HN user

maxgashkov

311 karma
Posts0
Comments122
View on HN
No posts found.

I do have love/hate relationship with passkeys.

Love: I truly have redundancy for most critical accounts, meaning I have 4 separate passkeys assigned, each not tied to one SPoF -- one in 1Password, one in iCloud -- both synced everywhere I logged in and if I'm ever banned/locked out of both of them somehow, I still have two additional USB keys (token2) as a fallback.

Hate: every fucking service seems to have different idea on how to implement them, whether to allow them as the only factor, how many to allow to have in any particular account.

On a separate note, for the hw side of things I'm kinda sad that old yubikey nano approach when the token is just sitting flush on the side of the laptop and I tap it occasionally is just dead, because every vendor moved to mandatory PIN to store passkeys on hardware tokens. I get the rationale but still.

I never understood the popularity of Tailscale, though that is on me.

I guess self hosting Wireguard is too boring to warrant any further discussion?

It's popular because you don't have to deal with NAT punching. It "just works", all the time. And Wireguard is not too boring, it's just not enough on its own.

I'm all for self-hosting and this is exactly why I prefer to use Tailscale and not have to manage jump-hosts and STUN points on some cloud, given that I won't be able to make it as reliable as Tailscale and as cheap as Tailscale (effectively $0). So this is literally the only tradeoff I made while self-hosting everything else.

Two more things:

- well-designed apps retain enough state to be useful offline or in places with spotty coverage; PWAs can kinda be made to work like this but IIRC iOS will happily evict them under disk pressure;

- notifications. I've read that Apple have implemented them for home screen installed web apps but for reasons unknown I have not seen this in action even once.

If they haven't relaxed the classifier this makes little to no difference as the model is essentially unusable no matter the token quotas.

What is the incentive for me to join the public mesh? Do you have any fairness guarantees, e.g. if I contribute 1/8th of the VRAM required to run a particular model, do I get at least 1/16th of the inference share, or anything similar to this?

I've settled on using .internal and Knot as a authoritative NS, step CA + ACME to issue short-lived certs, and a Split DNS resolver from Tailscale as the only external dependency (mostly as a convenience for when I'm on the road).

I do have a luxury of all the homelab VMs being rebuildable via IaC, so I've just injected CA trust at that step.

The biggest PITA so far were 3rd party docker images, each with its own way to inject custom CA.

iOS devices were surprisingly easy to handle.

There are degrees to "AI contributors". E.g. recently I have stumbled upon rare edge case in an OSS tool written in Rust. It would have taken me a week+ to be able to contribute a minor change in a clean and Rust-idiomatic way as this is not the language I'm proficient in, and Claude did that in 1 hour, with 3 or 4 rounds of tweaks from me to reduce the walls of text and make the contribution matching the of the original project. Alternative was just swiping it under the rug or opening an issue instead (thus placing the burden on the maintainer).

I do think I helped out.

And I have discovered this edge case when fiddling with my homelab which is my hobby.

Lexa (to be more precise, Lyoha) is a shortened version of Alexey (Aleksei); but if it wasn't reserved for that, Lyoha sounds a bit rude (and a more gentle version akin to Sasha would be Lyosha).

Proposed mitigations look weak:

- DNS block & SNI filtering: I expect BrightData to rotate the endpoints if this issues gains enough attention. It will take some time once all the apps embedding the SDK catch up, but if they're smart SDK may already have a backup C&C connection they will try to reach out to after prolonged unavailability of the current endpoints.

- TLS fingerprint: unless SDK pins it, it's the cheapest one to rotate continously.

- MDM solution: almost unattainable to private users; not clear how stable the SDK name is to rely on.

Not saying I have a better approach. It seems behavior like this should be explicitly banned on Apple/Google's side with immediate termination of their publisher accounts.

DaVinci Resolve 21 2 months ago

I tried Darktable and I don't doubt it's a powerful RAW editing software but it feels like to be effective with it you need to care about the software more than you do about photography. With Lightroom/Capture One etc. it's the opposite. Darktable is just too 'out there'

Looking for a REMOTE contract or full-time work:

  Location: Japan (Kobe)
  Remote: yes, with this time overlap for synchronous work:
    - PT: 15:00~22:00  &  06:00~08:00
    - CT: 17:00~24:00  &  08:00~10:00
    - ET: 18:00~01:00  &  09:00~11:00
  Willing to relocate: within Japan only
  Technologies: AWS, GCP, Terraform, k8s, Python, Go, PHP, Alpine, Debian, Ubuntu, PgSQL, MySQL, Wireguard
  Résumé/CV: https://assets.maxgv.dev/cv/Resume_MaxGashkov_2026.pdf
  Email: info@maxgv.dev
  Linkedin: https://www.linkedin.com/in/maxgashkov/
Mostly looking for infrastructure-related work (cloud or on-prem). If you struggle with your cloud bill, do reach out to me.

Will also manage a focused engineering team if needed.

Curious/optimistic about LLMs.

This is not about enjoying or not enjoying jail. If you happen to live and work in Japan in a typical job, getting arrested and held within this process for 23 days almost certainly means you're getting fired because you essentially have no contact with the outside world and even if you manage to sneak a word out through your lawyer, most of the employment contracts have clauses to extent of automatic termination for both missing enough days and breaking moral character.

So even if the prosecution decides to drop your case, you're already fucked -- this is not how proper justice system should work.

I'm on a fence about this.

First, the biggest issue r/n is the concern that external internet will be limited to a point of no return, for this meshtastic is quite useless because to go across the border you need powerful transmitters and risk of placing and maintaining them near the border. In russia this is not only risk of going to prison but also being literally shot if border patrol/FSB overreacts. Even if you're successful bandwidth is miniscule compared to what a modern country needs to communicate internationally.

Second, due to Ukraine piggybacking on cellular networks for drone targeting/control cell service is frequently disrupted by authorities in the areas of a likely attack (it's obviously as effective as this sounds compounded by general incompetence of the government). While they cannot shut it down completely because russia still doesn't want to go back to the stone age, this concern is largely non-existent for meshtastic though. If it becomes widely popular and coverage expands, it also could be used by Ukraine as a control network, and in this case I would expect russian authorities to just jam the whole frequency range and be done with it. So the moment it becomes viable alternative is the moment it will be shut down.

One of the use cases is pairing it up with ATAK or similar tactical awareness system during SAR operations by volunteer brigades in remote areas with spotty coverage by regular networks.

More info here if someone's interested: https://www.civtak.org/

They absolutely are. Fun example: when Revolut launched in Japan few years back they had a period of a relatively explosive success (especially within the immigrant community), so most of the cards of the period were issued with the same expiration month and with the same IIN (I'm assuming specific to Japan as well) which left very little entropy and lead to brute-force attacks via merchants not requiring 3DS (Uber etc.). Within only one community (approx. 1.5k people) we have had a handful of a 100% verified cases when the card was compromised without any exposure at all (i.e. the card was not used online or offline).

In all cases Revolut promptly reverted the charges and eventually they did a complete reissue of the cards for Japanese market (not sure how they've got around the entropy issue: maybe they've randomized the expiry dates or spread out IINs some more).

Not sure why your comment is downvoted, because it hits the issue dead center, namely it's completely possible to pass either of the required tests (N2/J2) and not being able to speak a single word of Japanese in a live conversation.

That's why at least one category of applicants abusing the visa (Chinese) will continue to do so without any issues.

Thank god. The only remaining failure mode I’ve seen with LE certs recently is API key used to manipulate DNS records for the DNS-01 challenge via some provider (Cloudflare etc.) expiring or being disabled during improper user offboarding.

Japan Post represents only a portion of shipping providers in Japan, for our idea to work others will need the same privileged access to the system: Yamato, Sagawa etc.

This will also require to alter the package label on the last mile because requiring the courier to scan every package or letter before they could even see an apartment number will slow things down to a crawl.

It solves an issue of Japanese addressing system being a total mess. There is basically a wild wild west when it comes to the address part on most of the ecommerce sites in Japan: some offer address auto-complete via zip code, some don't; some require a building name, some don't; and the address itself may be written down in different ways. Having a source of truth in a form of a provider which has vested interest in keeping the address uniformly correct on entry is god sent here.

almost all employers will pay for employees to commute by public transport but not by car, because the government heavily incentivises them to do so

Could you clarify this? To my knowledge only 2 things that could qualify as incentive exist:

- commuting allowances are not considered taxable income for employee

- commuting allowance could be used to reduce tax base for the business

But this is not something I'd call 'heavily'.

My understanding is that commute is universally covered as this is an expected job benefit in Japan, and commuting by car is disencouraged in cities due to the increased insurance liability (as commuting time could be considered work time and injuries incurred to 3rd party will expose the company to liability as well).