HNHacker News
TopNewBestAskShowJobs

dibarra

72 karma · joined November 11, 2010

submissionscomments
dibarra··on Datadog dashboard for the Texas power grid
Pretty unlikely. Outages are common, especially in this above average summer, due to higher transformer load and temps.

Ever since the freeze, people who have even planned outages, refer to them as “rolling blackouts”. ERCOT is a pretty open data organization aside from QSE and generator data, and it’s unlikely that this data would have been fudged. We would have seen EEA3 in addition to $5k settlement prices if there was enough of a shortage to invoke rolling blackouts. These prices directly affect end users, e.g. businesses, datacenters, end users still on RTM rates, and solar buyback users. Generators definitely have offers open up to the $5k price point, and there is no way they’d be able to lock the settlement price without it being obvious to businesses/end users, or to generators/REPs/TDUs that there is market manipulation.

As far as sagging frequency, this is also wrong, because frequency sag calls up additional reserves, and we haven’t run below 1 gigawatt of reserves since the winter freeze. The number to watch for is 59.5 hertz, which is automatic EEA3 (we haven’t hit this since the winter storm, where we reached a whopping 59.3 hertz) This is also directly measurable by TDUs and (maybe) end users.

dibarra··on Python is more popular than Ruby
I think the more interesting thing here is how less popular of search term perl/php has become. I really can't find a language that is on an upward trend. Why would people be searching for these terms less over time?

EDIT: Nevermind, it's relative to all searches. More terms to search will depress these numbers.

dibarra··on USDA is down
It actually looks like they withdrew their A records. anl.gov is having the same issue (Though strangely enough, not mirror.anl.gov, so thankfully my systems can still update.)
dibarra··on Google Now Seeing 2% IPv6 Traffic
My Verizon phone started showing an IPv6 number a few weeks ago.
dibarra··on 4.2.2.2: The Story Behind a DNS Legend
The idea is that they can cut off access to non-Level3 customers any day if they wanted to, and they'd be within their rights to do so.

The proper choice would be to use Google DNS or OpenDNS which are provided as a service to the public.

dibarra··on Photobucket's security hole may leave your nude photos exposed
This security loop hole has been there for years, they haven't fixed it since I last toyed with it a long time ago.
dibarra··on Ask HN: How do you Backup your Personal Files?
Rsync cron to my RAID 6 NAS box. Photos get sync'd to 3rd party service. Thumbdrive for critical passwords (keepass).
dibarra··on The Oatmeal's lawyer responds to FunnyJunk
"... I'll note simply that FunnyJunk does not appear to have a notice ofdesignation on file with the Copyright Office."

If true, that's pretty bad- that means that FunnyJunk's safe harbor status can be challenged (17 U.S.C. § 512(c)(2))

dibarra··on Get used to a life of layoffs
I am still feeling burned by how quickly my zv6000 disintegrated. (And anecdotally, how poorly they treated some of the people I know who had malfunctioning laptops from bad nvidia gpus).

I'm not interested in buying HP products anymore, I'm sure that there are people who feel similar. HP is not a brand that stands for quality in my eyes.

dibarra··on Ask HN:How do you avoid being a cog?
No language has a doom sentence on it- they're just tools. There's some languages that are definately more often found in certain "cog-ish" code production companies, which might be what you're referring to.

The best thing you can do for yourself is get familiar with most languages out there, and build a sense of generalism about yourself. If you're comfortable with learning new things, and have a portfolio to back it up, you can have enough options to avoid companies that places you in a "cog" position (If that's what you're looking for.)

dibarra··on Songkick's robots.txt has a few special rules.
It's interesting they're disallowing 008. I work at a popular webhost, and we've had problems with this crawler too (It's distributed, and can crawl things a little too fast).
dibarra··on Ask HN: Best text editor for python?
Sublime Text 2 is really great- it's even built on Python. If OP wants the frilly stuff, I recommend PyCharm http://www.jetbrains.com/pycharm/
dibarra··on Any Houston hackers want to hack?
I would, but these next few weeks are hectic for me :)
dibarra··on "Algorithm" is not a four letter word
Worked fine for me on Chromuum.
dibarra··on GoDaddy shared servers compromised – .htaccess redirection to sokoloperkovuskeci
You can do this fairly easily with Apache and symlinks, there's an issue with SymlinksIfOwnerMatch that people can circumvent if they're clever...
dibarra··on GoDaddy shared servers compromised – .htaccess redirection to sokoloperkovuskeci
Does GoDaddy use Fantastico? I know we recently patched our servers for http://www.1337day.com/exploits/16512

Not sure if GoDaddy did (or needs to) do the same.

dibarra··on Being hacked killed a 6k traffic spike on my blog yesterday
By the way, simply put, load averages are computed based on the number of processes in contention for the CPU, and are calculated based on a single CPU average. So, a load of 70 means 70 processes were in contention of the CPU, meaning the system is overloaded by 7000% (assuming the server had only one CPU core.)

http://en.wikipedia.org/wiki/Load_(computing)

dibarra··on Hookworm Stealth PHP Backdoor
A common way is just script vulnerabilities, allowing execution of arbitrary code. I work at a popular webhosting company, and I've seen cases where apps will execute PHP code inserted as a sooofed User-Agent, POST data, and other weird places. The idea is that you send a payload that executes on the remote host, GETs your shell from some free webhost or another compromised account, and then saves it on the target machine. At that point, you're set.

mod_security can help for people running Apache, and so will using maintained and up to date scripts.

dibarra··on Ask HN: Where do you host medium-scale start up sites?
Personally, I have a dedicated server, there's plenty to be had out there for a relatively cheap price. ($50ish range, they're out there, I'm hosting at http://securedservers.com)

A dedicated server is a good opportunity to learn about server administration too!

dibarra··on Record Industry: Limewire Could Owe $75 Trillion
The CIA Factbook cites the 2010 estimate for GDP at $74.48 trillion:

https://www.cia.gov/library/publications/the-world-factbook/...

Also of interest, another number close to this is the world's stock of broad money, at around $75.86 trillion. Because this is comprised of all money in circulation, plus the total quantity of money in money market funds, credit union deposits, and other liquid assets, the top end of what is being asked for is almost literally, all of the money in the world.

dibarra··on Test your IPv6 Connectivity
7/10 for both, Teredo is easy to set up. I can help anyone who has questions with it.
dibarra··on Keeping Punxsutawney Phil's Website Online Through Groundhog Day Traffic Flood
It's more like a reverse proxy. [1] You point your domain to their DNS, and then they cache your site on their CDN, reducing loading times and CPU consumption.

It also uses data from Project Honeypot to serve captchas and links to popular virus scanners to people who are listed as having a blacklisted IP addresses in Project Honeypot, the idea being that they're probably using a zombie computer and launching attacks without them knowing it. By raising their awareness that they've been listed, they're more likely (hopefully) to remove their malware.

[1] http://en.wikipedia.org/wiki/Reverse_proxy

dibarra··on World's worst hacker
Actually, you guys are both right. Speaking from experience (administrator at a popular webhosting company), he likely a lot of his rootkits macroed, so he can just login to the box, alt+1 (or whatever he has his macro set to) and then pop out. When the macros fail, he demonstrates his lack of actual knowledge of *nix systems and starts acting erratically.
dibarra··on Ask HN: DDOS attack remedies?
I deal with this in my day job as well. Many datacenters will have mitigation appliances such as Arbor Peakflow, Cisco Guards, IntruGuard, etc. For attacks that are throwing garbage to unused ports, you can block these fairly effectively by having your datacenter block these ports at the router. Just ask your datacenter's support for a service such as this, usually their SLA specifies a time limit for how long your site may consume mitigation services for free. Your datacenter will probably start nulling your IP at around 1gbps inbound (varies, might be lower)

Some DDoS's are easy to block via iptables- attackers who aren't very clever will have the same UA on all of their bots, and they are easy to block via a combination of tailing your domlogs, and adding bad ips to an iptables listing. Many don't set a user agent, making it much easier.

Floods that consist of holding open http server connections for long periods of time can be combated by throwing MaxClients to something large (about 5000) and setting keepalive to something low, like around 5 seconds (if you're using Apache, similar probably holds true for other http servers).

You can usually use string blocking via iptables, but these will still hold the connection open until the client times out, and you might have to resort to the above in conjunction (raise MaxClients, etc.). Usually, I try to mitigate via IP addresses before string blocking.

Rarely will I see an attack that will require a nullroute upstream. If you're worried about those, you will need to seek professional services. In most cases, you can mitigate at the server level easily. Also, ngrep is your friend.

dibarra··on 10 great WP plugins
#11. W3 Total Cache. Wordpress is CPU hungry.