HN user

EvanAnderson

17,024 karma

A boring, not-young, not-cool, not-working-at-a-startup IT generalist.

http://serverfault.com/users/7200/evan-anderson

Posts36
Comments3,840
View on HN
www.youtube.com 1mo ago

Five monitors on a Commodore 128 [video]

EvanAnderson
136pts36
news.ycombinator.com 1mo ago

Ask HN: Non-profit school possibly hacked, locked out of Google Workspace.

EvanAnderson
6pts2
thebuild.com 2mo ago

Pgxbackup: Continuity Support for PgBackRest

EvanAnderson
4pts0
pluralistic.net 6mo ago

The Post-American Internet

EvanAnderson
577pts456
www.experimental-history.com 10mo ago

Bag of words, have mercy on us

EvanAnderson
1pts0
hardwarehacks.org 1y ago

Installing AIX PS/2 v1.3 on a 486

EvanAnderson
24pts14
www.youtube.com 1y ago

Speedy Cutover Service, SXS switching cutover to ESS [video]

EvanAnderson
1pts0
design-of-forms.online 1y ago

The Design of Forms in Government Departments

EvanAnderson
2pts0
labs.watchtowr.com 1y ago

Palo Alto PAN-OS CVE-2024-0012 and CVE-2024-9474

EvanAnderson
1pts0
pdx.su 2y ago

Fixing a broken smart cat feeder with ESP32

EvanAnderson
87pts51
pdx.su 2y ago

Fixing a broken smart cat feeder with ESP32

EvanAnderson
6pts7
deater.net 2y ago

Second Reality for Apple II

EvanAnderson
117pts46
newnetworks.com 3y ago

The Book of Broken Promises: $400B Broadband Scandal and Free the Net

EvanAnderson
3pts0
www.johndcook.com 4y ago

Rare and strange ICD-10 codes

EvanAnderson
33pts12
www.dampfkraft.com 4y ago

A Spectre Is Haunting Unicode (2018)

EvanAnderson
268pts180
lite.cnn.com 4y ago

Iraqi Prime Minister survives exploding drone assassination attempt

EvanAnderson
53pts15
github.com 4y ago

Telemetry by tgauth · Pull Request #529 · PowerShell/OpenSSH-portable

EvanAnderson
4pts0
blog.dshr.org 5y ago

Unstoppable Code?

EvanAnderson
72pts51
blitter.net 5y ago

My Ken Williams Story

EvanAnderson
48pts1
status.solarwindsmsp.com 5y ago

Digital Certificate Update for MSP Products

EvanAnderson
1pts0
zend.to 5y ago

ZendTo – Web-Based File Transfer

EvanAnderson
2pts0
www.osr.com 5y ago

Microsoft: No Driver Updates Allowed for Win7 and Win8

EvanAnderson
147pts121
tumblr.beesbuzz.biz 6y ago

Advice to Young Web Developers

EvanAnderson
266pts318
www.youtube.com 6y ago

Antique 4x5 camera creates 20 micron photolithography masks [video]

EvanAnderson
164pts47
www.youtube.com 6y ago

Fossil Data Part 2: 8-Inch IBM Floppy Data Recovery [video]

EvanAnderson
1pts0
www.windowscentral.com 6y ago

Windows Search down for many – here's the fix

EvanAnderson
1pts1
lite.cnn.io 6y ago

Irish teenager may have a solution for a plastic-free ocean

EvanAnderson
2pts0
archive.oreilly.com 7y ago

DRM Helmets: An Idea Whose Time Has Come (2002)

EvanAnderson
5pts2
www.circleid.com 7y ago

Spurious Justifications for Eliminating Price Caps on .org and Other Legacy TLDs

EvanAnderson
4pts0
archive.oreilly.com 8y ago

DRM Helmets: An Idea Whose Time Has Come (2002)

EvanAnderson
3pts0

Speaking about hardware tokens:

If I have to go get the backup out of "secure" storage each time I want to add a new Passkey it's not really a backup.

The design should have allowed, even if it was just within only the purview of a single manufacturer, a method for the device to export an encrypted dump that could be reloaded onto a factory-new device. Heck, make it a value-added service that the manufacturer has to initiate and tie it to some real-world identity verification.

The idea of having to put backup devices in-hand regularly is a bad design.

Phone apps. get around this idiocy by backing-up the encrypted Passkeys to a hosted service.

PCjs Machines 1 day ago

Oregon Trail held up well but, man, Kings Quest is brutal with the killing you and having to start over.

Turning things on and off with a computer is always fun to me (think X10 modules, blinking LEDs with an Arduino, etc). That in itself makes this neat to me.

There's probably a way this could be used to floating batteries at around 80% on devices that support throttling their own charging.

That's an excellent link for getting down into the details. Thanks for posting it.

This editorial argues that the long-standing cap on residency slots, originating with the 1997 Balanced Budget Act, is the key structural constraint throttling the U.S. physician workforce.

In the 1990s, influential groups like the American Medical Association (AMA) and Association of American Medical Colleges (AAMC) had become convinced the U.S. faced an impending “physician oversupply.” In March 1997, just months before the BBA’s passage, a consortium of medical organizations, including the AMA, went so far as to recommend reducing the number of residency positions by 25% (from ~25,000 slots down to 19,000) to stave off a surplus [4]. “The United States is on the verge of a serious oversupply of physicians,” the AMA and others warned at the time.

(Not sure how I feel about the ideas the editorial poses about using ML in a supervisory capacity for residents, though...)

The number of Medicare funded residency slots are limited by law. Medical schools won't graduate more doctors because residency can't be guaranteed. Who wants to be the med school who graduates doctors with >$100K debt and no path to licensure?

In the 1990s the AMA lobbied congress to get the number of Medicare-funded slots limited. This was done in response to a projected "oversupply" of doctors (preventing a deflationary effect on doctors' compensation). That limit has stuck and now, even though the AMA is lobbying for the removal of the limit, the damage to the supply of doctors has been done and it's a process with a long pipeline.

The ACA made rescission of health insurance more difficult for insurers, but it absolutely happens. There are people at insurers tasked with looking for fraudulent omissions in policy applications for high loss ratio individual policyholders to target for rescission.

This one is pre-ACA but the insurer focused on an "omission" to justify the rescission: https://www.cnn.com/2009/POLITICS/06/16/health.care.hearing/...

I would agree that it's objectively terrible dealing with insurance companies, providers who are incredulous you care about the pricing of services, etc. There is no free market for healthcare services. Advocating for yourself is tremendously draining.

I'm happy with the ROI I've had with my insurance premiums over my life. I haven't had a catastrophic event but I've certainly had reasonably sizable claims. If I'd invested the last 20+ years of premium expense (about $400K to date) and had no claims I'd have a ton more money, but not enough to cover a catastrophic event later in life. The principal would also have been completely wiped-out a couple of times when I did have claims, however.

I pay the premiums because I'm not comfortable holding bets on both the market and on my health. I'm also unwilling to consider bankruptcy as a morally / socially acceptable solution.

This mixed socialized and capitalist "system" we've allowed to grow up feels like the worst possible one. Healthcare and health insurance expense are a mechanism to extract value from the middle class (i.e. everyone who has money but isn't wealthy enough to buy their way out of the "system").

My preference would be for a fully socialized system, built primarily around protection for catastrophic loss, where everyone contributes w/ no opting-out permitted.

Failing that I'll grudgingly take a fully capitalist system where people who can't afford to pay are left to fend for charity or die.

What we've got is a mix of the worst parts of both.

Every player in the US healthcare / health insurance "system" has adapted to the regulatory niche they play in.

If Americans had the fortitude to have grown-up conversations about what should be socialized, how care should be rationed, etc, the public could exert some control over the design of the "system". As it stands, the "system" has mostly been shaped by corporate interests while the public has been distracted by inflammatory rhetoric pumped-out by all the entrenched players designed to play to partisan feelings about "fairness" and "freedom".

If you have enough money for that gamble to pay off over the long haul the cost of health insurance would be immaterial to you anyway. You might get away with it in your youth, or you might have a catastrophic loss and have your finances wrecked.

You're often able to negotiate discounts for cash payment from providers, but back when I had insurance that excluded a pre-existing condition I ran into providers who steadfastly demanded the full list price (under threat of collections). It only takes one of those standing pat on a high 5 or low 6-figure bill to cause you to lose on your "bet".

Tierra[0], written by Tom Ray[1], immediately comes to mind. I was captivated when I read about it, as a teenager, in Steven Levy's "Artificial Life"[2]. Having played Core War[3], the description of Tierra in Levy's book inspired me to play around with making a virtual machine in Turbo Pascal and trying my hand at making a pale and naive clone. It was a lot of fun, and arguably has influenced a lot of my thinking about the origin of biological life.

[0] https://tomray.me/tierra/whatis.html

[1] https://en.wikipedia.org/wiki/Thomas_S._Ray

[2] https://www.stevenlevy.com/artificial-life

[3] https://en.wikipedia.org/wiki/Core_War

What happened to the original code (it wasn't in escrow somewhere?) ...

It seems like the early video games industry did a pretty bad job of preserving development artifacts. There have been a lot of stories about game code being found, but it seems to be the exception rather than the rule.

I don't call it a "dead man's switch", but I absolutely monitor some directories for new newest file. If the backup monitoring script doesn't find a file less than 24-ish hours old in the backup destination directory at any time it should send me an alert.

Microsoft made a product based on SLM called Delta[0]. I'd never heard of it until that Youtube video came up.

SLM's "architecture" reminds me a lot of Microsoft Mail postoffices-- a file share that every user interacts with and no actual server-side code (i.e. just using file sharing semantics for clients to interact). (Lots of apps, not just MSFT, did that back in the 90s and it was _hell_.)

Based on what I've read about source control at Microsoft I'd guess Comic Chat straddled the use of both SLM and Source Depot (post W2K, from what I've seen).

[0] https://www.youtube.com/watch?v=8bNLp_oTuNM

The future product will tunnel all the connections from the inner browser over an opaque pipe (like WebSockets) with the encryption handled by the inner browser (and using cert. pinning).

I've been waiting for this to happen.

The websites that don't want you to block ads will serve you an obfuscated "inner browser" that will render their site. All your ad blockers, etc, are rendered moot.

Once accessibility is solved this is absolutely going to be a thing on major websites.

It's shocking how loud even small ICE engines are. I drove a Geo Metro back in the 90s, with it's tiny little 1.0L motor (with 45 and 1/2 angry little horses-- and the half horse is the angriest of them all) and between the exhaust resonator and muffler rusting out I got to hear how loud a little motor is. Shockingly loud.

At one point my wife's 1995 Civic had a busted exhaust pipe ahead of the muffler and was loud as hell. She reported receiving compliments from a few different Civic enthusiasts, much to her confusion.

She just wanted me to fix the broken pipe.

In our family we use the expression "farting Honda" (or Toyota, Subaru, whatever) when we hear these kinds of cars on the road.

Zow! I had no idea FirstClass was a BBS server. I had a Customer in the early 2000's who was using a FirstClass server on a LAN for email, calendaring, and collaboration. It struck me as a really neat piece of software, albeit I would have preferred a web interface to the thick Win32 client. It was very well thought-out software, albeit I didn't have to sysadmin the thing (so I don't know what the back-end was like in terms of reliability, backup/restore, fault tolerance, etc).

I'm off to go down a rabbit hole re: the FirstClass software.

I generally suspect folks would be a lot happier if they'd had a few more crap jobs as a baseline!

I'll go one further. Not only should everybody have to do a crap job or two, but they should have to work with the public. Imagine how much more chill people would be with service workers having had the experience of being one themselves.

I'd argue all self-replicating systems subject to entropy (i.e. existing in the physical world) are automatically subject to mutation and natural selection and, therefore, alive and able to evolve around any innate goals or constraints. If the inmate goal isn't tied to a highly-conserved phenotype I would think the goal would disappear as mutations accumulate and natural selection takes its toll.

I love HN for this kind of serendipity.

I used Apple Writer in on Apple II machines in my public library in the 80s. I can't say I remember a ton about it but it's definitely a name I remember. I remember using AppleWorks on the machines at school, but I liked Apple Writer better and lamented that I wasn't permitted to use it at school (because the teacher said she wasn't familiar with it and couldn't help me if I had problems).

Hairpin NAT (or "NAT hairpinning") is the term for "...connecting from inside local network the router recognize that by connecting to public IP, he has to route it back onto some local IP address", and the Linux NAT implementation supports it.

For a homelab situation split-horizon DNS is just fine. You're going to have minimal duplication of records from the public DNS into the private DNS.

The canonical frustrating "bad split-horizon DNS" world I've seen, time and again, is a corporate network with a MSFT Active Directory named the same as the company's public-facing web property (e.g. "example.com" rather than "ad.example.com"). This creates the need to duplicate all the public-hosted resources into the internal "example.com" zone (and keep them updated when records inevitably change on the public Internet). It's make-work for no practical upside in that example.

I feel like I did. >smile<

Use DNS validation to allow these internal services to pull ACME certs...

The major ACME clients support DNS validation. If your DNS host doesn't have an API that your ACME client supports either get a new ACME client or a new DNS host.