HNHacker News
TopNewBestAskShowJobs

sickmate

144 karma · joined March 29, 2014

submissionscomments
sickmate··on Elasticsearch is open source, again
>The issue that Elastic had is that their entire business model was offering a managed elasticsearch solution. Amazon then created their own offering of the same thing

Amazon first offered Elasticsearch as a managed service in 2015. Elastic began offering managed services in 2018.

https://en.wikipedia.org/wiki/Elasticsearch#Managed_services

sickmate··on Retrieving 1TB of data from a faulty drive with the help of woodworking tools
Generally safe operating temperatures are between 0 and 70 degrees celsiuis.

e.g. Samsung https://download.semiconductor.samsung.com/resources/data-sh...

sickmate··on Enhancements to the Kagi Search Experience
This is not correct. ISPs cannot see the actual URL being requested. Your DNS provider can see the hostname. The ISP may be able to see the hostname unless encrypted SNI is in place. The ISP can see the IP address you are connecting to.
sickmate··on AWS Creates New Policy-Based Access Control Language Cedar
You can do this with Localstack, however it's gated behind their pro service.

https://docs.localstack.cloud/user-guide/aws/iam/#explainabl...

sickmate··on CircleCI security alert: Rotate any secrets stored in CircleCI
https://twitter.com/sanitybit/status/1610829345676996609

>I've been investigating the use of a @ThinkstCanary AWS token that was improperly accessed on December 27th and suspected as much.

sickmate··on The death of Rackspace’s ‘fanatical support’
It might have been called something else like cloud hosting, but it was definitely equivalent to a shared hosting model. We didn't manage the web servers, no root access etc and the database server was shared between 300+ of their customers.
sickmate··on The death of Rackspace’s ‘fanatical support’
>Highly trained people handled the company’s incoming telephone and online inquiries

Not sure I can agree with this. Almost a decade ago we had some shared hosting accounts at Rackspace for some very legacy clients (ones that even accounting had forgotten about and not billed them for years). We had an issue with accessing one of the databases to export for handover, and so I got in touch with their online support. They gave me full admin access to their database server which had several hundred other clients on there. I could also see the historical metrics for the server which were interesting. I told them immediately but it took them almost a day to revoke my access.

sickmate··on Bettercap – Swiss Army Knife for 802.11, BLE, IPv4 and IPv6 networks
https://archive.ph/sh7dE
sickmate··on Writing by hand is still the best way to retain information
Onyx Boox tablets can convert your handwritten notes to text, and export them as TXT files. I'm not certain but the export can probably be automated.

At work I use the handwriting keyboard input to write directly into Confluence notes.

sickmate··on Sonic: Fast, lightweight and schema-less search backend
AWS has a compatibility mode that allows your cluster to report its version as 7.10.
sickmate··on Tether Withdrawals Top $10B
I've never shorted or taken out crypto loans, but you could theoretically:

- Take out a loan of USDT, using a stablecoin you trust as collateral

- Immediately trade all USDT into your stablecoin

- If the USDT price crashes, buy it up to repay the loan.

e.g. Binance lets you borrow 800k USDT with 1.23m collateral. Over 180 days, interest paid would be 36k.

Say USDT crashes and you repay your loan at 10c/USDT - you would pay at most 84k to settle the loan. You then end up with 1.94m, a 58% return on investment.

It's probably not that simple however.

sickmate··on Former U.S. president Donald Trump launches 'TRUTH' social media platform
It doesn't exist yet.
sickmate··on Lithuania says throw away Chinese phones due to censorship concerns
https://www.synopsys.com/blogs/software-security/cve-2020-79...
sickmate··on Tether reserves backed by 2.9% cash
As a comparison, USDC reserves are 100% backed by US dollars held in custody accounts, currently 9.3B.

https://www.centre.io/hubfs/pdfs/attestation/grant-thorton_c...

sickmate··on Baserow.io – Self-hosted Airtable alternative
A perfect use case for Number.prototype.toLocaleString.

https://developer.mozilla.org/en-US/docs/Web/JavaScript/Refe...

sickmate··on Yet another macOS privacy protections bypass
You could also open restricted system preference panes by searching for a relevant term in Spotlight and going to a User Guide article. Often they would have a link to open the preference pane which would bypass any restrictions.
sickmate··on You can bypass YouTube ads by adding a dot after the domain
You could add this repository to get the latest github releases: https://archive.newpipe.net/fdroid/repo/

Some ongoing discussion on this issue thread here. https://github.com/TeamNewPipe/NewPipe/issues/1981

sickmate··on Web Vitals: essential metrics for a healthy site
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-...

>If a request goes through multiple proxies, the IP addresses of each successive proxy is listed. This means, the right-most IP address is the IP address of the most recent proxy and the left-most IP address is the IP address of the originating client.

sickmate··on Google Gives Feds 1,500 Phone Locations in Unprecedented ‘Geofence’ Search
https://myaccount.google.com/activitycontrols/location
sickmate··on Apple has pushed a silent Mac update to remove hidden Zoom web server
This blog post[1] has a good explanation of ConfigData updates. The flag would appear to force the install of new Gatekeeper configuration updates.

>To help distinguish Gatekeeper and XProtect updates from other updates in the software update feed, Apple marks them as being ConfigData updates.

>Marking these updates as ConfigData cues the App Store to not display these as available software updates in the App Store’s list of software updates. These updates are meant to be under Apple’s control and to be as invisible as possible.

[1] https://derflounder.wordpress.com/2014/12/27/managing-automa...

sickmate··on Google's Captcha in Firefox vs. in Chrome
My power company (the sole government-run provider in my area) now has reCAPTCHA on their payment form.
sickmate··on Google to developers: We take down your extension because we can
I'd guess that the warning period was set to 168 minutes (2hrs 48 minutes) instead of 168 hours (7 days).
sickmate··on Amazon EKS – Highly available and scalable Kubernetes service
>Common things like rolling updates were a 3-step operation (or they were for us), and node replacement was a pain

I had the same experience until I created an ECS stack using CloudFormation, which made it much easier to manage.

sickmate··on Breaking a large AWS spend into understandable pieces
The Cost Explorer now has Reserved Instance utilization and coverage reports which are quite useful.
sickmate··on Show HN: Folio for Mac – Simple version control app for designers based on Git
In their blog post on medium[1], they mention that it is built on git. webdesignledger.com[2] claims that it supports full version control.

[1] https://medium.com/@FolioForMac/building-a-better-time-machi...

[2] http://webdesignledger.com/folio-version-control

sickmate··on Little Snitch for phone?
For Android: XPrivacy will alert you when apps attempt any type of network access and allows you to whitelist or blacklist specific hostnames or wildcards.

That isn't it's main/only function though. From their github page: "XPrivacy can prevent applications from leaking privacy-sensitive data by restricting the categories of data an application can access."

It is a module for the Xposed framework, and requires root.

http://repo.xposed.info/module/biz.bokhorst.xprivacy

https://github.com/M66B/XPrivacy

sickmate··on UI Performance Decline – OS X Tiger to Yosemite [video]
This is one of the clear areas where performance is nowhere near previous versions. One solution is to switch to the "Picture-in-picture" zoom style under the Accessibility preferences.
sickmate··on OS X 10.9.4 Update Broken?
It's not completely fixed. My guess is that only certain Airport Express cards are affected, as I have some machines that fail to reconnect and others that are fine.
sickmate··on Sublime Text Development Status
To be fair, ST3 is pretty stable for everyday use.
sickmate··on Australian government likely to standardise on Drupal
With regards to Joomla, it really is terrible when it comes to security. Versions 1.5-2.5 have major vulnerabilities that allows anyone to create an admin user unless you disable account registration. Popular plugins like TinyMCE allowed unauthorised users to upload arbitrary files with a specially crafted request.

There are also plenty of bots that scan for vulnerable Joomla installs as they do with Wordpress.