HNHacker News
TopNewBestAskShowJobs

kbuck

1,020 karma · joined December 5, 2011

submissionscomments
kbuck··on Dropbox Could Have One of 2017’s Most Interesting IPOs
DropBox was hacked in 2012 (and all email addresses were leaked)[0], so you might have just been getting spam from regular spammers that got a copy of this list.

[0]: https://www.troyhunt.com/the-dropbox-hack-is-real/

kbuck··on Russian ship loitering near undersea cables
Looks like the site is down. Mirror: http://webcache.googleusercontent.com/search?q=cache:Iq7DDCu...
kbuck··on Say Cheese: a snapshot of the massive DDoS attacks coming from IoT cameras
Requests (i.e. HTTP requests).
kbuck··on IRC v3
> (most IRC servers keep logs anyway)

IRCd developer and network staff member here. Dead wrong. I don't think I've seen a single IRCd that keeps logs, and doing so would make it much more expensive to run an IRC network. Additionally, it would be a huge violation of privacy, and we value our users' privacy. The IRCd only logs server events (e.g. network-wide bans, server connection/disconnection, use of administrative tools) and user connections/disconnections (for anti-abuse purposes).

If network staff have logs of something, it was either because their IRC client was present in the channel or because someone else gave them logs.

Most of my network's servers hang around 2-3% CPU usage and <5GB disk usage, and we'd like to keep it that way because we don't want it to cost a lot to host. We have an average of 1000-2000 users per server.

kbuck··on Ask HN: How do you manage your web passwords?
I use a password manager (1Password). It both stores and generates secure passwords. I've tried KeePass and LastPass, but I didn't like them as much (although LastPass's form filling was very accurate).
kbuck··on Pokemon Go dev argues sponsored locations are more game-friendly than IAP
In Ingress, they had similar partnerships with a few companies. Notably, the sponsored "portals" (the Ingress version of Poke Stops) were only additional locations to get items. They didn't award special items or do anything else differently (ZipCar and Jamba Juice had this agreement with Ingress).

Ingress also had in-game items named after companies, but these items could drop from anywhere and were likely to be added to the game anyway. A couple examples of these are the SoftBank Ultra Link and the "MUFG" (Mitsubishi UFJ Financial Group) capsule.

I think the only time they had a commercial partnership that gave someone in particular an edge was when they introduced Ultra Strike items, which could initially only be obtained on some Motorola-branded Android devices. These can now be obtained on any device, though.

Given that it's the same team working on Pokemon Go, I think it's unlikely that they'll make things annoyingly intrusive or force you to go to specific Pokestops to get certain items.

kbuck··on How 'Pokémon GO' Can Lure More Customers to Your Local Business
The Dairy Queen picture in the article is a fake. Compare with this one: https://www.flickr.com/photos/z0/4830845696
kbuck··on ViperDNS closed down
It's definitely the IPs.
kbuck··on ViperDNS closed down
Presumably they have to change servers so often because that's how quickly Netflix detects them.

It's extremely unlikely Netflix will publish how they perform the detection, because that would make it easier for people to get around. My guess is that they know where your account should be located based on payment information or previous detection of region-switching services, and they use these flagged accounts to uncover new region switchers.

kbuck··on Empty DDoS Threats: Meet the Armada Collective
A booter is a DDoS-for-hire service. You pay them $X and they will DDoS someone for you.
kbuck··on Empty DDoS Threats: Meet the Armada Collective
I'd say yes: if you visit a purported malware URL and you are served malware, then it is a malware site. If you visit a purported booter site URL and it advertises booter services, then it is a booter. If the booter sites start trying to hide their identity, fine, I can see not removing that without proof. That will also severely injure the booter's signup rate, though.
kbuck··on Empty DDoS Threats: Meet the Armada Collective
Either way, CloudFlare is a part of the problem. They're either protecting booter services (thus necessitating your use of DDoS protection in the first place) or terminating the booter sites without "due process".

It's relevant to mention that CloudFlare already does terminate a class of sites without "due process": malware hosts. What makes malware hosts that much worse than booters? Answer: CloudFlare's IPs can get blacklisted for it.

kbuck··on Why IRC over SSL is pointless (2009)
I'm not too worried about the DNS integration; we have a fairly easily-automatable DNS infrastructure owing to the fact that we're frequently changing records around. I'll have to see if we can take advantage of lego to avoid some work on our side.
kbuck··on Why IRC over SSL is pointless (2009)
Many of our servers whitelist ports to harden themselves against attacks, and this whitelisting may not be done on the server itself (e.g. some of our servers do it on upstream networking equipment). We would also have to run some sort of HTTPd on ALL the servers in each round-robin being verified, which would essentially mean all our servers. DNS-01 is a much better fit for us (and our DNS server software makes it somewhat less painful).
kbuck··on Why IRC over SSL is pointless (2009)
DNS-01 is currently available (at least I believe it is -- I think I saw something about its availability recently). The issue is that I will need to write my own DNS-01 client.

Running a HTTPd on each server is a bad idea for us since it increases DDoS attack surface area. This would essentially have the same distribution issue that I would need to solve with a DNS-01 client as well, so either way new code is required.

kbuck··on Why IRC over SSL is pointless (2009)
Until recently, getting certificates that would work for IRC purposes has been rather difficult. Since individual IRC servers are usually available via multiple hostnames, it requires very expensive certificates (e.g. someserver.example.net's IP address might also be present in the irc.example.net, us.irc.example.net, ipv6.irc.example.net, ... DNS records). Your options consisted of getting a "Subject Alternative Name" cert with all of these subdomains, or getting a (very expensive) wildcard certificate. IRC networks don't generally have much/any money to work with and this can easily start running into hundreds of dollars per year (especially if you deploy it properly and get one cert per server).

It's theoretically possible to deploy Let's Encrypt now for IRC servers, which removes the cost issue. The new problems become the automated creation and deployment of IRC server certificates. You'll most likely need to use the DNS-01 challenge type, since most IRC servers aren't running a HTTPd and even if they were, you couldn't guarantee that the ACME server would pick the IP of the actual requesting server out of the "pool" records (e.g. irc.example.net). Using DNS-01 means you'll need to write code to interface with your DNS server, which also means securing that interaction (so other people can't modify your DNS records and get signed certs for your domain as well).

I actually manage the (signed) certificates for one of the IRC networks I'm an administrator for. Our two blockers for deploying Let's Encrypt are the aforementioned challenges with DNS-01, and the fact that our software currently validates server-to-server links using the fingerprint of each server's individual certificate, hardcoded into the configuration file. If we're switching certs every 3 months, we'll need some way to either distribute certificate configuration more efficiently or we'll need to change the ircd to verify the certificate chain instead of the fingerprint.

FWIW, our current deployment of signed certs is the "one cert to rule them all" deployed to all servers on our network. This is definitely not ideal, but it's by far the cheapest and easiest option prior to Let's Encrypt. All other options we evaluated were simply way too expensive ($X,000+), extremely labor-intensive (e.g. manually obtaining a new cert for every single server every year/every time something changed), or both.

kbuck··on VMWare Fusion IPv6 NAT Black Holes
The Palo Alto-based dev team was laid off and a new team in Beijing will continue to develop the Workstation and Fusion products. Given that a workaround for the NAT issue was published on the blog, I would expect the next maintenance release of Fusion to fix the issue.

Source: I was on the Workstation team when the layoff happened.

kbuck··on VNC Roulette
VMware has a built-in VNC server on both ESX and their desktop virtualization products.[1]

If you don't configure a password to connect, no password is required.

[1]: https://pubs.vmware.com/workstation-9/index.jsp#com.vmware.w...

kbuck··on The Vanguard Cyborg Takeover
You get a Roth IRA without ridiculous fees. For example, Vanguard (as mentioned in the article) has some.
kbuck··on Ask HN: Your thoughts about online developer recruitment tools like HackerRank?
The score is based entirely on the number of testcases you pass. If the company in question wants to look at other metrics, they need to do it manually.
kbuck··on Ask HN: Your thoughts about online developer recruitment tools like HackerRank?
Sorry for the confusing wording; I intended for "segfaults" and "failing non-sample testcases" to be interpreted as separate things. Showing stack traces or any other info from the program's execution for non-sample cases would be a bad idea. However, if it segfaults for a sample testcase, showing a stack trace should be fine (and this will probably catch the vast majority of segfaults).
kbuck··on Ask HN: Your thoughts about online developer recruitment tools like HackerRank?
I've been on both sides of HackerRank. I helped develop/configure a HackerRank test for candidates for my team, and recently I've taken a HackerRank test while applying for a position at another company.

HackerRank is just a tool. Its effectiveness depends on how well the company interviewing candidates configures it. I think algorithmic questions are the most popular, but it's completely configurable; you can have it ask whatever you want. It's also possible to manually review submissions. When we used it to evaluate candidates, we'd manually review the code for candidates that scored somewhere in the middle of the range. Depending on what their submission looked like, we'd decide whether or not to proceed with them. (HackerRank lets you see each version of the code attempted by the user, in addition to the final solution submitted.) We actually found it particularly efficient at finding good candidates; there was a very high correlation between interview performance and HackerRank score. If properly configured, HackerRank makes it easier to identify good candidates, which is (IMO) a good thing for everyone. For companies, it means that they spend less time interviewing bad candidates, and for candidates themselves, it means that they might be able to get their foot in the door somewhere where they'd usually get blocked by the "resume scanner" filter (since the company isn't risking engineer time/productivity to send out a simple HackerRank evaluation).

That said, HackerRank isn't perfect. My biggest complaint is the lack of feedback for some failure modes, most notably segfaults and failing non-sample testcases. For segfaults, it simply returns "segmentation fault" and you're expected to be able to find the problem (a similar tool I've seen, coderpad.io, dumps a stack trace). In some algorithmic questions, non-sample testcases include data that is vastly more voluminous than the sample data (which is intended to catch non-optimal implementations of the algorithm), but this isn't obvious at all. It would be nice if the non-sample test cases had titles (e.g. "extremely large input" or "edge case") so you could theorize about why yours failed.

People who have experience using HackerRank have a definite edge over candidates who have never used it before. If you are planning on taking a HackerRank test for a position, I would recommend trying some open questions on their site first. I also recommend having a local text editor, compiler, and debugger ready in case you hit a segfault that isn't immediately obvious. If your solution fails with "Terminated due to timeout", or your code works on all the sample cases but fails/crashes on the hidden cases, then your algorithm is likely not efficient enough (in the timeout case, look for ways to speed it up; in the 'mystery crash' case, look for ways to reduce memory usage). Lastly, if you have extra time after completing a HackerRank test, I recommend making sure your code is as clean as possible and is well-documented (but not over-documented), in case they decide to manually review it.

kbuck··on Ask HN: Your thoughts about online developer recruitment tools like HackerRank?
HackerRank's core product is a tool that companies can use to send programming tests to potential candidates. It's typically used to screen candidates prior to an interview.

The Stockfighter-like concept is newer for them; it seems like they're also trying to work the pipeline from the other direction as well (i.e. finding good candidates for companies, instead of just testing candidates that have already applied for a position).

kbuck··on Show HN: HackerRank's app guarantees an interview call after a coding challenge
My team (at VMware) has used HackerRank to hire. It worked out pretty well. The biggest advantage was being able to vet many candidates quickly. It's definitely improved our hiring process (it used to take us much longer to find a suitable candidate). I think my team was one of the first at our company to use it (and we haven't done much hiring since), so my knowledge about the specifics is a little out-of-date.
kbuck··on Zopfli Optimization: Literally Free Bandwidth
These are default (placeholder) avatars. Users can upload their own avatar image as well. They're serving PNGs so they don't have to deal with the case where users using default avatars get HTML output whereas users who have uploaded an avatar get an image inserted.
kbuck··on EC2 Update – T2.Nano Instances Now Available
Having been hit by AWS's CPU cap before (on the t2.micro instance type) and having used many other providers, I can tell you firsthand that AWS's CPU limits are MUCH lower than their competitors'. In our case, a sustained usage of about 15% CPU caused our VM to eventually be starved of CPU time, which in turn crashed the software running on it.

I've never dealt with stricter CPU limits than AWS's. Most providers will not be happy if you peg an entire core to 100% (after all, the physical cores are oversold), but they usually don't mind if the percentage is even as big as 50%.

kbuck··on Stop using gzip
You're confusing gzip (.gz) and PKZip (.zip). Windows has no native support for gzip, only PKZip.
kbuck··on Invoke God Mode in Windows 10
Yes. This is spam.
kbuck··on Issue 87 – google-compute-engine – UDP Packet Fragments cannot be reassembled
They've likely blocked your VPN because they think you're trying to bypass region restrictions. In this case they don't care whether you're human or not: they simply want to make sure you can't watch videos that would not normally be available in your country.

It's a ridiculous system, but it's unfortunately how media licensing still works.

You could try getting a cheap VPN endpoint device and putting it between your router and your residential internet connection. Then you could VPN to that device to access the (usually-blocked) YouTube while still using your residential IP (assuming the blocking is done on your router).

kbuck··on Please don't use Slack for FOSS projects
There are many issues that prevent us from easily serving your use-case, unfortunately. I'm not completely sure about the details around this specific case, but historically we've had to restrict connections from similar software that makes N:N connections (or even N:M connections) to our network due to our connection limit rules quickly becoming unmanageable. We've recently implemented new software that should make this a little bit easier for us (and we've accordingly started being a bit more lax about it), but this is a fairly recent development.

Additionally, we hesitate to cater to this use-case as it often ends up turning into "we want your network to relay messages between our bots" instead of "we want to talk to other people". We've found that channels used for such bots are typically not sufficiently staffed and frequently a target of abuse, which ends up taking network staff time to resolve.

Lastly, we've had a number of technical issues supporting certain pieces of IRC client software. Older versions of EiraIRC in particular have some nasty bugs; the worst of which is that they tend to get stuck in some state where they hold multiple connections to the network open while continuing to attempt to connect again and again, with no delay. While this doesn't impose load that our servers can't handle, it does generate a lot of administrative log traffic that is bogus and dilutes important log traffic.

Many of these use cases can be covered by IRC, but our network isn't configured to handle such use easily as it often looks very similar to the sort of abuse we usually deal with. The common denominator in most cases like this is that it's taking too much of the staff's time and attention to support the channel and its clients. Our time is finite, and for the health of our network, we'd rather say "no" to a few channels than to make all channels suffer from thinner network staff resources.

← PreviousPage 3 of 6Next →