Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
TimWolla
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
TimWolla
4y ago
OpenSSL 3 is in Ubuntu 22.04 LTS [1]. I expect that alone to be bad enough. [1] https://discourse.ubuntu.com/t/jammy-jellyfish-release-notes...
32.
▲
Forthcoming OpenSSL Releases – Critical Issue in OpenSSL 3
(mta.openssl.org)
61 points
by
TimWolla
4y ago
|
6 comments
33.
▲
Withdrawal of OpenSSL 3.0.6 and 1.1.1r
(mta.openssl.org)
107 points
by
TimWolla
4y ago
|
9 comments
34.
▲
by
TimWolla
4y ago
> When I need DNS I know 8.8.8.8 just works. I've never had the need to know the IP address of a DNS resolver from the top of my head. Either the IP address of a working DNS resolver is provided by DHCP or I just install a local cac
35.
▲
by
TimWolla
4y ago
When reading along: Keep in mind that I'm not a core developer and thus are not directly involved in development, design decisions, or roadmap. I have some understanding of the internals and the associated challenges based on my contri
36.
▲
by
TimWolla
4y ago
It does not, because HAProxy does not perform any disk access at runtime and thus would be unable to persist the certificates anywhere. Disks accesses can be unpredictably slow and would block the entire thread which is not something you wa
37.
▲
by
TimWolla
4y ago
Exactly all of this. I've mentioned the first point about add_header redefining instead of appending in a previous HN comment of mine: https://news.ycombinator.com/item?id=27253579 . As mentioned in that comment, HAProx
38.
▲
by
TimWolla
4y ago
Disclosure: Community contributor to HAProxy, I help maintain HAProxy's issue tracker. > For my mental model, nginx is the right choice for SSL termination, logging, request mangling, interpretation of cookies and loadbalancing base
39.
▲
by
TimWolla
4y ago
The dataplane API is an external product that itself uses the "stats socket". I personally don't have any experience with the dataplane API. Changing certificates ( https://docs.haproxy.org/2.6/management.
40.
▲
by
TimWolla
4y ago
I'm surprised you find the documentation lacking. What type of API are you talking about? The internal C API? Lua? Configuration? Something else? Disclosure: I'm a community contributor to HAProxy and help maintain the issue track
41.
▲
RX Line: Pushing the envelop of parallelization
(hetzner.com)
5 points
by
TimWolla
4y ago
|
0 comments
42.
▲
by
TimWolla
4y ago
There's this comment which is newer: https://news.ycombinator.com/item?id=32026565 . There's also comments on some test submission: https://news.ycombinator.com/item?id=32026568 that itself got del
43.
▲
HAProxy 2.6
(haproxy.com)
2 points
by
TimWolla
4y ago
|
0 comments
44.
▲
by
TimWolla
4y ago
> EDIT: `-O resident` might be what is doing it though, I wasn't aware of this option. Indeed. This will use FIDO 2 Discoverable Credentials / Resident Keys. Those are fully stored on-key (but their number is limited): https:&
45.
▲
by
TimWolla
4y ago
Unfortunately updates are required here; to support new PHP versions. To the best of my knowledge the current version of Adminer still is not fully compatible with PHP 8.0 (it will emit warnings into an exported SQL dump): https:/&#
46.
▲
by
TimWolla
4y ago
WebAuthn binds the credential to the domain. Under the assumption that your web browser and security key is operating according to spec this is unphishable. If your web browser or key contains a bug, or the domain is breached then all bets
47.
▲
by
TimWolla
4y ago
This doesn't make sense. As a website author, why would I visibly restrict the security keys to backdoored government keys, when I can simply give the government an invisible backdoor API or direct database access?
48.
▲
by
TimWolla
4y ago
WebAuthn supports sending an attestation certificate during the initial registration. But with an implementation according to the spec this certificate only identifies the model of the security key used and thus is shared across a 5 to 6 di
49.
▲
by
TimWolla
4y ago
You can use OATHTOOL [1] on the command line or even roll your own TOTP implementation [2] in just a few lines of code in your favorite programming language. [1] https://www.nongnu.org/oath-toolkit/oathtool.1.html [2]
50.
▲
by
TimWolla
4y ago
Yes, but the TOTP is only usable once and cannot be reused across unrelated sites ("password stuffing"). And with WebAuthn / U2F the second factor is completely unphishable.
51.
▲
by
TimWolla
5y ago
Yep, same here. I create many topical channels to discuss some narrow-ish topic and archive them after the matter is concluded. Some of those channels just live a few days or even just hours - other live for several weeks but with several d
52.
▲
by
TimWolla
5y ago
Databases, Caches or the authentication service? For me read-only requests are working fine and I've not seen any issues. Submitting new contents (e.g. comments) is where it's failing for me. It might be that their database primar
53.
▲
by
TimWolla
5y ago
-f does not sound like a good idea to me in a script like that.
54.
▲
by
TimWolla
5y ago
It's not part of the SMTP spec. SMTP treats the local part as an opaque identifier. It's somewhat common though and RFC 5233 extends the sieve filtering language to support it: https://datatracker.ietf.org/doc/
55.
▲
by
TimWolla
5y ago
Neither a mutt, nor an offlineimap user, but I believe those two are often used in combination: http://www.offlineimap.org/
56.
▲
by
TimWolla
5y ago
> What are the benefits of SSE vs long polling? The underlying mechanism effectively is the same: A long running HTTP response stream. However long-polling commonly is implemented by "silence" until an event comes in and then p
57.
▲
by
TimWolla
5y ago
> RFC 8441, released on September 2018, tries to fix this limitation by adding support for “Bootstrapping WebSockets with HTTP/2”. It has been implemented in Firefox and Chrome. However, as far as I know, no major reverse-proxy impl
58.
▲
by
TimWolla
5y ago
Laravel definitely is everything, but light-weight. It's the slowest of the large names in PHP. see http://www.phpbenchmarks.com/en/comparator/framework or https://www.techempower.com/benchmar
59.
▲
by
TimWolla
5y ago
This is my experience with Laravel as well. Laravel looks great on the surface for a simple CRUD application, but once you need to do something non-trivial with it, you need to start fighting the framework. Also I dislike the large amount o
60.
▲
Hetzner Storage Share and Storage Box: Data storage and management made easy
(hetzner.com)
70 points
by
TimWolla
5y ago
|
17 comments
More ›