HN user

theallan

358 karma

Author of DataTables.net and CloudTables.com. Hit me up with `allan` at either of those domains.

Posts8
Comments116
View on HN

Should one of the first things you do with a database not be to have a backup strategy? I understand that HA would be a "nice to have" when first starting out, but surly if you have a production db, a backup and restore plan should be on a survival guide? Neither appear to be mentioned here.

What do you all use for your pg backups? Is Barman ( https://pgbarman.org/) still the way many do it? (I haven't deployed a new pg instance for a while, but thinking about it for a new project).

I maintain an open source project funded by the Sovereign Tech Fund.

I would absolutely love to know more about this if you are willing to share the story?

Out of curiosity, could this have been a vector for a supply chain attack?

If you were using the CDN without SRIs, then yes, that would have been the most obvious channel. However, I don't believe the attacker ever set up for that and the URLs never resolved due to CloudFlare blocking it.

there's been some pretty huge breaking changes

Unless you were using the legacy API, there shouldn't be any major impediment [1]. I intentionally tried to keep backwards compatibility as I hate doing library upgrades myself! Drop me an email - allan at the domain in question if you have any questions about doing an upgrade.

It looks like newer versions of datatables don't import static files from the datatables CDN like this.

I rewrote aspects to use CSS styled elements in place of images, so there were less resources to load.

Would it make sense to issue a CVE for older datatables library versions that could be susceptible to this attack?

Per the above, if you were using the CDN without SRI for the resources, then any version could have been susceptible. However, I've seen no evidence that the attack took that vector.

[1] https://datatables.net/upgrade/2

Joker.com. Credit to them they fixed it reasonably quickly, but its a horrible policy to default to enact the change if no response if given. Their reasoning was what else would they do if someone got locked out of their email - they need a way to recover their domain somehow, and they ask for ID to be submitted, but as seen, that is trivial to fake.

Yeah - it was a well set up attack. What I don't understand is that there was no obvious follow on. I can only guess that it was a proof that it could be done. Maybe?

Regarding the 1000 error - I didn't have any 1:1 support contact with CloudFlare - the first I knew was they were returning 1000 errors, which I presume they were doing due to a blacklisted IP being used for the DNS resolving. I'm really not sure though.

Yeah, I really wasn't happy about that. I did put it to the registrar that such a policy is wrong and open to such an attack. I got the impression that they weren't going to change their policy though. Such policies are something I'm going to be looking at when considering a new registrar.

Didn't expect to see this here, it was over a month ago this incident happened! Happy to answer any questions about it (author of DataTables here). It was a super stressful event to say the least, and I've been reading along with the recent npm incidents wondering what I can do to make sure my OpSec is as good as it reasonably can be.

The flip side is, if you don't do auto updates and an exploit is published and used against you and you haven't yet tested / pushed the patch, that you would have been protected against if it had auto updated, you are up the creak without a paddle in that situation as well.

To some degree you have to trust the software you are using not to mess things up.

In case anyone finds this through search in future, I've just received this from the Yahoo postmaster team:

Our engineering team has looked into this and you'll need to have your users mark the mail and not spam. We don't have anything else to suggest.

It is unbelievably frustrating. I'm giving up on using Google Groups (which is perhaps what Yahoo and Microsoft want).

SPF, DKIM, DMARC are all set up correctly. There is no issue with deliverability when just sending from an indiviual account of the charity's domain to Outlook / Yahoo, it is purely when going through Google Groups that there is an issue.

Daft question, but if you hadn't realised, then your client's obviously asked that question yet (and might not)?

Open source needs to find a way to make money and backlinks is a reasonable way of doing it. I should say for my own open source project I refuse backlinks to gambling sites on morality grounds though - although looking at how much revenue it might bring in on a monthly basis, there is a lot of temptation there.

$100/m is cheap for a back link? (honest question - I've no idea).

67 logos on the home page at the time of writing this, that's $6'700/m. While obviously not FAANG salary scale, it isn't to be sneezed at either.

More details about that on their github page [1]. It seems you basically need to include a JS file from [their CDN](//cdn.jsdelivr.net/npm/eruda).

As someone who fondly remembers the early Firebug days, it is great to see this. It is very frustrating to me that tablets and phones are so powerful, but we can't do even basic dev stuff on them.

[1] https://github.com/liriliri/eruda

I think the confusion is coming from the framing of "Email API for Developers Using React" as the title for this post. React has nothing to do with "an email API" as far as I can see.

Your web-site is more clear in that it shows a Node.js snippet (and other environments, although funnily not just in the browser?). Then the site goes on to talk about the React components.

Perhaps "Email API for Developers, with React components" would resolve the issue. The title as it stands suggests I wouldn't be interested in this at all since I'm not using React. But actually, as an e-mail API, I would be (e.g. with a Hugo site).

Just wanted to say thank you for Typesense. I use it for my own open source software [1] and integration with it was really easy.

More generally, I think it is great to see development in this area from Algolia and Search.io to Typesense and others. Being able to have a customisable search which is really fast, can make a bit difference on a web-site.

[1] https://datatables.net

I don't disagree, but I think it is more complex than a simple tiering system. For example, where I live we have no mains gas, so heating is typically oil. Trying to be environmentally minded I've installed heat pumps to do the hot water and space heating. Add in an electric car as well.

Taking this approach would punish us for trying to move away from direct fossil fuel consumption (I'm aware that much electricity still comes form fossil fuels).

So there is a lot of nuance in the proposal - allowances for electric cars, heat pumps (which the government is actively encouraging), mains gas, etc. Do each of these affect the basic needs?

An alternative that crossed my mind was to change the unit price based on house hold income. Higher income households would pay a higher rate per kWh, which I think would be considered progressive. Can't see the Tories ever going for that though.