HN user

foxtrottbravo

124 karma
Posts0
Comments46
View on HN
No posts found.

I’m building datenba.ch, a hyper-local “digital village” for a few small communities in rural Germany (Neckartal/Odenwald-ish).

Instead of another social network, it’s a bundle of small, practical community tools under one umbrella, combining of the shelf-software with purpose-built projects of our own.

Our current areas of focus are

- help! a neighbor-to-neighbor help board (rides, errands, PC help, garden/handwork)

- hubs! for shared spaces / tool-sharing / events / social hubs

Right now I’m building the integration surface (claims, roles, provisioning), polishing onboarding, and trying to design help!/hubs! so they’re useful even with low activity.

If anyone’s done (hyper-)local community platforms: I’d love to hear what actually drove adoption and what did not work out for you.

AI created this, and it shows - but yes I agree somewhat for a rough prototype or experiment this might be enough

While yes, these devices are cool and I use them in a couple of projects (mostly centered around home automation), I think there is no good way to count people that way (other than placing them above ingress and egress points).

I think the original use case is not to know whether a dining hall is occupied at all but about how occupied it is (and if he should go to lunch now or wait another 20 minutes).

Those articles by both Jake and his wive are so well written and I would love to read them fully but I can't.

It's gut wrenching that I am just a CT scan away to being in the same (somewhat comparable) situation.

I shouldn't compare fates and still my mind wanders around the topic every time.

The facts they both present in a scientific manner (like remission rates) scare me to my bone. I cannot fathom what he and his loved ones are going through and that makes it even clearer what I have burdened on my wife, children and family.

I know this comment is ultimately me shouting "please let us both live" with many words and maybe this is me being a self serving asshole, maybe it is that. I don't know anymore.

I would love to offer the promise that everything is going to be alright but I cannot. I am just scared as hell and somehow I needed to get this out.

Interesting read on the BMW 7 series Protection vehicle. Here's a tidbit from the field: I've heard, through the grapevine, about a team responsible for the safety of a certain high-profile individual (no names mentioned, of course ). About a year ago, they made a strategic shift away from BMWs as protection vehicles. Why? Because in emergency escape scenarios, it's crucial to be able to move the car even with the doors not fully closed / deliberately open. But with the BMW, if the doors aren't fully closed, the car won't budge. It's a fascinating look at how design features in luxury vehicles can intersect with real-world security needs in unexpected ways.

Disclaimer: I don't have primary knowledge of this, and it's second-hand information from someone I trust personally. As with all such information, grain of salt recommended.

A solution for a major retailer for sportswear where I designed a compact Certificate Authority module for our product that can be used to easily generate TLS Certificate for internal services.

The main benefits for the customer is physical security, the device is built to be savely stored in a safe or at a bank vault when not in use.

It is built in a way which give total control over the keys to the customer so that our support teams managing the services never have to touch a private key and is easy enough to be used by a non-technical employee of our customers.

For the same audience I'm working on replacing the traditional multi-hub-and-spoke VPN we've built over the last few years (around 500 Hubs in Germany + Spokes) with a true End to end encrypted Mesh system with around 2000 wireguard nodes.

Lastly this is something I hope to do in the near future, building out the first cloud strategy, team, infrastucture and procedures for said sports retailer.

Oh I built a Powershell Wrapper around some parts of the Dynect API and a mostly complete wrapper around the tailscale API which is not widely used but made an impacton a handful of people.

At the start of the pandemic I ran a couple of Jitsi Meet instances for people to connect with their close-ones which was used by a low five figur number of people.

I started a project where we 3d printed a few thousand earsavers for wearing A FFP2 mask for for our local school. I think we at least got two school fully supplied and about a thousand pieces where donated to the hospital that saved my life.

I am not sure if this is sarcasm or not but in case it is Not:

No it's not a solution, Netflix already heavily uses IPv6 and most sane v6 endpoints will not be NATed. Maybe they could use v6 Subnets as an Identifier but this would be wonky at best.

This would be a support ticket pandemonium since there are more than enough providers with dynamic IP adressing on v4 and v6.

But to be honest I think they might not need all that, more likely is they use some sort of device ID the modern Smart TVs already have Baked in or build some hash of their own with some device specific identifier (size, resolution, manufactuter, User Agent).

The article and information out there seems to imply they're primarily targeting TVs and devices that are used with TVs (SetTopBoxes, AppleTV, Firetv, Roku et al). So it makes no sense to use a device type unspecific Identifier like the IP in any way

I really find it hard to pinpoint the exact reason. In the moment the "surprise" is what feels overwhelming. I know it's paradox because on the other hand, that's what the interaction my parents and their friends had were - little surprises.

It feels a bit like wanting a surprise gift for Christmas (contrary to something you wished to get) but then being upset because you did not get what you wished for...

I would love, to hear your theories maybe this willhelp explore that feeling a bit more

That‘s me but evermore so I‘m stuck between a rock and a hard place.

As one sibling comment - I too have noticed this: I can remember friends of my parents showing by having a good time completely spontaneously. I liked it very much.

On the other hand I’m one of those people who get irrationally upset by random visits especially when it’s from family.

I guess that’s one reason why it’s so hard for me to be happy.

Show HN: Caddy-SSH 4 years ago

First and foremost, congratulations on bringing the project to this stage - I think it's an impressive piece of work.

I am in no way qualified to trample on your parade but two things came to my mind that pinch a personal nerve of mine and I would really like to have alleviated by you or the folks who know that stuff:

- if your Goal was "secure by default", why did you allow passwords in the first place? Following Caddys recipe would be more like SSH-Keys only, wouldn't it? Is there a reason other than compatibility?

- In that same avenue? Why allow such a thing as downloading authorized keys from a third party? Domain takeovers or account compromises on say Github are a thing - so again while it may be a nice usability aspect isn't that contrary to the secure by default pradigm?

Again thank you for your work and congratulations on the project - those above are just honest questions that came to mind which I would really like to be educated on

Yes it still is, or at least may be depending on your threat model.

CertPinning and CT will go a long way, but do you know that all your software components (not only your webbrowser) use these effectively?

What is about credential snagging with tools like responder? Maybe your client will freely send a set of credentials down the line because of corporate shenanigans.

Depending on the protocol used it might be trivial for a MITM to prevent a secure connection altogether and transparently downgrade your connection to a less secure method (ie Filtering STARTTLS).

There may be a plethora of differences but the retry delivery has nothing to do with the client you're sending your mail from.

That is definitely in the realm of the server being tasked with delivering your mail.

In traditional desktop Mail clients the Outbox is a local folder and stores Mail that hasn't been delivered to the Server tasked with sending out the mail.

The retry method mentioned here is about a Mail that has been delivered to the outgoing mailserver which in turn may have trouble reaching the destination server

Excuse the maybe ignorant question, but I have no feeling for the prices: is this 1$ Tip on a 3$ beer or more like 1$ tip on a 15$ cocktail?

As a European - just put it on the bill in the first place.

I will happily give 15-20% tips for great service, but that is a additional and is given freely - not what is to be expected.

I was about to ask whether I'm missing something here. "Zero Click" just means no user interaction is required right?So from my Perspektive this is just another way of saying Remote Code Execution?

There really isn't something new here other than a fancy name - or I am not seeing the point.

DSL line connected to a AVM Fritzbox forwarding to a Unifi Dream Machine Pro with VLANs for home lan, guest wifi, DMZ, IOT jail

Unifi 24 port switches as backbone

6 Unifi WiFi APs powered over POE

Pihole on 2 virtual machines for redundancy

an old IBM M3650X4 2HE server running Proxmox with dual CPUs, 40 cores, 400GB RAM

Self built freenas with 72TB of storage

Some Pis for home automation stuff

A plethora of servers running on the VM host.

I am Planing to get another Server machine to make it more redundant.

Adding insult to injury is the last Paragraph I actually missed:

If companies like microsoft, facebook, twitter, nintendo or zoom can get hacked, what are our chances as a tiny team to not endup getting attacked ?

It's not about them getting attacked but they weren't the target of a three letter agency Throwing weaponized 0days their way either.

Anything that is remotely considered best practice would have helped:

Like having strong passwords for the "SuperAdmin" account that was compromised. It's called SuperAdmin for a reason don't you think?

Not using unsalted hashes in the first place?

Investing some of your ad revenue in making security updates to a system that was already bad the second it was conceived?

Their whole statement is insulting

Reading this makes me furious, not because they were hacked but because this shitshow of a Website was so damn lazy.

(paraphrasing) "We were stupid 15 years ago and have been lazy ever since" is a slap to the face.

Maybe they should have done something about their platform instead of watching anime with subtitles.

Those people should have their internet privileges permanently removed and the whole site should be burned in a dumpster like the dumpsterfire of security they had running for fucking 15 years.

Let's make it constructive then and talk about something that grinds my gears.

Throwing all ports in the direction of a single host has nothing to to with a DMZ. I know consumer router manufacturers like to call it that but it isn't. It's an Exposed Host setup.

A DMZ is a multi-tiered firewall approach where you have a Firewall between the internet and your DMZ and another one between your DMZ and your LAN

In a normal NATed setup your ports are closed from the outside until a client from inside your network Starts sending packets to the outside.

The Router will keep track of network package going through to the Internet and store it in a table. in case there is an answer from outside of your network the router will look up whether a client started this conversation (there is a corresponding entry in his table) and will forward the incoming packet to the client that started the conversation.

What nintendo is asking you to allow here is to allow any outside packet coming in over UDP to get to the switch whether it first asked for it or not.

This means in practice you won't be able to run any other service which needs an UDP port fowarded in your network. It also means anyone can talk directly to your switch on any port they like whether you want to or not.

And it means, that should something ever take/get the same IP as the switch it will be exposed to the Internet directly

This seems like an obvious case of Support-Team knowledge topic: people are having issues with their switch getting on to the Internet, here is a support article describing a one size fits all solutions. But as a network guy I hatte the assumptions they made. It's the same as telling a user: Just disable the Firewall and it will work.

I feel like it would be a fun excercise to intentionally subvert the assumptions they made and see how they handle it.

Something like putting your Switch on a /30 or Configuring DHCP to assign IPs in decreasing order.