HNHacker News
TopNewBestAskShowJobs

botw44

49 karma · joined April 13, 2023

submissionscomments
botw44··on Tired of paying per domain for DMARC, so I built a self-hosted one
DMARC aggregate reports are free XML that Google, Microsoft, Yahoo, and other mailbox providers email you every day. The dashboards that make them readable typically charge per domain per month. We were paying for one, so I built a self-hosted collector.

The main difference from parsedmarc (the mature, established project in this space) is that this one is the MTA. It runs aiosmtpd on port 25 and receives reports directly instead of polling a mailbox, so there are no IMAP credentials to manage. It also generates a unique report address for every domain and the DNS records to publish, including the _report._dmarc external destination verification record required for cross-domain reporting. If your host blocks port 25, it can poll an IMAP mailbox instead.

A few implementation details I'm particularly happy with:

- Raw messages are stored before they're parsed, so parser bugs are replayable instead of losing reports. Messages sent to unknown report addresses are quarantined rather than rejected, because a bounced DMARC report is gone forever. - DNS verification queries the domain's authoritative nameservers instead of a recursive resolver. I originally did the obvious thing and spent far too long convinced Cloudflare wasn't saving my changes. - Sending IPs are resolved to their network owner via PTR and RDAP, which turned out to be much more useful than I expected. The organisation sending the report is usually not the organisation that sent the email, and "Twilio SendGrid" is far more useful than an anonymous IP in a Google report.

It's built with FastAPI, aiosmtpd, SQLAlchemy, and PostgreSQL or SQLite. The UI is server-rendered with SVG charts—no JavaScript build step. Deployment is via Docker Compose or the included Helm chart. MIT licensed.

https://github.com/pescheckit/dmarc-service

It's only a few weeks old and has one maintainer, but it's already collecting real reports for five of our own domains, which is where most of the bugs were found. A substantial amount of the implementation was written with Claude Code under my review; I made the architectural decisions, reviewed the code, and wrote the tests.

Happy to answer any questions.

botw44··on Anthropic's Safety Superpower
The whole thesis falls apart though. You can't be on your way to "power over everything" and get distilled into free Chinese models within months. Pick one.

The bottleneck is compute and data, not the model. That's why they could only gate it for a bit. The ITAR thing proves it: no nationality controls in place, so the only option was killing the whole thing. Not exactly what an all-powerful gatekeeper does.

botw44··on Websites have a new way to spy on visitors: analyzing their SSD activity
I was interested in this so i created a proof of concept: https://github.com/brammittendorff/opfs-ssd-timing
botw44··on Sway-displays: interactive output setup with profiles (+ zero-copy mirroring)
Got tired of manually reconfiguring my outputs every time I moved my laptop between home and work. Existing tools were either broken, abandoned, or way more complex than needed.

So I wrote two small tools:

sway-displays interactive CLI for configuring outputs:

- Setup wizard that walks you through position, rotation, scale

- Save/load profiles (docked, portable, whatever)

- Calculates positions from relative placement (left-of, above, etc.)

sway-mirror zero-copy screen mirroring:

- DMA-BUF GPU-to-GPU transfer, no CPU copy

- Multiple scaling modes (fit, fill, stretch, center)

- Moves workspaces to source output automatically

Both are small, dependency-light, and designed for the "I just want my screens to work" use case.

Happy to take feedback or PRs.

botw44··on Effortless Multilingual File Translation with Python-GPT-PO
The "python-gpt-po" project on GitHub is a modest yet highly functional tool I developed, designed to utilize OpenAI's GPT models for translating files into various languages. This Python-based application is a straightforward, no-frills solution that aims to make language translation more accessible and efficient. It's particularly suitable for individual users or small teams looking to overcome language barriers without the complexity or cost associated with more elaborate translation software. The integration with ChatGPT ensures competent and context-aware translations, offering a reliable way to communicate across different languages. If you have improvements or other questions let me know.
botw44··on Show HN: GPT-4-powered web searches for developers
When i'm searching for point to poligon. This is a mistake of course, there are no results. And when using the alternative search engines they correct me. So for me this solution is currently a no go.