HNHacker News
TopNewBestAskShowJobs

thresh

578 karma · joined November 22, 2012

submissionscomments
thresh··on Show HN: Gnomecast – A Linux Chromecast GUI with transcoding and subtitles
Yeah, there is no subtitles support for now. It will be supported in the next release.
thresh··on Show HN: Gnomecast – A Linux Chromecast GUI with transcoding and subtitles
No, VLC does the transcoding on the fly, and that's why it's not very easy.
thresh··on Chrome 68 will mark all HTTP sites as “not secure”
Welcome to the world where ad company tells you which sites you should look at.
thresh··on VLC 3.0 Media Player release
It's not released yet - and the article in question links to our development server.

I've disabled all access to nightlies for win32/win64/mac for now since those binaries will not get update checks/will not be updated in a sane fashion. You should not be using them.

We're still working on a VLC 3.0 release, and will announce it when it's ready and our mirrors pick up all the binaries. Please have patience.

thresh··on The European Parliament has approved budget for VLC bug bounty program
mpv is dead
thresh··on HAProxy 1.8
> AFAIK, this is true of nginx also and from what I've heard in the past, they see no reason to change it.

http2 backends support is on the roadmap https://trac.nginx.org/nginx/roadmap - so you can expect it to be implemented.

thresh··on ACME Support in Apache HTTP Server Project
Are there any other CAs that support ACME?

Is ACME an Internet standard yet?

Is that turning into monoculture?

thresh··on Disabling the Intel Management Engine
Does that ruin the BMC/iLo/IPMI?
thresh··on I recommend against using biometric identification
I don't understand why what's essentially a login (fingerprint, face, dna) is considered a password. It simply isnt.

And I don't understand why I cant (on Android 7) combine fingerprint and then PIN/Pattern to unlock my device. It's mind boggling and completely stupid.

thresh··on How to find a trustworthy VPN service
To overcome nation-wide blacklists.
thresh··on Russia requesting to review source code of Western companies’ security products
Does that also happen with, say, German or French governments? Or US government? What about the Chinese?

Do they not ask to review source code of the tools they buy and use?

thresh··on Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
You can use snaps, but they are currently broken due to build issues.
thresh··on Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
Clearly VLC should be rewritten in Rust.
thresh··on Nginx 1.13 released with TLS 1.3 support
Is ACME an Internet standard yet? Are there any TLS CA that support it, other than LetsEncrypt?
thresh··on LinuxKit: A Toolkit for Building Secure, Lean and Portable Linux Subsystems
So will this replace alpine which is for some reason much loved in docker world?
thresh··on Nginx 1.12.0 stable
It's not like nginx-the-company and nginx-the-opensource-project are different people. It's not that "some company" just overtook the project and now is milking the users.
thresh··on Gitlab 9.0
You can actually distinguish between those on a single port using http://nginx.org/r/ssl_preread and some sslh-like checks using e.g. njs.
thresh··on An nginx.conf for 2017: HTTP/2, IPV6, HTML5 SSE, load balancing and more.
Yep - the warning clause in the documentation is there because of those issues.

thanks!

thresh··on An nginx.conf for 2017: HTTP/2, IPV6, HTML5 SSE, load balancing and more.
There is a problem with this change: https://github.com/certsimple/nginx-http2-load-balancing-con...

proxy_set_header in html5-sse.conf will discard all other proxy_set_header included in proxy.conf a level above: "These directives are inherited from the previous level if and only if there are no proxy_set_header directives defined on the current level", http://nginx.org/r/proxy_set_header

thresh··on An nginx.conf for 2017: HTTP/2, IPV6, HTML5 SSE, load balancing and more.
2a/ ok, I misread what was the intention, maybe it's a good idea then

3/ it's not about "better maintained", it's about trusting the internet on sensitive data, which you should never do, because dns is easily spoofed and nginx resolver was not written to operate in a hostile environment. if you don't have a local caching resolver on your machine (which you should), even trusting your cloud provider dns is better than trusting goog one. nginx documentation even says " To prevent DNS spoofing, it is recommended configuring DNS servers in a properly secured trusted local network. " on http://nginx.org/r/resolver

thresh··on An nginx.conf for 2017: HTTP/2, IPV6, HTML5 SSE, load balancing and more.
the configuration they provide is wrong on many things

1/ it says "An nginx config for your first million users",

but: worker_connections 768;

2/ html5-sse.conf:

proxy_buffering off;

bad idea for a loaded server / backend

proxy_cache off;

will enable proxy_cache, which is not defined anywhere, so this will actually fail to validate - and proxy_cache is already disabled when you're doing proxy_buffering off;

3/ https.conf:

resolver 8.8.8.8 8.8.4.4 valid=300s;

bad idea to trust anything but a local resolver, why do you trust internet to tell you IP addresses where you will go for ssl stapling info?

thresh··on IPv6 Support for AWS Extended to 15 Regions
And of course while it's Canonical's fault for not having a v6 dhcp, the similar problem affects Amazon Linux instances: repo.eu-central-1.amazonaws.com is ipv4-only so yum makecache fails.
thresh··on IPv6 Support for AWS Extended to 15 Regions
Fun fact: Ubuntu 16.04 image offered on Amazon does not support IPv6 out of the box.

Even when you log in via ipv4, and make relevant networking changes (basically enabled DHCP for v6), it will still fail to apt-get update, because eu-central-1.ec2.archive.ubuntu.com is ipv4-only.

Sad.

thresh··on Make Firefox support moz://a
I'm not picking, I'm just looking at the stats I have. I've actually have it graphed on http://thre.sh/stuff/browsers-stats-videolan.org.png now.
thresh··on Make Firefox support moz://a
Yeah, that will totally solve Mozilla's now so slow fading into irrelevance.

VideoLAN.org website stats tell me that Firefox hits percentage dropped from 26.3% through Jan 2016 to 21.2% through Jan 2017.

Of course this is not a 100% reliable measure, but stats usually don't lie about that.

thresh··on DMARC Secured Email Identities but Broke Mailing Lists
DMARC sucks.

Source: I run two big mailman installations.

thresh··on 64-bit Orange Pi – A Quad Core Computer for $20
Can it run stock vanilla mainline kernel?

It really sucks to be stuck with ancient 3.14 kernel on quite powerful things like Odroid C2.

thresh··on MacBook Pro
Ah, I love the "low end" of $1500 per machine.
thresh··on NAXSI – Open-Source, High Performance, Low Rules Maintenance WAF for Nginx
Why is that sad? Modsecurity sources are freely available on github - and nginx.com emails are seen in the commits.
thresh··on Docker 1.11: The first OCI-compliant runtime, built on containerd
You can use nginx to have zero-time redeployments without gross hacks haproxy requires to do that.
← PreviousPage 2 of 3Next →