HN user

Perceptes

2,067 karma
Posts72
Comments263
View on HN
www.executeprogram.com 7y ago

Execute Program: Learn programming tools fast. Then remember them.

Perceptes
4pts0
github.com 7y ago

Sear: An always-encrypted tar-like file archive format

Perceptes
48pts7
matrix.org 7y ago

Matrix.org Security Incident

Perceptes
74pts15
blog.seantheprogrammer.com 7y ago

Moving on from Rails and What’s Next

Perceptes
146pts86
blog.cryptographyengineering.com 8y ago

Attack of the week: DUHK

Perceptes
2pts0
blog.cryptographyengineering.com 8y ago

Falling through the KRACKs

Perceptes
3pts0
www.kloepfer.org 9y ago

Implementing IPv6 in a Home Network (2012)

Perceptes
2pts0
news.ycombinator.com 9y ago

Ask HN: Which wireless router do you use at home?

Perceptes
39pts83
www.jimmycuadra.com 9y ago

The highs and lows of Rust (2017)

Perceptes
7pts0
blog.cryptographyengineering.com 9y ago

The Future of Ransomware

Perceptes
2pts0
coreos.com 9y ago

CoreOS Tectonic Now Ships with HA Clusters by Default and Extends Installer

Perceptes
2pts0
coreos.com 9y ago

Quay: Introducing an Application Registry for Kubernetes

Perceptes
4pts0
github.com 9y ago

Tectonic Installer

Perceptes
3pts0
github.com 9y ago

Torus development has been stopped at CoreOS

Perceptes
124pts58
writing.kemitchell.com 9y ago

Feedback on the default contributor license in GitHub's draft terms of service

Perceptes
2pts0
github.com 9y ago

Steed: Rust's standard library, free of C dependencies, for Linux systems

Perceptes
23pts0
www.ruma.io 9y ago

This Year in Ruma, 2016

Perceptes
3pts0
blog.kubernetes.io 9y ago

Kubernetes 1.5: Supporting Production Workloads

Perceptes
2pts0
www.jimmycuadra.com 9y ago

The relationship between async libraries in Rust

Perceptes
2pts0
www.ruma.io 10y ago

Introduction to Matrix

Perceptes
14pts2
github.com 10y ago

CoreOS quayctl, a CLI for pulling ACIs and Docker images over BitTorrent

Perceptes
3pts0
www.ruma.io 10y ago

[Rust] This Week in Ruma, April 24, 2016

Perceptes
3pts0
www.jimmycuadra.com 10y ago

The highs and lows of Rust

Perceptes
6pts0
github.com 10y ago

Show HN: Ktmpl: Parameterized templates for Kubernetes manifests

Perceptes
3pts0
blog.cryptographyengineering.com 10y ago

On the Juniper backdoor

Perceptes
262pts48
www.youtube.com 10y ago

Incident Management from the Future [video]

Perceptes
1pts0
www.youtube.com 10y ago

OpenChatOps: Programming language agnostic ChatOps [video]

Perceptes
1pts0
coreos.com 10y ago

Official CloudFormation and kube-aws tool for installing Kubernetes on AWS

Perceptes
1pts0
github.com 10y ago

Show HN: Ghlabel: Easily use a custom set of default labels in GitHub Issues

Perceptes
2pts0
github.com 10y ago

Lita 4.6 released with support for chat-service-specific APIs

Perceptes
1pts0

Location: Oakland, CA

Remote: Exclusively

Willing to relocate: No

Technologies: Rust, Axum, Ruby, Ruby on Rails, TypeScript/JavaScript, Node.js, PostgreSQL, Python, Flask, AWS, Docker, Kubernetes

Résumé: https://www.jimmycuadra.com/jimmy_cuadra_resume.pdf

Email: jimmy@jimmycuadra.com

I was laid off by Cisco Meraki last summer, where I spent four years as a technical lead for the cloud side of the wireless products. I have experience in both web development and cloud infrastructure roles.

I have worked for years in open source software development. I created and ran two notable open source projects: Lita, a ChatOps framework for Ruby (https://github.com/litaio/lita) which is used by many companies for automating internal operations and workflows, and Ruma, an implementation of the Matrix protocol in Rust (https://ruma.dev/) which went on to become the basis for the official Rust SDK for Matrix.

My ideal role would be building software targeting other developers, either as a member of a developer tools team, or for a company whose products are made for developers. I'm also drawn to companies building "neutral" utilities whose value is fairly self-evident: Things like PagerDuty and Stripe which are generally useful and provide the infrastructure needed for other things to work.

I would love to use Rust professionally, but I'm fine with other languages, too. I'd also be very happy to work on a product with an amount of open source code, given my background working on OSS projects.

Location: Oakland, CA Remote: Yes, only Willing to relocate: No Technologies: Rust, Axum, Ruby, Ruby on Rails, TypeScript/JavaScript, Node.js, PostgreSQL, Python, Flask, AWS, Docker, Kubernetes Résumé: https://www.jimmycuadra.com/jimmy_cuadra_resume.pdf Email: jimmy@jimmycuadra.com

I was laid off by Cisco Meraki last summer, where I spent four years as a technical lead for the cloud side of the wireless products.

I have worked for years in open source software development. I created and ran two notable open source projects: Lita, a ChatOps framework for Ruby (https://github.com/litaio/lita) which is used by many companies for automating internal operations and workflows, and Ruma, an implementation of the Matrix protocol in Rust (https://ruma.dev/) which went on to become the basis for the official Rust SDK for Matrix.

Submitting this re: the recent discussion about PGP alternatives. It seems right in line with the types of tools that were being suggested for replacing specific use cases of PGP. Written by Tony Arcieri, who is well-regarded in the cryptography community.

The PGP Problem 7 years ago

I'd also be interested to hear Thomas clarify this. I saw a recent thread on Twitter where he and bascule were talking about it and it still wasn't super clear, but one specific point I recall is that Matrix has a significant amount of metadata stored on the server side which constructs a social graph. As opposed to something like Signal which has close to nothing stored on the server.

To me this seems like an issue of use case. If my goal is to be able to talk to my family and friends, and I don't care that it's known that I'm talking to them as long as the contents of the messages are private, that is fine for me. For a case with more stringent requirements, I can see Matrix not being a good recommendation in its current design.

The PGP Problem 7 years ago

I guess one difference here is that often major implementations of HTTPS make the best choices (like operating systems, major browsers, major web server software, etc.), whereas with something like PGP, everyone is using GPG which has only one implementation which is known to be terrible.

I don't know how I never heard about 1Password X. The last time I attempted to switch from macOS to Linux, the lack of 1Pasword was one of the biggest things that made it hard for me.

That said, a browser-based 1Password is really not what I want. I just really don't try web technologies for keeping my passwords safe. If I really was going to use it, this might be the only instance in which I'd actually prefer an Electron version to using it my main browser, just for the additional isolation.

I'd never heard of Boxcryptor. Does anyone else use this? I'm not sure I understand why I need to sign up for an account to use it if its entire purpose is to do client-side encryption.

Also, it's not quite the same functionality, but this also reminds me: For a long time I've used Knox (by AgileBits, the same company that makes 1Password) for encrypted disk images, but they no longer sell or maintain it. It works just fine, but I should probably find a replacement that's still maintained, at least for security updates. Anyone know a good alternative? VeraCrypt (mentioned in the article) seems like one possibility.

I desperately hope this is true. I have the first MacBook Pro that came with the Touch Bar, and it's the worst computer I've ever owned. The keyboard has failed twice, and the Touch Bar is inferior to the old hardware keys in every way. I hate it. The only reason I got it is because the MacBook Air it replaced was dying and I couldn't wait any more. Assuming this report is true, my only remaining worry is that they won't offer a version of this new Pro without a Touch Bar, or that only a model with a smaller display will offer hardware function keys, like they've done in the past.

It's been a while so the details are not fresh in my mind, but it wasn't the easiest thing in the world. I think most of my trouble came from the general lack of polish on Kubernetes (from a cluster operator's perspective) than from the specifics of the Raspberry Pi. One thing I remember clearly is that kubeadm has completely failed to upgrade k8s from one minor version to the next every time I've tried it. I always end up just saving my k8s resources, blowing away the cluster, creating a new one, and resubmitting the resources to the new cluster.

I have several of them:

* 1 original model that runs pi-hole for the household

* 1 RPi 3 running RetroPie for emulating classic video games

* 1 RPi 3 connected to an official RPi touch screen display that runs a Home Assistant UI

* 4 RPI 3s running as a Kubernetes cluster, mostly just for the fun of setting it up, but I have a few odd jobs that run on them, such as chat bots

I don't have a picture of the cluster all hooked up, but this is what it looks like without any cables attached: https://twitter.com/jimmycuadra/status/846935997619200000

Similar results for me. Does anyone know if it's possible to turn off WebGL, and if so, how? AFAIK I never use it for anything and I'd rather have increased anonymity. (Assuming disabling it prevents it from being used for fingerprinting.)

Edit: Answering my own question. In `about:config`, change the `webgl.disabled` preference from `false` to `true`. This reduced the "bits of identifying information" from WebGL from 11.26 to 2.56.

Edit 2: Apparently the CanvasBlocker add-on is a better solution as it randomizes the data used for fingerprinting on each read, and works for several exploitable APIs, not just WebGL. https://addons.mozilla.org/en-US/firefox/addon/canvasblocker...

Did this issue cause all add-on data to be wiped? After updating to 66.0.4, all of the containers I'd created with the multi-account containers add-on were gone and replaced with what appeared to be a default set of containers. I spent a lot of time setting that up—is there no way to get it all back if I don't have some sort of manual backup? And if not, what files do I need to manually back up to make sure I don't lose my data next time?

Edit: To be clear, at no point did I delete the add-ons I had installed.

But it does seem to be the case that the same SSH key pair that was used to access Jenkins also provided access to the production infrastructure. Unless I'm misunderstanding the nature of the attack.

Rust 1.34.0 7 years ago

The history of TryFrom/TryInto has spanned 3 years, from when it was originally proposed as an RFC in 2016. For a seemingly simple API, it's gone through a lot. Especially unusual was that it was stabilized a few releases ago and then had to be destabilized when a last-minute issue was discovered with the never type (`!`). The never type had been the primary blocker for stabilizing these APIs for the last year or so, but it was finally decided to simply use this temporary `Infallible` type, which would be mostly forwards compatible with the never type itself.

I've followed the issue closely because it's one of the features used in Ruma, my Matrix homeserver and libraries. In fact, for the library components of the project, it was the last unstable feature. With the stabilization of these APIs, I'll finally be able to release versions of the libraries that work on stable Rust. This will happen later today!

It makes me sad that people continue to put their time and effort into supporting these closed communication systems. If anyone else is considering making something like this, please base your efforts on Matrix. It's so much better for us and so much more deserving of our attention.

I wish this had gone into some more technical detail about what "CNB" does that is actually better. Most of the article was just rehashing some problems with Dockerfiles, but the conclusion is just "CNB fixes it!" The one specific improvement they mention is being able to "rebase" an image without rebuilding the whole thing, which certainly sounds interesting, but is not explained. How does it work? What else is CNB other than a wrapper around `docker build`?

I'm the original creator of Ruma, another homeserver implementation, and our project has received nothing but support and appreciation from the Matrix team. It's true that Synapse is the only homeserver that is in a "finished" state, but that has more to do with Matrix being young, the spec still needing work (although it's come a long way recently), and the lack of time and resources to complete such a big project if it's not your full time job.

It's probably worth making this clear up front. If I see that a service is free, I assume advertisements as a business model, which I believe is fundamentally at odds with any claims of privacy and transparency, which your service also claims. If the users are not paying you, your financial incentive to protect their privacy is not clear.

I'm the creator of Ruma, and so I can confirm this. :}

For anyone interested, a detailed list of what is blocking or slowing progress can be found here: https://github.com/ruma/ruma/issues/189

Up until very recently we'd been postponing work due to immaturity of both Rust and the Matrix spec. Now that all the Matrix specs have had stable releases, the main blocker is the maturity of async/await and support for it in the library ecosystem. Since Ruma uses nightly Rust currently, we don't need async/await to be stabilized to proceed, but it does need to be far enough along that it has been adopted by all the major components of the Rust HTTP ecosystem. I'm guessing we've got about six months left until this happens.