HNHacker News
TopNewBestAskShowJobs

dhess

470 karma · joined June 2, 2008

I'm the founder of Hackworth Ltd (https://www.hackworthltd.uk).

[ my public key: https://keybase.io/dhess; my proof: https://keybase.io/dhess/sigs/crk4X8HHgUjGwVBML-sHvIBrSzboEYoKiITc4kuYs0U ]

submissionscomments
dhess··on Notes from November 28 Meetup of Bay Area Tech Solidarity
whoosh.
dhess··on BeagleBone Black Wireless
Possibly too late for you, but if you decide to put the BBB to good use in the future, this is all you need:

http://elinux.org/BeagleBoardDebian

dhess··on FreeNAS: Open Source Storage Operating System
FYI for those running ZFS on Linux or FreeNAS (and maybe FreeBSD, as well):

The nice zfs built-in autoreplace functionality doesn't work on Linux or FreeNAS. You need some scripting/external tooling to do the equivalent. See

https://github.com/zfsonlinux/zfs/issues/2449

https://forums.servethehome.com/index.php?threads/zol-hotspa...

I've had a few drives fail on my ZFS for Linux fileserver and wondered why my hot spares weren't automatically kicking in, and this is why.

On Linux, if you don't use the zed script that's referenced in that Github issue above and just replace a failing drive manually, a hot spare is worse than useless, because you need to remove the hot spare from the array before you can use it with a manual replace operation.

dhess··on Pitfalls in Haskell
I don't think it's true that Template Haskell isn't available on ARM, at least not with recent versions of GHC.

Maybe what you're thinking of is the problem with cross-compiling and Template Haskell. Generally speaking, that does not work because Template Haskell can do evil platform-specific things at compile time, so if the host and target architectures don't match, you can run into problems.

Anyway, you can use Template Haskell on ARM, you just have to compile it on ARM.

dhess··on Turkey Extends Purge to Universities, Asking All Deans to Go
Never have I seen a more ironic username.
dhess··on How I deploy Haskell Code
You'll find this Reddit thread useful:

https://www.reddit.com/r/haskell/comments/3kjpwe/how_to_easi...

dhess··on OS X 10.11 buffer overflow with deep filesystem hierarchy
I reported this bug to Apple back in September, but as we know, filing Radars is practically pointless and as of today it still hasn't even been read.

https://openradar.appspot.com/22671534

dhess··on State of the Haskell ecosystem
This is the chief drawback of these two libraries: they are poorly documented (and are arguably not documented at all). In general, parsers is for parsing and trifecta is for reporting errors and diagnostics. Trifecta looks especially nice for giving context to error sites, but I haven't used it much yet (only for highlighting, really).

By "error recovery," do you mean backtracking? If so, there are several ways of doing that, which can be found here:

https://hackage.haskell.org/package/parsers-0.12.2.1/docs/Te...

See the 'choice', 'option', and 'try' combinators, and also the '<|>' operator in Control.Applicative.

If you need more than that, you can extend parsers' monadic parsing to roll your own error recovery.

Currently, the best way to understand how parsers and trifecta work is to look at projects that use them. I will give you some links to the ones I've used and found helpful, if a bit more complicated than the parsers I am currently writing:

https://github.com/ekmett/ermine/tree/master/src/Ermine

https://github.com/idris-lang/Idris-dev/tree/master/src/Idri...

And here is a relevant Reddit thread, which includes a link to Edward Kmett's slide deck which motivates trifecta/parsers and gives a high-level view of how they work:

https://www.reddit.com/r/haskell/comments/2uc6kp/are_there_a...

I hope this helps!

dhess··on State of the Haskell ecosystem
Try these:

https://hackage.haskell.org/package/trifecta

https://hackage.haskell.org/package/parsers

They are meant to be used together.

dhess··on Project Sunroof
Which installer did you choose, and would you recommend them?
dhess··on Windows 10 Free Upgrade Available in 190 Countries Today
Unless you want to run games, VMware Fusion. Parallels is slightly faster for some use cases other than games, but they lost my business last year when they installed their Parallels Access software without asking me first and without giving users an easy way to uninstall it without also uninstalling Parallels. (Parallels Access is their remote access software, so it potentially opens your Mac up to remote exploits and requires a subscription after a three month trial to boot.)
dhess··on Windows 10 Free Upgrade Available in 190 Countries Today
Thanks. That's what I was afraid the answer would be.

The cheapest MSDN subscription (OS-only) is $699/yr. For that price I could buy about 6 copies of Windows 10 Home edition. Or 2 new laptops each with a Windows license included. Sheesh.

dhess··on Windows 10 Free Upgrade Available in 190 Countries Today
Thanks for the reply. What does an MSDN subscription permit with respect to running multiple VMs?

Edit: sounds like pretty much whatever you want.

dhess··on Windows 10 Free Upgrade Available in 190 Countries Today
Anyone here know much about Windows licensing? This seems like a good opportunity to ask.

I never run Windows on bare metal. I only run Windows on virtual machines on my Mac desktop and Mac laptop; only for personal use; and only on the rare occasion when I need to run the odd Windows-only application.

I would like to go legit this time around, but it's nigh-impossible to find any specific documentation from Microsoft which states, in plain, simple English, how I would go about getting the proper license to cover my use case. I find this hard to believe as it's 2015 and certainly there must be countless others who do the same as I (and at least a few of them here on HN).

The only official Microsoft document I can find about Windows licensing and virtual machines pertains specifically to business use, and appears to be focused on running Windows in a "Virtual Desktop Infrastructure" (VDI) environment, so I don't believe it applies to me. (I confess I did not read the entire document as it contains so much unfamiliar jargon that I have a hard time parsing it past page one.)

Anyway, from what I can tell by gathering bits and pieces posted on various forums by Microsoft community reps or third-party Microsoft "solution providers," Microsoft expects me to buy a separate, full Windows license for each virtual machine I create, for each host machine I run it on (i.e., M * N licenses).

Can anybody here tell me whether that's correct? Because if that's correct, Microsoft can go fly a kite.

dhess··on New Study Shows A Rise In Cord Cutting
There is Acestream, which the authors claim is based on BitTorrent. Unfortunately, the client software is allegedly a bit dodgy, and nobody can tell for sure as it's all closed-source.
dhess··on New Study Shows A Rise In Cord Cutting
If you're in the US, Fox Soccer 2Go streams the Champions League, the Europa League, the English FA Cup, and (new this year) the full Bundesliga 2015-16 season, among other competitions. The quality isn't great, but it's reliable and pretty cheap ($99/year) compared to a US cable subscription that would carry the equivalent competitions. They also keep full match replays online for a few weeks after the live broadcast, for some competitions, anyway. You can watch on a PC/Mac in a browser with Flash (ugh), or use their Android or iOS app. I haven't used the Android app, but the iOS app, despite its awful UI, works fine and supports AirPlay to an Apple TV.

Also in the US, fubo.tv carries some matches in a few other top European leagues. It's a bit of a strange service, but it's cheap and worked well enough for me the few times I used it last season. The quality is slightly better than Fox Soccer 2Go, but still nowhere near broadcast HD. They appear to have a deal with BeIN Sports such that, if a match is being shown on TV on BeIN Sports USA, you can stream it online with just a subscription to fubo.tv (no TV service required). I can't figure out BeIN Sports USA; it seems like they show some Serie A matches, some Ligue 1 matches, and some La Liga matches, but not all. fubo.tv used to carry Bundesliga matches, as well, but as that's moving to Fox Soccer 2Go this season, I don't think fubo.tv will carry those anymore. In any case, I'm waiting until August to decide whether or not to renew my fubo.tv subscription, based on what they're offering for the upcoming European football season.

The Barclays Premier League is NBCSN-only in the US and requires a cable subscription -- for now, at least.

Links:

http://www.foxsoccer2go.com/competitions http://www.fubo.tv

dhess··on June Intelligent Oven
Doubles as a heating element?
dhess··on IPsec Vulnerabilities and Software Security Prediction
Yes, I do that as well, but I think that IPsec is a better backup solution.
dhess··on IPsec Vulnerabilities and Software Security Prediction
I use IPsec in addition to OpenVPN, primarily because that's all iOS used to support. Since iOS 5 or 6 (I think; maybe even as late as version 7?), Apple has allowed third-party VPN apps, so with an "official" OpenVPN client now available in the iOS App Store, it's not as important as it was. However, I've left it running as a fallback solution to OpenVPN (some hotel firewalls, for example, permit IPsec but actively block UDP-based OpenVPN).

I use ipsec-tools, as circa 2012 when I was originally setting this up, it was the only free software IPsec solution I could get to work with iOS clients, but based on this vulnerability I've now disabled it and will try StrongSWAN again.

dhess··on StartCom charges for reissuing SSL certs due to Heartbleed
Thankfully, I don't need those!
dhess··on StartCom charges for reissuing SSL certs due to Heartbleed
I want people to use real certs for START TLS email, client certs, etc.

Because StartSSL issues them for free, I actually did exactly that -- used a separate certificate for each of my secure services (IMAP, SMTP, HTTPS, etc.), on each of my domains. I believe I currently have roughly 25-30 certificates issued by them. My thinking was that, despite the extra configuration complexity, if a particular key were compromised, at least I wouldn't have to replace all my certificates!

Ugh.

So now, ironically, I'm faced with having to replace all my certificates, not to mention paying StartSSL $25 per certificate if I want to do the right thing again and have all the existing ones revoked, as well.

Instead, I'm tempted to "pay up" for a wildcard certificate for each of my domains from a provider whose revenue stream comes from minting certs, not revoking them. Configuring my services sure would be easier with 5 certificates rather than 25. Also, I've never leaked a key by any error of my own, and I'm beginning to think that's less likely than someone finding another hole in OpenSSL (or a CA) which requires wholesale certificate replacement again.

dhess··on Airbnb vs. Hotels: A Price Comparison
I've been having the same problem with Honolulu. In the last 3 weeks I've had 3 or 4 booking attempts declined because the host's calendar was not accurate.

Airbnb folks: this drags your product down to the level of VRBO, Flipkey, etc., where spotty availability calendars creates a large disincentive to use the service.

dhess··on NSA admits listening to U.S. phone calls without warrants
> Edit: sorry, I reversed the polarity wrt. your question. This confirms the other finding, i.e., Yahoo sends via TLS but doesn't accept.

I am. I sent this message to my personal domain from my Yahoo Mail account just now:

  Jun 16 01:46:01 shell postfix/smtpd[29319]: connect from nm4-vm6.bullet.mail.gq1.yahoo.com[98.136.218.165]
  Jun 16 01:46:01 shell postfix/smtpd[29319]: Anonymous TLS connection established from nm4-vm6.bullet.mail.gq1.yahoo.com[98.136.218.165]: TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)
However, it appears that Yahoo's MX did not accept TLS for my outbound reply. That's concerning....
dhess··on NSA admits listening to U.S. phone calls without warrants
Here is a data point; take it for what it's worth.

I run my own email service (Postfix) on 4 different domains. TLS is properly configured on all of my mailhosts, using certificates issued by StartCom. My servers routinely receive mail from Google, Apple, Yahoo, GNU, and other major email providers. Most of the messages are from various mailing lists.

I occasionally peruse the mail logs, and in the last 3 years, at least, I have never seen an unencrypted SMTP connection. I'm not saying it never happens, I've just never seen it. The most common protocol is TLSv1 with a variant of AES (nearly always 256-bit). Apple's listservs use TLSv1 with 128-bit RC4-MD5, but they're the exception.

dhess··on Google Talk Chat History can no longer be turned off by default
That does in fact work, even across browser sessions. Thanks!
dhess··on Google Talk Chat History can no longer be turned off by default
Is there a way to disable Google Talk/Chat/whatever entirely, so that no one can initiate a chat with me?
dhess··on Facebook aims to knock Cisco down a peg with open network hardware
Thanks! Last time I looked, I came up with nothing but the specs on the Open Compute page.
dhess··on Facebook aims to knock Cisco down a peg with open network hardware
I would love to buy a server that conforms to Open Compute and a rack that conforms to Open Rack. Where can I do that?
dhess··on Linode hacked, CCs and passwords leaked
FYI, the last 4 and your e-mail address are both visible in plaintext from your /account page in Linode Manager. Obviously, still disappointing and scary, but it doesn't necessarily mean that whoever has that information also has the full CC number.
dhess··on Linode hacked, CCs and passwords leaked
After seeing your original post here, I also asked for clarification, and received a similar reply from support:

  The Lish password is set to a random string by default, however we would still recommend resetting this password even if you had not set one manually previously.
I had expected that if the password was not set, then password auth was disabled. I've told them that's what I want and have asked when it will be implemented.
← PreviousPage 3 of 7Next →