HNHacker News
TopNewBestAskShowJobs

isclever

138 karma · joined February 25, 2017

submissionscomments
isclever··on Towards HTTPS by Default
You can buy a domain, put public NS servers on it for the only purpose of doing Letsencrypt DNS validation. Hint: Create root and wildcard (eg domain.ca and *.domain.ca) so you aren't leaking internal DNS records (not that it matters much).

You run an internal DNS server (Pihole + unbound is my combo of choice) which becomes authoritative for your internal LAN.

isclever··on So this guy is now S3. All of S3
Maybe, but the admin commented it was intentional for that specific post, it was slowing down the entire site.
isclever··on Mess with DNS
At least for certificate issuance they can turn it off via a CAA record:

https://en.wikipedia.org/wiki/DNS_Certification_Authority_Au...

isclever··on DNS doesn't “propagate”
Google and Cloudflare allow anybody to expire any record in their cache, handy to have to if you make a mistake that is affecting customers.

Google's 8.8.8.8: https://developers.google.com/speed/public-dns/cache

Cloudflare's 1.1.1.1: https://1.1.1.1/purge-cache/

isclever··on Btop++ is a power resource monitor for Linux
This is why I have trust issues when github pulling or exploding a tar.
isclever··on Serving Netflix Video at 400Gb/s on FreeBSD [pdf]
Go to fast.com, open webdev tools on the network tab. Run a speedtest, the hosts are the local caches (OpenConnect) that you would use to stream movies.

Note: I don't know for sure, but its the most likely.

isclever··on Whistleblower: Ubiquiti Breach “Catastrophic”
This boggles me when I see this option in any password manager (and I think every single one has this 'option').

Why do password managers let people store TOTP next to the password, this completely invalidates the 2FA of TOTP if your password manager get broken into.

isclever··on This electrical transmission tower has a problem
Try this: https://threadreaderapp.com/thread/1306359385656946688.html
isclever··on IBM Cloud was down, as well as their status page
It happens a lot, when you have so much infrastructure and redundancy you think it is too big to fail. Then you lose S3 in US-East1 and break everything.

https://www.theregister.com/2017/03/01/aws_s3_outage/

isclever··on Netflix urged by EU to slow streaming to save internet
Netflix is open to any peering, some ISPs are not: https://techcrunch.com/2014/07/29/netflix-and-att-sign-peeri...
isclever··on A man launched a new ISP from his garage (2018) [video]
For Canada, specifically Bell, they both an eye ball network and a transit provider. Bell has no incentive to peer at local IXs and "give away" part of their service (the eyes, as that is the lucrative part) when they can sell on the fact they are a large national network AND you can get access to their end customers as well.

Edit: clarification on the part that is more valuable.

isclever··on Cloudflare silently deleted my DNS records
A domain registered at a provider (but not DNS) can be down with no impact to your domain, so long as the domain is still in the TLD root servers, everything will keep going.
isclever··on Cloudflare silently deleted my DNS records
Here is a good list: https://github.com/n1trux/awesome-sysadmin#monitoring

Maybe one fits what you are looking for.

isclever··on Cloudflare silently deleted my DNS records
My takeaway:

1. Setup up monitoring on your critical domains. UptimeRobot and Hetrixtools are good starters with generous free tier. You should know when your website/email/dns isn't working.

2. Don't tie your domain registration with your DNS provider. You lose everything if something goes wrong with your account.

3. Be able to jump ship easily, have backups of your zone, already know where you will transfer to.

isclever··on Apple Edge Cache
There is also https://qwilt.com/ which is more of an open(?) local cache servers for ISPs.
isclever··on Netgear Signed TLS Cert Private Key Disclosure
mini-app.funjsq.com is revoked (https://decoder.link/result/418b8d20793d3f4daa4153752e45e78b...), can't check routerlogin.net/com as they didn't paste the public cert.
isclever··on Mail a Letter Online
You need to get on the HTTPS bandwagon as well https://doesmysiteneedhttps.com/
isclever··on Warren Buffett's Annual Letter to Berkshire Hathaway Shareholders [pdf]
My personal view of using Wealthsimple is a stepping stone, I've realise that I've throw away money to the banks with higher then needed MERs and Wealthsimple provide a easy way of transferring my money in and saving money now. When my portfolio is larger and I'm seeing a higher cost with them VS doing it myself I'll look into buying ETFs myself.

The lowest bank mutual fund in Canada that I've seen in from Tangerine at ~1% MER, are there ones lower?

isclever··on Warren Buffett's Annual Letter to Berkshire Hathaway Shareholders [pdf]
Not only do you get on average better returns, you can do better even when they perform poorly since those funds (in Canada) can charge you anywhere from 1.5% to 3% of your portfolio in fees (MER), while an index fund could charge as low as 0.1%.

https://www.wealthsimple.com/ (I'm a customer) has recently expanded into the US from Canada and are one of a group of what is being called Roboinvestors which take these index funds and let you easily invest in them.

Wealthsimple adds on 0.5% fee which is still lower then active funds, my portfolio has a weighted MER of 0.64%.