(random anecdote) My first and last experience with FreeBSD laptop was trying to use 3.x (!) on a Dell Inspiron 3500 (PII-350 maybe?), no sound modules were precompiled or included or whatever. Took about 3 days for `make world` to finally finish rebuilding... and then sound still not work. Red Hat 6.x "just worked" in all regards.
HN user
styanax
We had 2U VA Linux servers at a company (circa 2000), they were rock solid beasts which continued to run for years. I vaguely remember cannibalizing one chassis to beef up another / replace parts, but as you mentioned by then it was circa 2003 (?) and one could buy palettes of dotcom-bust servers off a dock in SF. A fully kitted HP DL380-G2 was around $100 IIRC, bought one it ran forever too - old Sun and SGI hardware as well, all of it. Dirt cheap, if you still had a job. :-/
I'm mildly surprised GKH doesn't deploy SSL. In this day and age I just close the browser window when the http-only browser warning comes up and move on to something else.
IMHO based on my use of the fediverse, fundamentally it's about porn and curtailing unwanted porn in your domain. I'm a user of mastodon.social in the "wee US hours" (before US mods are awake) and run across a lot of hit-and-run porn being pushed to Trending (and I report, etc.).
It's a thing, it happens a lot and Lemmy instances have the same problems to fight. Unwanted porn in my eyeballs is sadly a not uncommon experience until you've put in effort to set up blocks and filters on your personal accounts. Peertube being explicitly video based is a natural target for porn pushers.
nod We have different use cases, for my browser use I'm using it as described mainly for one-off playing of content (think like watching a single video from a hotlink, checking out a single track or two from a new band, etc.). For streaming I'm a shoutcast/icecast oriented person, tried and true. :)
I seem to have no problems streaming from either Bandcamp or Qobuz, the latter which I'd never heard of before. (or as far as I'm aware any other site) I intentionally want to click-to-play on every site out there, so perhaps you mean "blocks autoplay" or somesuch?
Here's the discussion forum post going over it: https://discuss.grapheneos.org/d/27068-grapheneos-security-p...
The about:config settings which you can look up:
media.autoplay.blocking_policy
media.autoplay.default
I have mine set to 2 and 5 respectively.This was the first one I looked for as well, NFCU is (per Wikipedia) the largest CU in terms of size and membership in the US - but wasn't included. I think you should add a "how I chose these Credit Unions" on your overview, as missing NFCU immediately made me wonder what others were missed; RBFCU - largest in TX and 10th largest in US - is missing as well. So I'm left to wonder how 2 of the largest CUs in the country were just... missed.
I completely agree with this. I performed really poorly on this axis. I’m sorry to the Zig community for that. I’ll take my L and get back to working on std.Io and the rest of the roadmap. [1]
[1] https://ziggit.dev/t/migrating-from-github-to-codeberg-zig-p...
Codeberg has been under DDOS attacks for most of 2025, someone out there has it in for them and has been attacking relentlessly. The volunteer team has been very transparent posting about in social media and their blogs.
On the previous HN article, I recall many a comment talking about how they should change this, leave the politics/negative juju out because it was a bad look for the Zig community.
It would appear they listened to that feedback, swallowed their ego/pride and did what was best for the Zig community with these edits. I commend them for their actions in doing what's best for the community at the cost of some personal mea culpa edits.
Hi Arathorn, I recognize your name as the core developer lead. :) Alas, when I was trying to cull my old messages I tried that (and a lot of other API type hacks I found floating around) and none of them, at that time, worked.
In short: the complete lack of user-facing easy to use controls for data retention and culling in the Matrix (Element) clients is a deal killer for me. That painful experience taught me a lesson - now when I test something new, one of the first things I look for is "how do I extract from this thing?". I never want to go through my Matrix extraction pain again, so a personal life lesson was learned.
Good to know, thank you - those of us currently using it are on Androids so we've not had a friend on iOS join yet. We're using a chatmail relay.
As a former user I felt these pain points trying to do nothing more than have a very active one-on-one chat with a good friend. Tens of messages an hour, maybe 2 years running. Using matrix.org and the pre-X clients. It's fine for group chat (IRC style) but that's not a high bar.
(a) the encryption between using a mobile and the webapp desyncs/breaks all the time, it just sucks. I mean you'll get "cannot decrypt" a lot, have to bounce back and forth and generally try and force it to re-sync properly again. Sometimes never worked at all. Lots of issues on GH over the years.
(b) as mentioned in this article, insane delays on new message notif and sending and receiving. Just logging in on the webapp every morning took minutes of some sort of mysterious sync process, often the mobile app had the same problems. The X stuff may fix this, we were pre-X.
(c) cleanup. There's no message retention set on matrix.org, when I wanted to extract and remove our past chats the process and experience was excruciatingly bad. It took tens of hours over several weekends of the webapp (mobile completely non-op in practice for this) polling and loading old content, just so I could select 100 at a time to delete and then it took an hour. Once I started culling back over a year or so, the loading got longer and longer and longer, until eventually it 100% stopped working at all to load old messages.
Signal and DeltaChat are far, far better experiences for one-on-one chats with friends & family. The Delta client is a bit UI/UX behind but not horrible; e.g. you can't correct a typo in a sent message in Delta, unlike Signal - because each msg is a unique gpg-encrypted "email" rather than a database object that can be re-manipulated.
My memory is really fuzzy, but I recall back when the new IM apps were all coming out and competing for the small share of people wanting to test them, either the Wire app or using the Wire service had a hard cost ($5 USD?) (no free-to-test tier, you had to pay to use). I believe history has shown a vast majority of folks will choose free (even with ads, sadly) over a hard cost for IM. Signal talked a better game and offered everything for free.
How do they compare in actual use? I have a Pixel 6a connected to $40USD bone conducting headphones and the range and punch-through are incredible; the phone is sitting in the living room playing music and I can almost make it to my mailbox at the end of the block (about 3 houses away) before it starts to degrade or cut out.
Do these alternatives compare with just how well UWB serves regular, normal daily activity like this? Because to me, what I have is absolutely excellent in use with daily routine.
I'm not horribly worried near term (not saying it won't ever happen), as there are very vocal, proud and energetic proponents on Mastodon like Elena Rossini[1] driving community engagement. Such a move by the software devs would jettison the very people evangelizing the platform.
Of all the articles this morning about the changes, this one has the most information about the reasons and lists the people taking on various roles as part of the non-profit's structure.
The war isn’t won by telling people to use GPG
Tangent, a friend and I started using Delta Chat with a chatmail relay and it's incredibly friendly to get started, and hides the fact GPG tech is being used from the user; one can export a bundle of the key data as needed and easily copy the key profile to a second device over local wifi (I was impressed at how smooth it was).
Not that I've kept track, but Delta Chat's UX is probably the first easy, no-nonsense implementation of using GPG tech as a foundation but keeping it away from the user experience I've encountered (and liked). It has it's pain points but I mean it just works and my buddy and I chat all day over it using a public relay.
Thanks to multiple mentions of Mullvad in this overall post comments, I decided to replace dnsmasq with unbound and convert the laptop to DoT. Here's the specific Mullvad snippet if anyone needs:
# Mullvad Unfiltered
forward-addr: 2a07:e340::2@853#dns.mullvad.net
forward-addr: 194.242.2.2@853#dns.mullvad.net
# Mullvad Adblock
# forward-addr: 2a07:e340::3@853#adblock.dns.mullvad.net
# forward-addr: 194.242.2.3@853#adblock.dns.mullvad.net
As mentioned in the default unbound config, the "#" is not a comment when used in the value, it's used for TLS checks. I followed this simple blog post from years ago: https://www.jwillikers.com/dns-over-tls-with-unboundInterestingly, I get 3 different source IPs, BUT! The one from Quad9 is IPv6 and the ones from 8.8/1.1 are IPv4. Google returns an extra TXT record as well with "edns0-client-subnet 172.56.95.0/24". I'm not a DNS pro, so not sure what to make of it.
As 9.9 returned an IPv6, I tested with AAAA records just now - 1.1/8.8 respond with 4x IPs, 9.9 only 1x so it mirrors the A records in spirit.
I actually do (did, I demoted it for now) use the unfiltered service (9.9.9.10) but find the same result on both, so I used .9 here to keep the chat more streamlined. But, could still be relevant somehow?
I'm sure geo has something to do with it - my connections generally terminate in Austin, TX but it varies around Central US. I have T-Mobile Home Internet and our IPs show up to remotes under the same general ASNs as the traditional mobile network (big huge CGNAT, my IP can change 5 times a day or whatnot and it doesn't reflect where I actually am located).
Edit: in case useful to someone reading, right now I have an IP assigned out of this block:
NetRange: 172.32.0.0 - 172.63.255.255
CIDR: 172.32.0.0/11
NetName: TMO9
NetHandle: NET-172-32-0-0-1
Edit edit: in the network record is a link to the self-reported geo data, I missed that. Comment: Geofeed https://raw.githubusercontent.com/tmobile/tmus-geofeed/main/tmus-geo-ip.txtHoping the HN DNS savvy reading this can help me understand a Quad9 thing I ran into. I was debugging (as in scratching my head) a bank website login problem and ended up doing some DNS checks against their domain, usual stuff, while using Quad9 as my DNS provider.
While testing, I was using Google and Cloudflare as well, and started noticing something - Quad9 does not return all A records listed for a domain, the same way Google/Cloudflare do.
dig -t A google.com @8.8.8.8 +short (6x IPs)
dig -t A google.com @1.1.1.1 +short (6x IPs)
dig -t A google.com @9.9.9.9 +short (1x IP)
This gave me a weird feeling; I get there's a lot of DNS geo magic and 8.8/1.1 serve 2 different subnets, and 9.9 a third. But... where did the other 5 expected IPs from Quad9 get off to?Something new I found - go to any link (news article) on commondreams.org in Firefox. Now use the Reader View button in your address bar - they've figured out how to hack Reader View to not show the content and only a beg screen for money.
Thank you, this is the one I recall from my youth (having them around the house). I did not realize there was another one with an almost identical name (this post).
Reading other comments, US folks seem divided; I am with you and the others on this side of the fence, I've seen this exact situation play out in corporate life many times. They are attempting to quiet a public discussion of dissent and dissatisfaction.
What's the legitimate use case for a package install being allowed to run arbitrary commands on your computer?
The paradigm itself has been in package managers since DEB and RPM were invented (maybe even Solaris packages before that? it's been a minute since I've Sun'd); it's not the same as NPM, a more direct comparison is the Arch Linux AUR - and the AUR has been attacked to try and inject malware all year (2025) just like NPM. As of the 26th (5 days ago) uploads are disabled as they get DDOSed again. https://status.archlinux.org/ (spirit: it's the design being attacked, pain shared between AUR and NPM as completely disparate projects).
More directly to an example: the Linux kernel package. Every Linux distribution I'm aware of runs a kernel package post-install script which runs arbitrary (sic) commands on your system. This is, of course, to rebuild any DKMS modules, build a new initrd / initramfs, update GRUB bootloader entries, etc. These actions are unique outputs to the destination system and can't be packaged.
I have no data in front of me, but I'd speculate 70% (?) of DEB/RPM/PKG packages include pre / post install/uninstall scriptlets, it's very common in the space and you see it everywhere in use.
Aside, this bit that Neil and the team are working on is something I think is the 'next big thing': https://www.ietf.org/archive/id/draft-ietf-jmap-emailpush-01...
The next, next big thing would be the Chatmail relays[1] supporting JMAP based servers (right now it's Dovecot) and this new targeted push extension for faster notifications without battery drain on mobile. I can see how the Fastmail mobile client will benefit from this RFC as well (it's already incredibly battery efficient, thanks to the team).