HNHacker News
TopNewBestAskShowJobs

kbuck

1,020 karma · joined December 5, 2011

submissionscomments
kbuck··on Please don't use Slack for FOSS projects
Mostly correct, but one nit to pick: IRC is not 7-bit; you can actually transmit unicode messages on every IRC network I've ever seen. It's also not usually unicode-aware, though, so if you send a message too long, it might get truncated halfway through a codepoint. Many IRC networks prohibit non-ASCII channel names and nicknames to prevent impersonation (e.g. with zero-width spaces).

The rest of what you've said is pretty much true.

kbuck··on Please don't use Slack for FOSS projects
EsperNet server administrator here. You did not 'nearly break EsperNet' with EiraIRC usage. Our capacity vastly exceeds our load (we could likely run the entire network from a single one of our servers). However, the time our administrative team has to spend differentiating abusive bots from non-abusive ones is finite, which is why we place so many restrictions upon bots.
kbuck··on Dell to Buy EMC in Deal Worth About $67B
Small correction: VMware isn't a spinoff of EMC, it's a subsidiary. VMware was originally founded in 1998 and acquired by EMC in 2004.
kbuck··on iPhone 6s and iPhone 6s Plus Preliminary Results
I'm not exactly a fan of Apple-focused reporting either, but every single graph except one in this article has statistics for the S6 Edge. The one that doesn't has stats for the S6, which has the same compute hardware as the S6 Edge.

Anandtech is historically not a Apple-focused reporter; in my experience they've been fairly neutral.

kbuck··on How I attacked myself with Google Spreadsheets (2012)
Almost certainly. Many datacenters offer free incoming bandwidth either to improve their ratio or just because it doesn't actually cost them anything (e.g. they're paying for a 10gbit internet exchange port but their traffic is highly asymmetrical on the outgoing side).
kbuck··on “Your monthly rent .. shall increase from $2145 to $8900”
In San Francisco (the subject of the post), houses built after 1979 are not covered by rent control[1]. This "new construction exemption" was designed to avoid stagnation in rental construction.

[1]: http://www.sftu.org/rentcontrol.html

kbuck··on Virtual DNS: DDoS Mitigation and Global Distribution for DNS Traffic
Is this just a service selling DNS slaves, or is there something deeper about how this works? From the URL, it just looks like the normal operation of a slave DNS server. What makes it "virtual"?
kbuck··on Scans of North Korean IP Space
Small correction: VMware authd runs on the host machine, not the guest. That's actually a Windows machine running VMware Workstation.
kbuck··on Ask HN: Does anyone remember this link that was posted?
If you upvoted the story, it'll appear in your "saved stories" list[0]. The URL is per-user and appears on your user profile page (or you can just change the id parameter in the URL).

[0]: https://news.ycombinator.com/saved?id=zkhalique

kbuck··on How browsers get to know you in milliseconds
It's fairly simple: none of those steps happen, because since the advertiser's scripts and iframes are blocked, they don't even know you've loaded a page with an ad on it.
kbuck··on Go 1.4 Release Candidate 2 is Out
The Go 1.4 release notes[1] mention a "fully precise" garbage collector, but I thought this was one of the major highlights in the 1.3 release? (The notes[2] for the 1.3 release say: "For a while now, the garbage collector has been precise when examining values in the heap; the Go 1.3 release adds equivalent precision to values on the stack.") What's up with that?

[1]: http://tip.golang.org/doc/go1.4

[2]: http://golang.org/doc/go1.3

kbuck··on Regex Crossword
(\sSAI) is a group, not a character class. It matches the fixed string " SAI" and stores it in a group. If it were [\sSAI], you'd be correct.
kbuck··on Regex Crossword
The "I" can't be "T" because the regex on the bottom (.(\sSAI).*) forces it to be "I".
kbuck··on Global Outage of AWS CloudFront CDN on Nov 26 2014
Browsers that do support SNI include:

IE7+ (unless running on Windows XP)

Firefox 2.0 and later

Opera 8.0 and later

Chrome 6 and later (unless running on Windows XP)

Safari 3.0 and later

Android default browser on Android 3.0 and later (this is probably the biggest chunk of users)

Windows Phone 7

So, realistically, you're looking at people who still use Windows XP (unless they're using Firefox) and people with really old Android phones that'll never receive a manufacturer firmware update.

kbuck··on Systemd redux: The end of Linux
It hinges upon the fact that people are more likely to be vocal when they don't like something than when they do. Consider online reviews: are you more likely to review a product when it's worked fine as you expected or when it died a month after you got it?

systemd has both good aspects (e.g. faster boot times and removal of the nasty nest of shell scripts) as well as bad ones (incredibly monolithic). There are arguments on both sides of the fence. It's just that you're more likely to hear from people who dislike something than you are to hear from people that like it. (And at this point most of the systemd proponents have given up talking about it because of the incredibly vocal and relentless opposition.)

kbuck··on FFS SSL
Configuring things is hard, and if you rely on Google to give you magic commands to execute instead of learning about what you're doing, you can really mess up.

If you don't have the time to spend properly administrating a system, don't do it; use a hosted platform so that someone else (who knows what they're doing) does it for you.

kbuck··on Microsoft takes down No-IP.com domains
What makes a site hosting malware per se harmful, and how can you consider malware per se harmful while booters avoid being classified identically? Malware is illegal and obviously a detriment to the internet, as are booter services. Perhaps you're just willing to deal with malware so you don't end up in the same boat as No-IP did here.

Booter services are so incredibly common that the police aren't going waste their time on them, especially since once the cops get the real IP from your convenient obfuscation service, it's likely hosted in China, Russia, or some other country where no action will be taken.

kbuck··on AT&T: We need to buy DirecTV because U-verse TV is a failure
They do, but you'll be charged a $200 (or more) "installation fee" if you don't bundle TV with it. When my service was installed, the guy literally walked in, plugged the modem into the wall, and was done. However, if you do order bundled TV with it, they'll prorate the fees if you cancel it... so I ordered TV + internet, cancelled the TV the next day, and now have an internet connection only (without paying their ridiculous $200 "plug it into the wall" fee). I only bought one day of TV service (the cost of which was negligible) and dropped the cable box off at UPS.

I would be using something else if there were ANYTHING else, but my apartment complex won't let cable providers wire the place. I'm moving soon, to hopefully greener pastures.

kbuck··on Can This Web Be Saved? Mozilla Accepts DRM, and We All Lose
This seems unlikely, and in fact, Firefox has been moving in the opposite direction with other binary components (Flash, Java, Silverlight). Newer builds of Firefox require you to explicitly confirm that you'd like to allow <site> to execute plugin code. I doubt this will change any time soon.

I'd rather have a (albeit stupid) DRM executable that only performs encryption/decryption than Flash, Java, or Silverlight, which are the current solutions for this. All three of these offer APIs for doing things other than decrypting DRM content, and these APIs have been proven time and time again to be vulnerable to attack, no matter how much time is spent trying to sandbox them properly.

kbuck··on Yahoo breaks every mailing list in the world including the IETF's
I disagree. I've had Yahoo reject my emails completely silently (didn't arrive in inbox OR 'spam' folder, even though Yahoo's MX said the message was accepted). Yahoo was entirely unresponsive about this issue. We didn't have the same problem with any other provider and it was resolved immediately upon switching to a third-party email delivery service.

Additionally, Yahoo has a huge amount of abuse and doesn't seem to have an abuse handle either; you have to fill out some form buried deep on their site. On the other hand, I've reported abuse incidents to Hotmail before and have gotten an actual reply from a human (a rarity when submitting abuse reports; most places act on them but don't bother responding).

kbuck··on Denial of Service Attacks
Actually, since this attack wasn't volumetric and was instead attacking GitHub's (TCP-based) applications, they have the rare ability to identify the attacker's drones and possibly hand the list off to someone that can get them shut down. Hopefully GitHub does the right thing here.
kbuck··on Steam's VAC reads all the domains you visited
I don't think this was made to capture people just visiting cheat sites. Elsewhere I've heard people mentioning that this functionality exists to detect a new and evolving set of cheats wherein you enter credentials into an innocuous-looking executable and start up a game. In the background, this executable connects to a cheat distribution server, authenticates you, and live-patches whatever game you're playing. The DNS hosts they're looking for are these endpoints.

Is this a reasonable way of detecting cheats? In my opinion, yes. They can't send the hostnames to the client (even in hashed format), because then the cheat authors could see if their hostname(s) are listed and subsequently change them, even if the list sent to the client is hashed (they'd just have to run their own hostnames through the same hashing function). Having my DNS cache sent to VALVe and used (likely ephemerally) is a small price to pay for multiplayer games that I enjoy to continue to be fun.

kbuck··on Ad blockers: A solution or a problem?
You're right in saying that annoying ads are getting less common and that a minority of advertising networks have them now. I used to manually block such advertisers myself, but I gave up and started using a filter list after spending several hours trying (unsuccessfully) to block YouTube video ads.

I'd like to support the sites I visit, but the bottom line is that it's far easier to use a filter list than manually comb through the "blockable items" list in AdBlock when I discover yet another excessively annoying ad. I sometimes manually whitelist entire sites when I specifically want to support them, but frequently I don't even think about it (and when I do, I have to consider whether the ad network they're using is responsible enough to stop clients from posting ads containing Java exploits and whatnot). Using a filter list with AdBlock is one of the biggest improvements that an end-user can effect on their page load times and web browser responsiveness.

kbuck··on Ad blockers: A solution or a problem?
> And some believe that today's ads aren't as obnoxious as yesterday's.

Today's ads are even worse than ads used to be (although the worse ads are less common now). These days, you can expect to have to see a full-screen ad or have to watch some sort of video before being allowed to view the content you requested. Then, once you finally get to view the content, you're assaulted with things like Vibrant IntelliTXT and JavaScript that injects content into your clipboard when you copy text.

I don't mind text ads. I don't mind most non-moving image ads, as long as they load fast and aren't too sizeable. Full-screen ads, video ads, flash ads, and JavaScript junk that modify the page contents are the problem here, and they're only getting worse as advertising companies figure out how to abuse our browsers more effectively.

kbuck··on Copper enables the ARM server ecosystem
To be fair, comparing core counts directly, each of those ARM processors is quadcore - so there are actually 192 physical cores in that 3U rack, not 48.

That said, I'm not convinced ARM is ready for server applications either. This might be interesting to hosting companies that want to sell low-end dedicated servers, though. (OVH already does something similar with Kimsufi, I believe?)

kbuck··on Battle-ready Nginx – an optimization guide
If you set an application to use more file descriptors than ulimit -n returns, then either the application will be smart and fix its configuration by using MAX(configured limit, ulimit -n) or it'll start dropping requests because it's assuming it's allowed to open more file descriptors.

Increasing an application's maximum file descriptors past ulimit -n is bad advice. The proper way is to increase the limit in /etc/security/limits.conf (note that assigning a limit to * applies it to every user but root, so if you really want to assign a limit to every user, you must assign it to both * and root) and then increase the application's max file descriptors. Restarting the application is usually required, although on newer versions of Linux, changing limits for running processes is possible.

kbuck··on Is Ad Avoidance a Problem?
I use an ad blocker. I used to use it without a filter list and would manually block any ad I found intrusive (e.g. Flash ads, ads that pick words out of the page content and highlight them, animated image ads), but then it simply became too much work. The tipping point for switching to filter list was spending two hours trying to figure out how to block YouTube video ads.

I want to support the sites I browse, but ad networks that host intrusive ads give all ads a bad name. Even worse are the irresponsible ad networks that allow advertisers to execute JavaScript, embed PDFs, embed Java applets, or even embed an entire iframe with a URL of the advertiser's choosing.

kbuck··on How not to validate email addresses
I've found that the best ways for validating email addresses, in order, are: checking for the '@' sign, resolving the hostname to the right of the '@' sign to see if it has MX records (or an A record, since the specification technically also allows sending mail to the server at the A record), and sending an email to the address that includes a verification link that the user must click.

The first two can be done without requiring any additional work for the user, but people are so used to clicking verification links that they don't really mind that either.

kbuck··on Did Stack Exchange staff members assist in the apprehension of Ross Ulbricht?
The criminal complaint[1] mentioned the FBI searching for the earliest mention of Silk Road. The earliest they found was a user called 'altoid' advertising it in two separate places (including bitcointalk) around the same time. Later, 'altoid' posted a second time on bitcointalk searching for an "IT Pro" and publicly listed the email address "rossulbricht@gmail.com" as the contact info for the gig. This was also the email address he used to register his Stack Overflow account.

[1]: http://www1.icsi.berkeley.edu/~nweaver/UlbrichtCriminalCompl...

kbuck··on If PyPy is 6.3 times faster than CPython, why not just use it?
I remember looking at that, but Twisted's epoll reactor was a C extension at the time. It looks like Twisted 12.1.0 switched to using the epoll provided by the Python base library, but that was released about a year after I was originally installing this daemon (and I was installing everything from apt, so add another year to the age of the packages I got).
← PreviousPage 4 of 6Next →