset of users was asking for trouble.

At some point you realize you have added aol, yahoo, gmail, etc., all the big guys, they need whitelisting because their IP's are huge, and ever changing. Keeping on top of which IP's they are publishing as public MTA based IP's, you hBe a solid whitelist able IP, but they change often.

AOL fully ignores greylisting last I looked. Most don't answer postmaster@ or abuse@ which are RFC required for postmaster and suggested strongly for abuse@.

Oracle ended up in spamhaus, after weeks, I finally got I touch with their admin. ( grind worked there, could not email him ) He'd ( Oracle MTA Admin ) been trying to figure it out for 4 months of bounced emails. How they never had a forwarded email from a bounce that shows the 5.5.0 code is all they would have needed.

But that poses another problem. You have to whitelist abuse@ and postmaster@ or the data you send them will trigger everything, anti-spam, and bounce. But then you get tons of spam, fully unfiltered on those two accounts.

Then there's DKIM and the rest plus the rest of the DNS based pseudo AUTH mechanisms. But those too are problematic. Some can't forward without bouncing, under SPF I believe. Oracle ended up in spamhaus, after weeks, I finally got I touch with their admin. He'd been trying to figure it out for 4 months or bounced emails. How they never had a forwarded email from a bounce that shows the 5.5.0 code is all they would have needed.

But that poses another problem. You have to whitelist abuse@ and postmaster@ or the data you send them will trigger everything from anti-spam and bounce. But then you get tons of spam, fully unfiltered on those two accounts.

In the end, I'm basically tailing logs, massaging them into a SNMP walkable data point so I can graph and chart. All to find out managing a mail server really is a near full time job. Add a secondary and it's even worse as spammers will direct target your mx2 Which means filtering, whitelist, blacklist, greylisting, geographically separated, and network role separated ideally, etc., full parity on two physically disparate boxes.

I was pushing about a million messages a day across a few 10's of thousands of accounts, forwards, aliases, etc. all over Comcast business.

The upsides: 4 hour support window 24/7/365. Direct phone line that a person answers. That person is an engineer of some sort or will transfer you to someone. I've spoken to engineers that maintain DNS, mail, web, etc. you get as close to he source as possible and they know how to unpack a gzipped or tar'd log file batch if you can even get a contact address for them.

Sorry if there's duplication of content. Either something is up with HN or my phone is being my phone as usual. I apologize for the illegibility in places.

biturd··on Online Anonymity Box Puts You a Mile Away from Your IP Address
Absolutely amazed that Starbucks and the rest are not using some kind of auth. I've noticed a few Starbucks now that have an SSID of google-Starbucks or something similar.

Anyone know if google at least does a better job. Some form of AUTH?

On OS X I can push ALL data through a VPN. Trouble is, it's based on a hostname. I put in anything from /* ( wild cards galore ), http://*, plus the SSL version and any other combination.

I, as well as many others, assuming Apple doesn't delete the thread from their support forums, have been trying to resolve this without running a separate dedicate VPN app that may or may not support auto-scanning type connections that tend to drop off and re-enable For now, 8+ years has never gotten VPN on demand triggered by a call to a hotname as the trigger. Calls from browser, shell, even higher level tools like dig, telnet, etc, do not instant AUTH a VPN connection. It has to be done manually.

If I could feel safe, a setting of, "any packet start of packet egress will stall the connection until VPN is up so zero Dara goes over a non VPN line. A VPZn should get around Sprint's idiocy in throttling video to 600k meaning once you add in audio, 320 is probably the best resolution you will be getting. With a VPN they should not be able to detect the traffic. I'm thinking VPN with all love pointed to a log server remotely stored and that nukes logs pretty quick or send logs to /dev/null but that may make debugging hard.

Edit: tons of spelling, grammar, and additions for clarity—mobile is really a terrible platform for typing ore than what you push to trigger. :)

biturd··on Online Anonymity Box Puts You a Mile Away from Your IP Address
Why do you even need his box? Just point the antennae at the Starbucks or library, change your MAC first.

OT: with the proliferation of xfinitywifi, I have joined at my home when the internet was down on one channel but the xfinitywifi worked. Now I notice when I am out and about, I auto join any wifi named xfinitywifi.

Is it now that simple? With most having joined Xfinitywifi at some time, I can just buy a cheap router, give the SSID xfinitywifi, and people will auto join and I can middle them all day long?

biturd··on Safari is the new IE
What if gmail or another large service implemented a reliance on these new features. Safari would be forced to add them in?
biturd··on Own-Mailbox, the first 100% confidential mailbox
Comcast busses class still has all their IP's in many RBL's, this product won't work reliably for deliverability.
biturd··on Own-Mailbox, the first 100% confidential mailbox
How are they going to receive mail? All blocks of IP's from any provider are blocked, usually huge blocks, larger than /24 often. No one is getting to any comcast users, they as do many others publish lists of their IP ranges so you can block then in your server or use an RBL.
biturd··on Project Fi Review: Cell Service from Google
buy a 20.00 burner phone from 7-11 and port your number into it, use the web account or phone options to set up your forwards. Put the phone in a drawer and shut it off. It should last years if not too many people call it.
biturd··on Our love of technology risks becoming a quiet conspiracy against ourselves
you just described photoshop perfectly.
biturd··on Dropbox Is Struggling and Competitors Are Catching Up
I think I have about 40GB of free storage with DB as a result of working there referral system. However, a friend bought some Android based phone, came with DB pre-installed, and he has something like 500GB or free storage. They were doing some promotion.

I think one of the main issues with DB is that it is too little space and too much cost to add more. Considering what they pay for bandwidth, any paid plan really should be unlimited.

biturd··on Wooden combination lock
Even more "HN applicable", a wooden calculator: https://www.youtube.com/watch?v=GcDshWmhF4A
biturd··on To Apple, Love Taylor
They gove away their OS and a ton of solid near business class apps in some cases. They do this to get people to buy hardware.

She said she supports herself on tours, five more music away, you should get more people at her tours. Same for the new band, you don't get discovered on the radio, 5K and they will play your song, it's that easy. Never works.

Play shows for 5 - 10 years, you may make it, or be coached and molded like Taylor, that Canadian Kid, and the ret of them.

biturd··on Individuals with social phobia have too much serotonin
Is any of this even solvable to the general mainstream public? They need to think in absolutes, as in, this medicine does x to fix, prevent, or repair y. That is how the general public measure things.

In reality, an anti depressant for example, probably works out to something like: it works about 50% of the time, with a bit of a lean over 50%, but if we calculate in spontaneous remission, placebo effect, and some other variable, now it looks like it is either a net zero effect, or in many cases, like AA meetings, statistically detrimental. But the general public will need a binary answer.

And I consider myself part of this general public, I just know there is more than meets the eye on anything, and in general I feel correlation and causation more often then not don't agree.

biturd··on How One Brain Came Back from Unconsciousness
I don't know about country wide, but Calif. has mandatory seat belts, I think $50 a ticket, and doubling each time thereafter. Though I have gotten about 5 seat belt tickets when the law first went into effect and it was always just 50.00 and does not affect your insurance or driving record. Things may have changed since then, that was a long time ago.

I don't personally agree with them, there are cases where not wearing them save you. Mt brother was tossed out of the windshield instead of getting crumpled into a small box of metal that was once a car.

Motorcyclists would be hitching a ride on a death trap if they were strapped, whereas, even at 50+ you can, if practiced, sort of roll out of a fall and you just slide on the pavement. You may get a little banged up but rarely a trip to the hospital. Impact another car or object and you are probably screwed, but I would say no more screwed than being in a car and getting tossed out the window at 50+mph.

I always felt it my decision to handle my life how I desire, so if I want to die and don't care, I can not wear my seatbelt, if they catch me, I am happy to pay the fine.

I have since long ago just started wearing it as every car I get into I get told to put it on, so it has just become habit. But I hate the way they ride on my neck, tighten on my stomach, and are generally restricting and uncomfortable. I spend more time adjusting with my eyes off the road than is probably safe, and this can't be don't pre-driving as belts tend to creep up on my like a loose pair of underwear :)

biturd··on How One Brain Came Back from Unconsciousness
Busses are designed in a way in which adding seat belts would be more harmful. It has to do with a combination of the seat in front of the person, how the seat they are sitting in is made to be very strong but collapse forward where the front seat acts as an airbag of sorts.

There is a How it's Made episode on school busses that explains it in short detail.

I can say, in my area, public transportation has never had sear lets, and do not to this day. The school busses are still all very old, and I doubt they have them. They did not when i went to school, and I don't see retrofitting them without full seat replacements as they are designed to break away and assume you are not connected to the seat.

biturd··on 68 Katy – 68000 Linux on a Solderless Breadboard
Would mac os 9 apps compile and run on this system?
biturd··on What's new in Xcode 7
I feel being a staunch Mac user from the beginning has been detrimental to me. My first computer was a commodore 64, which I typed the programs out of the book into the terminal and it made balls move around on the screen and such. But I was really young, and no one was there to catch me, so I never thought to fiddle with it, I thought it was like a set of instructions and you had to follow them. I did not yet understand creativity at that age.

I then later, many years later, was given a Mac Plus. I could use BBS software to chat, but remember thinking, it is very hard to even type a conversation back and forth to a user elsewhere with a modem. There really was no software for it, or if there was, it was hard to find or even know about.

How did you know to learn C and then get a compiler? And how did you afford the software to develop back then? Wasn't code warrior around several thousand?

biturd··on What's new in Xcode 7
Do you have a link to the patio11 anecdote?
biturd··on “Swift will be open source later this year”
What language is that link written in? It looks like bash sort of but not really?
biturd··on RedditStorage
how do you get a Mac OS X GUI around this if it is written in python? Can you do the same with perl, php, and other languages? Interface Builder has always been a stumbling block for me to even begin to learn Obj-C or Swift.
biturd··on Stress Test Recap: Bitcoin
I have never bought btc, there is a fee? This is a function the wallet provides? Who gets the fee? I have bought dogecoins as a joke, and I have a wallet for that, which I send a few coins here and there to others, which cost me nothing. Not quite following what I thought was the basic principles of how this works now.
biturd··on Dear AirBNB, No Thank You for the XXX Freak Fest
Does anyone know how he plotted where he slept on a map like that? I am assuming he did not hand enter it into some API maps tool, but rather, an app he has marks his location.

I would like an app like this in the event I ever need to prove my location. And I think it would be cool to see where I go on a map.

biturd··on Silk
Tried to make a face, failed. http://r.weavesilk.com/?v=4&id=ejh105uw8ug
biturd··on How does Tor bypass DNS
Thanks for the explanation, I appreciate it.
biturd··on How to vertically center a clipped image with CSS
doesn't work in safari though he talks about adding the safari prefix at the end.
biturd··on Ask HN: Why not just use ssh for everything
So this is just a dev wanting to scratch an itch issue and/or arrogance and/pr ignorance?

I always wondered why there was a separate layer for VPN's when you can so easily use ssh for a VPN at least for a secure way to use the internet. I suppose if you want it for the act of "being" on a remote network as if you are local is a VPN advantage, but I'm pretty sure ssh has a way to make that happen as well.

If I get this correct, it is a good idea to use ssh as a chat app's security methods?

biturd··on I would have hired Doug, but...
I was looking at some of the code for one of his projects that is a little node http server. I don't really know JS or node at all, but can someone explain this to me:

     function secondsSince (when) { 
	var now = new Date ();
	when = new Date (when);
	return ((now - when) / 1000);
	}
I'm assuming now returns seconds since some fixed point in time ( epoch ) when when someone passes in the 'when' argument, it must already be formatted a certain way, or node/js somehow managed to figure out the input? How would it deal with 5/8/2015 vs 8/5/2015

Or this is just a very case specific function and the input is already sanitized in a way that is prepared for this function?

github is here: https://github.com/scripting/pagepark/blob/master/lib/utils....

← PreviousPage 2 of 8Next →