HNHacker News
TopNewBestAskShowJobs

nsheridan

50 karma · joined September 22, 2011

submissionscomments
nsheridan··on Tell HN: Server error (5xx) in Google Search Console may not be 5xx at all
Expires header in the past is typically used to prevent caching.

The lower-case headers is part of the http2 specification.

nsheridan··on Passkeys will be importable, exportable, cross-device, and across managers
An SSH private key isn't "something you have" - it's not a physical object, you can make copies of it.

To me it falls into "something you know". You might not be able to type it from memory into a file but in practical terms it's no different to a password, it just usually happens to reside on disk.

nsheridan··on How To Get Started In Soldering
Lead solder is totally attainable for hobbyists - I bought a 100g spool a few weeks ago.
nsheridan··on Poll HN: Do you use SSH certificates (not mere public-key authentication)?
I use them for personal machines, and have deployed them in the past in work environments. A few years ago I wrote a CA which can exchange oauth tokens for signed keys: https://github.com/nsheridan/cashier

Auth is handled in a browser e.g. by Google, and the CA will sign a key and return a cert with a valid token.

nsheridan··on Ask HN: Any certification that is worth it? Legitimately helped your career?
> I always thought it was funny that I did the same job before and after the certs.

It’s often more advantageous for the company to have people with certs (it was with MCSE and such in the 90s anyway) - more MCSE etc on staff meant it was possible for the company to attain higher partnership levels with Microsoft which often meant more lucrative contracts and so on.

So while you may have been doing the same job as before, just by having the getting the certs you added more value to the business.

nsheridan··on Cloudflare had a partial outage
SLA - correct. That’s the contract between the operator and the users which describes the penalties for not meeting agreed-upon SLO

SLO - service level objective, the stated availability (or latency or durability etc) of the service. Usually expressed as a value over a period of time (e.g 99.9% availability as measured over a moving 30 average). The SLO is measured by the SLI.

SLI - service level indicator. Simply, the direct measurement of the service (i.e metrics)

SRE - Site Reliability Engineer, usually a member of a team who is responsible for the continued availability of the service and the poor sap who gets paged when it breaches SLO or has an outage or other impactful event.

nsheridan··on Microsoft and Meta join Google in using AI to help run their data centers
Not to mention fire suppression systems and electrical risks.
nsheridan··on Adding a security key to Gmail
There's noting stopping you from scanning the barcode multiple times
nsheridan··on Ask HN: What are some good technology blogs to follow?
I'm very happy with inoreader
nsheridan··on OpenSSH Keys: A Walkthrough
This exists - http://man7.org/linux/man-pages/man1/ssh-keygen.1.html#CERTI... - though the tooling is a bit bare-bones. There are some tools written to use certificates though, such as Netflix's BLESS (https://github.com/Netflix/bless), Gravitational Teleport (https://github.com/gravitational/teleport) and my own (https://github.com/nsheridan/cashier)
nsheridan··on AT&T Is in Advanced Talks to Acquire Time Warner
Ireland: 360/36 €60pm. No tv.
nsheridan··on New storage classes for Google Cloud Storage
I really wish AWS would introduce domain verification for 'domain-shaped' bucket names.
nsheridan··on Scalable and secure access with SSH
For (possibly) smaller scale I wrote a self-service SSH CA: https://github.com/nsheridan/cashier
nsheridan··on Sharkey: a service for managing certificates for use by OpenSSH
This is interesting. I wrote a service for issuing user ssh certs but it doesn't manage host certs.

https://github.com/nsheridan/cashier

nsheridan··on The little ssh that (sometimes) couldn't
It's pretty much unmaintained.

Every host it's installed on has to be properly tuned. Fine for large setups where finely tuned TCP stacks are the norm and maintaining your own ssh isn't much overhead, probably not fine for most setups where the 2MB buffer does the job. "To compute the BDP, we need to know the speed of the slowest link in the path and the Round Trip Time (RTT)". Do you know the slowest link in the path for everything you want to conceivably connect to?

The patches were an exercise in trying to max out high bandwidth connections using scp under ideal lab conditions, nothing more.

nsheridan··on Ask HN: How to deal with losing interest in your passion?
I lost interested in everything for.. a while, right around when I was diagnosed with depression. After eventually getting on the right brain medicine, I found my desire to work on the things I enjoy came back with a vengeance. Now I just need to make sure it doesn't happen again :)
nsheridan··on iOS 6 and OS X 10.8.2 Now Available
Witchcraft!
nsheridan··on Yeoman: Modern workflows for modern webapps
Worse, this script goes on to install homebrew using 'curl -k ...|ruby'. Yeah, no thanks.
nsheridan··on Yeoman at your service - A getting started guide
I can't be the only person who hates install instructions like 'curl -L some.host|bash'. Not to mention that the yeoman install script happily installs homebrew using 'curl -k ... |ruby'. No thanks.
nsheridan··on Pasting Text Into Vim
My .vimrc contains: set pastetoggle=<F2>

Life is suddenly easier :)

nsheridan··on No Ice Cream Sandwich For Galaxy S And Galaxy Tab, Says Samsung
3.0 was for tablets, not for phones.
nsheridan··on HOWTO: How to make multiple SSH connections to the same host faster
I'd recommend against putting the socket in /tmp. Anyone can reuse the connection.
nsheridan··on Why to avoid Google's IPO (2004)
http://www.google-watch-watch.org/