HNHacker News
TopNewBestAskShowJobs

robalfonso

499 karma · joined September 17, 2013

submissionscomments
robalfonso··on Authentication Is Largely Solved. Authorization Isn't
Agreed, this is like the lead the horse to water issue. Yes the water exists, no one is really drinking it yet.
robalfonso··on Apple's new ad: a perfect reflection of society
I feel in the minority, but took the ad as if it was compressing all those things into the iPad, not “destroying” them. Maybe it’s a glass half full kind of thing.
robalfonso··on Zigbee and Z-Wave are the best part of my smart home
I've found that some people have great zigbee experiences and terrible z-wave and just as many are the opposite. I chalk it up to individual environments etc. Go with what works best from you.
robalfonso··on Making my own bed sensor
Fibaro makes a similar device in a smaller form factor as well

https://www.thesmartesthouse.com/collections/fibaro/products...

robalfonso··on Making my own bed sensor
I've done this as well, but I moved to 500kg load cells on the bed legs for reliability.

2 Load cells one on each back leg of the bed. Upside too is I've been able to discern things like, sitting on the edge of the bed to put on shoes etc based on the weights.

Esphome, load cell, and hx711 chip for the load cell comes out to about $40-$50 each leg.

robalfonso··on NYPD will use drones to monitor backyard parties this weekend
My feeling would be this does violate the law. The problem is new technology must often go through courts to actually establish the law. So it seems that while the NYPD could decide it’s a no-go, their worse case is to do it, get sued and then let a judge make the call.
robalfonso··on AI bots are now better than humans at decoding CAPTCHAs
To that point, when I do the picture captcha (Select the crosswalks type question), I always click a square I know is not valid and then de-select it. Adds some "human-ness" to the interaction and I never get a 2nd challenge that way. Will that be the future? Look for behavior that is too perfect?
robalfonso··on Purchase and manage domains directly through Bluesky
This is actually really messy.

It’s unclear to me who is the registrant in this scenario.

If blue sky then you don’t own anything and there is no portability.

If you are the registrant that’s great but namecheap is going to need contact information that’s verifiable which may turn people off who would like a bit more separation on their social profiles. I also wonder does blue sky see that registrant data? Can’t say I like that very much.

robalfonso··on Hacking root EPP servers to take control of zones
This is interesting, however the vast majority of registries require connecting from a known ip, using a specific cert chain and in some instances their own ca. Turns out when you don’t follow industry practices in one way you don’t do much else right either
robalfonso··on Apple sued by two women over AirTag stalking
This is hyperbole. You typically can't sue (and win) against the maker of an item used in a crime just because they manufactured it.

There is usually some extenuating circumstance when these cases do prevail. For instance one manufacturer was found to have such incendiary marketing around their assault rifle it had risen to the level of a "call to arms". So typically it has to be more than "We are the manufacturer"

robalfonso··on It’s time to repeal the Jones Act
It’s not just those issues. The original Impetus for the jones act was to keep a strong merchant marine for war time, so we subsidise the us merchant fleet so that if we had need during war they would exist.

I find this difficult because my outlook for those kinds of conflicts indicates it’s not necessary to have such a fleet, but if you need it, it’s too late to decide. Those ships are a multi year build.

I would think some flexibility and also some accounting of exactly how many us merchant boats we’d need should inform changes to the Jones act.

robalfonso··on I wrote a short story about von Neumann probes
Another vote for bobiverse, absolutely great book.
robalfonso··on Show HN: Red Goose – Convert your website to mobile app
I have to think that in this case they mean "website" in the historical form as content vs "app-like" meaning like a web application. If you already have a web application and it works well on mobile, what more could they expect really?

If you are local news site, then this probably is going to be an issue. If your app allows someone to track how many package deliveries they have, then it likely already in a format they are happy with.

robalfonso··on A coding error caused Rogers outage that left millions without service
No-blame culture and no-consequence culture are not the same thing. Just because you don’t get fired doesn’t mean the org should allow someone the capability to make the same mistake, whether that’s access/permissions/change in org etc
robalfonso··on Being on call sucks
Your org needs to be at either end of a spectrum. Either on-call is mostly quiet, and non-disruptive and truly only there for huge issues that happen seldom. Or you staff up a dedicated 24/7 team. If it's in between you need to plan on getting to one end before you wear out your team.

I think on-call and the quality of life component are highly dependent on the company culture, the types of alerts, etc.

My org on-call was laid out like this:

3 days at a time and then a break of X days (depending on team size - This option was chosen by the team)

Comp time for any incidences (plus manager flexibility, up late fixing something no one expects you in early or at all depending on how it went)

We leveraged a provider to handle alert escalation, rotation, phone calls etc. If someone didn't answer it rotated through to the next person and on up to management.

A regular look back at the type of calls coming in, and re-balance of alerting priorities to make sure if someone is going to get a call out of office hours, it better be necessary. We always asked "Could this have waited"

A general culture of helping out, if you couldn't fix something you could ask for anyone else near a machine to handle it.

A general culture of asking could we have automated a fix for this alert before getting a human involved?

Almost all tools were available via mobile and you would be amazed how often you could fix something from a mobile phone. In fact I fixed some service issue in about 10s in a movie, never missed a beat.

Trading on-call windows was typical and easy.

If your org can't do above and is truly wearing people out then you need to go the other way, and just staff up 24/7 and let people have their lives.

robalfonso··on My Preferred Smart Home Vendors
For me zigbee has been more reliable. I have only had Z-wave devices fail.

Regarding batteries I minimise the use of anything with batteries, but I make a point of buying devices that use larger batterieswhen I have to. I have a couple zigbee motion sensors going on 18 months.

Alternatively I’ll use a dummy battery to hard wire a sensor so I can remove the battery

robalfonso··on Tell HN: Cloudflare prevents transfer-out of domains, sets to 'pendingdelete'
I was just illustrating the normal circumstance delete is used. But there is no reason a delete can’t be used any time on an active domain.

All I can say is read the rfc or take my word for it, I’ve run a registrar.

robalfonso··on Tell HN: Cloudflare prevents transfer-out of domains, sets to 'pendingdelete'
Pretty much, there have been times I’ve deleted a domain due to compliance/legal type issues. It’s more expedient than waiting for an expiration
robalfonso··on Tell HN: Cloudflare prevents transfer-out of domains, sets to 'pendingdelete'
It does apply here. A domain does not need to be expired, a delete can be sent any time it’s active. The only prohibition is if the domain has “clientDeleteProhibited” status which the registrar can remove.
robalfonso··on Tell HN: Cloudflare prevents transfer-out of domains, sets to 'pendingdelete'
You linked the wrong doc. You want domain delete

https://datatracker.ietf.org/doc/html/rfc5731#section-3.2.2

robalfonso··on Tell HN: Cloudflare prevents transfer-out of domains, sets to 'pendingdelete'
When a domain expires it’s automatically renewed at the registry in the case of gTLD’s.

A registrant then has 30-44 days (depending on the registrar) to “renew” but in fact the domain has already renewed so in what happens is the registrar deletes the domain in the case where they don’t have that affirmative action.

robalfonso··on Tell HN: Cloudflare prevents transfer-out of domains, sets to 'pendingdelete'
The key part of this is “upon request” if you delete their domain beforehand then it gets messy. There is an argument to be made that it shouldn’t have been deleted in the first place.

Now as the registrant you have right to redeem the domain so you could recover via that route. So the domain CAN be saved.

robalfonso··on Tell HN: Cloudflare prevents transfer-out of domains, sets to 'pendingdelete'
It sounds like the domain was deleted. that is absolutely an action a registrar can take and you would have a pendingDelete status in addition to a redemptionPeriod status on the domain.

If I had to guess they kill an account and delete any of its domains, which is absolutely the wrong way to go about handling that. The domain is already registered so you move it to a holding an account for further resolution. just because you terminated an account you shouldn’t be deleting a domain.

robalfonso··on Gov.uk drops jQuery from their front end
As a counterpoint, I had a similar conversation with a report of mine about jQuery. He said it was not necessary and you could just use vanilla js.

I said while yes that's true as a dev if I told you I needed you to implement a new payment provider for billing would you tightly and directly align with who we used or abstract it away via some wrapper so that if we ever had to change it wouldn't be difficult? Of course everyone builds abstractions so you aren't stuck with a single provider because it's crazy not to.

I see jQuery as that abstraction. At the end of the day each browser is an api implementer and while they've come so far, that doesn't mean the situation is stable and we'll never see implementation fracture again. It of course doesn't have to be jQuery but any direct implementation of JS seems to have that risk which is easily mitigated by wrapping the basic functionality. I don't know why you wouldn't choose to do it.

robalfonso··on A molecular drinks printer claims to make anything from iced coffee to cocktails
Agree, the hubris required to make a similar device (and similar business model) after such a spectacular failure really amazes me.
robalfonso··on I took down my Starlink dish (but haven't cancelled)
He’s got a video where he tried this and was unable to get it working.
robalfonso··on Starlink Premium
Sam here, still no news on the original order.
robalfonso··on Amazon KDP delayed royalties til Jan 1 then killed the account on Dec 31
This is unfortunate, it seems the author is Nigerian and was flagged. Of course conveniently amazon is taking their money.

This is the problem with Nigeria (Pop 200mm) and other high risk countries with a reputation for internet fraud. Rather than try to solve the problem automated systems take over and legitimate actors are left w/out recourse.

robalfonso··on Your eBay account has been suspended
Because of this, I make a point of having 3 2fa keys. A daily driver, a backup key on a key ring and the final one in a fireproof safe. Like you I would be afraid what would happen if I lacked my key.

Companies need to at least clarify “what happens if I don’t have my key” also one time codes are a thing that need to be saved and can help mitigate a hardware failure.

robalfonso··on Apple AirTags being used by thieves to track high-end cars to steal
I think this is only notable because it’s apple. There are many options on the market for gps trackers that have live updates. Not as cheap as an AirTag but cheap enough when stealing expensive vehicles.
Page 1 of 7Next →