Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kenmacd
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
121.
▲
by
kenmacd
4y ago
I like his videos, but I don't trust his numbers in this one. He shows a COP of ~1 when it's 10 degrees out. These are the easiest possible conditions for the HP, and where all the specs show the highest COP. His graph showing the
122.
▲
by
kenmacd
4y ago
Seems rather short-sighted and unlikely to accomplish the authors goals. If we incentivize weight it seems we might end up with less safe batteries just because safer ones weigh just a little bit more. We could also lose efficiency and dura
123.
▲
by
kenmacd
4y ago
The Carnot limit of heat pump heating from -25C (-13F) to 20C (68F) is over 6.5. That's 650% efficient. There's a lot of heat in our 'cold' air. If you're going to try to claim 'thermal dynamics' [sic] you
124.
▲
by
kenmacd
4y ago
While they can have these elements, heat-pumps in general have come a long way in their ability to get heat out of the air at cold temperatures. Mine is still over 160% efficient at -13F, with no loss of capacity. Below that it'll stil
125.
▲
by
kenmacd
4y ago
To get rebates in NS need to put a head per level. Also the systems can typically work a temperature sensor that's not in the unit. It can be in the remote or in a wired thermostat. This avoids the unit shutting off because the ceiling
126.
▲
by
kenmacd
4y ago
Pretty sure this is sarcasm, but for general interest I'll mention the Phantom of Heilbronn ( https://en.wikipedia.org/wiki/Phantom_of_Heilbronn ), "responsible" for multiple murders, but really just an em
127.
▲
by
kenmacd
4y ago
>> <sigh> there's a lot of similar comments to this one. > <sigh> and a lot of similar rebuttals to this one. My point is that a lot of people don't seem to understand the 'why' of this issue and ins
128.
▲
by
kenmacd
4y ago
No they couldn't. If you replace a .txt file with random html data bad things are going to happen. Tell me, how does CF put a 'Checking your browser' page in my `wget https://easylist.to/easylist/easylist
129.
▲
by
kenmacd
4y ago
That would be fine because then CF could replace that HTML with their "Checking your browser before accessing" content. What's the app going to think of that though?
130.
▲
by
kenmacd
4y ago
<sigh> there's a lot of similar comments to this one. In short, it's much harder to protect a text file against DDoS. The ToS say 'a disproportionate percentage ... non-html' likely because they need to be able to
131.
▲
by
kenmacd
4y ago
Then CF replaces the html with their Browser Integrity Check. How does the app deal with the list becoming real 'Checking your browser" html?
132.
▲
by
kenmacd
4y ago
You're looking at it backwards though. CF doesn't _actually_ care about what the content is, only that they can apply their DDoS protections to it. If you're serving a text file that's much more difficult as they can
133.
▲
by
kenmacd
4y ago
> Seems like if it were simply renamed to .html with no content changes, then it would be okay. Imagine you do that and I DDoS the URL. CF will then mitigate this DDoS by, in part, replacing your html with their Browser Integrity Check h
134.
▲
by
kenmacd
4y ago
Say you do that and I DDoS the easylist.html. Cloudflare will start applying their DDoS mitigation. Now everyone's app receives the Browser Integrity Check instead of the list.
135.
▲
by
kenmacd
4y ago
Imagine you're trying to block a DDoS attack. If the client is downloading HTML then they likely also have JS enabled giving you a ton of options for running code on their computer to help you decide if the traffic is legitimate. If th
136.
▲
by
kenmacd
4y ago
I used to love Weather Underground, but I stopped using them when they killed public API access. I get that they were trying to make money from products using their API, but they're making money on data from personal weather stations s
137.
▲
by
kenmacd
4y ago
My issue with this is that to access my own email I get countless warnings, and always have a 'You have recommended actions' Security Checkup for 'Remove risky access to your data'. This is after jumping through a bunch
138.
▲
by
kenmacd
5y ago
Yes it's local, but also can be taken away to run on a cluster. Looks like ssh-keygen is using 16 rounds of bcrypt_pbkdf. My laptop just took 185ms to try a password. So I guess I could run less than 10 passwords per second (per core?)
139.
▲
by
kenmacd
5y ago
But you add a password to the key, so it's the same. And not everyone saves it to disk. My ssh key is my gpg key. It's stored on a yubikey and can't ever leave it. If I do a `git pull` then my yubikey flashes and I have to ta
140.
▲
by
kenmacd
5y ago
They didn't say they want something to go wrong, just that if it does Putin will blame someone else.
141.
▲
by
kenmacd
5y ago
I expected this before they shipped models running Linux, but thought I was safe now. I've learned my lesson.
142.
▲
by
kenmacd
5y ago
Here's a script that will set that mode, in case you'd like to use it. It prevents someone/malware from being able to use your key after you've unlocked it. For example if you hacked my computer and tried to use it to ss
143.
▲
by
kenmacd
5y ago
Wow, I just tried it and found `gopass show -o ___` works perfectly to scripts that want just the password without any null bytes or newlines in it. You've converted me. Thank you for mentioning it, I never thought to look for a compat
144.
▲
by
kenmacd
5y ago
Did you have our key on a yubikey and that yubikey set to require a touch for every operation?
145.
▲
by
kenmacd
5y ago
You probably shouldn't be able to disable touch. If you can disable it then malware can disable it. I'd highly recommend using the `fix` option instead of `on` to make sure it can't be disabled.
146.
▲
by
kenmacd
5y ago
All great, but I wish `pass` was usable in scripts without having to pipe it through `head -n 1 | tr -d '\d'`
147.
▲
by
kenmacd
5y ago
I agree, but I think it's pretty clear that web-of-trust has failed. There may be 6 or fewer degrees of separation between us, but the chance that there's a path of people that actually validate and sign keys isn't very high.
148.
▲
by
kenmacd
5y ago
I am. My ssh key is my gpg auth key. It's stored on my yubikey requiring a touch each time I use it. I use the same gpg key for talking to anyone, so why wouldn't I do the same with my ssh key? I suppose I could try to build a wor
149.
▲
by
kenmacd
5y ago
The IP you connect to could host 1000 sites. Leaking which one you're actually accessing could be important.
150.
▲
by
kenmacd
5y ago
Just wait. The newer laptops don't have S3 in the bios at all.
More ›