HNHacker News
TopNewBestAskShowJobs

sarnowski

894 karma · joined July 6, 2011

submissionscomments
sarnowski··on Microplastics found in 93% of bottled water tested in global study
Living in Germany/Berlin and can confirm. Our tap water is excellent and is way cleaner than all bottled water you can buy. Keep in mind, bottled water is also kept around way longer and has the time to „breed“. In tests, the tap water is consistently less contaminated. I recommend everyone to just stick to it.

As an anecdote: you can let your tap water be tested for free if you have a newborn to ensure and confirm that you can use it for baby food without doubt.

sarnowski··on Using Git Wrong
Wait, what?

> git was invented before continuous delivery

git was invented 2005. So you mean when people used the term Continuous Delivery more frequently? Because using CI and automatically deploy is not "new" and was surely done before git - I remember doing that even with CVS and SVN.

sarnowski··on Android Oreo
Wondering if the following feature is enabled by default:

"Wi-Fi Assistant

Auto-connects you to high quality open WiFi and secures your connection with a VPN back to Google."

I really do not want to tunnel my whole traffic through Google's servers.

sarnowski··on Firefox Focus – A new private browser for iOS and Android
I don't know but assume its a similar issue as with Google Analytics. In Germany, you are not allowed to use default configured Google Analytics. User IPs are PII for our data protection laws (it is possible for someone on earth to know who is probably behind that IP like telcos). As a consequence, we need to disable IP tracking:

https://developers.google.com/analytics/devguides/collection...

sarnowski··on Show HN: Bt – BitTorrent library in Java 8
> Make sure to install http://www.oracle.com/technetwork/java/javase/downloads/jce8.... to allow 160-bit cryptography

Or don't use the Oracle proprietary distribution but the OpenJDK of your operating system which normally doesn't exclude proper crypto algorithms.

(be aware that the JDKs downgrade silently if certain libraries are missing in your host)

sarnowski··on European Parliament Draft to Enforce End-To-End Encryption for Citizens' Privacy
Somehow the actual EU states aren't really behind this. Germany's interior minister just recently proposed a new attempt at legalizing spying citizens devices.

http://uk.mobile.reuters.com/article/idUKKBN1951VG

sarnowski··on Basecamp Employee Handbook
In Germany, you can take several years parental leave in which you are protected against being fired. But you only get paid up to 14 months and only up to 60% or ~2000$/month after tax. This gets completely paid by your health insurance (which you have to have) and your enployer doesn't have to pay anything.
sarnowski··on Google Home now supports multiple users
Great, and now let me add my kids and have some parental control features based on their voice recognition ;-)
sarnowski··on Containers vs. Zones vs. Jails vs. VMs
Containers are just advanced chroots. They do the same with the network interface, process list and your local user list as chroot is doing with your filesystem. In addition, containers often throttle resource consumption of CPU, memory, block I/O and network I/O of the running application to have some QoS for other colocated applications in the same machine.

It is the spot between chroot and VM. Looks like a VM from the inside, provides some degree of resource usage QoS and does not require you to run a full operating system like a VM.

Another concept that is now also often automatically connected to containers is the distribution mechanism that Docker brought. While provisioning is an orthogonal topic to runtime, it is nice that these two operational topics are solved at the same time in a convinient way.

rkt did some nice work to allow you to choose the runtime isolation level while sticking to the same provisioning mechanism:

https://coreos.com/rkt/docs/latest/devel/architecture.html#s...

sarnowski··on Deploying PostgreSQL Clusters Using StatefulSets
We don't have a separate internal version. We are already running some hundreds PostgreSQL clusters in AWS + etcd with Spilo/Patroni. The Kubernetes variant is not used yet in production but we plan to migrate the first datasets soonish (probably some weeks).
sarnowski··on Deploying PostgreSQL Clusters Using StatefulSets
Yes, we are currently developing a PostgreSQL operator for Kubernetes. We are heavy PostgreSQL users. Spilo[0] supports all kinds of slave configurations, backups, monitoring tools[1] and all advanced capabilities.

[0] https://github.com/zalando/spilo [1] https://github.com/zalando/PGObserver

Edit: https://github.com/zalando/patroni is a better link

sarnowski··on Introducing Docker Secrets Management
That is the same trust boundary as in Kubernetes currently: https://kubernetes.io/docs/user-guide/secrets/

It is the most important step that you can package containers without having to know the production secrets and to have a "standard" was to retrieve them.

No one, without production access, has a way to obtain them.

sarnowski··on Introducing Docker Secrets Management
A single software piece can't be PCI compliant but only how you use it.

You have to argue that Docker uses the Linux isolation mechanisms that make those containers virtual machines in the sense and spirit of PCI.

Treating containers as VMs makes some other requirements even easier like the request to have a minimal system and to only have one function per server - thats how you want containers to work anyway.

(Btw PCI has nothing to do with PII.)

sarnowski··on Show HN: GitPlex – A new Git repo management server with code review
Sounds like you described https://www.jetbrains.com/upsource/

(I am not affiliated with Jetbrains in any way)

sarnowski··on Sad reality: It's cheaper to get hacked than build strong IT defenses
For Reference: https://en.m.wikipedia.org/wiki/General_Data_Protection_Regu...

This directive will drastically increase fines for data leaks in the EU.

sarnowski··on Don’t just pardon Edward Snowden; give the man a medal
Interestingly, the german preliminary constituion (we don't have a real one) that was written by the WWII allies also is about people but unambigously means all people on earth.

'Article 1 of the Basic Law (in German legal shorthand GG, for Grundgesetz), which establishes this principle that "human dignity is inviolable" and that human rights are directly applicable law, ...'

https://en.m.wikipedia.org/wiki/Basic_Law_for_the_Federal_Re...

sarnowski··on Haskell vs. Clojure (2014)
Not arguing that the following method can be trusted as much as in Haskell but properly used also prevents this kind of scenario:

https://clojuredocs.org/clojure.core/io℅21

The 'io!' macro marks a code block to have side effects which prevents using it in a STM transaction as 'dosync' might need to execute the functions multiple times in case of conflicts during the optimistic locking.

sarnowski··on Google Cast is now built-in to Chrome
Actually this is how the chromecast works. You never interact with the chromecast directly to configure your Netflix account for example. I assume (hope) they send a URL to the movie it should play with a one-time token to access the movie source.
sarnowski··on Vizceral Open Source
So, who is working on a ZipKin backend to reuse its data to have these nice graphs?
sarnowski··on Hypernetes: Bringing Security and Multi-Tenancy to Kubernetes
That is what rkt with kvm is essentially doing as well, correct?

https://coreos.com/rkt/docs/latest/running-lkvm-stage1.html

sarnowski··on Experienced Programmers Use Google Frequently
This small post is spot on. The search queries could have been typed by me. One of the important things a developer has to learn is how to actually use Google for software investigation. Especially with the acronyms and very short names that we use all the time, its important to know how to structure your Google queries. Writing Google queries to quickly find the correct solutions is a skill on its own.
sarnowski··on How Russia Works on Intercepting Messaging Apps
Yes, http://contrastrebellion.com/
sarnowski··on GPG signature verification
You can set up the --sign flag in your local gitconfig.

    git config --global user.signingkey $GPGKEY
    git config --global commit.gpgsign true
In general, since you definitely do not want to upload your key material to GitHub, you won't be able to use the pull request merge button and the new squash button. This means, your pull requests need to be fast-forwardable, else you cannot merge (as this merge would be unsigned). Also, instead of using the squash button, you would need to squash the commits on your local machine and push the newly signed squashed commit again. It comes as a cost but it also leverages the decentralized nature of git: you can do everything locally and sign locally so you do not need to trust someone else.
sarnowski··on GPG signature verification
That is great news! I hope they will also go the next tiny steps soon:

1) as another commenter already pointed out, I would really like to see an "unverified" badge instead of the "verified" to make GPG signing the default; everyone should really be aware that all commit metadata like author and committer are completely voluntary and you can lie as you want.

2) Please, add another merge restriction that only allows commit pushes/merges-to-master with GPG signatures. This allows me to fully verify future git repositories.

sarnowski··on Google nabs Apple as a cloud customer
It's a dedicated bare metal machine for you. The tradeoff with Hetzner is, that it's not expensive Server hardware, so you will encounter hardware problems more often compared to a Dell or HP server.
sarnowski··on OpenBSD vmm/vmd Update [pdf]
I think (please correct if I am wrong), systrace has some race conditions and is not considered completely secure.

"Applications that use clone()-like system calls to share the complete address space between processes may be able to replace system call arguments after they have been evaluated by systrace and escape policy enforcement."

http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man1/...

OpenBSD apps leverage traditional approaches heavily like chroot and privilege separation through different users - even within applications but there is no network separation or similar as in jails or Linux namespaces.

sarnowski··on Ad Blocking Irony
And now, it gets worse. My phone screen is so small compared to desktop - a lot of ads render sites unusable (blocking full screen without possibility to close). Thats why I love my Firefox on Android. Having the possibility of running uBlock on my phone makes surfing so fast and painless. Even if chrome performs and renders better in general, having an adblocker makes that void.
sarnowski··on RAML – RESTful API modeling language
https://github.com/zalando-stups/pierone/blob/master/resourc...

PierOne is a Docker registry in Clojure with S3 backend and OAuth support. I wrote swagger1st[0] which is used there. Swagger supports authorization definitions via scopes. Besides that, you can only define required basic auth or API key usage for authentication but not for authorisation.

Swagger defines various places, where you can add own x-* attributes to fill in your own logic if swagger is not expressive enough.

[0] https://github.com/sarnowski/swagger1st

sarnowski··on Sharding Pinterest: How we scaled our MySQL fleet
Hi, at Zalando, we are scaling all of our core businesses with PostgreSQL. Depending on your dataset, it can be fairly easy to shard your data for a horizontal scale-out (think of independent customer datasets). We have lots of databases that we scale horizontally to much bigger numbers. But, we also developed several tools that makes working with shards mostly transparent. Did not find a better source but one way we use PostgreSQL can be seen in detail in the following slides: http://gotocon.com/berlin-2013/presentation/Why%20Zalando%20...
sarnowski··on German Justice Minister Maas Terminates Federal Prosecutor Range
tl;dr

"netzpolitik.org" was accused of treason for publishing classified documents about plans by Germany's domestic spy agency to expand the surveillance of online communication. A big outcry to protect freedom of press brought a big political affair in which the federal prosecutor* was fired. The minister's own role will still be discussed.

*) The same prosecutor decided to stop investigating the NSA's role in spying at german politicians/companies/people.

← PreviousPage 2 of 5Next →