HNHacker News
TopNewBestAskShowJobs

pliu

241 karma · joined October 17, 2011

https://twitter.com/pwyliu

[ my public key: https://keybase.io/pwyliu; my proof: https://keybase.io/pwyliu/sigs/_COjb32nYGeprGg6N0wkb7NUI450EkJJTKGdRG57JBc ]

submissionscomments
pliu··on Developing with Docker at 500px, Part One
Hi, I'm the author. If you have any questions please feel free to ask, I'll be checking in periodically.
pliu··on Google loses data as lightning strikes
"The Google Computer Engine (GCE) service allows..."

Did anyone else cringe?

pliu··on Ask HN: Can you get to AWS?
In a situation like this, how do you know that routing to the status page is not the problem? Many of these companies use statuspage.io which is on AWS.

Edit: this is an edge case, clearly. I just think it's an interesting problem.

pliu··on Tarsnap performance issues in late March, most of April
The chef-client cookbook does a similar thing in its cron recipe:

  # Generate a uniformly distributed unique number to sleep.
  if node['chef_client']['splay'].to_i > 0
    checksum   = Digest::MD5.hexdigest(node['fqdn'] || 'unknown-hostname')
    sleep_time = checksum.to_s.hex % node['chef_client']['splay'].to_i
  else
    sleep_time = nil
  end
https://github.com/opscode-cookbooks/chef-client/blob/master...

This is random enough so you won't kill the server, and deterministic so the resource isn't always changing every Chef run.

pliu··on We are under attack
CDN costs money too. 722K req/s is a lot.
pliu··on Duplicate SSH Keys Everywhere
cloud-init

https://cloudinit.readthedocs.org/en/latest/

pliu··on An Open Love Letter to Our PC Fans
Definitely not the case. I have played through all the Kingdom Rush games, fully and doing all the bonus objectives, without spending a dime beyond the initial purchase. I had a great time too, and I have a pretty low tolerance for grind. I think the KR games are exceptionally well designed in this regard.
pliu··on AWS EC2 Container Service
Docker is built on LXC, Linux containers.

LXD is a new thing from Canonical, a hypervisor designed especially for containers that is supposed to guarantee hardware isolation.

pliu··on CipherShed, the Truecrypt fork
For disk encryption on Windows, I switched to Bitlocker for my personal use. At my workplace we use Symantec Encryption and Sophos Safeguard, my understanding is they are both pretty okay.

For file encryption, now I just do everything on my Ubuntu workstation and use GPG + tarballs. This is sort of a pain in the ass though, and it's not as secure as a TC container of course. It's kind of just a stop gap until I can think of something better.

pliu··on CipherShed, the Truecrypt fork
I used Truecrypt heavily for years, but since all the kerfuffle happened I've switched to other stuff. I like Truecypt and would like to move back, but I'm not sure when I'll be able to trust a fork. I can't audit the code myself so I have to rely, I guess, just on mind share and the opinions of security people who are smarter than me.

I'm curious about what other users are doing in this situation. What are your criteria for trusting a fork? How will you know when something (not necessarily CipherShed) is mature and safe enough to use?

pliu··on Justin.tv has shut down
I've never tried it myself, but I believe you can livestream on youtube.

https://support.google.com/youtube/answer/2474026?hl=en

pliu··on Machinery – A Systems Management Toolkit for Linux
If I understand correctly from reading the man page[1], unlike Puppet there's no server.

You just run a command line tool on a node to inspect or create a "system description". You can then export and deploy a description to create repeatable systems. In this regard I think it's similar to what Blueprint[2] does (or did I guess since Blueprint seems dead now). So it's a lot more lightweight tool and has many less features than Puppet, certainly.

Another cool thing is you can use Machinery to build images and deploy to Openstack. Where I work I spent a pretty long time building similar tooling for Xenserver. Sure would have been nice to have just been able to say "oh there's a thing for that". I'm excited to try this tool out and see what it does.

I think Machinery only works on SLES and opensuse right now. I didn't see any mention of other distros.

[1] http://machinery-project.org/manual.html

[2] http://devstructure.com/blueprint/

pliu··on Blink
Works on a phone too. "ok google, do a barrel roll".
pliu··on Poll: Where do you host your production environments?
Softlayer, HP Cloud
pliu··on Neutralizing the iOS camera click sound through active sound cancellation
It's all relative. There are probably a lot of subway riding Japanese ladies that would argue that this problem really really should exist.
pliu··on Finally a truly beautiful and real time Instagram and Twitter stream service
$299/day seems kind of steep. Who is this for?
pliu··on Google offering $1M prize for a much smaller power inverter
Not even for a million bucks? I feel like the intended audience will be interested enough to come back later.
pliu··on Clef – stop using passwords
You have to enter a 4 digit PIN number into the app. It's still two factor, since you have to auth to the app to get the one time pass.
pliu··on How to Create Your Own Git Server
I have pretty much the same setup at my work too. It goes Gitlab->Jenkins->Puppetmaster. This works super well with Puppet dynamic environments, since each team member can have their own branch to mess around in and make mistakes. On our master branch you have to pass puppet parser validate and puppet-lint before things get to production, which helps cut down on errors.

http://puppetlabs.com/blog/git-workflow-and-puppet-environme...

pliu··on The Great Firewall of Yale
This looks like the block page you get from a Palo Alto firewall. The feature set includes traffic inspection, among many other things. We've got a couple where I work, they are pretty great firewalls actually.
pliu··on Apple fined for price fixing
If they wanted to send a message like that they would have fined them $444 000.
pliu··on Reverse engineering Snapchat to store files
This seems like kind of a crummy thing to do to snapchat, but I like the idea.

I wonder if that could be successful, like a file swapping service built on the same premise of one time only. Charge a nickel a shot or something. I have no idea why that's useful, but for some reason I think it's cool. Maybe just because it's set and forget and you don't have to worry about cleaning up later.

Does anything easy to use do that already?

pliu··on My First Job: Fired and Rehired on Day 1
Your values are not universal to all humanity. Sometimes I work an 80 hour week. I do this because I'm engaged with something and I don't want to be doing anything else. When I don't want to do that, I work normal hours. I live how I want to live.

I have friends, family, and a life. I'm also naturally introverted, and sometimes I just want to put my head down for a week and jam. This is something I like doing.

Different strokes for different folks man. I think your life is sad if you can't understand that some people are different than you are.

pliu··on Twitter’s New Two-Factor Solution Kicks SMS to the Curb
Same for me. Super weird. I can't wait for the blog post that explains what code blew up for this to happen.
pliu··on Build your own private, encrypted, open-source Dropbox clone
There is nothing particularly special about Backupsy as far as I can see. Just cheap simple servers with a bunch of disks in them. This type of hardware is very cheap. The software layer is equally simple - seems like just KVM and a dashboard, nothing fancy. So then low cost, low price right. Good combo.

However as you can see from the SLA (99.9%), you do have to pay something in the form of reduced redundancy and availability. If, for example, an HP RAID card freaks out and all the VM's get corrupted on your blade, well you are out of luck. That data is gone forever. It's a small risk, but it is a real one (in fact with the P410 they are using, that's actually happened to me before in production). There are lots of other things that can go wrong too. Virtualization is not all rainbows and unicorns.

In the end I think it's still a good deal if you need a backup target with phat storage in it. But if you are interested in just trying out stuff, I think Digital Ocean is a better call since they have a higher SLA (99.99%) and probably a better dashboard and it's around the same price. Backupsy, as the name implies, is made for backups.

pliu··on Do_good.js
Hijacking my cpu without my consent is not doing good. There is nothing good about that.
pliu··on Google has indexed thousands of publicly accessible HP printers
I may or may not have just printed out some random messages for people to find.

There is something strangely compelling about sending thoughts out into the ether with no chance of feedback. Fax pranks are before my time, but I totally get it. I hope I made somebody smile today.

pliu··on Petition the Whitehouse to remove Carmen Ortiz from office
Quinn Norton:

"It wasn't Carmen Ortiz that hounded Aaron to death, it was Steve Heymann. And the system that helped him do it: that was all of us." https://twitter.com/quinnnorton/status/290204205124304896

And Tim Carmody:

"FWIW, Carmen Ortiz just runs the US Attorney's office in MA. Stephen Heymann is the Assistant US Attorney going hard after Aaron Swartz." https://twitter.com/tcarmody/status/290192055488094209

pliu··on Steam releases Big Picture mode
This is their console.
pliu··on Microsoft offering Linux virtual machines on Azure
The virtualization platform they are using for all this stuff is Hyper-V which runs on Windows, so the name is still relevant.
← PreviousPage 2 of 2