Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sgjohnson
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
61.
▲
by
sgjohnson
9mo ago
> Here’s our first problem, as those are located in the Signed System Volume (SSV), so we can’t change them in any way. The same applies to the other 417 LaunchDaemons and 460 LaunchAgents that account for most of the processes listed by
62.
▲
by
sgjohnson
9mo ago
The next sentence is also interesting actually. > It’s a closed-source proprietary operating system Most UNIX systems were proprietary & closed source though?
63.
▲
by
sgjohnson
9mo ago
I don’t think OpenAI could be considered a startup anymore.
64.
▲
by
sgjohnson
9mo ago
IPv6? You wouldn’t even need to expose the actual endpoints out on the open internet. DNAT on the edge and point inbound traffic on a VM responsible for cert renewals, then distribute to the LAN devices actually using those addresses.
65.
▲
by
sgjohnson
9mo ago
A lot of applications implement cert pinning for this exact reason
66.
▲
by
sgjohnson
9mo ago
Cloud providers could check the transparency lists, and if there’s a valid cert for the IP, quarantine it until the cert expires. Problem solved.
67.
▲
by
sgjohnson
9mo ago
"Ultra" isn't even binned - it's just 2x "Max" chips connected together. Otherwise, yes, if a chip doesn't make M4 Max, it can make M4 Pro. If not, M4. If not, A18 Pro. If not that, A18. And even all of th
68.
▲
by
sgjohnson
9mo ago
I’m pretty confident that the US SIGINT agencies wouldn’t manipulate BGP to redirect traffic somewhere, as such a hijack will ALWAYS leave traces that would be observable by anyone impacted, downstream or upstream. US SIGINT agencies? They’
69.
▲
by
sgjohnson
9mo ago
What do you mean? The internet is virtually entirely decentralized. There is no one central BGP router.
70.
▲
by
sgjohnson
9mo ago
If you don’t want to put Cloudflare in front of it, you can dual-stack the edge and run your own NAT46 gateway, while still keeping the internal network v6 only.
71.
▲
by
sgjohnson
9mo ago
If you have a /48 assigned, you’ll burn the prefix in your brain. Leaves 16 bits for the network address. e.g. you’ll get 2a06:a003:1234::/48 from the ISP - what you’ll really need to remember is the 2a06:a003:1234:xxxx::/64
72.
▲
by
sgjohnson
9mo ago
Cloudflare proxy automatically creates A and AAAA records. And you can’t even disable AAAA ones, except in the Enterprise plan. So if you use Cloudflare, your website simply is going to be accessible over both protocols, irrespective of the
73.
▲
by
sgjohnson
9mo ago
> We are still decades away from it being viable for servers to run IPv6 first. Just put Cloudflare in front of it. You don’t need to use IPv4 on servers AT ALL. Only on the edge. You can easily run IPv6-only internally. It’s definitely
74.
▲
by
sgjohnson
9mo ago
RFC 1631 is a memo, not a standard. Actually, my bad. NAT was NEVER standardized. Not only NAT was never standardized, it’s never even been on standards track. RFC 3022 is also just “Informational” Plus, RFC 1918 doesn’t even mention NAT So
75.
▲
by
sgjohnson
9mo ago
Not just the edge router. Every router between the ISP edge and the destination edge. And since the goal is “backwards-compatability”, you’d always need to poll, because a “legacy” IPv4 client would also be unable to send packets to the IPv
76.
▲
by
sgjohnson
9mo ago
that exists - ::ffff:0:0/96 space. It even supports dots. ::ffff:192.168.1.1 == 192.168.1.1 (as far as the linux kernel is concerned, in most contexts)
77.
▲
by
sgjohnson
9mo ago
Obviously they are. Most people use the equipment provided by their ISP without ever changing any settings. If the ISP is IPv6-first, you bet that their customers are using it in their home WiFi.
78.
▲
by
sgjohnson
9mo ago
> Basing your IP address on your Mac address doesn't help in that regard either. This hasn’t been the case for 20 years. Privacy Extensions solved that, and every SLAAC implementation supports them.
79.
▲
by
sgjohnson
9mo ago
Yes, the only key difference is that NAT is gone. Also a nitpick: switching is irrelevant here, that’s L2. L2 doesn’t even know what’s an IP address :) There was some dude on YouTube that resurrected the first Ethernet bridge (which was bui
80.
▲
by
sgjohnson
9mo ago
> It seemed so much more difficult and unpleasant to deal with. In my experience it’s much easier and much more pleasant do deal with. Every VLAN is a /64 exactly. Subnetting? Just increment on a nibble boundary. Every character can
81.
▲
by
sgjohnson
9mo ago
But that is a bug in history. IPv6 was standardized BEFORE NAT. “most what they know from IPv6” is just NAT. > A less ambitious IPv4 is exactly what we need in order to make any progress but we’re already making very good progress with I
82.
▲
by
sgjohnson
9mo ago
> Only the edge equipment would need to be IPv4+ aware. And even that awareness could be quite gradual, since you would have NAT to fall back on when receiving an IPv4 classic packet at the network. It can even be customer deployed. Add
83.
▲
by
sgjohnson
9mo ago
464XLAT is for dealing with IPv4 literal addresses in a v6 only network. Non-literals can be addressed with DNS64 & NAT64
84.
▲
by
sgjohnson
9mo ago
graalvm native binaries?
85.
▲
by
sgjohnson
9mo ago
Most likely still worth it when comparing by unit of energy produced.
86.
▲
by
sgjohnson
10mo ago
> This argument that nuclear power generation is clean if you ignore the times when it isn't seems a bit no-true-Scotsman to me. The same can be said about wind and solar. Nothing about producing the rare earths required is clean. E
87.
▲
by
sgjohnson
10mo ago
Nitpick: pretty sure both of those are in the billions. Mails could even be in the trillions.
88.
▲
by
sgjohnson
10mo ago
Breakout cables typically split to 4. e.g. QSFP28 (100GbE) splits into 4x SFP28s (25GbE each), because QSFP28 is just 4 lanes of SFP28. Same goes for QSFP112 (400GbE). Splits into SFP112s. It’s OSFP that can be split in half, i.e. into QSFP
89.
▲
by
sgjohnson
10mo ago
This was solved in 2007 with Privacy Extensions. It has been a non-existent problem for roughly 20 years now. Why do people still keep pulling out "uniquely identified down to the device" as an argument? Windows, macOS and most Li
90.
▲
by
sgjohnson
10mo ago
Yes. I’ll never forgive IETF for standardizing CGNAT back in 2013. They should have just said “no, deploy IPv6 with a transition technology”. If that had happened, IPv4 would likely already could be regarded as a relic of the past.
More ›