HNHacker News
TopNewBestAskShowJobs

mmh0000

3,958 karma · joined July 15, 2021

submissionscomments
mmh0000··on Tell HN: Uceprotect is extorting website owners
I ran my own small-business/family mail server for a little over a decade. Spam is out of control.

UCEPROTECT and other RBLs are just lists of text files. They do not block anything. As the mail administrator, you can choose what you do with a UCEPROTECT listing.

When I ran my mail server, I had UCEPROTECT tied into SpamAssassin, so that a UCEPROTECT listing by itself wouldn't block email; it would just raise the "spam probability rating" up.

UCEPROTECT is not a huge professional thing; it's "some guy" who's been running it, effectively, for free since the very early 2000s. No one is obligated to use it. If someone is being blocked by it, they need to contact the mail admin. UCEPROTECT just lists problematic hosts.

On to WHY DO and no CF/AWS? I don't know.. I'm not the "some guy" running the thing. But if I had to guess, it's that DO doesn't respond to spam complaints[1]. Whereas CF/AWS, while they host spammers, will take action against reported spammers.

[1] https://www.reddit.com/r/sysadmin/comments/1cwilrc/does_digi...

mmh0000··on Tell HN: Uceprotect is extorting website owners
It’s not ridiculous.

Hosting providers should be good citizens of the network and immediately terminate spammer accounts. This used to be standard practice until about 2015. When suddenly management decided it’s more profitable host spammers than not.

I think this is a great policy decision by uceprotect.

mmh0000··on Red Hat being phased out of existence?
Duh. I said in my first post: I like the RH ecosystem. I do not like RH corporate.
mmh0000··on Red Hat being phased out of existence?
As a Senior Engineering Manager, I can tell you that, per my directive, we've actively standardized on Rocky Linux. We're moving away from everything else, including RHEL.

I was a long-time RHCX (Red Hat Certified Examiner). From around 2005 to 2015. When IBM bought Red Hat, I saw the writing on the wall, but I was optimistic it might be a Good Thing™. It wasn't a good thing. Red Hat has been pretty stagnant, as the article says. RH is 90% AI slop today. They'll live on as a brand for a long time, but from a technical perspective, they don't have much to offer.

In the early 2000s, I recommended paying for RH because their technical support was amazing. Now, it's mostly 3rd-party contractors who know less than what you can find with a Google search. Unless you are extremely lucky, you never get to talk to actual RH engineers anymore.

I really like the Red Hat ecosystem and system design. However, I feel like they've petered out and won't recover from where they're headed. (I say, as I type this on my personal laptop running Fedora).

TL;DR: RH went from a super-nerd company to coasting on its former success.

mmh0000··on Red Hat being phased out of existence?
I don't know what Watson-powered elevators do, but your comment reminds me of this:

https://play.elevatorsaga.com/

Which, once you start playing, can be very difficult to detox from.

mmh0000··on Suspension of the de minimis administrative exemption for imports $800 or less
People are downvoting you.

But I'm assuming this was a joke about the conspiracy that midterms will be canceled one way or another due to a "national emergency". Which, sadly, is much more probable than it should be.

mmh0000··on Border agents can search cellphones without a warrant or reasonable suspicion
It is insane to me that judges consistently rule that the constitution doesn't apply because there's a "border" within 100 miles.

The 4th Amendment says, exactly:

   The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.
I do not know how that could be unclear. My cellphone is my effect, and arguably, also a "paper". Which SHALL NOT BE VIOLATED. But apparently, I'm too dumb to understand the sentence[1].

[1] https://en.wikipedia.org/wiki/Fourth_Amendment_to_the_United...

mmh0000··on Tell HN: OpenAI keeps re-enabling the 'allow training' setting
Yes, because if there is one thing societies of the 1700s are known for, it's consumer protection practices.

/s for the /s impaired.

mmh0000··on Tracking Costco gas prices
It really doesn't sound good. A loss leader is meant to get you into the store; the gas station is usually far away, in the back of the parking lot.

Their $5 chicken now, that's a great "loss leader" (if it even is; that isn't confirmed). Because that forces you not just into the store, but all the way to the back. So you go in for the $5 chicken and leave with $20 of blueberries, $20 of cereal $20 of milk $20 of mayo.

mmh0000··on Xorg-server 26.1.0 rc1
Sorry.

Easystroke is a mouse-gesture program: hold button, draw various lines or shapes, release button. Triggers any action. Like window minimize, execute command

This is the “official” repo but it was abandoned long ago: https://github.com/thjaeger/easystroke

My first linked repo is me and Claude working to fix build errors and app bugs to keep it running.

mmh0000··on Xorg-server 26.1.0 rc1
That's a new take: Project with new release 1 day ago declared deprecated!

I've been using Linux for around 2 decades. I am currently running Fedora 43/KDE Plasma ... and wait for it ... Xorg.

Why? Because it works. It works well!

Why don't I use Wayland? Because it breaks everything.

  - Screensharing is just wonky and inconsistent across applications. It has gotten better in the last 2 years, but it's still quite wonky. And janky. And flobby. I **could** put effort into fixing this, but it already works in Xorg. 
  - I have a bunch of Xorg/xdotool scripts bound to hotkeys. Move, resize windows. If AppX is running and the window isn't shown, show it; otherwise, hide it. If AppX and AppY are both running and meta+y is pressed, then tile in a specific way, else do something different. These scripts are either ungodly difficult to rewrite to work in Wayland or just flat-out impossible in the name of "security".
  - Easystroke. https://github.com/mmh0000/easystroke . Nothing like that exists on Wayland (that actually works). And I can not live without it after having it for 20 years.
mmh0000··on Claude writing a macOS driver for my obscure HP printer built only for Windows
LLMs are good at producing what they/the public know.

In this case:

  LLMs know the USB Spec very well.

  LLMs know how to read raw packet dumps.

  LLMs know how to convert a packet dump to USB spec

  LLMs know how to write code to generate USB packets from the spec.
LLMs are also VERY good at transliteration, i.e., converting known-good Python to Rust.

Basically, If you have a well-documented problem, the LLM is a shortcut to learning it yourself. LLMs fail when you have a novel or poorly documented problem. They also fail when you provide the LLM with terrible context or too much context.

mmh0000··on Fairphone 6 and PostmarketOS working main camera
Just of the top of my head:

Running Firefox with uBlock.

Installing any app I want, not just the ones Apple allows.

Faking GPS data to hide my location from spyware that "requires" location permissions

(To be fair, you can do these on Android "for now", but Google is actively working hards towards the more locked-down Apple "experience")

mmh0000··on Ask HN: What is your favorite lightweight tool or CLI utility in 2026?
I’m not saying yours does, but be careful with LocalCommand, it will often break rsync and other tools that use ssh behind the scenes.
mmh0000··on Tracking down a Zsh history data loss bug
This is exactly why I stopped using Bash around 2012. I was soooo tired of losing random shell history.

If you haven't looked into ZSH, it has some really nice customizations. Notably, from my config[1]:

  # Remove dups
  setopt HIST_FIND_NO_DUPS
  setopt HIST_IGNORE_DUPS
  # Don't  log commands starting with a space
  setopt HIST_IGNORE_SPACE
  # Replcae bang-command !34 with the actual command in the history
  setopt BANG_HIST
  # Remove extraneous spaces
  setopt HIST_REDUCE_BLANKS
  # Write the history file in the ":start:elapsed;command" format
  setopt EXTENDED_HISTORY
  # Record run-time of the command
  setopt INC_APPEND_HISTORY_TIME
[1] https://doc.xn0.org/.zshrc
mmh0000··on Tracking down a Zsh history data loss bug
I have nearly a decade of zsh history. Reading that article I came to the conclusion that I may have been hit by that bug in the past but I haven’t noticed.

Then I kept reading and the author mentions accidentally exporting HISTFILE[1] and I screamed in terror and ran to my computer as I realized a mistake I’ve been making for…ever.

I am now both happy and sad I read this article.

[1] https://github.com/stapelberg/configfiles/commit/32dcda0f49a...

mmh0000··on I close SSH port 22 (and what I use instead)
Seriously. If a zero-day drops in OpenSSH, it's quite literally the end of the world.
mmh0000··on I close SSH port 22 (and what I use instead)
This is a bad idea™. You should never have more than one UID 0 on a Unix system. This will violate most corporate security guidelines (STIG and CIS) *. And for good reason.

A much better idea is to set up a non-root user and configure sudo correctly.

* https://www.stigviewer.com/stigs/red_hat_enterprise_linux_9/...

mmh0000··on I close SSH port 22 (and what I use instead)
I've been using nftables for port knocking for a while now. I run an SSH tunnel server that needs to be globally accessible. But I don't want it getting hammered by bots nonstop.

So, I have this nft script which works alongside Firewalld:

  $ systemctl enable --now nftables
  $ cat /etc/nftables/portknock.nft
  table ip portknock {}
  delete table ip portknock
  
  table ip portknock {
      set knocked {
          type ipv4_addr
          flags timeout
          timeout 6s
          gc-interval 2s
      }
  
      # Before conntrack: record the knock, then drop the packet.
      chain prerouting_knock {
          type filter hook prerouting priority raw; policy accept;
  
          tcp dport 12334 fib daddr type local tcp flags syn counter add @knocked { ip saddr } drop
      }
  
      # Decision chain for port 41444. Every branch is counted so that
      # `nft -a list table ip portknock` shows which path traffic took.
      chain gate_41444 {
          # Established/related sessions pass unconditionally.
          ct state established,related accept
  
          # Host-local. Rarely matches: host-originated traffic is DNATed in
          # the output hook before it reaches prerouting. Kept as a safeguard.
          iifname "lo" counter accept
  
          # Podman containers reaching the published port (hairpin).
          ip saddr 10.88.0.0/16 counter accept
  
          # Trusted subnets.
          ip saddr { 10.0.0.0/24, 10.1.0.0/24 } counter accept
  
          # Knocked within the last 6 seconds.
          ip saddr @knocked counter accept
  
          # Default deny. If THIS counter is 0 and the accept counters are
          # also 0, the chain is not being reached at all -- investigate.
          # Do not assume the gate is working just because nothing got in.
          counter drop
      }
  
      chain prerouting_gate {
          type filter hook prerouting priority mangle; policy accept;
  
          tcp dport 41444 fib daddr type local jump gate_41444
      }
  }


Then on the client side, I can use anything to send the knock, but usually I just script it out with `ssh` like this:

  $ ssh -p 12334 -o ConnectTimeout=1 "${sServer}" &> /dev/null
  $ sleep .5
  $ ssh -o 'ExitOnForwardFailure=yes' -o 'StrictHostKeyChecking=no' -o 'LogLevel=ERROR' -fp 41444 -R "${iPort}:localhost:22" -T "${sServer}" "sleep 14d"
The biggest benefit is that it doesn't require any non-standard tooling. If you have an SSH client and know the rules, you can connect.

Yeah, it doesn't have all the "cryptographic signatures" of the article; at the same time, it doesn't have some "random" 3rd-party application that faces the internet and directly controls firewall rules that way.

It's still an OpenSSH server with key-auth only. I'm not worried about someone carefully watching my traffic and finding it. I just need Internet bots not connecting to it a million times a second.

mmh0000··on Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
It's all TLS certs, because they show up in the Transparency Log[1]

You can watch a live stream of it here: https://bencevans.io/security/certificate-stream

[1] https://en.wikipedia.org/wiki/Certificate_Transparency

mmh0000··on A year of fighting scrapers on my 1.5 million-page website
I disagree. I personally consider these my biggest problems with the Web:

  - Bias, specifically commercial bias
  - Webpage formatting: every website looks different, hides the information I want in different places. Sure, it "looks pretty", but I don't want pretty; I want info
  - Scams/SEO/etc...
The LLMs are very good at reading from multiple sources, parsing, and presenting only the data in a consistent format. There are many examples of this, but if you want a good one to try for yourself:

Google "How to make ham fried rice"; you'll get 10,000 articles, most pretty good recipes. But they're all different; most of them are just bait for ads. And most of them, the 10-line recipe is hidden between 50 useless paragraphs about how serving food is life's most important goal.

Now, ask an LLM to search for it, find the best combination, and list only the recipes. You get a perfect, 10-line recipe that doesn't waste your time.

mmh0000··on I added a real-time chat to my blog, people used it to attack me
There is a well-reviewed study on this from 2004 -

Greater Internet Fuckwad Theory[1]

[1] https://www.penny-arcade.com/comic/2004/03/19/green-blackboa...

mmh0000··on Ask HN: Who wants to be hired? (August 2026)
Linux DevOps/Infrastructure Engineer - Clouds(AWS, Azure, DigitalOcean, *), Kubernetes(OpenShift, EKS, k8s), CI/CD, Networking, programming, whatever.

I'm currently a manager of a team of 5 Infrastructure Engineers, and I've also worked as an I.C. in the same role.

If you want fast, secure, stable, scalable deployments and servers, that's me!

  Location: SLC, Utah
  Remote: Preferred
  Willing to relocate: Maybe, probably not.
  Technologies: All Things Linux, DevOps
  Résumé/CV: on request
  Email: mmh-hn49156682@headlee.net
mmh0000··on The lost civic life of movie rental stores
You’re not going to like this answer. But I think you’ve just described a Walmart Supercenter.
mmh0000··on Ask HN: Is the GitHub pancake menu now a pancake emoji?
Oh man. I just assumed this was unchecked Microslop.

It's funny when a brand doesn't realize how the public has started perceiving them and makes quite ironic choices that should have been caught well before they went to the public eye.

My train of thought was:

  - LLMs way over-use emojis
  - Replacing a standard icon with a look-alike emoji was probably an LLM mistake
  - From a company that has been pushing sloppy AI hard. 
  - Must be Microslop!

They should have either used a custom picture that wouldn't be mistaken for slop, or they should have more clearly called out why they changed it. For me, even now that I know it is supposed to be an easter-egg, it just feel like slop.
mmh0000··on Gemini Robotics 2 brings whole body intelligence to robots
I think this is way too optimistic. I suspect these things will be only available to the already-quite-wealthy. While the poor (i.e., not billionaires) are left to rot and starve without jobs, property, or livelihoods. Then, when the poors (i.e. us) become too much of a headache, these things will be deployed to murder the poors (i.e. me).

I am imagining a world somewhere between the movie Elysium and Oblivion.

mmh0000··on Using ThinkPad T480 as a mobile phone
May your wish be granted:

https://www.amazon.com/GPD-Pocket-LPDDR5X-Bluetooth-Handheld...

plus this: https://gpdstore.net/gpd-pocket-4-4g-lte-module/

mmh0000··on Using ThinkPad T480 as a mobile phone
Lenovo has whitelists for both wifi and cell cards. It's highly annoying.

A decade ago, I had a Lenovo Yoga 2. The Wi-Fi card it came with only supported 802.11g, or something old and outdated at the time. I learned about the whitelist the hard way when I bought a decently (then) up-to-date wifi card to upgrade, and the computer refused to boot.

But! I refuse to let a computer tell me no... So, after many many (too many) hours of reading forums, dumping firmware, flipping bits, and pushing firmware, I got the stupid card to work. And of course I took no notes, so if I had to do it again, I'd be starting from scratch.

mmh0000··on JetZero
That only works if the engines move the planet around the airplane.
mmh0000··on GDID Windows – Cut the tracker that follows you even under VPN
Have some light reading:

"required" spyware: https://learn.microsoft.com/en-us/windows/privacy/required-d...

"optional" (but on by default) spyware: https://learn.microsoft.com/en-us/windows/privacy/optional-d...

This is my favorite:

  Data Description for Browsing History data type

  Microsoft browser data subtype: Information about Address bar and Search box performance on the device

   * Text typed in Address bar and Search box
   * Service response time
   * Autocompleted text, if there was an autocomplete
   * Navigation suggestions provided based on local history and favorites
   * Browser ID
   * URLs (may include search terms)
   * Page title and notification text
Page 1 of 30Next →