HNHacker News
TopNewBestAskShowJobs

jackalope

571 karma · joined January 1, 2012

submissionscomments
jackalope··on Old-school desktop using Debian Jessie
"mpg123 has no controls..."

It does with the -C option:

    -C, --control
        Enable  terminal control keys. By default use 's' or the space bar to
        stop/restart (pause, unpause) playback, 'f' to jump forward to the next
        song, 'b' to jump back to the beginning of the song, ',' to rewind, '.'
        to fast forward, and  'q'  to quit.  Type 'h' for a full list of
        available controls.
It's actually a very competent player, even able to play streams. Mplayer and cmus are also very good for audio playback in a minimalist environment.
jackalope··on Show HN: What's My Chain Cert?
Doesn't it seem that configuration is needlessly complex for certificates? I think it would be easier to list the entire chain in one directive:

    TLSCertificates /path/to/host.crt /path/to/intermediate.crt /path/to/root.crt
That would support any number of intermediates and remove the need to concatenate certificates into a single file. Terminating with the root certificate would be optional, but if present the server could perform a check to verify the chain to the very end when starting.
jackalope··on Are You a Robot? Introducing “No CAPTCHA ReCAPTCHA”
I'm guessing your third sentence triggered a penalty. Replace "current captchas" with a blank and you'll see why.

I agree that the reCAPTCHA experience is terrible and assume many others agree with you, in part spurring the development of this new approach. I don't believe that every reCAPTCHA has a solution, or at least a consistent one, so I always feel like a percentage of time wasting is built-in. To work around it, I usually regenerate it until I get one that looks easy, but it's still frustrating. Improving the odds of getting it right the first time will help improve the experience a bit. But my biggest gripe is that they can make direct downloads impossible for resources that don't require extra protection.

jackalope··on Are You a Robot? Introducing “No CAPTCHA ReCAPTCHA”
I always assumed Google's use of reCAPTCHA was to augment the OCR used to digitize Google Books, particularly in results the software couldn't confidently match to a word. Is this true? It's interesting that it's still the fallback for the new method.
jackalope··on Linux kernel coding style
"Get a decent editor and don't leave whitespace at the end of lines."

Trailing whitespace always raises a huge red flag for me whenever I look at someone's code. It's not just sloppy, it often makes diff output so noisy you can't detect real changes to the code.

jackalope··on High-DPI displays and Linux
I thought the whole point of High-DPI was to was to free us from the need to render graphics pixel-perfect at native resolution. While scaling bitmaps will probably be necessary for photographs and most video for a long time, can't everything else be rendered using SVG? Does such an environment already exist?
jackalope··on EIZO Announces Monitor with 1920x1920 Resolution
I've just set up 3 different work areas consisting of laptops with external second monitors. I've settled on the configuration having the external monitor above the laptop display as being the most optimum. I find that I never need to move my neck to glance from one screen to the other, and only require a slight tilt at the waist to comfortably switch for longer periods. Contrast this to a side-by-side configuration, where it feels awkward to merely shift my eyes sideways, so I move my neck more. This in itself isn't so bad, until I need to focus on one screen that's off-center for prolonged periods, keeping my head in an awkward angle that doesn't seem healthy. Naturally, any configuration should still be augmented with regular stretching/activity breaks.

tl;dr: Vertical: Mostly eye movement. Horizontal: Lots of neck movement.

jackalope··on Launching in 2015: A Certificate Authority to Encrypt the Entire Web
I'd still be more comfortable if the process never went anywhere near the private key (and I'm concerned that a proprietary competitor or look-alike would prey on naive users by leveraging your example). But I also applaud your effort and transparency. I admit I trust openssl to manage my own keys and certificates, and there is definitely room in this space for improvement and alternative approaches. But it does sadden me that we risk making administrators as trusting and ignorant of the underlying principles as end users already are today.
jackalope··on Launching in 2015: A Certificate Authority to Encrypt the Entire Web
My concern is that your reach is too far. Asking domain administrators to trust your software to manipulate private keys (and server configurations) is as troubling as asking end users to click past security warnings. The whole purpose of the CSR is to obtain the signed certificate without putting the private key at risk. This decoupling isolates the challenge of identity verification in a reasonable place (nobody is saying it's easy). With your client, you're essentially telling people you accept checks or credit cards, but only if they show you their gold. It sets a bad precedent.

I do want your certs for free! But I also want/need to trust you and know that you're following best practices, not just with me but with everyone.

jackalope··on Launching in 2015: A Certificate Authority to Encrypt the Entire Web
There is no reason for the CA to ever see the private key. All they need is a CSR. This approach is fundamentally broken.
jackalope··on Launching in 2015: A Certificate Authority to Encrypt the Entire Web
I run Apache httpd, and there's no way I'd let a wizard anywhere near my configuration files or private keys, much less run it on a production server.

I think it's about time for a free CA that is recognized by all clients, but you still need to establish a trust chain to exchange a CSR for a signed certificate. This service needs to be server agnostic. The barrier to adoption isn't configuration, and HTTPS isn't the only thing that uses certificates.

jackalope··on My favourite Zsh features
I have this to use the arrow keys without any modifier:

    # Use up/down arrows to search on partially typed command
    bind '"\e[A"':history-search-backward
    bind '"\e[B"':history-search-forward
Just type the first letter(s) and use the up/down arrows to scroll through the filtered command history. Incredibly convenient.
jackalope··on How many of you use a Linux distro as your primary desktop OS?
I use Slackware and run stock dwm as my window manager.

Once I tweak it to my preferences, I never have to think about it again. My configuration is portable to different versions, different distributions, and even different *NIXes to a large degree. Once in place, the system stays out of my way and I can focus on the task at hand. I used to keep an Arch Linux box around to keep up on the latest versions of things, but I got tired of the constant updating and breakage.

I also use Macs, relying heavily on homebrew (MacPorts before that), but the experience isn't as seamless as it is on Linux. OS X is a great consumer OS, though, so that's what I set my family up with.

I can't get anything done on Windows. I feel like I spend more time maintaining it than using it. The updates are disruptive and kill performance, the endless notifications are annoying and often meaningless, and the interface is byzantine. I haven't tried Windows 8, but I'm curious about it since I love my Windows phone.

Since I'm very keyboard-centric, I doubt that Mac or Windows will change in a direction that interests me. I've been thinking about trying out a ChromeBook because of the instant-on capability. If I don't like it, I'll just wipe it and install Linux (which is another reason I love Linux: I can easily repurpose old or odd hardware).

jackalope··on Google’s Chromebooks Rule Schools as IDC Pegs Them as Top Sellers in K-12
I think it's fair to say that if your kid comes home with a ChromeBook that you didn't purchase, it's being subsidized somewhere. My local high school just issued them to all freshmen. What I find a bit odd is that if there is any paperwork involved, it's not "Do you give us permission to lend a laptop to your child?", it's "Your child must sign this pledge not to abuse this device." I support the program, but the responsibility goes two ways, and I expect the school district to advocate student privacy over the lure of "free stuff."
jackalope··on Gow – The lightweight alternative to Cygwin
When I used to install Cygwin, it was to get (in order of importance): ssh, vim, rsync & X11. Gow doesn't include the last two, so it feels like an apples/oranges comparison (for my use case). Still, it's pretty amazing what Windows doesn't include by default in this day and age, so a simple, lightweight set of tools like this definitely has its place.

I don't use Windows anymore, but if I did, I would probably just spin up a VM with a tiny live Linux ISO, because it would bring in so much other goodness without any extra effort.

jackalope··on Microsoft Band
There are times I wish I could leave GPS tracking on all the time, with a simple way to add markers either now or later, and with the ability to share the data with any app I want. There are times I just want to hop on my bike and ride without doing some dance with a finicky GPS app that I have to remember to stop at the end (and hope it doesn't crash during my ride).
jackalope··on A Unix-style mail setup (2012)
Mutt has had excellent built-in SMTP/IMAP/POP3 support for years. I'm always surprised to see guides suggesting helpers like msmtp, offlineimap, etc. And with a few macros and save-hooks that you'll only write once, you'll have a fast, flexible mail client that will beat nearly any GUI client in mail processing speed.
jackalope··on Pgweb: Web-based PostgreSQL database browser written in Go
Vim users might consider the dbext plugin: http://vim.sourceforge.net/scripts/script.php?script_id=356

It supports a long list of databases, a variety of common development languages, has a command history, prompts for variables in statements, and more features I haven't touched. As a Vim plugin, it's fairly light on the CPU, but with all the expressive power you expect from Vim (including syntax formatting/highlighting and the availability of your other favorite plugins). I like it because I can dedicate a plaintext file to a specific task, develop my queries, save my results, and come back to it at a later date if the need arises. Some of these files are an important part of my workflow. The only thing I'd change is a more secure handling of login credentials, but it sure beats the standard command line tools bundled with most databases and requires less overhead than the GUI or web-based ones.

jackalope··on The Fire Phone Is Officially a Failure
Surprise, that's a software-based feature you could build for just about any phone.

That's an interesting comment. Isn't "phone" a software based feature you could build for just about any computer? I wonder if a fully featured general purpose mobile computer and ubiquitous wifi could make smartphones a thing of the past...

jackalope··on Using GNU Stow to manage your dotfiles
You can do something similar to target *nix platforms like Darwin|FreeBSD|Linux|NetBSD|OpenBSD with:

  if [ -f ~/config/bashrc_$(uname -s) ]; then
      source ~/config/bashrc_$(uname -s)
  fi
jackalope··on Using GNU Stow to manage your dotfiles
I prefer dedicated repositories (I use mercurial) for each app (vim, mutt, etc.) or context (X11) that include Makefiles for creating the necessary links or handling some environment-specific details. This still allows me to cherry pick what I want on each machine, but keeps the commit history in the appropriate repo.
jackalope··on FFS SSL
That's ridiculous. There are plenty of ways to lose a private key that doesn't involve or lead to compromise.

I generate and store my private keys in my secure CA environment and copy them to the server. If I ever need to redeploy them or generate a new CSR (SHA-2 anyone?), I can do it without ever logging into the server.

jackalope··on Interview: Thomas Voß of Mir
Indeed. In fact, that's one of the reasons I switched to Windows Phone 8: It was the closest I could get to the linux+dwm environment where I do most of my computing. Why would anyone want a desktop metaphor on a phone, complete with tiny icons and illegible drop-shadowed text?
jackalope··on This POODLE bites: exploiting the SSL 3.0 fallback
With name-based virtual hosts (those that rely on the server selecting the appropriate resource based on the Host header), typical clients depend on the IP address returned by DNS for that host. If they visit that IP, ask for the host, and the server isn't configured to deliver that host's resources, it's good practice to give the client an error. Since the web server has to listen on that IP without knowing which host will be requested before the connection is made, it's convenient to have a fallback and handle errors there. I deny all access to the default host, which generates a 403 Forbidden error (with a custom message), but there are definitely other ways to deal with this situation.

The important thing is that a host's protected resources are served only when SSL/TLS is properly negotiated. Serving one host's content as the default when another host was requested violates this.

In practice, nearly all of these requests come from bots, crawlers and penetration testers. So another advantage is that the log entries can be used to block further requests at the firewall, freeing resources and even possibly protecting the server from undisclosed vulnerabilities (test this approach carefully to make sure it's appropriate for your site and doesn't subject you to a DoS).

jackalope··on This POODLE bites: exploiting the SSL 3.0 fallback
Or better yet, don't serve any content from the default. I actually return a 403 error for the default host or any request without a Host header.
jackalope··on Bash 'shellshock' scan of the Internet
The shellshock scan is setting the Host header, which might set the SERVER_NAME CGI variable in some environments and is not included in the Common Log Format or widely used Combined Log Format (which adds the Referer and User-Agent). For example, Apache's httpd directive UseCanonicalName is set to "off" by default, allowing the client to set SERVER_NAME via the Host header, possibly passing it to vulnerable scripts.

Furthermore, an admin might use directives to log the requested host in a name-based virtual hosting environment to facilitate parsing. For example, when using Apache's httpd LogFormat/CustomLog directives, if "%V" is used as the format string and UseCanonicalName is set to "off", the string provided by the client in the Host header will be written to the log. Naive parsers might choke on this or even execute the code. If the shellshock scan results in a delayed surge of pings from a single host, this is likely to be the cause.

jackalope··on Passwords in plain text
How is downloading a key pair generated by someone else safer? If this is only for login purposes (I don't use AWS, so maybe there is another reason), you should generate your own key pair and send them only your public key (which doesn't require an encrypted transfer, BTW). If AWS knows your private key and can view it or provide it to you at anytime, that's no different than storing passwords in plaintext.
jackalope··on The SSD Endurance Experiment: Casualties on the way to a petabyte
I'd like to see the same kind of test with identical drives mirrored (RAID 1 or another suitable way to precisely duplicate disk I/O). One of the things I've always wondered is if two SSDs from the same lot are more likely to fail at the same time. It's not unusual to have such an arrangement in a newly deployed server. Longevity is (more than) nice, but simultaneous failure is still a disaster, whenever it happens. Does it make sense to provision drives that don't match exactly (in age, manufacturer, etc.) in order to avoid potential issues?
jackalope··on Visualisation of the expansion of IKEA
It frustrates me that even as they expand, they seem to have a distribution model that is one-way-only. If your local store doesn't have an item, you can locate the stores that have it, but they won't send it to the store nearest you. You can order items online, but you can't pick them up at a local store to save on the outrageously high shipping fees. This is even more frustrating when the item is unavailable online, but is sitting in another store 200 miles away. Can't they toss it on a truck for redistribution?
jackalope··on The Questionable Link Between Saturated Fat and Heart Disease
I find it fascinating that:

The very cornerstone of dietary advice for generations..."

...is being challenged because:

Critics have pointed out that Dr. Keys violated several basic scientific norms in his study.

It's a cautionary tale worth telling no matter the discipline. Studies are often accepted without much challenge because we assume that rigorous controls were in place. But the adage of "Garbage in, garbage out" remains a fundamental truth. I think that is what is relevant and interesting to HN readers.

Page 1 of 9Next →