HN user

exiguus

1,099 karma
Posts50
Comments281
View on HN
www.yankodesign.com 2mo ago

Google-Free Phone Is IP68-Rated and Has a Replaceable Battery

exiguus
2pts0
entropicthoughts.com 2mo ago

Donating to Open Source

exiguus
2pts0
distrosea.com 11mo ago

Test drive Linux distros online

exiguus
3pts0
bits.debian.org 11mo ago

Debian Turns 32

exiguus
7pts0
www.dropsitenews.com 11mo ago

A New List Reveals Top Websites Meta Is Scraping of Copyrighted Content

exiguus
7pts0
hachyderm.io 11mo ago

NetBSD manpage of sleep(1) consider a bug

exiguus
2pts0
github.blog 11mo ago

From private to public: How a United Nations organization open sourced its tech

exiguus
1pts0
media.ccc.de 11mo ago

WHY2025: How to become your own ISP [video]

exiguus
209pts61
www.theregister.com 11mo ago

Network scans find Linux is growing on business desktops, laptops

exiguus
19pts3
isitreallyfoss.com 11mo ago

Projects evaluated to see if they're as free and open source as advertised

exiguus
159pts66
www.youtube.com 11mo ago

One Company Poisoned the Planet (PTFE/C8) [video]

exiguus
2pts0
www.youtube.com 11mo ago

Writing a Text Editor [video]

exiguus
3pts0
www.pizzint.watch 11mo ago

Pentagon Pizza Index

exiguus
101pts48
www.theregister.com 12mo ago

Microsoft admits it 'cannot guarantee' data sovereignty

exiguus
23pts0
america2.news 12mo ago

We mapped Jeffrey Epstein's social network. Here's what we found

exiguus
18pts2
www.inc.com 12mo ago

Female Founders Outperform Their Male Counterparts but Receive Much Less Funding

exiguus
4pts0
www.aquasec.com 12mo ago

AI-Generated Malware in Panda Image Hides Persistent Linux Threat

exiguus
5pts0
www.privacyguides.org 12mo ago

Privacy Is Like Broccoli

exiguus
3pts0
michael-prokop.at 12mo ago

What to expect from Debian/Trixie

exiguus
283pts203
kelpui.com 1y ago

Kelp: A UI library for people who love HTML

exiguus
6pts1
nsarchive.gwu.edu 1y ago

The CIA's 'Minerva' Secret

exiguus
6pts2
slatecave.net 1y ago

Smart SSH Jumping

exiguus
5pts0
www.eff.org 1y ago

Data brokers are selling flight information to CBP and ICE

exiguus
547pts287
josephthacker.com 1y ago

The Future of Tech

exiguus
2pts0
www.psychologytoday.com 1y ago

Strategies to Better Resist Distractions

exiguus
1pts0
blog.rust-lang.org 1y ago

Stabilizing Naked Functions

exiguus
1pts0
www.yankodesign.com 1y ago

Garmin patents a sensor that can detect dehydration levels

exiguus
2pts0
www.psychologytoday.com 1y ago

Building Organizational Capacity for Large-Scale Change

exiguus
1pts0
www.psychologytoday.com 1y ago

UFOs, Aliens, and the Unknown Other

exiguus
3pts0
www.theguardian.com 1y ago

Big tech's new datacentres will take water from the driest areas

exiguus
6pts1

IndieWeb is a form of social media. People have a certain image of themselves, and the internet helps them live up to it. Whether we're writing comments on HN, posting toots on Mastodon, uploading videos to TikTok, or writing a post on our own blog, there’s a lot of self-expression involved.

However, for a lot of people, platforms like TikTok are more appealing than IndieWeb, but for some, it's fun to set up an OpenBSD VPS, a static web server, and learn to write better in text files using their favorite editor.

A self-determined workflow can be more important than being seen. However, one doesn't rule out the other, and the Author and IndieWeb offers some good tips.

Thanks for the post.

I have a similar experience with a tendency to Digital Ocean. Actually, I semi-automatically collect IPs that are banned by (mostly SSH) fail2ban and eBPF bans from dnsdist. These IPs are then merged into CIDRs, which are used as ipsets in a firewall ban chain. The IPs are collected on around ~20 Machines with public, static IPv4 and IPv6 addresses. Most of the Machines are in Canada and Europe.

However, I have statistics for the CIDRs based on their whois record that look like:

CIDRs used: 1255

Already cached: 1252

Skipped uncached targets: 0

IPs scanned total: 985300

Estimated throttled wait: 0.10 minutes

== Country codes ==

Metric: Top 10 of 90 unique country codes

Total: 1183 country codes total and 90 unique country codes in 1255 targets

  US  287
  CN  132
  NL  88
  VN  53
  DE  51
  HK  45
  AU  38
  ID  36
  RU  33
  CA  27
  

== Regions ==

Metric: Top 10 of 29 unique regions

Total: 334 regions total and 29 unique regions in 1255 targets

  CO  48
  FL  40
  WA  37
  QLD  32
  GA  26
  NY  25
  CA  23
  TX  17
  QC  15
  UT  14
  

== Origin ASNs ==

Metric: Top 10 of 382 unique origin ASNs

Total: 805 origin ASNs total and 382 unique origin ASNs in 1255 targets

  AS16276  26
  AS132203  24
  AS24086  18
  AS38731  18
  AS7552  18
  AS24940  17
  AS9808  15
  AS135377  14
  AS137718  13
  AS62390  11
  

== Netnames ==

Metric: Top 10 of 630 unique netnames

Total: 1157 netnames total and 630 unique netnames in 1255 targets

  RIPE  38
  MSFT  31
  SINGLEHOP  25
  ACEVILLEPTELTD-SG  21
  VIETTEL-VN  18
  CMNET  17
  APNIC  16
  CHINANET-GD  14
  VOLCANO-ENGINE  13
  UCLOUD-HK  11
  

== Org names ==

Metric: Top 10 of 222 unique org names

Total: 703 org names total and 222 unique org names in 1255 targets

  RIPE Network Coordination Centre  55
  DigitalOcean, LLC  40
  Asia Pacific Network Information Centre  32
  Microsoft Corporation  31
  Internap Holding LLC  25
  HostPapa  23
  Korea Telecom  20
  Hetzner Online GmbH  17
  China Mobile  16
  ReliableSite.Net LLC  16
  

== Organizations ==

Metric: Top 10 of 236 unique organizations

Total: 691 organizations total and 236 unique organizations in 1255 targets

  RIPE Network Coordination Centre (RIPE)  55
  DigitalOcean, LLC (DO-13)  40
  Asia Pacific Network Information Centre (APNIC)  32
  Microsoft Corporation (MSFT)  31
  Internap Holding LLC (IC-1425)  25
  HostPapa (HOSTP-7)  23
  ORG-HOA1-RIPE  17
  ORG-CM1-AP  16
  ReliableSite.Net LLC (RL-323)  15
  FranTech Solutions (SYNDI-5)  13
  

== Domains ==

Metric: Top 10 of 534 unique domains

Total: 2581 domains total and 534 unique domains in 1255 targets

  rdap.arin.net  404
  apps.db.ripe.net  83
  chinatelecom.cn  63
  vnnic.vn  58
  ripe.net  55
  www.ripe.net  53
  apnic.net  46
  digitalocean.com  44
  ovh.net  38
  www.as14061.net  35
  


I deleted the (abuse) mail section. Because. 99% of the IPs are IPv4. In the IPset are mostly /32 but also a lot of ~/24 and rarely ~/16 segments. RIPE, ARIN and APNIC comes into play because some CIDR blocks are somewhat generously sized and block multiple network segments belonging to different organizations at the same time. E.g. this hides BR from the stats (because the ipset mostly bans every provider from BR).

I also think that educated and wealthy parents are better able to support their children; from education and financial literacy to real estate and plain money. However, I do think that this support makes the children more independent when they're adults.

I also thought that YC might be younger, but then i remembered that most (successful) founders are 40+. Do we know something about YC demographics? Aside from the fact that it's obvious that a great many of them come from STEM fields. I did not find anything about it.

I've asked myself the same question. And I've come to the conclusion that there's a difference between feeling independent and being independent.

Like: I built a $50 billion business with my own hands. Okay, I got the first $2 billion from my parents. Okay, I got the first $2 billion for every business from my parents until I was successful.

The question that was ask in the survey was: How financially independent you currently feel from your parents (meaning you could support yourself without them if needed)

I understand that YC is questioning the results of the survey. The YC community is very privileged; and i bet, if we do the same survey in this community, 20% or less of adults rely on their parents.

Personally, I know several databases where single tables have +500GB and the database has +100TB. With this huge databases the restore and backup process over network become indeed a bottleneck. So I can agree with the author. Also, the author does not say that they can't start with a single database server and just read replicas and max hardware out. Real world use cases with +100TB I know about are Stock Market, Traffic Data, Warehouses, Analytics and Monitoring.

As I understand the author: They describe the journey of scale from a single database server over read replicas to sharding. And its not only about a single server, its also about network (backup, restore).

I had a similar experience with macOS a few years ago. After using GNOME for over 15 years, I had to switch to a Mac for work for about two years; and I never fully adapted. Windows, on the other hand, I've never been able to take seriously; every time I use it, the interface feels completely different.

The same goes for tools like Word, Excel, and PowerPoint. I prefer Markdown for creating presentations and documents, and I even use Vim keybindings in VSCode and JetBrains IDEs (because I am lazy and you can use them nearly everywhere). My "TV/Steam" runs a tiling window manager (Sway) and is controlled by a keyboard instead of a remote (and you guest it, you can use Vim keybindings with sway). At one point, I used the right-hand for mouse at work and the left-hand at home. And, of course, there is the classic switch from a native-language keyboard to an English one for programming. What I'm trying to say is, you can adapt if you're motivated. And sometimes you don't.

I'm also a huge friend of trackpoints instead of touchpads. And I avoid to use the mouse and keyboard at the same time. Usually, mouse while planning, reviewing and presenting and keyboard when creating. And I learn keybindings for software that I use daily because of that.

Less GUI, means more Content / Information on the screen. And sometimes you benefit from that.

My takeaway? Do whatever makes you happy. Rewiring your brain from time to time keeps it flexible and sharp; like learning a new language or playing a musical instrument. It's a workout for your mind.

And Productivity isn't just about speed; it's also about quality. Sometimes, slowing down (by using a mouse) to focus on the craft of your work leads to better results than rushing to get things done as quickly as possible.

I ran my own YaCY instances. Three of them to be specific, because they are "super fast" and "reboot" often. I crawl with them the smallweb, smallcomic and smallyt sites and also all feeds from my miniflux instance; getting them via the miniflux api. Beside that i have other static entries that i crawl. For wikibooks and wikipedia i tried and use also YaCY, but it use a lot of resources. So its only in one instance. I suggest >16GB RAM and 300GB+ HDD if you want to do this. To access wikimedia, gutemberg, archwiki or media.ccc.de directly, I use also SearXNG. Usually it takes 1-3 Seconds to get search results from YaCY in my setup. I run them in docker on aarch64 with ~6GB of RAM and 200GB HDD. The VPS it-self has 8GB RAM, 6 arm cores and 250GB HDD. If YaCY hang, i just restart it. This are my pretty good working docker deploy and java settings I use currently:

    environment:
      JAVA_OPTS: >-
        -XX:+UseG1GC
        -XX:MaxGCPauseMillis=200
        -XX:+ParallelRefProcEnabled
        -XX:+UseStringDeduplication
        -XX:InitiatingHeapOccupancyPercent=45
        -XX:G1ReservePercent=15
        -Xms1024m
        -Xmx3072m
        -XX:MaxMetaspaceSize=256m
        -XX:MaxDirectMemorySize=256m
        -XX:+ExitOnOutOfMemoryError
        -XX:G1HeapWastePercent=10
        -XX:G1MixedGCCountTarget=4
    deploy:
      resources:
        limits:
          cpus: "4.2"
          memory: 5.2G
        reservations:
          cpus: "2"
          memory: 2.5G
    healthcheck:
      test: |
        /bin/bash -c '
        if ! timeout 55s wget --spider --no-verbose http://127.0.0.1:8090/yacysearch.html?query=exiguus; then
          exit 1
        fi
        if ! timeout 55s yacy_search_server/bin/checkalive.sh; then
          exit 1
        fi
        exit 0
        '
      interval: 120s
      timeout: 60s
      retries: 3
      start_period: 240s
That's the smallest I got it running mostly stable and self-healing with a index size of +100GB. I also avoid to use crawling by the build in tasks and use the API and cron jobs for weekly feed importing, because I found out, that kind of crawling eats up less resources then the usual. All-Over, to much running crawlers, make retrieving search results slow. For production use, I suggest to min. double the resources. If you do this, it becomes very stable.

Thanks to pointing out kiwix. I'll give it a try.

YaCY has a proxy mode that automatically index your web-serving. In my experience, the index grow in size very fast and reaches ~100GB or more. How does the index size of Hister compare to that?

SearXNG is my daily internet search now +5 years; with YaCY Backends and else as fallback. I also build internal document search or RAG applications with this setup (SearXNG also support json results). However, there are some downer I accept because of privacy: 1. Its slower and the results are not that good then with others. But fast and good enough for most of my queries. 2. From time to time you get blocked on the duckduckgo, brave or whatever search and you must solve some captures. You can prevent this by getting and using API-Keys from them.

The nice thing about using your own backend is, that you can prio it in the results and for example, if I crawl the smallweb and other site important for myself, this sites come up first in the results.

This is a fantastic article! I completely agree with the author's philosophy. Simple automation can reduce maintenance to nearly zero, and it's incredible how much can be achieved with just a few well-crafted scripts.

I use a nearly identical alias for docker pull to keep my containers updated. To ensure everything stays running smoothly, I've built a lightweight watchdog (a mix of bash scripting and Uptime Kuma/Beszel) that monitors my services and containers and restarts them if they crash. This way, I rarely need to intervene manually.

For critical services (DNS, VPN, git, web search, crawler and mail, etc.), I add an extra layer of redundancy by running them on multiple servers across different locations. If one server fails, the others seamlessly take over. I also use DNS round-robin as a simple but effective way to handle load balancing and failover; no HaProxy, K8, expensive IP Takeover (ARP Spoofing) or BGP Anycast and VRRP/CARP, Proxmox or fancy orchestration tools required. If a node goes down, another watchdog script temporarily removes it from DNS, and traffic shifts to the remaining servers. Most often the services are self-healing. The best part? My deployment and monitoring are fully self-scripted (no Terraform, Ansible or BundleWrap). Moving services to a new server is as easy as running some scripts over SSH. Everything sets itself up automatically. Currently I run my services on 2 Pi's, 2 stratum 1 servers (from centerclick), and 8 VPSs that cost me around $40/month. It's a great example of how a little automation and redundancy can go a long way in keeping things cheap and reliable without unnecessary complexity.

I invest around 1-2h/month to maintain and (mainly) adjust my setup. Before I head multiple Proxmox instances and a backup server that cost me around $250/month, I was spending 1-2h/week just to keep everything running. The difference is night and day.

However, I've personally had bad experiences with consumer hardware like the Raspberry Pi and hardware failures. Most of the time, I didn't feel motivated to replace the hardware and set up all the services again (even if I had a backup). As an Unify alternative i can recommand GL-iNET; build modern hardware for OpenWRT with some additions and the hardware has enough power to run Wifi7, AdGuard and Tailscale or ZeroTier. (Before I run Protectli Vaults with a virtual PfSense, Tailscale and AdGuard on Proxmox and extra OpenWRT access points) I can recommand the Protectli Hardware over a Raspberry Pi, especially if you want to run a single server/hardware homelab.

Thanks for the inspiration; it's always refreshing to see others embracing simplicity!

How do you use DNSCrypt on Android or iOS?

On my notebooks, I run two Docker instances of AdGuards dnsproxy, using my own DNSCrypt resolvers as upstream servers. This setup provides anonymity from the resolver and protects against man-in-the-middle attacks, since DNSCrypt authenticates DNS responses. However, root DNS queries from the upstream remain unencrypted. Additionally, not all nameservers support DNSSEC, so a fallback is often needed. Which can still leave the upstream vulnerable to man-in-the-middle attacks. Of course, DNSCrypt is more secure (authentication, no bootstrapping), faster and anonym (against the resolver). But i think it is still not useable for "normal" people. And as a provider, the setup is more complex then DoH, DoT or DoQ, because of cert rotation and the DNS entries.

Do you mean when communicating directly with a root DNS server over unencrypted UDP or TCP? You're right. There's currently no universal way to encrypt direct queries to root DNS servers. To work around this, the best approach is to host your own public DNS server outside your untrusted ISPs network and connect to it securely using DoH, DoQ, or DoT. Alternatively, you can rely on a trusted third-party public DNS provider that supports encrypted connections. In the end, there's no perfect solution. You have to choose who to trust. Personally, I trust my ISP more than external DNS providers. For anonymity you could route your DNS root queries throe tor or a VPN for the cost of performance.

I also used third-party public resolvers before. Mainly FFM (its not on the list) but non-profit, EU and encrypted. If you boil down the list (from the website) to this categories, you have 4 providers. You can trust, in my opinion. But the problem with all this provider is, that you ran quick into rate limits or some query type restrictions. Especially if you run your own mail server or other DNS expensive task.

Fun fact about hosting your own DNS infrastructure and offering it to friends and family: They might actually trust other providers more than they trust you. Even if they know and trust you personally. Because they know you can theoretically read their queries, it’s more convenient for them to have a stranger do it instead.

To be honest, there’s no way to prevent others from using my DNS server without putting it behind a VPN or in any other non-public network. Also you can do port-knocking or something, but that's not rely authentication. However, I'm not aware of any authentication mechanisms in DNS. That would also cause performance to plummet. If you use a VPN or something, in turn, would mean you'd have to rely on someone else's DNS infrastructure. So I don't have any of this and its public.

The good thing about dnsdist is that it acts as a sort of load balancer for DNS queries and offers features such as dynamic blocking (including via eBpf) at the IP level and rules and rate limits for query types you can combine. Therefore, there are no limits (or very open limits) for all query types from whitelisted IPs, and stricter rules for all others. IPset and GeoIP banning of known malicious IPs and regions (using block-lists) also keeps the footprint of "unwanted" use very, very small.

I use my own public powerdns dnsdist and recurser/authoritave instances for DoH, DoT, DoQ, TCP and UDP now for ~3 years. Setup took some time, because i used bind, unbound and dnsmasq before. It's super stable and i can also use it on my mobile or legacy devices and as resolver in unbound, adguard/dnsproxy or just in my local resolve.conf.

Most important and super privacy/security related topic: DNS. Instead of choosing a public one. Host your own infrastructure. You don't need public instances. Just run ADGUARD or unbound/dnsmasq/dnsdist in recursive mode on your router or machine. And you can set limits and block-lists to your needs.

I enjoy collecting old ThinkPads and other Notebooks, and I wanted to clarify a few points about 32-bit vs. 64-bit support.

The last true 32-bit processors were the AMD Athlon XP and Intel Pentium 4 (early Core Duo models also had 32-bit variants). ThinkPad series like the T6x, T4x, R5x, and X3x/X4x are limited to 32-bit. Meanwhile, models like the X2xx and newer generally support 64-bit and run modern distros like Debian or Fedora smoothly, often this models have at least 2GB of RAM and 64GB+ storage.

The article's title feels a bit misleading to me. It's more about limited resources (RAM/storage) than truly "old" hardware. In my view, the defining factor for "old" should be 32-bit processor support, which is far more restrictive than storage or RAM constraints. Usually the 32-bit systems are better typewriter. They don't have enough power the browse smoothly the modern web.

For 32-bit systems, I usually go with Q4OS (great for old hardware compatibility) or Puppy Linux (unlimited 32-bit support). For 64-bit, it's Fedora (Sway) or Debian (GNOME). I choose these distros because I want to get the manual installation and setup done in under an hour. Worth noting: many distros still support 32-bit, but some (like Debian) are phasing it out by 2028.

That reminds me of that time when Reddit doxxed the alleged Marathon Bomber, ruined his life, and then it turned out it wasn't him. Aside from all the nicknames, I don't see any evidence. But the article shows how to doxx responsibly.