HN user

kolp

314 karma
Posts3
Comments76
View on HN
Bunny Database 6 months ago

I've been using their DNS (migrating away from Cloudflare) for over a year and I've found it solid. Good latency and fast propagation. Custom nameservers are easy to setup. Migrating from CF is easy too - just export your zonefile from CF and import it to Bunny and you're good to go.

I had to use tailscale to bust through port forwarding on chained routers because, even with ports configured correctly, wireguard wasn't able to get through.

My use case was for remote access into a home-hosted Nextcloud instance, via an ISP supplied fibre router (IPv4, not CGNAT), then my own Gl iNet router, then to my Nextcloud instance.

Despite opening up port forwarding correctly, wireguard just couldn't get through that chain, whereas tailscale got through with no problems.

Downside of using tailscale is that it's messy to use at the same time as a VPN on your client device. Split tunnelling supposedly works, but I couldn't get it going.

When I lived in NL, it was explained to me that closing the curtains would imply, in some sort of weird Calvinistic belief, that the occupants were engaged in some nefarious activities; therefore the curtains are left open to show that the occupants have nothing to hide and are engaged only in wholesome activities.

The other side of the social contract obliges passers-by to not look inside.

The other strange thing that I found is that some apartments have little spy mirrors mounted on the exterior wall to allow the occupants to monitor what's going on in the street.

These Cloudflare WAF rules (not my creation) should help mitigate some of the threat by blocking TOR traffic, blocking bots and blocking datacenter IPs (eg bots running on a VPS). The rules are granular so you can tweak them when you start to identify the traffic sources of the bad actors.

You'll probably need to block entire ASNs. I assume most of your legitimate customers aren't using VPNs or eg DigitalOcean droplets to access your site.

https://webagencyhero.com/cloudflare-waf-rules-v3/

In addition, you should start looking for alternatives to PayPal in case they decide to drop you.

Might be worth adding that Bunny offers DNS services as well.

I've started switching a few sites from Cloudflare to Bunny and the experience has been great so far. Bunny offers custom name servers as well, so if you can setup glue records with your domain registrar, it's easy enough to have custom nameservers, DNS and CDN hosted with Bunny. Cheap as chips and great performance so far.

I'm looking for a decent alternative to ReCaptcha or Turnstile but haven't found one yet that has easy integration (form builders etc.)

My move away from US providers isn't in protest - it's just risk avoidance. The unpredictable nature of the current administration reduces the attractiveness of using US based providers.

[dead] 1 year ago

Irish police used newly updated Cellebrite system to bypass security on murder suspect's locked phone. Suspect immediately changed plea to guilty.

Irish government has banned purchases of military equipment from Israel, but the ban doesn't extend to purchases by the police force.

SFR will switch you from cgnat to ipv4 if you contact customer support and explain that you work from home and need to open specific ports to access your work servers or VPN. I did just this a month ago. Takes less than 24 hours and you should be OK on ipv4.

Gobshite, while it might appear to be "mouth shitter", isn't used to describe a braggard bullshitter or liar, as the components might suggest. It's more commonly used to describe a person who's both stupidly incompetent and contemptible, as in:

"Why is the system down?"

"Dave pushed the updates to the production server again."

"F*king gobshite."

Gobdaw is a less offensive variation, typically used by those who say fe_k instead of fu_k.

Lane assistance is fine, if it can be permanently disabled. But I've rented cars where it seemed to have been hard coded to default = ON for each trip. Every time I started the car, I had to go into the car config (great fun on a rental with a different GUI each time) and disable it before driving.

Otherwise, in city driving, it's like some paranoid front seat passenger grabs the wheel every 30 seconds.

First, nobody owns a domain; it is assigned to a registrant, by the registry, via the registrar. No domain "owner" has ownership rights; you have the right to use the domain subject to the rules of the registry. If the rules of the registry require the registrant to be a citizen or body of the EU and the registrant no longer meets that requirement, the registrant loses the right to use the domain.

Your proposed solution of grandfathering existing registrations would cause confusion or uncertainty for end users (site visitors) who could not ascertain with confidence that the organisation with which they were dealing was actually in the EU, or registered to an EU citizen or body.

Your assertion that the EU enforced the established rules because they were "being dicks" to the UK is similar to the anti-EU tropes spouted by the anti-EU press in the UK, eg the EU is punishing Brits by making them use non-EU passport lanes, restricting their visits to 90 days, etc. Your fellow citizens voted (unfortunately) to leave the organisation and these are the consequences of non-membership. If you decide to leave your golf club, you don't get to continue using the golf course and clubhouse.

It's currently operated in Dublin. Barcode on back of each of 3 bins (recyclables, non-recyclables and organic). Recyclables and organic are free, and non-recyclables includes a quota of x kg per month included in your monthly fee. You pay extra per kg if you go over the quota for non-recyclables in any month. The system encourages recycling, but at the risk of people contaminating the (free) recyclables bin with non recyclable material.

Another happy user of Purelymail here. The GUI is unpolished, but deliverability and reliability have been excellent for me in the few years that I've used it. Unlimited custom domains and inexpensive.

It's not suitable for bulk sending, but for transactional and personal email, I've found it meets my needs.

Be warned, however, that it appears to be a one-man band, and if he goes under a bus...

I'm also a happy user of Migadu. More polished GUI and more features. I've never hit their limits, so not sure how suitable it would be for a medium-sized enterprise. As with Purelymail, it's not intended to be used as a bulk sending service.

I like them as a company, but I wouldn't use them as a registrar if there was a significant risk of UDRP. Domains are not their core business and customer service is close to non-existent if you're not at least a pro-level customer. For your case, you should use a dedicated domain registrar, such as the ones I outlined earlier. Infomaniak is another registrar that I've found good in terms of customer service and price. They're Swiss based, and I've found them to be competent and professional.

Most enterprise class registrars (registry =/= registrar) are brand protection and brand monitoring services. Quite expensive for individuals and probably not in the price range of OP, according to the description of his circumstances.

I've used name.com, namecheap.com, sav.com and porkbun.com as registrars without difficulty, although one will always find anecdotal reports of problems other users have had with any service.

GoDaddy, on the other hand, is to be avoided. It's like the PayPal of domains. Awful customer service and dark patterns everywhere.

Domain investor here. Some, but not all of the advice here is absolutely dreadful and is an example of why you should not take advice from random strangers on the internet.

Some basic rules if you wish to keep the domain:

* Don't offer to sell the domain. If you are contacted by a prospective buyer, just decline, saying that the domain is not for sale. Don't counter-offer or enter into discussions or negotiations.

* Don't put ads or links to third-party commercial entities on your website. If you're going to use it for business purposes, make sure that it's just for your business, which incorprates your family name, eg FamilyName IT Services Ltd.

* Make sure your website has an "About Me/Us" page, which briefly outlines who you are, ensuring that you mention that your Family Name is the same as the domain name.

* The advice in this thread regarding use of 2FA on everything is sound. I've a high value domain portfolio and receive password reset requests every week, triggered by bad actors trying to access anything that they can think of that might give them access to accounts.

* Don't use GoDaddy or any or their network.

* Read up on UDRP (dispute resolution) and Reverse Name Hijacking if you want to get up to speed on the legal and procedural issues that might affect you.

* Domain disputes are a specialised field and you would need the advice of a specialised lawyer if you find yourself the recipient of a UDRP complaint. John Berryhill (I've no connection) is well regarded in this area, and I'm sure that there are others. He would be my first port of call.

At highway speed here in France, (110-130 km/hr), the wind noise is sufficient to cause tinnitus for me, if I'm not wearing ear protection under my helmet. The bike style is a factor - my touring bike has a movable windshield that can push the airflow above my head, but the wind noise from the daily bike, with a tiny windshield, is like sticking your head out the window of a moving car.

I follow the news in France, but the reason people were scrambling to fill their cars had nothing to do with an energy crisis.

The first wave of "people scrambling to fill their cars" was caused by union strikes at French refineries in October, leading to supply shortages at the pumps.

The second wave was caused by people scrambling to fill up their cars at a lower price per litre, before the government "subsidy" on fuel was reduced in mid-November. Whatever one might think of people who will sit in a traffic queue for several hours to save €10 at the pump, it has nothing to do with an energy crisis.

>I can't imagine who the "left wing" writers on it are supposed to be?

Rod Liddle - his brain is addled by the booze, but he still manages to phone in a few hundred words each fortnight.

One way of looking at the "destruction" of the value of the property is based on Net Present Value of future rent payments. Let's take one hypothetical building, its owner and its tenant.

The market value of this building (not its construction cost) is the Net Present Value of future rent payments to be made by a tenant to the owner. There is a scheduled, anticipated transfer of value from tenant to owner based upon the agreed market rental value of the building.

When the agreed market rental rate declines, the amount of value to be transferred from tenant to owner declines and consequently, the present value of those future payments is lower. This is the basis for journalists or commentators to say that value has been destroyed. But, the value hasn't been "destroyed"; it has been transferred to the tenant in the form of the net present value of his rent reduction.

Scammers are sticking QR Codes on parking meters in Austin, Texas. The victim scans the QR code using a smartphone and is taken to a fake parking payment site.

Personally, I think a better scam would be to follow clampers (parking boot in US), find cars that have been clamped and replace the release notice instructions with your own version and payment QR code.