HNHacker News
TopNewBestAskShowJobs

time4tea

606 karma · joined June 28, 2013

submissionscomments
time4tea··on Vinyl Cache and Varnish Cache
I initially read this as "we" being "Varnish Software", but maybe that was wrong.
time4tea··on Vinyl Cache and Varnish Cache
Thanks for the info, but I'm a bit confused, sorry.

The reason for hitch was that tls and caching are a different concern, and the current recommendation is to use haproxy, which also isnt integrated into varnish/vinyl.

But you say that the reason to migrate off hitch is that its not integrated?

But what happend to separation of concerns, then? Is the plan to integrate tls termination into vinyl? Is this a change of policy/outlook?

Thanks!

time4tea··on Vinyl Cache and Varnish Cache
Thanks for this. You dont mention hitch though. Is that now deprecated/discouraged?

It hasn't seen much action in a while, but maybe thats cos it works?

time4tea··on Vinyl Cache and Varnish Cache
just use the tool that does the job.

TLS in -> hitch or caddy Cache -> varnish/vinyl TLS out -> haproxy

Connect them up with Unix sockets, if you like.

time4tea··on Revision Demoparty 2026: Razor1911 [video]
One of the most uplifting things I've seen for a long while.

Amazing artistry and skills.

time4tea··on One Method Was Using 71% of CPU. Here's the Flame Graph
Quite hard take an article seriously with this line in it:

int hour = order.timestamp().atZone(ZoneId.systemDefault()).getHour();

(Because... does the hour you did the thing change according to where you run the code? no - it should use either the location of the trader, or the exchange, neither of which are related to where the code runs)

Using strings as different kinds ids is kind of an anti pattern too. They are IDs in different domains. They can be a strongly-typed long (or other type, uuid, snowflake, whatever). No string concatenation required. This then carries on to the regular expressions - if you use strong types, you then don't need to validate that the stringly-typed stuff you used earlier, and hopefully didn't permute some function arguments somewhere is actually valid.. it just is)

The example shows rentrantlock for a single entire method.. there's no huge advantage over synchronised in this case.. maybe there's other code thats not shown.

Using double for prices & costs? You really need to be much more sure about what number of money you really have. I cant pay you $2.19999999999999.

If you have a cpu-bound algorithm, running vastly more threads than cpus isn't ever going to help, and if you really have 200 cores, then you'll want to modify your algorithm to remove synchronization... thanks Amdahl!

There may be some suggestions in the article, but it feels forced.

edit: added details on timezones, validation & threads.

time4tea··on LLM scraper bots are overloading acme.com's HTTPS server
You can block CN, RU, SG, KR, and the level 3 from "ipsum" and the numbers go down a lot.

People might not know about ipset - dont use individual rules in iptables.

Nginx can reject easily based on country.

geoip2 /etc/GeoLite2-Country.mmdb { $geoip2_metadata_country_build metadata build_epoch; $geoip2_data_country_code default=Unknown source=$remote_addr country iso_code; }

  map $geoip2_data_country_code $allowed_country {
    default yes;
    KR no;
    SG no;
    CN no;
    RU no;
 }
server { .... if ($allowed_country = no) { return 444; } }
time4tea··on NYC ends criminal summonses for cyclists, e-bike riders
Its because, although sometimes a delivery cyclist might be annoying, the reality is that there are almost zero KSI due to cyclist in any country worldwide. The rules designed for SUV dont actually make sense for human-scale transport.
time4tea··on Lazy JWT Key Rotation in .NET: Redis-Powered JWKS That Just Works
Its a spectrum, like all things.

It crosses from everyone has the keys like in this example, to centralising a signing service using just software, or using something like KMS or CloudHSM, or YubiHSM, or going big and getting a HA Luna (or similar) HSM setup.

time4tea··on Lazy JWT Key Rotation in .NET: Redis-Powered JWKS That Just Works
Private key material should not be kept in the clear anywhere, ideally. This includes on your dev machine, serialised in a store, in the heap of your process, anywhere. Of course, it depends on your threat environment, but the article did mention pci-dss. If you put it in redis, then anyone that has access (internal baddies exist too!) can steal the key and sign something. Its hard to repudiate that.
time4tea··on Lazy JWT Key Rotation in .NET: Redis-Powered JWKS That Just Works
From article:

Private key redis key

    public static string PrivateKey(string kid) => $"{Root}:jwks:private:{kid}"; // full private material (short life)
time4tea··on Lazy JWT Key Rotation in .NET: Redis-Powered JWKS That Just Works
The key material is in redis? Seems odd. Should be in fips 140 hsm? Else key can be stolen easy.

Maybe missed something.

time4tea··on Dbslice: Extract a slice of your production database to reproduce bugs
Copying production data to dev is widely regarded as being a bit of a bad idea, if the data contains any information that relates to a person or real life entity.

Uncontrolled access, inability to comply with "right to be forgotten" legislation, visibility of personal information, including purchases, physical locations, etc etc.

Of course sales, trading, inventory, etc data, even with no customer info is still valuable.

Attempts to anonymise are often incomplete, with various techniques to de-anonymise available.

Database separation, designed to make sure that certain things stay in different domains and cant be combined, also falls apart if you have both the databases on your laptop.

Of course, any threat actor will be happy that prod data is available in dev environments, as security is often much lower in dev environments.

Caveat emptor.

time4tea··on C64 Copy Protection
Can confirm tape-to-tape worked 100%... it got a bit less reliable after copy-of-copy-of-copy though.
time4tea··on What does " 2>&1 " mean?
Useless use of cat error/award

But also | isnt a redirection, it takes stdout and pipes it to another program.

So, if you want stderr to go to stdout, so you can pipe it, you need to do it in order.

bob 2>&1 | prog

You usually dont want to do this though.

time4tea··on New site design and philosophy for Stack Overflow
Did anyone click through?

That is a horrible website! Wow

time4tea··on Sewage Spill in the Potomac River
Sewage Map is great.

You can get a great picture of the scale of the problem in the UK at

https://top-of-the-poops.org

It shows live and historic sewage dumps for the last 5 years for constituencies, beaches & shellfish areas...

time4tea··on Trunk Based Development
TBD - its pretty great... aligned also with continuous deployment:

It allows you to get feedback from customers very fast.

It allows you to improve the software very fast.

It allows you to react to the feedback you just got very fast.

Yes, its tricky! You need fast builds, that give you actionable feedback on whether you did a whoopsie.

Yes, it works for all sorts of things: regulated industries, incl finance, embedded systems, apps, websites, ...

Yes, you do need to rethink how changes happen, to look for ways to make that big change into multiple or even many smaller changes, this often has lots of unanticipated benefits.

Yes, it scales to very large deployments and quite large teams.

time4tea··on Ask HN: How do you find the "why" behind old code decisions?
Its what commit messages are for!

The diff tells the 'what' - no point in writing 'added method bob()'

The message tells the why.

You can bet that over time, the jiras, the issues and the confluence, slack, o365, will all have been deleted, "upgraded" or whatever, and all you have is what's in the repo.

Using in-repo ADR, and in-repo 'what's missing, what's next' files are also useful, because they co-evolve with the code.

time4tea··on Medium Was Built for an Internet That No Longer Exists
Medium is mid.
time4tea··on How much of my observability data is waste?
A lot of "regular expressions" are just text searches, or can be, and then you can use aho-corasick - which is implemented in many languages, and check a few regular expressions for the ones that really are.

Sure, nor perfect, but works surprisingly well.

time4tea··on Dev-owned testing: Why it fails in practice and succeeds in theory
The abstract says it really:

"It was clearly a top-down decision"

Many many things that are imposed like this will fail.

Its not willful non-compliance even, its just that its hard for people to do things differently, while still being the same people in the same teams, making the same products, with the same timelines...

Context is key here, lots of people see a thing that works well and think they can copy the activities of the successful team, without realising they need to align the mindset.. and the activities will follow. The activities might be different, and thats OK! In a different context, you'd expect that.

I'd argue that in most contexts you don't need a QA team at all, and if you do have one, then it will look a lot different to what you might think. For example, it would be put after a release, not before it.. QA teams are too slow to deal with 2000+ releases a year - not their fault, they are human.. need to reframe the value statement.

time4tea··on Amiga Desktops Worth Seeing
Nice icon for Ced, aka Cygnus Ed, I'm thinking. Such a great and fast editor..
time4tea··on Why did we use leaded petrol for so long? (2017)
Same guy invented CFCs. What a **!

https://www.bbc.co.uk/sounds/play/p0m89fqk?partner=uk.co.bbc...

Cautionary Tales: The Inventor who almost ended the world. BBC Sounds Podcasts

Edit: add title Edit: typo

time4tea··on How I block all online ads
There is also py-hole

https://github.com/time4tea-net/py-hole/

You can run it on your openwrt router - see readme. Its just a python script that updates a file that dnsmasq uses. No funny business, you are in charge of everything.

Disclaimer: author of said script.

time4tea··on The C++ standard for the F-35 Fighter Jet [video]
The point really was that the unused method parameter should in almost all cases be removed, not that some trick should be used to make it seem used, and this is the wrong trick!
time4tea··on The C++ standard for the F-35 Fighter Jet [video]
a = a; // misra

Actual code i have seen with my own eyes. (Not in F-35 code)

Its a way to avoid removing an unused parameter from a method. Unused parameters are disallowed, but this is fine?

I am sceptical that these coding standards make for good code!

time4tea··on RAM is so expensive, Samsung won't even sell it to Samsung
Dec 2023:

96GB (2x48) DDR5 5x00 £260 today £1050

128GB (4x32 ) DDR5 5x00 £350 today £1500

Wut?

Edit: formatting

time4tea··on Confessions of a Software Developer: No More Self-Censorship
100% test coverage is a bit of a distraction.

You can get to 100% by having tests that run the code, but have no assertions.

You can run tests that test unimportant code just as much as super critical code. There's no differential between the two. Of course super critical code should have a number of different tests that exercise it. Its not the same as testing every path, its testing different inputs and checking that you get the right results. Also see property testing.

Chasing 100% is like any metric that becomes a goal, it perverts the metric, and moves the meaning away from the metric.

Why is that? Well, we dont really want tests at all, if only people could write perfect software first time, we wouldn't need them. Stupid people!

What we want are reliable systems! So we use feedback loops between deployed systems and code to help us discover those places where we need more tests, or a different type of testing, and then we do that.

Of course if your test coverage is 0%, thats probably bad, but 100% is a non-goal.

You'll also find that if there are no tests in a system, when you need to add them, its really hard, cos its not designed in a way that makes it testable. So maybe the TDDs will help you! You end up with a system that you have high confidence in, and also is testable.. so when you find something that doesn't work how you thought, its easy to add that test right in there.

time4tea··on All your data belongs to us: the rise of Palantir
"all your data are belong to us" ftfy
← PreviousPage 2 of 7Next →