HNHacker News
TopNewBestAskShowJobs

brentcetinich

49 karma · joined December 2, 2020

<https://blog.cetinich.net>
submissionscomments
brentcetinich··on Ask HN: Blog with no marketing effort – what's the likely amount of traffic?
If all you do is push it onto google index and no other marketing, it will take 1 or 2 years to get to 10 people a day. My blog has been going for more than 10 years and gets about 10 people a day at least consistently. There are a few pages that rank very well on the search engine and drive 99% of the traffic. Its seems that they value being the first one to write about something ALOT as that is the only thing I can see special about those high traffic pages. pretty much everything else gets zero.

First one in terms of I wrote about a very common error on K8s but I just happened to be using a bleeding edge version so I was the first to write about that specific error.

First one to write about an AWS feature because I found it in API by chance and it became GA weeks later (I guess they were waiting for the initial roll out to complete before posting Geoff's blog).

brentcetinich··on 32“ E Ink screen that displays daily newspapers on your wall (2021)
I have taken a look at the protocol between the software and the display and it is straightforward to hack, but the docker image is lightweight and reliable enough that I don't see the need to.
brentcetinich··on 32“ E Ink screen that displays daily newspapers on your wall (2021)
I have the same thing, gitlab job scheduled every 12 hours refreshes it using the visionect docker image, I have google calendar at the bottom, and currency exchange over the top left, localized weather on the right, countdowns to holidays, F1 schedules ect... I decreased the heartbeat timer and battery lasts about 2 months. I can't find an asian or european news paper that gives a good high res front page like the NYT. Waking up to read the US centric world view of the NYT gets old and the headlines are not so entertaining anymore without trump. Let me know if you find a more global news source that has a good high res reliable front page dump without advertisements. There has only been one time where NYT had on the front page over ~2 years and that was some fake diamond company took out the entire front page.
brentcetinich··on Show HN: Hacker News user blogroll
The latest post seems to show the oldest post sometimes
brentcetinich··on Ask HN: Could you share your personal blog here?
https://blog.cetinich.net

Most popular posts is one an AWS X-ENI and the EMC VNX hacking and the Z16 Thinkpad review

- https://blog.cetinich.net/content/archive/2017-aws-xeni/ - https://blog.cetinich.net/content/2022/2022-lenovo-z13-z16-g... - https://blog.cetinich.net/content/archive/2015-emc-vnx-hacki...

But I like my real adventure where I got trapped in my car next to a leapoard, maybe everyone will find it boring but there is a terrible video I took with proof.

- https://blog.cetinich.net/content/archive/kruger-stuck-overn...

brentcetinich··on AWS to deprecate boto resource abstractions
The AWS Python SDK team is no longer planning to support the resources interface in boto3. Requests for new changes involving resource models will no longer be considered, and the resources interface won't be supported in the next major version of the AWS SDK for Python. The AWS SDK teams are striving to achieve more consistent functionality among SDKs, and implementing customized abstractions in individual SDKs is not a sustainable solution going forward. Future feature requests will need to be considered at the cross-SDK level.
brentcetinich··on Ask HN: Preferred Platform to Blog
Sphinx and ablog hosted on cloudfront/s3 using disqus for comments not that anyone comments anymore. They used to when I ran it on wordpress long ago. My setup is described here https://blog.cetinich.net/content/2020/2020-sphynx-ablog-blo...

It’s just rst so keeps it simple and updates are easy, I have a gitlab that will trigger a content refresh on push so updates are zero friction which gets all the ugly stuff out of the way of just writing.

brentcetinich··on Microsoft Is Forcing Me to Buy MacBooks
I bought a new Z13 which is a Ryzen, I still have this issue on Windows I called up support to complain that the machine is boiling hot every morning when I take it our of my brief case. They sent a tech to replace the motherboard. Still have the same issue, not sure if I should bother calling them back. Luckily I also purchased the battery warranty (expecting this issue as I had a HP and a Thinkpad which had the same issue and I suspected it was a Windows issue) as I am sure this is destroying its life.
brentcetinich··on Is OpenStack fighting a lost battle?
Does anyone remember eucalyptus ? what happened to them?
brentcetinich··on Self-host your blog on a Raspberry Pi
Self hosting is cool, but if you actually want people to find your content my experience is that search engines will penalise heavily your ranking for being hosted off a residential IP that’s is not close to them and likely has a history of being unreliable. Unreliability and slowness both from the network latency and page rendering time (Wordpress doesn’t render so fast on a pi - at least when I tried it) will put you all the way to the bottom. If you don’t care about that then this is just fine, depending on what I am hosting changes where I put it, but stuff I want to be findable I host in cloud front/s3 as static pages and costs about $1 a month.

These are my notes on setting that up http://blog.cetinich.net/content/2020/2020-sphynx-ablog-blog...

brentcetinich··on AWS RDS Vulnerability Leads to AWS Internal Service Credentials
I wish you enumerated the identity’s Iam permissions or at least did a describe-db-clusters it would give good insights into the internal security of the Aws service roles , I would have thought such a role would be restricted to only be used via internal network leg of the RDS not over the internet. Now we will never know and have to take their word for it. Imagine if that role was able to describe all instances in the region, or dump a backup to a public bucket of every rds . Now that would be a sensationalistic headline !
brentcetinich··on Ask HN: Company wants to isolate corporate network from the Internet
There are others like this. This is the one I can recall now . Basically the proxy mitm a Js agent which is pretty much vnc for your browser. You only get the view of the headless proxy sandbox rendering whatever page you requested . So if any escape happens it happens in an isolated disposable compute managed by the proxy

https://www.broadcom.com/products/cyber-security/network/web...

brentcetinich··on SingleFile: Save a complete web page into a single HTML file
I use HAR file extractor because normally I don’t want a single file I want a replica of the web servers file system structure including any dynamically loaded assets https://blog.cetinich.net/content/2022/download-website-and-...
brentcetinich··on Trying to get past the 500 nits limit of the MacBook Pro (and failing)
I think if you zoom in whilst showing a corner of the viewport it works because the hdr videos are still in play but if you zoom so the corners are not visible it will fade out
brentcetinich··on AWS Lambda now supports IPv6 endpoints for inbound connections
Its not the lambda run time that gets Ipv6, its the lambda API that is now dual stack. (the endpoint you hit when you want to invoke a lambda.)

When you do an invoke, if you use lambda.us-east-1.api.aws instead of the old ipv4 only lambda.us-east-2.amazonaws.com you will hit a v6 ula if you are on v6:

so if you want to talk to ipv6 unicast endpoint to invoke a lambda do so by specifying the new endpoint with --endpoint-url:

aws lambda invoke --function-name my-function out --log-type Tail --endpoint-url lambda.us-east-1.api.aws

> lambda.us-east-1.api.aws Server: one.one.one.one Address: 1.1.1.1

Non-authoritative answer: Name: lambda.us-east-1.api.aws Addresses: 2600:1f18:20cb:b301:7ced:3d08:1e2b:ed32 2600:1f18:20cb:b303:fa58:3743:b0dd:f703 2600:1f18:20cb:b302:d19a:21c7:11ee:8ad2 54.85.112.20 3.220.153.240 34.235.81.32

brentcetinich··on Deterministic IP Addressing for WSL2
Not mine, but it solves a problem that has been a pain for me for a long time I think it could be useful to others here since the WSL issue (https://github.com/microsoft/WSL/issues/4210) making static allocation difficult is popular. Surprisingly this repo does not have so much love thus posting in case it is helpful.
brentcetinich··on Summary of the AWS Service Event in the Northern Virginia (US-East-1) Region
It doesn’t matter about the dependency graph , but on the definition of unavailable for s3 in its sla
brentcetinich··on AWS us-east-1 outage
Don’t think there is an sla for the console , so you would not be claiming anything for the console at least
brentcetinich··on Nanos: A kernel designed to run only one application in virtualized environment
See also https://github.com/direktiv/vorteil

The above also wrote a Uni kernel but it seems they abandoned that as was too large a problem and just link and package now

brentcetinich··on New Zealand council ends contract with wizard after 23 years of service
Disagree
brentcetinich··on Localstack – Local AWS Emulator
aws cli v2 is such a sad story long live awscli1!
brentcetinich··on 20 kV Diode Teardown [video]
YT premium FTW
brentcetinich··on Ask HN: Where can I find a free fork of Docker?
https://github.com/moby/moby
brentcetinich··on The last S3 Security document that you will ever need
It is a 160 Page PDF on S3. If you are putting any confidential information in S3 you need to see the S3 service map in the PDF on page 3. All the different access points and places you can set an ACL... All the bolt on services that keep on piling on starts to show the age of the service.

https://github.com/trustoncloud/threatmodel-for-aws-s3/raw/m...

Here is a nice threat:

Etags includes the MD5 of the file but not consistently and can be used by developers to verify the integrity of a file. An attacker can affect an upload function to change the etag of a file, in order to disrupt a workflow downstream.

brentcetinich··on AWS Frankfurt incident
I have been in this situation , maintenance on cooling tower 1 engineer put it into bypass mode so he can work on it safely (in case bms decides to turn it on while he is on it.) When he left the site he forgot to take it out of bypass mode. every few days the BMS rotates the cooling towers switched off tower B and turned on tower A which was still in bypss mode… so air was blowing but the water was not circulating. the temperature graphs show the effected floors of data Center space heat up very quickly. there was a lot of permanently damaged equipment 24/7 human operators ignored many warning about ambient temperature and Low humidity assuming it was system error ( does it look hot on the cameras?? shrug ?? ) various equipment have different power down temperatures the halon did not trigger for us. some equipment did not for whatever reason shutdown when they hit the cutoff temps and cooked themselves. I suspect the Low humidity caused too much static and that’s where the damage was from..

I guess thats something hard to test for , let’s put this switch in an oven and run it to make sure it auto powers down at 80c :) every time we release a firmware.

was a problem from multiple vendors who issued bios / firmware patches. Cisco, dell, Emc, brocade.

brentcetinich··on Ask HN: Well-Crafted Manuals / Handbook?
Emc symmetrix dmx series
brentcetinich··on Do we really need a third Apache project for columnar data? (2017)
Just a note for people running this type of experiment to make sure that when using an ec2 t2 instance type, note it has burstable CPU credits by default which run out after some time where you basically get throttled (the credits accumulate back over time) (it can be configured into unlimited mode but you need to set it explicitly for t2 and it costs more)

https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/burstabl...