HNHacker News
TopNewBestAskShowJobs

rmdoss

722 karma · joined April 26, 2013

submissionscomments
rmdoss··on Splunk IP suit against Cribl
Hope Splunk loses. Trying to kill a good player that makes Splunk less expensive.
rmdoss··on US border forces are seizing Americans' phone data and storing it for 15 years
The border is often a lawless section of most countries - specially the US.

People can get detained, deported and humiliated for no reason and with no resource. Specially foreigners trying to go through.

rmdoss··on Drop in Cloudflare Replacement
A couple that I know:

Sucuri: DNS, WAF and CDN

NOC.org: DNS, WAF and CDN

rmdoss··on Ask HN: Boring but important tech no one is working on?
Duolingo is doing it amazingly to learn a new language.
rmdoss··on Impact to DigitalOcean customers resulting from Mailchimp security incident
Mailgun here. Just works, pretty cheap.
rmdoss··on Peloton to Cut 800 Jobs, Hike Prices and Shut Stores in Sweeping Overhaul
Isn't it the second or third round if layoffs? Great concept and loved my peloton during the worst of covid, sad to see what is happening.
rmdoss··on Ask HN: How to deal with children's online habits?
So hard to balance both.

For my young kids ( under 10 ), I am very strict on what they can see and do online. Screen time, CleanBrowsing, and app restrictions enabled.

For my teenager, it is a bit different. More conversation, more privacy and more spending time teaching her about computers, security, privacy, etc. She chose to install CleanBrowsing, an ad blocker, all on her own to protect herself.

Good luck!

rmdoss··on I've started using Firefox and can never go back to Chrome
As a long time Firefox user, my main issue with Firefox is Mozilla itself and their focus shifting to VPNs, pocket and things non browser related.

But still love Firefox.

rmdoss··on Ask HN: What do you code when learning a new language/framework?
It depends on the reason to learn a new language. Once you know a few languages, you generally only learn a new one if you are trying to solve a specific problem that it can do better.

What I try is to solve a small piece of the problem I am trying to solve to get more familiar with it before committing.

rmdoss··on New GitHub Profile Badges Beta
Everything needs to be gamified now.
rmdoss··on Report says Microsoft will require SSDs for new PCs soon, but is it a big deal?
Makes sense for the US market, where every device already comes with SSDs. But that's not as common in other countries.
rmdoss··on Find a good available .com domain
Most new companies now are on generic TLDs ( or .nets, .orgs, etc). Don't think .com matters as much anymore
rmdoss··on Yep: Google alternative that shares revenue with creators – by Ahrefs
What's wrong with ahrefs? Besides having a pretty annoying crawler?
rmdoss··on How to Enable DNS-over-HTTPS in Firefox
Not from my experience. That's why I had to disable DoH locally.
rmdoss··on Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)
Archive.is is very interesting. I was checking and they block (by responding back with 127.0.0.3):

- 1.1.1.1

- Neustar DNS

- AdGuard DNS

But they don't block Quad9 or CleanBrowsing that also do not send the EDNS subnet. Very curious way of blocking itself out of the Internet. OpenDNS blocks it (sends to their block page):

https://dnsblacklist.org/?domain=archive.is

Would love to hear from someone from archive.is what is going on.

rmdoss··on Tell HN: Archive.is inaccessible via Cloudflare DNS (1.1.1.1)
Firefox is likely falling back to your local resolver (the default) when it can't find a domain.
rmdoss··on DNS-over-HTTPS Policy Requirements for Resolvers
Note that with DoH on Firefox, your intranet domains do not work. Had issues with it before and had to disable DoH just to access our company printer. Also causes issues with DC.

That goes into the argument that DNS (domain name lookup) should be a system and network-level setting, not an App-based setting.

rmdoss··on Paul Vixie thinks more people should be running their own DNS servers
More people should be running their own mail servers, their own web servers, their own IRC servers, etc.

But I don't think we are ever going back to that direction. The arguments and benefits for running one locally are not enough the trouble as well.

Performance? Due to DNS caching at the resolver level, it is probably faster to use Google's 8.8.8.8 or CloudFlare's 1.1.1.1, than anything local (where all dns requests are a MISS).

Privacy? With DNS over TLS/DNS over HTTPS, your ISPs can't see what you are doing. If you run DNS locally, they can. Yes, they will see all the requests your resolvers are doing to the auth DNS servers.

Security? Some good resolvers, like Quad9 or CleanBrowsing will block malicious domains. CleanBrowsing will also help blocking adult content if you have kids. I don't think maintaining such control is practical for most people (pi-hole helps, but still hard to keep it updated and find good enough databases to use).

I would love a de-centralized web, but it is pretty hard to go back.

rmdoss··on How the H-1B Visa System Can Hurt American Workers (2015)
He might be defending the value of immigration (and immigrants), not much the h1b. So I wouldn't accuse him or pushing an agenda because of that comment.
rmdoss··on Ask HN: How did you decide what problems to solve in your lifetime?
I dont think most people choose that (or even have a choice).

Whatever luck you get on your first job or whatever your pays more, becomes the problems you are solving.

rmdoss··on SQLite updated Code of Conduct
Thanks. I remember seeing that, but thought was a joke.
rmdoss··on SQLite updated Code of Conduct
Oh, I thought that was added a joke.
rmdoss··on SQLite updated Code of Conduct
Have any info on that?
rmdoss··on Someone used my IPFS gateway for phishing
Yep, both DO and Linode do the same thing. Just null route your IP and take forever to remove it once you fixed whatever problem it was (even if it was a false alarm).
rmdoss··on OpenSSL 1.1.1 Is Released
Does anyone know if nginx will support TLSv1.3 automatically if you recompile it with 1.1.1?
rmdoss··on Firefox’s Trusted Recursive Resolver DNS feature is dangerous
Yes, that's the big issue. Plus, changing to a different resolver is not very simple and most users won't even know.
rmdoss··on DragonFly BSD 5.2
Don't think the MD5 is there for security reasons, just to detect broken downloads.
rmdoss··on How to keep your ISP’s nose out of your browser history with encrypted DNS
It is not much about privacy, but about the integrity of your data.

Your ISP can see the IP addresses and all the meta data for your traffic. With the current way DNS is setup, they can modify the responses and re-route you any where they want.

With HTTPS and encrypted DNS, it makes a lot harder for them to inject content or redirect you without browsers warnings.

rmdoss··on IBM Quad9 – A free security solution using DNS to protect against cyber threats
Quick performance test comparing these 4 players:

* Google: 8.8.8.8 * Quad9.com: 9.9.9.9 * http://OpenDNS.com: 208.67.222.222 * https://CleanBrowsing.org: 185.228.168.168

Results:

  New York:
  64 bytes from 8.8.8.8: icmp_seq=2 ttl=60 time=1.62 ms
  64 bytes from 9.9.9.9: icmp_seq=2 ttl=60 time=0.924 ms
  64 bytes from 208.67.222.222: icmp_seq=2 ttl=60 time=1.18 ms
  64 bytes from 185.228.168.168: icmp_seq=2 ttl=57 time=1.93 ms

  Montreal:
  64 bytes from 8.8.8.8: icmp_seq=2 ttl=55 time=13.0 ms
  64 bytes from 9.9.9.9: icmp_seq=2 ttl=56 time=16.7 ms
  64 bytes from 208.67.222.222: icmp_seq=2 ttl=56 time=16.5 ms
  64 bytes from 185.228.168.168: icmp_seq=2 ttl=50 time=9.18 ms

  Dallas:
  64 bytes from 8.8.8.8: icmp_seq=1 ttl=61 time=1.09 ms
  64 bytes from 9.9.9.9: icmp_seq=1 ttl=59 time=29.8 ms
  64 bytes from 208.67.222.222: icmp_seq=1 ttl=58 time=1.03 ms
  64 bytes from 185.228.168.168: icmp_seq=1 ttl=57 time=1.29 ms

  Paris:
  64 bytes from 8.8.8.8: icmp_seq=2 ttl=56 time=4.61 ms
  64 bytes from 9.9.9.9: icmp_seq=2 ttl=56 time=6.71 ms
  64 bytes from 208.67.222.222: icmp_seq=2 ttl=56 time=4.60 ms
  64 bytes from 185.228.168.168: icmp_seq=2 ttl=54 time=3.85 ms

  Tokyo:
  64 bytes from 8.8.8.8: icmp_seq=1 ttl=59 time=1.10 ms
  64 bytes from 9.9.9.9: icmp_seq=1 ttl=55 time=65.7 ms
  64 bytes from 208.67.222.222: icmp_seq=1 ttl=57 time=1.57 ms
  64 bytes from 185.228.168.168: icmp_seq=1 ttl=59 time=0.551 ms
Only New York and Paris were close. Their performance in Tokyo & Dallas were sub optimal. OpenDNS has a much better performance and closer to Google than quad9.

But I will still try it out and hope they keep supporting it.

rmdoss··on Qubes OS: A reasonably secure operating system
QubesOS -> Secure Desktop

OpenBSD -> Secure & minimal Server

OpenBSD doesn't have the isolation and hardening on the desktop apps, as Qubes has.

Page 1 of 4Next →