HNHacker News
TopNewBestAskShowJobs

honestSysAdmin

7 karma · joined January 12, 2025

submissionscomments
honestSysAdmin··on Pixelfed Hit 500K Users
I wonder how many of those are bots.
honestSysAdmin··on Apache Iceberg
Iceberg is a pretty cool guy, he consolidates the Parquet and doesn't afraid of anything.
honestSysAdmin··on Snowdrop OS – a homebrew operating system from scratch, in assembly language
Some of us are "spoiled" by Rust. About ten years ago the Erlang argument may have been somewhat compelling. Now we use software libraries that don't crash in the first place. Not every Rust library meets that metric, but using Rust as a baseline and a small handful of other patterns/practices it's not hard to meet these days.
honestSysAdmin··on Snowdrop OS – a homebrew operating system from scratch, in assembly language
Yeah, you're right, Redox using a micro-kernel architecture taking inspiration from Plan9 and seL4 is not new ideas. What Redox is doing differently than the others that is new is successfully delivering these ideas.

Redox has delivered these existing ideas in a manner that will soon enough be (if not already) suitable for production use and available to package for casual non-hacker users. If there is another project that has also done this in a non-academic way, I'd like to see it.

honestSysAdmin··on Migrating Away from Bcachefs
Some of the zpool configurations I have set up seem "odd" to others, but they do have a purpose and are well thought out.

What motivated you to combine ZFS and bcache? What did that configuration look like? What was the thinking behind it? I would prefer to inquire further rather than make and present wrong assumptions as to why the configuration is wrong.

honestSysAdmin··on Snowdrop OS – a homebrew operating system from scratch, in assembly language
illumos on RISC-V with CHERI would be the ultimate. There is another variant of RISC-V that is spectre immune. I have also recently heard of approaches at compile-time, such as RESPECTRE, that remove the spectre problem.
honestSysAdmin··on Snowdrop OS – a homebrew operating system from scratch, in assembly language

  https://learning-0mq-with-pyzmq.readthedocs.io/en/latest/pyzmq/patterns/pair.html
honestSysAdmin··on Snowdrop OS – a homebrew operating system from scratch, in assembly language
The best answer, given the specific opposite edges you have broadly specified, is

  https://redox-os.org/
honestSysAdmin··on We Need to Talk About Docker Hub
Seemed like "everyone" switched to Podman and Buildah over two years ago. Nothing screams "amateur and clueless" like still using Docker.
honestSysAdmin··on Migrating Away from Bcachefs
I don't expect ZFS to be dethroned this decade, nor the next one.
honestSysAdmin··on Is social media more like cigarettes or junk food?
Thanks to social media, Facebook in particular, and sometimes Instagram, I have gotten laid. Thanks to social media I have gotten laid more than I otherwise would have, or probably should have.

I have not had the same experience with cigarettes and junk food.

honestSysAdmin··on Analysts say real datacenter emissions are a dirty secret
As a consultant I often accompany CTO/CIO/CISO to both formal and informal events. I also have a working relationship with many other categories of executives and some board members. When I talk to execs and board members in a private setting, none of them seem to have even the most remote concern about CO2, or even believe that CO2 is bad for the planet.
honestSysAdmin··on Ask HN: Organize local communities without Facebook?
Rural USA is extremely distrustful and quick to show both that distrust and disdain towards any Silicon Valley based company. "Technology is bad" is the general sentiment. These are "fossil of America" places where privacy is highly valued.

This is just my anecdotal experience, overwhelming anecdotal data, and I won't mention the specific regions so as to maintain my respect for those regions by not "out"ing them for having their views.

honestSysAdmin··on 0-click deanonymization attack targeting Signal, Discord, other platforms
If you've ever been stalked by a crazy ex-girlfriend who is from a very rich family, you'll probably feel a little "paranoid" or whatever.

I was already on the "I just want to be left alone" vibe generally before all that happened to me, so I just carried on as usual.

honestSysAdmin··on DHS removes all members of cyber security advisory boards, halts investigations
Fortunately, there are plenty of private sector companies investigating Salt Typhoon.

I can speak for the firm I work for. Our clients are effectively invulnerable to Salt Typhoon. Yes, I know that sounds like a "big claim" but it's really not. We enable our customers to run endpoints that aren't based on Windows or macOS. So...

honestSysAdmin··on DHS removes all members of cyber security advisory boards, halts investigations
CISA is the organization that declared that the 2020 election was the most secure election ever. So it is expected that CISA would get "liquidated" by this new administration.
honestSysAdmin··on Ross Ulbricht granted a full pardon
The Silk Road run by Ross Ulbricht did not have assassins on it, nor did it have any human trafficking on it.

I support your right to disagree with the pardon. But please don't recklessly post disinformation like that.

honestSysAdmin··on 0-click deanonymization attack targeting Signal, Discord, other platforms
I guess I'm not so "crazy" for funneling all my Android's outbound traffic through a VPN that does two hops.
honestSysAdmin··on More than half of U.S. counties have no or limited access to local news (2023)
A lot of people in the U.S. are not happy with the corporation that was running a lot of local news stations. This isn't the 1990s, we have broadband internet now. Everybody knows.

  https://rumble.com/v593bca-sinclairs-soldiers-in-trumps-war-on-media.html
honestSysAdmin··on TikTok says it is restoring service for U.S. users
A little bit difficult to get the president elect who is to be inaugurated today (the 20th) when that same president elect in his own words reasonably believes that the 2020 election was stolen.

I think we're all very certain that a thorough investigation into the 2020 election will clear up any concerns about it.

honestSysAdmin··on I'm a 17-Year-Old TikTok Junkie. I Need This Ban

  I have a problem and it needs to be everyone else's problem too.
honestSysAdmin··on Bypassing disk encryption on systems with automatic TPM2 unlock
Long before UKI was a thing, this kind of attack was prevented by hardcoding into an EFI stub kernel the sha512 hash of a trusted initrd that would verify the cryptographic authenticity of the initrd that did the "heavy lifting" (mounting disks etc).

We have had not just secure boot but had it better on Linux (and other Unix-like) systems for a very long time.

honestSysAdmin··on Ozempic and Wegovy are selected for Medicare's price negotiations

  https://www.vox.com/22553793/gila-monster-lizard-venom-inspired-obesity-drug-semaglutide
honestSysAdmin··on Nevada court shuts down police use of federal loophole for civil forfeiture

  18 U.S. Code § 242 - Deprivation of rights under color of law 
  https://www.law.cornell.edu/uscode/text/18/242
honestSysAdmin··on dnSpyEx: .NET debugger and assembly editor
This looks like an amazingly useful tool. Would be great to see this for other languages.
honestSysAdmin··on Imaging mounted disk volumes under duress (2021)
Since the year 2007, my working assumption is that if data is not on ZFS on physically redundant media that the data has not been successfully saved. And, any machines that don't have ZFS (some RedHat based boxes) should be configured only through Ansible and configured with the intention that all data (including syslogs) is either forwarded somewhere that does have ZFS or is accessed via NFS (backed by ZFS).

Or Ceph Bluestore, which does checksums on physically redundant media. We do N+3 replication because we're lazy.

honestSysAdmin··on Docker Desktop Broken on Mac OS Update for over a Week
What you can do is have a cron job that continuously polls one or more URLs looking for tarballs with Git repos accompanied by GnuPG or Signify signatures. The primary idea is that the tarballs are only unpacked and executed if the signatures are valid and anything received by the machines is only executed after the hashes and signatures are successfully logged, this prevents (or at least documents) any abuse on the part of the IT team. Inside the tarballs are Salt, Ansible, and/or shell commands.

In addition to a cron job, we had an active pubsub listener on each machine to poke this process.

You can do this on macOS too, or at least, modern macOS "should" be able to do this.

We did this on a large fleet of user machines (laptops) running Windows 10/11, macOS, and Linux.

honestSysAdmin··on ZFS 2.3 released with ZFS raidz expansion

  https://openzfs.github.io/openzfs-docs/Getting%20Started/index.html
ZFS runs on all major Linux distros, the source is compiled locally and there is no meaningful license problem. In datacenter and "enterprise" environments we compile ZFS "statically" with other kernel modules all the time.

For over six years now, there is an "experimental" option presented by the graphical Ubuntu installer to install the root filesystem on ZFS. Almost everyone I personally know (just my anecdote) chooses this "experimental" option. There has been an occasion here and there of ZFS snapshots taking up too much space, but other than this there have not been any problems.

I statically compile ZFS into a kernel that intentionally does not support loading modules on some of my personal laptops. My experience has been great, others' mileage may (certainly will) vary.

honestSysAdmin··on Spain proposes 100% tax on homes bought by non-EU residents
Bloated/unnecessary bureaucracy is essential to the bribe collection process.
honestSysAdmin··on Obvious things C should do
Thank you.
← PreviousPage 2 of 3Next →