HNHacker News
TopNewBestAskShowJobs

cuillevel3

308 karma · joined April 6, 2013

submissionscomments
cuillevel3··on M1 Macs Review
Ah, let me tell you the story of the "IBM" compatible PC.

"What's an IBM?"

cuillevel3··on M1 Macs Review
I wondered about that, doesn't it get hot and throttle performance?
cuillevel3··on Mozilla DNS over HTTPS (DoH) and Trusted Recursive Resolver (TRR) Comment Period
You could be using a VPN. I always found DNS with VPN messy, how not to leak queries, how to resolve internal records, how to react to the VPN servers dhcp info.
cuillevel3··on OpenSUSE MicroOS
So it's for Kubernetes nodes, VMs and bare metal?
cuillevel3··on Technical debt as a lack of understanding
It's a ponzi (pyramid) scheme.

I think there are ways for the company to escape that scheme, maybe by investing into other fields, outsourcing, buying growth and such.

I still find it risky, especially if you join late.

cuillevel3··on Packaging Kubernetes for Debian
Build time dependencies. Normally distributions would put every library from the dependency tree in a package and build it. Then install all the dependencies on the build host and produce the Kubernetes package.
cuillevel3··on Comparison of Kubernetes Ingress Controllers
Traefik supports letsencrypt and DNS updates (via lego I think).
cuillevel3··on Putin says Russia and U.S. should agree not to meddle in each other's elections
I have to disagree here. Not poisoning political opponents is a major democratic achievement.
cuillevel3··on Putin says Russia and U.S. should agree not to meddle in each other's elections
https://en.wikipedia.org/wiki/1996_Russian_presidential_elec...

That doesn't sound too bad?

cuillevel3··on Letsencrypt, the Good, the Bad and the Ugly
The first plane started in 1903, they have a bit more experience. Also they are crazy expensive and dangerous. Your mail server is not.
cuillevel3··on Letsencrypt, the Good, the Bad and the Ugly
Interesting perspective. For me it was clear from the beginning that I'm trading convenience for free certs.

Criticism of the "official" client was also very loud from the start.

I do agree that LetsEncrypt has been a constant source of maintenance problems over the years. For example now, I have to switch to another alternative acme client, since the old one doesn't seem to be in active development anymore...

However, certificates used to be expensive, even unaffordable for some projects.

cuillevel3··on Libvirt – The Unsung Hero of Cloud Computing (2013)
XML can be used to represent data formats, but is missing things like types.

It's powerful enough to represent documents, which might be too much for data structures:

  <a>This is <b>valid</b> XML</a>
And let's not forget how hard it is to escape data in XML, so every value ends up as CDATA in the end.

  <config>
    <somekey type="string"><![CDATA[4byte emojii]]></somekey>
  </config>
cuillevel3··on An Argument for Race Abolitionism (2020)
As a German I always feel offended, when American sign-up forms (conferences and such) ask for my 'race'. Are they asking for my migrant background? Asking for race is just so Nazi, what should I put there, "Herrenrasse", "Fremdrasse", ...?

There are no different human races.

cuillevel3··on New German law would force ISPs to allow secret service to install trojans
There are a lot of insecure updaters. I remember reading the list from evilgrade a few years back. It was shocking.
cuillevel3··on Why Climate Change Won't Be Stopped (2018)
I'd go further and say it's actual harmful advise. If you don't drive a car, you just made space for another car and you just started paying for someone elses parking.

Appealing to virtuousness and living by example, is not going to replace regulation and realigned incentives.

cuillevel3··on Hacking Together an E-ink Dashboard
I'm still postponing coding my own dashboard. Until then I run PaperTTY in VNC mode to display HTML in chromium...

Refresh is horrible on the 7.5in waveshare anyhow.

cuillevel3··on Convert Markdown to a Mind Map
This looks beautiful, but I guess it's only useful for acyclic maps? References would be great.

Just learned, that I'm looking for a 'cognitive map'.

cuillevel3··on LastPass stores passwords so securely, not even its users can access them
I think I did this once with one password service and was surprised that they don't even send a warning email to inform me, that that just happened... very scary.
cuillevel3··on LastPass stores passwords so securely, not even its users can access them
In theory they can do more security, than you get when you just store a keepass file on a server. Things like temporarily blocking access when GeoIP information for the client changes, or a lot of secrets are accessed in bulk. The keepass file, you only lose once and the attacker has years (or up to your next rotation) to crack it.
cuillevel3··on Software is a focus intensive industry
Maintaining focus is actually labor. Adding more devs might not help with a late project, but it does help with building bigger systems. So, I disagree, software is extremely labor intensive work.
cuillevel3··on Germany looks to step up coal exit timetable
Germany did have a thorium based reactor, it had multiple incidents and was never profitable.

It was only online for two years and was eventually torn down. Well, the cooling tower was, they still have to wait for the reactor to lose it's radioactivity.

Check out https://en.wikipedia.org/wiki/THTR-300

cuillevel3··on Germany looks to step up coal exit timetable
The amount of money spent on nuclear reactor research is insane. It's very expensive, it takes very long, it requires so much security. The whole private nuclear sector was heavily subsidized.

And nobody wants a reactor or storage facility in their backyard. Keep in mind Germany has a higher population density than France. And even France has problems to find locations for their new plants.

In the end after Fukushima, there just wasn't enough support left in the population.

cuillevel3··on San Francisco has nearly five empty homes per homeless resident
also some of them might not want to be registered? having a home might not be enough to be able to deal with bureaucracy and such
cuillevel3··on The sad state of sysadmin in the age of containers (2015)
It also no different from using 'make install' or installing packages from a community repository, like Ubuntu Universe, homebrew, Arch AUR and so on.

There is an absurd amount of trust put in distributions and their package managers. Unless people are paying for it, or use very old software, they probably don't get the level of security they expect.

cuillevel3··on The sad state of sysadmin in the age of containers (2015)
After a few decades it's no longer a baby ;)

Software is becoming more complex and moving faster than ever. 'Controlling your dependencies' was always an illusion and a trade-off at best. Often a trade-off against security, inheriting the folder of JAR files from your predecessor and such.

I think of containers and all these new tools as designs which are supposed to help us manage existing complexity. They don't create it, it's already there in the requirements and real-world deployments. The friction we feel, is that some of those tools are not very good (yet), but maybe better than the previous generation (sometimes). On the negative side, there is a lot of nostalgia ("ah, do you remember bare metal...") and unwillingness to change and learn.

cuillevel3··on The sad state of sysadmin in the age of containers (2015)
> I’m not complaining about old-school sysadmins. They know how to keep systems running, manage update and upgrade paths.

Sadly these ways of olde didn't scale. They could only do it for a handful of servers, change request took months and the systems were not to be 'touched'.

> And since nobody is still able to compile things from scratch, everybody just downloads precompiled binaries from random websites. Often without any authentication or signature.

Right, that would have never happened back then, when packages were not signed and freshmeat.net was still a thing. For some reason compiling C code from some website (`wget;./configure;make;make install`) seems to be more secure than `go install`, maybe because nobody understands automake anymore.

cuillevel3··on DNS Security: Threat Modeling DNSSEC, DoT, and DoH
This comes to mind: https://sockpuppet.org/blog/2015/01/15/against-dnssec/
cuillevel3··on Software Architecture Is Overrated, Clear and Simple Design Is Underrated
I remember reading somewhere, that it's wise to avoid naming your classes after design patterns. It only leads to discussions about technicalities.

Makes sense to apply this to bigger designs, discussing the concepts is more important than following the book by the letter.

cuillevel3··on Apple downloads ~45 TB of models per day from our S3 bucket
Are those full downloads or just HEAD or range requests from some CI?
cuillevel3··on Webmin 1.890 Exploit – What Happened?
webmin has been around for centuries and was dropped from Debian in 2005.

It has a long history of vulnerabilities (https://www.cvedetails.com/vulnerability-list/vendor_id-358/...).

← PreviousPage 3 of 6Next →