Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Snawoot
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
31.
▲
by
Snawoot
2y ago
> But you can still get reduced performance with multiple channels due to head of line blocking. Later problem can be solved with the use of pool of separate SSH connections: https://github.com/Snawoot/rsp?tab=readme
32.
▲
by
Snawoot
2y ago
That's great! I see you use `sync.Pool`, which is way safer alternative. However, I wasn't able to secure much of performance gains for linked list benchmark using sync.Pool. It's not even clear how much objects it will conta
33.
▲
Generic Freelist Allocator for Go
(pkg.go.dev)
10 points
by
Snawoot
2y ago
|
3 comments
34.
▲
by
Snawoot
2y ago
No, sir.
35.
▲
Show HN: Lock-free concurrent maps for Golang
(pkg.go.dev)
5 points
by
Snawoot
2y ago
|
2 comments
36.
▲
by
Snawoot
2y ago
You can achieve the same on virtually any DNS hosting with RGAP[1]. The trick is to delegate name of your interest to server which runs RGAP DNS server and let it respond to queries for such domain name. Bonus: you can have more than one ad
37.
▲
by
Snawoot
2y ago
> The client generates a premaster secret, encrypts it with the server’s public key, and sends it to the server. It's already not true for, like, ages.
38.
▲
by
Snawoot
2y ago
There is also Aggregated Rendezvous Hashing[1] available, which kind of solves problem of growth of required calculations for large numbers of nodes. [1] https://github.com/SenseUnit/ahrw
39.
▲
by
Snawoot
3y ago
Why use PREROUTING chain? You could have achieved same with INPUT chain without specification of ingress interface and server IP address.
40.
▲
by
Snawoot
3y ago
The trick is just to hang it and film upside down /s
41.
▲
Redundancy Group Announcement Protocol
(github.com)
2 points
by
Snawoot
3y ago
|
0 comments
42.
▲
by
Snawoot
3y ago
No waka-waka - no fun.
43.
▲
by
Snawoot
3y ago
Great! Here is the feedback: https://github.com/saucelabs/forwarder/issues/616
44.
▲
by
Snawoot
3y ago
z-base-32 is one example: https://philzimmermann.com/docs/human-oriented-base-32-encod...
45.
▲
by
Snawoot
3y ago
Sure you can. Fingerprint of key is just a shorter and more convenient option to reference key everywhere, including manual verification. Article tells just that and it's commonly used in the industry. And, by the way, signature in X.5
46.
▲
by
Snawoot
3y ago
Which https proxy you're referring to? HTTP proxies capable of forwarding HTTPS just offer HTTP CONNECT method, which allows client to tunnel regular TCP connection and HTTPS inside it. These proxies do not do anything with certificate
47.
▲
by
Snawoot
3y ago
murmur3 is not a cryptographic hash, so it's not even in the same field.
48.
▲
by
Snawoot
3y ago
TLS 1.3 encrypts server certificate, so it will not be possible to filter such connections out using just passive inspection.
49.
▲
by
Snawoot
3y ago
Are there any benchmarks?
50.
▲
by
Snawoot
3y ago
It's not about stealth, it's about a bad habit of sending some bytes without thinking how it will be interpreted. Examples: - Syslog-ng server will interpret it as valid log messages - HP JetDirect on port 9100 will print HTTP req
51.
▲
by
Snawoot
3y ago
Not sure if I'd like to send anything into tested port just to tell if it is open. I'd rather stick with telnet or whatever is available. Also worth mentioning that bash also has network capabilities, you can check port like this:
52.
▲
Show HN: Dtlspipe – Like Stunnel, but for UDP
(github.com)
1 points
by
Snawoot
3y ago
|
0 comments
53.
▲
by
Snawoot
3y ago
Why not use protocols which are specifically designed to report mapped IP address like STUN? It's faster as UDP exchange is shorter than 3-way TCP handshake (or even TCP+TLS handshake). Here is an implementation which uses parallel STU
54.
▲
by
Snawoot
3y ago
Double that, "degraded performance" is simply a lie. It's a major outage. Also paying Protonmail customer, Pro plan.
55.
▲
by
Snawoot
3y ago
> The PC market was very good at catering to every price point. No wonder, it's because processors were actually cheap, but higher price points were created artificially. Great example is Intel 486SX ($333) vs 486DX ($588). In fact,
56.
▲
by
Snawoot
3y ago
Or instead you can have HTTP proxy over TLS in just four steps: https://github.com/Snawoot/dumbproxy/wiki/Quick-deployment You don't even need a client for this, any modern browser can work with it right
57.
▲
by
Snawoot
3y ago
I had similar problem with logs retention in past and came up with shell script[1] which deletes half of least recent files if disk usage hit high water limit. [1]: https://gist.github.com/Snawoot/9fdc348a8539cc74f80734
58.
▲
by
Snawoot
3y ago
Wireguard is known to be fingerprintable[1]. But at this moment it is unlikely UDP traffic will be filtered by Chinese GFW[2]. But this may change any moment. [1]: https://lists.zx2c4.com/pipermail/wireguard/2018-S
59.
▲
by
Snawoot
3y ago
Or just consider some HTTP over TLS proxy like this one: https://github.com/Snawoot/dumbproxy It may appear a bit more flexible option, especially if forwarding all traffic to VPN entirely is undesirable.
60.
▲
by
Snawoot
3y ago
Bruteforce of such random password is just not plausible and talks about KDF "weakness" is just a distraction. I think most likely it was evil maid attack. Here are projects which try to mitigate some of evil maid attack risks: h
More ›