HNHacker News
TopNewBestAskShowJobs

s_ting765

158 karma · joined June 27, 2022

submissionscomments
s_ting765··on I close SSH port 22 (and what I use instead)
If one is so worried about zero days in openssh, the more practical solution would be centered around these 2 questions:

1. "would you know if you got breached?" 2. "would you have any reaction time?"

A simple solution that answers this: https://github.com/64mb/ssh-login-alert-telegram/blob/master...

s_ting765··on I hate packaging my software for Linux
There is Open Build Service from openSUSE which allows you to create packages and repos for a handful of distros. https://build.opensuse.org/
s_ting765··on Docker Sandboxes – Disposable, isolated sandboxes for AI agents
I use Flatpak/bubblewrap instead: https://news.ycombinator.com/item?id=48978112#48980221
s_ting765··on Annoying and alarming things about OpenCode
The solution is not to use docker to sandbox Opencode. It is to use flatpak/bubblewrap/flatseal.

I have vscode running in flatpak with directory permissions handled by flatseal. Vscode only has access to my dev folders and nothing else. Even the git bundled by vscode cannot call git push because of this (vscode doesn't have permission to read ~/.ssh!).

It's an easy sandbox that's provided free of charge courtesy of bubblewrap/flatpak.

As someone who uses opencode regularly, the quip about it asking for permission to read logs in /tmp after already writing to the directory is pretty funny.

s_ting765··on Rebuilding My Homelab with Compose, Ruby, IPv6, and No Kubernetes
Kubernetes is good for two things. Zero downtime deployments and self-healing (where the looping state mechanism comes in). There are people who want k8s to handle every single operation that can run on a server, do not listen to those kinds of people they will lead you astray.
s_ting765··on TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
1.98.9 has already been tagged since bulletin was published (don't know why they chose on github to tag but not release).

1.98.9 version exists! That's not the question. It should already have been made available for Linux distros assuming this resource from Tailscale is accurate https://pkgs.tailscale.com/stable/?v=1.98.9

Edit: Their changelog also mentions the version: https://tailscale.com/changelog#all

s_ting765··on TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
I don't see the point of publishing a security bulletin if you are not going to timely push the fix to artifacts on all affected platforms. Tailscale needs to do better on their release process, docker hub shows last update was 8 days ago.
s_ting765··on I Don't Maintain My Homelab
Same here. Even though my homelab runs on a VPS. https://github.com/rhee876527/expert-octo-robot
s_ting765··on Replacing Systemd with OpenRC in Debian
Sure. After you have located root and the boot partition which is what this addresses.
s_ting765··on Replacing Systemd with OpenRC in Debian
Partition autodiscovery is pretty neat. I did my archlinux install with it using this guide[0]. I have never touched /etc/fstab and I have had zero to worry about corrupting a boot with wrong fstab entries.

[0] https://walian.co.uk/arch-install-with-secure-boot-btrfs-tpm...

s_ting765··on Minimus container images are now free
Pausing software updates by X days old is a hack at best for specific distribution platforms (npm), not a general security recommendation.
s_ting765··on Frood, an Alpine Initramfs NAS (2024)
You can do the same from an USI made from mkosi (mainstream distros support) with kernel boot parameter systemd.volatile=overlay. https://github.com/rhee876527/UKIfy-Xubuntu
s_ting765··on Open source AI must win
Well, open source AI is mostly coming from China. Title should have been China must win.
s_ting765··on SQLite is all you need for durable workflows
This decision tree doesn't make much sense to me. Why you someone forego performance today in favor of adding a completely unnecessary network layer to every DB query in order to "satisfy" future imaginary "scaling concerns"?
s_ting765··on An update on GitHub availability
> Vladimir Fedorov is GitHub's Chief Technology Officer .... He currently serves on the board of Codepath.org, an organization dedicated to reprogramming higher education to create the first AI-native generation of engineers, CTOs, and founders.

I think I found the issue.

s_ting765··on State of Homelab 2026
What makes you think simply throwing random crap on a home VPN network is secure?

Tailscale/Wireguard is overkill because it is not needed where access controls work fine which is true for the majority of the popular self-hosted apps. And you now have to install a VPN client/cert on every device you want to access your services from. That's a major oof.

s_ting765··on State of Homelab 2026
Tailscale is an overkill solution. Opening ports 80 and 443 for a reverse proxy is enough security provided your apps don't have broken authentication. I've been doing this for years now.
s_ting765··on Open Source Security at Astral
Double checking Github actions does not mitigate threats from supply chain vulnerabilities. Forking an action moves the trust from a random developer to yourself. You still have to make sure the action is pulling in dependencies from trusted sources which can also be yourself depending on how far you want to go.
s_ting765··on Open source security at Astral
Pinning github actions by commit SHA does not solve the supply chain problem if the pinned action itself is pulling in other dependencies which themselves could be compromised. An action can pull in a docker image as a dependency for example. It is effectively security theatre. The real fix is owning the code that runs in your CI pipelines. Or fork the action itself and maintain it as part of your infrastructure.
s_ting765··on AI has suddenly become more useful to open-source developers
Coding agents are like asking a genie for code. They will give you the code you ask for alright but you never know what kind of curse has been crontabbed for you.
s_ting765··on Astral to Join OpenAI
It should have been FastAPI instead.
s_ting765··on Mount Mayhem at Netflix: Scaling Containers on Modern CPUs
Interesting blog post. For what it's worth, I count 7 em-dashes used.
s_ting765··on Ghostty – Terminal Emulator
> Ptyxis: Your Container-Oriented Terminal for GNOME

> A modern terminal emulator built for the container era. Seamlessly navigate between your host system and local containers like Podman, Toolbox, and Distrobox with intelligent detection and a beautiful, responsive GNOME interface.

https://gitlab.gnome.org/chergert/ptyxis/-/blob/main/README....

s_ting765··on Ghostty – Terminal Emulator
I tried this out after getting annoyed for the 100th time by a recent bug in kgx/console that will occasionally fail to launch windows leaving incomplete windows as tabs.

Console has long since become abandonware pushing people towards ptyxis which is now the default gnome terminal. A damn shame considering console is basically complete software (the quality of software in gnome is on a downhill).

I would have given ptyxis a chance if they didn't take a basic terminal and added some fluff (features related to distrobox) on top of other annoying things I can't be bothered to remember about because I ended up removing the software every time I gave it a spin.

In just a few days I've been able to replace console with ghostty-nightly and I don't miss anything.

s_ting765··on Vibe coded Lovable-hosted app littered with basic flaws exposed 18K users
Ask the LLM to create for you a POC for the vulnerability you have in mind. Last time I did this I had to repeatedly make a promise to the LLM that it was for educational purposes as it assumed this information is "dangerous".
s_ting765··on NewPipe: YouTube client without vertical videos and algorithmic feed
I revived a once popular Youtube frontend called Cloudtube. All the Youtube media url deciphering is still done by Invidious and I use it more like a frontend for invidious.

https://github.com/rhee876527/clean-youtube/

s_ting765··on Lennart Poettering, Christian Brauner founded a new company
Opensuse have been working on making secure boot/TPM FDE unlock easy to use for a while now. https://news.opensuse.org/2025/11/13/tw-grub2-bls/
s_ting765··on You are not required to close your <p>, <li>, <img>, or <br> tags in HTML
Same with <svg> but Firefox's XML parser will not greenlight you.
s_ting765··on Sandboxing Untrusted Python
Docker provides some host isolation which can be used effectively as a sandbox. It's not designed for security (and it does have some reasonable defaults) but it does give you options to layer on security modules like apparmor and seccomp very easily.
s_ting765··on A super fast website using Cloudflare workers
The perfect lighthouse score might have changed since this was last updated. Am seeing 97% on accessibility.
Page 1 of 5Next →