HNHacker News
TopNewBestAskShowJobs

dontdoxxme

225 karma · joined August 6, 2023

submissionscomments
dontdoxxme··on Redis array: short story of a long development process
Your comment is not constructive, why can't it be trusted?

If every user of an LLM took this much care and attention, many people would have fewer issues with LLM assisted coding. In this case the author has demonstrated they can write plenty of code without an LLM, so why not use it carefully to benefit their productivity?

dontdoxxme··on Copy Fail
No, it is not affected by the exploit as presented. This is a page cache write, so writing to a binary that root will run later can work too. This isn’t a reason to push an agenda that dislikes setuid binaries.
dontdoxxme··on Integrated by Design
The style of the blog post, with short, abrupt sentences does not captivate me. I’d like to think someone writing a book has a more interesting writing style. Or maybe LLMs have damaged me and I’m too critical of writing style now, whatever it is this doesn’t sell the book to me.
dontdoxxme··on Microsoft suspends dev accounts for high-profile open source projects
Microsoft loves sending emails with "Action required" in the subject, when actually no action is required, or it doesn't apply to you, or whatever. Such corporate speak. It's fun searching your email for "Action required" and finding all the things you were supposed to do and it turns out didn't need to do anything about.
dontdoxxme··on RX – a new random-access JSON alternative
Very similar to bittorrent’s bencode. That has the benefit that it has a canonical encoding which this doesn’t (because of the different compression options). I wouldn’t be put off by how it looks as text.
dontdoxxme··on Notepad++ hijacked by state-sponsored actors
Previous NS records were pointing at dns-parking.com, which is Hostinger. Although hard to be certain without more details whether a reseller or other supplier is involved.
dontdoxxme··on The Holy Grail of Linux Binary Compatibility: Musl and Dlopen
Clearly a joke if it uses the .lol tld.
dontdoxxme··on Killing the ISP Appliance: An eBPF/XDP Approach to Distributed BNG
The code is mostly vibe coded and under the BSL. I think the interesting bit here is a single developer can write something like this with an agent. Does it make sense to open source such a thing or just each ISP write their own to their requirements?

I also don’t get the focus on handling DHCP renewals in the kernel fast path. With 2000 subscribers per OLT and say a 5 minute lease time that’s only a few renewals a second.

dontdoxxme··on Show HN: DevicePrint – device fingerprinting without cookies
Same, it's all over the place. Whatever it is doing isn't a very strong fingerprint.
dontdoxxme··on Is Northern Virginia still the least reliable AWS region?
Why aren't you using IBM cloud?
dontdoxxme··on Fabrice Bellard Releases MicroQuickJS
Yes, previously: https://news.ycombinator.com/item?id=35989909

The Redis test suite is still written in Tcl: https://news.ycombinator.com/item?id=9963162 (although more recently antirez said somewhere he wished he'd written it in C for speed)

dontdoxxme··on Android introduces $2-4 install fee and 10–20% cut for US external content links
Most users don’t see it that way.
dontdoxxme··on A better zip bomb (2019)
Previously: I use zip bombs to protect my server (idiallo.com) 1076 points https://news.ycombinator.com/item?id=43826798
dontdoxxme··on O'saasy License Agreement
It is not open source, it is not free. It’s a term tacked on to the MIT license.

It’s also vague as, what if I run a VPS provider and someone can upload images to a marketplace like thing, does that count as SaaS? How about if someone’s only use of my services is to run that image?

Steer clear unless you want to open yourself up to the copyright owners opinion changing. (See for example the pine email client and the copyright discussions there.)

dontdoxxme··on GNU recutils: Plain text database
This among other things is why the GNU project as a whole has little credibility left.
dontdoxxme··on Advent of Sysadmin 2025
Without sharing too many spoilers... I solved the challenge but the check script was unhappy. The curl commands in the script worked fine, the earlier parts of the script failed, i.e. it didn't like how I'd decided to make that work.

This kind of thing annoys me. This is why CTFs are great, where the goal is to get the flag string. Obviously harder to do for sysadmin, but expecting a particular configuration when I managed to make it work without doing things exactly as they wanted is no better than a poorly written exam.

dontdoxxme··on Stopping bad guys from using my open source project (feedback wanted)
Some background in https://gist.github.com/kemitchell/fdc179d60dc88f0c9b76e5d38...

Basically you end up with something not legally enforceable. And will someone actually doing evil care about your license?

dontdoxxme··on Show HN: Whole-home VPN router with hardware kill switch (OpenWrt and WireGuard)
> And netns is for single-host isolation. This is a router forwarding LAN→WAN. Different problem

Not at all. Put the LAN interface in a network namespace that is different to the host (ip link set ... netns ...).

This gives you your "kill switch" without even needing firewall rules, it happens on a lower level.

dontdoxxme··on Show HN: Whole-home VPN router with hardware kill switch (OpenWrt and WireGuard)
> Not a techie? The README is optimized for AI-assisted deployment. Feed it to your LLM of choice (Claude, GPT, etc.) and it can walk you through the entire setup for your specific hardware.

The whole thing is AI slop. I thought there might be something interesting here but it's just a bunch of disconnected fragments of OpenWRT config and some other bits without any overall thought.

It doesn't even use network namespaces. You can probably do better by giving your LLM https://www.wireguard.io/netns/ as input.

dontdoxxme··on Widespread service disruptions reported as major platforms go down worldwide
https://how.complexsystems.fail applies in all cases. (Particularly here “Post-accident attribution to a ‘root cause’ is fundamentally wrong.”)
dontdoxxme··on Monotype font licencing shake-down
> acknowledge the message

I think it is more nuanced than that -- they are sending a message via LinkedIn, is it really the company or a scam?

You should take time to respond appropriately and not be rushed in all cases. By acknowledging the message they'll want to continue the discussion. It's probably worth considering a standard response to approaches like this, along the lines of "Please contact us on generic-something@domain, I cannot discuss this on my personal social media account."

dontdoxxme··on Cloudflare Global Network experiencing issues
Did you ask an LLM to try to guess the error message?
dontdoxxme··on Ask HN: Self Hostable Alternative to Jsonbin.io?
It depends what your needs are, you haven't given any details. I'm not aware of anything with the JSONBin.io API (frankly I don't like their API, I think it should be more RESTful).

CouchDB is in many ways very similar to JSONBin and self hostable. I have also written small services that use SQLite's JSON support and wrap that up in a fairly restful API (e.g. POST a document to a list adds an item, etc.).

Another option is to use something like PostgREST, which I get isn't at all what you asked, but in this day and age you can just ask ChatGPT to make you a schema and it takes 2 minutes to prototype a REST API.

Really it depends if you have preferences for what datastore you use, as that is the more difficult bit when self hosting.

dontdoxxme··on Plumbing vs. Internet, Revisited
It's also interesting to consider that most commercial data centres depend on plumbing for aircon or even direct water-cooling. Therefore depending how far you take this, it could result in an internet that exists, but with a limited set of services (as they can only be self hosted, or at least not at the huge scale we are accustomed to).
dontdoxxme··on Ask HN: What in the world is going on at Supabase?
The sad fact is investors don’t care about abuse. Provided the company aren’t deliberately faking customers there is no incentive to spend any resources on a free trial other than looking for customers to convert.
dontdoxxme··on Leaked Apple M5 9 core Geekbench scores
Sounds like you need to spend some time optimising your build. Faster hardware just makes developers lazy. I'm still on an M1 and it's fine, although I do have 32GB.
dontdoxxme··on GPT-5 Thinking in ChatGPT (a.k.a. Research Goblin) is good at search
There are searches where that is the best way for a human to get the answer too. It can also search the Internet Archive if you ask for historical details, so does it not just do what a good human researcher would do?
dontdoxxme··on Cloudflare incident on August 21, 2025
I think the intention is to show the divide between Amazon's and Cloudflare's responsibility, over the piece of fibre linking their network devices together. It would have been clearer to continue the lines and just put a dotted divider between them I feel.
dontdoxxme··on Workday suffered a data breach

    The company said the breach hit some of its third-party customer relationship databases. If any other data was stolen, Workday didn’t say for sure. The company only said there was “no indication of access to customer tenants or the data” within those databases
So that would be customer data of the admin / HR team at their customers, but not all the users, so while not good, it's not going to directly give really sensitive data; most likely to be used for further phishing attacks.
dontdoxxme··on Australian bank gives out customer phone to another customer by asking ChatGPT
You sound like a crazy person. The actual relevant bit of law is APP 13[1], which has a definition for "holds", which shows the source of the information does matter. If you're going to go and quote half the law, but ignore the actual relevant piece, at least talk to a lawyer.

[1]: https://www.oaic.gov.au/privacy/australian-privacy-principle...

Page 1 of 3Next →