HNHacker News
TopNewBestAskShowJobs

throw0101d

8,337 karma · joined January 1, 2023

submissionscomments
throw0101d··on How to Keep a TV Show Relevant for 70 Years
* https://archive.is/https://www.rollingstone.com/tv-movies/tv...

* https://archive.is/XLpVQ

* https://www.pbs.org/show/open-mind/

* https://en.wikipedia.org/wiki/The_Open_Mind_(TV_series)

throw0101d··on A Farewell to ARPs: IPv4 Service on IPv6-Only Networks
Because dual-stack means having to deal with stand up IPv4, which entails more configuration, more address planning, more infra, etc. See perhaps "§5.1 IPv6-only Compared to Dual-Stack":

* https://datatracker.ietf.org/doc/html/draft-ietf-v6ops-6mops

Fewer IPv4 deployed subnets means those addresses can be used where they're 'really' needed instead of being 'wasted'.

throw0101d··on European "age verification" "app" forcing everyone to use Android or iOS
> As a purely tactical measure, we use the same older person (me) for age verification for all family members - zero failures so far and it poisons the well.

Is there a 'break glass' workflow in case you are not available (e.g., health incident)?

throw0101d··on A Farewell to ARPs: IPv4 Service on IPv6-Only Networks
For corporate networks, where you control what devices get onto non-guest VLANs/subnets, you'll have better control over devices that support this new functionality. See for example Google's work on removing IPv4 on corporate networks:

* https://www.youtube.com/watch?v=UTRsi6mbAWM

Even in organizations where IT cannot control devices, like universities which are largely student-BYOD, IPv6 take-up can reach 80%:

* https://www.youtube.com/watch?v=2B-liebzcOMmkm&t=10m

"Obviously" in what way?

throw0101d··on A Farewell to ARPs: IPv4 Service on IPv6-Only Networks
ARP is not an issue at smaller scales, but at larger ones it can cause problems. Reducing the L2 broadcast 'blast radius' is one of the touted benefits of EVPN (which use may be worth considering once you get above ~20 switches):

* https://www.youtube.com/watch?v=W_z37Rq7qgY

throw0101d··on Vint Cerf, “father of the Internet”, is retiring
> Having 1.2.3.4 in v4 doesn't make ::ffff:1.2.3.4 or 2002:1.2.3.4 route to me in v6. It would route to a relay that translates/resends to v4 1.2.3.4, then it reaches my router over v4. Nobody can use that address over pure v6.*

Sure they could: if your ISP owns 1.2.0.0/16, it could advertise 2002:1.2::/24 via BGP. So if someone on the other side of the planet wants to send something to 2002:1.2.3.4::/48 they would know where to send it.

And just like how something sent to 1.2.0.0/16 globally is then handled internally via IS-IS/OSPF/etc so your ISP knows how to send something for 1.2.3.4 to your CPE, your ISP would know how to handle 2002:1.2.3.4::/48 to get it to your CPE.

Routers are told to map traffic for (::ffff:)a.b.c.d to 2002:a.b.c.d::/48. If you're sending from w.x.y.z, you can put the source address as from something in 2002:w.x.y.z::/48.

It has nothing to do with "clean slate" or not. There are two immovable facts:

"""

IPv4 implementations, in 1994 and still today, have the 32-bit address format built into their code. Whether you expand the address size to 33, 64 or 128 bits, all IPv4 implementations will discard the packets. So it's a matter of mathematical and physical fact that to expand the address size, you must change the protocol, and that means two things immediately:

1. You have to change the version number.

2. You have to add new code to handle the new version.

""

* https://github.com/becarpenter/book6/blob/main/01.%20Introdu...

And this also includes 'accessory protocols': DNS A records are fixed at 32-bits, so if you want to use hostname with IPng you needed to upgrade the DNS infrastructure, including APIs to say "give me A and Ang", and then you perhaps need fallback mechanisms, in which case you're at:

* https://en.wikipedia.org/wiki/Happy_Eyeballs

Any IPng protocol, including 'just' adding bits, regardless of how you want to hand wave it as being 'just' an extension of IPv4 will be in same situation because you can't fit >32-bits in the 32-bits of the original code. You're rolling out new code in a rolling fashion, just like had to be done with IPv6.

throw0101d··on DOGE is done. What happened to its records?
> Complex systems don't pop out of thin air.

You've obviously never been part of an SAP/ERP implementation. /s

throw0101d··on DOGE is done. What happened to its records?
Movements/causes that use violence are less successful (23%) than those that use non-violence (45%):

* https://www.journalofdemocracy.org/articles/the-future-of-no...

* https://global.oup.com/academic/product/civil-resistance-978...

At least per historical surveys (600 movements since 1900).

throw0101d··on DOGE is done. What happened to its records?
Perhaps a GAO look-see is needed?

* https://en.wikipedia.org/wiki/United_States_Government_Accou...

May be worth noting/reminding of the 17 inspectors general that were fired on the first Friday (2025-01-24) of Trump 2.0 administration:

* https://en.wikipedia.org/wiki/2025_dismissals_of_U.S._inspec...

throw0101d··on Vint Cerf, “father of the Internet”, is retiring
> If I have 1.2.3.4 in ipv4 world, I want 1.2.3.4 in ipv6 world instead of a random new address.

::ffff:1.2.3.4

* https://en.wikipedia.org/wiki/IPv6#IPv4-mapped_IPv6_addresse...

By having 1.2.3.4 you also got 2002:1.2.3.4::/48 'for free' (per 6to4). So if you want to send things to 1.2.3.4 / ::ffff:1.2.3.4, you tell your router that it's available via 2002:1.2.3.4::/48.

Any idea that you think is clever and to 'just' do X and/or Y for IPng, and would work, has probably already been thought of and attempted in the last 20-30.

throw0101d··on An Infuriating Goodbye to Photoshop
> It's also entirely free with no gotchas.

How is this sustainable for a for-profit entity? How do they pay the bills/developers?

throw0101d··on Vint Cerf, “father of the Internet”, is retiring
> You don't actually own the IPv4-mapped-V6 address, as in packets don't get routed to you, they go to a relay that was notoriously flaky.

6to4 is exactly ownership:

> For any 32-bit global IPv4 address that is assigned to a host, a 48-bit 6to4 IPv6 prefix can be constructed for use by that host (and if applicable the network behind it) by appending the IPv4 address to 2002::/16.

> For example, the global IPv4 address 192.0.2.4 has the corresponding 6to4 prefix 2002:c000:0204::/48. This gives a prefix length of 48 bits, which leaves room for a 16-bit subnet field and 64 bit host addresses within the subnets.

* https://en.wikipedia.org/wiki/6to4

The relaying is a necessity:

              OLD    DUAL   NEW     
            ----------------------
        OLD |  32  |  32  |  XX  |      
            |------|------|------|
       DUAL |  32  |  64  |  64  |
            |------|------|------|
        NEW |  XX  |  64  |  64  |
            ----------------------
* https://github.com/becarpenter/book6/blob/main/01.%20Introdu...

There's no way around it: a non-IPng-having node will have to go through a translation box of some kind.

throw0101d··on Vint Cerf, “father of the Internet”, is retiring
> It's a shame TUBA (CLNP + TCP) failed.

See "The Recommendation for the IP Next Generation Protocol", §8.3 TUBA Reviews:

* https://datatracker.ietf.org/doc/html/rfc1752

The document explains why SIPP was chosen (with the tweak of 128-bit addresses instead of 64).

throw0101d··on Restarting Germany's Reactors: Viability and Outlook [pdf]
See also perhaps "Restarting Germany’s Reactors: Feasibility and Schedule" from May 2025:

> By 2028, three reactors could be restarted, adding 4 GW of capacity. If decommissioning stops now and rehiring begins, Brokdorf could resume operation as early as the end of 2025. With swift legislative action and proper planning, Emsland and Grohnde can be operational by the end of 2028. Six additional reactors could all be restarted by the end of 2032.

* https://www.radiantenergygroup.com/reports/restarting-german...

throw0101d··on SpaceX wants to launch 100k more Starlink satellites for 100x the bandwidth
> You'll be sad to know there's another mf trying to put a mirror to reflect sunlight near twilight

This has been approved:

* https://ca.pcmag.com/networking/16760/fcc-approves-reflect-o...

* https://news.ycombinator.com/item?id=48866452

throw0101d··on TLS certificates for internal services done right
> What you describe is a user and resolver configuration problem.

That won't prevent me from getting a ticket saying "the network is down".

throw0101d··on TLS certificates for internal services done right
If you generally had "search example.com" in you resolv.conf, and were in the habit of having "web01.dev" in places, behaviour may have changed if you were happen to be on a machine that had the "search" line missing (or something else).
throw0101d··on TLS certificates for internal services done right
> He’s using it as a subdomain.

Lots of folks were using "dev" as a sub-domain which was fine until ICANN decide to give Google a TLD:

* https://en.wikipedia.org/wiki/.dev

So if you generally had "search example.com" in you resolv.conf, and were in the habit of having "web01.dev" in places, behaviour may have changed if you were suddenly on a machine that had the "search" line missing (or something else).

throw0101d··on TLS certificates for internal services done right
> You need a DNS provider which supports API calls (I use DNSimple) but the core is all very straightforward.

Library/CLI that speaks the API of several dozen DNS providers so you don't have to re-invent the wheel:

* https://github.com/dns-lexicon/dns-lexicon

throw0101d··on TLS certificates for internal services done right
Just use IPv6: no "internal" (10/8) or "external" address, just an address. ;)
throw0101d··on TLS certificates for internal services done right
> Then use a wildcard so none of leaks into cert transparency logs

You now also have to build infrastructure to distribute the wildcard from (presumably) central place where you generate it to all the different places where it is desired.

And hope the wildcard's private key does not leak from one of myriad of places it now lives.

throw0101d··on TLS certificates for internal services done right
> I use the acme dns-1 challenge on my public domain.

See also perhaps DNS aliasing in case you are not able to dynamically update your 'primary' domain, but can update a secondary or sub-domain:

* https://github.com/acmesh-official/acme.sh/wiki/DNS-alias-mo...

So if "example.com" is control by Corporate IT, and they don't want 'random' folks fiddling with it, then you can create a "dnsauth.example.com" and point the dns-1 challenge record from "…foo.example.com" to "foo.dnsauth.example.com" (or a completely different domain, like "…example.net").

There are DNS servers written strictly focused on this use case:

* https://github.com/acme-dns/acme-dns

Also code that handles a bunch of DNS provider APIs so you don't have to roll your own for ACME client hooks:

* https://github.com/dns-lexicon/dns-lexicon

throw0101d··on Every new car sold in the European Union must include a driver monitoring camera
> Then these features are not for you.

Which could (maybe) be fine if they could be permanently turned off (and not reset-to-on on every startup). Heck, even if it was a dealership-only change it would be something.

See recent driving 4 answers video on the silliness of some of these features:

* https://www.youtube.com/watch?v=f-S76WEl25k

An alert that causes you to look down every time to enter an intersection/roundabout when you most need to be looking up? Warnings when you put on sunglasses?

throw0101d··on Reform UK leader 'in real trouble' against Count Binface
"Can you win?"

"Probably not, but then my job is to celebrate and defend the wonders of British democracy. And look at this: the fact that you're interviewing me, on the Today program, because all the other parties are not standing [up candidates] says more about them than it does about me."

throw0101d··on NSA and IETF: Fairness
My general point is that the category or track of an RFC may mean different things to different people (assuming they're even aware of them at all).
throw0101d··on Every new car sold in the European Union must include a driver monitoring camera
I have a manual 2003 Golf TDI (purchased in 2003; has a tape deck!) that's slowly rusting, and I'm not looking forward to when I have to replace it.

I don't have a garage/drive way, and so have to park on the street, which makes me leans towards another short [1] vehicle: currently thinking about VW Golf, Mazda 3, Mazda CX-30, Kia Niro.

From what I've seen from almost all cars, lots more screens and lots fewer buttons.

[1] https://www.carsized.com/en/

throw0101d··on NSA and IETF: Fairness
I have gotten flack for giving ULA+NPTv6 as a possible solution to an IPv6 multi-homing issue because the RFC that describes it was 'only' "Experimental":

* https://datatracker.ietf.org/doc/html/rfc6296

When I pointed out that the NAT(44) RFC (1631/3022) was 'only' "Informational" I got radio silence:

* https://datatracker.ietf.org/doc/html/rfc1631

throw0101d··on NSA and IETF: Fairness
> “People are already doing it, so we might as well rubber-stamp it even if it’s not great” introduces problems of its own: people will perceive that rubber-stamping as validating it, and now they’ll use it even more, where perhaps if you held back, they wouldn’t.

The GOST cipher, which is Russia's AES equivalent, is also in an RFC:

* https://datatracker.ietf.org/doc/html/rfc9189

* https://en.wikipedia.org/wiki/GOST_(block_cipher)

Is the IETF validating its use?

The GOST document is categorized in the same way as the one currently being debated/discussed: Informational. It also has "N" under the "Recommended" column (like ML-KEM-only will have):

* https://www.iana.org/assignments/tls-parameters/tls-paramete...

throw0101d··on NSA and IETF: Fairness
> https://www.iana.org/assignments/tls-parameters/tls-paramete...

Further the draft that this is all about does not make a recommendation for its use. The currently IETF-recommended TLS algorithms are: X25519MLKEM768, x448, x25519, secp384r1, secp256r1.

As noted by someone on the IETF list [1] there are already ML-KEM-only implementations in various libraries, so if we want interoperability then it's best to have a standard document. No one is forcing anyone to use this algorithm, and it's not even 'officially' recommended (per above).

[1] https://mailarchive.ietf.org/arch/msg/tls/SXo4iVmp0ng_vi57ce...

throw0101d··on Trump Financial Disclosure Shows 21,000 Trades in 2025
While there are 365 days in a (non-leap) year, live trading days are fewer:

> Trump averaged 85 trades per market day, an analysis of the report shows. Just 10 days accounted for about a quarter of all trades executed in 2025. Many of those came during heightened volatility on Wall Street after Trump had already announced policy changes.

← PreviousPage 7 of 34Next →