HNHacker News
TopNewBestAskShowJobs

buro9

24,701 karma · joined January 8, 2008

barely active on here now, VP Eng @ Grafana Labs
submissionscomments
buro9··on The Blue Yonder SaaS ransomware incident is bad
The replies are incredibly elucidating on the impact (things like payroll for Starbucks, and the fact that this is VMWare powered private cloud).

The full text of Kevin Beaumont toots:

The Blue Yonder SaaS ransomware incident is bad.

They got into their Private Cloud environment at hypervisor level, deleted the DR and backup storage, then encrypted all 5 datacenters.

On this - Blue Yonder, aside from doing supply chain management (how many Pot Noodles you should order per day per store etc), they also sell a HR suite called Blue Yonder Workforce Management, or WFM. It's another SaaS solution, does HR stuff, payroll etc. WFM was hosted in their private cloud and is toast.

One of the Blue Yonder things is they have absolutely nothing about the situation on their website - just a list of customers, many of whom are mentioned in the press as suffering. They’re on day four.

Learning: have a comms plan.

buro9··on I Didn't Need Kubernetes, and You Probably Don't Either
I still just use VPS devices and some colocated hardware.

I'm constantly told "I am not the typical customer, most do use K8s".

Side projects and volunteer things I run include 470 websites serving about 320K registered users and about 500K-1M monthly guest users... on about 15 VPS devices or small servers.

It's just classic dynamic websites, HTML is the output of a server (no single page web apps), lots of caching for guest users, reasonable complexity (load balancers ahead of web front ends ahead of API back ends ahead of databases).

Things that look like microservices exist... it's just API calls, and they come back through the front door, it's easy to reason about.

Monitoring is mostly Prometheus node exporter, it turns out that CPU + Memory + Disk IOPS + Network IOPS is +90% of what you need... some HTTP logs or profiles are the last 10%.

It's just simple... this is run in my spare time, effort is under an hour per month. (and no it's not monetised, not everything has to be)

buro9··on How I configure my Git identities
I use a unique account with every distinct git org / github org that I interact with.

Even if I'm in my work profile and I need to do something in an org called `acmecorp`, I will create @acmecorp-identifier to do that.

This is just a very long experience...

* Security policies for work things have a blast radius of just that employer

* OSS things have a lifetime beyond the life of an employment / contract

* Source control elsewhere (GitHub / GitLab / Bitbucket / Gitea / Forgejo / etc) all has a local blast radius, and if a provider / org forces changes (roll your keys!) then the impact is limited to just that provider

* When something changes ownership (i.e. an org), the impact to me is low

It seems much more sane.

I think of a single git identity across multiple orgs as a bit of a smell.

buro9··on Canvas Fingerprinting
Have you tried?
buro9··on Canvas Fingerprinting
The safest way to browse the web in any browser is by disabling JavaScript or using a NoScript extension.

A lot of the web works surprisingly well still, and you can turn on just what you need when you need it, placing your most visited sites on an allow list, but still denying a lot of third party things on those sites.

The internet is a joy with js disabled virtually everywhere. And all the canvas fingerprinting, webrtc leak, font fingerprinting, super cookies, etc... are all defeated by simply not running JavaScript

buro9··on NotebookLM launches feature to customize and guide audio overviews
AI tooling has now made it too easy to find things.

On a web forum I am admin on, a user opened a DM a week ago titled "Google Notebook LM", someone else had shared a generated podcast thing that summarised the view of the forum on a particular subject, and it called out the usernames of someone who had strong opinions.

In response, another user ran with this and asked for a podcast to be generated summarising everything that was said by the user, their political views and all their hot takes.

Erm... uh-oh.

The use of real identity, the use of the same username across multiple sites, now makes it trivial for things like "take this Github username, find what sites the same username exists on, make a narrative of everything they've ever said, find the best and worst of what they've ever said"... which is terrifying.

I've said to the user the same old line we always repeat, "anything placed on the internet is effectively public forever", but only now are the consequences of this really being seen.

The forums I run allow username changes, encourage anonymity as much as possible, but we're at a point where multiple online identities, one for every site, interest, employer, etc... is probably the best way to go.

I notice on HN that there are many accounts that seem to register just to comment on particular stories and nothing more, and the comments are constructive and well thought out, and now I wonder whether some are just ahead of the curve on this — obscuring the totality of their identity from future employers, or anyone else who might use their words against them.

It feels like our lightweight choices in the past will start to have significant consequences in the present or future, and it's only a failure of imagination that is delaying a change in user behaviour.

buro9··on Why does everyone run ancient Postgres versions?
Upgrading isn't automatic.

Let me check what I'm on... brb... Postgres 14.

Because it's not automatic I leave it, I leave it until it's so unsupported that I must upgrade the whole system, then I build a new system with a new Postgres and I migrate the old to the new.

I want, so badly, for Postgres to just automatically update itself, that a new binary just works with the data directory of an old version, and that if required it does an in-place upgrade to those data files when it can (i.e. if it can detect the last version was the same major as the current version, upgrade the files transparently to the admin).

My databases are all backed up each night, and these are single server Postgres with no replication or other trickery, an automatic upgrade for a single-server Postgres should be possible.

As it's not done... I assume (incorrectly?) that there be dragons and risks, and I mitigate that by never upgrading, just waiting and migrating. Migrating puts all of the risk on me, human error, and I am definitely fallible, so I can best handle this risk by just not doing it until I must.

Last migration I performed was from Postgres 7 > Postgres 14 in October 2021... I guess I have quite a few years of Postgres 14 ahead of me still. I would take downtime, my systems aren't zero downtime critical, just give me a super simple one-command no-questions upgrade as I really dislike migrations.

buro9··on FIDO Alliance publishes new spec to let users move passkeys across providers
The second one is particularly pertinent:

> Passkeys are essentially site-specific cryptographic keypairs, which are fine, combined with big tech company paternalism, which is intolerable.

buro9··on ByteDance’s Bytespider is scraping at much higher rates than other platforms
Also the Facebook hit scraper.

Which does not respect robots.txt and definitely is just scraping.

AS blocks are the only really effective tool now, there are many scrapers that do not even respect user agent

buro9··on What are the best options for Amazon SDEs thinking about leaving over RTO policy
You have, in some countries, the legal right "to request" work from home under laws typically aimed at flexible working. But that's it.

A company can, for any reasonable reason, decline the request.

buro9··on Ford patents in-car system that eavesdrops so it can play you ads
I'm not sure it's patentable given that smart TVs already do this, the prior art is obvious.
buro9··on Malaysia started mandating ISPs to redirect DNS queries to local servers
DoH helps us against governments, but doesn't help us against advertisers, i.e. what stops Google or an app maker talking to their own DNS endpoint via DoH and avoiding local measures to block malware and tracking.

DoH is a double edged thing, advertisers are a more present and pervasive threat to most than their own government

buro9··on Is My Blue Your Blue?
The monitor yes, the mobile lol no.
buro9··on Is My Blue Your Blue?
I have a colour calibrated monitor, and landed at hue 181 which is almost dead centre.

Fascinating... so I then tried on my mobile device and skewed to the left at 171.

Retried the monitor, dead centre again. Retried the mobile device, back to the left.

What device you use, the brightness, capabilities, calibration, environment... will all change the outcome.

buro9··on They don't make 'em like that any more: the 3.5mm headphone jack socket
Belkin, along with Anker, make pretty good things and I trust them... I don't know how to criticise a "charge whilst playing music" thing as it does both of the things it claims to do and I've not tried silly things like chaining this with other dongles.
buro9··on They don't make 'em like that any more: the 3.5mm headphone jack socket
I know it's not what he is looking for: https://www.belkin.com/uk/p/3.5mm-audio-usb-c-charge-adapter...

A USB-C adaptor for mobile phones to allow charging whilst listening on a 3.5mm headphone jack.

buro9··on Purism Domain Puri.sm Suspended?
Oh I bet the registrar didn't pay the annual fee and that .sm suspended the domain as a result.

Context, this would be the third time I've heard of this, I was the second time I heard of this happening to .sm domains and it was via Gandi screwing it up. The first was actually Purism.

https://puri.sm/posts/the-great-purism-dns-outage-of-2018/

https://www.lfgss.com/conversations/386644/

buro9··on Starting today, YouTube is almost unusable on Firefox
I found it freezes every 60 seconds, and I just click the "Share" button and "Starting at", and copied the time into the URL and reload the page... then it works.

After a few times I got into the habit of "increment seconds by 60, reload page".

I don't know why it has to be so hard, I seldom to never go to YouTube now because of how badly it works.

Feels super anti-competitive to own YouTube and Chrome, and to punish Firefox users so aggressively.

buro9··on Predicting the Future of Distributed Systems
it's the Kafka API, not Kafka itself, that I see as having become the standard.
buro9··on Predicting the Future of Distributed Systems
Things I have come to know about distributed systems:

The S3 API (object storage) is the accepted storage API, but you do not need AWS (but they are very good at this).

The Kafka API is the accepted stream/ buffer/ queue API, but you do not need Confluent.

SQL is the query language, but you do not need a relational database.

buro9··on Australian employees now have the right to ignore work emails, calls after hours
This is nearly always a myth.

On call has a huge precedent, it's not tech, it's the health sector.

"Paid" on call is already defined as the active portion where you're responding to a page, not the passive portion where you're carrying the pager.

Some countries have rules around time to respond within the definition of active vs passive, but most do not and the carrying the pager isn't compensated at all.

Even with the active part, time-in-lieu can be the definition of paid... still 40h per week (or whatever), but if you only responded to 1h of active on call in a week, finish work an hour earlier one day the next week.

People in tech like to imagine that their salary rises by some significant %, but it seldom does... nurses and A&E staff aren't paid far more for being on-call and carrying a pager, and that precedent travels far, countries aren't legislating in a way that makes their health services untenable.

Some countries do legislate hard in this area, i.e. France, but then... they have a much smaller tech sector as a lot of companies will avoid hiring there or setting up an office there (especially when neighbouring countries do not have such legislation).

To be clear I don't know what the exact text of the Australian law is, but I'm just clarifying that on call does not have to be paid, and as soon as one thinks about the health service and the impact of such legislation it's clear why. Sure one can also view this as wage theft in every industry, but in that case workers need to go make that case. Most large companies will likely continue to avoid such legislation by treating their workforce as fluid, and just withdrawing from some countries and only hiring in others.

Note: None of the above is reflective of where I currently work, but are things I've learned from prior places of employment.

buro9··on Anthropic Claude 3.5 can create icalendar files, so I did this
I'm finding Claude to hallucinate less than ChatGPT, and to be far more accurate at coding than CoPilot. Pleasantly surprised on both counts.

Example hallucinations from ChatGPT include researching the dates of historical events for the company I work at, trivially verifiable by me but I was being lazy... ChatGPT told me about blog posts that never existed and I could prove never existed, Claude was spot on with dates and source links (but only appeared to have data through to the end of last year).

On coding, CoPilot came up with reasonable suggestions but Claude was able to take a file as an input and match the style of the code within the repo.

Claude, for me, is starting to hint at what a highly productive assistant can achieve.

buro9··on Organic Maps Removed from Play Store Due to "Requirements for Family Program"
Ah, I wasn't online yesterday and submitted thinking it would de-dupe (I expected it to be here already).

But yesterday's was a Twitter link, and I used the Fedi link. Ah well :)

buro9··on Flaw has Microsoft Authenticator overwriting MFA accounts, locking users out
Yesterday I had a good example of this.

Website: "Please choose a complex password of at least 8 characters including special characters and numbers"

Me: Fires up the password manager, generates a 128 character random password, feels smug.

Website on next visit: "Please enter the characters in the 31, 98, 102 position from your password"

Me: WTAF

Context: Mortgage website in the UK

Edit: It's now dawned on me that they're storing this plain text so that they can do this... or at least encrypting rather than hashing, meaning that they can always decrypt the password.

buro9··on Shortwire: The smallest VPN that connects two computers via the Internet
The rest of the ideas seem valid, it's a shame to have the project undermined by the crypto.

Is there no website of canonical examples of good crypto that can be shown to the author, so that they may trivially have good crypto?

buro9··on Dazed and Confused: A Large-Scale Real-World User Study of ReCAPTCHAv (2023)
I abandon 1 in 10 captchas recently. They're becoming so abstract and confusing, few are on sites that I critically need to persevere with. Of the ones I do, I need to regenerate about a third as I'm slightly colour blind, but apparently enough to not see whatever they need me to see.

Mostly I won't sign up to a service that has a captcha unless I know in advance it's a service I need (unlikely), it's an immediate click away.

I'd rather have one time magic links and codes via text and email than a captcha.

Inconvenience that is robotic on my behalf (copy a code from here to there and treat this as part of "something you have") is much preferred over something that is demanding on my behalf (interpret this puzzle we're showing you, and pause the context you were in to now solve the puzzle).

The worst recent offenders are a grid of 9 abstract representations of something with the instruction to click the one that is correct (right way up), which is only as good as those generated images. Next up is the ones where you need to click images that are in certain "orbits" depending on what the object in orbit is. And of course the never-ending hell of solving Google Captchas where you must pick American English items and perform several leaps of "maybe the computer thinks this is a staircase or bridge?" when what you say and it thinks clearly disagreed.

Captchas are nothing but friction, they've become too hard for humans and too trivial for machines, and the result is that they are only friction to humans... the very humans you want to extract time, money and attention from.

buro9··on The New Internet
I love this.

Except to use tailscale you do need to bring in a while OIDC authentication provider.

It's all small and aimed at avoiding scale until the very first step, when suddenly only the big complex thing is acceptable.

I still just want to just use my email and a top. The only one of the auth providers tailscale supports that I have is GitHub, but I don't use GitHub as beyond work as I self host my git.

When the onboarding is "maintain and run a full oidc provider", all we've done is trade one aspect of complexity for another.

buro9··on Don’t try to sanitize input, escape output (2020)
I store the raw input in my database, but run it through bluemonday before rendering it. Simples.

https://github.com/microcosm-cc/bluemonday

buro9··on Jelly Star – The Smallest Android 13 Smartphone
This makes a great, capable, burner phone for traveling to high risk countries.

The low price, decent performance, small package is perfect for travel and you wouldn't have to worry if it was lost or stolen if you only load up minimal things in there and it doesn't have all your banking apps, etc.

buro9··on AT&T says criminals stole phone records of 'nearly all' customers in data breach
Including all location metadata associated to that?
← PreviousPage 2 of 34Next →