HNHacker News
TopNewBestAskShowJobs

kassner

474 karma · joined July 8, 2013

submissionscomments
kassner··on CSRF protection without tokens or hidden form fields
Exactly.
kassner··on BYD's Engine Flexes Between Ethanol, Gasoline, and Electricity
Any car in Brazil already has to cope with a high ethanol mix (it’s now 30%, with plans for 35%), so not sure how they are making something “more accessible” when everything else in the market already has it.

Do they have some innovative measuring system? A better way to switch between ICE and electric based on emissions/cost/range?

kassner··on Quad9 DOH HTTP/1.1 Retirement, December 15, 2025
I’d say nowadays 443/tcp is the only port that you’ll find open in any usable network, anything else is part of a corporate network whack-a-mole game. So while DoH and DoT traffic shouldn’t be distinguishable, 853/tcp is surely a weird port in the grand scheme of things.
kassner··on Decreasing Certificate Lifetimes to 45 Days
Thank you for writing it!

> What you're doing right now makes sense for your scale, IMO

Absolutely. I use DNS validation, and I’m fine running it manually every quarter, but I’m sure I’ll be quite annoyed to have to do it every month.

kassner··on Decreasing Certificate Lifetimes to 45 Days
In my case is multiple servers handling the same FQDN. They are load balanced via DNS or use DNS anycast in some situations. In any case, my server is the one terminating TLS.
kassner··on Decreasing Certificate Lifetimes to 45 Days
How do people here deal with distributed websites? I’m currently issuing one certificate on my machine and then Ansible-ing it into all the servers. I could issue one certificate for each server, but then at any given time I’d have dozens of certs for the same domain, and all must be valid. That doesn’t sound right either.
kassner··on WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]
Agreed. My experience was pre-Matt drama, and even then the boundary between wp.org and Automattic was quite unclear.
kassner··on WordPress plugin quirk resulted in UK Gov OBR Budget leak [pdf]
TBF there is some scrutiny on existing plugins, the team is just extremely understaffed (it’s ran by volunteers after all). I got involved in a plugin that ended up getting de-listed for some minor ToS violations after several years of being “fine”, they re-reviewed the plugin with the same rigor as a new submission.
kassner··on Self-hosting a Matrix server for 5 years
> you can't correct a typo in a sent message in Delta

At least on the iOS app you can, just tested it. I run my own postfix/dovecot, so shouldn’t require any esoteric configurations.

kassner··on Europe is scaling back GDPR and relaxing AI laws
The problem was not the cookie banner, but rather that they were doing things that required user consent (most commonly: filling up the website with 3rd-party marketing tools).

You can have a website as big as GitHub without a cookie banner yet still be compliant.

kassner··on Hiring a developer as a small indie studio in 2025
I still consider this a red flag. The company wants me to put time into the hiring process, but they can’t be bothered to do the same.

If there is at least a recruiter screening first, I’ll apply and ask about “Bring Your Own Code Examples”, mostly when their daily work would use tools that I have some code published.

kassner··on IP blocking the UK is not enough to comply with the Online Safety Act
I guess the case he’s making is that not even Ofcom knows, because it has nothing to do with the block itself. They want to make a scene, however possible.
kassner··on Google suspended my company's Google cloud account for the third time
Second and third suspensions are a week apart. Wouldn’t be enough time to shift customers to a new auth format, specially when most of the burden is on them.
kassner··on HTTPS by default
> There are also other ACME providers which will let you skip challenges for DCVd domains

Do you have examples? I’m not sure how to search for this feature.

kassner··on HTTPS by default
How do you tell iOS/Android which website to open? You do that by hijacking the request to http://captive.apple.com and then 301/302 it to your domain, with or without https. If the first request iOS made was to be secure, you’d have to have a valid certificate for captive.apple.com running in your infrastructure OR the iOS would have to allow self-signed without asking for exceptions. Both sound like a terrible idea.
kassner··on Forgejo v13.0.2 contains critical security fixes
Also affects v11
kassner··on Replacing a $3000/mo Heroku bill with a $55/mo server
Put swap on the “instance store” disk, not EBS.
kassner··on AWS multiple services outage in us-east-1
> billing […] can't tolerate eventual consistency

Interesting point that banks actually tolerate a lot more eventual consistency than most software that just use a billing backend ever do.

Stuff like 503-ing a SaaS request because the billing system was down and you couldn’t check for limits, could absolutely be locally cached and eventual consistency would hurt very little. Unless your cost is quite high, I would much rather prefer to keep the API up and deal with the over-usage later.

kassner··on European.cloud: A Curated Directory of EU-Based Cloud Providers
Thank you, I'll give it a try!

I quite like the low-end offering, €5 can get you a managed ValKey, a managed Postgres and a 512MB RAM Linux VM. In most other PaaS offerings you start at $10 just for a managed database.

If you don't mind answering, how do you handle those low-memory databases? For i.e. DS-G2-256MB, you get a 256MB VM with a dedicated Postgres installation, or you get an user/db in a shared Postgres server?

kassner··on European.cloud: A Curated Directory of EU-Based Cloud Providers
They rely on Leaseweb: https://www.nodion.com/en/docs/regions/
kassner··on European.cloud: A Curated Directory of EU-Based Cloud Providers
Basically everyone with even a CDN endpoint on the US is under Cloud Act. Hetzner, OVH, etc. Maybe only Scaleway that I couldn’t find any mentions of an US PoP.
kassner··on European.cloud: A Curated Directory of EU-Based Cloud Providers
Their website has basically nothing. Is it under a different brand, or just not generally available yet?
kassner··on European.cloud: A Curated Directory of EU-Based Cloud Providers
Haven’t heard of Nodion before. What is your main selling point? What does it do different from just reselling Leaseweb?
kassner··on European.cloud: A Curated Directory of EU-Based Cloud Providers
It would be awesome to have this list vetted for the CLOUD Act. IIRC only Scaleway is “safe” from it, given they don’t have any PoP in the USA.
kassner··on European.cloud: A Curated Directory of EU-Based Cloud Providers
AFAIK they haven’t launched yet.
kassner··on ChatGPT will soon allow erotica for verified adults
Isn’t it just porn with the images rendered directly on your biological GPU? What’s next? Neuralink-safe DRM?
kassner··on Offline card payments should be possible no later than 1 July 2026
That’s a different thing: pre-authorization. It’s used for when you want to authorize some purchase before delivering the goods (that you later confirm once it’s delivered). The pre-auth is still done online for amounts above the card-offline limit.

The nicer feature of preauth is that you can confirm a lower amount. So in the case of a gas pump, they first have to make sure you have the money, without knowing how much, because you haven’t pumped it yet. Once you finish, then they know the amount, and confirm the transaction at a lower amount.

kassner··on Offline card payments should be possible no later than 1 July 2026
If you ignore supermarkets, basically no place sells stuff in that low of an amount. Using Stripe as an example, transaction fees are 1.5%+1.8kr. I’m hard pressed to find a place that sells items with a price below 20kr, and even cheap crap from china costs at least that when buying online. So unless your business has an unexpectedly large amount of low price transactions, it’s not a big issue.
kassner··on EU age verification app not planning desktop support
That I know of: Danske Bank, ICA Banken and Nordea give you some “calculator”-style device to generate codes and login. Danske calls it “kodbox”, Nordea “ID-dosa”. I got mine at account opening, and you need it to issue BankID for the first time.
kassner··on Delete FROM users WHERE location = 'Iran';
> The problem is when a large amount of abusive traffic comes from a handful of countries, it's technically easier to block entire IP ranges and ASNs

Abuse is becoming a much bigger problem lately, to the point that even large western providers are getting the same treatment nowadays. More and more I see people talking about banning Hetzner, OVH, DigitalOcean, and at any given time I can see several of their IP addresses in abuse reporting websites (spamhaus, abuseipdb).

What is the future here? I see no reason for those providers to tighten on abusers, given how long they’ve already ignored it. Pretty sure at some point you’ll have to have your own ASN and IP ranges to be able to do anything on the internet.

← PreviousPage 2 of 8Next →