HNHacker News
TopNewBestAskShowJobs

jbergstroem

1,162 karma · joined November 6, 2013

I like open source and Kenyan coffee.

Check out what I do at https://github.com/jbergstroem.

[ my public key: https://keybase.io/jbergstroem; my proof: https://keybase.io/jbergstroem/sigs/xNH99zh5DSCLJR_hrHtShFLmo8RcAbg79Hs506_5KdI ]

submissionscomments
jbergstroem··on Why I do not like Hugo
I'm happy with the abstraction that https://www.contentful.com/ provides; be it a personal static site or more complex integrations which involves multiple content feeds. You get to define a content model and then just create away [within the limits of said model]. Their pricing is fair too (read: free for most).

Edit: Downside(s) would include that $webmaster has to figure out whether to render content at browser or though "ssr".

jbergstroem··on Nginx 1.13.4
tarball: http://nginx.org/download/nginx-1.13.4.tar.gz (or wait for it to show up in your package manager)

The most notable change is the (new) mirror module which allows you to more transparently pass requests to your backends. Previously, this required modifying headers and potentially request body.

Documentation here: http://nginx.org/en/docs/http/ngx_http_mirror_module.html

jbergstroem··on Git v2.14.0 released
Check fork out. I use it for quick overviews [MacOS only]: https://git-fork.com
jbergstroem··on A survey of BSD kernel vulnerabilities [pdf]
Thanks for these!
jbergstroem··on A survey of BSD kernel vulnerabilities [pdf]
I wonder if the foundation would consider putting money into such a task?
jbergstroem··on Where’s all my CPU and memory gone? The answer: Slack
I noticed this a while back too. Switch to a private chat that only contains text when you tab out of a team and it doesn't hog. I think the "don't draw in inactive windows/tabs" feature implemented in most browsers is missing.
jbergstroem··on Where’s all my CPU and memory gone? The answer: Slack
Used to be some time ago when downloads were ~5-7mb. Nowadays it uses Electron:

/Applications/Slack.app/Contents/Frameworks/Electron Framework.framework/Versions/A/Electron Framework

jbergstroem··on OpenBSD switches the default compiler on amd64 and i386 to clang
Switched roughly two years ago: https://www.gentoo.org/news/2015/08/12/git-migration.html

It was an interesting migration project to follow seeing how the portage tree is huge.

jbergstroem··on Status update from the Reproducible Builds project
Yeah; I've seen both work and developer mindset about this for a long time in bsd-centric mailing-lists. I tried to keep it short here though, seeing how the debian developers have done a great job and didn't want to shift that focus [in this thread].

I think its great that we have come to a point where packagers shift mindset from "it works" to "we can reproduce the results" in more than one package manager.

jbergstroem··on Status update from the Reproducible Builds project
Not just Linux; FreeBSD and NetBSD have been along the ride for a while: https://reproducible-builds.org/who/
jbergstroem··on HTTP/2 Server Push on Netlify
You'd have to handle this in service workers. You want this: https://datatracker.ietf.org/doc/draft-ietf-httpbis-cache-di...
jbergstroem··on Ask HN: What Happened to the Hacker News Colour Scheme?
This picture - making the rounds on reddit - hits the nail on the head: https://cdn1.vox-cdn.com/uploads/chorus_asset/file/4252153/w...
jbergstroem··on Symantec explores selling web certificates business
> It's like buying a burning tyre fire, where's the upside ?

I see it as buying the customer stock with the opportunity of a "fresh start". Rebrand, ensure the that the new organization follows compliance.

jbergstroem··on Final Removal of Trust in WoSign and StartCom Certificates
I can understand how my comment might have come off as somewhat judgmental (to either side) but that was not my intention. The idea was to [without derailing the thread too much] give people interested in certificate issues a relatively quick summary on what has happened and my concern about it.
jbergstroem··on Final Removal of Trust in WoSign and StartCom Certificates
Speaking of removing trust bits; the ever-delayed Symantec saga continues with no clear decision.

What concerns me is:

- the lack of public communication, as shown here (tl;dr: private meetings): https://groups.google.com/forum/#!topic/mozilla.dev.security...

- the contrast between symantec and the mozilla security groups path forward [as well as how its communicated] (https://groups.google.com/d/msg/mozilla.dev.security.policy/..., https://www.symantec.com/connect/blogs/symantec-s-response-g...)

jbergstroem··on Another Ransomware Outbreak Is Going Global
teardrop?
jbergstroem··on Interview with Mikeal Rogers of the Node.js Foundation
Perhaps lesser known: you can find node.js download metrics here: https://nodejs.org/metrics/ - you can also download raw (anonymized) data to draw additional conclusions (link at page).

If you find a bug, feel free to report it with our infra/build team: https://github.com/nodejs/build

jbergstroem··on Escape from systemd
I think this is very well put. The ever-going philosophical debate is about interface complexity (developer vs sysop), not how it actually works.
jbergstroem··on Apple Gives the MacBook and MacBook Pros a Kaby Lake Refresh
Is there a tell on the purchase page about them being kaby lakes? If so, I'm missing it.
jbergstroem··on Apple Announces macOS High Sierra
Mozillas tracker: https://arewefastyet.com
jbergstroem··on MySQL 8.0: Retiring Support for the Query Cache
Out of curiosity: how does people using Wordpress [at somewhat scale] handle layers of cache? Last I used it, relying on the Wordpress cache layer just didn't cover enough cases. The MySQL one "saved" me seeing how Wordpress likes to ask the same question. A lot.
jbergstroem··on How Much Does it Cost to Climb Mount Everest?
I understand you argue about "those internet people", but you also choose to question my motives which I find disrespectful. I'm not climbing for anyone but myself.

For what it's worth, ascending the Andes is what got me into altitude mountaineering in the first place. I'm looking forward to Cho Oyu which will be the first step towards Everest. Seeing how I'm yet to surpass 7000m (Aconcagua in December), it will surely be a test of faith.

jbergstroem··on How Much Does it Cost to Climb Mount Everest?
Is there perhaps a resource where there are "stories" of failed attempts? I'm planning for 2021 and very humbly want to walk in the footsteps of others.
jbergstroem··on FreeBSD January-March 2017 Status Report
I think these are great to read and hope more open source projects follows suit:

1. It allows people to understand where the project is heading (including pace)

2. It acts as sub-project discovery and usually uncovers areas that otherwise likely had been overseen

3. It serves as recruitment; links to each subproject and its members - letting users quickly get engaged should they want to.

jbergstroem··on Remotely Exploitable Type Confusion in Windows 8, 8.1, 10, Windows Server, etc
You are right. That comment was based on this quote:

"The debugging session below was captured after visiting a website that did this:"

In hindsight: It can be interpreted in many ways and my standpoint was too pessimistic/bold from a security standpoint.

jbergstroem··on Remotely Exploitable Type Confusion in Windows 8, 8.1, 10, Windows Server, etc
> Did she? How do you know this?

Left column says: Finder-natashenka

twitter.com/natashenka -> Natalie

I added a "seems" since I wasn't sure, but let me use it again: there sure seems to be a connection.

jbergstroem··on Remotely Exploitable Type Confusion in Windows 8, 8.1, 10, Windows Server, etc
Exploitability Assessment for Latest Software Release: 2 - Exploitation Less Likely

Exploitability Assessment for Older Software Release: 2 - Exploitation Less Likely

Anyone with ideas on how they came to this conclusion? Yes, I read the linked document but felt that the index assessment didn't really reflect that google (Natalie?) seems to have found this "in the wild".

jbergstroem··on Nginx 1.13 released with TLS 1.3 support
I think its because nginx was (and for most, still is) generational [compared to apache] in terms of core features and ease of configuration. I can see how caddy would be the next alternative though: more – "modern" if you may – features (money quote: built-in letsencrypt) but more importantly even simpler configuration.

edit: This is also where your use case makes it easy to see why nginx (or caddy) won't cut it.

jbergstroem··on Caddy 0.10 Released
I would just like to bring up how much I admire the way they want to profit off Caddy[1][2]. Sponsorships and focused development; followed by "remember, caddy is open source". My only feedback would be that they introduce a "$50/mo; my bank is not big enough" for people that wants to endorse their model/software.

Look at nginx, where new functionality is hidden behind a paywall. I don't want to deny them [nginx devs and sales people] their well-deserved money, but it pushes me away.

[1]: https://caddyserver.com/blog/options-for-businesses

[2]: https://caddyserver.com/pricing

jbergstroem··on Moby: An open-source project to advance containerization
Thinking marketing split? Docker is the product you pay for and Moby is "may break, use at own risk".
← PreviousPage 5 of 7Next →