HNHacker News
TopNewBestAskShowJobs

kenny_r

1,514 karma · joined April 15, 2011

submissionscomments
kenny_r··on macOS 26 breaks custom DNS settings including .internal
What I'd suggest is using lvh.me, which always resolves to localhost, as do all it's subdomains. If you need a specific IP you can use nip.io.

If you want valid certs you can generate them with mkcert and add them to your system trust store.

kenny_r··on Building an "Easy" Web Application
My pleasure. Claude 3.5 Sonnet made the diagrams after 3 rounds of prompting.

LLM's are surprisingly good at making diagrams in monospaced ascii or MermaidJS.

kenny_r··on Building an "Easy" Web Application
CORS is enforced by the client, the web browser.

  +----------------------+                               +-----------------------+
  |     User Browser     |                               |     WordPress Site    |
  | (viewing from        |          CORS Error           |     (blog.com)        |
  |  example.com)        |     Browser enforces CORS     |                       |
  |    +------------+    |        Direct request         |    +------------+     |
  |    | Frontend   |<-----------------------------------X    | xmlrpc.php |     |
  |    | App        |    |     example.com → blog.com    |    |            |     |
  |    +------------+    |                               |    +------------+     |
  +----------------------+                               +-----------------------+
       Browser security blocks cross-origin
       requests (CORS is browser-only!)

The bottle app presumably uses some python library like Requests. It wouldn't care about CORS.

  +----------------------+     +------------------------+     +-----------------------+
  |     User Browser     |     |    App Server          |     |     WordPress Site    |
  | (viewing from        |     |    (example.com)       |     |     (blog.com)        |
  |  example.com)        |     |                        |     |                       |
  |    +------------+    |     |    +------------+      |     |    +------------+     |
  |    | Frontend   |<-------->|    | Backend    |<---------->|    | xmlrpc.php |     |
  |    | App        |    |     |    | (Bottle)   |      |     |    |            |     |
  |    +------------+    |     |    +------------+      |     |    +------------+     |
  +----------------------+     +------------------------+     +-----------------------+
           Same origin         Uses requests library           Different origin
       Browser allows this       No CORS checks here!         (Server doesn't care
                               (Not a browser!)                  about origin)
kenny_r··on Microsoft Outlook Outage
It's not just you. I'm also in the EU experiencing an outage.
kenny_r··on Royal Caribbean to use SpaceX's Starlink to provide internet onboard their fleet
I don't disagree with your sentiment, but I think it's interesting that this reached the front page of HN at all, and I have to think it's _because_ of the cult of personality around Musk.

Some of these comments suggest that having satellite internet onboard a cruise ship is a new thing. It's certainly not.

After some quick googling it looks like the current provider is O3b Networks (now part of SES), using modem equipment manufactured by ST Engineering iDirect.

I somehow doubt that when O3b Networks won that contract in 2013 it made the front page of HN. But now, there's "SpaceX's Starlink" in the title and it sits on #7 on the front page with 130+ comments.

kenny_r··on Multipass 1.0 – Mini-cloud on Mac or Windows workstation
I've been playing around with it for a bit, but I don't really see what it has to offer that Vagrant doesn't already do.

"multipass launch" and "multipass shell" do the same as "vagrant up" and "vagrant ssh".

Vagrant has been around since 2010 and is super mature by now. Multipass seems to be limited to LTS Ubuntu releases, for now at least. There are Vagrant boxes for all Ubuntu releases but also Debian, CentOS or whatever else you would want to run.

kenny_r··on Multipass 1.0 – Mini-cloud on Mac or Windows workstation
They're marketing this as a "mini-cloud". If it can only network through NAT, that eliminates all use cases where the VM instances would act as a server.

I'm a sysadmin, so I like tools like this to test out provisioning of servers with configuration management such as Ansible or Puppet.

Running tests at the end where I actually test the endpoints of the deployed services would be really nice to have, but impossible to do through NAT.

I guess that's a niche use case for this because Vagrant had the same issue for a long time, where setting up a bridged network was not possible or required some hacks.

kenny_r··on U.S. widens trade blacklist to include some of China’s top AI startups
The comment you replied to was sarcastic.
kenny_r··on Ocean plastic waste probably comes from ships, report says
> Greta visited the US[...]

Yes, to address the United Nations.

kenny_r··on Handler beliefs affect scent detection dog outcomes (2011)
This particular horse is mentioned in the very first sentence of the introduction of the paper.

I think it's a worthwhile study, especially considering such dogs are currently still used in law enforcement. It's important to be aware of the shortcomings and biases of this methodology, and to do so in a sound, scientific manner.

kenny_r··on Libra, 2 Weeks In
The same €3000 limit for cash transactions has already been implemented in Belgium, France has an even stricter limit of €1000.

Starting in January, the ECB will stop the distribution of the €500 bill.

We're nearing the death of cash.

kenny_r··on Raspberry Pi 4 not working with some chargers
My personal take-away is "hold off on buying a Pi4 until this issue has been addressed in a future revision".
kenny_r··on DNS-Over-HTTPS (DoH) Operational and Privacy Issues
As a sysadmin I disagree strongly.

Being able to host my own authoritative servers for my domains inside my org is a fantastic feature of DNS.

It lets me do things like split-horizon, which lets me deal with clients coming from different origins that may reach certain servers with or without NAT.

I'm also not keen on putting all my records on public name servers, for everyone to discover.

kenny_r··on Vertcoin (VTC) is currently being 51% attacked
The animated gif embedded in the article is incredibly hard to follow, since it has no controls to pause or go back to the previous frame. I wish the author had just embedded it as a series of images.
kenny_r··on Deutsche searched in money laundering probe over Panama Papers
I'm not German but this headline irked me. They could have just used the full name of the bank.

They use "Deutsche" and "Danske" as a shorthand throughout the article itself, too.

kenny_r··on Minimal Ubuntu, on Public Clouds and Docker Hub
Finally an answer to the domination of Alpine as base for Docker images. I like the small footprint of Alpine but Ubuntu and apt/dkpg will always be more familiar to me.
kenny_r··on Android container in Chrome OS
Could you tell us exactly which part of Docker you think is "quite closed"? Docker (Moby) is licensed under Apache 2.0, and so is containerd, the default runtime.
kenny_r··on Why Mickey Mouse’s 1998 copyright extension probably won’t happen again
I don't think anyone will ever live for another 70 years after their death.
kenny_r··on Diaspora-common: does 'rm -rf /' on purge
ShellCheck warned me of a very similar issue in a script of mine recently. In that script I ran the following:

  rm -rf "${FOO}/"
ShellCheck helpfully warned me that that could have disastrous consequences when FOO is unset, instead it advised me to use this:

  rm -rf "${FOO:?}/"
I'd also like to point out that ShellCheck is in the AUR for users of Arch Linux[0], and that there's a handy plugin which I use for the Atom editor[1].

[0] https://aur.archlinux.org/packages/shellcheck-git/

[1] https://atom.io/packages/linter-shellcheck

kenny_r··on Android permissions and hypocrisy
I'm not the person you replied to, but Keepass2Android [0] has the custom keyboard for password entry.

[0]. https://play.google.com/store/apps/details?id=keepass2androi...

kenny_r··on Diamonds Suck (2006)
According to Wikipedia[0], the patents for the creation of Moissanite expired in 2015 in the US and in 2016 for the most of the rest of the world.

[0]: https://en.wikipedia.org/wiki/Moissanite#Applications

kenny_r··on Snoopy Has Been Fired by MetLife
A recent feature of HN actually uses this trick. If you look on the comments page for any article, there's a series of links: "flag | hide | past | web" and so on. The link labeled "web" takes you to a web search for the title of the submitted article, so that you can bypass the paywall.

I agree it's very silly.

kenny_r··on Italy’s rarest pasta
I found another link [0] to the article at the bbc.co.uk domain but it seems to immediately redirect to the article hosted at bbc.com.

[0] www.bbc.co.uk/programmes/p01gns25

kenny_r··on Samsung to Permanently Discontinue Galaxy Note 7 Smartphone
FYI: HN has a recent feature where there's a link labeled "web" under the article link, which brings you to a web search.

Clicking the first result will bypass the paywall.

kenny_r··on Fitbit Acquires Coin
"Malaysia car thieves steal finger" (2005) [0]

These were not casual muggers, since they resorted to kidnapping, also keep in mind that this was done to steal a very valuable car.

With phones also now also becoming wallets, it's not outlandish to think a thief would cut off a finger.

[0] http://news.bbc.co.uk/2/hi/asia-pacific/4396831.stm

kenny_r··on The AMDGPU Additions for Linux 4.7 Are Enormous
I'm hopeful it'll get better. Steam itself was _awful_ in the early days. There's an old NSFW animated gif of the Steam logo that's tells you a little bit about how early users felt when Steam became mandatory to play Counter Strike. Look at Steam today, though. It's gone through a tremendous evolution.
kenny_r··on Detecting the use of “curl – bash” server side
I don't disagree.

You rarely see curl|sh installers for server stuff though. I think the topic at hand mostly concerns workstations.

kenny_r··on Detecting the use of “curl – bash” server side
I know you're being facetious but `go get` is just as convenient and is a controversial installation method for different reasons.
kenny_r··on Detecting the use of “curl – bash” server side
Thanks, that explains a lot.

It's really a shame that you have to wrap the best practices aproach in a bad practice in order to make it convenient.

> Point being that even if you install "the right way" on linux using package managers it's still a multi-step complicated process that benefits from being automated in a bash script.

Right, because distributions want different things than software authors.

If you're a Debian/Ubuntu/RHEL maintainer, you want stable, tested versions of software that you can vouch for and support for several years.

If you're the maintainer of an application, in this case Docker, you want your users to run the latest and greatest version of your software. You can't just demand that each distro just ships the latest and greatest version of your software. So if you're Docker you end up having to do the following for each distro:

  * package the software for that distro
  * sign that package
  * serve your your own repository containing that package
  * ask your users to add the repository
  * ask your users to trust the signature
And then finally your users can install the package.

That's one of the reasons I like running Arch Linux on my workstation. The desires of the software authors, distro maintainers and users align.

  Docker Inc: "Hey wouldn't it be cool if your users could install the latest
               stable version of Docker?"
  Arch Linux maintainers: "Yeah, it would. We'll keep the latest version in the
                           repo and our users can just `sudo pacman -S docker`"
  Docker Inc: "Cool."
  Arch Linux users: "Cool."
kenny_r··on Detecting the use of “curl – bash” server side
I was genuinly confused with regards to your last point.

There's a section on their website[0] there are installation instructions for various distributions using repositories and package managers. In other words, the right(tm) way of doing software distribution on Linux.

But then on a different part of their website I found the curl | sh instructions you allude to[1]. Bizarre that they still support that installation method.

To make matters worse, the big orange "Get Started" call to action button actually leads to the curl|sh installation instructions. In light of that I certainly can't blame you for not knowing about the proper distribution packages.

[0] https://docs.docker.com/engine/installation/

[1] https://docs.docker.com/linux/step_one/

Page 1 of 3Next →