Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mike-cardwell
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
mike-cardwell
2mo ago
I turned this on a few days ago. Looking good so far (UK)
2.
▲
by
mike-cardwell
2mo ago
Also, if your domain doesn't receive mail, set up a null mx record: @ IN MX 0 . https://datatracker.ietf.org/doc/rfc7505/
3.
▲
by
mike-cardwell
3mo ago
That timeline was exactly my experience with Apple here - https://www.grepular.com/Apples_Protect_Mail_Activity_Doesnt... They don't seem to know or care what is going on with their own email systems.
4.
▲
by
mike-cardwell
3mo ago
The text is added to get around bayesian filters. The spammer doesn't want the text to be displayed to the end user though typically.
5.
▲
Show HN: Sanitising Email
(grepular.com)
1 points
by
mike-cardwell
3mo ago
|
0 comments
6.
▲
by
mike-cardwell
4mo ago
I spend a lot of time telling Opus 4.8 to search for security bugs in the code it wrote, and it spends a lot of time finding them, and then fixing them. Fable wont let me fix the security issues that Opus 4.8 created.
7.
▲
by
mike-cardwell
4mo ago
https://gitlab.com/grepular/calendiff - Point it at a .ics URL and it monitors for calendar changes and emails you about them. https://gitlab.com/grepular/foxcage - Runs Firefox inside podman to i
8.
▲
by
mike-cardwell
4mo ago
I don't use X. You can tell him if you want.
9.
▲
by
mike-cardwell
4mo ago
That wouldn't be better guidance. That would be additional guidance. I'm sure Google also never let anybody set up postmaster@gmail.com
10.
▲
by
mike-cardwell
4mo ago
I wasn't able to sign up for postmaster@rootshell.is, but I was able to get abuse@rootshell.is. You should be careful about what standard email addresses you allow people to take. I recommend you take abuse@ back from me and you should
11.
▲
by
mike-cardwell
4mo ago
You declare HSTS preload, but you are not in the preload list. You can not be added to the preload list at https://hstspreload.org/ because www.rootshell.is exists but has an invalid certificate. Your MX TLS configuration s
12.
▲
by
mike-cardwell
4mo ago
Weirdly, if I click Load Images, all I get is a load more CSP errors and the image fetches don't happen.
13.
▲
by
mike-cardwell
4mo ago
You defeated https://www.emailprivacytester.com straight off. Which is more than most new email services. You seem to be relying on CSP entirely for this, but it works.
14.
▲
by
mike-cardwell
4mo ago
Targetted automated spam, most likely written by an LLM you say. By any chance do you see the text "agentmail" anywhere in the headers/body of that email?
15.
▲
by
mike-cardwell
4mo ago
Working 14 hours a day isn't normal. From an IT person who works 8 hours a day.
16.
▲
by
mike-cardwell
5mo ago
This reads like you just made up a workaround without reading the proposed law or without looking at the reality of the situation in other countries that it has been implemented. Your suggested workaround doesn't work.
17.
▲
by
mike-cardwell
5mo ago
Are you unaware that scalpers are set up to hoover up as many tickets as possible before an actual person that wants to visit the event can get one? Because it seems like you are?
18.
▲
by
mike-cardwell
5mo ago
The "market price" you're talking about, is set by how many scalpers are creating scarcity. If the number of scalpers is 0, then the "market price" is different. It becomes the price that both the vendor is willing
19.
▲
by
mike-cardwell
5mo ago
Re "sent via AgentMail" - that's good to hear, but I hope it's not the entire planned text, as "AgentMail" will mean nothing to most people that receive an email from your service. It wont indicate that the ema
20.
▲
by
mike-cardwell
5mo ago
I received this email the other day: From: Kushal <kushal@kushalsm.com> Date: Mon, 18 May 2026 05:03:11 +0000 Saw your question on the Agent Vault thread about websocket-frame auth (Home Assistant) and the worry about the m
21.
▲
by
mike-cardwell
5mo ago
> Why should anything be done? Because there is demand for it. A lot of people like going to live music and theatre events and scalpers make it more difficult and more expensive for them. Why shouldn't anything be done? Because ca
22.
▲
by
mike-cardwell
5mo ago
In the UK they're making it illegal to resell tickets for more than the original cost. That should deal with the majority of the problem.
23.
▲
Auth Proxy Injection for LLMs
(grepular.com)
3 points
by
mike-cardwell
5mo ago
|
0 comments
24.
▲
by
mike-cardwell
5mo ago
Perhaps he's moribund
25.
▲
by
mike-cardwell
5mo ago
Does it work for websockets too, where the authentication is done in a websocket frame? Like for Home Assistant? Also, if the LLM manages to do something to reflect the authentication token back in a response, do you detect it and strip it
26.
▲
by
mike-cardwell
6mo ago
https://gitlab.com/grepular/claude-sandbox runs claude in a podman container. The way it deals with this is: claude-cli executes whatever is in the BROWSER env variable to open your browser at a current URL, so I point
27.
▲
by
mike-cardwell
6mo ago
Ah I see. Recommend you run "npm install" on your host then instead.
28.
▲
by
mike-cardwell
6mo ago
Guessing you meant "python" rather than "docker", as docker is not subject to the same type of attack. However, it's a single .py script that you copy somewhere. Not even close to a typical nodejs project using npm
29.
▲
by
mike-cardwell
7mo ago
I host my own email. I use a default SpamAssassin configuration along with some basic greylisting. I barely get any spam. Maybe one every month or two.
30.
▲
by
mike-cardwell
7mo ago
I've had a few emails, and a few contacts over Matrix over the years. Barely any though. My email and matrix id are both on my front page at https://www.grepular.com . I recently added a "Like" button at various pl
More ›