HNHacker News
TopNewBestAskShowJobs

daemon13

224 karma · joined March 14, 2012

submissionscomments
daemon13··on Getting started with login verification
I wonder how to approach this if one has to manage multiple Twitter accounts... for example for several brands

Anyone any ideas?

daemon13··on GPGTools – OpenPGP Tools for Apple OS X
Which one?
daemon13··on 0 second visits according to Google Analytics
Error: TypeError: sock is undefined

Ubuntu, Firefox 20.0

daemon13··on This is what a DDoS attack looks like
Is this originating from specific country or all over?
daemon13··on This is what a DDoS attack looks like
With nginx you can easily rate-limit connections, requests and downloads (which you can throttle also). Can also do this by GeoIP - country, etc.

No need for extra steps - this module shall be compiled and part of nginx-full package from nginx official PPA, if OP is using Ubuntu.

daemon13··on Nginx-1.4.0 stable version has been released
any pointers how you implemented hearbeat with nginx?

thank you

daemon13··on Show HN: Dendrite, a golang log parser
>> How do you ship logs? UDP? TCP? TLS?

> Yes ;)

ok, missed it, checked again. UDP, TCP - yes. TLS - not yet?

I checked tutorial, nothing there. Since most [semi]serious projects have a least some servers, I suggest to add a separate example, smth like:

1. We have 5 servers. And we collect logs to server 6. 2. These are settings you need to use for 5 servers. 3. And these are settings you need to use for the collector [IP:Port:TCPwithTLS].

> Dendrite scrapes your existing logs

Does Dendrite tail? Can Dendrite consume/scrape some existing/old log files?

BTW, what was your actual max throughput? Did you use some internal queue in the design, like rsyslog is doing?

> Dendrite isn't trying to be Logstash. I'd like dendrite to be the agent you use with logstash, greylog, papertrail, or whatever.

I am confused here a bit. So Dendrite is like StatsD on steroids?

daemon13··on Things I set on new servers
Is there smth similar for Python?
daemon13··on Show HN: Dendrite, a golang log parser
This is an excellent start! Have some q:

Why did you use yaml for configs? Yaml is/can be kind of fragile (whitespace, etc). Do you consider something more practical - nginx config formats?

How to set-up log collector? For example I need to collect logs from several instances. Could not find in cookbook.

How do you separate logs for different hosts/applications?

How do you ship logs? UDP? TCP? TLS?

How is this compared vs Logstash?

Thank you!

daemon13··on The secrets of body language
Sorry to hear about your past troubles.

Usually it helps when you learn to consiously (on demand) get yourself into a more relaxed state/mood internally. I found that when I am in the relaxed state, this really smoothes some rough edges in how people perceive myself.

daemon13··on Sales search: Writing a query parser/AST using Pyparsing and ElasticSearch
Simple and excellent write-up. Part 2 please!)
daemon13··on 1Password GPU brute-force with 3M hash/s
In terms of security, any opinion on how KeePassX for Linux is compared vs 1Password?
daemon13··on "j" for switching directories - hacking "cd" with python
so autojump, z and fasd - which one is better and why?
daemon13··on AppGratis Is Nothing More Than A Black Hat Marketing Company
Since the app discovery process in the Apple's own App Store (or on an iDevice) is far away from acceptable user experience, it is not a big surprise that companies like AppGratis are trying to fill this niche.

Apple's ban does not help in improving users' [that's us] experience. A better response from Apple would be fixing core of the matter.

I recall that couple of years ago Apple purchased app search&discovery start-up for circa $50M. Looks like reverse integration took place... unfortunately.

I discovered more high quality apps on HN than in App Store.

daemon13··on Introducing Lanyrd Pro, for companies that speak at and sponsor events
Some commenters are referring to specific prices ("Silver and Gold plans are definitely not cheap at $799/month / $1599/month ") - well, unless I am missing smth, right now the pricing page does not have ANY numbers.

Bug?

daemon13··on A quick message queue benchmark: ActiveMQ, RabbitMQ, HornetQ, QPID, Apollo
Any advice on dealing with de-duping?

Also, how was performance using JSON data format compared with ProtoBuffers & MsgPack?

daemon13··on A quick message queue benchmark: ActiveMQ, RabbitMQ, HornetQ, QPID, Apollo
Any gotchas moving from RabbitMQ to nsq?

Also, are you missing any features in nsq?

daemon13··on AppGratis pulled from the App Store. Here’s the full story
Re >> Of course App Gratis use iTunes affiliation to get revenues, but they didn't charge us for anything.

Can you please elaborate on this? Do you mean that Apply is paying some kind of affiliate fee? And what happens if the app is free of charge (FOC)?

daemon13··on AppGratis pulled from the App Store. Here’s the full story
Can you please elaborate on this? Do you mean that Apply is paying some kind of affiliate fee? And what happens if the app is free of charge (FOC)?

Edit: sorry, mixed the thread

daemon13··on Everpix
Also I think that you should not offer unlimited. What if someone will dump his favourite 100 PB of photos? If I would be using your service, I would not want you to go down due to abuses of your service's normal usage, i.e. normal users would be fine with such limit.

Just put it in.

daemon13··on Everpix
Nice design. Really like it and the interface. But before I commit to [any] new service, I would like to understand my future time commitment to [1] start with you and [2] stay with you.

I would suggest that you add a couple of Starting Up tutorials - smth like:

Tutorial 1/2/3

"I have my collection of photos on Ubuntu/Windows/MacBook"

Level Beginner

Time estimate 5-10-15 min

Goal: in 5 min your collection is backed-up and synced with your mobile device.

ToDo....................

If starting up with you is easy, then make it easy for people to discover this in the form they already got used to (most good libraries and plugins announced here have Quick Start Up section).

daemon13··on NetBSD turns 20
> "rump kernels"

> compile and use large swathes

Can someone elaborate in plain speak?

daemon13··on Persona is distributed. Today.
FYI, latest stable Firefox says this:

You have asked Firefox to connect securely to cacert.org, but we can't confirm that your connection is secure. Normally, when you try to connect securely, sites will present trusted identification to prove that you are going to the right place. However, this site's identity can't be verified.

daemon13··on GoIRC - Event-based stateful IRC client framework for Go
Good it was helpful. Have a look at ipset. It is easy to use and very powerful. According to one of the sources China is appr. 5000 IP sub-nets only. one ipset can block up to 65000+. One of the sources for IP is MaxiMind - they shall have a free set of fresh IPs.
daemon13··on GoIRC - Event-based stateful IRC client framework for Go
There are several ways to deal with it.

Basic:

1. SSH - security related - modify sshd config - no password auth, only key based, no root login, other than that the default sshd config for Ubuntu 12.04 is pretty ok.

PermitRootLogin no

If you do not use IPv6, you can disable sshd to use it.

#ListenAddress ::

ListenAddress 0.0.0.0

2. SSH - ease of maintenance related - change default port from 22 to smth else. This will not help against targeted attacks, but this will reduce the noise in the logs and will allow better visibility of attack attempts.

#Port 22

Port 63777 (or whatever)

Don't forget to reload ssh for changes to take effect and check with netstat what's running where.

If you are concerned with getting locked out you can do this:

2.1. enable sshd to listen on multiple ports simultaneously

Port 22

Port 63777 (or whatever)

2.2. Login through Port 63777, and only then disable Port 22.

3. The PRC thing - fail2ban and hosts is simple but not the best tools for the job.

3.1. You can disable access to your site for all China (or any other country for this matter) using ipset. Much better speed and ease of maintenance, it's even better then using iptables itself [ipset is iptables module], one set can contain/block up to 65000+ IPs.

3.2. If you want smth more targeted, then consider either sshguard or psad. They can be configured to block inline and dynamically add rules [perm/temp] to iptables.

Edit: forgot to mention another cute recipe. see below

If you are on AWS and are using security groups (you should), after you are done on the server, you can go to the security group in AWS Mgt Console and remove ingress for ssh ports. Now your server is accessible only on 80/443 and ssh is NOT accessible to anyone. Later, when you need to access the server - enable ingress for the ssh ports, do your job and disable again.

daemon13··on HipChat is now free for teams of 5 users or fewer
Unfortunately, I missed the IRC era.

Can someone recommend good tutorials on:-

1. Using IRC [beginner] & [advanced]?

2. How to set-up own IRC server and which are the good ones?

daemon13··on Benefits matter, or why I won't work for your Y Combinator startup
Same question on Trinet - since they also have no prices on their website - based on your experience, how do they charge (per employee, per transaction, etc) and how much does it cost, roughly? 100$/empl/mth, 1'000$/empl/mth?
daemon13··on Benefits matter, or why I won't work for your Y Combinator startup
Their website does not have any prices listed.

Based on your experience, how do they charge (per employee, per transaction, etc) and how much does it cost, roughly?

daemon13··on An apology to open source
many thanks...

the fork docs point to the original site, which was taken down :-(

Edit: docs are in index.html, but w/o css

daemon13··on An apology to open source
many thanks...

docs no? :-(

← PreviousPage 3 of 9Next →