Copilot's main target is probably enterprises, who already pay per token with both Claude and Codex, on top of a per-seat subscription. With Copilot they get both Claude and Codex and many other models in one subscription. Also, per-seat price includes usage and the cost of extra usage is identical to going direct with model providers. I'd say it makes sense.
HN user
matteocontrini
Founder of DMARCwise
https://dmarcwise.io
As far as I know, the DANE spec (RFC 7671) requires DNSSEC to be enabled, while MTA-STS does not.
I've run some benchmarks a couple years ago, I don't have them at hand unfortunately but off the top of my mind, seqread 4k produced around 1500 IOPS while seqwrite was like a third of that. The practical performance was abysmal, I moved PostgreSQL storage to a volume and it was very noticeably slower just by browsing the web app (compared to NVMe SSD storage).
For comparison, I'm now using UpCloud which uses network-attached storage for all volumes and easily hits 10k IOPS (up to 100k with some tuning).
I certainly may have missed something while testing this so I'm happy if someone else wants to contribute and correct me if I'm wrong.
Beware of Hetzner Cloud volumes, they're unusable for a database, they're too slow. I'm not sure what workloads people run on Hetzner but the low-performance volumes and unreliable load balancers don't seem like a good fit for real production stuff with traffic.
The EU Data Act forbids cloud switching charges, that's why they made these changes (while presenting them as if they cared about customers being charged for switching away):
https://digital-strategy.ec.europa.eu/en/factpages/data-act-...
Because they also offer free DNS and email. There are no ads.
They're working on a new manager UI that should solve most pain points:
Someone that worked at Vimeo until last month tweeted:
Reviving this account to say: Almost everyone at Vimeo was laid off yesterday, including the entire video team. If you're looking for talented engineers, there are a few on the market.
Finally? This content has been up since 2018.
Did you miss Thunderbird Pro?
The status page was updated 6 minutes after the first internal alert was triggered (8:50 -> 8:56:26 UTC), I wouldn't say this is too long.
VP9 and AV1 are less affected not because they're free and open source, but because they're backed by large-enough companies (Google) and a consortium that promised they won't claim royalties for the patents used in the formats. Companies outside Google or the consortium can still claim royalties, and indeed they do. See the Sisvel VP9/AV1 patent pool for an example of patent holders claiming royalties for technologies used in VP9 and AV1.
It would still fail if you were unluckily on the new proxy (it's not very clear why if the feature was not enabled, indeed):
Unrelated to this incident, we were and are currently migrating our customer traffic to a new version of our proxy service, internally known as FL2. Both versions were affected by the issue, although the impact observed was different.
Customers deployed on the new FL2 proxy engine, observed HTTP 5xx errors. Customers on our old proxy engine, known as FL, did not see errors, but bot scores were not generated correctly, resulting in all traffic receiving a bot score of zero. Customers that had rules deployed to block bots would have seen large numbers of false positives. Customers who were not using our bot score in their rules did not see any impact.
This was not about DDoS defense but the Bot Management feature, which is a paid Enterprise-only feature not enabled by default to block automated requests regardless of whether an attack is going on.
https://developers.cloudflare.com/bots/get-started/bot-manag...
What the article says is true, but Firefox mobile doesn't get the basics right. From weird decisions like the new tab page not actually being a tab like in every other browser on Earth, to consistent bugs and lack of polish in basics functions like scroll direction locking or scrolling to hide the top bar.
I'm referring to outbound email being silently dropped, not inbound email being rejected or put into Junk.
Another thing is that they appear to have some spam scanning on outbound emails and when they detect something suspicious they simply drop the email silently, and nobody will ever know about it.
It got better though, especially with the new 3-AZ regions.
Apparently ai.google.com currently redirects to ai.google, which is different from ai.google.dev where the Gemini stuff actually is.
ifconfig.me is not behind Cloudflare, at least currently.
What do you mean? Videos on that page are served by CloudFront. If you're seeing issues it may be that videos are not encoded for web playback (faststart, etc.) but I haven't checked.
It seems that ChatGPT Enterprise already has many of these:
Both the "require DKIM" and the mailing lists problem were discussed at length by the working group, with many having opposite strong opinions, so in the end the only consensus that was reached is a trade-off that left everyone unsatisfied.
There's hope that the mailing list problem will be solved by DKIM2 [1], since ARC has the problem of trusting the intermediaries.
On `pct`, you're right in theory, but it seems that implementers didn't get the message. From the mailing list [2]:
That's how we intended it when we wrote that, and that's how early implementations did it. But maybe this is the lesson: People have inferred lots of different things from that rather straightforward definition, so maybe it's more ambiguous than we realized all those years ago.
And the draft says [3]:
Operational experience showed that the pct tag was usually not accurately applied, unless the value specified was either 0 or 100 (the default), and the inaccuracies with other values varied widely from one implementation to another.
I agree that replacing it with another tag is such a confusing and unnecessary change, though.
[1] https://datatracker.ietf.org/doc/draft-gondwana-dkim2-motiva...
[2] https://mailarchive.ietf.org/arch/msg/dmarc/Sk6JnDlXH_MkM4xm...
[3] https://datatracker.ietf.org/doc/html/draft-ietf-dmarc-dmarc...
Yeah, that was one of the controversial parts. I updated that paragraph to be more precise.
The draft says:
It is therefore critical that Mail Receivers *MUST NOT* reject incoming messages solely on the basis of a "p=reject" policy by the sending domain. Mail Receivers must use the DMARC policy as part of their disposition decision, along with other knowledge and analysis. "Other knowledge and analysis" here might refer to observed sending patterns for properly-authenticated mail using the sending domain, content filtering, etc. In the absence of other knowledge and analysis, Mail Receivers *MUST* treat such failing mail as if the policy were "p=quarantine" rather than "p=reject".
So basically `p=reject` doesn't actually mean reject anymore and receivers should instead treat it as quarantine by default.
The document then goes on by saying "nobody will listen to us anyway", which is an interesting thing to read in what will be a Proposed Standard:
In practice, despite this advice, few Mail Receivers apply any mitigation techniques when receiving indirect mail flows, few organizations consider the effect of DMARC policies on their users' indirect mail, and it is unlikely that any advice in this document will change that.
I don't know what people use object storage for, but R2 is missing lots of features and it's not a replacement for S3 in many cases.
For example: no regions, no replication (and no AZs either), limited lifecycle management, no versioning, no MFA protection, no intelligent tiering, no customer encryption, no IAM, etc.
Here's the tweet: https://twitter.com/Hetzner_Online/status/183422842493353593...
Unfortunately managed Kubernetes isn't coming soon: https://twitter.com/bebehei/status/1838119096254173348
Where does it say they don't have the keys? It literally says they store the keys in their own datacenters. Which is obvious anyway, otherwise the API wouldn't be able to return the unencrypted data.
There are actually hints they're working on S3-compatible object storage:
https://www.reddit.com/r/hetzner/comments/14e8asj/object_sto...
The thing is that Cloudflare has no proper channels. Anyone that has tried Cloudfare's support (even as a paying customer) knows that it's almost impossible to get a sensible answer to anything.
I wrote about it here last year: https://matteosonoio.it/cloudflare-support/
Italy built the Leonardo HPC cluster, it's one of the largest in EU and was created by a consortium of universities. After just over a year it's already at full capacity and expansion plans have been anticipated because of this.