HN user

teoruiz

2,225 karma

20 years a CTO, engineer, and humanist — in no particular order.

You'll find me on most online services as teoruiz.

Posts66
Comments101
View on HN
pythonspeed.com 1y ago

Should you use uv's managed Python in production?

teoruiz
5pts0
www.youtube.com 3y ago

Matrix 2.0 – How we're making Matrix go voom

teoruiz
2pts0
www.imperialviolet.org 4y ago

Passkeys

teoruiz
2pts0
fasterthanli.me 4y ago

Remote Development with Rust on Fly.io

teoruiz
1pts1
jvns.ca 4y ago

SQLite-utils: a nice way to import data into SQLite for analysis

teoruiz
2pts0
sobolevn.me 6y ago

Typechecking Django and DRF

teoruiz
2pts0
kev.inburke.com 8y ago

AWS’s response to ALB internal validation failures

teoruiz
2pts0
www.youtube.com 8y ago

Distributed Transactions are dead, long live distributed transaction

teoruiz
2pts0
about.gitlab.com 8y ago

GitLab Announcing January 16, 2018 Critical Security Update

teoruiz
21pts9
android-developers.googleblog.com 9y ago

Android Announces Support for Kotlin

teoruiz
1pts0
tmate.io 9y ago

Tmate – instant terminal sharing with tmux

teoruiz
1pts0
sortega.github.io 9y ago

Intro to type classes

teoruiz
2pts0
cloudwebinars.withgoogle.com 10y ago

GCP Next Keynote live stream

teoruiz
2pts0
web-in-security.blogspot.com 10y ago

Practical Invalid Curves Attack on Java TLS Implementations

teoruiz
4pts1
queue.acm.org 10y ago

Fail at Scale

teoruiz
1pts0
www.bbc.com 11y ago

Will the UK's gas holders be missed?

teoruiz
65pts81
major.io 12y ago

Performance benchmarks: KVM vs. Xen

teoruiz
2pts0
teespring.com 12y ago

Get your Heartbleed t-shirt and donate to OpenSSL

teoruiz
13pts2
blog.rubymotion.com 12y ago

RubyMotion Raises Millions, Becomes Free, Introduces Smart Suggestions

teoruiz
2pts0
blog.twitter.com 12y ago

Twitter rolls out photo tagging, up to four photos in a tweet

teoruiz
4pts1
www.getchef.com 12y ago

Chef (formerly Opscode) Closes $32 Million In Series D Funding

teoruiz
2pts0
www.infoq.com 12y ago

Scaling Instagram

teoruiz
3pts0
typesafe.com 12y ago

Running a 2400 Akka Nodes Cluster on Google Compute Engine

teoruiz
4pts0
aws.amazon.com 12y ago

Amazon RDS for PostgreSQL

teoruiz
593pts239
news.ycombinator.com 13y ago

Ubuntuforums.org compromised

teoruiz
1pts0
www.h-online.com 13y ago

Backdoor in HP backup servers

teoruiz
3pts0
speakerdeck.com 13y ago

Scaling Realtime at DISQUS

teoruiz
2pts0
www.postgresql.org 13y ago

Security Release FAQ

teoruiz
54pts10
blog.balancedpayments.com 13y ago

How Balanced does Database Migrations with Zero-Downtime

teoruiz
1pts0
www.kissmetrics.com 13y ago

KISSmetrics down for 8+ hours

teoruiz
3pts1

Back in 2011 (!) I went to a wedding in Denia, a medium-sized town on the Mediterranean coast of Spain.

The day after the wedding we went to a restaurant by the sea to have some hangover paella, part of the wedding celebrations. Weddings in Spain are usually 2 or 3 day affairs. Anyway, since we were travelling back to Madrid later that day we left our luggage in the trunk of the car, not visible from the outside. We locked the doors and off for paella.

Or so we thought: some bad guys were jamming the car key frequencies so the car didn’t actually lock. They hit jackpot with my bag: my Canon IXUS camera (I loved that camera), my Kindle 3G, my MacBook Pro and my iPad… with 3G.

When we found out later that day we went to the local Guardia Civil and told them the story. I opened “Find My” on my phone and told them exactly where the bad guys were, all the way in Valencia already.

You should have seen the face of the two-days-shy-from-retiring officer when I told him that my iPad was connected to the internet and broadcasting its location continuously. Remember this was 2011.

So they sent a police car to check out the area and found a suspiciously hot car. They noted it down and did some old-fashioned policing the rest of the summer. Two months later I got a call: they had found them and waited on them to continue stealing using the same MO, until they had a large enough stash that they could be charged with a worse crime.

They had found my bag, my MacBook and my iPad. The smaller items had already been sold on the black market.

It still is one of my favourite hacker stories. I went to court as a witness and retold the whole thing. The look on the judge’s face was also priceless.

Honest question: why are houses in the US primarily built with wood? Is it just because it’s cheaper?

Even if it’s cheaper, is it worth to have a cheaper but obviously less durable building when compared to brick and mortar?

It’s always been baffling for my southern European mind.

How long will it take for the CA to be distributed to a large enough browser base?

I mean, it could be years. Is there any other, speedier process? (cross-signing, for instance).

I joined a startup wholly-owned by GOWEX 5 months ago. A startup that is now defunct.

I know it sounds crazy but we all believed those numbers, we were happy, money everywhere.

But from time to time one of my mental alarms would go off, and I would just ignore it. "What could possibly be wrong with this company? It's a publicly-traded company, after all."

The moral of the story is: pay attention to your instincts.

The first time around you curled "www.trucrypt.org" (note the missing "e") and it went to a domain parking service (findingresult.com).

The second time you went to the real "www.truecrypt.org", which is the real domain that now redirects to SF.

All of Bach 12 years ago

I would absolutely love subscribing to that list, would you be open to share the Spotify link?

Thanks!

OP here. Mandatory disclaimer: we're not affiliated with the OpenSSL Software Foundation but we thought it was a good idea to launch a commemorative Heartbleed t-shirt and donate all proceeds to the foundation.

The Teespring base cost for the t-shirt is around $11, the remaining $4 will be donated to the OpenSSL Software foundation once the campaign ends.

Weird. Can you try "openssl version -a" on both? Like this:

  $ openssl version -a
  OpenSSL 1.0.1 14 Mar 2012
  built on: Mon Apr  7 20:33:29 UTC 2014
  platform: debian-amd64
  options:  bn(64,64) rc4(8x,int) des(idx,cisc,16,int) blowfish(idx)
  compiler: cc -fPIC -DOPENSSL_PIC -DZLIB -DOPENSSL_THREADS -D_REENTRANT -DDSO_DLFCN 
  -DHAVE_DLFCN_H -m64 -DL_ENDIAN -DTERMIO -g -O2 -fstack-protector --param=ssp-buffer-size=4
  -Wformat -Wformat-security -Werror=format-security -D_FORTIFY_SOURCE=2 
  -Wl,-Bsymbolic-functions -Wl,-z,relro -Wa,
  --noexecstack -Wall -DOPENSSL_NO_TLS1_2_CLIENT -DOPENSSL_MAX_TLS1_2_CIPHER_LENGTH=50 
  -DMD32_REG_T=int -DOPENSSL_IA32_SSE2 -DOPENSSL_BN_ASM_MONT -DOPENSSL_BN_ASM_MONT5 
  -DOPENSSL_BN_ASM_GF2m -DSHA1_ASM -DSHA256_ASM -DSHA512_ASM -DMD5_ASM -DAES_ASM 
  -DVPAES_ASM -DBSAES_ASM -DWHIRLPOOL_ASM -DGHASH_ASM
  OPENSSLDIR: "/usr/lib/ssl"
In any case, it could be that something else (not built with OpenSSL) is listening on port 443 in the one that's "safe".

Mainly because those come from Akamai. Facebook would likely be able to add SPDY to their own services, but it's up to Akamai to start doing something on their side.

Don't hold your breath.

To install the whole set of Python modules needed and iPython in a virtualenv (trick: there is no "pylab" module to install):

  % virtualenv --distribute --no-site-packages pandas_venv
  [blahblah]
  % . pandas_venv/bin/activate
  (pandas_venv) % easy_install readline # Probably only needed in Mac OS X for iPython to behave 
  [blahblah]
  (pandas_venv) % pip install ipython
  [blah blah]
  (pandas_venv) % pip install numpy
  [lots of blahblah]
  (pandas_venv) % pip install matplotlib
  [quite a bit of blahblah]
  (pandas_venv) % pip install pandas
  [some more blah blah]
  (pandas_venv) % pandas_venv/bin/ipython --no-banner
  
  In [1]: import numpy as np
  
  In [2]: import pandas as pd
  
  In [3]: import pylab as pl
  
  In [4]:

It's a great step towards domain anonymity, but at the end of the day Namecheap is a company in the USA that needs to comply with USA law and its enforcers. And we know it's not the most privacy-friendly country in the world.

To be fair, registering a .com domain is a bad idea if you want to stay anonymous. Go for a .is, a .ch or even a .eu.