Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
zrm
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
121.
▲
by
zrm
2y ago
What you're referring to is politics. Different people have different preferences, often because they're more familiar with one of them, or for other possibly good reasons. Somehow you have to decide who wins.
122.
▲
by
zrm
3y ago
It can solve the same problem, but it also solves it better. If you're using DoH to e.g. Cloudflare, Cloudflare can still see all of your DNS queries. If your own local device operated recursively using DNSCurve to the authoritative se
123.
▲
by
zrm
3y ago
The root ('.') is also variously treated as a label or ignored, so beware the off-by-one errors.
124.
▲
by
zrm
3y ago
DoH typically encrypts the connection between the client and the recursive DNS server, and TLS is reasonably suitable for this because the client is always querying the same server and can keep the connection open or use session resumption.
125.
▲
by
zrm
3y ago
Assuming there isn't another commit somewhere modifying a library-provided error string or anything returned by libc. There is all kinds of mischief to be had there, which may or may not have already happened, e.g. now you do some i18n
126.
▲
by
zrm
3y ago
Shouldn't either of these allow the site to ban them and then block anyone from signing up again with the same credit card?
127.
▲
by
zrm
3y ago
Keep one copy in your fire-resistant safe at home. Then encrypt a copy, give the encrypted copy to your best friend and the decryption key to a family member, or keep one of these things in your desk at work. Neither of them have access unl
128.
▲
by
zrm
3y ago
Planes use two engines because they can land with one and smaller jet engines are about as complicated as larger ones. Ships have different constraints. For example, a lower output diesel engine could have fewer cylinders and correspondingl
129.
▲
by
zrm
3y ago
> Maybe there's some lighter weight interventions we could do that would further halve the risk of something like this happening that are less costly than fully redundant engine and drive. Redundancy doesn't inherently have to
130.
▲
by
zrm
3y ago
And starting Google is the high-risk high-reward thing.
131.
▲
by
zrm
3y ago
It's expecting the high reward which is high risk. Creating a small business that can trudge along and pay you a modest salary is fairly common.
132.
▲
by
zrm
3y ago
Startups are high-risk high-reward. That doesn't necessarily mean they're a bad idea. Expected value can be positive even when probability is low. Moreover, a lot of young people can afford to take a chance on something. If you sp
133.
▲
by
zrm
3y ago
> Remember that a lot of mathematics is converting your system into another system Claude Shannon had something to say about this as I recall. > Do you have another suggestion? Because I don't see how code, English, or literally
134.
▲
by
zrm
3y ago
Wouldn't they just buy over the internet?
135.
▲
by
zrm
3y ago
What stops them from using a SIM card from any country that doesn't require registration?
136.
▲
by
zrm
3y ago
Which is why rate limiting by phone numbers doesn't work against them either, as you've noticed. If they have $5 in assets to burn then they can buy a $5 prepaid SIM card.
137.
▲
by
zrm
3y ago
In that case why not have an alternative where you pay $5 in cryptocurrency? It costs no more than that to get a phone number, meanwhile you now have more money in the development fund.
138.
▲
by
zrm
3y ago
> This is getting worse with ML clusters. Is it? What causes there to be unused capacity when there is currently so much demand for training?
139.
▲
by
zrm
3y ago
> You’ll still ban at least /64 and you’ll switch to /48 for the particularly nasty ones. The entire /64 will nearly always be a single ISP customer, not thousands of customers behind one address as it can be for IPv4. And
140.
▲
by
zrm
3y ago
What I'm asking is, how is this unique to self-hosting? You set them up on Cloud Email and it asks for a phone number to create an account, then they find out some debtor used to have their phone number and they're getting calls f
141.
▲
by
zrm
3y ago
> a 2FA email confirmation with random 6-digit code would be sent where? To _my_ email, not theirs. So you set up an email account specifically for those, and put the credentials for it in the documentation. You probably want that to b
142.
▲
by
zrm
3y ago
> if you have an open source project, why do you need a TLD? Why is that special? It's not really a matter of whether it's a TLD, though that makes more sense in this context because putting it under some existing TLD like .org
143.
▲
by
zrm
3y ago
DNS has a design flaw where the responses are often much larger than the requests, so dropping the response could reduce bandwidth use by a factor of ten or more.
144.
▲
by
zrm
3y ago
> There was a very large, um, "discussion" about whether or not there should be a registration system for alternate spaces when many of the alternate spaces were being specifically designed because they hated registration syste
145.
▲
by
zrm
3y ago
We're not talking about taking down the root servers, we're talking about the root servers mitigating the attack by dropping requests for that specific .com domain name. That would have no effect on any recursive resolver that had
146.
▲
by
zrm
3y ago
This doesn't help much to prevent collisions though, does it? An alternate namespace is obviously not going to use a TLD that already exists in the DNS, but it's much more likely to use one that exists in a different alternate nam
147.
▲
by
zrm
3y ago
That isn't necessarily incompatible with alternate domain name systems. If OpenNIC is registering names under .pirate and ICANN is aware of this then it can simply refrain from using .pirate as a TLD and you still have a unified namesp
148.
▲
by
zrm
3y ago
> Either your domain names are universally accessible, or someone needs to follow specific instructions to use them, in which case why use AlterNIC or OpenNIC, when you could just give instructions that were specific to your chosen domai
149.
▲
by
zrm
3y ago
> I doubt they thought they'd take down the root servers, but it seems totally reasonable that they might have wondered if the root server operators would filter DDoS traffic based on the domain name appearing in the requests. Which
150.
▲
by
zrm
3y ago
Is it permissible to set DF on a datagram which is already fragmented? Or if not formally impermissible, does it trigger some interesting bugs in something that assumes DF set = not fragmented?
More ›