HNHacker News
TopNewBestAskShowJobs

nf-x

5 karma · joined September 18, 2022

submissionscomments
nf-x··on JetKVM Mini
Using one for couple of months so far. I need it once a month for a couple of hours or so, but it saves me 3x more time, so money well spent. But wow, at 3x less price tag it a deal!
nf-x··on D2 Is Non-Profit
Oh, does that already integrate with GitHub? Need to check how it deals with layouts and arrows in comparison to Mermaid
nf-x··on Show HN: Sol, my macOS music player and jukebox app, is now free and open source
By the way, what can you tell about Roon as an active user? It costs as much as Qobuz, but it’s your responsibility to fill up your library and provide infrastructure - which is weird. Sure, it sponsors musicbrainz and lastfm for metadata and puts some nice UI, gets buddies in HiFi manufacturers, but what else?..

I’m very surprised that Roon does UNPnP for own port, potentially exposing home network through some zerodays. For that money it has to do reverse tunneling or something like that.

nf-x··on Show HN: Sol, my macOS music player and jukebox app, is now free and open source
Local library playback has always been a challenge when the size is in tens of thousands. But after that the main challenge is headless networked playback from separate subnets - e.g. one great stereo system controlled by multiple members of the household from multiple devices
nf-x··on Show HN: Laptop is the last place your secrets are still in plaintext
to begin with, why not setting validity for 1hr? you don't need to onboard an untrusted tool then.
nf-x··on Show HN: Laptop is the last place your secrets are still in plaintext
i wonder when Claude/Codex would start baking it as first-party features
nf-x··on Show HN: Laptop is the last place your secrets are still in plaintext
there are so many great tools in the baseline core infrastructure. and there's so much NIH syndrome still.

appreciation and OS aside, systemd-creds relays long-lived creds into long-lived processes, and author's AI slop attempts at short-lived/on-demand injections. Apparently, author's AI slop gets a lot of iterations, but has not much of external scrutiny yet.

nf-x··on Show HN: Laptop is the last place your secrets are still in plaintext
keepass is great, because it doesn't require any service to operate - it's just a file. technically, you are responsible for backing it up, but more centralized options possible. I used it for 4 years pre-touchID era in a corporate setting and it worked great. For a single device. UX was very "open source", but hey - it's a free software with other focus in mind.

i know other people partitioning their secrets into multiple keepassx vault files, so the argument about using the same password manager can be interpreted differently.

nf-x··on Show HN: Laptop is the last place your secrets are still in plaintext
But the IPC is process-wide, not vault-dependent. And requires touch approval on every access, without “trust this process for X minutes” possibility.

Other 1pass is a great UX. It was even greater before Electron refactor and non-subscription model.

nf-x··on Show HN: Laptop is the last place your secrets are still in plaintext
How funny it may sound, but I was recently researching around for these kinds of tools for the same exact purposes.

Where I got stuck was at the Secure Enclave storing biometric-crypted payloads in the keychain, but couldn’t get it to work without Apple Developer subscription for code signing, otherwise these features wouldn’t work. And nobody with an Apple Developer subscription wants to sign someone else’s code, obviously. I really wonder why Apple itself, or any other reputable company, didn’t publish an utility like this already - it’s also a trust issue, when you run code like this.

The issue is that /usr/sbin/security invocations can be obscured to read from keychain, but require password typing every time, which is annoying. And lazy people can just hit “trust” by mistake. And then it’s just another clear text, but more annoying to reach.

Even though, it may be possible to show a touchID prompt in two other scenarios: - encrypting payload with a key stored in the enclave - then it becomes closer to SOPS approach. Age plugin for sops also supports using private keys on yubikey, by the way. But SOPS UX feels clunky. - just calling the APIs to show touchID as part of the application logic, like all modern password managers do. But then you really have to trust the password manager or the tool that does it, because touchID doesn’t equal security in this case.

Some password managers support CLI, SDK, and Terraform providers for working with their secrets, but that requires an IPC enabled, potentially increasing the risk for the other secrets stored in the same password manager.

Oh well, tough choices everywhere.

nf-x··on France to ban unsolicited telemarketing calls
some of the third-party apps can show if a number is potentially a spam or a business. it's handy when your phone number is listed in the business directory to avoid those annoying calls.
nf-x··on Show HN: Sqlsure – deterministic semantic checks for AI-generated SQL
How much of it is written by AI?
nf-x··on Show HN: Davit, a Apple Containers UI
Looks neat, need to give it a spin
nf-x··on Show HN: Halo – open-source, tamper-evident runtime evidence for AI agents
Looks very slop, but it’s a good idea. The main difficulty is that no big name is hosting a witness.
nf-x··on Official Python SDK for Databricks
Interesting. Does it run from notebooks? It has been the biggest challenge so far.
nf-x··on [dead]
In fact, many data teams are guilty of overlooking critical questions like “Are we actually monitoring the data?” after deploying multiple pipelines to production. They might celebrate the success of the first pipeline and feel confident about deploying more. Still, they need to consider the health and robustness of their ETL pipeline for long-term production use. This lack of foresight can lead to significant problems down the line and undermine trust in the data sets produced by the pipeline.
nf-x··on Fingerprinting Linux process trees with Rust
Could you share some data from your experiment?
nf-x··on Exposing Azure Storage on Domain Apex with Let's Encrypt SSL
How to expose an Azure Storage Account through a top-level domain with the Let’s Encrypt SSL certificate you can get for free, almost all via Terraform.
nf-x··on Ask HN: Value Assessment for Internal Projects
I think you should have couple of chats with different department leaders about what they think and capture systematized feedback somewhere. This will show value prop exactly for your org, exactly for the values your company operates with.
nf-x··on [dead]
Typical problems Dependabot solves range from updating direct upstream dependencies when they get a patch release to propagating the security vulnerabilities your upstream projects have already fixed. If you have minimal time and don’t have a whole team of people to manage dependencies, Dependabot is a solution for you.
nf-x··on [dead]
Driving unit test coverage is essential but very dull. We need to make it as fun as possible. And for the “shippable” OSS products, it’s vital. In the SaaS world, you roll out an emergency release for all users. Once a user downloads something and runs it in their environment — it’s done. You cannot effortlessly swap the binary artifact. And if it’s broken — it’s your fault. The best way to prevent this is decent unit-testing coverage. This time we’ll cover something boring and automatable — API calls to a predefined service. The most time-consuming activity is writing fixtures. They represent the state of the world for the system under test. Different systems need different complexity of fixtures, especially for multi-threaded applications.
nf-x··on Ask HN: Best way to keep the raw HTML of scraped pages?
Did you try using some of the cheap cloud storage, like AWS S3?
nf-x··on [dead]
Do you ever wonder if you should include a third-party library in your code or not? Sometimes it’s worth it, but mostly it’s not. Here’s a quick way to tell: …
nf-x··on Open Source Dependencies: Is It the Holy Grail or a Can of Worms?
Do you ever wonder if you should include a third-party library in your code or not? Sometimes it’s worth it, but mostly it’s not. Here’s a quick way to tell: If the library is doing something you don’t comprehend, or if it’s doing something you could do yourself with little effort, then don’t use it. The only exception to this rule is if the library is doing something that would be very difficult or time-consuming to do yourself. In that case, it might be worth using the library even if you don’t fully understand it.
nf-x··on Structured HTML table data extraction from URLs in Go
htmltable enables structured data extraction from HTML tables and URLs and requires almost no external dependencies.
nf-x··on Golang Generics Empower Concise APIs
You’ve likely heard and read dozens of stories about generics in Go about ordinary slices and maps but haven’t yet thought about a fun way to apply this feature. Let’s implement the peer of pandas.read_html, which maps HTML tables into slices of structs! If it’s achievable even with Rust, why shouldn’t it be with Go?! This essay will show you a thrilling mix of reflection and generics to reach concise external APIs for your libraries.
nf-x··on Show HN: Airflow is cool but have you tried this for data pipelines?
This is cool, but looks like https://github.com/dagster-io/dagster

The issue with less popular data pipeline projects is that they’re less stable in production

nf-x··on Musings about “Inherited the worst code and tech team I have ever seen.”
There’s no such a thing as a bad code in the company that makes money
nf-x··on Do I need to read a book to learn to use Linux?
In the end, you’ll end up using approx 20 commands. Maybe reading a book is worth it. For me it was. I could recommend two:

https://www.amazon.com/Power-Tools-Third-Shelley-Powers/dp/0... (old but gold) https://www.amazon.com/UNIX-Linux-System-Administration-Hand...

nf-x··on Putin orders partial Russian mobilisation, warns West over nuclear blackmail
Bilgorod is actually Ukrainian territory. They are just fighting back what commies took a while ago.
Page 1 of 2Next →