HNHacker News
TopNewBestAskShowJobs

hjuutilainen

720 karma · joined February 25, 2013

submissionscomments
hjuutilainen··on Tailscale's Pricing v4
Oh noes… I’m a single-user but I have just a little under 50 tagged devices and a lot of ACLs. I don’t think my tagged device count is getting any smaller since I like to play around in my homelab. Been paying the Personal Plus subscription since I’m getting a lot of value out of Tailscale. Hopefully I can purchase some upgrades to the Personal plan.
hjuutilainen··on Little Snitch 6.0 Released
Instant purchase. This is one of the first apps I install on a new machine.
hjuutilainen··on BBEdit 15 Release Notes
A master course on how to write good release notes.
hjuutilainen··on Ask HN: How do you monitor your systemd services?
Another happy healthchecks.io user here. You can also run it on your own infra: https://healthchecks.io/docs/self_hosted/
hjuutilainen··on Changes to Tailscale Pricing and Plans
I just got an email about this and here’s what they say:

> Your plan is unaffected and you can continue to use the Personal Pro plan as you normally do. However, Tailscale's new Free plan includes nearly everything that Tailscale has to offer for up to 3 users on a custom domain and 100 devices. This plan may be more aligned with how you use Tailscale. Go to the Billing page in the admin console to review your options.

So I’ve been paying them for a while now but now they’re telling me I could just get the same functionality with the free plan. I really like what this company is doing! Thank you Tailscale, I’ll just keep paying to show my appreciation!

hjuutilainen··on New macOS malware steals info, including a user's entire Keychain database
> MacStealer being an unsigned DMG file is also a barrier for anyone, especially beginners, attempting to run the program on a modern mac, said Malwarebytes' Reed. "Its attempt at phishing for login passwords is not very convincing and would probably only fool a novice user. But such a user is exactly the type who would have trouble opening it."

Given the above and the default macOS security configuration, you really have to work your way to get this malware running.

hjuutilainen··on Ask HN: How do you save and browse external interesting URLs?
I was a heavy pinboard user but recently made the switch to a paid plan on https://raindrop.io/. I tested a few self-hosted OSS solutions but none of them felt right for me. Still too early to say anything meaningful about raindrop but I’ve already found it useful a number of times.
hjuutilainen··on Ask HN: Concise, pragmatic baby manual for first-time dad?
This is based on experience that nearly broke me almost ten years ago:

- It’ll be fine, don’t stress every detail

- Take care of yourself

- Get enough sleep

- Get enough sleep

- Get enough sleep

hjuutilainen··on CircleCI says hackers stole encryption keys and customers’ source code
It would be so interesting to get more details about the initial compromise. What was the engineer trying to do that ended up with downloading PTX-Player.dmg and (probably) the PTX.app installed in /Applications? Was it targeted directly at CircleCI or is this some generic info stealer? What AV / endpoint security solution were they using? Did it pass the built-in macOS protections (gatekeeper, xprotect, etc)? Public VirusTotal seems to know nothing about that hash.
hjuutilainen··on What’s in a PR statement: LastPass breach explained
There’s also Enpass (https://www.enpass.io/) which markets itself as an offline password manager.
hjuutilainen··on Ask HN: What RSS Reader do you use in 2022?
If you are on Apple ecosystem, NetNewsWire is free, reliable and syncs between devices. You don’t need a paid third party service to use it.

https://netnewswire.com/

hjuutilainen··on Duplicati: Free backup software to store encrypted backups online
There’s also resticprofile which takes care of scheduling (with launchd on macOS) and maintenance tasks for restic. I especially enjoy that resticprofile can create a prom file for the backup status that I can just scoop up to my monitoring.

https://creativeprojects.github.io/resticprofile/

hjuutilainen··on Recommended settings for Wi-Fi routers and access points
Two more useful and related Apple KB articles:

macOS wireless roaming for enterprise customers https://support.apple.com/en-us/HT206207

About wireless roaming for enterprise https://support.apple.com/en-us/HT203068

hjuutilainen··on Apple has stopped providing standalone installers for macOS updates
Shameless plug for my own little macOS app to see the contents of these update catalog files: https://github.com/hjuutilainen/sus-inspector
hjuutilainen··on Amazon EC2 Mac Instances
There’s a good blog post from Macstadium explaining the recent EULA changes. 24 hours is mentioned there. https://blog.macstadium.com/blog/developers-big-sur-and-vind...
hjuutilainen··on Bypassing Firewalls in macOS Big Sur
Please file new bugs for this even though it has obviously been already reported to Apple. Apple always touts that the more reports it gets for an issue, the more attention it’ll get.
hjuutilainen··on Open-source photo gallery with cloud backup and end-to-end encryption
I have one computer which always has all originals locally available. That computer is backed up with borg to three separate borg repos (1 local, 2 remote).

I use iCloud photos for sharing with friends and family.

hjuutilainen··on Open-source photo gallery with cloud backup and end-to-end encryption
This is exactly the reason I recently chose to move all my photos to Adobe Creative Cloud and also keep them backed up to multiple separate locations. Almost all other data I can recreate (even if it took years) but the memories I have through photos and videos are irreplaceable.
hjuutilainen··on XCSSET Mac Malware infects Xcode projects, performs UXSS attack on browsers
Already replied to another comment with this but you could try https://sqwarq.com/detectx/ which has command line usage included. (Not affiliated with them)
hjuutilainen··on XCSSET Mac Malware infects Xcode projects, performs UXSS attack on browsers
There’s https://sqwarq.com/detectx/ which would fit your needs nicely. They also recently tweeted about detecting this specific malware in question.
hjuutilainen··on Ask HN: What feature did you find after years of using macOS?
Emacs key bindings work in all standard text boxes and views. For example ctrl-A to go to the beginning of the line and ctrl-E to go to the end.

Also, damn you Microsoft for using non-standard views in your macOS apps.

hjuutilainen··on Ask HN: What feature did you find after years of using macOS?
And if, for example, a webpage has a button to select files through the open file dialog, you can just drag and drop a file to the button and not go through the open dialog at all.
hjuutilainen··on Prepare for changes to macOS Server 5.7.1
First of all you get an MDM service. Doesn’t matter which one but these days this is essentially a requirement. Some MDM’s with good reputation in macadmins community are AirWatch, Jamf, SimpleMDM, MicroMDM (open source).

You then add a couple of more components to get some more enterprise features: Munki for software distribution (free and open source), Chef or Puppet for configuration management (both free and open source) and osquery for monitoring and visibility (free and open source).

hjuutilainen··on Ask HN: What are some of the best documentaries you've seen?
Grizzly Man still gives me goose bumps: https://www.imdb.com/title/tt0427312/
hjuutilainen··on Google’s revamped Cloud Source Repositories in beta
Quickly glanced through the blog post and the docs but didn’t find any mention of Git LFS. Does Cloud Source Repositories support mirroring LFS content?
hjuutilainen··on Ask HN: Alternatives to Team Viewer?
https://www.nomachine.com/
hjuutilainen··on Validating Your Version of Xcode
The problem with "spctl" is that it also evaluates trust which depends on your system settings and you have to pay attention to the output (as pointed out in the article). If you only want to verify the code signature _and_ provide your own requirement string, you could use something like (long options for legibility):

    $ codesign --verify --verbose --deep --test-requirement "=anchor apple" /Applications/Xcode.app/
The "anchor apple" means Apple’s own code, signed by Apple ("anchor apple generic" for developer IDs too).

Add verbosity for all the gory details:

    $ codesign --verify --verbose=999 --deep --test-requirement "=anchor apple" /Applications/Xcode.app/
hjuutilainen··on OS X Yosemite
Option-clicking will do maximize instead of full screen.
hjuutilainen··on My Synology NAS has been hacked by ransomware calling itself Synolocker
And the plot thickens. Synology acknowledged on Facebook and customers are not happy: https://www.facebook.com/synology/posts/10152343606857897
hjuutilainen··on My Synology NAS has been hacked by ransomware calling itself Synolocker
One forum post mentions this too: http://forum.synology.com/enu/viewtopic.php?f=3&t=88716