HNHacker News
TopNewBestAskShowJobs

mivok

166 karma · joined August 15, 2007

[ my public key: https://keybase.io/mharrison; my proof: https://keybase.io/mharrison/sigs/k--vU3rR5ddONbKLfCZcI8h0ZV-IDjGlTtvw-m8Gq2Q ]
submissionscomments
mivok··on K3s – Lightweight Kubernetes
It includes the flannel network plugin by default (although you can change this) and a basic service load balancer (technically not an ingress, but providing the same functionality). From the README:

> k3s includes a basic service load balancer that uses available host ports. If you try to create a load balancer that listens on port 80, for example, it will try to find a free host in the cluster for port 80. If no port is available the load balancer will stay in Pending.

mivok··on The joy of index cards (2009)
This sounds very similar to what you're looking for: https://thenoteboard.com/. Sadly it doesn't seem to be available right now, but it's a pocket whiteboard made up of 3x5 segments. It folds down rather than being a stack of cards, but it may work for what you're thinking of.
mivok··on IoT Goes Nuclear: Creating a ZigBee Chain Reaction
Hue forces updates on you every time you go into the app if there's one available, and you can't use the app until you've updated. Granted this isn't ideal if you primarily use your light switch or an amazon echo to control the lights, and fully automatic updates would probably be better, but it comes pretty close to aggressively pushing updates.
mivok··on Why Your Excellent Conference Talk Was Rejected
A lot of the comments here are complaining about the last point in the article (the n00b), asking how on earth you get started if you have to have presented before in order to present. The article is telling you exactly how to do that:

- Speak at local user group meetings. Most of my local meet ups are constantly calling for speakers, and it's an excellent way to get practice at presenting in a lower stress environment. It's not always small audiences either, I've seen and given talks with 50 or more attendees at a local meet up. As for getting accepted, organizers are always in need of talks, and organizers are not getting 6 submissions per month, they're usually lucky if they can fill every month with a talk, so you're much more likely to be accepted.

- Maintain a blog. Writing articles on your blog is practice for writing a talk, and gives you a steady stream of ideas that can be turned into a presentation fairly easily.

I'm going to add a couple more:

- Give a lightning talk at conferences you attend. As well as giving you practice, you are also visible to all the attendees, including people who will be selecting talks at future conferences you submit to.

- Submit to smaller, more focused or more local conferences. You can't expect to be accepted at huge popular conferences speaking in front of hundreds of people on your first try. Submitting to more focused conferences gives you a better chance of being accepted.

These steps aren't going to make it so that you're immediately accepted at large conferences, but they give you the start the article is claiming you need. And finally, if you're rejected, don't give up. Conferences do take chances on new speakers (although probably not all new speakers who submit a talk), and being rejected doesn't mean your talk is bad, or that your skills are bad, just that you didn't get it this time.

mivok··on ODROID-C1 – Quad Core ARM Linux computer
Micro HDMI. You have to go to the technical details tab to see it mentioned.
mivok··on Command-line file sharing
Even shorter/easier to remember version of the command (you don't have to specify the filename twice if you don't want):

    curl -T ./filename transfer.sh
mivok··on Curl.io – Share files from your terminal or ssh
Make it support PUT instead of POST with a file form field and the command becomes simplified to:

    curl -T filename http://curl.io/send/abc123
mivok··on Does your browser rejected revoked certificates?
Explanation of exactly why chrome doesn't have 'Check for server certificate revocation' checked by default: https://www.imperialviolet.org/2012/02/05/crlsets.html

The short version is that it's slow and not as effective as it might seem.

mivok··on Npm's Self-Signed Certificate is No More
If the clients trust the npm CA, can't they just sign the digicert CA with that CA and include it in the certificate chain provided by the server? That way the chain would be:

    npm CA -> digicert CA -> any other intermediates -> server cert
Clients that only trust the digicert CA (and other standard CAs) will see that and accept it because they trust the digicert CA, and clients that trust the npm CA will trust the cert also, allowing both old and new clients to work. Once (almost) everyone has upgraded, the npm root CA can be removed from the chain presented by the server. Am I missing something here?

Edit: It looks like what I'm missing is that you'd need the private key of the digicert CA to generate the request to sign with the npm CA. I was thinking about how CAs have been migrated in the past (e.g. equifax to geotrust global CA). It looks like it won't work in this case.

Edit2: Actually, it appears to work after all. I just tested with the openssl ca command, and you give it -ss_cert instead of -in for the certificate to sign a certificate instead of a request.

mivok··on Ask HN: Who Is Hiring? (September 2012)
Fulton, MD or REMOTE

Site Reliability Engineer at OmniTI Computer Consulting

The OmniTI Ops team is a flexible and progressive group. We work closely with developers, DBAs, and client groups to help them manage availability and performance in the midst of constant changes. We are not risk averse; instead we strive to understand why things fail and understand the true impact of those failures, so that we can empower others. Collaboration is a cornerstone, and we understand that being friendly and outgoing are keys to making that work.

See http://omniti.com/is/hiring/site-reliability-engineer

mivok··on One-time Secret: Share passwords etc with URIs that work only once
Then the receiver reports to the sender that the link didn't work. The sender, not knowing if the password was compromised or if it was a situation you mentioned above, changes the password/revokes the key and generates a new one. This time, the receiver doesn't access it at closing time in Starbucks/doesn't switch tabs, and gets the new password correctly.

Unexpected behavior doesn't happen every time.

As an optimization, if you have a self hosted service of this sort that gives proper logs, you can probably verify that the link wasn't intercepted by looking at the source IP and comparing to what the user reports (if they're able to do that, if not, you fall back to assuming it was compromised), and if so, skip the revocation/regeneration procedure.

mivok··on One-time Secret: Share passwords etc with URIs that work only once
All of those objections boil down to not trusting a 3rd party service.

I wonder objections there are to running your own service of this type? This way you could guarantee the physical security, keep up with regular patches, manage your own logging, and securely delete the secrets to your satisfaction.

The only real objection I can think of is that writing software without security holes is hard. This applies to any security related software however, and the solution is to use 'proven' apps that have survived scrutiny. This type of app is pretty simple, which would ideally be relatively easy to audit.

In principle, a read-once URL that you can safely send via email seems to be a pretty efficient way of dealing with sending passwords or other keys without having to deal with GPG or similar. Just tell the client 'Click on this link, that's your password. This message will self destruct'. If it's intercepted, you can detect this, and change the password/revoke the key. I'm sure I'm missing something, but if not, it would be nice to have this become the standard way of distributing new passwords or keys for services rather than sending by email (for those services where you have an initial password generated for you).

mivok··on Ask HN: Who is Hiring? (April 2011)
Columbia, MD - OmniTI

Site Reliability Engineer (Systems Administrator), Database Administrator, Web Engineer (Perl or PHP), Project Manager, Javascript Developer, Web Interface Designer

See http://omniti.com/is/hiring (and http://circonus.com/careers for the Javascript Developer Position).

mivok··on How Allies Used Math Against German Tanks
If you like stories like this, there are a number of similar stories (e.g. this one, cracking the enigma code, protecting convoys) in a book called The Pleasures of Counting: http://www.amazon.com/Pleasures-Counting-T-W-K%C3%B6rner/dp/... - it's not all world war 2, but is very interesting and does contain a lot of information on the math used during the war.
mivok··on Google sends Cr-48 to "Will it Blend?"
Go to about:flags and enable media player, then it will play pretty well (although it's a little laggy when played full screen)
mivok··on Open ID Is A Nightmare
Why not blame the bigger sites? If they accepted logins from other OpenID providers, then people would have a lot fewer possibilities to remember. I honestly believe this is a big part of the problem with OpenID adoption currently.
mivok··on Open ID Is A Nightmare
It seems to me that the problem of multiple OpenID providers and people not knowing which one they're using would be a lot less serious if all of these companies that are OpenID providers actually accepted logins via OpenID themselves instead of everyone paying lip service to the idea while trying to be the one source of identity for everyone else. That way you could be using the same ID for twitter/google/facebook etc. and when it says 'use your google/twitter credentials to log in' then there is only one set of credentials to use.
mivok··on Open ID Is A Nightmare
Actually, it seems to me the bigger problem is that some providers just decide to change who they say you are, and those providers (Google) just happen to be the biggest because you're telling users 'just use your google login here'. They don't know anything about openID. Sure, users having multiple OpenIDs is an issue when they forget which they used, but even if this was solved, the other issue seems to be much worse.
mivok··on Piwik hits 1.0 - Open source web analytics
No (speaking from experience - we've had no end of issues with piwik and larger websites)
mivok··on No visa required
I just recently returned to the US and for the first time got to go through the citizen's/residents line (Green card holder), and the difference between the two was unbelievable. This time round, the queues were a fraction of the size, the immigration officers were friendly (as opposed to being outright rude to visitors) and the whole process was incredibly simple and quick. The difference is striking, and I'm certain it's not just me - visiting family always complain about how long immigration takes.
mivok··on Reddit: I stopped using a task killer to see if there's a difference. It's huge.
My wife's phone (Eris) has the exact same issues. I put a task killer on, and immediately the lag issues were reduced. I've just tried switching from Sense to the stock home app and removing the task killer to see if it would help. Interestingly my own phone (Droid) has never had any issues and works fine without any task killer apps.
mivok··on Proposal: "{" and "}" to be known as openstache, closestache
That's how I learned it (although I never used 'round brackets' explicitly). This gets really confusing when you begin to talk to Americans and refer to 'brackets', thankfully everybody understands parens, and the others are the same.
mivok··on Emacs Org-Mode: for Notes, Project Planning, and Authoring
I've been working on a todo list app for vim, loosely based on org mode. It doesn't cover many of org mode's features right now, but if you want to take a look anyway, the source is at http://git.mivok.net/gitweb/?p=vimtodo.git;a=summary
mivok··on Corporation Says It Will Run for Congress
One of the best comments I saw on the page was that, if one person has the right to free speech, then groups of people also have a right to free speech. However, it also seems clear to me that if one person can have a seat in congress, multiple people can't have that seat. This argument would allow the courts to strike this down while keeping the Citizens United decision in full force.
mivok··on Amazon, Macmillan: an outsider's guide to the fight
Actually it looks like you got it. Apple isn't trying to be the publisher too, whereas Amazon is. The publisher is objecting to what Amazon is trying to do.
mivok··on Founder visa bill proposed
It's possible that it will end up being a 'conditional permanent residence' that you have to renew after 2 years (the condition being that you still have the company). This is what happens for green cards that are granted on the basis of a new marriage.
mivok··on Do what you love mirage
So... a food critic or mattress tester?
mivok··on Send packages via social networks (without disclosing recipient address)
Sounds like it will work great until you send a GPS tracker along.
mivok··on Ask HN: Who's hiring (take 3)?
OmniTI is hiring: http://www.omniti.com/is/hiring (Columbia, MD and Brooklyn, NY) - DBA/SA/Web Dev
mivok··on Stackoverflow Eating Away at Experts-Exchange
The actual values are probably even word for expertsexchange than that. The traffic to serverfault.com and superuser.com should be added to the above values also.