HNHacker News
TopNewBestAskShowJobs

smashed

1,617 karma · joined December 7, 2015

Email: veilleux.cedric@gmail.com Github: https://github.com/cveilleux
submissionscomments
smashed··on The web server deployment model breaks at hobby scale
That is exactly what I am talking about.

You say caddy. The next person will say nginx-proxy-manager. The next will say DNS challenge let's encrypt behind wireguard VPN. The next will say Traefik. The next will say CloudFlare tunnels.

Everyone has their preferred solution and its always the best and simplest.

smashed··on The web server deployment model breaks at hobby scale
I can relate to the TLS termination issue. It is difficult to provide a self hosted version of a web app with a sensible TLS setup.

The best is almost not to do it at all. Just have a docker image serve http/1.1 and document that a reverse proxy is required to expose the service.

There are simply too many ways to do it and every sys admin/hobbyist has their own preferred way.

For the anonymous and authenticated caching issues the author goes into, I think once again it is useless for self hosting. Just embed a performant web server like nginx for example that is pre configured to serve static files. Use proper headers, and predictable/simple paths. Self-hosted versions are going to be low traffic and just need to work.

Have advanced settings for more control, but keep the default simple and working out of the box with minimal dependencies.

smashed··on NetBSD 11.0
Afaik it has always been that way. I remember 20 years ago as I was dabbling with various bsds, OpenBSD was known for security, FreeBSD for features and netbsd for small, ultra portable kernel.
smashed··on SpaceX wants to launch 100k more Starlink satellites for 100x the bandwidth
Lack of competition is the reason. Not the size of the country. Especially in a suburb.
smashed··on OpenAI Losses Increased Nearly 8X in 2025, with Spending Hitting $34B
If these numbers are right, it's actually not that bad. Cut r&d costs and they are mostly profitable.
smashed··on RFC 10008: The new HTTP Query Method
Use the QUERY method in your http query to query search results. Do not add query parameters.

I think the name is confusing because the term 'query' is already used to refer to http requests in general.

Just the title of the RFC confused me.

smashed··on Quay.io Is Down
this is still ongoing and status remains 'Investigating'.
smashed··on GitHub confirms breach of 3,800 repos via malicious VSCode extension
The data has been stolen by a criminal group. Paying for "restoring" the data does not guarantee they will delete all copies. There is no way of proving they actually did and they have in fact very little incentive to actually delete it.

You have to take their words for it but how can you trust crooks?

smashed··on Restore full BambuNetwork support for Bambu Lab printers
That does not mean I cannot use the ink I want in a tool that I own.

Yes, your ink might be better. Market it that way and make it known. No problem with that. But prevent me from using my tool using DRM and firmware updates? That is customer hostile.

smashed··on Who owns the code Claude Code wrote?
I meant in the sense that the "tool" is an LLM and the "work" was vibe coded.

If vibe coded work is not copyrightable, it cannot be reassigned to the employer and become copyright protected.

smashed··on Who owns the code Claude Code wrote?
The "if you generated the code at work using company tools, it's owned by your employer" affirmation in the article makes no sense to me?

If computer generated code is not copyrightable, ownership cannot be reassigned either.

smashed··on Kimi K2.6: Advancing open-source coding
Openrouter will route to china hosted models when there are US hosted providers of the same model. Is there a setting to set your preference or to blacklist providers like alibaba cloud for example?

I use OpenCode and the openrouter provider. From opencode I only select the model like kimi-2.6 and have no way of selecting which cloud hosting will receive my request.

smashed··on Qwen3.6-35B-A3B on my laptop drew me a better pelican than Claude Opus 4.7
OpenCode?
smashed··on How to turn anything into a router
Lots of "just use X" comments but the article is about showing the bare minimum/how easy the core part of routing actually is.

Also, if you have ever used docker or virtual machines with NAT routing (often the default), you've done exactly the same things.

If you have ever enabled the wifi hotspot on an android phone also, you've done pretty much what the article describes on your phone.

All of these use the same Linux kernel features under the hood. In fact there is a good chance this message traversed more than one Linux soft router to get to your screen.

smashed··on WolfGuard: WireGuard with FIPS 140-3 cryptography
This is addressed on the known issues page [1].

Basically it does not need dedicated hw acceleration because it can use generic vector instructions to reach similar speeds. I wonder how true that is though.

[1]: https://www.wireguard.com/known-limitations/#:~:text=WireGua...

smashed··on Cyber.mil serving file downloads using TLS certificate which expired 3 days ago
An official government source is teaching users to ignore security warnings about expired certificates.

Mistakes happen, some automation failed and the certs did not renew on time, whatever. Does not inspire confidence but we all know it happens.

But then to just instruct users to click through the warning is very poor judgement on top of poor execution.

smashed··on XML Is a Cheap DSL
The problem comes when malicious actors start crafting documents with extra features that should not be parsed, but many software will wrongly parse them because they use the default, full featured parser. Or various combinations of this.

It's a pretty well understood problem and best practices exist, not everyone implements them.

smashed··on A basket of new fruit varieties is coming your way
Depends on where you are maybe? Cortland is still readily available here (Quebec). Hope it stays that way, I'm feeling slightly worried. Seems like the trend of trademarked new apple varieties has not quite caught up here yet as orchards are not interested in replacing tried and true stocks.
smashed··on Show HN: Kula – Lightweight, self-contained Linux server monitoring tool
Yes. Besides AGPL makes a lot of sense for any web based tool, as it keeps the original intent of the GPL.

I don't get the hate/questioning on it either. It's a good balance if you want to prevent straight up cloning/stealing for profit motives while still making it open.

smashed··on Show HN: Kula – Lightweight, self-contained Linux server monitoring tool
Most (all?) temperature monitoring tools on Linux rely on libsensors.

Seems like hardware maintainers never could agree on a standard way of exposing temperature on Linux.

smashed··on Show HN: Kula – Lightweight, self-contained Linux server monitoring tool
Vibe coded netdata clone?
smashed··on GPT-5.4
It's text submitted to APIs. Not real conversations.
smashed··on Bootc and OSTree: Modernizing Linux System Deployment
> the bleeding edge of immutable Linux distros (GNOME OS, KDE Linux)

These are words but they don't make sense.

smashed··on AI adoption and Solow's productivity paradox
Doubtful
smashed··on Anthropic tries to hide Claude's AI actions. Devs hate it
How long until the status display is just an optimized display of what the human wants to see while being fully disconnected from what is actually happening?

Seems like this is the most probable outcome: LLM gets to fix the issues undisrupted while keeping the operator happy.

smashed··on Coding agents have replaced every framework I used
I have some healthy skepticism on this claim though. Maybe, but there will be a point of diminishing returns where these refactors introduce more problems than they solve and just cause more AI spending.

Code is always a liability. More code just means more problems. There has never been a code generating tool that was any good. If you can have a tool generate the code, it means you can write something on a higher level of abstraction that would not need that code to begin with.

AI can be used to write this better quality / higher level code. That's the interesting part to me. Not churning out massive amounts of code, that's a mistake.

smashed··on Netbird – Open Source Zero Trust Networking
That is good news!

The problems we had is users could not reliably tell when they were connected/disconnected, how to initiate the login flow, get network status (why is that service not working, but this other one is?), tell to which router they were connected, etc etc. I know these are big asks, and I suspect a lot of these troubleshooting and status info are probably available in the commercial offering.

That being said I think OpenZiti/NetFoundry is in a different class entirely and any lurkers here should consider it for their use. It's not really the same thing as NetBird or Tailscale.

smashed··on Netbird – Open Source Zero Trust Networking
We evaluated it last August/Sept.

From memory: oAuth login flow (browser based) was only supported on the windows client. For a Zero trust solution, having the only auth truly supported be a permanent JWT/Cert on the machine is doing device authentication, not user authentication, thus completely failing your primary objective.

UX was overall atrocious. Our users could not comprehend it at all. It was deemed that a custom client was required to be made.

The SDK first approach was an overall major plus point, allowing for a full customization to a specific use case.

Don't get me wrong we were overall impressed with the technology and the architecture choices. It's not a finished product, but something that does all the infra and you just need to apply the final veneer on top.

smashed··on Netbird – Open Source Zero Trust Networking
OpenZiti is promising but their desktop and mobile clients are very incomplete.

The feature set varies greatly between platforms.

If you are supporting a single platform (example desktop windows) it could work. Even better if you have the resources to write your own clients using the SDK, like it's meant to be.

smashed··on Netbird – Open Source Zero Trust Networking
We tried netbird but could not get the client to register to a self hosted server. It ignored the setting or failed.

Good chance it was user error on our part.

Most of their documentation is very unclear about what is a cloud offering feature and what is possible using self-hosting. There are features not available on the community edition and you have to be very careful reading their doc.

Just putting it out there so people do not think it's an easy solution. It will require appropriate planning.

I do think its a more promising solution than headscale if you want to self host as it is a complete package, unlike tailscale where you need to modify registry keys to change the cloud URL and headscale is a simplified, non-multi-tenant signaler.

← PreviousPage 2 of 11Next →