HNHacker News
TopNewBestAskShowJobs

donnachangstein

803 karma · joined March 9, 2025

submissionscomments
donnachangstein··on The child-like role of dogs in Western societies
FWIW I wrote that post with no aggression intended. I suspect you may be overanalyzing things. Have a Coke and a smile, Dan.

Unfortunately, if my manner of speaking directly is breaking the site guidelines, then I'm afraid my values are incompatible with posting here.

I hope you didn't expend too much energy digging through my post history looking for transgressions. Though I do think it's funny the post that got me yelled at was the post insulting pit bulls.

Remember to not throw the baby out with the bathwater. Many of my posts were highly upvoted. I bid you good day.

donnachangstein··on Brian Wilson has died
I never said Ben wasn't talented. He's very talented. I like Ben.

That said, they are leagues apart. It's like claiming Eric Clapton is as good as a guitarist in some shitty bar band.

Perhaps you're not familiar with who Brian was and what he's done.

donnachangstein··on Brian Wilson has died
Ben is a hipster Elton John. To put him in the same league as Brian is insulting.
donnachangstein··on The child-like role of dogs in Western societies
People bringing their pet dogs into grocery stores is an especially egregious societal ill. It's a major problem in places like Seattle where dogs outnumber children.

I once watched a woman hold her little dog over the glass at the pizza bar in Whole Foods. Was waiting for the dog to drop a free sausage link onto the pizza below.

Placing dogs into shopping carts is another one. Dogs rub their dirty buttholes on the same surfaces where you later place your fruits and vegetables.

donnachangstein··on I'm Wirecutter's water-quality expert. I don't filter my water
> and maintaining a dedicated three stage filter spout next to my kitchen faucet costs me approximately nothing

Calling bullshit on this one. I have one, it's positively wonderful, but the filters are expensive and per the manufacturer's recommendation you're supposed to change them all simultaneously. So when one times out, they all time out. This runs approximately $150 a year minimum depending on usage.

donnachangstein··on I'm Wirecutter's water-quality expert. I don't filter my water
> but do people brew green tea or good coffee with tap water?

I use filtered tap water (under-sink type) which removes most of it.

A lot of the higher end coffee makers like Keurig have built-in filter cartridges in the water tank.

Most commercial coffee maker setups I've seen (hard-plumbed) in offices have a filter attached to the plumbing behind the appliance.

Water can be safe/potable and taste terrible, and vice versa.

donnachangstein··on I'm Wirecutter's water-quality expert. I don't filter my water
> But hey, at least it's not bottled water, which is basically tap water that has been put in a single-use plastic bottle and trucked across the country.

Everyone acts like bottled water is evil until there is a water crisis, then it's the lifeline.

donnachangstein··on A proposal to restrict sites from accessing a users’ local network
Globally routable doesn't mean you don't have firewalls in between filtering and blocking traffic. You can be globally routable but drop all incoming traffic at what you define as a perimeter. E.g. the WAN interface of a typical home network.

The concept is frequently misunderstood in that IPv4 consumer SOHO "routers" often combine a NAT and routing function with a firewall, but the functions are separate.

donnachangstein··on A proposal to restrict sites from accessing a users’ local network
> The modern Mac is a sea of Allow/Don't Allow prompts

Remember when they used to mock this as part of their marketing?

https://www.youtube.com/watch?v=DUPxkzV1RTc

donnachangstein··on A proposal to restrict sites from accessing a users’ local network
> Can anyone explain to me if there is any way to determine whether an inbound IPv6 address is "local"?

No, because it's the antithesis of IPv6 which is supposed to be globally routable. The concept isn't supposed to exist.

Not to mention Google can't even agree on the meaning of "local" - the article states they completely changed the meaning of "local" to be a redefinition of "private" halfway through brainstorming this garbage.

Creating a nonstandard, arbitrary security boundary based on CIDR subnets as an HTTP extension is completely bonkers.

As for your application, you're going about it all wrong. Just assume your application is public-facing and design your security with that in mind. Too many applications make this mistake and design saloon-door security into their "local only" application which results in overreaction such as the insanity that is the topic of discussion here.

".local" is reserved for mDNS and is in the RFC, though this is frequently and widely ignored.

donnachangstein··on A proposal to restrict sites from accessing a users’ local network
> Sure - a destination is "local" if your machine has a route to that IP which isn't via a gateway.

Fantastic. Well, Google doesn't agree

The proposal defines it along RFC1918 address space boundaries. The spitballing back and forth in the GitHub issues about which imaginary TLDs they will or won't also consider "local" is absolutely horrifying.

donnachangstein··on A proposal to restrict sites from accessing a users’ local network
Can you define "local network"? Probably not. Most large enterprises own publicly-routable IP space for internal use. Internal doesn't mean 192.168.0.0/24. foo.corp.example.com could resolve to 9.10.11.12 and still be local. What about IPv6? It's a nonsense argument fraught with corner cases.
donnachangstein··on A proposal to restrict sites from accessing a users’ local network
Ironically, Chrome partially supported and utilized IE security zones on Windows, though it was not well documented.
donnachangstein··on When will M&S take online orders again?
> what are you even doing?

Forensics, among a hundred other things.

> Literal amateurs can launch a WooCommerce site from nothing in a weekend

Selling low-volume horseshit out of your garage is in no way comparable to running a major eCommerce site.

> two Stanford grads in YC can do a hundred-fold better than that.

No they literally can't.

> Yes, a big site is more complicated, maybe there will be some frazzled manual data entry in Excel sheets while your team gets the "real" site back up

Great idea, we'll have Chloe in Accounts manage all the orders in a million-row Excel sheet. Only problem might be they come in at 50 orders a minute, but don't worry I hear she's a fast typist.

donnachangstein··on When will M&S take online orders again?
> whereas startups building new products often get by with relatively few people

90% of startups fail within 5 years so probably not the best example of how to run things.

The few that do "succeed" often carry over mountains of cruft and garbage code into perpetuity (for example Reddit).

donnachangstein··on When will M&S take online orders again?
HN posters love talking gangster shit when something goes offline but never walked a mile in their boots.

I most recently remember sifting through gloating that 4chan - a shoestring operation with basically no staff - was offline for a couple weeks after getting hacked.

I've worked at a shop that had DR procedures for EVERYTHING. The recovery time for non-critical infra was measured in months. There are only so many hands to go around, and stuff takes time to rebuild. And that's assuming you have procedures on file! Not to mention if there was a major compromise you need to perform forensics to make sure you kick the bad guys out and patch the hole so the same thing doesn't happen again a week after your magical recovery.

And if you don't know, you shut it down till it's deemed safe. How do you know the backups and failover sites aren't tainted? Nothing worse than running an e-commerce site processing customer payment card data when you know you're owned. That's a good way to get in deeper trouble.

donnachangstein··on Japan Post launches 'digital address' system
> RFID isn't smart

Makes it utterly useless as a digital signature then.

donnachangstein··on Japan Post launches 'digital address' system
> tap a RFID hanko

we call those contactless smart cards

donnachangstein··on Japan Post launches 'digital address' system
UPS driver left a $3500 MacBook Pro on my front steps, didn't even ring the bell... signature required my ass.
donnachangstein··on Japan Post launches 'digital address' system
This being Japan, you still have to sign for your digital delivery with a rubber ink stamp.
donnachangstein··on Every wondered how Facebook spoofs Gmail message list snippet text?
Thanks for linking to a picture of testicles.
donnachangstein··on US pauses new student visa interviews as it mulls expanding social media vetting
"US Person" has a very specific definition in government parlance. It includes citizens and green card holders, a few very specific exceptions like those granted permanent asylum, but NOT visa holders.
donnachangstein··on Hacker News now runs on top of Common Lisp
The genius of Slashdot's moderation system is that it forced you to be fastidious with how your limited mod points were allocated, only using them on posts that really deserved them.

As opposed to tearing through a thread and downvoting any and everything you disagree with.

Slashdot encouraged more positive moderation, unless you were obviously trolling.

The meta-moderators kept any moderation abuse in check.

It's sad to see we have devolved from this model, and conversations have become far more toxic and polarized as a direct result of it. (Dissenting opinions are quickly hidden, and those that reinforce existing norms bubble to the top.)

I believe HN papers over these problems by relying on a lot of manual hand-moderation and curation which sounds very labor intensive, whereas Slashdot was deliberately hands-off and left the power to the people.

donnachangstein··on Hacker News now runs on top of Common Lisp
It's not a special case at all. 20 years ago this was standard architecture (hell, HN still caches static versions of pages for logged-out users).

No, what changed is the industry devolved into over-reliance on mountains of 'frameworks' and other garbage that no one person fully understands how it all works.

Things have gotten worse, not better.

donnachangstein··on I used o3 to find a remote zeroday in the Linux SMB implementation
1. People that were using the in-kernel SMB server in Solaris or Windows.

2. Samba performance sucks (by comparison) which is why people still regularly deploy Windows for file sharing in 2025.

Anybody know if this supports native Windows-style ACLs for file permissions? That is the last remaining reason to still run Solaris but I think it relies on ZFS to do so.

Samba's reliance on Unix UID/GID and the syncing as part of its security model is still stuck in the 1970s unfortunately.

The caveat is the in-kernel SMB server has been the source of at least one holy-shit-this-is-bad zero-day remote root hole in Windows (not sure about Solaris) so there are tradeoffs.

donnachangstein··on Why I no longer have an old-school cert on my HTTPS site
I said it was dead-simple and you delivered a treatise describing the most complex use case possible. Then maybe it's not for you.

Most software in the OpenBSD base system lacks features on purpose. Their dev team frequently rejects patches and feature requests without compelling reasons to exist. Less features means less places for things to go wrong means less chance of security bugs.

It exists so their simple webserver (also in the base system) has ACME support working out of the box. No third party software to install, no bullshit to configure, everything just works as part of a super compact OS. Which to this day still fits on a single CD-ROM.

Most of all no stupid Rust compiler needed so it works on i386 (Rust cannot self-host on i386 because it's so bloated it runs out of memory, which is why Rust tools are not included in i386).

If your needs exceed this or you adore complexity then feel free to look elsewhere.

donnachangstein··on Why I no longer have an old-school cert on my HTTPS site
OpenBSD has a dead-simple lightweight ACME client (written in C) as part of the base OS. No need to roll your own. I understand it was created because existing alternatives ARE bloatware and against their Unixy philosophy.

Perhaps the author wasn't looking hard enough. It could probably be ported with little effort.

donnachangstein··on Mozilla to shut down Pocket on July 8
Another feature no one asked for, meeting its technological grave. For those few users of Pocket this function could have been easily handled as an extension.

If Mozilla spent the engineering hours wasted on this toward fixing the ever growing mountain of existing bugs they might have more than 1% market share.

donnachangstein··on Building my own solar power system
Relocating is a simpler ask to most ordinary people than is turning their garage into a battery vault.
donnachangstein··on Building my own solar power system
[flagged]
Page 1 of 5Next →