HN user

diftraku

199 karma

Kweh!

[ my public key: https://keybase.io/diftraku; my proof: https://keybase.io/diftraku/sigs/WFcsXbW40O8hpHNWb4f1wZ4iXosR-QmcadiEyzM8c4M ]

Posts0
Comments46
View on HN
No posts found.
Kevo app shutdown 10 months ago

One of their digital lock designs had a rather cough Pleasing vulnerability.

I'm assuming you're referring to the VingCard vulnerability from 2018? (https://www.bbc.com/news/technology-43896360)

Digital locks aside, this is more applicable to any lock you buy and rely on (substitute US with your local region):

lack of availability in the US

I wouldn't go out of my way to find something like Schlage here, when Abloy (Assa Abloy) locks are available in abundance with locksmiths able to duplicate usually all the key variants.

They're still technically Avago Technologies, just wearing the name of Broadcom after the acquisition in 2015-2016. Not sure if there's much of Broadcom left, beyond the name and what IP they had at the time which was not sold off, like they did with the IoT related IPs.

I'd be really curious on how hard programmatic access to your own, personal banking data might be in the PSD2-era.

I can link my secondary bank account to my main bank's app so I can see the balance in one place, but the catch is that I need to refresh this authorization through the app every 90 days.

Ideally, you'd just use your banking credentials to authorise the API access and pull data through that. What this requires in practice, I have no idea but it probably involves a bit of bureucracy.

I opted for Ikea glass containers partly for wanting to avoid plastics (except the lids) and partly to not have to deal with tomato sauces staining the pristine white plastic containers after a single use

Micro/nanoplastics are a secondary consideration overall, primary was just to reduce my usage of plastics a bit, even how infinitesimal it really is. I only realized how much plastic packaging I go through once I moved to an apartment with plastic "recycling", I still separate out most plastics but not everything.

I personally am not really swayed towards ditching whatever plastics I still have, given how ubiquitous it is and I am already happy with my Ikea glassware.

At the same time, I'm in awe and in horror of seeing those high current, high voltage disconnects being opened only to end up with a few meter high arc of current jumping through the air between contacts.

I was taught the procedure of disconnecting a 10/20kV disconnect for an on-site transformer (alas, only an old one that had been decommissioned) and that thing scared the crap out of me when I first heard the spring loaded high voltage disconnect actuate.

Having a 3 meter fibreglass pole to actuate the thing, just incase, tells you there is a real risk of the thing blow up in your face, on a good day.

In the video it appears that Peter was using the Flipper Zero to wireless turn the power meter on and off, which also controlled the power to a large AC unit. Eventually switching the meter on and off while under a heavy load resulted in the meter self destructing and releasing the magic smoke.

Calling out Flipper Zero for someone (ab)using the meter's remote control features cuts me the wrong way: you could've done the same with any other SDR, not just the Flipper Zero.

It's not even a surprise this happened, the cut-off is not meant to be operated constantly to cut heavy loads. Similarly you should not use a breaker to turn off heavy (or any, in that matter) loads as you're needlessly wearing down the protective device, instead of a separate cut-off switch that's designed to be replaceable. Especially since it can be positioned downstream from the protective device.

It all boils down to which part of the circuit you can easily repair in case of a fault, in this case the meter is by far the least accessible.

Another note for nordic layouts and Linux: tilde (~) is considered to be a "dead key" on most nordic layouts, meaning you may need to follow AltGr + ~ with a space before typing out the dot. Otherwise you might get weird looks from the terminal trying to figure what you meant with the tilde-dot.

Incidentally, while testing on Windows (in both WSL and cmd.exe) with a Finnish layout: you do not need a space after typing out the tilde.

Another source of constant hilarity is when the voice guidance tries to pronounce the names of ring roads in Helsinki metropolitan area: Kehä I / Ring I. They're numbered using roman numerals (I through III) but Maps has no such knowledge of this so it just ends up rattling off the route number and "Kehä / Ring" with the ring road numerals as if they were just a literal letter I.

Sometimes the lane guidance also likes to pick up on the destinations from the overhead signs, trying to pronounce the Finnish and Swedish names with less than stellar results.

When Signal finally drops SMS support, I will also drop Signal. It always was SMS foremost, secure communications second when I initially started using it. Having people on Signal was an added benefit, not the main drive for using it.

For me personally, Signal will turn into a messaging app among dozens of similar apps, of which I have enough already. SMS was why I stuck with Signal over the years I used it and now I have no real reason to stay on it.

For those of us in the dead key land (using AltGr to type ~), remember to hit space after typing out the ~, otherwise it won't register properly.

One point worth of note when it comes to Docker caching, more specifically pulling images, is the rate-limiting on Docker Hub.

While hosted GitLab might make use of a transparent pull-through cache (as I've gathered from glancing at relevant parts of the docs), you can benefit a lot by using one with your own local GitLab instance (assuming it does not already provide it via container registry).

We ended up switching to Harbor[1] from the vanilla registry and almost by chance stumbled on the fact that it supported a pull-through cache from various other sources (including Docker Hub).

This was especially useful after we hit the rate-limit after one of our pipelines got out of hand and decided to rebuild every locally hosted Docker image (both internal and external).

[1] https://goharbor.io/

While I have not been this deep into the inner workins, I personally have skimmed that rabbit hole when I started a side-project that was essentially grep but for (mainly) MKV files.

Idea was that you could "grep" by specific text in the subtitles and automatically create a clip of every occurrence of the text (by looking at the subtitle timing and padding that in both directions).

The biggest source of my frustration was that I was unable to get the clipping to work exactly as I wanted, where the start or end of the clip would seemingly drift back and forth. That was until I realized it boiled down to how the different seek modes in ffmpeg handled keyframes.

I still haven't gotten the clipping to work exactly as I want but I figured doing two passes might be the way to go: first pass would do a fuzzy match and ensure there is enough extra on both ends of the desired clip and the second pass could re-encode the fuzzy-matched clip to shuffle the keyframes around, allowing more accurate clipping.

Definitely not, I'd still preferr to have proper multi-account support over having to use a work profile on Android (or multiple profiles if using a browser).

I got around the single-account limitation on Element by installing a work profile on my Android phone using Shelter[1]. I initially spotted this from HN while we were looking at migrating from Slack to Matrix and I wanted to keep my personal account separate.

Works surprisingly well for my use-case (keep work stuff separate on Element) and even allows me to disconnect completely from work by simply turning off the profile.

[1] https://github.com/PeterCxy/Shelter

Edit: added note about using Android

You say "standards-based clients", does this mean I do not have direct access to the filesystem? Or a shell account for that matter?

Using email as an example, having to transfer email with drag'n'drop in something like Thunderbird is clunky, slow but works to a degree.

Having direct access to the mailbox directory on the filesystem would make it easier to transfer out/in (assuming you already have your emails in the same format).

It's a very similar case in Finland, case-in-point when HRT (Helsinki Region Transport) requested bids from operators to run the trains in the greater capital area (Helsinki, Espoo, Vantaa and the neighbouring municipalities).

- Rolling stock is owned by HRT

- Transport Infrastructure Agency (Väylävirasto) is responsible for the tracks and stations

Which means the bid is mainly for personnel operating the trains.

There were couple companies that placed bids for this, most of them withdrew before the end of the call, essentially leaving one competing bid along with VR's (then and now current operator).

In the end, nothing changed and VR still operates the trains using HRT's own rolling stock. The only real change going forward are the plans to have a dedicated maintenance depot for HRT's own stock, since VR does not want to have the burden of maintaining stock they don't directly own.

At least with freight, it's going to be different... right?

And now the hardware controller we have (Dream Machine Pro) plasters "How likely are you to recommend" polls and usability surveys after being forced to use the new settings and dashboard following an automatic update.

While not outright ads, the usability survey keeps pestering for feedback, I do not have much faith in Ubiquiti having any tact left to not pester for the recommendation feedback as well.

A long-time personal favourite naming scheme of mine has been Pokemons (and by extension, Digimons).

There's a good selection, it's pretty varied and there's no shortage of em (assuming you don't exceed 100-200 new systems in a 3 year period). This also has an accidental side-benefit of not being tasked to name new hosts at work, unless your really want to call the new database server Stufful, for example.

Another thing to keep in mind with more descriptive hostnames like `database`, is to serialize them from the start. It's a very minor thing but after you have three hosts with one of them missing the serialization, it's going to stand out like a sore thumb and it could be a major undertaking on changing that name where it's used.

When it comes to project names, there is a certain level of permanence that name (or codename) is going to have. Once chosen, that name will be thrown around in the codebase almost universally. The same does apply to the hostnames, at least in part when it comes to configuration files (and by extension, certain hard-coded hostnames that could linger around in the code years after the host in question has been decommissioned).

I'm a bit disappointed that I can't watch anime at the (home) office from that domain. Wumpus had my hopes up for a moment there!

I personally prefer to use contactless cards or Google Pay instead of MobilePay.

The major reason behind this is mainly due to how MobilePay integration was done with the card terminals over here in Finland: you need bluetooth (or in some cases, a camera to read a QR-code) to start the payment transaction. I believe this is primarily due to Apple restricting the use of NFC to Apple Pay (and other first-party apps).

Another big reason is that my bank has native support for adding cards to Google Pay through their own app.

I do still use MobilePay very often over my bank's own transfer app (Siirto). MobilePay was one of the first ones to the market (if you exclude the app/card scheme Elisa had a few years ago, currently owned by Aktia) and is still faster than asking for someone's IBAN.

I may have used "free as in free beer" in a wrong way, what I meant with 1 was there are no additional costs to the current or new users (the rates for the services on offer stay the same).

For 3 (as was in the example), the cost of the DDoS protection service is directly added to the rates of services on offer.

OVH was quite blatant in this, as it had offered an optional DDoS protection service for a fixed rate of 3€/mo (this was a few years ago, exact details might be hazy). After they had a large network overhaul (with major interruptions), they simply raised the prices by 3€ and advertised the new, "free" DDoS protection service which was included in all of the services.