HNHacker News
TopNewBestAskShowJobs

cmhamill

291 karma · joined July 12, 2011

Don't pay him any attention.

[ my public key: https://keybase.io/cmhamill; my proof: https://keybase.io/cmhamill/sigs/8AtPp6ruUgJKx3TRdlKj1oGs6mLtvZYxvpohrRhPEMw ]

submissionscomments
cmhamill··on The Macintosh in 1984
You're probably correct, though subjectively I didn't start feeling like something was amiss until Mac OS 9, perhaps as early as 8.5.

I think OS X, as the child of NeXTSTEP and Mac OS, ended up somehow less than the sum of its parts.

cmhamill··on iPhone 7. Apple Just Showed Us the Future
I honestly can't tell if this is profound satire or contentless nonsense. Without knowing, it's impossible to discuss this.
cmhamill··on DNS: Basic Concepts (2013)
I actually think the DNS binary protocol is a rather well-designed one, but others might disagree.
cmhamill··on DNS: Basic Concepts (2013)
I'm partial to including the `www` prefix, but most of the reasons are aesthetic and not technical.

The summaries for each side:

http://www.yes-www.org

http://no-www.org

cmhamill··on Docker for Mac Beta Review
This would help immensely with converting our development process to use Docker. My hub ID is cmhamill.
cmhamill··on Systemd mounted efivarfs read-write, allowing motherboard bricking via 'rm'
The issue here is actually bricking the device. It's not your standard "do we let people hang themselves or limit the user's capabilities" debate.

A filesystem is a perfectly reasonable way to implement access to the EFI vars.

cmhamill··on Stealing keys from PCs using a radio: cheap electromagnetic attacks
I assume folks using a smartcard for their everyday encryption are safe from these kinds of attack?

Can anyone confirm that?

cmhamill··on Operational PGP
If you're expecting trouble from state actors, then yes, you may want to consider other options.
cmhamill··on Operational PGP
kernelconcepts.de sells them and ships to the U.S.
cmhamill··on Ask HN: Who wants to be hired? (March 2015)
Location: Connecticut, intent to relocate to Los Angeles in the near-ish future

Remote: yes (or LA)

Willing to relocate: yes if to LA, no otherwise Technologies: Unix administration, Salt Stack, Ansible, Apache, Nginx, Python, Perl, Ruby, Go, SQL, C, etc. I'm a sysadmin, so my job, in principle, is to know everything, and I take that seriously. If I don't know it now, I'll learn it. That's what I'm for.

Résumé/CV: http://resume.cmhamill.org/ (PDF: http://resume.cmhamill.org/resume.pdf)

Email: me@cmhamill.org

I can be your jack-of-all-trades.

cmhamill··on Linux Containers: Parallels, LXC, OpenVZ, Docker and More
So, the question that jumps to mind reading this is:

At what point do we acknowledge that we're re-inventing Plan 9 poorly?

I don't mean to be glib (well, maybe a little), but all of this (with some exceptions — zones and jails, mainly) feels incredibly hacked-together.

Perhaps someone paying more attention could tell me if, say, the folks working on the Linux kernel are learning the lessons from Plan 9? kernfs seems promising, at a glance, but I haven't really looked into it.

cmhamill··on The New Racism: This is How the Civil Rights Movement Ends
For some definition of "his basic thesis" meaning "radical misrepresentation of his basic thesis," sure.

Whether you like the ideology behind the forces at work in the American South or not, the real effect of these policies is to make the lives of the poorest and most marginalized people in these states worse. In the American South, it just so happens that this means black folks.

I don't know what you'd want out of an article on this issue, but I sure hope it wouldn't be a false rendering of the realities of the situation in the hopes of pandering to some sense of feel-good political ecumenicalism.

cmhamill··on The getrandom(2) system call was requested by the LibreSSL Portable developers
Does anyone have any idea why Linux has a distinction between /dev/random and /dev/urandom?

Legacy adherence to some defunct interface? Ignorance on the part of kernel devs (seems unlikely)?

cmhamill··on My Opinionated Guide To Go
Not entirely on-topic, but the mention of the various language "stacks" at the beginning of the article reminded me of something I've been wondering.

Why does the de facto standard for web apps in Go-land seem to be using the built-in HTTP server provided by net/http, or otherwise having the program server as its own HTTP server?

Most other languages seem to have converged on FastCGI or some similar model ({W,P}SGI, Rack, etc.).

It irks me a bit because I don't understand why you'd want to do it this way; it seems preferable to have a dedicated HTTP server in pretty much every way I can think of.

Does anyone have any insight there?

cmhamill··on Wikipedia redesign
To put it more bluntly: I think it's reasonable to argue that Wikipedia is the single most important product of the Internet to date.
cmhamill··on GitLab – Open Source Git Management Software
Would you folks ever consider releasing a non-omnibus package? I'm averse to packages which include their own dependencies, but have developers who would benefit greatly from GitLab otherwise.
cmhamill··on Wesleyan bucks trend, lets students graduate in 3 years
Wesleyan has no hard-and-fast gen ed requirements, which makes this easier to pull off for students.

Some majors do require them for Honors, though.

cmhamill··on Mozilla employees tell Brendan Eich he needs to “step down”
I asserted nothing of the sort.
cmhamill··on Mozilla employees tell Brendan Eich he needs to “step down”
Some very strange reactions in this thread. The idea that this somehow validates the notion that Eich's politics don't affect Mozilla as a workplace seems particularly bizarre, to me.

My read on this is that there are employees at Mozilla who feel strongly enough about this to speak publicly, and the most likely reason is because they believe that Eich as CEO will affect their workplace.

cmhamill··on Just what we need. Another package manager.
My knee-jerk inclination to this post is to yell, "oh holy hell, yes!"

That said, and as others in this thread have noted, there are actually two use cases that need to be satisfied.

1. Here, you've got a base system, and you want to install some piece of software in order to use it. You want this to be guaranteed, for some reasonable definition of "guaranteed," to work with your existing base system.

2. Here, you want to install packages within a segregated environment, and you want those packages to work with any packages previously installed in said environment. You're probably attempting to do something like recreating your deployment environment locally.

It strikes me that there are only two issues preventing the latter from being subsumed by the former.

1. Not all package management systems provide a means to have multiple versions of a package/runtime/what-have-you installed at the same time. Often, this capability is there , but packages need to be specially crafted (unique names, etc.) for it to work. See Debian's various Ruby and Python runtime packages for example.

2. Not all package managers provide a way to install a set of specific package versions in a contained environment which is segregated and requires intention to enter.

(Note that I'm ignoring the "there are different package formats" issue; I don't think is in practice a huge barrier, and the package maintainers should be involved anyway.)

If we could get RPM and YUM to provide those services, then we could remove the vast majority of this duplication.

Alternatively, if we all agreed that developers should just use Linux containers as development environments, then all we'd need is upstream to use native OS packages (which is, really folks, not very hard).

Can we do that pretty please??

cmhamill··on Saving 9 GB of RAM with Python's __slots__
Does anyone know if there's any similar ability in Perl 5?
cmhamill··on TogetherJS as a Postmodern Programming Tool
I can't really speak to the programming part of it (but it almost certainly has a lot to do with Perl), but this article has a pretty, um, interesting conception of what makes something postmodern.

The basic idea is that modernism is the idea that there exists a state that is somehow better, more advanced, more organized, for a given system, and the goal of human endeavor is to move towards that. Postmodernism is basically a skepticism towards that viewpoint, trying to pull the teleological aspects out of it, saying that there's no intrinsic metric by which a given system can be measured to determine its relative state of progress towards more advanced forms.

The idea the article is getting at is that there's an analogous approach to programming which says that there's no intrinsic measurement by which a program can be measured which will tell us its quality.

It's kind of flawed as an analogy really, for a variety of fairly subtle reasons. I should write a "Pomo for Programmers" and post it here some time.

cmhamill··on Primer on elliptic curve cryptography
Luckily, djb's opinions seem to usually be right!
cmhamill··on Security/Server Side TLS
The "OpenSSL Cookbook" book you get when you sign up for notifications about the book at this site[1] is very good. Written by the guy behind SSLLabs, if I recall correctly.

[1] https://www.feistyduck.com/books/bulletproof-ssl-tls-and-pki...

cmhamill··on Monitor your Website’s Uptime with Google Docs
Ahh, this is different. I'll admit to thinking it's strange, but not insane. Sorry for the quick judgment.
cmhamill··on Monitor your Website’s Uptime with Google Docs
Do you make API calls, or just grab web pages? I've noticed the Google APIs seem to occasionally return errors for no apparent reason. You could try double-trying in your Nagios check.

It's also complicated by Google's infrastructure — services are scattered across many, many servers, and Google's outages tend to be on some subset of services and/or servers. Your Nagios checks are probably not always checking the same endpoint as users connecting.

cmhamill··on Why Not Use Port Knocking? (2012)
Any resources on best practices for a bastion host?
cmhamill··on Monitor your Website’s Uptime with Google Docs
Yes, this is probably the real issue.
cmhamill··on Monitor your Website’s Uptime with Google Docs
"Bad" is probably a strong word. But issues are:

1. Reliance on Google Docs' uptime. While any monitoring service will in theory present the same problem, you're putting all your eggs in one basket.

2. It's just the wrong tool for the job. Install and learn Nagios or Zabbix or what-have-you. If you're worried about uptime, get a couple VPSes from different providers and run your monitors from both.

There's nothing utterly horrifying about it technically, but I just can't imagine how one comes up with this answer to the question of monitoring services.

cmhamill··on Monitor your Website’s Uptime with Google Docs
Wow.

To paraphrase Babbage, I cannot apprehend the confusion of ideas which could lead someone to think this is a good idea.

Page 1 of 3Next →