HNHacker News
TopNewBestAskShowJobs

merpkz

594 karma · joined March 7, 2022

submissionscomments
merpkz··on Self-Hosting on the Dark Web
we have been hearing this all the time whenever Dark Web is being discussed, but fact of the matter is that all the big darknet market busts have been done in past because of sloppy opsec by their operators and not some magical government wand which can pinpoint location of a hidden service
merpkz··on Nokia Design Archive (2025)
Nokia N95 had an impressive media menu [1] where you could select music, internet, radio, navigation apps and what-not, it was great for it's time. They even had a gaming figured out at one point, if I am not mistaken even with a store for their n-gage games. So yeah, I don't agree that they avoided building a truly personal computer, but at the same time they still managed to screw up everything.

1: https://www.reddit.com/r/FrutigerAero/comments/1k2ao9b/the_m...

merpkz··on US diesel prices hit a record high of $5.85 on average
> only way we are able to eat affordable food is because some diesel truck is transporting it.

I would also add to that affordable food is being first produced by agricultural machinery running on diesel, which is then transported by trucks running on diesel on roads build by machinery running on diesel. There is a good youtube video about this from channel driving 4 answers.

merpkz··on The Raspberry Pi Interactive Timeline · 2006–2026
Raspberry Pi Zero 2 is the sweet spot these days for price/performance, but it's nowhere to by found in stock, sadly despite the fact it has LPDDR2 type of RAM
merpkz··on How to get a free .arpa domain
Hurricane Electrics brings back memories of first playing around with IPv6 many years ago. Thanks a lot to them for offering such a great service free of charge for anyone to learn about IPv6 networking. Sometimes I wonder don't they have a lot of abuse from those services with people using them as proxies or something
merpkz··on Understanding ChatGPT Work
I feel like in near future the meme about "it's all just chatbots emailing each other" will actually be true. I wonder when I will receive my first AI generated email and will I bother to respond to it at all
merpkz··on Harvesting SSH Credentials: Insights from My Honeypot Network
Back when it was called Backtrack if my memory serves right. I remember being puzzled that it was not the case anymore one day and they even switched to regular user around when Kali became a thing
merpkz··on BMW Spider-Man in-car advertising
Electronic injection sounds like too complex system to maintain, now if it had an actual carburetor that might be a peak "ICE", true and pure mechanical experience. Jokes aside, I hope that car at least have airbags, otherwise it's just death trap
merpkz··on BMW Spider-Man in-car advertising
What stops your navigation app on phone collecting all the data anyways and sharing it with insurance corps?
merpkz··on We discovered a new variant of Super Mario Bros
Why are some copies of the game "graded" higher than the others if they are all the same copy of the same game?
merpkz··on Securing Services with Rootless Containers
That privileged port thing is not true anymore for Docker created containers, since it lowers that limit and unprivileged containers can listen on any port.

  docker run -ti --rm --user 1000:1000 --privileged=false alpine:latest
  ~ $ cat /proc/sys/net/ipv4/ip_unprivileged_port_start
  0
  ~ $ id
  uid=1000 gid=1000 groups=1000
  ~ $ nc -lvp 80
  listening on [::]:80 ...
Also the iptable rules Docker creates is for routing traffic to container with destination NAT, to actually limit traffic you have to do it yourself by inserting rules in DOCKER_USER chain.
merpkz··on Securing Services with Rootless Containers
That is what I have been thinking too about recent linux vulnerabilities in context of container escape, but upon brief research I am not convinced it's all that straightforward. For example here https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC relies on sharing same container layers with other privileged workloads, which is quite a stretch to find in the wild and moreso it says that having a seccomp enabled breaks the exploit - "The default seccomp policy disables the unshare syscall." Other thing is that temporary remedy to lot of these exploits is to blacklist esp4, esp6, algif_aead modules, but how on earth are they going to be loaded in host kernel, which they are not by default, from unprivileged container in first place?
merpkz··on Google Books (or similar) all book scans – $200k bounty (2025)
Copy data into extra large capacity micro sdcard and hide it in your rubiks cube, nobody will suspect a thing
merpkz··on EU to legislate about Chat Control behind closed doors
What's in there for these people to push for chat control of all things?
merpkz··on Framework's 10G Ethernet module exposes USB-C's complexity
Raspberry Pi 4 doesn't need a fan. People just like to put them on because because micromanaging CPU temperature is part of the hobby for some. Yes it might throttle its CPU speed when going full tilt for some time, but lets be real how many workloads require poor Raspberry Pi to be loaded 100% for prolonged periods of time?
merpkz··on How we run Firecracker VMs inside EC2 and start browsers in less than 1s
It's not. Fertile land is as valuable as ever and all bought up. Every season you are at the mercy of weather, new government regulations and subsidy rules, corporate overlords with repairs of your agricultural machinery and in the end price of your produce being dictated by same speculative market assholes ruining everything. It sucks, software people have it easy in comparison.
merpkz··on Stop Killing Games fails to secure EU law despite 1.3M signatures
Ah, the same guy who promised to end wars, that sounds good
merpkz··on Humiliating IIS servers for fun and jail time
"This is the brute-force fallback when the smart approaches fail, and honestly, it works more often than you’d expect."

Found the LLM generated part.

merpkz··on The Pirate Bay Remains Resilient, 20 Years After the Raid
Isn't that just Cloudflare? thepiratebay.org resolves to CF IPs at the moment.
merpkz··on Removing the modem and GPS from my 2024 RAV4 hybrid
There is no way that is true, basic cars have always existed, like Dacia with bare minimum features to pass all requirements and they are far from being popular. The fact of the matter is, is that people just like fancy things and cars especially
merpkz··on Removing the modem and GPS from my 2024 RAV4 hybrid
I honestly can't either. A lot of people drive around with navigation set on their phones which also track every movement and knows your exact location and travel speed, might even know how aggressive you drive based on accelerometer data and all that info can be uploaded from navigation app like Waze which is very popular
merpkz··on Removing the modem and GPS from my 2024 RAV4 hybrid
How will they get access to this data? Hax into Toyota to track this one specific Rav4?
merpkz··on Poland is now among the 20 largest economies
First time I hear this explanation of why demographics is in decline in Europe and it kind of makes sense, every so often having this discussion about having children people bring up that they wont be able to enjoy things anymore, like travel, which in itself is a form of consumerism - buying the "experience"
merpkz··on Nintendo announces price increases for Nintendo Switch 2
What a wild statement, how much you have to eat in Japan to offset the airline ticket prices?
merpkz··on Valve releases Steam Controller CAD files under Creative Commons license
I played through whole Half-Life 2 on steam deck with aiming and shooting using right touch pad and it was alright. Strongly suspect though the game should have a support for it properly otherwise it feels janky in everything else I tried with it. No idea what's the use case for left pad though - I sometimes play with it during loading screens due to nice sound it makes, that's about it
merpkz··on Should I Run Plain Docker Compose in Production in 2026?
Well, as an example we usually set incoming rules to filter SSH only from administrator IP addresses, TCP 10050 only from zabbix monitoring server and leave few icmp types required and rest is dropped and logged.

For forward chain we set docker network ranges to route between themselves and only services actually used in containers. Allow container outgoing connections to our DNS servers, centralized HTTP proxy server and monitoring - nothing else containers are allowed to route to.

And for output is similar, only allow our DNS servers, NTP, HTTP proxy, centralized rsyslog where everything goes and zabbix monitoring server and a few icmp types - nothing else gets out and is logged.

With the advent of these supply chain attacks we read about often here it's just a matter of time some container is compromised and this seems like only viable way to at least somehow limit impact when such an event occurs.

merpkz··on Should I run plain Docker Compose in production in 2026?
How do you guys, who run Docker in production deal with managing nftables firewall on hosts running containers? By design docker daemon creates and manages a set of firewall rules to forward traffic between containers and ingress traffic into containers as well as masquarades the outgoing container traffic. That is all well until admin needs to alter hosts firewall to allow and deny other traffic unrelated to docker - and restarting nftables or even applying new nftables rules usually ( flush ruleset in /etc/nftables.conf ) purges all the docker created rules and effectively breaks everything until docker daemon is restarted and rules re-created. I have partially solved this by using nftables filter chains with different names - admin_input/admin_output and using input hook with negative priority - so that traffic I choose to block is evaluated before docker rules are applied - that feels a bit like hack, but so far is the only way I have found. It is good practice in this day and age to run local firewalls on all hosts with policy deny, so that only traffic explicitly allowed can pass, that can severely limit blast radius during compromise.
merpkz··on IPv6 traffic crosses the 50% mark
As if people doesn't already carry always online machine in their pockets
merpkz··on IPv6 traffic crosses the 50% mark
How does IP bans work in IPv6 case? One just blocks whole /64 or /56 address range?
merpkz··on Meta Platforms: Lobbying, dark money, and the App Store Accountability Act
> Some kids will be trafficked with the help of all these tech solutions, because they know exactly where your kids are at every moment.

What the hell are you talking about? They already know where my kids are! At school which is funded by government.

Page 1 of 5Next →