HNHacker News
TopNewBestAskShowJobs

nullify88

904 karma · joined July 25, 2017

submissionscomments
nullify88··on YouTube May Force You to Watch 10 (Or More) Unskippable Ads in a Row
Perhaps consider Invidious, Piped, or alternative UI. Pair with Privacy Redirect / libredirect to redirect any hits to youtube to your trusted instance.
nullify88··on Document Foundation starts charging €8.99 for 'free' LibreOffice
Regarding convenient access, I'd argue that since there are many providers of TV media with their own libraries, the space is, if not already, becoming fragmented and inconvenient. I often open the wrong app, trying to find the media I want to watch.

"Oh its only available in another region".

"Oh it got pulled from Netflix".

Providers introducing Ads will make it worse.

nullify88··on DVD Bouncing Logo
FWIW, Netflix released a special episode in 2019 reuniting a lot of the key people back with the show. It brought back some great memories and hasn't lost its touch. https://en.m.wikipedia.org/wiki/Invader_Zim:_Enter_the_Florp...
nullify88··on Windows10Debloater: Script to remove Windows 10 bloatware (2021)
Perhaps load up sysinternals Autoruns and see if a particular plugin / DLL is being loaded which is causing the slow downs.
nullify88··on Falling for Kubernetes
The larger the log buffer is, the slower k9s gets unfortunately. For me the builtin log viewer is useful for going back short time periods or pods with low log traffic.

You can work around it by using a plugin to invoke Stern or another tool when dealing with pods with high log traffic.

nullify88··on Technical reasons to choose FreeBSD over GNU/Linux (2020)
Perhaps VHS vs Betamax is a suitable equivalent to FreeBSD vs Linux.
nullify88··on Arris / Arris-variant DSL/Fiber router critical vulnerability exposure
> Not sure if you'll see this but I'll give it a shot

Thank you :)

The Wikipedia page on Ubiquiti also paints a bleak picture of the company; GPL violations, vulnerabilities, etc. I admit I brought 2 U6 Meshes on account of them passing the wife acceptance test, and so far they've been good (Some minor "Multicast Enhancement" issues aside). I haven't been interested in their router / gateway offerings since I think there's better out there with a better bang for buck. But its promising hearing about TP-Links efforts and I'll certainly give them another look if I need more Wi-Fi gear.

nullify88··on Arris / Arris-variant DSL/Fiber router critical vulnerability exposure
Since you've operated both, whats your opinion on the Ubiquiti vs the TP-Link Omada and why did you switch?

I've done something similar with a Mikrotik CRS-309 as a router and some Ubiquiti U6 Meshes. The fiber ISP here leaves it to the owner to buy their own hardware to connect to a Icotera in bridge mode. I believe it allows the ISP to reduce their operating costs since theres no need to support a complex all in one router / switch / AP. Anything beyond the bridge is the users responsibility.

nullify88··on Recommended settings for Wi-Fi routers and access points
WiFiMan reports -85db and 80m when 3 floors down on the opposite side of the house from 1 Ubiquiti U6 Mesh. We have a second U6 Mesh to cover this area and users roam between the two when on the second floor where we are most of the time.

The house is detached, very open plan, and doesn't have many solid walls. We also have traditional wall radiators, I imagine the lack of underfloor heating and foil insulations allows wifi to travel further between floors.

nullify88··on Recommended settings for Wi-Fi routers and access points
These days I just disable 2.4ghz completely since all our devices support 5ghz and we have enough (2) access points around the house to give a good signal anywhere.
nullify88··on Twenty years of Valgrind
I have a similar experience with xdebug for a PHP shop I used to work at. It feels very similar to being a nerd back at school, rescuing peoples home work, and being rewarded with some respect.
nullify88··on A Crack in the Linux Firewall
I can't think of anything in the wild. You could get far with setting up some webhooks and sending events to IFTTT.

Having it self hosted, in the end its a matter of logging some information about users requesting access in to a database, having a UI to display data from said database and having some small automation to add the IP to a whitelist / blacklist.

nullify88··on Lockheed Martin Prepar 3D
I'm not sure how sucessful the games were as a recruiting tool, but Americas Army 2.x was a well received game. Pipeline and Bridge brings back some good memories. I believe theres still an active community for it.

Its popularity tanked once Americas Army 3 was out.

nullify88··on Tunneling Wikipedia through WhatsApp to (maybe?) get around WiFi restrictions
What do you do when wifi has a captive portal though requiring a user name and password?

I use my Samsung S10 for exactly this as it has multiple radios that allows connecting to wifi and hotspotting to share that connection with other devices. Great for Chromecasting.

nullify88··on How to Remove the Frustration of Reading in Games
I've just started Control and I'm really enjoying the game. Naturally I too am listening, watching and reading all collectables. Its a beautiful game and its art direction very unique.

Doom Eternal was another game I was interested in reading the lore and text. It offers a nice pause from the action.

nullify88··on The Invention of Battlezone (1982)
The first real game I fell in love with was the Activision & Pandemic remakes of Battlezone in to a FPS / RTS hybrid.

I recall the introvideo had a little nod to the original battlezone.

nullify88··on Thank You, Valve
There is a community contributed Steam Flatpak that isolates its dependencies away from the system. https://flathub.org/apps/details/com.valvesoftware.Steam

Seemed to do the job fine, ymmv.

nullify88··on Google to turn on activity tracking for many users who turned it off
https://www.migadu.com/
nullify88··on I discovered thousands of open databases on AWS
Re Elasticsearch. It used to be much worse.

Even basic authentication was only available to those with an xpack subscription, it didnt have any security unless you paid money or used Nginx or another server to apply the auth and proxy the connection.

That didn't stop people from making instances available publicly, and it was only until Elasticsearch started hitting the news about all the open instances did they make it available in the free tier from May 2019 (6.8.0 / 7.1.0)

nullify88··on MicroShift
FWIW, although I've known for a while that OpenShift coverts ingress resources to routes, I just found out that the Ingress Controller sets up a watch on the secretref which keeps the inline TLS in the Route in sync. That could be enough for some people.
nullify88··on MicroShift
You can create Ingress resources on OpenShift and it will automatically create routes for you. You can customise the generated Route by using annotations on the Ingress resource.

This has worked well for us because not all helm charts are OpenShift friendly but they usually do allow customising the ingress resource with annotations or we patch it in via Kustomize.

https://docs.openshift.com/container-platform/4.8/networking...

nullify88··on MicroShift
A big inconvenience is that for HTTP2 Routes or edge / re-encrypt Routes with a custom TLS certificate, the TLS certificate and keys must be inline in the Route resource instead of referencing a secret like Ingress resources do. I think this is a big oversight where Routes mix secrets and Ingress configuration together.

It makes GitOps annoying because I don't want to treat the whole Route resource as a secret that needs to be encrypted or stored in vault.

Do I also then treat Route resources as sensitive and deny some users access on the account they could contain private keys?

I also have to worry about keeping the route updated before certificates expire instead of having it taken care of by cert-manager.

So we use Traefik's IngressRoute.

nullify88··on MicroShift
Openshift-dns is just their custom operator which deploys and configures CoreDNS. OpenShift is k8s with alot of RH operators bundled in to configure stuff like monitoring, logging, networking, ingress, etc.
nullify88··on MicroShift
I'm running both OpenShift and k3s in production, and there isnt that much that requires different treatment between the two. There are some specific OpenShift APIs (like routes which are terrible) and some quality of life improvements (service-ca signer) but nothing drastic.
nullify88··on Approved Cameras
Did Arcane fall under those requirements? Its been a long time since I saw something animated and styled so beautifully.

Before that, I was usually impressed by Ufotables quality (Garden of sinners, Fate Stay / Night stuff).

nullify88··on Approved Cameras
Might be related but I'm finding recent TV shows and film to have a really narrow field of focus while the rest of the screen is either blurry like your example or a depth of field effect.

My eyes generally wander to look at the surrounding scene or detail but I get the feeling I'm not supposed to be looking there.

nullify88··on Intel completely disables AVX-512 on Alder Lake after all
I wouldnt call it hacking. If you can find or backup the bios image for your motherboard, you can replace the microcode in it and reflash. Bios images are modular and the microcode is a replacable component.
nullify88··on Upgrading Executable on the Fly
Correct but to clarify, only the master process binds to the ports. The master process creates socketpairs to the workers for interprocess communication. The workers accept connections over the shared socket.

https://www.nginx.com/blog/socket-sharding-nginx-release-1-9...

Page also has an example of how SO_REUSEPORT effects flow.

nullify88··on Upgrading Executable on the Fly
You would need more than one to do a rolling restart. Alternatively to do it with one instance of a software load balancer is a bit more work, spin another instance up and update DNS. Wait for traffic to the old one to die as TTLs expire, then decommission.

But I agree it isn't as easy as a in place upgrade.

nullify88··on Upgrading Executable on the Fly
Once the USR2 signal is received the master process forks, the child process inherits the parents file descriptors including listen(). One process stops accepting connections creating a queue in the kernel. The new process takes over and starts accepting connections.

You can follow the trail by searching for ngx_exec_new_binary in the nginx repo.

← PreviousPage 8 of 14Next →