HNHacker News
TopNewBestAskShowJobs

uaygsfdbzf

242 karma · joined September 7, 2013

submissionscomments
uaygsfdbzf··on Almost Always Add Swap Space
Author said almost always. Nothing is absolute in cases like this. I agree with the article. We enable swap on our production servers precisely because the engineers don't rectify their memory leaks or whatever problems are internal to their software. Some of those engineers are our own and we can't convince them to fix their software. Others are for things we have no control over, such as Kafka, for example. When Kafka starts going out of control and you've got no swap, oom killer will kill it and you'll end up with corrupted index files, which is a bigger problem than the performance problem you'll see if it has to swap for a while until it gets itself sorted out.
uaygsfdbzf··on Told vultr.com thier IP is blacklisted. Says my sources are “not reliable”
awesome thanks! I was under the false impression that mxtoolbox.com was trust worthy.
uaygsfdbzf··on JMAP – a better way to email
It is solved for some specific platforms, GNOME for example:

https://mail.gnome.org/archives/gnome-announce-list/2014-Nov...

The average user doesn't use GNOME or Linux though :(

uaygsfdbzf··on Generating code
Ick...
uaygsfdbzf··on OpenSSD – Open firmware for SSDs
In 10 years flash will be dead and we'll be using memristors.
uaygsfdbzf··on JMAP – a better way to email
In case you hadn't noticed, the authenticity model of SSL was an afterthought and is completely broken. I recommend listening to Moxie's talk about this:

https://www.youtube.com/watch?v=pDmj_xe7EIQ http://www.thoughtcrime.org/blog/ssl-and-the-future-of-authe...

uaygsfdbzf··on JMAP – a better way to email
You don't need to trust the keyservers since you verify the fingerprints of downloaded keys against the fingerprints given to you in person.

The keyserver protocol includes commands to include keys in the keyserver network. How you send keys depends on the UI of the tool you use, geeks will do this:

gpg --keyserver <keyserver> --send-keys <fingerprint>

uaygsfdbzf··on Generating code
Committing generated code is just a recipe for badness. I never commit the output of cpp/yacc/etc to git, why would I do that for go stuff?
uaygsfdbzf··on Reverse-engineering the Kayak app with mitmproxy
I would just use wireshark for that.
uaygsfdbzf··on Reverse-engineering the Kayak app with mitmproxy
There are at least three addons that allow viewing network activity with Firefox:

https://getfirebug.com/ http://chrispederick.com/work/web-developer/ https://addons.mozilla.org/en-US/firefox/addon/live-http-hea...

I haven't tried it but I expect the developer edition does too:

https://www.mozilla.org/firefox/developer/

uaygsfdbzf··on Skipping fsck during boot with systemd?
There was a more productive thread on a related topic on debian-devel recently:

https://lists.debian.org/20141213135648.GA14679@fishbowl.rw....

Basically it isn't possible to check at runtime if the next boot will require an fsck, so developer filed a bug asking for mechanism to do that:

https://bugs.debian.org/773267

uaygsfdbzf··on ShellCheck: a static analysis and linting tool for sh/bash scripts
What are you using for Perl and JavaScript?
uaygsfdbzf··on ShellCheck: a static analysis and linting tool for sh/bash scripts
Some ideas for the future:

Add support for the Firehose XML output format:

https://github.com/fedora-static-analysis/firehose

Checks for features that are specific to one shell (bashisms etc) when used with POSIX #!/bin/sh.

Checks for features that aren't implemented in the desired shell (for running on busybox sh for example).

Check for the various issues listed here:

http://mywiki.wooledge.org/BashPitfalls

uaygsfdbzf··on Reverse-engineering the Kayak app with mitmproxy
Personally I would just use the Firefox web developer tools rather than mitmproxy, much easier.
uaygsfdbzf··on Reverse-engineering the Kayak app with mitmproxy
How is using the API any different to using the website or app? Sounds like you need to move your access controls one layer down, into the API. If the app does rate limiting, the API should too/instead.

Take the github approach and let open source devs write innovative apps based on your open API!

uaygsfdbzf··on Multiple vulnerabilities released in NTP
Your article about that:

https://blog.hboeck.de/archives/863-Dont-update-NTP-stop-usi...

uaygsfdbzf··on Possible upcoming attempts to disable the Tor network
Many of these are probably running the Linux kernel, which recently had some security updates so the restarts might be related to that.
uaygsfdbzf··on German researchers discover flaw that could let anyone listen to cell calls
The technology to do these things is open source and available here:

http://osmocom.org/

uaygsfdbzf··on Ask HN: If we could redesign the Internet from scratch, what should it be?
I would use the GNUnet name system:

https://gnunet.org/gns-implementation

uaygsfdbzf··on Snowdrift.coop: Funding for free projects
I'm not affiliated with snowdrift but their website source code is here:

https://gitorious.org/snowdrift/snowdrift/

uaygsfdbzf··on Show HN: An interactive comparison chart of the 300 most popular smartphones
Both of you should look at the Neo900:

http://neo900.org/

It is an N900 chassis (inc keyboard) with a GTA04 motherboard plus some cool anti-spying features to isolate the LTE modem (which of course runs a proprietary OS).

uaygsfdbzf··on Revisiting the “Cookieless Domain” Recommendation
You are duplicating the 'loading' indicators in the browser.
uaygsfdbzf··on The Two Pillars of JavaScript: Part 1: How to Escape the 7th Circle of Hell
"What you think is a tool is actually a footgun" This man has a way with words.
uaygsfdbzf··on GitHub blocked in Russia
Wow, a whole thread about Internet censorship and not one mention of the Tor project and their bridges and obfuscated pluggable transports? Tor is not just for anonymity but also for censorship avoidance.

https://www.torproject.org/ https://www.torproject.org/docs/bridges.html https://www.torproject.org/docs/pluggable-transports.html

uaygsfdbzf··on Ask HN: Confused software developer
A great way to gain more experience is to contribute to open source.

One way would be to join the Debian mono group to help improve the C#/.NET stack in Linux Mint (they pull packages from Debian):

https://wiki.debian.org/Teams/DebianMonoGroup

Similar teams exist in Debian for many all languages.

uaygsfdbzf··on 64-bit ARM Kernel Development Demo on a Nexus 9
It is fairly easy to get Debian on an Android device, the problem is you will end up drinking over 9000 litres of beer due to the mainline Linux kernel not supporting your device.

http://bonedaddy.net/pabs3/log/2012/12/03/debian-mobile/ https://wiki.debian.org/ChrootOnAndroid

uaygsfdbzf··on 64-bit ARM Kernel Development Demo on a Nexus 9
ARM SoC support in Linux mainline is usually pretty good but support for individual mobile devices that normally run Android's version of Linux is almost non-existent. Basically we are never going to get the usual Linux distros running on Android devices without using Android's version of Linux. There isn't anyone with the available, time, skills and motivation to get new or old Android devices supported by Linux mainline. I expect the same goes for other vendor-controlled Linux based mobile distros (Tizen, Sailfish, FirefoxOS etc). Probably the closest to mainline is the very old Nokia N900 but that doesn't even support all of the hardware on the device:

http://elinux.org/N900

uaygsfdbzf··on How to reward skilled coders with something other than people management
Science says that will give you worse results:

http://www.ted.com/talks/dan_pink_on_motivation

uaygsfdbzf··on The Ashton Disinterest Curve – JavaScript and Node
Wow. Completely agree. JS for fun, not for production maintainable apps.
uaygsfdbzf··on [dead]
I guess that's why he has a 'perfect' reputation in Ebay. hope Ebay was more responsive with these cases...
Page 1 of 2Next →