HN user

mholt

11,843 karma

I'm the author of the Caddy web server. https://caddyserver.com

Twitter: https://twitter.com/mholt6

Personal: https://matt.life

[ my public key: https://keybase.io/mholt; my proof: https://keybase.io/mholt/sigs/X_pNtQp3_Et_7qwkBKVjmZv4dl7vP8bX83hu4N9lyz8 ]

(I do not use Keybase)

Posts115
Comments1,741
View on HN
timelinize.com 9mo ago

Show HN: Timelinize – Privately organize your own data from everywhere, locally

mholt
630pts163
unmitigatedrisk.com 10mo ago

Incident Mis-Issued Certificates for IP Address 1.1.1.1

mholt
17pts2
dunglas.dev 1y ago

FrankenPHP 1.3: Performance Improvements

mholt
1pts0
www.cpsc.gov 2y ago

Recalls

mholt
1pts0
caddyserver.com 2y ago

Profiling Caddy

mholt
14pts2
blog.laravel.com 2y ago

Octane and FrankenPHP

mholt
1pts0
en.wikipedia.org 2y ago

Neijuan

mholt
2pts1
gis.stackexchange.com 2y ago

111,111.1 meters is reliably 1 degree of latitude

mholt
341pts259
caddy.community 3y ago

Caddy Announcements for 2023

mholt
2pts0
news.ycombinator.com 3y ago

Ask HN: Map services that offer historical tiles?

mholt
1pts0
matt.life 4y ago

The Asymmetry of Open Source

mholt
121pts43
caddy.community 4y ago

HTTPS in your VPN: Caddy now uses TLS certificates from Tailscale

mholt
4pts0
github.com 5y ago

Caddy 2.4 Released

mholt
5pts1
dgraph.io 5y ago

Building a Kubernetes Ingress Controller with Caddy

mholt
2pts0
news.ycombinator.com 5y ago

Ask HN: What companies are you excited about?

mholt
63pts77
github.com 5y ago

Show HN: Project Conncept – Multiplex Over TCP/UDP with Composable Handlers

mholt
3pts0
github.com 5y ago

Caddy 2.2 Released

mholt
3pts0
caddy.community 6y ago

How to sleep through the next Internet-breaking Cloudflare outage

mholt
2pts0
caddyserver.com 6y ago

Show HN: Caddy 2

mholt
778pts240
github.blog 6y ago

NPM Is Joining GitHub

mholt
1829pts557
docs.https.dev 6y ago

Best Practices for Acme Client Operations

mholt
1pts0
waynehale.wordpress.com 6y ago

Oops: What to do if the Space Shuttle payload bay doors don't close properly

mholt
4pts0
caddyserver.com 7y ago

Caddy 2 Is Ready for Developers

mholt
3pts0
github.com 7y ago

Show HN: Caddy 2 Development Branch

mholt
3pts1
caddyserver.com 7y ago

Caddy 1.0, Caddy 2, and Caddy Enterprise

mholt
71pts42
caddy.community 7y ago

Caddy 0.11.5 Released with TLS 1.3 Support

mholt
6pts0
github.com 7y ago

Show HN: Timeliner – A tool to download all your online content

mholt
9pts0
github.com 7y ago

Show HN: CertMagic – Caddy's automagic HTTPS features as a Go library

mholt
33pts2
datatracker.ietf.org 7y ago

Statement from the IETF SEC Area Directors Regarding “enterprise TLS”

mholt
3pts0
github.com 7y ago

Show HN: Archiver 3.1 – Cross-platform, multi-format archive utility in Go

mholt
6pts0
Grok 4.5 14 days ago

Thank you! I'm glad you like it.

Sure. I'm not sure if I will actually publish this thing, but I can show you: https://x.com/mholt6/status/2074986102428139754

I wanted a phone app rather than yet another electronic device. Phones do not have great screens in bright sunlight, and they run hot, so it's not ideal for a bike computer in the first place. But I can't deny the convenience of the multipurpose tool that is my phone.

This app will have a few UI/UX modes. The default is the futuristic-looking HUD, but it has a low-power mode that's mostly monochrome on black, and an even lower-power "Cruise mode" that removes the map entirely and just shows you speed, approximate heading, and nav directions. Still very WIP and mostly for my own amusement!

Grok 4.5 14 days ago

Of the 3 models I tried, Grok did the best at making an iOS app I wanted for personal use (a bike computer with specific qualities). (Claude just gave up and did an HTML/CSS implementation but I insisted on native SwiftUI+Metal.) Grok definitely fumbles sometimes, but I have been surprised what it CAN intuit versus me having to micromanage it.

(I am not an iOS developer, so getting something specific that I needed in a few hours/days was really helpful instead of spending months/years learning the language, APIs, etc.) (I am absolutely not "vibe-coding" Caddy btw, just tinkering with it for personal projects.)

Googlebook 2 months ago

This page crashes in my Google-based browser. I can't scroll down more than ~50 pixels.

Using profanity indicates a weak vocabulary. A lack of discipline. A degree of unrefinement unbecoming of astronauts representing the "best" of humanity and their country.

Depending on the type of profanity it can divide societies by reinforcing social schisms/prejudices. Such words typically cluster around areas of cultural discomfort such as religion, sex, and hygiene, causing polarizing emotional reactions. It's biological as well as cultural.

Seems like the "best and bravest humanity has to offer" can probably represent a little better than that for one of the most significant feats of history.

Yeah but if you need Internet failover, cell phone towers are likely flooded. Starlink will be much more available (probably).

And yet, try getting a full backup of your Google phone onto your own computer. (Without rooting/wiping the whole thing.) Heck, try getting just your text messages off (without a separate app)!

You can't. (Last time I checked.) The backup is encrypted in the cloud, and the only way to download it is to restore it to a phone.

Whereas I can just plug in my iPhone and get a full backup, complete with sqlite manifest, completely accessible. Text messages, photo library, everything.

I never loved the idea of GSB or centralized blocklists in general due to the consequences of being wrong, or the implications for censorship.

So for my masters' thesis about 6-7 years ago now (sheesh) I proposed some alternative, privacy-preserving methods to help keep users safe with their web browsers: https://scholarsarchive.byu.edu/etd/7403/

I think Chrome adopted one or two of the ideas. Nowadays the methods might need to be updated especially in a world of LLMs, but regardless, my hope was/is that the industry will refine some of these approaches and ship them.

If you look at the R1 pages, you'll see those pages, though scroll-heavy, at least contain more useful info. I'm hoping that after R2 is actually available to order, that they'll update the page with more information. It's still early.

We can of course host our code elsewhere, the problem is the community is kind of locked-in. It would be very "expensive" to move, and would have to be very worthwhile. So far the math doesn't support that kind of change.

Usually an outage is not a big deal, I can still work locally. Today I just happen to be in a very GH-centric workflow with the security reports and such.

I'm curious how other maintainers maintain productivity during GH outages.

Of course they're down while I'm trying to address a "High severity" security bug in Caddy but all I'm getting is a unicorn when loading the report.

(Actually there's 3 I'm currently working, but 2 are patched already, still closing the feedback loop though.)

I have a 2-hour window right now that is toddler free. I'm worried that the outage will delay the feedback loop with the reporter(s) into tomorrow and ultimately delay the patches.

I can't complain though -- GitHub sustains most of my livelihood so I can provide for my family through its Sponsors program, and I'm not a paying customer. (And yet, paying would not prevent the outage.) Overall I'm very grateful for GitHub.

The autonomous vehicle should know what it can't know, like children coming out from behind obstructions. Humans have this intuitive sense. Apparently autonomous systems do not, and do not drive carefully, or slower, or give more space, in those situations. Does it know that it's in a school zone? (Hopefully.) Does it know that school is starting or getting out? (Probably not.) Should it? (Absolutely yes.)

This is the fault of the software and company implementing it.

LE has 2 primary production data centers: https://letsencrypt.status.io/

But in general, one of the points of ACME is to eliminate dependence on a single provider, and prevent vendor lock-in. ACME clients should ideally support multiple ACME CAs.

For example, Caddy defaults to both LE and ZeroSSL. Users can additionally configure other CAs like Google Trust Services.

This document discusses several failure modes to consider: https://github.com/https-dev/docs/blob/master/acme-ops.md#if...

Don't rockets also start with the same horizontal velocity though, since nothing canceled it out when it got off the launch pad?

It would be like jumping, and finding yourself ~250-400 meters away from where you lept by the time you landed.

That said, neat project, and way fun learning experience. Good job.