HNHacker News
TopNewBestAskShowJobs

jand

406 karma · joined November 7, 2014

submissionscomments
jand··on Clay PCB Tutorial
> Too many of these projects become viral hits that stop making any progress after the first symbolic success. Cynics would say these projects all too often stop exactly at the point where the actual challenges start.

What can you do to ensure the "real work" can actually be done, more precise paid for? Well, you could demo early in hope to attract coins. Maybe that is happening here.

jand··on Adk-go: code-first Go toolkit for building, evaluating, and deploying AI agents
I have not test-driven adk-go. But if you - like me - have not toyed around with agents until now, there is a readable, nice example in [1] which explains itself.

[1] https://github.com/google/adk-go/tree/main/examples/web

jand··on I took all my projects off the cloud, saving thousands of dollars
This becomes much clearer with a balance sheet in front of you.

What is saving? _Spending less_, that's all. Saving generates no income, it makes you go broke slower.

Independent of the price or the product, you can never save more than factor 1.0 (or 100%).

Wasn't there a guy on TV who wanted to make prices go down 1500%? Same BS, different flavor.

jand··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
Who do you mean with "many people"? Developers who do not care or middle management that oversold features and overcommitted w.r.t. deadlines? Or both? Someone else?
jand··on Secure boot certificate rollover is real but probably won't hurt you
> Even if you don't notice the pot being boiled there are those of us that do.

Tangent: To me that sounds like a reference to the "frog boiling" story. This has been debunked [1], a healthy frog will not remain in a gradually heated pot of water. We need a better analogy for this.

[1] https://en.wikipedia.org/wiki/Boiling_frog

jand··on The EU can be shut down with a few keystrokes
I get your point, but according to [1] ASML was a bad example.

There is no kill switch which might be pressed only under circumstances that may never be "adapted to current situations". So who does said plow belong to?

[1] https://www.bloomberg.com/news/articles/2024-05-21/asml-tsmc...

jand··on Show HN: CSS generator for a high-def glass effect
Are users allowed to copy the referenced egg-shell.png and host it themselves or is this connected to some sort of metric you like to gather?
jand··on Starcloud can’t put a data centre in space at $8.2M in one Starship
And it enjoyed some popularity. [1]

[1] https://en.wikipedia.org/wiki/Beer_boot

jand··on Is GitHub Down?
More than US. From EU i can't even reach https://github.com/<user>/<repo>.
jand··on Bypassing GitHub Actions policies in the dumbest way possible
> I am a bit confused on the "bypass" though. Wouldn't the adversary need push access to the repository to edit the workflow file? So, the portion that needs hardening is ensuring the wrong people do not have access to push files to the repository?

I understand it that way, too. But: Having company-wide policies in place (regarding actions) might be misunderstood/used as a security measure for the company against malicious/sloppy developers.

So documenting or highlighting the behaviour helps the devops guys avoid a wrong sense of security. Not much more.

jand··on MinIO Guts Management Dashboard
The community edition is not robbed of its value by this move. They provide a CLI tool (mc) for those admin tasks which previously could be solved via dashboard.

I have several minio instances deployed to k8s for small to medium, and non-profit projects. Easy to deploy, no problems or outages, yet.

But anecdotally i remember multiple occasions, where a quick tour of the dashboard convinced peers, that minio was the right tool for the job.

From my point of view it is much more questionable, that they "dare" to advertise the paid version with a 96.000 USD p.a. "platform fee" plus additional cost if you use more than 400TB. Small fish need tools, too.

jand··on MIT asks arXiv to withdraw preprint of paper on AI and scientific discovery
> How is this not the same issue?

Although not explicitly stated, i read previous comments as using dick.less@privateequity.com to cancel his personal Netflix account. (Let's say that privateequity.com allowed personal usage of company email.)

I see a difference between accessing an email account and impersonating the previous account holder.

jand··on Don't force your kids to do math
As we are sharing anecdotes:

One of my school math teacher had the same approach in another way: We were expected to use greek letters, not latin ones.

Same reasoning: It showed us kiddos that the letter was insignificant compared to the concept expressed by the letter.

So my take would be: Your friend taught the students for the first time what they were actually doing while handling equations with "a letter in it". That is no problem of algebra in itself. It just means their previous teachers sucked.

jand··on You might not need WebSockets
"Unreliable" is a bit harsh - the problem arises imho not from the websocket ping itself, but from the fact that client-side _and_ server-side need to support the ping/pong frames.
jand··on Thoughts on having SSH allow password authentication from the Internet
sry to be that guy (with a snarky comment):

> Over the 20+ years, I witnessed a few security incidents.

As you said, the attackers who breached your system had ssh root access and you had no chance to detect them.

jand··on Mercure: A WebSocket alternative for server-sent events
> ... because you cannot attach an Authorization: Bearer header to a websocket.

Well, not properly. You can abuse the Sec-Websocket-Protocol header to pass an initial token to the server.

jand··on Mercure: A WebSocket alternative for server-sent events
Was there a specific reason to use AGPL-3.0? Not critizing, just asking.

Tried to read about the license and was greeted by a tl;dr summary of the AGPL-3.0 license [1]. I am no lawyer but my gut tells me that providing such a summary is an invitation to strange disputes. Take care.

[1] https://mercure.rocks/docs/hub/license

jand··on An Analysis of the Performance of WebSockets in Various Programming Languages (2021)
Another option is to have a read-, and a write-pump goroutine associated with each gorilla ws client. I found this useful for gateways wss <--> *.
jand··on The Retreat to Muskworld
> They will still be a game changer for workplace safety.

Sure. The robots could be used to distribute shoes and safety equipment to the less fortunate child laborers around the world.

jand··on EU: Definition of "potential terrorists" opens door to broad information-sharing
"support or engage in terrorist or violent extremist offences"

What constitutes "support"? Hopefully your next government is OK with you back then liking the post of that one organization previously not classified as terroristic.

jand··on NIST to forbid requirement of specific passwords character composition
> 9 Verifiers SHALL verify the entire submitted password...

Is this "don't microwave your hamster"-requirement a result of the bcrypt trouble [1] or how comes?

[1] https://security.stackexchange.com/questions/39849/does-bcry...

jand··on CISA boss: Makers of insecure software are the real cyber villains
> The response has been what's called "safety certification":

This is the most scary part for me. Certifications are mostly bureaucratic sugar and on the other hand very expensive. This seems like a sure way to strangle your startup culture.

If customers require certifications worth millions, nobody can bootstrap a small business without outside capital.

jand··on PgManage: Modern, cross platform graphical database client
Is there an existing comparison between pgManage and pgAdmin somewhere?

At first glance, it seems they serve the same purpose. Am i missing something? (besides the support for some other DBs - but pgManage states to target postgres primarily)

jand··on No Uptime Hosting (2006)
I am not very good at telling jokes.

But even i can tell, that this is low effort. You really get a laugh out of it? Like "hahahaha, they said PHP 5"?

jand··on Kubernetes attacked by patent troll Intellectual Ventures
half-serious question:

What is the omnipresent "defined by a domain name" in the "claims"-section of the patent (see [1]) all about? To me it seems unfit as a defining criterion for a network.

[1] https://portal.unifiedpatents.com/patents/patent/US-7949785-...

jand··on Ask HN: What are your favorite parables, anecdotes, idioms, etc.?
"Was Hans nicht lernt, lernt Hänschen nimmermehr."

german, roughly - "What Hans did not learn, his son will never learn."

It is so obviously wrong as a generalized truth but painfully accurate on occasion. Cool about it: The reaction of others towards this saying is a great signal on their views regarding life, society and education.

jand··on EU doubles down on penalising privacy-friendly and encrypted messaging services
> They will get all the data collected by the service, which is none.

(disclaimer: not rooted in knowledge, but in pessimism)

If the web service / whatever cannot provide the requested data, it would be in violation of the order.

So all you really need are harsh fines for not complying with the order and the problem morphs from a technical one to a business decision.

jand··on Linux Code for “Device Memory TCP” – Network to/from Accelerator RAM
Devmem TCP sounds a lot like direct memory access. Am i mistaken if i think of it as a security nightmare? Do you have by chance any links to security considerations?
jand··on Hunting for Nginx alias traversals in the wild
Even in (the official) docker image, a nginx user is created: (latest, layer 6)

/bin/sh -c set -x && groupadd --system --gid 101 nginx && useradd --system --gid nginx --no-create-home --home /nonexistent --comment "nginx user" --shell /bin/false --uid 101 nginx .....

[1] https://hub.docker.com/layers/library/nginx/latest/images/sh...

jand··on Hunting for Nginx alias traversals in the wild
Please excuse the silly question: Would proper directory and file ownerships not prevent this traversal?

If nginx does not run as root, how can it read other files than the ones explicitly assigned to the nginx user?

Page 1 of 6Next →