HNHacker News
TopNewBestAskShowJobs

dpifke

3,032 karma · joined August 4, 2008

My name is Dave. My handle is my first initial followed by my last name; to send me email, use my first name at my last name dot com.

[ my public key: https://keybase.io/dpifke; my proof: https://keybase.io/dpifke/sigs/KuMWBJfGH_TWY1BWLB4luWLnVqnG6BZbXR5Y427QR4o ]

submissionscomments
dpifke··on Ask HN: Who wants to be hired? (October 2026)
Location: Anywhere in U.S.

Willing to relocate: Temporarily

Technologies:

I’m looking for 3- to 12-month contracting opportunities (corp-to-corp), anywhere in the U.S., with organizations looking to move some or all of their infrastructure on-prem.

I can...

Design reliable, secure, scalable, and cost-effective compute, storage, and networking that’s tailored to the needs of your business, using open source software, open weight LLMs, and off-the-shelf hardware.

Find suitable colocation host(s) and negotiate agreements for space, power, bandwidth, and insurance; or hire and supervise a licensed general contractor for building out a server room in your office or other facility.

Get the best deals on equipment, cabling, transportation, and everything else.

Hire and supervise temporary labor for the buildout (“rack and stack”).

Bootstrap networking, storage, cluster management, and Gitops systems. I have lots of experience running Kubernetes on bare metal, arranging BGP peering at public interconnection points, and connecting private clouds to public ones.

Perform initial validation and load testing, and help you migrate services from public clouds or SaaS providers.

Provide training and consultation on SRE best practices, observability, oncall rota, etc.

Resume/CV:

I have 30 years of experience in ISP, web, and related businesses, including as a Technical Program Manager for Google SRE. I started an ISP in 1996, back when all that was needed to do so was a bank of modems and a Linux box or two. I led data center buildouts for several dot coms—including a major social networking site, Bebo—in the late 90s and early 2000s, before the “cloud” existed, and I have tons of experience in the intervening years writing software and operating production services on all of the major hyperscalers. I had a stint managing wifi buildouts in hotels all over the country, where I learned the ins and outs of finding and working with skilled and reliable tradespeople. As the founder of two startups, I know how to be scrappy and move fast in a high-growth environment; I’ve also been an employee and consultant embedded in more mature organizations, always with a reputation for getting things done.

Email: dave at pifke dot org

dpifke··on Real-time feedback: My closing move in every interview
I've interviewed hundreds (maybe thousands at this point?) of candidates in the course of my career, and as much as I think giving feedback at the end of the call is a great idea, I personally would struggle with doing it in a way that was actually useful to the interviewee. Because unless it's a hard "no" (e.g. someone is obviously lying about their experience), I almost always need to ruminate on the interview afterwards before I can write up useful feedback. Sometimes it's the act of writing itself that helps me form a coherent recommendation.

This is also why I hate interview processes where my co-interviewers want to debrief immediately, or when I have a recruiter breathing down my neck as soon as the call ends.

dpifke··on Ask HN: Are others seeing Google's reCAPTCHA rejecting Firefox users?
I never got a response when I wrote to the FTC, requesting formal guidance as to whether having to disable NoScript (a browser security measure) to complete a CAPTCHA to unsubscribe from email spam satisfies 16 CFR § 316:

"Neither a sender nor any person acting on behalf of a sender may require that any recipient pay any fee, provide any information other than the recipient's electronic mail address and opt-out preferences, or take any other steps except sending a reply electronic mail message or visiting a single Internet Web page"

https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C...

A simple reading says, no. But I guess they don't want to put that in writing.

dpifke··on GrapheneOS will remain usable by anyone without requiring personal information
Let me introduce you to California's way of doing things: https://guncad.substack.com/p/special-issue-state-of-califor...

They're suing Florida residents with no ties to California for linking to pictures of guns on the internet.

They will likely lose, but the goal is not to win, it's to score points with their political base and maybe bankrupt the defendants with legal fees.

dpifke··on We Do Not Support Opt-Out Forms (2025)
In the U.S., requiring a login (or any information other than your email address) to opt out is against the law. Additionally, you cannot require any steps other than "sending a reply electronic mail message or visiting a single Internet Web page."

I once wrote to the FTC for guidance as to whether or not this included requiring unsubscribers to solve a CAPTCHA or disable adblockers or enable Javascript, but did not get a response. I believe the law is plain with regards to this, but a lot of companies seem to be willing to risk it.

See: https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C...

dpifke··on Microsoft mishandling example.com
In this case, "null MX record" means MX exists, but does not specify a valid server:

   $ host -t mx example.com
   example.com mail is handled by 0 .
Senders should not fall back on the A record in this case.
dpifke··on Ask HN: Is it time for HN to implement a form of captcha?
I use uBlock Origin for this, something like:

  news.ycombinator.com##:matches-path(/^/item\?id=/) tr a.hnuser:has-text(/^dpifke$/):upward(tr)
This mostly works, but only kills the user's comments and not replies, so it sometimes can be confusing.
dpifke··on Inside CECOT – 60 Minutes [video]
The very first subheading is entitled "What to Submit." I quoted it in my initial reply as rationale for why the people flagging this submission as off-topic were justified.
dpifke··on Inside CECOT – 60 Minutes [video]
This seems similar to the "Is Github Down?" submission problem, where the submitter simply links to github.com.

That's a poor submission, because by the time most people click on it, Github will no longer be down.

There might be an interesting discussion to be had about outages at Github, but the better submission would be an article or blog post about the outage, not just a link to the site and a three-word title.

If someone wants to write an article or blog post about this news broadcast, which links to "hard facts and analysis not available through popular channels," that seems like it might be a worthwhile submission. But just a link to the broadcast by itself is not leading to interesting or on-topic conversation—the top comment right now is an ad hominem attack against Larry Ellison, without any supporting facts or analysis that he had anything to do with this story at all.

dpifke··on Inside CECOT – 60 Minutes [video]
Lots of hackers find porn very interesting. In fact, my first "real job" as a hacker was for a company with ties to the 1-900 industry that had decided to expand out onto the internet (not just to sell porn). Stories about porn would be interesting, submissions of nothing but pornography itself ("because it's censored!") are not.

I would be more sympathetic to the argument that this is relevant if the submission was an article about media censorship, or CBS's audience or leadership, and how said censorship, audience, or leadership relates to technology or emerging trends in media.

But this is literally just a controversial TV news broadcast, that people of one political persuasion say was "censored" and people of another political persuasion say was held off the air "temporarily" until it met network fact-checking standards. That sort of political bickering is most uninteresting, and is most definitely not why I've been reading HN for the past few decades.

dpifke··on Inside CECOT – 60 Minutes [video]
Strong disagree.

Gay porn is censored in a lot of Muslim countries, that doesn't make it on-topic for HN.

dpifke··on Inside CECOT – 60 Minutes [video]
It's off-topic, per https://news.ycombinator.com/newsguidelines.html:

If they'd cover it on TV news, it's probably off-topic.

This submission is literally a TV news broadcast.

There are lots of other places on the internet where this is on-topic, I wish people would have their debates there instead.

dpifke··on Cartoon Network channel errors (1995 – 2025)
As someone who has moderated online communities in the past, I recognize the value in having a page like this, to which you can point people if they want to enumerate such trifles instead of discussing the episodes or series themselves. Rather than just say such discussion is off-topic, you give them a separate, on-topic place to discuss it.

(I don't actually know if that is how this page came about, but it seems similar to other wiki pages I've seen used for such a purpose.)

dpifke··on Autoland saves King Air, everyone reported safe
At an untowered field, saying the airport name at the beginning and end of each transmission is standard phraseology.
dpifke··on A better zip bomb (2019)
If it causes more than $5k in damage. Otherwise, it's a misdemeanor.

But you probably don't want to be investigated for either.

dpifke··on Please just try HTMX
https://unpoly.com touts "progressive enhancement."

Third link on the page ("read the long story") points to https://triskweline.de/unpoly-rugb/, which renders as a blank page with NoScript enabled.

Sigh.

dpifke··on Yep, Passkeys Still Have Problems
Please don't complain about tangential annoyances—e.g. article or website formats, name collisions, or back-button breakage. They're too common to be interesting.

(quoting https://news.ycombinator.com/newsguidelines.html)

dpifke··on Claude CLI deleted my home directory and wiped my Mac
Shouldn't you be out protesting your local chess club instead of posting on HN right now?
dpifke··on A supersonic engine core makes the perfect power turbine
We do use gyroscopic power storage, see e.g.

https://h-cpc.cat.com/cmms/v2?f=subfamily&it=group&cid=402&l...

https://www.activepower.com/

...and probably others.

(A couple of decades ago I worked for a company that was a tenant at a datacenter that used these instead of batteries; it's not new or particularly exotic technology.)

dpifke··on Go Proposal: Secret Mode
Related: https://pkg.go.dev/crypto/subtle#WithDataIndependentTiming (added in 1.25)

And an in-progress proposal to make these various "bubble" functions have consistent semantics: https://github.com/golang/go/issues/76477

(As an aside, the linked blog series is great, but if you're interested in new Go features, I've found it really helpful to also subscribe to https://go.dev/issue/33502 to get the weekly proposal updates straight from the source. Reading the debates on some of these proposals provides a huge level of insight into the evolution of Go.)

dpifke··on Ask HN: Should "I asked $AI, and it said" replies be forbidden in HN guidelines?
I recently logged onto LinkedIn for the first time in a while, and found an old job posting from when I was hiring at a startup ~2 decades ago. It's amazing how much it sounds like LLM output—I would have absolutely flagged it as AI-generated if I saw it today.
dpifke··on Tested: 1981 Datsun 280ZX Turbo (1981)
My first car (hand-me-down from my Dad) was a 1980s Datsun, that I managed to total within a few weeks of getting my license, much to the consternation of my younger brother and sister who expected it to eventually be handed down to them as well.

The "left door is open" voice alert will forever be ingrained in my memory: https://www.youtube.com/watch?v=6hJBko3-oV4 It seemed so futuristic when the car was new.

dpifke··on Testing shows automotive glassbreakers can't break modern automotive glass
If you're in the U.S., you might check if your local fire department has a CERT[0] training course. (I did it many years ago in San Francisco; they call it NERT for some reason.)

It'll give you a chance to practice putting out an actual fire, refresh first aid skills, learn the incident command system, learn basic search and rescue, and other preparedness skills to help yourself, your family, and neighbors in an emergency (in that order).

[0]: https://www.fema.gov/emergency-managers/individuals-communit...

dpifke··on Google flags Immich sites as dangerous
Spamhaus has been sued—multiple times, I believe—for publishing DNS-based lists used to block email from known spammers.

For instance: https://reason.com/volokh/2020/07/27/injunction-in-libel-cas... (That was a default judgment, though, which means Spamhaus didn't show up, probably due to jurisdictional questions.)

The first step in filing a libel lawsuit is demanding a retraction from the publisher. I would imagine Google's lawyers respond pretty quickly to those, which is why SafeBrowsing hasn't been similarly challenged.

dpifke··on Google flags Immich sites as dangerous
I had this same problem with my self-hosted Home Assistant deployment, where Google marked the entire domain as phishing because it contains a login page that looks like other self-hosted Home Assistant deployments.

Fortunately, I expose it to the internet on its own domain despite running through the same reverse proxy as other projects. It would have sucked if this had happened to a domain used for anything else, since the appeal process is completely opaque.

dpifke··on Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
With Windows 11, WSL has X and Wayland support, so you can run graphical applications as if they're native (e.g. share the same cut-and-paste buffer, switch between windows using alt+tab, and so on). It's also much easier to attach USB devices like Yubikeys to an already-running container than the last time I tried to do the same with Parallels. (That was quite a few years ago, so maybe it's gotten better.) You can also launch Windows applications from Linux, which is makes it trivial to control my (Windows-native) browser from within WSL.

I strongly disagree about Mac hardware vs. Thinkpads or Framework, but to each their own.

dpifke··on Foreign hackers breached a US nuclear weapons plant via SharePoint flaws
That's basically WSL.

My work laptop is Windows, and the only native applications I run on it are a web browser, Zoom, and the company's VPN software. Everything else runs inside WSL.

I greatly prefer Debian to Homebrew, so if I can't run actual Linux, this is (to me) superior to trying to develop on a Mac.

dpifke··on Why we need SIMD
Related: Go is looking to add SIMD intrinsics, which should provide a more elegant way to use SIMD instructions from Go code: https://go.dev/issue/73787
dpifke··on Cloudflare Email Service: private beta
Wow, that's pretty crazy, compared to the US. I paid a one-time fee of $50, then $262.50/year for IPv4 block + IPv6 block + ASN: https://www.arin.net/resources/fees/fee_schedule/

I've been through the process about 10 times now at various companies, and the paperwork (at least for ARIN) is no more difficult than what would be expected to justify IP space from your typical ISP. If anything, the ARIN folks are more responsive and technically competent than your average ISP support agent, which makes the process easier.

dpifke··on Cloudflare Email Service: private beta
From your HN profile, I see you're in Brazil, which is part of the region IANA has delegated to LACNIC. Per [0], LACNIC has further delegated numbering authority in Brazil to Registro.br.

Following the links on that page (or performing a simple Google search) leads one to: https://registro.br/tecnologia/numeracao/como-solicitar/

[0]: https://www.lacnic.net/1016/2/lacnic/ip-request

Page 1 of 18Next →