It doesn't. My server is appropriately engineered to its task.
HN user
tquai
Yeah, I think there's a misunderstanding somewhere. Some people think I believe a $5 computer could handle amazon.com's traffic, which is clearly preposterous.
I know that almost all of my downtime comes from when I overengineer things. And I don't need to "patch my kernel" because my OS doesn't have kernel holes once a week. Linux isn't the only Unix OS out there.
Today, a lot of sysadmins believe that "LAMP" is a synonym for webserver, and consequently there are a bunch of webservers serving static content on a machine with way too many moving parts. Complexity is bad.
"Things should be made as simple as possible, but not any simpler." -- Albert Einstein
It's a lesson in overengineering. At this point my $5 Pentium 3 server has a greater uptime than Amazon.
FWIW, Obama and Romney have both lived abroad. I think it takes a certain kind of person to want to be president, and the effect of travel is different on a person like that.
For this and other reasons, I think electoral politics is one of the least effective places to put energy, in working for change.
I compared US-based carriers with non-US based carriers. Southwest, a US-based carrier, competes with other US-based carriers. You're right, Southwest is a great choice if you're flying in the US, but that's not what my post is about. You can't compare Southwest with Cathay Pacific or EVA Airlines because they operate totally different routes.
Same thing regarding EasyJet comments, which is another "niche" airline. Try flying EasyJet from LAX to NRT, for example.
Just a general comment on airlines:
With US-based carriers, expect low prices, inflating awards points/miles, and bottom-level service.
With non-US based carriers, expect higher prices, no awards programs, and excellent service.
This is my experience flying in N. America, Europe, and Asia.
The market is capitalized at $2.5 billion, but what does that mean in an economy with no production?
Does the author define "production" as manufacturing where the exclusive currency used (for raw materials, wages, utility bills, etc.) is bitcoin? If so then I'm not sure of the relevance.
One could make all sorts of clever but offtopic points about a fiat paper currency when viewed through the lens of a P2P currency like bitcoin. "The Canadian dollar is supposedly worth more than the USD today, but what does that mean when the Canadian network has zero nodes?" The wrongness of such a statement leaps out since fiat currencies are familiar to us. In contrast, bitcoin doesn't need a manufacturing base, but this is less obvious since P2P currency is a new idea that people (myself included) don't well understand.
Recently I was offered a free flight for a weekend trip. I declined, citing the myriad displeasures of flying.
Now, should we initiate a behavior recall? Take the number of McDonalds-level staff in the air (A), multiply by the probable rate of power tripping (B), multiply by the average loss of tickets sold (C). A times B times C = X. If X is less than the cost of some basic decency training, we won't do any. Which airline do you work for? A major one.
How is this possible?!
In any sufficiently large organization, the people who make the decisions and the people who enact those decisions are separated by distance, background, experience, or other reasons. This is why you see so much dysfunction in large organizations, and it extends to politics and other things that affect you as well. Look for it and you'll start seeing it everywhere.
Earlier today this had 135 comments. Checked later, 200. Now 350! OMG BUY! BUY! BUY!
The Open DNS Resolver Project has a list of 25 million open resolvers. You can query their database for your IP address or up to a /24. Their site also has information on how to reduce or eliminate the problem via a couple options (RRL, BCP38). If you run a BIND resolver, consider switching to unbound. Part of this problem is rooted in BIND combining resolver and authoritative service in one daemon, which IMO "mis-educated" a lot of people.
Once you got black-listed getting removed wasn't always an easy process no matter how quickly you tried fix whatever caused it.
I took a job in the year 2000, at a company with 3000 email users, listed by Spamhaus. First thing I did was close the open relay they were running. The listing was promptly removed, and the mail queue was back to normal within only a few days. I'm skeptical of your claim. I've never seen a confirmed case of Spamhaus aggression, but I've seen a lot that were disproven, and even more that sound like they were written by miscreants. Like the kind who would advocate DDoS attacks cough.
Good point; I think both of our statements are true due to ambiguous wording upstream. I also took it literally, "any filter relying on the SBL" -- I use the SBL (via ZEN) but don't use SpamAssassin. And so my mail servers wouldn't block any domain that resolves to an IP address in the SBL, as described in the link you provided.
As for DNSBL false positive rates, I haven't seen statistics in a few years, and by now they wouldn't be worth much. The only ones I saw were from 2005 or 2007. This one (linked to from the below article) from 2011 doesn't even test Spamhaus:
http://www.spamresource.com/2011/05/dnsbl-safety-report-5142...
This is just my personal experience saying (in 2013) that Spamhaus has the lowest FP rate, which isn't scientific. I'm kind of surprised there haven't been more FP comparison reports of major DNSBLs in recent years. If anyone has a link I'd love to see it.
any filter relying on the SBL is now marking email with the url "paulgraham.com" as spam.
Impossible. The SBL lists only IP addresses; there is no content filtering at all.
Furthermore, there's a lot of FUD in this thread about Spamhaus listing people who don't emit spam. IF this is true, then Spamhaus would have an unacceptably high false positive rate, and we would be able to observe this. In reality, Spamhaus has the lowest FP rate in the industry. Occam's Razor suggests those who claim to have been wrongly blocked are mistaken about the reason for their listings (if they ever existed in the first place).
In some countries, like France, asking someone you barely know "What do you do (for income)?" is considered vulgar. There, you ask what people are interested in, what they like doing, and so on. I like that. A lot.
Any ETA for allowing to block Referer header from being included in cross-origin requests?
This feature has been supported in Firefox for a long time, but you have to set it in about:config via the "network.http.sendRefererHeader" integer.
2 = always send
1 = send only to same FQDN (what you seem to want)
0 = never send
IMO this is one of the best bang-for-your-buck privacy configurations. I would love it if Mozilla changed the default from 2 to 1, and at the least, it SHOULD be an option under the Preferences -> Privacy tab.Run your own resolver on 127.0.0.1, and your own authoritative nameserver on 127.0.53.1, and configure the resolver to ask the nameserver (returning NXDOMAIN) for
* facebook.com
* doubleclick.net
* google-analytics.com
* su (abuse)
* 2o7.net
* any others you want; get ideas from the MVPS hosts file
Since facebook domains (fbcdn.net, facebook.net, etc.) are all serviced by facebook.com nameservers, returning NXDOMAIN for *.facebook.com will thereby sabotage all facebook related queries. This way you won't have to play whack-a-mole with future facebook tracking hosts, so long as they use facebook.com nameservers.Or hell, just create a list of prefixes announced & owned by AS32934, Facebook, and block all. Just to be sure.
I did this once, too. It's so nice to hear other people appreciate the approach!
The "CMS" I wrote was about 75 lines of sh, and had slightly fewer features than the one linked here. That's the beauty of writing your own: you decide what to include, and no more. cp wc sort awk etc. is all you need. If you want it to look beautiful, that's where design and CSS come into play, both of which are outside the scope of content management.
One of bitcoin's strengths is decentralization, and you just told people not to manage their own wallets.
How do you accept bitcoin? Please enlighten us.
I've lived/worked in both the USA and France, and this guy's comments are so transparently uninformed. To simplify things greatly: In France, there is more time off, but people are more sérieux while at work. In France, time off is taken outside of work, while in the US, time off is taken at work -- at the coffee machine, on reddit, chatting about banal stuff with coworkers, complaining about stuff (that's usually related to working too much)...
On a different note, I've noticed numerous CEOs lately bringing up politics in reference to their work. The most common example is, "my company isn't doing as well as expected, and it's a certain politician's fault, not mine." Gotta love the personal responsibility, there.
Ahhh.... I wrote a response wondering out loud why this doesn't work on my browser, then checked the source, and it's javascript. No wonder, I browse without it!
"Yeeaahhpp, with enough javascript one can blow up just about anything." ~Tyler Durden
They will need a stunning amount of marketing and advertising for this to become socially acceptable.
Well, according to the already existing marketing, if I buy one of these things, I'll have a happy family, dance with a classy, beautiful woman, have fun at New Year's, travel to Sedona, ride a snowboard, see the Brooklyn Bridge, shop for veggies in Chinatown, and travel some more.
You know what's interesting to me is that none of the faces staring back at "you" in the marketing are wearing Geordi La Forge glasses. If they were, would these "friends" seem as interested?
Before I can respond to that, I think there's a misunderstanding about what "public service" means. HTTP is a public service: you open it up to the world, and want anyone to be able to connect to it. It is intended and hoped that as many people use it as possible. If your website is slashdotted, then that's GREAT! In contrast, I don't want 100000 people to try logging in over SSH to my private server. To put it another way, SSH is only a public service in the cases of:
* CVS over SSH
* rsync over SSH
* Commercial SSH tunnels
Logging into my authoritative nameserver over SSH, however, is not a public service. And since it's not a public service -- that is, intended for the public -- I don't treat it like one.SSH is rarely a public service. What's the motivation for making it so public?
email is absurdly involved if you want to make sure that gmail etc. accept your messages as non-spam.
I've self-hosted DNS, mail, web, etc. for years, and several people have posted the same kind of comment here, so here's what people will need to know/do to self-host their own mail.
First, you'll almost surely need a non-end user IP address, as many/most of such address ranges are in the Spamhaus PBL list [0]. To see if your IP address is listed in PBL, for the example IP address 192.0.2.200, do
dig 200.2.0.192.pbl.spamhaus.org
Here, the octets are reversed and prepended to pbl. While you're doing this, you may as well also do
dig 200.2.0.192.zen.spamhaus.org
Again, replacing the above IP address with your own. This checks the Zen list [1].
For a non-end user IP address you'll most likely need a datacenter machine, a business line, a VPS, or a machine hosted at a large organization. A home Internet connection won't cut the mustard for mail.
Second, you'll need FCrDNS [2], or at least rDNS. rDNS is just short for reverse DNS, which means having a PTR record in DNS for your IP address. It could be anything, but something non-generic is best, such as mail.example.com, or puffy.example.com. wireless-cust-0-200.example.com is generic and will score "bad" points on some remote systems.
It's best if you can do FCrDNS, which is trivial. All that entails is matching PTR/A records.
This is all you need for Gmail or any other serious mail provider to accept your mail. Unfortunately it makes self-hosting from home more difficult, but the upside is a huge reduction in spam.
Last thing, you should check http://dnsbl.info or a similar site to see if your mail server's IP address is listed in any DNSBLs.
0. http://www.spamhaus.org/pbl/ 1. http://www.spamhaus.org/zen/ 2. https://en.wikipedia.org/wiki/Fcrdns
you are infinitely more likely to take a flight if you know everyone is being molested.
Speak for yourself; I for one don't like being treated badly. It's security theater at best, and runaway government power at worst, and either way it's at the cost of human dignity.
Inspiring! I'm glad to have read it.
After posting this comment, I'm going to start something similar: reduce Internet usage to a minimum (checking health of my servers, etc.) for a week, and with the free time, de-clutter. OMG the clutter is killing me. All these little pieces of paper, things lying out, stuff I don't use... it's negatively impacting my life. So call it a kill two birds with one stone deal.
In The Matrix Reloaded, Trinity uses nmap and then an OpenSSH exploit that was published a couple months before the film officially opened in theaters. Contrast this with Swordfish, where you get lines like (I'm paraphrasing from memory), "We have a DS3, allowing you to access eight systems simultaneously." Ugh, just hit stop and go outside.
Back on topic, Tron: Legacy to me feels like a highly technological father/son movie, in the same way that Google is a highly technological advertising company. So it seems we're already living in the future. "The Matrix has you..."
Even though getting officials fired is not your preferred method to help jumpstart reform there are no reasons for you to discourage others of doing so.
Exactly. Bottom-up action is strongest when supported by a diversity of tactics. Alice may not like Bob's methodology, and Bob may not like Alice's, but when they expend their energy discouraging each other from doing something they believe in, neither have a shot at advancing their shared cause. Gatekeepers are the undeclared allies of power.
Put your energy into action you believe in, and let the chips fall where they may.
How many? The population of the Internet is almost 3 billion.