HNHacker News
TopNewBestAskShowJobs

msmith

473 karma · joined January 14, 2010

submissionscomments
msmith··on The Twelve-Factor App
How did you see a connection to Intuit? I believe this originated from Adam Wiggins, cofounder of Heroku - acquired by Salesforce.
msmith··on DNS-Persist-01: A New Model for DNS-Based Challenge Validation
To mitigate the threat from an attacker who controls the network between the cert issuer and the DNS server, CAs will check the DNS records from multiple vantage points.

Let's Encrypt has been doing this for several years, and it's a requirement for all CAs as of 2024.

[1] https://cabforum.org/2024/08/05/ballot-sc067v3-require-domai...

msmith··on Seattle tumbles to No. 20 in global ranking of startup ecosystems
1 is the lowest score. 10 is highest
msmith··on Recreating the Flying Toasters screen saver for the Vision Pro
- “G4” the TV network, not to be confused with the series of Mac computers
msmith··on Cutting down AWS cost by $150k per year simply by shutting things off
https://www.infracost.io/ might do what you're imagining
msmith··on Turbo Pascal Turns 40
I had a similar experience in the same era. In addition to the deviant stuff I also used it to tinker with graphics programming using inline assembly for the “performance critical” (for a 386SX) parts. That experience definitely laid the foundation for what I do today.
msmith··on After Boeing declines to pay up, ransomware group leaks 45 GB of data
This sounds like how we use a CVSS score to gauge the severity of software vulnerabilities.

Maybe the world needs a standardized place to catalog and rank all the data breaches that have been disclosed.

msmith··on Cloudflare API Down
I feel the same way. What about Akamai, Fastly, or Okta? Maybe Cloudflare gets more attention because their low end plans are accessible to anyone.
msmith··on FCC launches inquiry to increase minimum broadband speed [pdf]
It boggles my mind that Google Fiber has been available in Austin, TX for 10 years but is still not available in the communities next door to Google HQ.
msmith··on Tesla earns $690M less than expected in third quarter
I'm going to guess dboreham is Canadian?
msmith··on Better HTTP server routing in Go 1.22
I think you're assuming that the panic happens when a request is received, but it actually happens when a conflicting route is registered.

To me, that's reasonable behavior and is consistent with other things such as https://pkg.go.dev/regexp#MustCompile

msmith··on Ask HN: Show me your half baked project
Definitely. I have a couple use cases for it at <dayjob>.

Thanks for sharing that link. https://www.url2png.com/ is another I know about.

msmith··on Ask HN: Show me your half baked project
https://www.pagesnap.app/

Webpage screenshots as a service. I was scratching a personal itch with this one but maybe some day I will make it something others can use at scale.

Backend powered by Google Cloud Run, Pupeteer, and headless Chrome. Website is Next.js.

msmith··on HTTP/2 rapid reset attack impacting Nginx products
Also Go's HTTP/2 packages - https://news.ycombinator.com/item?id=37863419
msmith··on Infrastructure Manager: Provision Google Cloud Resources with Terraform
Can your example be solved by having the k8s cluster resource reference the network resource’s “name” attribute?

Doing that allows Terraform to create both resources in one plan/apply step, and it also helps Terraform understand the dependency between the resources so that they are created in the correct order.

msmith··on Show HN: I spent 2 years building a personal finance simulator
I use New Retirement and one of my biggest complaints about that app is that it expects you to provide the optimistic/pessimistic rate of return for each of your investment accounts. I would love to have a tool that provides some guidance on setting those numbers, based on historical returns and the asset classes in the account.

I can see value in having similar guidance for things like mortgage interest rates. Maintaining all of this educational content and keeping it up to date may be a challenge, though.

msmith··on Show HN: I spent 2 years building a personal finance simulator
I love to see more tools like this for do-it-yourselfers like me. I've only just now tried using ProjectionLab for about 20 minutes, so take this with a grain of salt, but I've watched Rob Berger's review of the tool and I've been a subscriber to New Retirement for a few months now.

First impressions:

- It's obvious you've put a lot of love into this tool and it really shows. The UI is very responsive and I think I would enjoy using it.

- At first glance, it compares favorably to the core features in New Retirement: Tracking your assets and investments; Showing projections based on different scenarios and assumptions.

- I didn't see any places where it's providing financial planning suggestions. New Retirement offers "Digital Coach Suggestions" which recommends various things to look into, based on the information you enter. For me, that's a valuable feature because one of the reasons why I'd pay for a tool like this is so that it can help me poke holes in my financial plan.

- Your pricing is totally fine. I see your competition as financial planners who charge a few thousand dollars for a one-time financial plan or, worse, an ongoing 1% AUM fee. I've paid a human to do a financial plan. It was worth the money because it gave me the reassurance that I kinda know what I'm doing, but I didn't see the value in paying a recurring fee for them to "monitor" my investments going forward. I'd much rather pay for direct access to a tool that lets me do that myself.

- Despite the previous bullet point, I do see some value in having a human who can give good financial planning advice. I would pay a few hundred dollars to meet with a human who can give me useful advice whenever I'm at an inflection point in my financial life. Maybe that's another potential revenue source for you in the long run.

msmith··on No-more-secrets: recreate the decryption effect seen in the 1992 movie Sneakers
This is great. It reminds me that I tried to recreate this effect with Turbo Pascal back in the 90’s when I first got into programming.

Sneakers, Wargames, and BBS culture were pretty influential for me at the time.

msmith··on Apple Announces New MacBook Air with 15.3-Inch Display and M2 Chip
Oh, right. I meant to say 14” MBP in my parent post.
msmith··on Apple Announces New MacBook Air with 15.3-Inch Display and M2 Chip
Does it support more than one external display? The lack of that feature was the primary thing that drove me to choose a 13" MacBook Pro instead.
msmith··on Musk’s first email to Twitter staff ends remote work
I wonder if you've read Turn the Ship Around [1]? It's one of my favorite leadership books and tells the true story of the Navy captain who was put in the awkward position of running a submarine class that he was not familiar with.

He adapted to the situation by leaning on the expertise of the crew in a way that was very different than the normal command-and-control style of leadership. It sounds like what you describe in type 1.

[1] https://davidmarquet.com/turn-the-ship-around-book/

msmith··on Apple’s next big thing: A business model change
This study claims that there was a decrease in weather prediction accuracy caused by the reduction in commercial flights due to Covid. Maybe there are still some lingering effects from that?

https://www.sciencedaily.com/releases/2020/07/200717101026.h...

msmith··on Ask HN: Hacker News is for tech, as X is for Y?
as Bogleheads is for investors
msmith··on Submarine cable map rendered onto a globe
It's interesting that there are so many cables running through the Suez Canal. I wonder if it's because of geopolitical reasons for avoiding going over land through the Middle East.
msmith··on Vercel Serverless Functions vs. Cloudflare Workers
We’re using it to customize Cloudflare’s default caching policies so that we can cache more content at the edge. For example, we can segment the cache based on the geolocation or device type of the client. We can also normalize the URLs before doing the cache lookup, by stripping query params which we know aren’t going to affect the content in the response.

This can save hundreds of ms from the response time of the initial HTTP request, which means all of the other page resources will load more quickly too.

It does add some additional complexity, but for large sites and hosting platforms, this can have very significant cost savings. It’s usually way cheaper to serve bytes from Cloudflare’s cache than to serve them from your origin.

msmith··on Simulating the PIN cracking scene in Terminator 2
Turbo Pascal 7 was my intro to programming and it was such a great learning environment
msmith··on China is now blocking all encrypted HTTPS traffic using TLS 1.3 and ESNI
That link was fascinating to me. For as long as I remember, there have been tools to evade network intrusion detection systems and stateful firewalls, but I never thought about how the same techniques can be used to evade censorship.
msmith··on How many of you know that the team is working on something that no-one wants?
You might enjoy reading all the things that Marty Cagan has written about product management. I think he has a good take on what it means to be a good PM, and what you're describing sounds like what he calls a Feature Team [1]. Unfortunately, it's really common to be in an organization like this where the roadmap is driven by outside stakeholders, and product managers are treated like project managers who just implement their ideas.

[1]: https://svpg.com/product-vs-feature-teams/

msmith··on FBI kicks some of the worst ‘DDoS for hire’ sites off the internet
I was a lead on Blitz. You’re right that there are ways to get around this domain ownership check, but in practice it was enough of a hurdle to avoid bad actors. Also, I’m pretty sure that these stressors were way more cost effective if your only goal is to DDoS a site.
msmith··on Mmm, Pi-hole
Since Pi-Hole is a DNS server running on a separate machine, it just doesn’t have the same level of access as browser extension would. Even if it was rogue, the worst it could do is share the list of domains that you visit, and possibly hijack your HTTP (but not HTTPS) sessions.
Page 1 of 4Next →