Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
r1ch
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
91.
▲
by
r1ch
4y ago
We used the C++ version of uWebSockets to replace a legacy node app. We went from four fully loaded cores to about 20% of a single core and a fraction of the memory usage. It's a great library.
92.
▲
by
r1ch
4y ago
Even with the WAF disabled (at least as much as I can disable it without the Enterprise plan, i.e. "Essentially Off"), I've found it will still block legitimate requests. Tainted CGNAT or dynamic IPs are my guess. The WAF doe
93.
▲
by
r1ch
4y ago
There's a couple of "previously connected" bits with QUIC: - The very first connection to a site is usually HTTP/2, which requires an additional RTT compared to QUIC, as the browser doesn't yet know if the server su
94.
▲
by
r1ch
4y ago
An interesting idea, but QUIC / HTTP/3 also avoids the extra RTT for TLS negotiation by bundling it with the connection handshake and in a less janky way than this. I don't see a good reason for a server or browser developer
95.
▲
by
r1ch
4y ago
It's disappointing how much junk gets shipped in non-Google ROMs and how little OEMs seem to care. I bought a Xiaomi phone several years ago and in addition to the usual bloatware it came complete with Qualcomm radio debugging tools ru
96.
▲
by
r1ch
4y ago
There's a few things that can help: - DMCA takedowns (domain registrar, ISP, IP space owner) - Report the fake site as phishing in Google Safebrowsing and similar - If they're hotlinking any assets, replace them with broken /
97.
▲
by
r1ch
4y ago
They're multi part which seems to trip up Gmail, it seems one part is scanned and another displayed. Base64 decode the source parts and add a keyword filter for the "non-spam" text as it's usually pretty static.
98.
▲
by
r1ch
4y ago
I've never had a good experience using a registrar's DNS service for production. Point it at Cloudflare or HE or something.
99.
▲
by
r1ch
4y ago
It's kind of a joke, the entire thing is relying on the locked down hardware as it contains the keys that generate coins. You can set up your own mini network that only sees / validates your own nodes and get rewarded. The solutio
100.
▲
by
r1ch
4y ago
It's in one of the popular AdBlock lists.
101.
▲
by
r1ch
4y ago
I believe most of these "physical attacks" are datacenter support teams being socially engineered and not state-level actors. They hook up a USB rescue drive to "help" you back into your server, using full disk encryptio
102.
▲
by
r1ch
4y ago
On Windows, a USB device's configuration is tied to its port, so by using this hack the device's settings will change depending on the orientation of the connector. This can't be good for user confidence in USB-C.
103.
▲
by
r1ch
4y ago
It's a tiny amount compared to the traffic that does get through, but enough that affected users make it to our support channels. I think a good amount are due to VPNs used by users, the rest seemed like standard residential IPs that I
104.
▲
by
r1ch
4y ago
I pay for Cloudflare Pro and the lowest I can set the WAF is "Essentially Off", requiring me to block whatever IPs are left at that level (which turns out to be a decent amount of legitimate requests). "Actually Off" app
105.
▲
by
r1ch
4y ago
I use an Aranet4 in the living room. Mechanical ventilation in most homes in NL allows configuring a precise flow rate in cubic meters so I've found the breakpoint to keep it < 1000 ppm. I took it to the office one day and it measur
106.
▲
by
r1ch
4y ago
You may as well just SYN flood at that point. None of this is really new, you can take down a lot of TCP based servers with the right combination of packets and volume.
107.
▲
by
r1ch
4y ago
Although there's no source code, Microsoft's public debug symbol information makes it pretty easy to determine where certain functionality lies in most of their binaries. Then you overwrite the opcodes to get the desired functiona
108.
▲
by
r1ch
4y ago
I've tried all of those workarounds, unfortunately none of them worked for me for whatever reason.
109.
▲
by
r1ch
4y ago
Unfortunately it's not that simple. On my system with bridges for hyper-v and wireguard tunnels, the NCSI service happily ignores my default route and tries to establish connectivity through one of the other devices when resuming from
110.
▲
by
r1ch
4y ago
The adjustment algorithm still requires blocks to be generated before it adjusts. If enough miners shut down at the same time, time between blocks will skyrocket, pushing the difficulty adjustment forward even further and crippling the tran
111.
▲
by
r1ch
4y ago
You're making a lot of assumptions here. Of course containers will be a thing, I'm not arguing against that and I run plenty myself. My point was that for simple tasks, you don't need to immediately jump into a technology you
112.
▲
by
r1ch
4y ago
Yup. I remember messing around with Redhat when I was 13. I installed Apache, edited the default index.html in htdocs then went to another computer, put in my IP and it worked! I was amazed, here I was running my own website. 25+ years late
113.
▲
by
r1ch
4y ago
Cloudflare's TOS only permit caching for HTML content and related assets. It's probably a useful catch-all they can pull out any time someone uses too much bandwidth.
114.
▲
by
r1ch
4y ago
Companies will realize the majority of abuse comes from humans completing CAPTCHAs and little to none from TPM attestations. It's then a small leap to only trust TPMs and lock everyone else out. After all, every genuine user has an OS
115.
▲
by
r1ch
4y ago
Check the raw email body and see if it consists of multiple encoded MIME parts. I'm seeing some spammers sending the message body as one part of innocuous content but then a different part is displayed when you open the email. I'm
116.
▲
by
r1ch
4y ago
Yes, HTTP / HTTPS requests can be proxied this way. Any CF IP seems to work. HTTPS only works if the target hasn't disabled Universal SSL (i.e, they have a TLS cert provisioned on Cloudflare's IPs).
117.
▲
by
r1ch
4y ago
This was an interesting Cloudflare "feature" I found out about the hard way. Even if you only use Cloudflare for DNS hosting, they will happily accept proxied requests for your hostnames and route them to your origin. I discovered
118.
▲
by
r1ch
4y ago
Amazon affiliate links contain a "tag" query parameter, these do not appear to be affiliate links.
119.
▲
by
r1ch
4y ago
There's also net.ipv4.conf.interface.arp_filter. I found it quite confusing to identify exactly which of all of these should be tweaked. I run arp_ignore=1 and arp_filter=1 on my router to avoid the behavior and it seems to work.
120.
▲
by
r1ch
4y ago
Yeah I didn't realize CF's payouts were so low.
More ›