HN user

mivok

166 karma

[ my public key: https://keybase.io/mharrison; my proof: https://keybase.io/mharrison/sigs/k--vU3rR5ddONbKLfCZcI8h0ZV-IDjGlTtvw-m8Gq2Q ]

Posts4
Comments30
View on HN

It includes the flannel network plugin by default (although you can change this) and a basic service load balancer (technically not an ingress, but providing the same functionality). From the README:

k3s includes a basic service load balancer that uses available host ports. If you try to create a load balancer that listens on port 80, for example, it will try to find a free host in the cluster for port 80. If no port is available the load balancer will stay in Pending.

This sounds very similar to what you're looking for: https://thenoteboard.com/. Sadly it doesn't seem to be available right now, but it's a pocket whiteboard made up of 3x5 segments. It folds down rather than being a stack of cards, but it may work for what you're thinking of.

Hue forces updates on you every time you go into the app if there's one available, and you can't use the app until you've updated. Granted this isn't ideal if you primarily use your light switch or an amazon echo to control the lights, and fully automatic updates would probably be better, but it comes pretty close to aggressively pushing updates.

A lot of the comments here are complaining about the last point in the article (the n00b), asking how on earth you get started if you have to have presented before in order to present. The article is telling you exactly how to do that:

- Speak at local user group meetings. Most of my local meet ups are constantly calling for speakers, and it's an excellent way to get practice at presenting in a lower stress environment. It's not always small audiences either, I've seen and given talks with 50 or more attendees at a local meet up. As for getting accepted, organizers are always in need of talks, and organizers are not getting 6 submissions per month, they're usually lucky if they can fill every month with a talk, so you're much more likely to be accepted.

- Maintain a blog. Writing articles on your blog is practice for writing a talk, and gives you a steady stream of ideas that can be turned into a presentation fairly easily.

I'm going to add a couple more:

- Give a lightning talk at conferences you attend. As well as giving you practice, you are also visible to all the attendees, including people who will be selecting talks at future conferences you submit to.

- Submit to smaller, more focused or more local conferences. You can't expect to be accepted at huge popular conferences speaking in front of hundreds of people on your first try. Submitting to more focused conferences gives you a better chance of being accepted.

These steps aren't going to make it so that you're immediately accepted at large conferences, but they give you the start the article is claiming you need. And finally, if you're rejected, don't give up. Conferences do take chances on new speakers (although probably not all new speakers who submit a talk), and being rejected doesn't mean your talk is bad, or that your skills are bad, just that you didn't get it this time.

Even shorter/easier to remember version of the command (you don't have to specify the filename twice if you don't want):

    curl -T ./filename transfer.sh

If the clients trust the npm CA, can't they just sign the digicert CA with that CA and include it in the certificate chain provided by the server? That way the chain would be:

    npm CA -> digicert CA -> any other intermediates -> server cert
Clients that only trust the digicert CA (and other standard CAs) will see that and accept it because they trust the digicert CA, and clients that trust the npm CA will trust the cert also, allowing both old and new clients to work. Once (almost) everyone has upgraded, the npm root CA can be removed from the chain presented by the server. Am I missing something here?

Edit: It looks like what I'm missing is that you'd need the private key of the digicert CA to generate the request to sign with the npm CA. I was thinking about how CAs have been migrated in the past (e.g. equifax to geotrust global CA). It looks like it won't work in this case.

Edit2: Actually, it appears to work after all. I just tested with the openssl ca command, and you give it -ss_cert instead of -in for the certificate to sign a certificate instead of a request.

Fulton, MD or REMOTE

Site Reliability Engineer at OmniTI Computer Consulting

The OmniTI Ops team is a flexible and progressive group. We work closely with developers, DBAs, and client groups to help them manage availability and performance in the midst of constant changes. We are not risk averse; instead we strive to understand why things fail and understand the true impact of those failures, so that we can empower others. Collaboration is a cornerstone, and we understand that being friendly and outgoing are keys to making that work.

See http://omniti.com/is/hiring/site-reliability-engineer

Then the receiver reports to the sender that the link didn't work. The sender, not knowing if the password was compromised or if it was a situation you mentioned above, changes the password/revokes the key and generates a new one. This time, the receiver doesn't access it at closing time in Starbucks/doesn't switch tabs, and gets the new password correctly.

Unexpected behavior doesn't happen every time.

As an optimization, if you have a self hosted service of this sort that gives proper logs, you can probably verify that the link wasn't intercepted by looking at the source IP and comparing to what the user reports (if they're able to do that, if not, you fall back to assuming it was compromised), and if so, skip the revocation/regeneration procedure.

All of those objections boil down to not trusting a 3rd party service.

I wonder objections there are to running your own service of this type? This way you could guarantee the physical security, keep up with regular patches, manage your own logging, and securely delete the secrets to your satisfaction.

The only real objection I can think of is that writing software without security holes is hard. This applies to any security related software however, and the solution is to use 'proven' apps that have survived scrutiny. This type of app is pretty simple, which would ideally be relatively easy to audit.

In principle, a read-once URL that you can safely send via email seems to be a pretty efficient way of dealing with sending passwords or other keys without having to deal with GPG or similar. Just tell the client 'Click on this link, that's your password. This message will self destruct'. If it's intercepted, you can detect this, and change the password/revoke the key. I'm sure I'm missing something, but if not, it would be nice to have this become the standard way of distributing new passwords or keys for services rather than sending by email (for those services where you have an initial password generated for you).

Why not blame the bigger sites? If they accepted logins from other OpenID providers, then people would have a lot fewer possibilities to remember. I honestly believe this is a big part of the problem with OpenID adoption currently.

It seems to me that the problem of multiple OpenID providers and people not knowing which one they're using would be a lot less serious if all of these companies that are OpenID providers actually accepted logins via OpenID themselves instead of everyone paying lip service to the idea while trying to be the one source of identity for everyone else. That way you could be using the same ID for twitter/google/facebook etc. and when it says 'use your google/twitter credentials to log in' then there is only one set of credentials to use.

Actually, it seems to me the bigger problem is that some providers just decide to change who they say you are, and those providers (Google) just happen to be the biggest because you're telling users 'just use your google login here'. They don't know anything about openID. Sure, users having multiple OpenIDs is an issue when they forget which they used, but even if this was solved, the other issue seems to be much worse.

No visa required 16 years ago

I just recently returned to the US and for the first time got to go through the citizen's/residents line (Green card holder), and the difference between the two was unbelievable. This time round, the queues were a fraction of the size, the immigration officers were friendly (as opposed to being outright rude to visitors) and the whole process was incredibly simple and quick. The difference is striking, and I'm certain it's not just me - visiting family always complain about how long immigration takes.

One of the best comments I saw on the page was that, if one person has the right to free speech, then groups of people also have a right to free speech. However, it also seems clear to me that if one person can have a seat in congress, multiple people can't have that seat. This argument would allow the courts to strike this down while keeping the Citizens United decision in full force.

It's possible that it will end up being a 'conditional permanent residence' that you have to renew after 2 years (the condition being that you still have the company). This is what happens for green cards that are granted on the basis of a new marriage.