HNHacker News
TopNewBestAskShowJobs

phaer

2,288 karma · joined February 7, 2011

submissionscomments
phaer··on Nix-Powered Development with OCaml
Afaik it's not finished yet, but there recently has been quite a lot of activity regarding secureboot for nixos https://github.com/nix-community/lanzaboote/
phaer··on How do Nix builds work?
Grepping nixpkgs is what i do as well, but for functions specifically i found https://noogle.dev/ to be useful.

Same experience with mkDerivation as well - I personally have lots of hope for https://github.com/DavHau/drv-parts and similar projects to improve that situation :)

phaer··on Dusting off Dreamcast Linux
> On the other hand what’s the use case of a POWER9 desktop system?

It's pretty much the only platform which can be run without firmware blobs that's somewhat competitive in terms of performance afaik.

phaer··on Show HN: Git Heat Map – a tool for visualising git repo activity for each file
Looks useful on big repositories!

https://github.com/nixos/nixpkgs/ would be a great benchmark for a tool like this :) One of the larger repos on github, close to half a million commits by a large set of contributors to thousands of files.

phaer··on Companies hiring remote software engineers anywhere in the world
Whenever a company has got a "Python" tag, there's a "Pyth" tag right before that, I assume that's a typo?
phaer··on ZFSBootMenu – A boot loader to manage ZFS boot environments for Linux
What do you mean "have been trying to make zfs happen"? ZFS is used in production in many places.
phaer··on Ntfy.sh – Send push notifications to your phone via PUT/POST
It's of course possible to mitigate, but that's somewhat more involved than "just" sprinkling e2e encryption on top ;)
phaer··on Ntfy.sh – Send push notifications to your phone via PUT/POST
Especially with things like notifications, even e2e encryption can't generally provide complete privacy because metadata is data too ;)
phaer··on Dutch employee fired by U.S. firm for shutting off webcam awarded €75K in court
All true, but it might be worth mentioning that most of those benefits are still Austrian law, not European law. So while they generally better than the US, other EU states might lack some of those law.
phaer··on Mastodon.technology Shutdown
> Can you really build a social network on volunteers that invest their own money and time, with little reward?

You can at least use it for existing communities and "social networks": family, friends, geographical communities, hobby- or work-related ones. To provide them a somewhat self-administered space online to connect and share photos and other info. Thanks to federation this community can have its own "space" without being isolated from the rest of the internet. Open-ness can be somewhat gradual.

There's lots of different of ways to organize funding and the ongoing technical work for such communities.

I think it becomes harder to build sustainable instances the less socially connected the admins are to the average user.

phaer··on Is the internet killing the nude beach?
Same in Austria, and I believe, in the whole EU.
phaer··on SSH tips and tricks
Thanks, I personally grew accustomed to just writing "ssh $host 'tmux a || tmux'
phaer··on Page was served from Nginx on ReactOS
This might not work the same for a fresh port on an alternative system. For example: I have no idea how many open connections reactos could handle on the kernel-side with a standard config.
phaer··on Nix: Taming Unix with Functional Programming
Flake-utils, flake-utils-plus, https://flake.parts/, https://github.com/divnix/std/ and others :D
phaer··on Our Roadmap for Nix
Yes, my understanding is that the official documentation lags behind community usage, because flakes are still an "experimental" feature as details of the implementation are worked out.

For reference documentation, there's "experimental commands" in the manual https://nixos.org/manual/nix/stable/command-ref/experimental...

phaer··on Nix: Taming Unix with Functional Programming
Great introduction and overview on the theoretic foundations of the nix ecosystem!

For people new to it, I am trying to provide a quick glossary of terms here, as I understand them after about 2 years of using nix.

* nix: a language to create derivations and the interpreter/package-manager which provides the implementation of said language. It currently offers two command-line interfaces, the stable on with hyphenated commands like "nix-build", "nix-shell", etc. And the newer, "experimental" one which includes support for nix flakes and so on, without hyphens: nix build, nix shell, nix run, etc.

   repo: https://github.com/nixos/nix
   docs: https://nixos.org/manual/nix/stable/
* nixpkgs & nixos is a huge mono-repo containing instructions how to fetch the source of tenthousands of software packages and how to build them on supported platforms. It also contains the whole nixos operating system and tooling to support all of that.

repo: https://github.com/NixOS/nixpkgs docs: https://nixos.org/manual/nixpkgs/stable/ docs nixos: https://nixos.org/manual/nixos/stable/

This tooling includes higher-level helpers for language-/environment-specific packaging, like "buildGoModule", "buildRustPackage" and so on, as well as e.g. tooling to run integration tests in a whole cluster of inter-connected linux VMs!

Packages which are submitted to nixpkgs must fulfill certain criteria, such as not using "IFD" (input-from-derivation, to simplify: "letting nix evaluate nix-code which was generated by another deriviation/"nix package".

nixpkgs is alive and well with lots of daily contribution and an everlasting effort to keep Hydra, the nix-specific CI/CD system and public binary caches up to date and responsive. Thanks to all maintainers & contributors!

* flakes are an approach to standardize a way to package nix code outside of nixpkgs but to still keep it re-usable. They are still "experimental" as the details are figured out, but nevertheless used in production. There are some frame-works to keep boilerplate low, like "flake-utils", "flake-parts" and others, as well as e.g. deployment tools like "colmena" and "deploy-rs" and re-usable helpers for system-configuration like e.g. https://github.com/nix-community/impermanence

There's lots of other stuff in the community, things like home-manager, direnv + flakes and devshells changed my workflow fundamentally to the better since I've switched. If you got the time and are still interested, join us on matrix or elsewhere :) https://github.com/nix-community/awesome-nix

phaer··on Adding Modules to C in 10 Lines of Code [pdf]
That's my understanding as well, so I think you are correct but I am no C wizard myself :)
phaer··on Adding Modules to C in 10 Lines of Code [pdf]
It's including another C file, normally you'd just include a "header file" in C and compile each C file separately.
phaer··on Ask HN: What is your Kubernetes nightmare?
Why would you need a load-balancer if you only have a single machine?
phaer··on Zoom.us is down
I think the problem might be less on the technical and more on the business-side of things.

Status pages that raise customers confidence in your service are good from a marketing perspective.

Automatically publishing uptime data without human review might be bad from a marketing perspective, if you don't trust the engineering department to actually deliver or if your service depends on too many external dependencies.

phaer··on The integrated timetable of Switzerland
> I find it even more amazing that there are more people who have a Generalabonnement than a Bahncard 100 (the German equivalent which is a bit cheaper). [1]

To contextualize this a bit: Switzerland has about a tenth of the German population (~8.5M vs ~83M)

phaer··on How to Store an SSH Key on a Yubikey
Ah yes good point for the gpg key itself, but I store a few other important secrets there as well ;)
phaer··on How to Store an SSH Key on a Yubikey
I think the official recommendation is to store a second yubikey in a safe location.

Personally I just generated my key offline (on a tails livecd) and backed it up to two different LUKS-encrypted USB sticks. One of those is stored at my place and another one at a trusted person, in case my flat burns down or so. The yubikey itself only stores subkeys, my master key stays on said USB sticks.

Been using this setup for about 5 years now and it's been working well for me so far. Once a year, I extend my gpg keys expiration time by using on of the USB sticks.

phaer··on Wp-SQLite: WordPress running on an SQLite database
You could get WP "5.9.3" (https://github.com/stokry/wp-sqlite/blob/main/wp-includes/ve...) from upstream and diff -ru them, i think? But yes, ongoing maintenance and following upstream might be more difficult then necessary with this fork
phaer··on How Nix and NixOS get so close to perfect
You can't make them go away, but you can follow upstream for security fixes as close as possible and communicate them as good as possible.

Nixpkg does quite a good job in tracking those issues, imho. https://github.com/NixOS/nixpkgs/issues?q=is%3Aopen+is%3Aiss... is a list of security issues. Most of them generated by automated scans of nixpkgs-unstable.

But as far as I am aware, there's no mailing list or so for receiving notifications upon critical vulnerabilities(?). https://nixos.org/community/teams/security.html mentions github issues, discourse and matrix. Triaging security issues requires significant work and it's a task even more traditional distros like Debian often struggle with.

One thing I'd like to see eventually is an option to nixos-rebuild and other to emit warnings if installed packages are affected by known vulnerabilities. I think that should be doable and would maybe raise awareness and provide most visibility to the issues affecting most users.

https://github.com/flyingcircusio/vulnix does something like this, but it's currently a third-party tool

phaer··on Show HN: I made a privacy-first minimalist Backblaze
[Pika Backup](https://apps.gnome.org/app/org.gnome.World.PikaBackup/) is a simple and well-designed GTK frontend for borg IMO
phaer··on Advice on accessing BBC News
Yes, it's an encoded public key, identifying the service. See https://en.wikipedia.org/wiki/.onion#Format

even "bbcnews" is part of that key, probably brute-forced until that prefix was found.

phaer··on Csv.vim: A Filetype plugin for CSV files
Visidata is such a gem of software! A real good example of what kind of UIs are possible for "power users"
phaer··on MirageOS 3.0 (2017)
Please note that this release announcement is from 2017. I'd suggest adding that to the title.

There have been several releases since, including the first 4.0.0-beta just yesterday https://mirage.io/blog/announcing-mirage-40-beta-release

EDIT: submitted the current one here https://mirage.io/blog/announcing-mirage-40-beta-release

phaer··on You can change your number
TextSecure, Signals name before re-branding started out doing only SMS encryption. Sending messages over data started earlier if I remember correctly. I think that must have been almost 10 years ago
← PreviousPage 2 of 17Next →