HN user

dpifke

3,026 karma

My name is Dave. My handle is my first initial followed by my last name; to send me email, use my first name at my last name dot com.

[ my public key: https://keybase.io/dpifke; my proof: https://keybase.io/dpifke/sigs/KuMWBJfGH_TWY1BWLB4luWLnVqnG6BZbXR5Y427QR4o ]

Posts28
Comments516
View on HN
www.cisa.gov 11mo ago

Vulnerabilities in EG4 Inverters

dpifke
2pts0
lwn.net 1y ago

Improved load balancing with machine learning

dpifke
2pts0
www.elastic.co 1y ago

Elastic's journey to build Elastic Cloud Serverless

dpifke
1pts0
www.elastic.co 1y ago

Better Binary Quantization with hardware accelerated SIMD instructions

dpifke
1pts0
www.elastic.co 1y ago

Better Binary Quantization in Lucene and Elasticsearch

dpifke
1pts0
pifke.org 1y ago

The Middle-Manager Rotation: A Modest Proposal, or Possibly a DevOps Parable

dpifke
3pts0
pifke.org 2y ago

Who manages compliance for your outsourced compliance specialists?

dpifke
2pts0
www.txnd.uscourts.gov 3y ago

Mandatory Certification Regarding Generative Artificial Intelligence

dpifke
125pts43
reason.com 3y ago

ChatGPT-Authored Legal Filing “Replete with Citations to Non-Existent Cases"

dpifke
62pts71
news.ycombinator.com 3y ago

Ask HN: Can we have a 30 day moratorium on Musk/Twitter posts?

dpifke
46pts35
news.ycombinator.com 3y ago

Ask HN: Have you commented on HN about a court decision without reading it? Why?

dpifke
19pts18
coloradosun.com 3y ago

FAA asks Denver airlines to stop disabling collision-avoidance alerts

dpifke
2pts1
tinyseed.com 4y ago

Interesting SaaS Trends for 2022

dpifke
4pts0
everydayastronaut.com 6y ago

How much do rockets pollute?

dpifke
82pts39
pifke.org 7y ago

Let's talk about killing PGP

dpifke
1pts0
everydayastronaut.com 7y ago

SpaceX Raptor: Methane fueled full-flow staged combustion cycle engine

dpifke
242pts27
www.crowdsupply.com 9y ago

The State of Owner-Controlled Computing as Talos Winds Down

dpifke
19pts4
googleonlinesecurity.blogspot.com 12y ago

A Roster of TLS Cipher Suites Weaknesses

dpifke
43pts19
plus.google.com 14y ago

Stopping SOPA/PIPA isn't enough; some suggestions for real copyright reform

dpifke
1pts0
torrentfreak.com 15y ago

Firefox add-on to route around US Government domain seizures

dpifke
1pts0
news.ycombinator.com 15y ago

Ask HN Angels: Did you register under the California Finance Lenders Law?

dpifke
3pts0
www.eff.org 16y ago

EFF on Apple's iPhone Developer Program Agreement

dpifke
102pts78
www.boingboing.net 16y ago

Adventures in Ex Ante Crowdfunded Securities Law

dpifke
2pts0
www.sbecouncil.org 16y ago

The Most Entrepreneur-Friendly States

dpifke
1pts0
laughingsquid.com 16y ago

Jacob Appelbaum & Donald Knuth Demonstrate The Recursive Homeboys Principle

dpifke
8pts1
blog.amandapalmer.net 16y ago

Artist Who Made $30k On Webcasts Is Not Afraid To Take Your Money

dpifke
5pts0
www.crossingwallstreet.com 17y ago

The stock market loves Wednesdays

dpifke
7pts4
www.alleyinsider.com 17y ago

Tech Reporters From 1981 Ask: Will People Ever Read Their Newspaper On A Computer?

dpifke
3pts0

In the U.S., requiring a login (or any information other than your email address) to opt out is against the law. Additionally, you cannot require any steps other than "sending a reply electronic mail message or visiting a single Internet Web page."

I once wrote to the FTC for guidance as to whether or not this included requiring unsubscribers to solve a CAPTCHA or disable adblockers or enable Javascript, but did not get a response. I believe the law is plain with regards to this, but a lot of companies seem to be willing to risk it.

See: https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C...

In this case, "null MX record" means MX exists, but does not specify a valid server:

   $ host -t mx example.com
   example.com mail is handled by 0 .
Senders should not fall back on the A record in this case.

I use uBlock Origin for this, something like:

  news.ycombinator.com##:matches-path(/^/item\?id=/) tr a.hnuser:has-text(/^dpifke$/):upward(tr)
This mostly works, but only kills the user's comments and not replies, so it sometimes can be confusing.

The very first subheading is entitled "What to Submit." I quoted it in my initial reply as rationale for why the people flagging this submission as off-topic were justified.

This seems similar to the "Is Github Down?" submission problem, where the submitter simply links to github.com.

That's a poor submission, because by the time most people click on it, Github will no longer be down.

There might be an interesting discussion to be had about outages at Github, but the better submission would be an article or blog post about the outage, not just a link to the site and a three-word title.

If someone wants to write an article or blog post about this news broadcast, which links to "hard facts and analysis not available through popular channels," that seems like it might be a worthwhile submission. But just a link to the broadcast by itself is not leading to interesting or on-topic conversation—the top comment right now is an ad hominem attack against Larry Ellison, without any supporting facts or analysis that he had anything to do with this story at all.

Lots of hackers find porn very interesting. In fact, my first "real job" as a hacker was for a company with ties to the 1-900 industry that had decided to expand out onto the internet (not just to sell porn). Stories about porn would be interesting, submissions of nothing but pornography itself ("because it's censored!") are not.

I would be more sympathetic to the argument that this is relevant if the submission was an article about media censorship, or CBS's audience or leadership, and how said censorship, audience, or leadership relates to technology or emerging trends in media.

But this is literally just a controversial TV news broadcast, that people of one political persuasion say was "censored" and people of another political persuasion say was held off the air "temporarily" until it met network fact-checking standards. That sort of political bickering is most uninteresting, and is most definitely not why I've been reading HN for the past few decades.

As someone who has moderated online communities in the past, I recognize the value in having a page like this, to which you can point people if they want to enumerate such trifles instead of discussing the episodes or series themselves. Rather than just say such discussion is off-topic, you give them a separate, on-topic place to discuss it.

(I don't actually know if that is how this page came about, but it seems similar to other wiki pages I've seen used for such a purpose.)

If it causes more than $5k in damage. Otherwise, it's a misdemeanor.

But you probably don't want to be investigated for either.

Related: https://pkg.go.dev/crypto/subtle#WithDataIndependentTiming (added in 1.25)

And an in-progress proposal to make these various "bubble" functions have consistent semantics: https://github.com/golang/go/issues/76477

(As an aside, the linked blog series is great, but if you're interested in new Go features, I've found it really helpful to also subscribe to https://go.dev/issue/33502 to get the weekly proposal updates straight from the source. Reading the debates on some of these proposals provides a huge level of insight into the evolution of Go.)

My first car (hand-me-down from my Dad) was a 1980s Datsun, that I managed to total within a few weeks of getting my license, much to the consternation of my younger brother and sister who expected it to eventually be handed down to them as well.

The "left door is open" voice alert will forever be ingrained in my memory: https://www.youtube.com/watch?v=6hJBko3-oV4 It seemed so futuristic when the car was new.

If you're in the U.S., you might check if your local fire department has a CERT[0] training course. (I did it many years ago in San Francisco; they call it NERT for some reason.)

It'll give you a chance to practice putting out an actual fire, refresh first aid skills, learn the incident command system, learn basic search and rescue, and other preparedness skills to help yourself, your family, and neighbors in an emergency (in that order).

[0] https://www.fema.gov/emergency-managers/individuals-communit...

Spamhaus has been sued—multiple times, I believe—for publishing DNS-based lists used to block email from known spammers.

For instance: https://reason.com/volokh/2020/07/27/injunction-in-libel-cas... (That was a default judgment, though, which means Spamhaus didn't show up, probably due to jurisdictional questions.)

The first step in filing a libel lawsuit is demanding a retraction from the publisher. I would imagine Google's lawyers respond pretty quickly to those, which is why SafeBrowsing hasn't been similarly challenged.

I had this same problem with my self-hosted Home Assistant deployment, where Google marked the entire domain as phishing because it contains a login page that looks like other self-hosted Home Assistant deployments.

Fortunately, I expose it to the internet on its own domain despite running through the same reverse proxy as other projects. It would have sucked if this had happened to a domain used for anything else, since the appeal process is completely opaque.

With Windows 11, WSL has X and Wayland support, so you can run graphical applications as if they're native (e.g. share the same cut-and-paste buffer, switch between windows using alt+tab, and so on). It's also much easier to attach USB devices like Yubikeys to an already-running container than the last time I tried to do the same with Parallels. (That was quite a few years ago, so maybe it's gotten better.) You can also launch Windows applications from Linux, which is makes it trivial to control my (Windows-native) browser from within WSL.

I strongly disagree about Mac hardware vs. Thinkpads or Framework, but to each their own.

That's basically WSL.

My work laptop is Windows, and the only native applications I run on it are a web browser, Zoom, and the company's VPN software. Everything else runs inside WSL.

I greatly prefer Debian to Homebrew, so if I can't run actual Linux, this is (to me) superior to trying to develop on a Mac.

Wow, that's pretty crazy, compared to the US. I paid a one-time fee of $50, then $262.50/year for IPv4 block + IPv6 block + ASN: https://www.arin.net/resources/fees/fee_schedule/

I've been through the process about 10 times now at various companies, and the paperwork (at least for ARIN) is no more difficult than what would be expected to justify IP space from your typical ISP. If anything, the ARIN folks are more responsive and technically competent than your average ISP support agent, which makes the process easier.

"Extraordinary claims require extraordinary evidence."

My reply involved the effort of sending a test message from my Chase account, to capture the exact text used. If you want people to engage with you in good faith, you should put similar effort into your replies, rather than just use Reddit-speak for "I think you're wrong."

FWIW, a huge percentage of the spam I get is via Sendgrid, and at some point in the past year or two their abuse reporting mechanisms all turned into black holes, so mail sent via Sendgrid is heavily penalized in my spam rules.

Sending reputation is just as applicable if you're using a third party as if you're hosting it yourself, but much less under your control.