HNHacker News
TopNewBestAskShowJobs

keeperofdakeys

1,623 karma · joined April 16, 2011

submissionscomments
keeperofdakeys··on The future of AlmaLinux
Alma has had this for some time now - https://almalinux.org/elevate/ - and I see no reason why it would stop working after this announcement.
keeperofdakeys··on XFS online filesystem check and repair
Compared to Ext4, I've always found XFS more consistent performance wise. Plus it doesn't require a monthly FSCK which strikes you when you least want it. (Though Ext4 made this way faster than Ext3). XFS also gives you reflink - which is a game changer for some OPs tasks and backups.
keeperofdakeys··on How I Use My Mouse
There have been some interesting experiments in this regard, like the Plan 9 operating system (Built by Rob Pike and Ken Thompson).

For example here is a tour of the Acme Text Editor:

https://www.youtube.com/watch?v=dP1xVpMPn8M

keeperofdakeys··on NameCheap's email hacked to send Metamask, DHL phishing emails
Ultimately a DNS record tells other email servers how to send email to your domain. So you just need to get an email service at another provide, and update your DNS records. Most providers have instructions on how to do this.

I'd recommend having a look at Fastmail as well.

keeperofdakeys··on Is A.I. Art Stealing from Artists?
If an artists work is used in training an AI model without a license, should it be legal to distribute the images generated by that AI model?

What about distributing the AI model itself?

Would you use an online service if the Terms and Conditions stated that "You agree that content uploaded to this service may be used in training AI models without compensation, rights or acknowledgement"?

keeperofdakeys··on Show HN: Docker rollout – Zero Downtime Deployment for Docker-compose
It would depend on the program. If you've got a load balancer in front, or they're receiving requests through a database or message queue, then there won't be an outage.

Arguably anything where uptime is important should be setup this way. Upgrades can fail, and that will cause downtime anyway.

keeperofdakeys··on Ask HN: Alternatives to 1Password
There is also the reimplementation of Bitwarden's server, vaultwarden. https://github.com/dani-garcia/vaultwarden. It's worth a look if you're self hosting.
keeperofdakeys··on Overview of new features in Apache HTTP Server 2.6
Apache has shipped with an event-based backend for many years now, so in terms of architecture it's on par with Nginx (while still supporting the classic pre-forking).

Personally I've found apache is more fully featured for niche use cases. For example you can do client cert authentication, then further look up a username from the certificate in ldap for authorisation - all from your apache configuration. For Nginx many of these niche use cases seem to be gated behind Nginx Plus.

keeperofdakeys··on Imaging mounted disk volumes under duress
Qemu has a native changed blocks API like vmware, but I'm not sure of anything that uses it extensively (besides oroxmox backup server pointing at a oroxmox server).

https://lwn.net/Articles/837053/

Also you can always do the fsfreeze yourself (which is what qemu agent can do, and is used by proxmox backup server).

keeperofdakeys··on Golang.org will be merged into go.dev

  dig +noall +answer   A ai
  ai.   86006 IN A 209.59.119.34
For better or worse the developers of browsers/libraires decided to allow it, it takes extra code to check for it and block it. Now that sites rely on it they can't exactly back track. Another strange one is domains with names that end in hypen - "example-.example.com". These are technically against standards, and don't work on linux/unix based OSs. However they happily work on windows. I've seen a github username that ended in -, which prevented me from viewing their github.io site. (Github seem to no longer allow this).
keeperofdakeys··on Public Suffix List
With Let's Encrypt your script can just publish a dns record "_acme-challenge.dev.app.org.dept.nsw.gov.au", and Let's Encrypt will verify it based on DNS delegations. The fact that you can publish it means you control/own the domain. A similar thing occurs implicitly with HTTP verification, the A record verifies that the owner of the domain trusts the web server (in some sense).

It sounds like Azure require some kind of manual, out of band verification. Maybe they tried emailing a well-known email (like postmaster@_nsw.gov.au), based on information from the PSL. A tiny contractor deploying a single application may control that one URL, but not the whole domain.

keeperofdakeys··on An early look at Postgres 14: Performance and monitoring Improvements
Postgres has some disadvantages that can pop up on certain workloads (eg. bloat) but so does MySQL. And most of those limitations are only when you've got long open transactions, trying to hammer it IO wise, or you're making really big databases (100GB-1TB or more). However for both Postgres and MySQL there is plenty of documentation about these problems, and how to resolve them. So you'll never be "stuck" with issues.

In general I find postgres "just works" a lot more than MySQL. MySQL has a really bad habit of sticking with bad defaults for a long period, while having better configuration available. On the other hand postgres devs actively remove/change defaults so you're always getting the best it has to offer.

If you pick one, and you don't like it there are plenty of tools to change between them. If you're curious you could even deploy both of them.

keeperofdakeys··on Tree.h in OpenBSD: dependency-free intrusive binary tree (2002)
The linux kernel also has some nice comments in its red black tree implementation.

https://github.com/torvalds/linux/blob/master/lib/rbtree.c

keeperofdakeys··on The Norway Problem
This is part of more general problem, they had to rename a gene to stop excel auto-completing it into a date.

https://www.theverge.com/2020/8/6/21355674/human-genes-renam...

Edit: Apparently Excel has its own Norway Problem ... https://answers.microsoft.com/en-us/msoffice/forum/msoffice_...

keeperofdakeys··on All my servers have an 8 GB empty file on disk
I find that either a server needs more space, or has files that can be deleted. For the former you just increase the disk space, since most things are VMs these days and increasing space is easy. For the latter you can usually delete enough files to get the service back up before you start the proper cleanup.

If you really need some reserve space (physical server), I'd much rather store it in a vg (or zfs/btrfs subvolume). Will you remember the file exists at 2am? What about the other admins on your team?

keeperofdakeys··on TLS certificates specifying hosts via the CommonName field is more or less gone
You still have bugs like this when you generate certs with an empty CommonName field, https://github.com/nodejs/node/issues/11771. I have an app which has certificate checking turned off due to this bug, I hope they'll update the packaged nodejs sometime in the future.
keeperofdakeys··on OpenZFS 2.0
Probably never. ZFS isn't just a filesystem, it was developed to be an entire storage system that's vertically integrated, so ARC is a fundamental part of the filesystem design.

ZFS also has a huge legacy. Right now the license (probably) prevents you from legally shipping a compiled zfs module with the linux kernel, just solving that seems insurmountable. It's also supported on Illumos and FreeBSD, trying to refactor it to use the linux page cache would have a chance of introducing bugs to these platforms.

keeperofdakeys··on Deprecating scp
Just a sidenote, this is probably the fastest way to copy lots of tiny files across a high latency link (but without -v [1]). Most protocols transfer files individually, waiting for the server to finish writing it - adding a tiny delay for each file transferred. The tar above simply pushes the files across the pipe as fast as it can without waiting, while the receiving tar can write them as soon as the data is received. Recommended to pair with lzop for fast compression.

Second sidenote, using this with pv is a great way to view total progress. http://www.ivarch.com/programs/pv.shtml

1. With -v every filename is written to the terminal, which causes context switches and IO waits. This can significantly slow file copies with lots of tiny files.

keeperofdakeys··on Deprecating scp
And unfortunately there are some devices out there that still require scp with no sftp support (copying files to a cisco switch for example). You can also use tftp or ftp, but it's not as handy.
keeperofdakeys··on Pressing YubiKeys
> Congratulations, you've defeated the purpose of having a YubiKey.

Even a virtual 2fa button is useful. It prevents people using your stolen credentials to login to websites unless you click the button, even if it's just a virtual button.

Sure your computer can be compromised, but it's probably still more secure than sms 2fa.

keeperofdakeys··on Chromium's Impact on Root DNS Traffic
You can also use stub zones to forward traffic for a single subdomain to your AD servers, while the other dns server handles recursive queries to the internet.
keeperofdakeys··on FF Sandbox Escape
Firefox uses some of the chromium code/libraries for the sandboxing on Windows.

https://wiki.mozilla.org/Security/Sandbox/Specifics

keeperofdakeys··on Medium-hard SQL interview questions
Data changes, so the best query plan changes with it. SQL was built to handle this data-dependent environment.

Is one column composed of mostly one or two values? Then an index lookup on that column is not very optimal, and the database can use something else.

There is more than one type of join (INNER, LEFT OUTER, etc), and more than one join algorithm (neesed loop, merge, hash, etc). All these change based on the data. Even the join order can have a huge impact on query time, and needs to adapt based on the number of rows you'll pull from each table.

A lot of SQL queries are built from templates, or built by ORMs. Optimisations are critical to turn these templates queries into something efficient.

SQL can also be very expressive, a "NOT EXISTS (SELECT 1 FROM thing WHERE foobar)" could be more readable than doing a join and where clause.

Though interestingly, you get a much more declarative query style with nosql databases and key-value stores. So there are alternatives out there.

keeperofdakeys··on Bad times in corporate wireless networks
One issue with WPA2 Enterprise is the client user interface. It's hard for users to configure the correct settings because there is no feedback about configuration issues - wrong EAP mode - vs credential errors - wrong user password. All you get is a "Can't connect".

There is also the problem of so many eap modes. There are some interesting EAP modes that have come along - like EAP-PWD - that remain unimplemented on major platforms, and are basically unusable. So you're left with EAP-TTLS with PEAP and MSCHAPv2 (stores passwords weakly), or EAP-TLS with client certificates. And no one wants to manage client certificates if they can help it.

Both of the above make WPA2 Enterprise on BYO devices quite a challenge.

keeperofdakeys··on How to SSH Properly
I'd recommend you try "AddKeysToAgent confirm", then you'll get a prompt to approve the key usage each time its used. (Can be annoying for usage with automation like ansible).

Having a forwarded agent was how matrix recently got hacked, confirmation is a decent work around if you need to forward your agent.

keeperofdakeys··on OpenWrt 19.07
Most of that latency would be VDSL, it was around 20ms RTT extra latency on ADSL though. The encoding has extra overhIf you really want 0ms latency, you'd want to look into fibre services.

You should also look into buffer bloat, and see if that's affecting your latency.

keeperofdakeys··on OpenWrt 19.07
VDSL needs its own NIC, as it operates very differently to ethernet. Recently I discovered that my telephone line was operating on one wire, but VDSL was still operating in a degraded fashion. Suffice to say this would totally prevent ethernet from working.

ADSL could only encapsulate ATM frames (hence using PPPoA), VDSL includes a new mode called PTM that can encapsulate ethernet frames. This may be what you were reading about.

keeperofdakeys··on A push gone wrong in the name of what, exactly?
An interesting case of rollback vs rollforward from bitcoin.

https://github.com/bitcoin/bips/blob/master/bip-0050.mediawi...

In that case they decided to rollback.

keeperofdakeys··on NASA and ESA are going to slam a spacecraft into an asteroid to deflect it
Another idea for deflecting an asteroid:

https://en.wikipedia.org/wiki/Gravity_tractor

keeperofdakeys··on Investigators who know you’ve faked your death
"... but won’t in insurance fraud. “You have to have an actual body to collect on insurance,” says Ahearn. “And it has to be the body of the insured. Ashes are not a body.”"

It sounds like you can't just get insurance money for a missing person.

← PreviousPage 2 of 30Next →