HNHacker News
TopNewBestAskShowJobs

hbz

160 karma · joined May 20, 2010

submissionscomments
hbz··on Show HN: 300k lines of Java UI code running native in browser at desktop speed
Seemed to freeze up after I loaded a sample and clicked a few things inside it
hbz··on What Rock Climbing Taught Me About Engineering
Designing software related to healthcare / electronic medical records requires more thoughtfulness than other kinds of development.
hbz··on Ask HN: What do you use for Log Management?
Self hosted ELK stack, not HA at the moment. Will move the ES nodes to AWS's managed service once I'm ready to make it more resilient.
hbz··on Switching Costs in Software Development
I like all the guesses on which company “Scaling R Us” represents. My guess is RightScale.
hbz··on SSL considered bloated
A counter to the author's "webserver in 1 line of code" - https://gist.github.com/denji/12b3a568f092ab951456#simple-go...

I prefer proxying of SSL (and automatic generations of LetsEncrypt certificates) using containers so that my web servers don't have to worry about that aspect of configuration.

hbz··on [dead]
Because it's lazy and insecure?
hbz··on [dead]
One of the biggest complaints about the curl - bash paradigm are the security implications. URLs can point to different content at different times. Project maintainers can (and have) changed the content at these URLs for malicious or other reasons. A lot of people will not examine the source of what they're piping into the shell.

To me, https://github.com/jbenet/hashpipe addresses a lot of these issues by pinning the content to a hash.

You can't force somebody to read and understand the install script, but at least those who do can know it's the one they verified in advance.

hbz··on Vim GIFs
Thanks!
hbz··on Vim GIFs
Does anybody know what program was used to generate the gifs?
hbz··on Show HN: Turn a markdown document into an interactive tutorial
An interactive guide to fork bombing
hbz··on Viking Horde: A New Type of Android Malware on Google Play
Cached version: http://webcache.googleusercontent.com/search?q=cache:http://...
hbz··on Fully automated dockerized Let's Encrypt reverse proxy
I use 2 containers to accomplish this:

https://github.com/jwilder/nginx-proxy

https://github.com/JrCs/docker-letsencrypt-nginx-proxy-compa...

Since both are long running processes, it makes sense to keep them in separate containers.

hbz··on Show HN: ResumeFodder – Go app for generating Word resumes from JSON Resume data
If you already have your work history filled out on LinkedIn, this seems like a handy tool: https://github.com/JMPerez/linkedin-to-json-resume
hbz··on Deploy a .onion Site in Less Than 5 minutes
Why even do this in ansible? Your heavy reliance on command instead of the provided ansible modules makes it more of a bash script.
hbz··on Recplay: Motorbike simulation record player
My jaw dropped when I saw it was Elastomania. Love that game!!
hbz··on Google hacked account
Are you sure that's still the case?

This[1] would seem to indicate you can use a U2F device[2] as an alternative to providing a cell phone for verification.

[1] https://www.google.com/landing/2step/#tab=how-it-works

[2] http://googleonlinesecurity.blogspot.com/2014/10/strengtheni...

hbz··on Google hacked account

  My mistake was that I didn't enable 2 factor authentication.
Kind of aggressive calling out Google's engineers when you couldn't bother protecting yourself with their free and easy to use security mechanisms.
hbz··on Bundle Club – Curated essentials for your baby delivered monthly
I wish they had posted this to HN after it was available...I want it now! This project still appears to be in its infancy.
hbz··on NGINX open sources TCP load balancing
Technically incorrect. WebSockets handshake over HTTP and then "work" over TCP. I'm actually curious which HTTP stacks are non compliant and what you mean by that.

As to my original comment, you can probably get by without having full TCP load balancing.

hbz··on NGINX open sources TCP load balancing
http://en.wikipedia.org/wiki/WebSocket are a completely legitimate use.
hbz··on Show HN: Building terminal dashboards using ASCII/ANSI art and JavaScript
Seems to be randomly generated- https://github.com/yaronn/blessed-contrib/blob/master/exampl...
hbz··on Infrastructure for Data Streams
No worries, thanks for taking the time to write all this up!
hbz··on Infrastructure for Data Streams
I was hoping he'd post the http-to-kafka adapter but I'm guessing that's ChartBeat IP.
hbz··on Big Data Firm Says It Can Link Snowden Data To Changed Terrorist Behavior
Did Snowden reveal anything about "Mujahideen Secrets" or whether the NSA was able to unscramble communications made using that program? If it really was using homebrew cryptography, one can imagine it was already vulnerable to the types of attacks that programmers make when rolling their own security schemes.
hbz··on Drp.io: Fast and easy images hosting
Really great image host workflow.

I'd love to see the source of this (or something similar) so I could implement it privately. Any ideas?

hbz··on Here’s who probably did that $150 million Bitcoin transaction
This type of "sophisticated analysis" will be useless whenever zerocoin is proven as a viable addition to the protocol. True anonymity is scary from a regulatory standpoint but extremely desirable to many others.
hbz··on Github.com is down
Right in the middle of a deploy for us! Thankfully we're getting enterprise so hopefully this is last time a DDoS messes with our productivity.
hbz··on Show HN: Piki, a fresh take on the wiki
I tried to edit the article entitled "Internal server error" but the controls for contributing to it weren't intuitive enough.
hbz··on The Most Revealing Job Interview Question
Can somebody just post the question? Server's aren't responding.
hbz··on After a spectacular crash, Bitcoin makes a surprising comeback
"Therefore ARE servers only hold encrypted private keys and neither we or anyone else can access them. Only you."

Misspellings on your landing page don't inspire confidence.

Page 1 of 2Next →