Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jcgl
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
91.
▲
by
jcgl
5mo ago
You don’t need to roll your own LMS—you can self-host Canvas: https://github.com/instructure/canvas-lms/wiki/Production-St...
92.
▲
by
jcgl
5mo ago
> Nope. Key material rotation is just circus when it's done for the sake of rotation. I'm a mere sysadmin and not a cybersecurity expert. But this is always something that leaves me torn. On the one hand, yes, rotation period
93.
▲
by
jcgl
5mo ago
I think that's why this new IPv6-Mostly stuff is so exciting. You can dual stack a network segment if some of those v4-only devices exist there, but IPv6-Mostly will make sure that the other devices stay on v6 (translated or native).
94.
▲
by
jcgl
5mo ago
Same experience here. Linux admin. I’d absolutely love to be told I’m holding it wrong, but all I can see is that there’s no way to hold it right. Your consternation is seconded.
95.
▲
by
jcgl
6mo ago
Agreeing with my sibling commenter, this writer is extremely experienced and has been writing this blog for many years. I’d be appalled if this were LLM-written, but thankfully it reads with the same style and tone that he’s always had. >
96.
▲
by
jcgl
6mo ago
Preface: I’m not sure exactly who runs this blog or whatever viewpoint they hold. Seems to be a lot of AI boosting mostly? But my response is really just about this article itself. This article seems mostly content-free. It alleges (correct
97.
▲
by
jcgl
6mo ago
See Podman quadlets.
98.
▲
by
jcgl
6mo ago
Depending on the model though, aftermarket (or even new old stock) is readily available. If you buy used business class laptops like I do, you’re all but guaranteed to be in good shape regarding at least batteries.
99.
▲
by
jcgl
6mo ago
> The right way is to have the creds fetched from a vault, which is programmed to release the creds auth-free to your VM Or have whatever deployment tool that currently populates the env vars instead use the same information to populat
100.
▲
by
jcgl
6mo ago
> Only if the L2 network actually supports L2-multicast. Ethernet doesn't, except if your switches are intelligent enough. With cheap ethernet switches, multicast will be simulated by broadcast. True, but outside bottom-barrel switc
101.
▲
by
jcgl
6mo ago
I guess it depends on what you mean by "impossible." If you only mean that it's theoretically possible, then sure, one can imagine a world where that is done. But even with IPv4's meager 32 bits of address space, it woul
102.
▲
by
jcgl
6mo ago
But it's not the only way to tackle the problem of resolving layer 2 addresses, and you can do so without introducing the layering violations and expansive broadcast traffic that ARP implies (along with the consequent problems with WiF
103.
▲
by
jcgl
6mo ago
Ironic, considering that Meta is one of the more notable companies to run IPv6-only internally.
104.
▲
by
jcgl
6mo ago
> The stuff on my network assigns itself ipv6 addresses based on their mac address? That's how you can do stateless ipv6? Nit: per RFC8064[0], most modern, non-server devices do/should configure their addresses with "seman
105.
▲
by
jcgl
6mo ago
That'd be really cool. I'd never thought about enabling deeper graphical capabilities in a shell. But if you were to have a shell with rich objects rather than dumb bytes, that is a world that would open up! PowerShell, for inst
106.
▲
by
jcgl
6mo ago
Without knowing exactly what happened here, it could be hundreds, dozens, or zero other such vulnerabilities. The usual convention for configuring listening interfaces usually involves listing IP addresses or interface names. There's v
107.
▲
by
jcgl
6mo ago
I don't see how this generalizes into a security hole caused be lack of IPv6 knowledge. It just sounds like a random bug in Snapcast (great program!). If a user configures a program to only bind to loopback, but the program binds to ot
108.
▲
by
jcgl
6mo ago
> Linux file locking is to put it mildly, deficient. Since the introduction of flock on Linux, how bad is it really though? I don't see why one would need kludges like filename.lock. Though of course flock is still an "honor sy
109.
▲
by
jcgl
6mo ago
A specific implementation (OneDrive) doing something dumb doesn't invalidate the entire paradigm though. Things work just fine elsewhere (Dropbox, Google Drive, Nextcloud, and Seafile are all solutions I've had good experiences wi
110.
▲
by
jcgl
6mo ago
Doesn’t VMware have Tanzu, a container-based offering? Why not keep trying to adapt?
111.
▲
by
jcgl
6mo ago
But they were a mature company. Why would growth be the expectation? Note: I’m not asking for the Reddit armchair kvetching about the evils of modern capitalism and the failings of line-must-go-up. I’m wondering why, when serious financial
112.
▲
by
jcgl
6mo ago
OpenSnitch seems to do this just fine? Unless I’m misunderstanding your point. Connections seem to just block until I take an action on the dialog. Now, if an application itself has specified a short timeout (looking at you, NodeJS-based st
113.
▲
by
jcgl
6mo ago
I’m not aware of flatpaks specifically having th capability to run system software, daemons, etc. Some other immutable packaging formats should be able to (systemd-sysext at least, and snap iirc).
114.
▲
by
jcgl
6mo ago
> See perhaps OPTION_IA_TA (Temporary Address): I was unaware of this, so thanks. Sounds like it addresses (pun intended) my concern. > How does DHCPv6 hold back IPv6-mostly? First, most clients will send out a DHCPv4 request in case
115.
▲
by
jcgl
6mo ago
> except Android That alone is significant. Furthermore, DHCPv6 holds you back from various desirable things like privacy addresses and (arguably even more importantly) IPv6 Mostly.
116.
▲
by
jcgl
6mo ago
ARP-schmarp. That doesn't matter to almost anyone who doesn't need to go deep into the network. But yeah, SLAAC's paradigm of moving assignment logic into the node (away from network infra like in DHCP) is definitely a stumbl
117.
▲
by
jcgl
6mo ago
I think your summary is really great. One of the better refutations I've seen about the "what about v4 but longer??" question. However, I think people do get tripped up by the paradigm shift from DHCP -> SLAAC. That's
118.
▲
by
jcgl
6mo ago
> 3. History has shown that upgrading network backbone hardware (in particular) is incredibly difficult through a process that's been described as "ossification", which is a nice description. Basically, network relays and
119.
▲
by
jcgl
6mo ago
Right, the variable-length thing was my point. That's fine when you're dealing with byte slices that you scan through incrementally. But it's not fine for packets and OS data structures that had their lengths fixed at 32 bits
120.
▲
by
jcgl
6mo ago
Yep. Translation technologies like NAT64 and company basically as good a job as can be hoped for. And they're quite good nowadays! But to stick with the ASCII->UTF-8 comparison: how would you have done the transition if you had to s
More ›