HN user

mstrem

102 karma

Product at Cloudflare. Tech person at dodify.com and Spesati.com.

Posts16
Comments43
View on HN

There is no such intent from us to throw around our weight. The team is challenged with a very hard task of balancing protecting web assets VS ensuring that those same assets remain accessible to everyone. It's not an easy problem.

The features you refer to are not bleeding edge, and not only that, they are security features. We are still discussing internally but I hope we can publish soon the details so that point can be addressed.

Final but not last, this only affects our challenge system, which is never issued by us as a blanket action across Internet traffic. It's normally a configuration a Cloudflare user implements in response to an ongoing issue they have (like a bot problem). We do report challenge pass rates and error rates but we can certainly always improve that feedback loop.

Michael Tremante here. I'd like to address some points openly as I'm personally mentioned in the forum. I reached out to the Pale Moon community on behalf of the team to try and resolve the issue with the Pale Moon browser.

- We sent our standard NDA to speed things up. I explicitly said in the message that it may not be required, but in the interest of moving fast we sent it to them so they could review it just in case

- We are committed to making our challenge system work on all browsers by clearly documenting what APIs need to be supported. For example, part of the issue with Pale Moon, is that it does not support CSPs correctly

- Notwithstanding the above, to resolve the issue quickly we are willing to lower some of our checks if and only if, we find the right approach. Of course this would introduce some security issues that bot developers may quickly leverage

- Contrary to what many have said in this forum, our challenge has no logic that relies on the user agent strings. We rely on browser APIs. We don't have any special checks for any specific browser

- To address this longer term, we are discussing internally a program for browser developers to have a direct channel with our team and we hope to have something to share soon with the browser developer community

I am happy to answer any constructive questions.

No. Cloudflare is configured as a reverse proxy in front of the site. So traffic reaches the Cloudflare edge first, then it is proxied to the origin on Azure unless the file is served directly from the Cloudflare cache.

I also don't have many interesting things to say. I also don't think I'm a particularly good programmer.

But yet I have a blog. Mostly to improve my writing. And to give me an additional reason to explore a new topic once in a while. It's also a nice notebook.

If I get a reader that's good. But building a high profile blog does not have to be the main goal.

I feel this is a generalisation. A lot of coding assignments are unrelated to the actual work and have no value to the potential employer besides assessing skills.

With my dad being an airline pilot and having grown up in the "pilot community" I must say that this style of living is probably by far the exception rather than the norm.

My family, and all my parent's friends (most of which were pilots or air attendants), all had what you could call normal a house with normal lives etc. etc.

By most means life was pretty much the same as anyone else.

what is he fleeing from in France? => nothing. France is a great place.

However, I have lived both in the UK and in France. If I had a choice, and if I was looking for asylum, I would choose the UK every time. In another video from him he says his two friends made it to the UK before him. The best country to get into Europe (as an asylum seeker) is the UK. It is also a reason why there is such a big fuss about immigration. The benefits are great, it is a very safe country, wealthy, lots of opportunity... etc etc. I might be very biast but the UK is quite a bit ahead of the other European countries in my opinion (with a few exceptions). If the UK was on mainland Europe it would have waayyy more immigration problems.

Edit: I am happy he made it. I am pro immigration.

Right, I personally literally change my resume based on each application focusing on the experience which I think would be most relevant for each position. I also change the introduction sentence and when I respond to open ended questions (in the quizzes) I always refer back to the company and relevant examples. Cover letter, when requested, also takes me a lot of time to write up.

I somewhat agree with your statement. Mainly because I personally put a LOT of effort into each job application and I would not be able to apply to more than 2-3 jobs a week. Takes time to find the right company, do research, make a perfect personalized application etc.

As a result to that pretty much all applications I have ever made have at the very least gotten back to me. I would never be able to apply to 38 jobs in 2 months. I feel like a lot of copy paste went on and that sets you to a negative start.

This is typical, I have just done the whole process myself a few weeks ago from scratch (fresh CentOS install) and now this comes up.

However I do not regret it at all. I had Linux experience and it took me one day and a half work to get it all working very nicely.

I am happy with my config: Postifx, Dovecot, RoundCube, SpamAssassin, ClamAV

Server supports unlimited domains and user accounts - SSL is required for all connections, I only allow IMAP and I have configured it with two valid free StartSSL certificates:

    One under mail.domain.com (for email clients)
    One under webmail.domain.com (for the webmail)
And both of course do not show warnings and green padlock is always nice.

The thing that scared me the most was outgoing emails being dropped - however to date I have delivered fine to all main email provider - followed a few simple rules:

    Ensure you have both SPF and TXT correct DNS records
    Ensure you have IPv6 configured properly (Google was  rejecting due to this) 
    Set your reverse DNS
    Set your machine hostname etc. in postfix

Disclaimer: I have a number of free StartCom certificates.

However, even though I own some certs with StartCom, I personally think this comment has literally no basis.

Looking at the CA market - if anything - we should be happy that a CA like StartCom exists. It is a very small team lead by Eddy Nigg (he is very helpful by the way) and given that they are the ONLY ones (as far as I am aware) offering free certs - we should applaud them. Besides, the fee for revoking is very small.

I also was very much aware that revoking a cert had a charge before I signed up for one - I think it is pretty clear - so not a problem for me at all. Of course if I had to revoke a cert because of StartCom's mistake that would be a different story.

Bare in mind these are only domain validated certificates - perfect for small website owners who wish to offer their site over httpS without paying any extra fee.

The Heartbleed Bug 12 years ago

From the CloudFlare blog: "This bug fix is a successful example of what is called responsible disclosure".

I just discovered this now and

    yum info openssl
Yields 1.0.1e as available package which is vulnerable. I guess not all "stakeholders" have been warned properly - or am I jumping to conclusions?

True, however you could require say 4 users to block a comment out and this maybe would mitigate the problem a little?

I think the point I was trying to make was that by turning it around it would require "less" active participation from the users and by default everyone gets a chance, but the really bad comments would still get removed I think. Anyway we shall see how it works out!

This seems quite drastic to me. Personally I don't have a lot of Karma (and I don't really care to) but every known and again I post a comment and usually I hope it provides a good contribution.

Like this the system is putting a lot of weight on the users with more Karma... and I am guessing there are "many" more users with less than 1000 compared to those with more? Some people may never have a chance to state their opinion like this.

Rather, the opposite approach might work? Users with more than X karma can completely remove some comments, and say if your comment has been removed, you are not allowed to comment again for a specific period of time. If you post x rejected comments in a row then potentially you get banned.

EDIT - maybe a little off topic: another "comment" about comments - I notice you can up vote and down vote comments. I see this functionality sometimes is used to indicate agreement (or lack of) towards a comment. This as far as I cant tell is not the intended functionality, I am unsure however how this can be fixed easily.

I get the feeling no one has a clue yet. It is easy to come up with theories... e.g.

Malfunction in plane - transponder turns off - cabin loses pressure (and everyone on plane goes unconscious or similar) - because cockpit is locked crew does not manage to do anything in time - plane keeps on going - fuel runs out.

of course that is probably totally wrong.

One thing though - if it did fly low over land - I would expect at least someone would have used their cell phone - so I would rule out that option.

Well, that is not the full story though... I expect older people to watch more TV. All my grand parents basically sit in front of the TV all day... I would expect I would watch a lot more if I was older currently, even simply because I would have a lot more free time.

There has been a single sign on for most services for a long time (although the login page was different in some cases depending on which service you were accessing).

The difference now is that they re designed the log in interface to be the same across services and I have also only noticed the new design in the past week or so.

I agree, also I personally prefer the idea of having things separate, HTML for the structure, CSS for the style, and JavaScript for the behavior. You can create very clean and neat pages like that especially if you don't mix each technology e.g. keep everything separate in different files..

I am however open to new ways of doing things so I will keep an eye on this, but I must admit, that index page looks a lot more daunting to edit than a normal HTML page, especially if you are not familiar with JavaScript.

Well actually, you can do nearly all the tricks in windsurfing without stopping and sinking and coming out of it planing... it is just incredibly difficult to do though. Even the top surfers don't manage very often