HN user

anticristi

1,699 karma

Cloud architect, speaker and researcher. Father of two. Inline skater.

https://cristian.kleinlabs.eu

Posts29
Comments555
View on HN
news.ycombinator.com 2y ago

Ask HN: How do you check out at the end of the working day?

anticristi
3pts2
cristian.kleinlabs.eu 2y ago

Is Ubuntu Linux spying on you?

anticristi
6pts4
cristian.kleinlabs.eu 3y ago

Please Stop RTFM-Ing

anticristi
2pts0
cristian.kleinlabs.eu 3y ago

Designing Microservices Effectively

anticristi
2pts0
cristian.kleinlabs.eu 3y ago

Leap Seconds: When the cure is worse than the disease

anticristi
1pts0
news.ycombinator.com 4y ago

Ask HN: Where can I find public domain score sheets for free?

anticristi
1pts2
elastisys.com 4y ago

We Selected Thanos for Long Term Metrics Storage

anticristi
1pts0
elastisys.com 4y ago

DevOps: Why it is misunderstood and what it always should have been

anticristi
2pts0
elastisys.com 4y ago

Principles for Designing and Deploying Scalable Applications on Kubernetes

anticristi
3pts1
edpb.europa.eu 4y ago

GDPR right to erasure does not apply in front of God

anticristi
1pts0
noyb.eu 5y ago

Noyb aims to end “cookie banner terror” and issues more than 500 GDPR complaints

anticristi
2pts1
en.wikipedia.org 5y ago

360-Day Calendar

anticristi
2pts0
cristian.kleinlabs.eu 5y ago

Net Neutrality and Data Sponsorship: Can we have both?

anticristi
2pts0
www.bbc.com 5y ago

Europe seeks to limit use of AI in society

anticristi
156pts147
news.ycombinator.com 5y ago

Ask HN: How does it feel to be a dark pattern programmer?

anticristi
15pts15
www.cncf.io 5y ago

What Was Observability Again?

anticristi
2pts0
elastisys.com 5y ago

What do I need to add on top of Kubernetes?

anticristi
4pts0
news.ycombinator.com 5y ago

Ask HN: How quickly should ADRs be implemented?

anticristi
3pts0
news.ycombinator.com 5y ago

Ask HN: Can I trust brokers with my stocks?

anticristi
52pts63
elastisys.com 5y ago

What Was Observability Again?

anticristi
3pts0
elastisys.com 5y ago

Top cloud-to-cloud migration woes and how to solve them

anticristi
3pts0
compliantkubernetes.com 5y ago

Compliant Kubernetes 0.9.0 supports multiple workload clusters

anticristi
4pts0
elastisys.com 5y ago

How to set up Kubernetes on Exoscale

anticristi
6pts0
elastisys.com 5y ago

How to set up Rook with Ceph on Kubernetes

anticristi
2pts1
cristian.kleinlabs.eu 5y ago

Rational Design Process: How and Why to Fake It

anticristi
4pts0
cristian.kleinlabs.eu 5y ago

Generalized Leaky Abstractions

anticristi
1pts0
news.ycombinator.com 5y ago

Ask HN: Physical work creep in IT jobs, the root cause of unconscious bias?

anticristi
5pts10
news.ycombinator.com 6y ago

Zoosk Spam: Ignore or remind them about GDPR?

anticristi
1pts1
news.ycombinator.com 6y ago

Ask HN: Is using my personal information for scam a GDPR violation?

anticristi
6pts5

Interesting angle: Compiler errors brings back math teacher trauma. I noticed Rust tries to be a bit more helpful, explaining the error and even trying to suggest improvements. Perhaps "empathic errors" is the next milestone each language needs to incorporate.

Where I work, we have company-wide breaks between 10.00-10.15, 12.00-13.00 and 15.00-15.15. These cannot easily be enforced with external parties, but running an internal meeting over a break will need an explanation. What I noticed is that back-to-back meetings are more likely "capped" at 2 hours, so it's easier for people to show up on time and energized.

This is great news! Who would have expected Cloudflare to truly contribute to EU digital sovereignty.

On a more serious note, I'm surprised Cloudflare wants to pull out of Italy. Being a company which terminates TLS connections for Italy must be a gold mine for the NSA.

Whether the claims are true or not, this was a very entertaining BGP refresher. It made me wonder: 15+ years ago, I was network engineer and we used quite a bit of "BGP community magic" to get the routing outcomes we wanted.

If BGP only really needed to represent three types of peers (provider, customer, actual peer), wouldn't BGP configuration and perhaps even BGP be massively simplified?

Well said! I used to administer both FreeBSD and Linux (Debian) servers at the same time. I found them different, but couldn't say either was better or worse.

How about trying out legal solutions against browser fingerprinting? The European Data Protection Board -- i.e., the union of "GDPR Police" in each EU Member State -- made it clear the fingerprinting violates the ePrivacy Directive.

No adblocker detected 11 months ago

That's what I love most about using ChatGPT vs Google for finding information: less bloat, just what I asked for.

This is really scary. It could have totally happened to me too. How can we design security which works even when people are tired or stressed?

Once upon a time, I used a software called passwordmaker. Essentially, it computed a password like hash(domain+username+master password). Genius idea, but it was a nightmare to use. Why? Because amazon.se and amazon.com share the same username/password database. Similarly, the "domain" for Amazon's app was "com.amazon.something".

Perhaps it's time for browser vendors to strongly bind credentials to the domain, the whole domain and nothing but the domain, so help me Codd.

I work as a Data Protection Officer, which is a legal role under GDPR, and am rather unimpressed by GPC. I could whine for a day, but among the most problematic issues: It's not clear if "Sec-GPC: 0" should be interpreted as:

1. "no" to collect personal data under GDPR consent; or 2. "objection" to collect personal data under GDPR legitimate interest or; 3. "no" to retrieving and storing data on a user device (e.g. cookies, localStorage); or 4. A linear combination of the above.

Personally, I think we should simply fine the heck out of all websites until they all feature a "Reject all" button. No need for browser vendors to propose standard which at least one browser vendor can't be bothered to implement.

There is something about the "moving humans" part in the article that doesn't hold water.

From what I noticed, dentists use fingers 4 and 5 to track the movement of the head or jaw. I saw no such tracking in this robot, with the article simply making a handwavy "trust AI" argument.

In general, I think if robots are to overdo humans, they should do that with improved sensors and actuators, not just "enough AI".

Sjunet also uses public IP, but never exposes those on the Internet. No clue why, probably it turned out to be the easiest solution to avoiding collision with private ranges used at all member organizations.

My understanding is that the members need to sign a contract to join Sjunet. I'm not sure of penalties, but being kicked out of Sjunet is likely an incentive for decent IT staffing.

In Sweden, there is a private network (Sjunet) which is isolated from the Internet. It is used by healthcare providers. Its purpose is to make computers valuable communication devices (I love how the article points this out), but without exposing your hospital IT to the whole Internet. Members of Sjunet are expected to know their networks and keep tight controls on IT.

I guess Sjunet can be seen as an industry-wide air-gapped environment. I'd say it improves security, but at a smaller cost than each organization having its own air-gapped network with a huge allowlist.

The EU DORA regulation (Digital Operational Resilience Act for Financial Entities) has explicit provisions to avoid concentration risks. I heard a story that a bank was forced to use Google Cloud, because two other banks were already on AWS and Azure.

It sounds to me near-impossible to convert C or C++ into as-safe-as-possible Rust code, because the original intention of the developer are missing. However, I wonder if some clever generative AI could be taught to recognize sufficient C programming patterns in relevant code bases to make the problem tractable.

The proposed EU Cyber resilience Act positions itself to be a solution. To put it simply, vendors are responsible for vulnerabilities throughout the lifetime of their products, whether that is a firewall or a toaster. Thus, the vendors are incentives to keep OSS secure, whether that means paying maintainers, commissioning code audits or hiring FTEs to contribute.

But wait. There’s more. With the team growing, how are we supposed to manage shared resources? Do I have to run tf apply, wait for completion, and then immediately commit and push, and hope I don’t have to manually manage a state file merge conflict? Or should I use some bizarre, self-built mutex?

In one project, we had Terraform run from GitLab CI. The CI was creating a plan. The reviewer had to approve applying that plan.

I'm curious about your usage of Ansible for AWS resources. How do you delete them? Do you have a policy of always having 'state: absent' for at least one commit?