HNHacker News
TopNewBestAskShowJobs

movedx

2,540 karma · joined September 11, 2015

Systems engineer and educator.

YouTube: https://www.youtube.com/c/MichaelCrilly Discord: https://discord.gg/MTzBvSS

submissionscomments
movedx··on Polis: Open-source platform for large-scale civic deliberation
Every Body Corporate Strata in Australia basically goes through something like this at least once a year (by law.) Questions are posed about what to vote on and you either vote for, against, or abstain.

Something like Polis would be good for putting forward ideas throughout the year leading up to the vote, as it would find a consensus of ideas and help shape what you eventually vote on (you decide as a body corporate.)

Some Strata are hundreds of people in size.

movedx··on Photos capture the breathtaking scale of China's wind and solar buildout
I feel like energy is the most critical aspect to any economy and military. It's the beginning of anything and everything you want to achieve.
movedx··on Apple Creator Studio
Please don’t take this as me saying you were wrong to ever trust Apple, however the best way to organise any data is usually just files on a disk.

That’s becoming a recurring theme for me and even some of my corporate clients now. Confluence, for example, is out the window for secure documentation around sensitive environments and Word Docs in One Drive are back in. It’s surprisingly refreshing and gets the job done way better.

movedx··on UK Orders Ofcom to Explore Encryption Backdoors
UK isn’t an EU member state.
movedx··on I got hacked: My Hetzner server started mining Monero
Learning to manage an operating system in full, and having a healthy amount of paranoia, is a good first step.
movedx··on I got hacked: My Hetzner server started mining Monero
You’ll set yourself up for success if you check the dependencies of anything you run, regardless of it being containerised. Use something like Snyk to scan containers and repositories for known exploits and see if anything stands out.

Then you need to run things with as least privilege as possible. Sadly, Docker and containers in general are an anti-pattern here because they’re about convenience first, security second. So the OP should have run the contains as read-only with tight resource limits and ideally IP restrictions on access if it’s not a public service.

Another thing you can do is use Tailscale, or something like it, to keep things being a zero trust, encrypted, access model. Not suitable for public services of course.

And a whole host of other things.

movedx··on A Safer Container Ecosystem with Docker: Free Docker Hardened Images
Thanks for only doing this like, ten years later after all the damage is done.
movedx··on Thin desires are eating life
Very cool.

I started using my IT and data management skills on film sets to provide data security around the footage. It’s been a breath of fresh air to use advanced concepts in a field that’s very hands on and a big team effort. A lot of communication and working together. It’s been great.

movedx··on A Love Letter to FreeBSD
You don’t learn in production. We’re talking about running production workloads here, not a localised lab. You can learn just fine locally with or without docker and other tooling that “eases” deployment of software. But when it comes to production it’s best to have a solid idea of what you’re doing and what a real production system requires.

Sadly, when people learn locally with “docker compose up” that becomes their baseline, their reality, and they believe everything else is taken of for them. Actually, you’re still running a process that’s bound to a network port (but with extra steps, because you used a container), and the entire ecosystem around that still needs to be secured.

That’s what’s been lost as of late :-(

movedx··on A Love Letter to FreeBSD
Thanks for sharing and clarifying those details :)

And yes, jails are way better, but here we are.

movedx··on A Love Letter to FreeBSD
> Dockerfiles are also an excellent way to distribute FOSS to people who unlike you or I cannot really manage a systems, install software, etc without eventually making a mess or getting lost (i.e. jr developers?).

Read what you just said:

> ... to people who unlike you or I cannot really manage a systems ...

These are people who should not be running systems.

> I build my important images from scratch all the time...

I doubt it, but assuming you're telling the truth, then you're a rare cookie because my clients don't even do that, and they're either government bodies with millions in funding or enterprises with 60,000 employees across the entire globe.

Again, the art of the operating system, and managing it, has been lost. It's been replaced with something that adds even more problems, security or otherwise, for the sake of convenience.

I hope everything works out super well for you, friend.

movedx··on A Love Letter to FreeBSD
You couldn't be further from the truth, though.

What you're saying here is: someone new to this simply uses Docker and everything just works and is fine. The support is heavily reduced (for you, not the user) and so everything is good.

And that mentality is why we have crazy botnets doing terabytes per-second attacks these days -- your users just firing up a VM, using "docker compose up", and walking away because "it just works". The reality is, that system falls out of date pretty quickly, and exploit is found and patched, but that patch never sees the light of day for that user.

It's awesome you can get a user up and running so quickly, but the sheer amount of work required to actually maintain a server is too much for the average EVE Online player trying to run some ESI tool

movedx··on A Love Letter to FreeBSD
From another commentator: "Lenovo T480s works great with FreeBSD."

It was a Lenovo T480s :)

movedx··on A Love Letter to FreeBSD
> FreeBSD doesn't afford you any more or less control over how the system works than Linux.

And yet, I'm constantly patching and working around lib issues on Linux (on the desktop), but never with FreeBSD. That's the point being made. Linux is a lot of stuff mashed together to make a system, and it works really well, but FreeBSD is a collection of components carefully curated and maintained as one and works very, very well most of the time.

If Linux works for you, use it. No one is trying to convert you.

movedx··on A Love Letter to FreeBSD
I think that’s true yeah.
movedx··on A Love Letter to FreeBSD
> Yeah ok ... 500 out of 500 supercomputers running Linux ...

So what? Big whoop.

movedx··on A Love Letter to FreeBSD
Sigh. Yes. It’s the boring choice and therefore the better choice a lot of the time. Not all of the time, but most of the time.

Impatience and lost skills is why it’s not a mainstream player.

movedx··on A Love Letter to FreeBSD
Why does it have to? Why does everything have to supper everything? Why can’t a project have a focus on servers and that’s its “thing”?

Also it’s OSS — contribute that support if you’re so passionate about it.

movedx··on A Love Letter to FreeBSD
Linux is OK. It’s a mess compared to BSD, but it’s OK. It’s the lazy man’s solution. It’s mainly for people who only want to “docker compose up” and walk away. The art of the OS has been lost. People think the OS is something to be abstracted away as much as possible and it’s evil and hard to secure. Shame.
movedx··on A Love Letter to FreeBSD
I’ve been using it in VMs just fine. Used it on my desktop just fine for a year. Used it on laptops just fine.

You might have just hit a bad hardware setup that’s outside the scope of support. It happens.

movedx··on A Love Letter to FreeBSD
For years and years to come. You’ll never need to update that box, frankly.
movedx··on A Love Letter to FreeBSD
Lovely stuff. The industry would be so much better off if the family of BSDs had more attention and use.

I run some EVE Online services for friends. They have manual install steps for those of use not using containers. Took me half a day to get the stack going on FBSD and that was mostly me making typos and mistakes. So pleased I was able to dodge the “docker compose up” trap.

movedx··on A Love Letter to FreeBSD
I feel like you may never have used it. Would that be true?
movedx··on A Love Letter to FreeBSD
I once upgraded a FreeBSD system from 8 to 12 with a single command. I don’t recall having to reboot — might have needed to.

Can you give that shot for me on Linux? Could you spin up a Ubuntu 14 VM and do a full system update to 24.04 without problems? Let me know how you go.

I once needed help with a userland utility and the handbook answered the question directly. More impressive was the conversation I had with a kernel developer, who also maintains the userland tools — not because they choose too but because the architecture dictates that the whole system is maintained as a whole.

Can you say the same for Linux? You literally cannot. Only Arch and RedHat (if you can get passed the paywall) have anything that comes close to the FreeBSD Handbook.

FreeBSD has a lot going for it. It just sits there and works forever. Linux can do the same, if you maintain it. You barely need to maintain a FreeBSD system outside of updating packages.

Most people who use containers a lot won’t find a home in FreeBSD, and that’s fine. I hope containers never come to the BSD family. Most public images are gross and massive security concerns.

But then, most people who use FreeBSD know you don’t need containers to run multiple software stacks on the same OS, regardless of needing multiple runtimes or library versions. This is a lost art because today you just go “docker compose up” and walk away because everything is taken care of for you… right? Guys? Everything is secure now, right?

movedx··on Free software hasn't won
Well said.

“When you create a machine to do the work of a man, you take something away from the man.” — Star Trek: Insurrection.

A month ago I watched animatronic dogs herd sheep around a paddock just minutes after some Border Collie did the same thing. What came to mind straight away was: that’s not a problem that needs solving. Yet here we are, injecting technology into every nook and cranny we can and ultimately all it’ll do is free us from our own freedom as people and enslave us to the rich, who will own all the tech and knowledge to support those animatronic dogs.

movedx··on Microsoft Azure: "Multiple international subsea cables were cut in the Red Sea"
BGP <3
movedx··on When the sun will literally set on what's left of the British Empire
Very cool article. Really well researched.

That being said, I don't think the sun can ever set on the British Empire, because the empire shifted to a financial once as opposed to one based on the idea of controlling physical land. You'd have to take out its entire financial/banking network spread out across the world for the sun to "set" on it.

movedx··on Malleable Software
> Employees, current and prospect, know how to work with the tool.

Just an FYI, this isn't the case at all. I've contracted and consulted at well over 20+ business at this point, and no one knows how-to use that hot garbage.

movedx··on I used to know how to write in Japanese
Thanks for sharing this part of your life. That’s so cool.
movedx··on How we built Bluey’s world
> As a Queenslander now living in the UK

As a Brit now living in Queensland, thanks for swapping places with me. Appreciated. Cheers mate. Enjoy the rain and moaning.

← PreviousPage 2 of 34Next →