Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
justin_oaks
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
justin_oaks
6mo ago
When a company makes it impossible to correct their stupidity, it's a malicious act. The behavior speaks loud and clear: "We don't care what damage we do to developers or users. And we don't want to hear about it."
2.
▲
by
justin_oaks
6mo ago
That happened to me exactly once in my 20-year career. It was on a web server (maybe even NGINX) that had too many cached files. Even though it only happened once, I still set up monitoring for inode exhaustion.
3.
▲
by
justin_oaks
6mo ago
The list of API integrations provided by the lego project looks quite impressive. https://go-acme.github.io/lego/dns/index.html
4.
▲
by
justin_oaks
6mo ago
Yes, I see that AWS Route53 can limit credential scope. That kind of thing helps a lot. I've never heard of that CNAME approach for changing the validation domain. That looks like a viable solution since it requires a one-time setup on
5.
▲
by
justin_oaks
6mo ago
Moving subdomains to separate zones can make sense for a small set of subdomains and all your certificates would be for names under those subdomains. It gets unwieldy if you have to create a separate zone for each certificate because the ce
6.
▲
by
justin_oaks
6mo ago
That looks like a great solution. I'll probably make use of that as soon as it's available.
7.
▲
by
justin_oaks
6mo ago
Ah, that's a clever mechanism. That way the secondary machine could not only keep the token secure, but also validate which DNS records to create.
8.
▲
by
justin_oaks
6mo ago
Oh... that's fantastic! It specifically addresses my concerns about needing DNS credentials accessible to scripts. The article says it is for those who > prefer to keep DNS updates and sensitive credentials out of their issuance pat
9.
▲
by
justin_oaks
6mo ago
Some of this might have been "because I want to see if I can". Another reason is "It bothers me to keep seeing this browser tell me my connection is insecure". As for putting it on a separate VLAN and securing traffic wi
10.
▲
by
justin_oaks
6mo ago
I read a lot about people running things like Caddy which will automatically retrieve Lets Encrypt certificates. And I think it makes sense for publicly accessible web sites since you can use an HTTP challenge with Let's Encrypt. For i
11.
▲
by
justin_oaks
1y ago
I agree that it's not a serious project, but I wouldn't call it a joke. Jokes are funny.
12.
▲
by
justin_oaks
1y ago
Without TLS, sometimes still referred to as SSL, a webite's content can be modified by anyone controlling the network path. This includes ISPs and WiFi operators. Sure, your website may have unimportant stuff on it that nobody relies o
13.
▲
by
justin_oaks
1y ago
This has been my experience as well. I implemented 2FA for my previous employer and we would have gladly skipped SMS 2FA if we could get away with it. It's more expensive for the company and the customer. And it sucks to implement bec
14.
▲
by
justin_oaks
1y ago
I implemented 2FA at a previous job and I was responsible for the production implementation working as expected. My thoughts were that uncompleted 2FA attempts are common for a number of reasons: typos, someone gets distracted, didn't
15.
▲
by
justin_oaks
1y ago
You may have to temper your expectations. Free usually means "sells/uses your data to offset costs". If you're OK with that, there's no need to switch off of GMail. If you're not OK with that, you'll have
16.
▲
by
justin_oaks
1y ago
I wish consoles were like the Steam Deck: computers running a common OS that just so happen to be used for gaming.
17.
▲
by
justin_oaks
1y ago
Knowing that there are only 25 responses, it makes it all the more funny that rate limiting is mentioned. And you can host the service yourself! Hard pass. I'll read the 25 responses from your gist. Thanks!
18.
▲
by
justin_oaks
1y ago
Once you remove the duplicates that are different only because of the typos in them, yes, that's correct.
19.
▲
by
justin_oaks
1y ago
The author doesn't seem to consider someone's desire to behave morally as an incentive. How odd.
20.
▲
by
justin_oaks
1y ago
Avoiding shame is an incentive. It boils down to: "Why are people violating these unenforced rules? Sure it benefits them, but don't they feel bad?"
21.
▲
by
justin_oaks
1y ago
Generally it isn't done because the people in power benefit from the status quo. To fix it, you need collective action. And now you have a collective action problem: https://en.wikipedia.org/wiki/Collective_action_
22.
▲
by
justin_oaks
1y ago
Your comment could have been simplified to: "I don't like the syntax" And that could be optimized further by leaving no comment. All syntax is learned. None of it is "intuitive". Anything unfamiliar to you will seem
23.
▲
by
justin_oaks
1y ago
In my day we memorized IPs AND ports. 10.24.67.22:78342 was to access our bug tracker and 192.168.240.17:21282 was for our CVS repository! Seriously though, one of the first things I did when I was hired as the sysadmin for a small company
24.
▲
by
justin_oaks
1y ago
I recommend using the .test TLD. * It's reserved so it's not going to be used on the public internet. * It is shorter than .local or .localhost. * On QWERTY keyboards "test" is easy to type with one hand.
25.
▲
by
justin_oaks
1y ago
I'd recommend using some other reserved IP address block like 169.254.0.0/16 or 100.64.0.0/16 and assigning it to your local loopback interface. (Nitpick: you can actually use all of 127.0.0.0/8 instead of just 127.0.0.0
26.
▲
by
justin_oaks
2y ago
One of my favorites in this space is Feather Wiki: https://feather.wiki/
27.
▲
by
justin_oaks
2y ago
So we're back to another maxim: Everything should be made as simple as possible, but not simpler. Or perhaps: Bugs happen.
28.
▲
by
justin_oaks
2y ago
Like many of the other commenters, I have no code to show. I'm strongly motivated at work to solve problems and create correct, performant, maintainable code. I appreciate a job well done. Outside of work, I just don't have the mo
29.
▲
by
justin_oaks
2y ago
I like the code review approach and tried it a few times when I was needed to do interviews. The great thing about code reviews is that there are LOTS of ways people can improve code. You can start with the basics like can you make this cod
30.
▲
by
justin_oaks
2y ago
Yup, that's just one of the many ways to do a code-review interview wrong. Each code sample should have multiple things wrong. The best people will find most (not necessarily all) of them. The mediocre will find a few.
More ›