HN user

matteocontrini

677 karma

Founder of DMARCwise

https://dmarcwise.io

Posts33
Comments58
View on HN
dmarcwise.io 17d ago

Why DMARC's new "NP" tag can fail with DNSSEC

matteocontrini
56pts25
dmarcwise.io 2mo ago

DMARC is now an IETF Proposed Standard: what's new in RFCs 9989–9991

matteocontrini
3pts0
bsky.app 1y ago

You can now build an entire SvelteKit app into a single `.html` file

matteocontrini
2pts0
www.hetzner.com 1y ago

Hetzner Object Storage

matteocontrini
11pts7
dmarcwise.io 1y ago

DMARCbis is around the corner: what's changing

matteocontrini
10pts6
www.youtube.com 1y ago

Audio Basics, Ep. 1: Signals, Waves, Mixing, and the Physics of Audio [video]

matteocontrini
1pts0
www.youtube.com 1y ago

The Italian company that bought WeTransfer [video]

matteocontrini
1pts0
twitter.com 1y ago

Hetzner to Announce Managed Kubernetes and Object Storage on 19 September

matteocontrini
6pts2
www.hetzner.com 1y ago

Hetzner Cloud Expands to Singapore

matteocontrini
26pts64
www.todepond.com 2y ago

Being Understood

matteocontrini
2pts0
www.hetzner.com 2y ago

Hetzner lowers pricing of Intel cloud servers

matteocontrini
84pts31
www.hetzner.com 2y ago

New Hetzner storage servers: 88 TB for 104 €

matteocontrini
6pts5
www.hetzner.com 2y ago

New Hetzner dedicated server with AMD EPYC 9454P

matteocontrini
4pts1
robot.hetzner.com 2y ago

Hetzner GPU Server

matteocontrini
249pts157
www.hetzner.com 2y ago

New Hetzner Managed Servers

matteocontrini
2pts0
github.com 2y ago

GitHub Copilot Chat in JetBrains IDEs

matteocontrini
20pts3
github.blog 2y ago

GitHub Advanced Security: AI-powered application security testing

matteocontrini
7pts1
twitter.com 2y ago

Brevo (formerly Sendinblue) forgot to renew their domain

matteocontrini
3pts0
rig.dev 2y ago

Rig.dev: The open-source application platform for Kubernetes

matteocontrini
6pts0
www.rewind.ai 2y ago

Rewind.ai now has a free plan

matteocontrini
1pts0
www.hetzner.com 2y ago

New Hetzner dedicated vCPU cloud servers with AMD Epyc CPUs

matteocontrini
56pts20
hetzner-cloud.de 3y ago

Hetzner Cloud is building S3-compatible object storage

matteocontrini
5pts0
blog.cloudflare.com 3y ago

Are you measuring what matters? A fresh look at Time To First Byte

matteocontrini
3pts0
help.openai.com 3y ago

How ChatGPT and Our Language Models Are Developed

matteocontrini
3pts0
www.apple.com 3y ago

Apple introduces new Mac mini with M2 and M2 Pro

matteocontrini
6pts1
www.apple.com 3y ago

Apple unveils M2 Pro and M2 Max

matteocontrini
36pts16
www.hetzner.com 3y ago

Hetzner continues its growth in the US with a new location

matteocontrini
545pts334
github.blog 4y ago

View commit history across file renames and moves (GitHub)

matteocontrini
3pts0
www.hetzner.com 5y ago

Hetzner: New dedicated vCPU servers with AMD EPYC 7003 are now available

matteocontrini
3pts0
www.emailmeter.com 5y ago

Email Meter WFH – Discover how working from home changed your email habits

matteocontrini
1pts0

Copilot's main target is probably enterprises, who already pay per token with both Claude and Codex, on top of a per-seat subscription. With Copilot they get both Claude and Codex and many other models in one subscription. Also, per-seat price includes usage and the cost of extra usage is identical to going direct with model providers. I'd say it makes sense.

I've run some benchmarks a couple years ago, I don't have them at hand unfortunately but off the top of my mind, seqread 4k produced around 1500 IOPS while seqwrite was like a third of that. The practical performance was abysmal, I moved PostgreSQL storage to a volume and it was very noticeably slower just by browsing the web app (compared to NVMe SSD storage).

For comparison, I'm now using UpCloud which uses network-attached storage for all volumes and easily hits 10k IOPS (up to 100k with some tuning).

I certainly may have missed something while testing this so I'm happy if someone else wants to contribute and correct me if I'm wrong.

Beware of Hetzner Cloud volumes, they're unusable for a database, they're too slow. I'm not sure what workloads people run on Hetzner but the low-performance volumes and unreliable load balancers don't seem like a good fit for real production stuff with traffic.

VP9 and AV1 are less affected not because they're free and open source, but because they're backed by large-enough companies (Google) and a consortium that promised they won't claim royalties for the patents used in the formats. Companies outside Google or the consortium can still claim royalties, and indeed they do. See the Sisvel VP9/AV1 patent pool for an example of patent holders claiming royalties for technologies used in VP9 and AV1.

It would still fail if you were unluckily on the new proxy (it's not very clear why if the feature was not enabled, indeed):

Unrelated to this incident, we were and are currently migrating our customer traffic to a new version of our proxy service, internally known as FL2. Both versions were affected by the issue, although the impact observed was different.

Customers deployed on the new FL2 proxy engine, observed HTTP 5xx errors. Customers on our old proxy engine, known as FL, did not see errors, but bot scores were not generated correctly, resulting in all traffic receiving a bot score of zero. Customers that had rules deployed to block bots would have seen large numbers of false positives. Customers who were not using our bot score in their rules did not see any impact.

What the article says is true, but Firefox mobile doesn't get the basics right. From weird decisions like the new tab page not actually being a tab like in every other browser on Earth, to consistent bugs and lack of polish in basics functions like scroll direction locking or scrolling to hide the top bar.

Another thing is that they appear to have some spam scanning on outbound emails and when they detect something suspicious they simply drop the email silently, and nobody will ever know about it.

Both the "require DKIM" and the mailing lists problem were discussed at length by the working group, with many having opposite strong opinions, so in the end the only consensus that was reached is a trade-off that left everyone unsatisfied.

There's hope that the mailing list problem will be solved by DKIM2 [1], since ARC has the problem of trusting the intermediaries.

On `pct`, you're right in theory, but it seems that implementers didn't get the message. From the mailing list [2]:

That's how we intended it when we wrote that, and that's how early implementations did it. But maybe this is the lesson: People have inferred lots of different things from that rather straightforward definition, so maybe it's more ambiguous than we realized all those years ago.

And the draft says [3]:

Operational experience showed that the pct tag was usually not accurately applied, unless the value specified was either 0 or 100 (the default), and the inaccuracies with other values varied widely from one implementation to another.

I agree that replacing it with another tag is such a confusing and unnecessary change, though.

[1] https://datatracker.ietf.org/doc/draft-gondwana-dkim2-motiva...

[2] https://mailarchive.ietf.org/arch/msg/dmarc/Sk6JnDlXH_MkM4xm...

[3] https://datatracker.ietf.org/doc/html/draft-ietf-dmarc-dmarc...

Yeah, that was one of the controversial parts. I updated that paragraph to be more precise.

The draft says:

It is therefore critical that Mail Receivers *MUST NOT* reject incoming messages solely on the basis of a "p=reject" policy by the sending domain. Mail Receivers must use the DMARC policy as part of their disposition decision, along with other knowledge and analysis. "Other knowledge and analysis" here might refer to observed sending patterns for properly-authenticated mail using the sending domain, content filtering, etc. In the absence of other knowledge and analysis, Mail Receivers *MUST* treat such failing mail as if the policy were "p=quarantine" rather than "p=reject".

So basically `p=reject` doesn't actually mean reject anymore and receivers should instead treat it as quarantine by default.

The document then goes on by saying "nobody will listen to us anyway", which is an interesting thing to read in what will be a Proposed Standard:

In practice, despite this advice, few Mail Receivers apply any mitigation techniques when receiving indirect mail flows, few organizations consider the effect of DMARC policies on their users' indirect mail, and it is unlikely that any advice in this document will change that.

Italy built the Leonardo HPC cluster, it's one of the largest in EU and was created by a consortium of universities. After just over a year it's already at full capacity and expansion plans have been anticipated because of this.