Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
terrywang
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
terrywang
6y ago
Cloud Firewall, VPC, glad to see useful features added. Personal experience with DO: I've been a happy DO customer for the past [7 years](1). Linux VM [uptime](2) record has been amazing for personal use case. This week I migrate the d
62.
▲
by
terrywang
6y ago
Pretty good guide covering Keybase features as well as PKI, OpenGPG/GnuPG, encryption/decryption, signing,authenticity/integrity and generic security & privacy guidelines average human beings can understand. Thumbs up, Ke
63.
▲
by
terrywang
7y ago
In addition to peek, I found ffscreencast works well for simple use cases (full desktop + multi monitor). asciinema works very well for recording / capturing terminal session (Linux + macOS). https://github.com/asciinem
64.
▲
by
terrywang
7y ago
Ed25519 keys have a fixed length and the -b flag will be ignored [1], it works for ECDSA though, 521 is the largest ec size supported. [1]: https://man.openbsd.org/ssh-keygen.1
65.
▲
by
terrywang
7y ago
In addition to the traditional | way of adding public key to target hosts, ssh-copy-id [1] is a wrapper script (shipped by most distros, for macOS it is a separate formula) which can be used to batch add a public key target hosts (love to u
66.
▲
by
terrywang
7y ago
Thank you place1. I was looking for something like wg-access-server web UI when moving away from strongSwan. Found Subspace but id didn't work the way I wanted, settled pretty well with some shell scripting for my own use cases and hap
67.
▲
by
terrywang
7y ago
IPsec is industry standard, but the whole IPsec stack and surrounding technology stack are very complex, different implementations (e.g. those Swans), configuration combos (phase 1,2 or in strongSwan sense - IKE, ESP, route-based, policy-ba
68.
▲
by
terrywang
7y ago
Search indicated that ShadowSocks (or its variants) can be used to tunnel WireGuard traffic, however, ShadowSocks is already on the way out due to continuously evolving GFW. I am looking to see if V2Ray is a viable option. In the meantime,
69.
▲
by
terrywang
7y ago
Really appreciate your input (and congrats!), Jason ;-) I have been running 2 simple standalone WireGuard VPN servers for remote access and encrypting traffic (2 EC2 instances inside a VPC, scripted configuration). Admittedly I didn't
70.
▲
by
terrywang
7y ago
Gravitational has built something called wormhole (clashes with magic wormhole, bad naming, isn't? Some other hold can be better) https://github.com/gravitational/wormhole It can be used to replace flannel if encr
71.
▲
by
terrywang
7y ago
Very exciting news, indeed! Finally WireGuard is in the Linux kernel 5.6 onwoards (will arrive soon in the next few days for those who are on rolling releases). I've been using WireGuard to replace IPsec (strongSwan - the whole stack i
72.
▲
by
terrywang
7y ago
Forgot to mention a potential problem with WireGuard, server keeps the list of clients' virtual IPs (AllowedIPs used for routing/ACLs), not ideal for VPN service providers in terms of privacy. It's not a problem for overlay n
73.
▲
by
terrywang
7y ago
Good news (rare) in Jan 2020 ;-) Using WireGuard to establish a mesh network seems good to start with but it does not scale well (even with the help of subspace web UI). Nebula (from Slack) seems to be a better option which is simple, secur
74.
▲
by
terrywang
7y ago
Before Boxer, everyone seems to be a bit reluctant to get Terran at random in a 1v1 game as it's relatively weak and requires lots of micro ops (high APM) to win against Zerg or Protoss ;-)
75.
▲
by
terrywang
7y ago
Good Read. StarCraft and the expansion set (Brood War) had huge influenced on my student days (they way of thinking, overview of strategies vs tactics, economy, resources). To some extent it helped me to find passion and inspired me to be t
76.
▲
by
terrywang
7y ago
Not the same crossing the Tasman sea. It's mixed in Australia. One can only have 5 pre-paid mobile numbers under 1 name (activation limit). However, you can still buy SIM packs from supermarkets or convenient stores, not sure if activa
77.
▲
by
terrywang
8y ago
Those decision makers (sign the POs) normally don't have insight into the IT industry ;-)
78.
▲
by
terrywang
8y ago
Correction: XenServer 6.2 and earlier dom0 is CentOS 5.x based, however it's kernel is based on SLES kernel.
79.
▲
by
terrywang
8y ago
Personally, I admire the fact that openSUSE polishes KDE and GNOME (Xfce4 as well) pretty well, satisfying details, really makes the effort to make the distro more user friendly and easy to use. However, I wouldn't use it as personal w
80.
▲
by
terrywang
8y ago
Almost thought this was an April fools joke (the app icon also makes it like more. While it's good to have option for non-technical people who needs to protect their network traffic and privacy, I'd stick to my own DIY WireGuard (
81.
▲
by
terrywang
8y ago
Haven't touched Pidgin or Adium for ages, although I've got them installed on Linux and/or macOS (really liked them). The way of IM has changed, so many social features added into IM making it more like a social chat profile
82.
▲
by
terrywang
8y ago
Here is another good article written by Shaohua's close friend Coly Li (who is the main bcache maintainer), a lot more details on the contributions (elegant code, performance patches, etc.) he has made to the Linux kernel, as well as h
83.
▲
by
terrywang
9y ago
- high quality information & comments (including famous people that I'd never meet in person or have a direct conversation/discussion) - passion for technology - probably the current job plus an once in a lifetime IPO experien
84.
▲
by
terrywang
9y ago
The title is very misleading. One should always use VPN to encrypt traffic when connecting to untrusted network (wired or wireless). Just use your DIY VPN (IPsec - strongSwan is very good option, or OpenVPN), don't use any free or untr
85.
▲
by
terrywang
9y ago
It's downloadable archive (searchable HTML format), file size is 707MB, the download link will be provided via email, it can be used up to 6 times before it expires forever ;-) You can directly save the file to Dropbox. BTW: Linux Jour
86.
▲
by
terrywang
9y ago
It's been quick this time for Kernel Newbies to come up with the newly released kernel changelog. For many kernel versions it took quite a while for the complete list to show up and some just refers to Phoronix articles or so. It think
87.
▲
by
terrywang
9y ago
SSH Dynamic forwarding (ssh -D) to do application-level port forwarding and configure browser to use remote host to do DNS lookup was 1 of the earliest techniques to bypass the GFW and was countered by the GFW long time ago. The wall can ea
88.
▲
by
terrywang
9y ago
Try to change the default port 1194 to something else (e.g. 443) - this may not help as the GFW has the ability to detect OpenVPN specific traffic. If it is only for yourself and traffic is very little, it may survive the period of your sta
89.
▲
by
terrywang
9y ago
Grew up in China (moved to Australia since early 2008) where GFW is in place and getting overwhelmingly powerful, I've been through multiple stages to cross the `great wall`, SSH Dynamic Forwarding, PPTP, OpenVPN and now IPsec (strongS
90.
▲
by
terrywang
9y ago
Highly recommend the Termux:Styling, most well known color schemes are available. The others are Boot, Widget, Fload, Task. Buy if you need or have $ to spare ;-)
More ›