HNHacker News
TopNewBestAskShowJobs

nominated1

458 karma · joined October 10, 2014

submissionscomments
nominated1··on Upgrade Raspberry Pi 4 with a NVMe boot drive
These sorts of posts come up often and I cringe every time I see dongle attached storage. An unnecessary additional failure point seems counterproductive.

I have a Raspberry Pi and I use an SD card because what I’m using it for doesn’t require anything more. If you need fast storage I believe you should buy an appropriate device and maybe petition the Foundation to add it in a future model.

Right tool for the job and all that.

nominated1··on How to turn off Android TV's homescreen ads, 'staff picks'
The Android Debugger is best for wrangling these unfortunate creations. Here are some random notes I took while beating my Sony Bravia into submission.

# Enable Develepor Tools TV > Home menu > Settings > About.

Click the build number 7 times to activate the developer tools menu item.

Open it and click on "enable ADB debugging."

# Default ADP Port TCP - 5037 and 5555

adb connect 192.168.x.xx

A popup will appear on your TV. Use your remote to check the box to always allow connections from your PC

# Sideload app

TV > Settings > Security & restrictions > Unknown Sources

adb install apkname.apk

# List all apps

adb shell pm list packages -f > bravia-tv-packages.txt

# Uninstall an app.

adb shell pm uninstall -k --user 0 tv.samba.ssm

adb uninstall tv.samba.ssm

# Reinstall (example only)

adb shell pm install -r --user 0 tv.samba.ssm

# Disable an app if uninstall fails

adb shell pm disable-user --user 0 <package_to_disable>

# Re-enable a disabled app

adb shell pm enable <package_to_enable>

# Safe Mode

Unplug or Reboot (Settings > About)

Press and hold volume down

# Factory Reset

Unplug

On lower left (ports side)

Press and hold bottom two

Plug back in

# Filter to only show system packages.

adb shell pm list packages -f -s

# List including uninstalled packages.

adb shell pm list packages -f -u

# List all disabled apps

adb shell pm list packages -d

# Force stop app

adb shell am force-stop com.netflix.ninja

adb shell top

adb shell ps > android-processes.txt

adb shell dumpsys wifi > dumpsys_wifi.txt

adb shell logcat > logcat.txt

adb shell dumpsys package com.foo.bar > dumpsys_com.foo.bar

adb shell pm [grant|revoke] [package] android.permission.CAMERA

When done, turn off ADB debugging on the TV for security.

nominated1··on Why there’s so little left of the early internet (2019)
But you managed to add google-analytics to the site which launched in 2005. ;-P
nominated1··on Windows 10: HOSTS file blocking telemetry is now flagged as a risk
Not that I don’t believe this is happening, but I’d love to see the Wireshark logs proving this.
nominated1··on Breached Data Indexer ‘Data Viper’ Hacked
> Smoke and mirrors, indeed. It’s entirely possible this incident is an elaborate and cynical PR stunt by Troia to somehow spring a trap on the bad guys.

That’s the juicy bit of the story. Has this all been staged?

nominated1··on Apple Silicon: The Passing of Wintel
Brings back memories of those “Born American Buy American” bumper stickers. I was only a kid but I remember them everywhere.
nominated1··on When Security Takes a Backseat to Productivity
I’m led to believe that the CIA is run like Equifax but I can't shake the feeling that this is all a smokescreen.
nominated1··on Flatpak – A Security Nightmare (2018)
> Unless this has been updated since 2018

I think this might also apply to Flatpak.

Has Flatpak addressed any of these concerns? If so, how?

nominated1··on Lenovo to Certify ThinkPad and ThinkStation Workstation Portfolio for Linux
Yes, many vendors for many models do the same. Even if they don’t you could install it via Windows.

“Support” is more than just the ability to install an update. It’s to do with whether an issue affecting Linux is being addressed. In the case of the E and L series Thinkpads there are many shared components with the T series so your chances are much better.

nominated1··on Lenovo to Certify ThinkPad and ThinkStation Workstation Portfolio for Linux
When looking at Linux support I start with the Linux Vendor Firmware Service [1]. If the model I’m looking at isn’t supported then it’s off my list. You’ll notice that not all Thinkpads are supported [2].

The E, L and Yoga series are not supported but the T, P and X series are.

[1] https://fwupd.org/

[2] https://fwupd.org/lvfs/search?&value=thinkpad

nominated1··on Microsoft Defender SmartScreen is hurting independent developers
I ran into this issue when writing a small automation tool for a friends business.

The workaround for now:

Right click .exe → Properties → at bottom of the General tab check “Unblock”

Microsoft – same wolf, different clothing.

nominated1··on Easy to read Covid-19 Dashboard
I find it a bit unnecessarily politicized. I’m not sure President approval rating is relevant and rather than comparing total deaths to war and terrorism I’d like to see how it stacks up against Cancer and other health related deaths.

Otherwise, I love it. It’s easy to read and the layout is wonderful. I’ve bookmarked it! Thank you!

nominated1··on Port knocking
Interesting. The only issue I’ve had was ensuring knocks were received in order. DDNS being the worst culprit. Ensuring an adequate delay between knocks solved my problems. However, I use this for home (friends and family only) nothing serious.

If I were to use a daemon I’d go with an SPA, like fwknop. The lack of an iOS client is the only reason I still use port knocking.

nominated1··on Port knocking
I use port knocking and I don’t take it seriously. Anyone using it in a serious setup is batshit. However, for fun home projects where users install that giant php based file sharing program, or that IoT camera, why not? They don’t have automated intrusion prevention, etc. They can’t understand the code to determine it’s quality, etc.

When the next 0day hits… will it be enough to protect them, yes. After all, they’re not a target and the automated attacks won’t affect them.

nominated1··on Port knocking
I too am a fan of port knocking. I don’t use knockd, just iptables. I found the Arch Wiki most helpful. You’ll need to figure out which chain works for your setup but it’s pretty straightforward.

https://wiki.archlinux.org/index.php/Port_knocking#Port_knoc...

Here’s my example for a VPN running on OpenWrt. If you experience any race conditions with iptables you can pepper each rule with something like “-w 5”

This opens Wireguard port 666 for 15 seconds. I have a script that creates my ipset allowing connections from the USA only.

   # The correct port sequence is  1111 -> 2222 -> 3333 -> 4444; any other sequence will drop the traffic 
   iptables -N WG-INONE
   iptables -N WG-INTWO
   iptables -N WG-INTHREE
   #
   iptables -A input_wan_rule -m conntrack --ctstate NEW -m udp -p udp --dport 666 -m set --match-set usa src -m recent --mask 255.255.255.0 --rcheck --name WG3 --seconds 15 -j ACCEPT
   iptables -A input_wan_rule -m conntrack --ctstate NEW -m tcp -p tcp -m recent --mask 255.255.255.0 --name WG3 --remove -j DROP
   iptables -A input_wan_rule -m conntrack --ctstate NEW -m tcp -p tcp --dport 4444 -m recent --mask 255.255.255.0 --rcheck --name WG2 -j WG-INTHREE
   iptables -A input_wan_rule -m conntrack --ctstate NEW -m tcp -p tcp -m recent --mask 255.255.255.0 --name WG2 --remove -j DROP
   iptables -A input_wan_rule -m conntrack --ctstate NEW -m tcp -p tcp --dport 3333 -m recent --mask 255.255.255.0 --rcheck --name WG1 -j WG-INTWO
   iptables -A input_wan_rule -m conntrack --ctstate NEW -m tcp -p tcp -m recent --mask 255.255.255.0 --name WG1 --remove -j DROP
   iptables -A input_wan_rule -m conntrack --ctstate NEW -m tcp -p tcp --dport 2222 -m recent --mask 255.255.255.0 --rcheck --name WG0 -j WG-INONE
   iptables -A input_wan_rule -m conntrack --ctstate NEW -m tcp -p tcp -m recent --mask 255.255.255.0 --name WG0 --remove -j DROP
   iptables -A input_wan_rule -m conntrack --ctstate NEW -m tcp -p tcp --dport 1111 -m recent --mask 255.255.255.0 --name WG0 --set -j DROP
   iptables -A WG-INONE -m recent --mask 255.255.255.0 --name WG1 --set -j DROP
   iptables -A WG-INTWO -m recent --mask 255.255.255.0 --name WG2 --set -j DROP
   iptables -A WG-INTHREE -m recent --mask 255.255.255.0 --name WG3 --set -j DROP
EDIT - For those wondering about the Netmask, it's for mobile connections.
nominated1··on New Lenovo ThinkPad Range with Ryzen 4000 and 4000 Pro Mobile
AMD GPU drivers are still suspect. I LOL’d at this commit [1] before reverting it in my local branch and thinking glad I went with Intel.

[1] https://github.com/mpv-player/mpv/commit/6385a5fd1b8a67c051b...

nominated1··on Oil's Collapse Is a Geopolitical Reset in Disguise
Please expand on Pat Tillman. He does not belong on that list. This is the same man that as soon as the war moved from Afghanistan to Iraq was quoted as saying “this war is so fucking illegal.”

Full disclouse: I knew him personally… mostly from a distance. It was disgusting seeing the likes of Senator John McCain try to capitalize on his death. That doesn’t mean he wasn’t the man depicted in Jon Krakauers’ book.

nominated1··on WD Sets the Record Straight: Lists All Drives That Use Slower SMR Tech
I am using uBO. Blocking 3rd party scripts is what triggers it.
nominated1··on WD Sets the Record Straight: Lists All Drives That Use Slower SMR Tech
For those unwilling to disable their Adblocker, here is the official WD blog post with PDF containing make and model numbers:

https://blog.westerndigital.com/wd-red-nas-drives/

nominated1··on Performance, Protection, and Sterilization of Face Mask Materials
What if I have X masks and rotate their usage without any cleaning at all. Would this allow the virus to die naturally without the need to clean the mask?
nominated1··on [dead]
Can we stop with these low quality fear mongering articles please? I’m by no means dismissing the virus but there’s no substance at all here, none.
nominated1··on Intel Abandoning 10nm, Planning to Use TSMC’s 6nm and 3nm for GPUs
> The transition to TSMC for GPU production is something that has been rumored before and just like before, we do not have independent validation of this information - so this post has been marked rumor and to be taken with a grain of salt.

So... why is this on the frontpage??

nominated1··on AMD is determined to gets its rightful datacenter share
My biggest concern when considering AMD on Linux is drivers. I see in my feeds Phoronix is constantly reporting on updates to recent kernels. However, most of these power management, etc equivalent features have been available for years from Intel.

How are people finding AMD hardware in the real world wrt Linux on say 4.19 or 5.4 kernels?

nominated1··on FreeNAS and TrueNAS Are Unifying
These NAS targeted distros are amazing. However, my needs are simple. I just don’t need 90% of the features they have.

Maybe I’m just a simpleton but I run an rsync script each night. The beauty is that if I accidentally delete something I can easily recover it and if a drive fails I lose less than one days worth of data. This trade-off is well worth it for me.

If I had several drives I’d use SnapRAID to cut down on costs.

Oh and I’m lazy so I installed CentOS on it. In several years when CentOS reaches EOL I’ll just buy new hardware and install the newest version.

Synology type devices make me nervous. Krebs[1] recently did a piece on IoT gear being the new target for ransomware. I also wouldn’t feel comfortable exposing anything running on these devices to WAN.

[1] https://krebsonsecurity.com/2020/02/zyxel-fixes-0day-in-netw...

nominated1··on ThinkPad Mods, Done Right
I’m typing this reply on a T490. It ain’t your parents Thinkpad. Don’t get me wrong, it’s nice but I’d be surprised if it lasts me longer than an XPS or equivalent would.

Opening it up to add more memory and larger SSD was nerve racking. I was worried I might snap the tabs on the “glass fiber” shell. Better than an Inspiron or Pavilion but not confidence inspiring. I don’t look forward to replacing the battery in a couple years.

nominated1··on Dickbars and Other Readability Excrement (2017)
I’ve found the following list to help with “dickbars” and other modern nonsense.

https://github.com/yourduskquibbles/webannoyances

nominated1··on Firefox 71
I’m hoping Mozilla will move to libplacebo [1] when it’s stable. It’s seems the most promising.

[1] https://code.videolan.org/videolan/libplacebo

nominated1··on Ex-FDA Advisor Says of Lasik Eye Surgery: ‘It Should Have Never Been Approved’
Most of this reads like quibbles to me. The thought of possibly having permanent eye damage, no matter how “insignificant”, in exchange for minor convenience/vanity and only myself to blame is a bit too much.

In my sisters case, she now has prescription night driving glasses and prefers not to drive at night with my niece. I’m not sure why but “was worth it” is what she’d say and similar reasons to yours are what she’d give.

nominated1··on Ex-FDA Advisor Says of Lasik Eye Surgery: ‘It Should Have Never Been Approved’
Dry eyes and halos, many I speak to say they have these issues. Followed by “I don’t regret it, best thing ever”. I walk away mostly confused.

Watching my sister, who had it done ~10 years ago, struggle to stay between the lines on the freeway at night due to halos I wrote it off completely. Even with these issues she’s perfectly happy with the results. Again, I don’t get it.

nominated1··on Ubiquiti adds phone-home to the access point firmware
I was aware of Ubiquity’s past GPL violations and it was the only reason I avoided them. According to Wikipedia they settled a GPL violation in 2017 but I wasn’t aware of the recent issue. Looks like their Wikipedia page could use an update.

https://en.wikipedia.org/wiki/Ubiquiti_Networks

← PreviousPage 2 of 4Next →