Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ongy
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
ongy
1y ago
The core devs were all paid to work on it when I was still active. Not sure how many of the gnome (mutter) people are paid. Last I checked, the nvidia support was donated by nvidia (paid) for both KDE and Gnome. I think KDE got some work sp
62.
▲
by
ongy
1y ago
My homenet is 1GBit, so is my Internet I.e. no traffic beyond my legitimate saturation can reach the ISP I have saturated my link with quic or wireguard (logical or) plenty of times. The lack of any response on high data rates would be an i
63.
▲
by
ongy
1y ago
I think that's the point. You don't have to run the full kernel to run some linux tools. Though I don't think it ever supported docker. And wasn't really expected to, since the entire namespaces+cgroup stuff is way deepe
64.
▲
by
ongy
1y ago
The default hook systemd uses to wait for network is documented in https://www.freedesktop.org/software/systemd/man/latest/syst... It has the slightly odd behavior with trying to get all configured lin
65.
▲
by
ongy
1y ago
The encryption itself may not be. Establishing the initial exchange of crypto key material can be. That's where certificates are important because they add identity and prevent spoofing. With TOFU, if the first use is on an insecure
66.
▲
by
ongy
2y ago
This is after the jit. I.e. don't think fancy language shenanigans that do negative indexing. But negative offset from the beginning of the array memory access. When there's some inlining, there will be no function call into some
67.
▲
by
ongy
2y ago
> Europe’s largest makerspace for founders, startups, SMEs and many other creators This feels like it'll have none of the community character that makes maker's spaces what they are And more of a rental machines co-working spac
68.
▲
by
ongy
2y ago
Yea. The leet amount of payout seems like this was someone saying that the classification was technically correct, but it's worth fixing either way and it'd be nice to pay an amount.
69.
▲
by
ongy
2y ago
> > Whether and under what circumstances trans women have no advantage over cos women is a highly complex question. > Again, not really, except for all the misinformation online. If trans woman have such an high advantage, why have
70.
▲
by
ongy
2y ago
While this looks hard, the FSF has long ago provided us with a solution. The preferred form to make modifications on.
71.
▲
by
ongy
2y ago
Yes.
72.
▲
by
ongy
2y ago
That's how I use it Envoy as TLS terminating reverse proxy, and then locally it does http2.
73.
▲
by
ongy
2y ago
The value in the stock market is an increasing function, but neither nondecreasing, nor constant. And most of all, not monotonically increasing. The monotonically is important because it says that at every zoom level the function is increas
74.
▲
by
ongy
2y ago
I'm with the middle commenter Use proper title case in titles.
75.
▲
by
ongy
2y ago
Kinda useless to reply to a throwaway after 5h but let's see 1. Minor mistake. 42% marginal is at 60k~ish, the 278k number is 45% 2. The effective income tax rate around 100k is in the area of 25%. When there's numbers thrown arou
76.
▲
by
ongy
2y ago
This might be me being daft, but I never quite understood the appeal of doing this with istio. OR also partially just due to the timing of when I started to care about things in k8s world. (Rather recently) My understanding of that model is
77.
▲
by
ongy
2y ago
My reading is that it's supposed to provide an API that's safe to use, but might not allow to do everything technically possible within the HTTP spec.
78.
▲
by
ongy
2y ago
I suspect this is partially from google's internal 0 trust cluster networking. I.e. even if the communication is entirely between components inside a k8s (or borg) cluster, it should be authenticated and encrypted. In this model, there
79.
▲
by
ongy
2y ago
They don't mention it in the article, but by default ports 80 and 443 require elevated privileges. There's some (namespaces) knob to avoid that, but the lack of nod to it makes me worried. OTOH containers as security boundary is i
80.
▲
by
ongy
2y ago
I wanted to avoid making this a "it's Lennart" point. Even then, IME he's building software for 99% of users, which this covers. It can be quite annoying when he makes life hard for the remaining 1% (or fraction thereof)
81.
▲
by
ongy
2y ago
He's generally (I suspect p>99, probably a 9 more by volume) correct with his statement.
82.
▲
by
ongy
2y ago
While the single point of failure (especially for browser cookies) can be an issue, handing authentication and associated bookkeeping to an entity that does that , instead of plugging your own essentially least viable product level auth on
83.
▲
by
ongy
2y ago
For something like input field validation, a request per keystroke might be a bit much, but the update rate of feedback users expect. In systems with frontend UX validation and backend functional validation, errors from the backend tend to
84.
▲
by
ongy
2y ago
If the server is not behind NAT, the only reason you might require TURN is a restrictive egress firewall blocking UDP to arbitrary ports. It'll be a host<>prflx connection pair. Though if the host can be reached that way, I'
85.
▲
by
ongy
2y ago
What's the purpose of this? Mostly a tech-demo, or primarily to plug a p2p layer onto existing servers?
86.
▲
by
ongy
2y ago
Provide a server on-prem at the customer, but allow them a hybrid access to the system. Via cloud when necessary, "local" (by WebRTC) when possible. While we could just open a local port, using the cloud to arbitrate gives us a co
87.
▲
by
ongy
2y ago
You can use SEccomp for some of it as well. But for SEccomp something in the hierarchy needs to do this actively While SELinux can be set up somewhat orthogonal to the running system. OTOH systemd should make it easy to confirm every serv
88.
▲
by
ongy
2y ago
> Only authorized images will boo How do you do this on modern commodity hardware without secure boot? Or do you assume something in the category of embedded systems that allow to blow some efuses to get similar trusted boot?
89.
▲
by
ongy
2y ago
It's not controversial to write secure software. Saying that it's what should be fine is useless. Since it's not instructive. Don't fix implementation issues because that just papers over design issues? Great. Now we jus
90.
▲
by
ongy
2y ago
Then people gain options. Some of them might be worse for privacy, but if they offer better (or cheaper, which can be a quality) features, that's up to people. If this was "the olden days", it would be a legitimate concern. B
More ›