HNHacker News
TopNewBestAskShowJobs

d_k_f

142 karma · joined May 29, 2014

[ my public key: https://keybase.io/dkoch; my proof: https://keybase.io/dkoch/sigs/xAVjr5VrYr9KMvVVrYXvmOcfcekyKqSgBP7iAFa13uY ]
submissionscomments
d_k_f··on Fly.io Postgres cluster down for 3 days, no word from them about it
Yes and (unfortunately) no. Terraform providers are here [1] with the official documentation at [2]. Managed databases are not available, though. I think they have some sort of database offering if you select their web hosting options, but you can't just get a managed Postgres instance yourself.

[1] https://registry.terraform.io/providers/hetznercloud/hcloud/... [2] https://community.hetzner.com/tutorials/howto-hcloud-terrafo...

EDIT: For what it's worth, I have had good experiences with app servers hosted on Hetzner Cloud and managed Postgres provided by ElephantSQL (https://www.elephantsql.com/) for Germany-based apps.

d_k_f··on I Got Banned for Life from Airbnb (2018)
You can add the names and emails of the friends you're traveling with, both so they can receive a copy of the itinerary and so the host can see it. It's not required, though, and in my history with Airbnb the host never cared.
d_k_f··on Visual Studio Code is designed to fracture
Interesting (and sad), thanks for the correction.

I was using "Kiwi Browser" on mobile to ensure I had the right address, which is a Chrome fork that allows extensions (I think they're forking Chrome instead of "just" Chromium since it looks and feels like regular Chrome otherwise). In here, I still have it available. Might be high time to check for something similar on the desktop.

d_k_f··on Visual Studio Code is designed to fracture
Additionally, you can remove stored HSTS states using Chrome's chrome://net-internals configuration page.
d_k_f··on Inflation rose 9.1% in June, even more than expected
If you believe that the stock market is going to go downhill as well, investing in a stock is only worthwhile if it loses less than it pays in dividends.

I guess that a lot of people are on the fence about whether they should short stocks since "everything is going down" or just sit on their cash reserves, eat the inflation and hope to buy in again once the bottom has been reached.

d_k_f··on Dropbox Backup
Just to add to this: there are usually two or three offers per year (black friday, Christmas and the like, just check Amazon) where your can get a year for the family plan (6 licenses, as mentioned, each one good for 5 devices or so) for around 40€ all in. They stack, so you can buy several just to be prepared.
d_k_f··on Windows Subsystem for Linux GUI
Whenever you want to natively operate on files within WSL instead of going through the network share abstraction, this is definitely helpful. I'm running my git GUI (Sublime Merge) on the Linux side and am currently piping the UI through to Windows using VcxServe. If I can remove another dependency using this - great.
d_k_f··on macOS in Svelte
Without having opened the page: visibility can be animated using CSS transitions, so you can fade in/out the menus. Display doesn't work that way, so that's probably the reason.
d_k_f··on Postgres sequences can skip 32 unexpectedly
They are sequential for all intents and purposes, they are simply using two separate series within the same number – you are perfectly able to determine the order of the invoices.

I do agree that (as is so often the case) the directive is not specific enough to determine whether the Italian interpretation is correct or not, though I can provide some context from the German side as provided by the ministry of finance: "Eine lückenlose Abfolge der ausgestellten Rechnungsnummern ist nicht zwingend"[1] (~ "it is not required for the invoice numbers to be gapless"), which directly contradicts the Italians as far as I understand it.

[1] https://www.bundesfinanzministerium.de/Content/DE/Downloads/... - p. 522, 14.5 (10) 4

d_k_f··on Postgres sequences can skip 32 unexpectedly
Nothing stops you from using the "...or more series" part to generate numbers that are specific to the day, the hour or, if you feel like it, the minute.

Today's first invoice could be 2021-07-16-001, the second one 2021-07-16-002, etc.

If you really don't want people to be able to guess your invoice volume from numbers alone, there are various ways to do that while still being compliant to EU laws.

d_k_f··on Why Johnny Won't Upgrade
You could use containers to "emulate" private mode for these windows by completely isolating them from your regular browsing data. They should survive a restart and keep you logged in afterwards. As long as you only use the container to access one site, no data should be leaked to other sites.
d_k_f··on Migrating a 40TB SQL Server Database
I'm late to the party, but he mentioned this in the article. The new server didn't have enough space to hold both the backup and the newly restored database, so that approach didn't work.

Quote: "We’re a very lean shop when it comes to hardware, and this is by far our largest chunk of data we have to store, so there wasn’t a place anywhere on the network to store a 33-38TB full backup temporarily, while it was being restored to a server."

As others have mentioned in the thread, a lot of the problems seem to have been solvable by just buying/attaching more storage, even if only temporarily.

d_k_f··on HPE ProLiant MicroServer Gen10 Plus vs. Gen10 Hardware Overview
At least up until Gen8 you could use any drive; the bays came in standard dimensions and took my Western Digital drives without a problem. I don't see why that should have changed in the meantime.
d_k_f··on React Concurrent Mode
No, it does not. Turbolinks keeps a local cache of previously visited pages so transitions to those seem instantaneous, but this is session-only and can't be populated in advance.
d_k_f··on Parallelism in Crystal
True, unfortunately. You can't pass functions around as first class objects, you'll have to use lambdas or procs for that (although even then composition doesn't work like that in Ruby).

(No judgement from me on whether that's better/worse/about equal, just confirming.)

d_k_f··on Cloud Run Button: Click-to-deploy your Git repos to GCP
Heroku's buildpacks make some default assumptions regarding an app's startup. For a Ruby on Rails app, for example, it would simply start the web server using `bundle exec rails s` unless you define something else in the Procfile. I'd assume there is a similar procedure for PHP apps, probably starting an nginx instance and pointing it at the app's index.php or something like that.

The way I understood it, app.json is there to customize the environment for the application to run in – providing ENV variables, required addons (think databases, memcache, etc.) and pre/post deploy scripts. A sort of configuration-as-code if you will. It is explicitely not used to define the actual processes that should be started when the app is deployed, that's what the Procfile is for, as long as you're running in an environment that supports Procfiles.

I'm not really sure what to tell you regarding vendor lock-in. Apart from the app.json the repo itself looks completely vendor-unaware, as it is simply a PHP application. It doesn't seem to make many assumptions regarding your (local) infrastructure but rather assumes you know how to get a PHP application to run on your server/computer. The presence of the app.json file is just an affordance to those who would want to try out the app without having to configure anything themselves.

On the contrary, now that I think of it. I always found Heroku to be rather non-locking, as you can just take your code and run it somewhere else. You need to provide some additional tooling around your deployments yourself in those cases, but that's true for all PaaS providers, isn't it? Heroku Addons are nice features, but usually simply services provided by third parties that are made available using automatically generated ENV variables, which you could simply copy over to wherever else your app is running.

d_k_f··on Cloud Run Button: Click-to-deploy your Git repos to GCP
I'm not sure how much you know about Heroku, but their runtime environment is based around so-called buildpacks, which provide the required executables, packages, configuration, etc. for various languages (ruby, php, js, ...). Once you push code to Heroku's git remote it will analyze your code and select the proper buildpack to run the code on.

So you are absolutely right that you can't simply go from an app.json file to a local development system in one step, as you (very likely) don't have the required infrastructure on your system.

d_k_f··on Write HTML Like It's 1999
Limitations imposed upon embedded scripts from foreign domains by technologies like CORS and the like, combined with modern styling abilities.

You can place another service's elements on a page that look like they're actually part of the page layout while the JS running them can freely communicate with the service's backend without having to bother with cross domain problems.

Think of all the support/chat widgets you see on modern-day pages, they're all iframes.

And obviously: tracking all the things!

d_k_f··on Crossfit Inc. suspends use of Facebook and associated properties
I think the main problem with the Crossfit-kipping-approach you often see on YouTube is that it doesn't look like the person being filmed is at all interested in ever transitioning to a proper muscle up, but rather to kip as much as possible to get as many reps as possible in 60 second or w/e.

You're absolutely right in that you need to start somewhere, and a properly instructed kip can definitely help there. But you could also start by doing negatives of the partial exercises (start pulled/pushed up and lower yourself down in a controlled manner), which can be at the same time used to teach proper form and naturally transition into a full muscle up.

Once again, it's the classic Crossfit problem: if you do it properly and controlled, it is a nice exercise regimen. According to most anecdotal evidence, a lot of people don't, though.

Edit: retiredcoder also replied with bands etc. to support in the beginning, which is obviously also a good method and, now that I think of it, one I've often seen in my gym. In the same vein, there's usually a pull up machine somewhere in the back that will support you by using a counterweight on the way up, though here you'll have the usual discussion regarding machine/no machine.

d_k_f··on Building a home NAS on a shoestring budget with the Rock64 SBC (2018)
A second vote for HP's Gen8 MicroServer!

I couldn't get the low voltage Xeons for a sane price in Germany, so I settled for a second-hand i3, which turned out to be more than enough for what I'm throwing at it.

I'm running ESXi as a hypervisor managing two Ubuntu VMs at the moment: a router and a fileserver managing two volume groups (6 TB dump storage for movies, music, etc. that's not too important and thus unmirrored, 2x2TB mirrored storage for photos and other important data that should not get lost). Thanks to the two network ports I can completely isolate the fileserver from the open internet as only the router VM has access to hat port. If I want to access my stuff from outside, I can VPN into the router and thus have access to the fileserver.

The next points on the list is Plex or something similar so I don't have to manually re-encode movies when my TV doesn't like the audio codec. Here, the i3 might struggle a bit, but we'll see.

As for the cost: I spent 200€ on the server itself, 88€ on 16GB RAM, ~20€ for the SSD case and power adapter cable and ~65€ on the SSD. The i3 was ~25€, so I'm up to roughly 400€ for the entire server (plus storage costs, but you'll have those anyways). Compared to what you'll get for that price it's an absolute steal, especially when you compare it with several "low budget"/homemade NAS builds floating around the net/youtube.

Bonus points: you can stack them on top of each other.

d_k_f··on Firefox Send: Free encrypted file transfer service
While Windows does allow for code signing of executable files in general, I doubt Signal is using their system. The official windows store would probably work similarly to how Apple and Google handle updates, but Signal doesn't use it either.

You can always implement signing yourself, though, without relying on somebody else's infrastructure. Just include the public key in the app itself and use it to verify your updates are properly signed by your private key before accepting them. I haven't checked but assume/hope Signal is doing this with their updated JS packages.

If none of this were to happen, however, then the answer to your last question is "yes", though with a caveat: If Signal's servers are compromised and push out a malicious update, then all bets are off, as the app running on your system has access to all your unencrypted messages. If the compromised server is only one of the messaging/relay servers, however, things are not as bad, as they don't have access to your keys and thus can't decrypt your messages. They can still forward them somewhere else for later decryption, but thanks to perfect forward secrecy this is currently rather unrewarding.

d_k_f··on Firefox Send: Free encrypted file transfer service
Yes and no, depending on your threat scenario.

I would assume Signal to have a proper signing infrastructure in place, so that the keys used to sign new releases are not available to the server hosting/deploying the actual update files (or providing them to Google/Apple for that matter). So simply taking over that server would not be enough, as malicious updates could not be installed.

Assuming Moxie goes over to the dark side, however, you are screwed. There's nothing stopping your Signal app from bundling all your plaintext messages once you've entered your password and sending them off to China, save maybe a firewall you have in place. Google or Apple might stop such an update during their reviews, but I wouldn't bet on it.

d_k_f··on An error message, still found in Windows 10, is a mistake from 1974
Judging by how the article was written, that probably wouldn't have helped him. You couldn't delete these directories directly, but rather had to delete the nested "unnamed" directory: “/path/to/COM1/ /“, which is also how you would create the directories in the first place. Usually, the tag-directory would also go along with a list of directories explaining that you should not create "undeletable" directories on NT-based servers, as that would annoy the admin and might cause them to remove anonymous access. You were only supposed to create large mazes of directories to prevent other random anonymous users from finding and deleting your files.
d_k_f··on An Amateur Rap Crew Stole Surveillance Tech that Tracks Almost Every American
Preface edit: I'm from Germany.

Usually in the same way it's done everywhere else: name, date of birth, registered/current address, sometimes an additional pin/security question/etc, depending on who you're calling.

If it's official business you might be required to send an actual letter, though I doubt they ever check your signature unless you're suing them.

If it's online and state business (portal for unemployment stuff, state employee pension details, etc.), you usually have to provide your name and address first, which they then check against your registered address. They'll then send you a letter with a one-time password you can use to register your account.

Edit: Modern E-Business companies often require you to "verify" your identify by ways of Postident (you present your ID to a post office) or IDnow (you present your ID to a random guy via webcam who asks you to move it around so he can see all holograms, data, etc.) and can compare it to your picture in the webcam.

This is considered to be enough for financial transactions according to our current money laundering laws, so it's about the most though version you can go through.

d_k_f··on The death of a TLD
Honestly though: why bother? If you're really set on opening a second account, email validations won't stop you. If I as a service provider want to stop you, I'd check your address, credit card number, vat Id, etc.

If you're unsure whether you've already registered an account, I could understand the frustration of finding your "proper" dot configuration, but as a developer I'd figure that to be your problem.

d_k_f··on ClassicKit – A collection of UI components for iOS influenced by Windows 95
After running a quick monochrome filter over it on my smartphone, you're not wrong: https://i.imgur.com/9m2hbu4.png
d_k_f··on What Dockless Bikes and Scooters Are Exposing
No, but it would make it possible to actually check whether they do or not, which I guess is why parent is asking.
d_k_f··on AWS Media Services – Process, Store, and Monetize Cloud-Based Video
I can speak to 1.) a bit as I have done just that for a client of mine. By default, they're using Zencoder/Rackspace to encode/store their videos and usually get one-off videos from their customers. However, sometimes there are requests to encode 2.000+ videos at once which gets prohibitively expensive in their constellation.

So we basically started out with a very naive solution: A Docker image with ffmpeg and access to a shared Redis DB used for job coordination running on a somewhat beefy server from Hetzner (beefy compared to regular VPS offerings, something in the 40€ range with 16 or 32gb of RAM I think). This turned out to work surprisingly well so we built a small API around that mirroring parts of Zencoder's API. This way, we can switch between both services on a per-job-basis and only need to change the encoding service's endpoint URL.

The main thing that will get you (if you do input validations) are the video formats. I've tried to get an authoritative list of valid MIME types beforehand, but still people managed to somehow send us videos with weird encodings that I'd never heard of before. Other than that, the usual caveats regarding self-hosted services (availability, failover, backups, etc.) apply but have so far not been much of a problem to us (especially since we can just go back to Zencoder when something breaks and needs to be done fast).

Feel free to drop me a message (mail is in my profile) if you have any questions.

d_k_f··on USS McCain collision ultimately caused by UI confusion
https://app.hackerwebapp.com is rather nice, although read-only. Tapping a link if you want to comment is acceptable to me, though I'd love to have voting on there.
d_k_f··on Linux on Samsung Galaxy smartphones
I just googled this, do you mean https://softwarebakery.com/projects/drivedroid?

Sounds rather nice, especially considering I've been installing various systems over the last few days and flashing images to a thumb drive gets old really fast.

Thanks for mentioning this, it'll probably save me a few hours in the future!

← PreviousPage 2 of 3Next →