HNHacker News
TopNewBestAskShowJobs

juriansluiman

170 karma · joined January 3, 2013

Dutch entrepreneur and occasional blogger at juriansluiman.nl

[ my public key: https://keybase.io/jurian; my proof: https://keybase.io/jurian/sigs/2jlFRm8JMzToO0V9-LL2AfUUrPfN85ZZP49Nt1gwljE ]

submissionscomments
juriansluiman··on Ask HN: How do small personal website/blog owners comply with GDPR?
My personal website [0] is -afaik- GDPR compliant. I have access logs disabled, as I don't care about them. It's a static site (Hugo) deployed as container with an nginx server behind Traefik.

I don't use comment forms, as they are a headache to maintain over the years. I used to have comments but removed them and discussions move to other media (HN, Twitter, Reddit). For analytics I use Plausible [1], self-hosted, and that's fully GDPR compliant.

I live in the EU (NL) and the server is located in AMS3 for DO. This setup runs perfectly fine for me for several years now.

  [0] https://jurian.slui.mn/
  [1] https://plausible.io/
juriansluiman··on I received a patent infringement email for my weekend project (2010)
Part 2: https://www.royvanrijn.com/blog/2010/11/patent-infrigement-p... TL;DR:

> I’m sorry, but I can’t comply.

> Good luck.

The follow up around 2016: https://twitter.com/royvanrijn/status/788436253532426241

> Nothing happened, never heard from them again...

I couldn't find the code anywhere on his Github profile, so not sure if he actually took the step to publish the code.

juriansluiman··on Podman can transfer container images without a registry
Actually it's the process how I (DIY) deploy several static sites from my local machine. I build the Docker image (hugo sites with nginx, expose a single port for HTTP traffic) and save it as tar. Ironically the base images do come from a registry, but I can't deploy to a public registry and don't want to host my own.

On the server where I need to run that site, I just transfer the tar, load the image and run the docker image. It's so straightforward I much more prefer this way than being dependant on external registry sites for deployments.

juriansluiman··on You can now send replies from your Duck Addresses
The biggest missing feature on Masked Email by Fastmail is they don't remove trackers, as far as I know.

Masked Email gives you more privacy (the identity behind the receiver is unknown) and with data breaches, there's is no login data leaked.

Duck's Email Protection does also remove trackers from the forwarded mails. So senders can't trace back whether you have opened the mail. I hope they also remove click trackers, but I am unsure how they would implement that technology with the referral codes in the URL.

juriansluiman··on Issue with TLS-ALPN-01 Validation Method
As my Traefik setup is affected, I cleared the `acme.json` and let Traefik get new certificates for all services.

Seems LE is pretty busy right now, got time outs flying around every where.

juriansluiman··on Ask HN: Good open source alternatives to Google Analytics?
As stated by others already, there's Plausible (plausible.io) and Matomo (matomo.org).

I have used both and stuck at Plausible. A few reasons (subjective):

1. Plausible is GDPR compliant by default, it has an effective way to measure analytics throughout the day without cookies

2. It is simple and that's key. I don't need to know much, Plausible just gives me that

3. It's fairly lightweight. Matomo is quite heavy and as my VPS'es are pretty much scaled down, less is just more

4. The Plausible self-hosting doc is centered around Docker, which is the architecture I use myself and is set up in literally a few minutes

juriansluiman··on Bitwarden Send - A trusted way to securely share information with anyone
I have done exactly the same more than a year ago. Couldn't be happier. The bitwardenrs server is extremely lightweight so it runs with almost no resources.

Please consider bitwardenrs is a 3rd party implementation, indeed community led, so it lags several features which have been introduced by Bitwarden itself.

See the full list of feature requests in the Rust implementation here [1], but the two things I'll miss most are Emergency Access and now this feature called Bitwarden Send.

[1]: https://github.com/dani-garcia/bitwarden_rs/issues/246

juriansluiman··on LastPass Android app has got 7 trackers in it
> Autofill is relatively poor (it fails even on HN!).

Autofill is much more customizable than LastPass afaik. You can both define how (domain)name matching should occur as you can have multiple entries to match.

This means you can have instagram.com (as website) and androidapp://com.instagram.android (as app) which will use the same autofill entry.

If you configure name matching correctly, any site should be able to provide autofill. My HN entry does match with news.ycombinator.com with default matching settings. But matching settings include hostname / domain name / starts with and even regex!

> Also, Lastpass has a convenient timed expiry that doesn't work (well) on Bitwarden (BW will expire the login when the browser is closed).

You can specify BW timeout settings. Even further, you can define if BW should lock the session (only a password is required to unlock) or if a sign-out is required. With a sign-out, you also need to provide your MFA if applicable.

Time outs can happen directly (after autofill), after an amount of time (1/5/15/30 minutes or 1/4 hours) or upon closing the browser.

So tbh, there is plenty to configure Bitwarden to suit your needs.

juriansluiman··on Blog with Markdown and Git, and degrade gracefully through time
> The real reason most websites disappear is a much more human one.

So true.

I have had a blog running since 2006, all was php based back then with (html) posts inside a database. The tooling shouldn't be a problem, I switched systems several times (once every few years).

Currently on Hugo with markdown posts. As long as you treat your migration carefully and take some time to migrate, every tool should suffice. It's mostly about human effort and human error when things get lost.

juriansluiman··on Secure your MQTT server with authentication and encryption
(Author here)

I run it to communicate with much more applications. It just depends on your own preferences. For example, some tools provide an API (local or cloud based) and you can directly plug in into that API. In The Netherlands you can read your electricity meter yourself by a "Dutch Smart Meter Readings" and DSMR integrates into Home Assistant with MQTT. I use Z-Wave as wireless mesh technology for lights and switches, the Z-Wave controller integrates into Home Assistant with MQTT.

MQTT is so easy to setup and configure, you can use it for any messaging you want. As an example, I run Home Assistant locally to run my home automations, but also check the status of my local devices and online servers (Digital Ocean droplets). One use case is my backup script which publishes the backup results to an online MQTT server, my Home Assistant checks the topics at that server to display backup stats locally. If something went wrong, Home Assistant notifies my directly. PS. The backup script also sends out e-mails which I filter in Fastmail, the success mails are trashed and only error messages are kept in the inbox ;)

juriansluiman··on Secure your MQTT server with authentication and encryption
You're totally right. Although in my experience this is much easier to maintain with "upstream root certificates" (not sure how you'd call them) then self-signed certs. Applications like Home Assistant are already TLS aware and simply trust all root certs which are available on the host. With self signed certs, you have to distribute them all by yourself.

Besides this trade-off, you have to check all clients to be TLS aware on beforehand. In my setup, all clients were capable of TLS. The only hassle are my NodeMCU devices which need to swap the WifiClient to a WifiSSLClient and you need to embed the public DST Root CA X3 yourselves.

juriansluiman··on Secure your MQTT server with authentication and encryption
Author here:

That's exactly what this post does only with Traefik instead of haproxy. The TLS of Mosquitto is just too much of a maintenance burden.

A cross post from what I replied at a Reddit topic:

> Mosquitto does have TLS support by itself, but the manual only deals with self-signed certificates. Self-signed certificates do involve a maintenance burden I don't want to deal with. All my applications/devices which expose a HTTP frontend (or other TCP stream) are encrypted via Let's Enncrypt certificates. They are automatically trusted by a lot of platforms (pc's, phones and other devices).

> I was using acme.sh before and the post-install hook can refresh every service, but it just wasn't working properly on every occasion. You also have to reload all your applications for loading the new certs (that is, Home Assistant, Unifi, Pi-hole, mosquitto, my smart meter readings platform and so on). Just reloading everything for a cert renew felt cumbersome, and Traefik dealing with TLS termination decouples the TLS part from the application itself.

> Since I used Traefik already, it was really straightforward to put Mosquitto behind Traefik too. Of course every situation is different, this post is mainly geared towards users which do not authenticate or encrypt Mosquitto at all.

juriansluiman··on Ask HN: What's your quarantine side project?
I started groceri.es (https://groceri.es), a recipe manager and smart shopping list in one. Its goal is a combination of paprika (https://paprikaapp.com) and Listonic (https://listonic.com).

I was continuously fighting my recipe planning. I did it for a long time in Google Keep. I can't manage recipes there, I have to add items to the shopping list manually. Changes in menu planning don't keep up with the shopping list, I forget to check the pantry. Etc. This time looked right to create something to mitigate the frustrations.

The technology is quite simple, it is a CRUD app in Flask with SQL backend. Everything is a docker container with data in a volume. UX is now quite limited, based on Fomantic UI. There is no goal to make it Saas, for friends I will just spin up a second instance.

I have been a software engineer for over a decade, but haven't been programming the last 5 years. Besides I am a fanatic home cook. So this looked like the perfect opportunity to have some fun again.

juriansluiman··on Static Sites with Elasticsearch
Yes. I have a Google Custom Search engine which I dispatch via javascript. It just displays the results formatted from a json list. It is just a matter of preference, since DDG can't integrate search with an API as far as I know.
juriansluiman··on An alternative to using Google Analytics on your website
They have a version "Fathom lite" which is nowhere mentioned on their site (anymore?). You can get it from Github though:

https://github.com/usefathom/fathom

juriansluiman··on Mycroft – An open-source voice assistant
Mycroft as software is used by a small group of users and seems pretty stable. More features are continuously added and the design principles look promising (open source, as private as possible).

The biggest problem is their hardware: they have a Mycroft v1, (to me personally) a prototype alike piece of hardware. There have been successful campaigns for a v2 release, with new hardware and an improved design.

However, they fail to work with reliable partners and there's still no working device which resembles the final production level. I have been a backer of the indigogo campaign but it's frustrating they postpone their Mycroft v2 every time again. I really hope the can deliver the device at some point, but they keep rewriting software and if they ship, the hardware is pretty outdated probably.

juriansluiman··on Google's Abandoned Android Authenticator App
Yes but that's a whole different 2FA implementation, where sites must support U2F (webauthn). Unfortunately, the implementation of TOTP is far more common than U2F.

Ideally all sites will implement U2F as two factor authentication, but there aren't that many users who have a U2F compatible token. The reach of TOTP is far more beyond U2F, which is probably why sites use TOTP more than U2F.

When sites offer both, choose U2F. When sites offer TOTP only, use it. It is better than nothing. When you have a yubikey already, use the Yubico authenticator app to store the TOTP secret to make your TOTP attack surface less and to have the availability to change your phone without losing TOTP secrets.

juriansluiman··on Google's Abandoned Android Authenticator App
Because usually the server sends the shared secret and there are just 32 slots for shared secrets available.
juriansluiman··on AWS now supports U2F/Yubikeys
Use the Yubico Authenticator app. The main difference is the (secured) storaged of the shared secret. With Google Authenticator, your keys are stored on the phone.

With Yubico's authenticator, you store the secrets ontp your Yubikey. This means you can reset your phone and still be able to use the same TOTP shared secrets. Or if that matters, ask a friend to install the app and use your Yubikeys to get the TOTP.

juriansluiman··on November Workshop: Running the Pi-hole Network-wide Ad-blocker, and more
PiHole is a fantastic system and works really well.

The only issue I have is its installer works on a bare system. I prefer to use the Pi as a multi purpose system: for home-assistent, as unifi controller and for pi-hole. It will costs you some time to get it running with all the pi-hole features (auto update and so on) operational.

juriansluiman··on Nylas Mail is now free
The app looks great, but I just am not in favor of piping everything I have with email through your servers. Just a standalone app as basic version with opt-in for Google OAUth would justify its use case.
juriansluiman··on Python Versions Used in Commercial Projects, 2016 Edition
Afaik, it has nothing to do with Ubuntu or any other Linux distro specifically, but this is rather a choice from python itself. See PEP394 [1]:

"for the time being, all distributions should ensure that python refers to the same target as python2."

I read above as the python community itself made "python" the default for python 2.7 and "python3" for python 3.x. Nevertheless, an unfortunate choice at this time. I understand the reasoning at the time of writing (March 2011) but now this should be reconsidered.

    [1] https://www.python.org/dev/peps/pep-0394/
juriansluiman··on Lodash 4.0.0 is out
I loved bower and really preferred it in regard with npm for frontend modules. However more and more packages went to npm-only and we completely switched to npm for all.

Looking back, I am glad since it's just a nightmare to deal with dozens of package managers. Because bower was installed via npm, we had npm installed already and just skipped the bower part.

juriansluiman··on Ask HN: What's your favorite “read later” web tool?
Expecting a discussion or just a poll?

Anyhow, I prefer pocket. I have a Kobo ereader and it has perfect integration with pocket. Every article I receive on my phone, laptop, tablet or get send via email, I read via the ereader. It just works great.

Perhaps to mention, I am not using any of the tagging features. It just takes more time to categorize than scrolling a list.

juriansluiman··on Only 3 northern white rhinos left on Earth
There are two species of white rhinos: southern and northern.

The southern [0] has one horn and there are an estimate of 20,400+ alive in the wild. Although they are still quite rare, they are considered the most common and widespread rhino.

The northern [1] white rhino is the one mentioned in this article and is much, much more rare. There are now only three individuals alive. I haven't found any confirmation, but I thought the northern was more popular by poachers because of the two large sized horns, instead of a large and small one from the southern rhino.

All in all, very sad we came to the point human beings have (almost, for now) killed yet another species.

[0] https://en.wikipedia.org/wiki/Southern_white_rhinoceros

[1] https://en.wikipedia.org/wiki/Northern_white_rhinoceros

juriansluiman··on Ruby gaining a safe navigation operator: '.?'
That's where the coalesce operator ("??") is for. Exactly to suppress the warning and avoid verbose isset() calls:

    echo $foo['a']['b'] ?? 'default_value';
juriansluiman··on Typeset.js – A ty­po­graphic pre-proces­sor for HTML
I have used a similar tool [1] some time ago in PHP. The project hasn't been kept updated, but the idea of processing text/HTML and converting the right entities is pretty neat. At least the readability improves massively.

This project Typeset.js is slightly different as it adds additional markup and styles. For me, converting here's to here’s was enough for me back then.

[1]: https://github.com/scoates/lexentity

juriansluiman··on UI Design Dos and Don'ts
I just see it as pointing where I'd like the hands of a clock. The only learning curve I had is the difference between 10:00 and 22:00 (or likewise, between AM and PM).
juriansluiman··on UI Design Dos and Don'ts
Android has a simple calendar which you can swipe to change the month. Click on the year and a year selection is shown.

The time is a clock where you're able to select the hour first and minutes thereafter. This is the most intuitive mobile touch interface I have seen so far, any other is really small, awkward or not mentally easy to comprehend.

Image: https://raw.githubusercontent.com/CiTuX/datetimepicker/maste...

juriansluiman··on Passwordless login done right
> Basically, this is an extremely secure, 2 form factor, idiot proof login system

As far as I know, factors are

1. Something you know (password)

2. Something you have (a dongle or phone)

3. Something you are (iris or fingerprint)

With only pressing a button on a phone, how can this be two-factor? There is no password ("passwords are obsolete" and usernames are not a knowledge factor in multi auth) and nothing of biometrics. Am I missing something?

By the way, not entering passwords is a fantastic way to login. I have been using the Passwordless [1] method for some time and it works great.

[1]: https://passwordless.net/

Page 1 of 2Next →