HN user

buro9

24,701 karma

barely active on here now, VP Eng @ Grafana Labs

Posts116
Comments3,460
View on HN
www.lfgss.com 1y ago

Lfgss shutting down 16th March 2025 (day before Online Safety Act is enforced)

buro9
798pts545
cyberplace.social 1y ago

The Blue Yonder SaaS ransomware incident is bad

buro9
4pts3
labaneilers.com 1y ago

Prometheus Vendor Death Match

buro9
1pts0
remarkable.com 1y ago

ReMarkable Paper Pro

buro9
664pts546
fosstodon.org 1y ago

Organic Maps Removed from Play Store Due to "Requirements for Family Program"

buro9
43pts6
www.backblaze.com 2y ago

Smart 22 Is a Gas, Gas, Gas (2015)

buro9
3pts0
grafana.com 2y ago

Translate Datadog Metrics into OTLP

buro9
74pts10
remarkable.com 2y ago

ReMarkable

buro9
4pts3
djmag.com 2y ago

Spotify demonetizes all tracks under 1k streams

buro9
357pts408
social.treehouse.systems 2y ago

VLC can't update on Android without giving Google private signing keys

buro9
116pts60
github.com 2y ago

Redis License Changed

buro9
289pts1
www.independent.co.uk 2y ago

Wheel falls off United Airlines Boeing 777 and crushes cars in San Francisco

buro9
18pts16
www.theguardian.com 2y ago

Nose wheel falls off Boeing 757 airliner waiting for takeoff

buro9
29pts13
www.techdirt.com 2y ago

Substack Turns on Its 'Nazis Welcome ' Sign

buro9
11pts0
kottke.org 2y ago

Substack explains why they are paying Nazis to publish on their platform

buro9
5pts9
www.experian.co.uk 2y ago

Experian Consumer Product Privacy Policy

buro9
1pts1
blog.janissary.xyz 2y ago

Using Tailscale Custom OIDC with Authelia and Carpal

buro9
1pts0
apps.london.gov.uk 2y ago

London Street Trees

buro9
139pts73
grafana.com 2y ago

Grafana Pyroscope 1.0: continuous profiling for a modern OSS observability stack

buro9
10pts0
github.com 2y ago

Grafana Pyroscope v1.0.0 Release

buro9
6pts1
hoodmaps.com 3y ago

Crowd sourced city overview maps

buro9
1pts0
issuetracker.google.com 3y ago

Tell HN: Google App on Android is draining batteries within hours

buro9
5pts2
apps.london.gov.uk 3y ago

London Street Trees

buro9
4pts0
news.ycombinator.com 3y ago

Ask HN: Why isn't WiFi calling totally free?

buro9
3pts8
grafana.com 3y ago

Pyroscope and Grafana Phlare join together

buro9
187pts21
www.marksaunders.com 3y ago

Tricky and the Making of Maxinquaye

buro9
1pts0
twitter.com 3y ago

Workers at Monzo notified senior management of their intention to form a union

buro9
2pts1
www.independent.co.uk 3y ago

US sanctions on Chinese 'decapitate' semiconductor industry

buro9
5pts5
www.forbes.com 3y ago

Adam Neumann’s New Startup Sounds a Lot Like One He Invested in Two Years Ago

buro9
5pts0
twitter.com 3y ago

Collapse of emergency healthcare in England may be costing 500 lives every week

buro9
270pts442

and in a single moment, the value of software patents to companies is fully restored... the software license by itself is not enough to protect software innovation, a non-trivial implementation can now be (reasonably) trivially re-implemented.

I'm sure most people here would agree patents stifle innovation, but if copyright doesn't work for companies then they will turn to a different tool.

A reply of sorts, and a standard disclaimer that I work at Grafana Labs.

career-driven development

we don't have this and promote and reward as frequently for "I've done solid operations" as we do for "I've added this feature" (I'm on promotion committees and can state this confidently).

what we do have is high autonomy for engineers. This autonomy means it's a freedom that engineers have to identify problems they feel are important and to work on them, they do not need permission and leadership do not veto this. Some of the best features in the last few years have been a direct result of this autonomy, it's one of the things that makes working here so attractive to many of the engineers. But, with autonomy comes a little chaos, and not everything that is done is going to satisfy every end user of OSS or paid customer (of which these are a small percent of the whole).

a lot of the innovation speed is just in the DNA of the company, even the creation of Grafana can be traced to a desire to get things done; Torkel wanted Kibana to also work for Prometheus, Kibana declined to add this, Torkel didn't stand still and added things to a fork of Kibana now called Grafana and hasn't stopped adding things since.

They also deprecated Angular within Grafana and switched to React for dashboards. This broke most existing dashboards.

we did, I think the entire journey was 7 years long, communicated many times, over at least 6 major releases. maintaining dashboards in two languages increased complexity, whilst reducing compatibility, and gave a very large security surface to be worried about. we communicated clearly, provided migration tools, put it in release notes, updated docs, repeated it at conferences and on community calls.

arguably we went too slow, and should've ripped the band-aid off, but we were sensitive to the fact that it was a breaking change and so we proceeded with extreme caution. it's done now, it was finally completed in the last version, only a very small number of users reported impact as a result of the time and care taken on this.

I just hope OTEL settles, gets stable and boring fast

this is distinct from Grafana, but it's a good point... OTel is the product of virtually every vendor at this point, and a hell of a lot of engineers, it now has a lot of momentum and the pace is unlikely to ease up due to the sheer number of contributions and things that OTel as a community wishes to achieve.

the most likely eventuality is that enough stability emerges to allow vendors (including but not limited to Grafana Labs) to abstract away the pace of innovation occurring underneath, but this is in tension with providing the benefits of the innovation to the people that use it.

what I would say is that for most people the boring and slow path does still exist, and it's still good... just use Prometheus, a logging option of your choice, and simple Grafana dashboards and alerts. that combination hasn't varied in years, and those on it today are still immune from caring about the pace of innovation and change in OTel and across the Observability industry. OTel is being used in production at massive scale by lots of companies, but whether your project or company need move to it now reflects your priorities, many are adopting to gain independence from vendors, or just control over their telemetry, but many customers are also saying they're happy to stay on the slow and boring path and for everything to work predictably with low cost to keep pace... it works too.

I hated it so much I migrated to ProtonPass, deleted my data, and set my account to expire.

Then Proton CEO made some statements I found offensive, so I re-activated my Bitwarden account, migrated back, and am now learning to love the changes.

The best I've got for tips are:

1. Settings > Appearance > Quick Copy

2. Settings > Appearance > Compact Mode

3. Settings > Appearance > Extension Width > Wide

I still don't love it, but it remains the best of the bunch.

not any more, now the thing about Arsenal is that it's all set pieces and over-reliance on corners.

Saka isn't all that either, he'd be nothing within Odegaard.

(this is convincing, and I know about as much as the IT Crowd did)

I don't agree with the law, there's no point in using emphasis to labour the point, the UK Govt advice on who it applies to is here https://www.gov.uk/government/publications/online-safety-act... and feel free to read it. As to enforcement, it's a new law so there has been none, hence no-one can speak to that, but you're right that extradition is the path and on that front if a similar law exists and agreements are in place, then for example most European countries would extradite. We don't know where the author is, but they posted on here in the morning of European time zones, and all I suggested is that they do their diligence on their personal risk as a result of laws that do claim to apply their service. No-one should dismiss the risk, the person should speak to a lawyer.

The law has ridiculous overreach, that's true. And we haven't seen what international enforcement of it looks like yet. But to deal with the facts as they are now, the law states that it applies if you have UK users, and that the personal liability for officers of the company can be up to £18M... The overreach continues because it also covers "harmful but not illegal" content.

The app publishing didn't exclude the UK, it probably should.

The article doesn't even touch "people enter their email incorrectly when registering an account".

I've received magic links to my Gmail account that belong to other people, for accounts that have ordered flight tickets, or clothing, or digital services.

Those people, I guess they now have no way to access their online account, as they cannot password reset (if that was the fallback), or change their email (usually requiring confirmation), or receive their magic link.

There's nothing I can do here, except to delete the email, I don't have any indication as to what the correct email should be, and the person's name is the same as my legal name and there are a lot of people with that name in the World.

Few services verify an email during sign-up, because I'm sure data shows that added friction during sign-up results in fewer people signing up.

403 is generally a bad way to get crawlers to go away

Hardly... the article links says that a 403 will cause Google to stop crawling and remove content... that's the desired outcome.

I'm not trying to rate limit, I'm telling them to go away.

Oh I did this with the Facebook one and redirected them to a 100MB file of garbage that is part of the Cloudflare speed test... they hit this so many times that it would've been 2PB sent in a matter of hours.

I contacted the network team at Cloudflare to apologise and also to confirm whether Facebook did actually follow the redirect... it's hard for Cloudflare to see 2PB, that kind of number is too small on a global scale when it's occurred over a few hours, but given that it was only a single PoP that would've handled it, then it would've been visible.

It was not visible, which means we can conclude that Facebook were not following redirects, or if they were, they were just queuing it for later and would only hit it once and not multiple times.

I have thought about writing such a thing...

1. A proxy that looks at HTTP Headers and TLS cipher choices

2. An allowlist that records which browsers send which headers and selects which ciphers

3. A dynamic loading of the allowlist into the proxy at some given interval

New browser versions or updates to OSs would need the allowlist updating, but I'm not sure it's that inconvenient and could be done via GitHub so people could submit new combinations.

I'd rather just say "I trust real browsers" and dump the rest.

Also I noticed a far simpler block, just block almost every request whose UA claims to be "compatible".

Their appetite cannot be quenched, and there is little to no value in giving them access to the content.

I have data... 7d from a single platform with about 30 forums on this instance.

4.8M hits from Claude 390k from Amazon 261k from Data For SEO 148k from Chat GPT

That Claude one! Wowser.

Bots that match this (which is also the list I block on some other forums that are fully private by default):

(?i).(AhrefsBot|AI2Bot|AliyunSecBot|Amazonbot|Applebot|Awario|axios|Baiduspider|barkrowler|bingbot|BitSightBot|BLEXBot|Buck|Bytespider|CCBot|CensysInspect|ChatGPT-User|ClaudeBot|coccocbot|cohere-ai|DataForSeoBot|Diffbot|DotBot|ev-crawler|Expanse|FacebookBot|facebookexternalhit|FriendlyCrawler|Googlebot|GoogleOther|GPTBot|HeadlessChrome|ICC-Crawler|imagesift|img2dataset|InternetMeasurement|ISSCyberRiskCrawler|istellabot|magpie-crawler|Mediatoolkitbot|Meltwater|Meta-External|MJ12bot|moatbot|ModatScanner|MojeekBot|OAI-SearchBot|Odin|omgili|panscient|PanguBot|peer39_crawler|Perplexity|PetalBot|Pinterestbot|PiplBot|Protopage|scoop|Scrapy|Screaming|SeekportBot|Seekr|SemrushBot|SeznamBot|Sidetrade|Sogou|SurdotlyBot|Timpibot|trendictionbot|VelenPublicWebCrawler|WhatsApp|wpbot|xfa1|Yandex|Yeti|YouBot|zgrab|ZoominfoBot).

I am moving to just blocking them all, it's ridiculous.

Everything on this list got itself there by being abusive (either ignoring robots.txt, or not backing off when latency increased).

Yes you can https://www.ofcom.org.uk/siteassets/resources/documents/onli...

A forum that isn't proactively monitored (approval before publishing) is in the "Multi-Risk service" category (see page 77 of that link), and the "kinds of illegal harm" include things as obvious as "users encountering CSAM" and as nebulous as "users encountering Hate".

Does no-one recall Slashdot and the https://en.wikipedia.org/wiki/Gay_Nigger_Association_of_Amer... trolls? Such activity would make the site owner liable under this law.

You might glibly reply that we should moderate, take it down, etc... but we, is me... a single individual who likes to go hiking off-grid for a vacation and to look at stars at night. There are enough times when I could not respond in the timely way to moderate things.

This is what I mean by the Act providing a weapon to disgruntled users, trolls, those who have been moderated... a service providing user generated content in a user to user environment can trivially be weaponised, and it will be a very short amount of time before it happens.

Forum invasions by 4chan and others make this extremely obvious.

I am the OP, and if you read the guidance published yesterday: https://www.ofcom.org.uk/siteassets/resources/documents/onli...

Then you will see that a forum that allows user generated content, and isn't proactively moderated (approval prior to publishing, which would never work for even a small moderately busy forum of 50 people chatting)... will fall under "All Services" and "Multi-Risk Services".

This means I would be required to do all the following:

1. Individual accountable for illegal content safety duties and reporting and complaints duties

2. Written statements of responsibilities

3. Internal monitoring and assurance

4. Tracking evidence of new and increasing illegal harm

5. Code of conduct regarding protection of users from illegal harm

6. Compliance training

7. Having a content moderation function to review and assess suspected illegal content

8. Having a content moderation function that allows for the swift take down of illegal content

9. Setting internal content policies

10. Provision of materials to volunteers

11. (Probably this because of file attachments) Using hash matching to detect and remove CSAM

12. (Probably this, but could implement Google Safe Browser) Detecting and removing content matching listed CSAM URLs

...

the list goes on.

It is technical work, extra time, the inability to not constantly be on-call when I'm on vacation, the need for extra volunteers, training materials for volunteers, appeals processes for moderation (in addition to the flak one already receives for moderating), somehow removing accounts of proscribed organisations (who has this list, and how would I know if an account is affiliated?), etc, etc.

Bear in mind I am a sole volunteer, and that I have a challenging and very enjoyable day job that is actually my primary focus.

Running the forums is an extra-curricular volunteer thing, it's a thing that I do for the good it does... I don't do it for the "fun" of learning how to become a compliance officer, and to spend my evenings implementing what I know will be technically flawed efforts to scan for CSAM, and then involve time correcting those mistakes.

I really do not think I am throwing the baby out with the bathwater, but I did stay awake last night dwelling on that very question, as the decision wasn't easily taken and I'm not at ease with it, it was a hard choice, but I believe it's the right one for what I can give to it... I've given over 28 years, there's a time to say that it's enough, the chilling effect of this legislation has changed the nature of what I was working on, and I don't accept these new conditions.

The vast majority of the risk can be realised by a single disgruntled user on a VPN from who knows where posting a lot of abuse material when I happen to not be paying attention (travelling for work and focusing on IRL things)... and then the consequences and liability comes. This isn't risk I'm in control of, that can be easily mitigated, the effort required is high, and everyone here knows you cannot solve social issues with technical solutions.

In addition to the cookie privacy pop-over when viewing that site

I don't know where you're seeing that as the site does not have such things. The only cookies present are essential and so nothing further was needed.

The site does not track you, sell your data, or otherwise test you as a source of monetisation. Without such things conforming with cookie laws is trivial... You are conformant by just connecting nothing that isn't essential to providing the service.

For most of the sites only a single cookie is set for the session, and for the few via cloudflare those cookies get set too.

the real risk I see is that as it's written, and as Ofcom are communicating, there is now a digital version of a SWATing for disgruntled individuals.

the liability is very high, and whilst I would perceive the risk to be low if it were based on how we moderate... the real risk is what happens when one moderates another person.

as I outlined, whether it's attempts to revoke the domain names with ICANN, or fake DMCA reports to hosting companies, or stalkers, or pizzas being ordered to your door, or being signed up to porn sites, or being DOX'd, or being bombarded with emails... all of this stuff has happened, and happens.

but the new risk is that there is nothing about the Online Safety Act or Ofcom's communication that gives me confidence that this cannot be weaponised against myself, as the person who ultimately does the moderation and runs the site.

and that risk changes even more in the current culture war climate, given that I've come out, and that those attacks now take a personal aspect too.

the risk feels too high for me personally. it's, a lot.

It's a beautiful pump, but feels like only part of what an espresso machine is.

What heats the water? What provides temperature control? How would I produce steam?

It is so single purpose that it does not feel useful by itself, it feels like the prototype for part of a whole.

I like the idea of it, and I like the idea of "part of the whole" being a composable coffee machine where one could put together components which were all independently maintainable and highly serviceable... this feels like a taster for that, but by itself is very expensive for a pump that claims to be an espresso machine but could not produce an espresso alone, and would need something else to make any espresso derived coffee.

What this replaces is a lever espresso machine, but I'm not sure anyone with a home coffee machine would've purchased a lever espresso machine without the integrated boiler... and if they would, then this is right there https://bellabarista.co.uk/collections/lever-machines/produc...

You would benefit greatly from a video that showed the workflow end-to-end of making an espresso... from bean to the final drink.

I agree on not using iOS, because Firefox + Adblock + NoScript is incredible on Android.

but... Android sucks because the default permissions and business model on Android all veer towards advertising, and this is heavy on network and bandwidth as well as background processing across lots of apps... and that drains battery and performance.

I switched to GrapheneOS and just disable network on many things like Camera, etc... the Cloud AI features are not worth it... I also run web apps instead of installed apps for the vast majority of things, if an app doesn't require some hardware capability that only an app can provide then it's staying as a web app, m.uber.com works, most news websites work best as web apps with the JS disabled... I routinely get multi-day battery and stellar performance by just not running apps that are always trying to continuously exfiltrate data about me.

I've found only 2 things that don't work the same on GrapheneOS: Revolution banking just does not work at all - so I closed my account with them, and AMEX forces 2FA on every sign-in - which I can tolerate. Nothing else was impacted, everything else is an improvement in performance and battery.

IMG_0001 2 years ago

TIL: Americans really like firing guns, and videoing their friends firing guns.

UPDATEs should require a WHERE clause too.

At which point we could just say all SQL should have a WHERE clause.