HNHacker News
TopNewBestAskShowJobs

mgbmtl

2,457 karma · joined April 7, 2013

.
submissionscomments
mgbmtl··on Ask HN: What are you reading?
You may enjoy :

- End Times Fascism, And the Fight for the Living World (Naomi Klein and Astra Taylor)

- The Age of Extraction: How Tech Platforms Conquered the Economy and Threaten Our Future Prosperity (Tim Wu)

mgbmtl··on Nitter and XCancel receive cease and desist notices
Most of the forums I participated in, in the past, ended up dying because of a very persistent troll or two. Some of them I knew in person. They were just so arrogant and thought they were doing the right thing. The communities died. A healthy community gives everyone the chance to speak. In person, that's often done subtly by moderators.
mgbmtl··on A year of fighting scrapers on my 1.5 million-page website
I run scripts on my servers on an hourly basis to check which are the top 25 IPs visiting the server (aggregated by /24). If anyone in those top 25 IPs are from China, Vietnam, etc, or from Alibaba/Amazon/etc, the /24 gets blocked by iptables.

It's far from perfect, but it was a quick way to get rid of bots, while not completely blocking people from countries such as Vietnam.

However, on a Gitlab instance I manage (500 users), we have to restrict viewing of git logs and pretty much everything except issues. The bots were too aggressive. Chinese crawlers have access to a huge range of IPs and they often do only 10-20 requests per day, while generating in total over 50k requests per day. Our server load went from 99% down to 0.1% after that (and it's a fairly big server).

mgbmtl··on Ubuntu 26.04 Ends 46 Years of Silent sudo Passwords
I have a really long passphrase in keepassxc. I often try to type it, fail 50% of the time, display the password, fix the typo. I would not use a long passphrase otherwise. (I understand there are other risks, such as having spyware that is recording my screen, but my main worry is for the safety of the file itself)

I know sudo-rs will likely not allow viewing the password in the short term, but the benefit to being able to have some visual feedback, is that it lets me use a more complex password.

Other example: if I'm on a ssh link with very high latency (ex: on a phone), I might type one character at the time, make sure they register correctly, and continue. If I can't do that, then I'll type the password in a text editor, then copy-paste it into the password prompt.

mgbmtl··on France dumps Zoom and Teams as Europe seeks digital autonomy from the US
We have EU clients that now force us to use BBB (big blue button) for security reasons. It's not perfect, but good enough, and Zoom/Hangouts/Teams all have their quirks. We decided to adopt it where I work, and cut a few paid Zoom accounts.

Some clients use Jitsi, but I find it more complicated to run Jitsi in-house. BBB was really easy to setup.

mgbmtl··on Mozilla appoints new CEO Anthony Enzor-Demeo
Donations only get you so far. Take a mid-sized project, that needs $500k per year (a few devs, very modestly paid, zero expenses). It's a lot of money. It requires a huge user base. Say you have 500k users, and 5% donate $25 per year (I'm optimistic). And that's just $500k US, a few devs, zero expenses. A project that size probably has audit requirements, hosting costs, accounting, legal, trademarks, etc.

I see finances for a few free software projects, and many of them really struggle to get donations year after year, in a way that helps make the project predictable and sustainable.

For the US, people want you to be a 501c3, and then you need a EU equivalent. Canadians are unlikely to give to a US org (especially these days), but the market is too small to setup a local charity. So you need partners. All that has many compliance requirements and paperwork, so you need non-tech employees for the fundraising and accounting.

Eventually your big donors start blackmailing the project if you don't do what they want, and often their interests are not aligned with most users. You need various income sources.

mgbmtl··on Mozilla appoints new CEO Anthony Enzor-Demeo
I for one, am grateful to Mozilla for still being around, pushing for an open web.

Their documentation is excellent, the improvements and roadmap for Thunderbird made me finally adopt it, and I appreciate their privacy-friendlier translation services. uBO works great in Firefox, and I can't stand using a browser without its full features.

About MBA types: the free software project I work for has an MBA type, which I initially resented as being an outsider. However, they manage the finances, think about team and project growth long-term (with heavy financial consequences), and ignore the daily technical debates (which are left to the lead devs), and listen to users, big and small. Some loud users like to complain that we don't listen to them, and sometimes we kick them out, because we do listen to users.

I don't know much about Mozilla internals, if I am to judge from the results: Mozilla is still here, despite everyone saying for 10+ years that they are going to die. They are still competitive. They are still holding big tech accountable, despite having a fraction of their power. I can imagine that they make a lot of people here very uncomfortable.

mgbmtl··on Ask HN: How do you backup your Android?
The sync would stall and I'd have to go retry, or it would fail with no error clear message. In the end, I had no idea what had really synched correctly. The app was unhappy if I deleted a photo too quickly.

With Syncthing, I sync to a directory that my Nextcloud user can access (a read-only mount), so I can still easily share photos using Nextcloud, for example.

(although it's unfortunate that the Android syncthing app is being retired. h/t for the heads up and the recommended alternatives)

mgbmtl··on Ask HN: How do you backup your Android?
My device is not rooted, but I use Syncthing as well. I mainly sync my photos and my TOTP tokens (Aegis). The rest I don't care about.

I used Nextcloud sync in the past, but found it unreliable.

mgbmtl··on Court of Milan orders Cloudflare to block ‘piracy shield’ domains, IP addresses
I'm all for competition, but smaller players would have been completely blocked by Privacy Shield, whereas they cannot block CloudFlare completely without breaking a lot of other sites.

And CloudFlare went to court. Most companies would not be able to afford it.

mgbmtl··on Decline in teen drug use continues, surprising experts
ICQ was a way of texting friends so that you could go party. At least for me, and I'm a nerd. I remember even "normal" friends were using IRC as a way to hookup. Cell phones were not very common.

Looking at my non-nerd 17 year old, they meet maybe once a month, and it's to cook food together during the day. Nobody drinks. They just see it as a waste of money. Maybe not the most normal sample. They love biking and also go to circus school together (Montreal).

mgbmtl··on Ask HN: What do you monitor on your servers?
I like icinga's model, which can run a small agent on the server, but it doesn't run as root. I grant specific sudo rules for checks that need elevated permissions.

I find it easier to write custom checks for things where I don't control the application. My custom checks often do API calls for the applications they monitor (using curl locally against their own API).

There are also lots of existing scripts I can re-use, either from the Icinga or from Nagios community, so that I don't write my own.

For example, recently I added systemd monitoring. There is a package for the check (monitoring-plugins-systemd). So I used Ansible to install everywhere, and then "apply" a conf to all my Debian servers. Helped me find a bunch of failing services or timers, which previously went un-noticed, including things like backups, where my backup monitoring said everything was OK, but the systemd service for borgmatic was running a "check" a found some corruption.

For logs I use promtail/loki. Also very much worth the investment. Useful to detect elevated error rates, and also for finding slow http queries (again, I don't fully control the code of applications I manage).

mgbmtl··on Shoe prints lead FBI to suspect couple involved in multiple New Mexico wildfires
I mean, sure, you could blame the climate crisis on the petrol companies that have doubled production in Alberta in the past 10 years, or you suspect "eco-terrorists" which, as far as I know, is a Maxime Bernier conspiracy theory that has never been proven, despite the fact that environmental groups are constantly under CSIS watch? (https://www.france24.com/en/live-news/20230609-canada-wildfi...)
mgbmtl··on Ask HN: Best way to learn robotics with a 10 year old?
The Crunchlabs agent seems to be based off the Arduino Agent, so I'm surprised they don't support Linux.

My teenager never had any issues with using Linux since the age of 10 (old laptop with Firefox and Minecraft), and never used Windows (school uses Chromebooks). Hopefully this works with just a standard editor too, although the Crunchlabs IDE looks nicer for learning.

mgbmtl··on 10% of Cubans left Cuba between 2022 and 2023
Cuba rarely stamps passports to avoid those problems. They give you a piece of paper with a stamp, that you return on your way out.
mgbmtl··on Tech companies are flocking to the Middle East
That's an odd reference to DEI. I'd say the negative consequences of authoritarian regimes is that they suppress freedom, and therefore art and technological innovation.

China is authoritarian, but also has a huge political system, somewhat strong institutions. That can't be said of many authoritarian regimes, which tend to be more fragile. It takes a really long time to build civil institutions. For example, Russia has the money and an authoritarian regime, but repeatedly fails to innovate, and we can't predict what will happen when Putin leaves.

mgbmtl··on Show HN: BandMatch – “Tinder” but for finding musicians to create bands/collab
More like Feeld, imo :)

(Feeld also lets you skip a profile, and get back to it later)

mgbmtl··on I turned my open-source project into a full-time business
This may be terrible advice, but as a freelancer, getting sued by a company will cost them a minimum of $20k in legal fees just to get started. Unless you really messed up in bad faith, I would assume that most people will attempt to resolve things amicably.
mgbmtl··on Why are shopping carts always broken?
It's easier to maneuver, way easier to turn.
mgbmtl··on Google is making a map of methane leaks for the whole world to see
Seems OK to me? Coal mining has been steadily declining, but oil/gas production keeps increasing (at least in the US/Canada).
mgbmtl··on Git tips and tricks
Looks neat, but I tend to get way too distracted by graphical interfaces. I assume it's really a question of personal preference. CLIs are faster to use, but have a bigger learning curve. (we will probably not solve that debate here, but I do wonder sometimes, whether to recommend the CLI or not)

Most of my git usage on the CLI is nothing fancy, just a few commands, but I keep a text file for some tips/tricks I don't use regularly.

mgbmtl··on "Fake Chinese income" mortgages fuel Toronto real estate bubble: HSBC bank leaks
I'm surprised that you didn't mention the role of petrol in Alberta and hydro power in Quebec. They play a key role to sustaining the economy and social services. It's not just that though.

People are definitely less risk-taking, workaholics, despite having a social safety net, or maybe because of it. It's just maybe less in our culture to "go big or go home". Having a cabin in the woods and free time to live your life is nice.

Maybe because I live in Quebec, and language is definitely a barrier (requires immigrants to be trilingual), but I haven't met many shady people from China or India, on the contrary. My ancestors came here by accident from different countries, taking a random boat in a port, worked hard and made it. I hope we can give that opportunity to others too.

mgbmtl··on Trello Allegedly Breached
What's the endpoint? Why did it provide personal information? Why wasn't it throttled?

Many things don't matter at a small scale, but they do at 15M-scale.

Trello users are about to get bombarded by phishing attempts and spam.

mgbmtl··on Using the ZBar barcode scanning suite in the browser with WebAssembly
This would be awesome. I wish it at least worked on Safari iOS. (Firefox seems unlikely: https://bugzilla.mozilla.org/show_bug.cgi?id=1553738)

We have a web app that does QR scanning for event badges, using a JS library, but it's painfully slow compared to the camera app.

mgbmtl··on Critical Gitlab vulnerability exposes 2FA-less users to account takeovers
Isn't that a usability vs security trade-off? Asking naively as a non-expert here.

In some systems, a password reset lets you bypass MFA. On Gitlab, however, you might be able to reset the password, but it will not let you bypass MFA (which was a nice mitigation for this CVE).

I often wonder about this, because people's email should have fairly good security (MFA, detect new devices, suspicious IPs, alerts, etc), and MFA on the other service lets them have similar protections. Both services might not be bullet-proof, but an attacker will likely generate alerts in one or the other.

Most of my users are very non-technical, and might not have access to their MFA (MFA reset requests are fairly frequent), so to be able to access using a one-time-secret sent by email seems like an acceptable compromise, especially if it means that more users will enable MFA. In systems I administer, less than 20% of users tend to enable MFA (it depends on org policy, and it's often optional).

Speaking of, I wish services would do auth by: login -> MFA -> pass, instead of login -> reCaptcha -> pass -> MFA. Especially for scenarios where MFA is mandatory. Having reCaptcha is really annoying considering I went the extra step of enabling MFA (ex: Stripe, Quickbooks).

mgbmtl··on Bluesky has launched RSS feeds
Yeah I have an account on that Mastodon server and even logged-in, that page shows popular (rage-bait) content regardless of my personal preferences. It filtered by language but not region (so it was mostly content from another continent).

However, my actual Mastodon feed only has content from people I follow, without any recommendations, and that works great.

mgbmtl··on Outlook/Hotmail is no longer blocking my mail server
I guess it depends if the government recognizes the marriage date that is declared, or the date that they process it (if the marriage was not in front of an official).

Divorce date can be pretty random, since it's rarely done live by a judge/official.

mgbmtl··on Did English ever have a formal version of "you"? (2011)
I guess like "comrade", any kind of imposed social norm becomes an object of satire?
mgbmtl··on Substack says it will not remove or demonetize Nazi content
I was being cynical, but I think it's a safe assumption. Visa/MC guidelines are usually the reason for bans on sex-related content elsewhere. I really doubt they have morals here. They just want to drive engagement/revenue, lower their expenses on moderation.
mgbmtl··on Substack says it will not remove or demonetize Nazi content
Sadly, Stripe bans the former, not the latter. And that seems to be their moral guidelines: Nazi content drives engagement.
Page 1 of 23Next →