HNHacker News
TopNewBestAskShowJobs

omh

1,776 karma · joined September 13, 2010

Email: hn @ doublegeek.com
submissionscomments
omh··on IT administrators are "fed up" with Microsoft's "useless" apps and Windows 11
It's mind boggling how bad Microsoft have made this.

I just want to install a few apps and manage their settings. But the combination of Windows, Intune, modern Store apps, multiple similar settings, and licensing, make it a full time job full of footguns.

If they just had one team with responsibility for end user experience they could bring this tech together in amazing ways.

But instead there's probably at least one FTE is every IT department in the world just managing Microsoft's bullshit

omh··on USB Power Delivery: Plugging into the Benefits
There are some SFF PCs that can take USB-C power.

Lenovo have some,but sometimes require adapter cards. And a few of the Chinese N150 units will take PD power

It's great for hot swapping and more portable than a laptop.

omh··on IPv6 traffic crosses the 50% mark
I'll take that bait ;-)

IP filtering is a valuable factor for security. I know which IPs belong to my organisation and these can be a useful factor in allowing access.

I've written rules which say that access should only be allowed when the client has both password and MFA and comes from a known IP address. Why shouldn't I do that?

And there are systems which only support single-factor (password) authentication so I've configured IP filtering as a second factor. I'd love them to have more options but pragmatically this works.

omh··on UK House of Lords attempting to ban use of VPNs by anyone under 16
Thanks. That wasn't clear from the Mail article above.

But the Times article also says:

> A spokeswoman for Leicestershire police said crimes under Section 127 and Section 1 include “any form of communication” such as phone calls, letters, emails and hoax calls to emergency services.

So I think the categorisation is a mess, and probably not even consistent across forces

omh··on UK House of Lords attempting to ban use of VPNs by anyone under 16
This is based on statistics for the Malicious Communications Act. That includes people sending, for example, threatening messages to an ex partner.

Not all of them are online posts, in fact probably a minority

omh··on Want to piss off your IT department? Are the links not malicious looking enough?
And Microsoft own the client, so they are the one company who don't need to do this!

If you really want to check every time someone clicks on a link then you can do this in the client and keep the visible link the same for the end user.

But instead there are different teams working on this in Outlook, Teams, Exchange, Defender and god knows where else.

(I'm one of the people in corporate IT trying to turn this off and often struggling)

omh··on Coffeematic PC – A coffee maker computer that pumps hot coffee to the CPU
Many years ago we used a hot P4 to heat mulled wine.

https://imgur.com/a/mulled-wine-pc-WW1pW

It could get to 60°C which is a bit low for coffee but was great for mulled wine

omh··on Perceptually lossless (talking head) video compression at 22kbit/s
One use case might be if you have limited bandwidth, perhaps only a voice call, and want to join a video conference. I could imagine dialling in to a conference with a virtual face as an improvement over no video at all.
omh··on Canarytokens: Honeypot for critical credentials, get notified when they are used (2015)
Spying how?

If you embed a URL in emails then a lot of corporate email gateways will blindly follow the link, trying to check it for malware.

This may or may not be a useful security measure but it has many issues. One of which is that it could look like spying.

omh··on Second factor SMS: Worse than its reputation
Good point.

But what's the threat model here?

I didn't think of 2FA as being protection against password reuse. People should still avoid reusing passwords and change them if they know of a breach.

Are there really attackers who are picking up breach databases and then sim-swapping to get the 2FA as well?

omh··on Second factor SMS: Worse than its reputation
The article conflates two issues that have different security implications.

The "1-click login" links are a concern and just having access to the SMS would be enough to take over things like WhatsApp.

But 2FA codes seem notably less worrying. They are the second factor and require an attacker to have the password too. For these cases I'm much more relaxed about the use of SMS and the risks of interception.

omh··on Gavin Newsom wants to take smartphones out of schools
I agree that it would be fine to not have phones - we'd all cope.

But when my daughter hasn't got home on time if I can check her GPS and see that she's in the park then I can relax a little.

If she needs to say she's staying out late, using a group chat to let the whole family know is easier than trying to phone mum, then dad, then grandma.

Or she can include a photo showing how much fun she's having.

My life is richer because of communication on things like family group chats. It would be a shame to throw the baby out with the bathwater and lose that

omh··on Gavin Newsom wants to take smartphones out of schools
There is a potential clash here between control and privacy.

A few years ago Apple blocked[1] some parental control apps because "they put users’ privacy and security at risk"

This actually came up with our school. They tried to use an app to control student phones but it was fundamentally limited by these Apple restrictions.

[1] https://www.apple.com/uk/newsroom/2019/04/the-facts-about-pa...

omh··on Gavin Newsom wants to take smartphones out of schools
This debate seems to conflate two or three different issues.

1. Use of phones in classrooms 2. Having phones present in schools, but unused 3. The impact of social media on schoolchildren

(1) is undeniably bad and should be banned everywhere.

(2) raises some issues. I don't want (1) but I would like my child to have a phone for the journey to and from school. And a smartphone is much better at this than a dumb phone (group chats are really good!)

(3) is a concern but it seems almost totally unrelated to the other issues. The children who are banned from having a phone at school will use the same social media when they're at home and schools will still have to deal with bullying.

Our school current bans (1) and is consulting on more bans. But from parent discussions it feels like both the school and parents are mixing up these issues and just coming back with "phones are bad".

omh··on My insulin pump controller has a bug
Also it would be very possible to misread the confirmation.

If I've just entered "0.21" then when the confirmation screen reads "21" it's not immediately obvious that it's wrong.

omh··on My insulin pump controller has a bug
Yes.

A typical pump will contain enough for several days. My pump right now has 100 units and is only half full.

omh··on My insulin pump controller has a bug
I've got this Tandem pump and we discussed this exact bug when I received the pump.

To my understanding this isn't the same type of bug. Tandem are just saying "it can be confusing to enter fractional rates".

This bug is for a different pump and is "when you enter a fraction rate it will change the rate". That is much worse

omh··on My insulin pump controller has a bug
A clearer description of the bug is here:

https://twitter.com/Tims_Pants/status/1730515134731182490

It's wild that this sort of bug got through testing.

As a diabetic it feels like our insulin pump software is very conservative and lacking in features especially compared to what some of the "closed loop" things would like to do.

That seems reasonable if the manufacturers are having to do lots of safety testing.

But if bugs like this are getting through then the testing obviously isn't anywhere near as robust as we'd like.

omh··on London Street Trees
As a slightly more frivolous use of this website - we're approaching conker season!

Last year my kids wanted to go collecting conkers and I used a similar website (https://www.treetalk.co.uk/) to find a local place with lots of horse chestnuts.

It worked brilliantly and the kids thought I was some kind of genius for finding so many.

omh··on Ask HN: Indoor air quality sensors and other IoT that's local-first and not DIY?
I have the Awair Element and I'm reasonably happy with it.

The primary interface is through their app and I think you might need to use this to get it up and running initially. But they have a supported local API feature[1] that has so far worked as I'd expect. In the end I've been happy with their app so have primarily used that so far. The data seems good.

They're quite expensive new. But they were involved in some sort of cryptocurrency (!) that failed. So there are a lot of them available as nearly-new on eBay. In the UK I picked one up for about £60, I think.

[1] https://support.getawair.com/hc/en-us/articles/360049221014-...

omh··on UK government ban for Chinese Hikvision CCTV cameras
Even in this dual-homed setup, there is still the potential for the cameras to infect, or otherwise compromise the recording server

I agree that this is a potential risk.

But if the cameras themselves can't route to the internet in this scenario then how are they infecting the recording server? Is the suggestion that they come shipped from the factory with code to compromise common recording servers? It seems like that would be very significant and something that we'd be able to see in action.

My biggest concern with CCTV networks that I manage is some sort of backdoor access to the cameras themselves. So the dual-homed server design is exactly what I'd choose in order to control things.

omh··on Show HN: Tracking my local bus with a RaspberryPi
I love the form factor of this and the ambient data.

TFL do have some quite good APIs so you could use those rather than scraping the HTML.

https://tfl.gov.uk/info-for/open-data-users/api-documentatio...

I think you need to register but they seem happy to have amateurs and enthusiasts using them and they work quite well.

omh··on Cloud desktops aren't as good as you'd think
[ Disclaimer - I am responsible for a Citrix environment, but I'm reasonably proud of how well it works for our company ]

The technology behind remote desktops is fundamentally limited but I'm amazed at how good the user experience can be on a modern well-configured Citrix environment.

- The protocol responds well even on low bandwidth as long as latency is OK. On the office LAN it feels like a local computer.

- There is offloading for Teams[1], media streams[2] and even entire web browsers[3]. The tech behind this is impressive and it works pretty well (mostly!)

- For most staff it's easier to use a thin client or a minimal laptop.

- I can keep the Citrix environment patched and managed much more easily than a proliferation of laptops and home devices.

It can be a struggle at times and it's definitely not the right fit for developers. But it's got a lot of advantages and most of the time it works amazingly well.

[1] https://docs.citrix.com/en-us/citrix-virtual-apps-desktops/m... [2] https://docs.citrix.com/en-us/citrix-virtual-apps-desktops/m... [3] https://docs.citrix.com/en-us/citrix-virtual-apps-desktops/m...

omh··on My Preferred Smart Home Vendors
There is something odd about the battery life on the Ikea motion sensor.

I use it in our bathroom and it's activated multiple times per day. The first battery lasted about 3 months but the second battery has been going for over a year.

There are some reddit threads but I never got a clear answer.

omh··on In defense of cryptocurrency
> It's not even using more energy than Christmas lights or wash dryers

I can't come up with any reasonable measure by which Christmas lights use more energy than Bitcoin mining. The reports that suggest this seem to extrapolate US figures across the world, which looks unrealistic. And they're old enough that they don't account for the switch to LEDs.

Even if a billion households had 50 strings of LED lights each and kept them lit 24/7 for all of December, they'd still use less energy than the annual usage of Bitcoin.

omh··on Reversing a 2.4GHz Remote Control
You're right that an artificial pancreas needs to be super careful.

The diabetes community got started on this before the official manufacturers did. Probably in part because the manufacturers were concerned about being 100% bulletproof whereas (some) people living with diabetes were willing to take a bit more risk. And there's a balance around alarms. Some glucose monitoring tech can be frustrating and lead to "alarm fatigue".

Most of the artificial pancreases I'm aware of mitigate some of the risk by rarely sending large boluses at all. They tend to adjust the background basal rate and only send a bolus when you explicitly tell them you've eaten.

omh··on Reversing a 2.4GHz Remote Control
I also have an unhackable pump, unfortunately. I know there were attempts on the later Medtronic pumps by some pretty smart people so it looks unlikely that they'll ever be able to be controller openly.

My next pump will definitely be one that allows remote control and some sort of looping. Whether that's officially from the manufacturer or not.

omh··on Reversing a 2.4GHz Remote Control
I suspect you're aware, but there is a significant community effort on communicating with various insulin pumps.

The old Medtronic pumps were hacked years ago and Medtronic responded by making it impossible with newer pumps.

By now there are at least 3 different apps on different platforms and they support a variety of pumps.

omh··on Lambdas as values in Excel
Quite a lot of organisations are now running Office 365. It gets updated monthly with new features as well as security updates.

Even more conservative organisations will often be running Office 365 with a lag, still getting features after ~6 months.

If you need 100% compatibility that will always take a while, and I'm sure some big enterprises are on old style office. But it seems like the vast majority of small/medium business is on the Office 365 juggernaut now.

omh··on Vue 3 drops IE11 support plan
I've been asking the vendor the same question!

They seem to think it's not a drop-in replacement and don't want to rework their code to deal with the changes. I'm not sure to what extent this is Microsoft making compatibility hard or just a lazy vendor.

Page 1 of 14Next →