HN user

yabones

5,483 karma
Posts49
Comments569
View on HN
www.spaceweather.gov 6d ago

Goes-19 weather satellite enters Safe Hold mode

yabones
178pts92
nbailey.ca 3mo ago

How to turn anything into a router

yabones
777pts261
www.syncdna.com 10mo ago

Time travel? Or, just clever technology

yabones
75pts31
status.matrix.org 10mo ago

Matrix.org – Database Incident

yabones
17pts25
arstechnica.com 1y ago

Self-driving Waymo cars keep SF residents awake all night by honking

yabones
100pts29
www.cbc.ca 3y ago

CBC pauses Twitter activity after being labelled 'government-funded media'

yabones
34pts33
mta.openssl.org 3y ago

OpenSSL Security Advisory

yabones
3pts0
nbailey.ca 3y ago

Block web scanners with ipset and iptables

yabones
110pts44
confluence.atlassian.com 4y ago

Confluence – Critical unauthenticated remote code execution vulnerability

yabones
14pts3
www.openssl.org 4y ago

OpenSSL – C_rehash script allows command injection

yabones
6pts3
lists.apache.org 4y ago

CVE-2022-24706: Apache CouchDB Remote Privilege Escalation

yabones
2pts1
arstechnica.com 4y ago

Chrome’s “Topics” advertising system is here, whether you want it or not

yabones
43pts3
www.cisa.gov 4y ago

CISA: Russian state-sponsored cyber actors target defense contractor networks

yabones
5pts0
nbailey.ca 4y ago

Simple server alerts on a need-to-know basis

yabones
62pts9
nbailey.ca 4y ago

Simple server alerts on a need-to-know basis

yabones
1pts0
www.debian.org 4y ago

Debian 11.2 Released

yabones
6pts0
www.openssl.org 4y ago

OpenSSL Security Advisory (14 December 2021)

yabones
124pts41
nbailey.ca 4y ago

Castles, alligators, machine guns, and mail

yabones
1pts0
www.malwaretech.com 4y ago

An in-depth look at hacking back, active defense, and cyber letters of marque

yabones
4pts0
www.openssl.org 4y ago

OpenSSL 3.0

yabones
150pts54
nbailey.ca 5y ago

Windows 11 will create heaps of needless trash

yabones
293pts335
msrc.microsoft.com 5y ago

CVE-2021-31166 – Windows HTTP Protocol Stack Remote Code Execution Vulnerability

yabones
5pts1
en.wikipedia.org 5y ago

Mojibake

yabones
2pts0
www.openbsd.org 5y ago

OpenBSD 6.9

yabones
174pts49
nbailey.ca 5y ago

Domesticated Kubernetes networking – Making it work on bare metal behind NAT

yabones
1pts0
outage.report 5y ago

Rogers cell network is down nation-wide

yabones
9pts4
gcn.com 5y ago

Software glitches leave Navy Smart Ship dead in the water (1998)

yabones
2pts1
www.troyhunt.com 5y ago

Data Breaches, Class Actions and Ambulance Chasing

yabones
2pts0
nbailey.ca 5y ago

The Cursed Certificate

yabones
2pts0
archlinux.org 5y ago

Arch Linux: Installation medium with installer

yabones
12pts4

It's probably somewhat regional, as the ones in Canada seem to have pretty good tourism interest, especially when they're right inside a city like Quebec and Halifax.

But we're also very starved for true "Medieval Castles" like Europe or east Asia, so we take what we can get!

Not sure if they count, but the site appears to be missing loads of British star-forts built around the great lakes, st. lawrence, and eastern Canada!

https://en.wikipedia.org/wiki/Citadel_Hill_(Fort_George)

https://en.wikipedia.org/wiki/Georges_Island_(Nova_Scotia)

https://en.wikipedia.org/wiki/Citadelle_of_Quebec

https://en.wikipedia.org/wiki/Old_Fort_Erie

https://en.wikipedia.org/wiki/Fort_Anne

They built these things _everywhere_, probably a good part of what bankrupted the British Empire!

https://en.wikipedia.org/wiki/Fort_Charlotte_(Nassau)

https://en.wikipedia.org/wiki/Prince_of_Wales_Fort

It once made me exit the highway, using the nearly empty exit ramp, then do a U-turn on the surface street and get back using the lightly used entrance ramp. Wow, all that effort to move about 250m forward in traffic, saving me perhaps 30 seconds of time on my 3 hour drive. Very "over-optimized" software does bizarre stuff that no sane person would ever do.

There's likely an "updater service" that runs with elevated privs that's used for all kinds of other nasty stuff. Windows task scheduler is full of stuff like this if you know where to look, and plenty of hidden services on Macos.

The problem is that there haven't been good enough native ways to do updates & maintenance on installed applications, at least in the past, so this type of stuff became acceptable and commonplace.

I don't see the issue with dry cask storage medium term, and deep geological storage long term. Spent fuel isn't really that dangerous once it's been cooled down and for a couple decades before putting it in the ground, to the point that there are far more dangerous natural things you can dig up.

What concerns me is that 250 years of fossil fuel energy continues to store its waste products in my lungs and the water I drink. That's the issue we need to solve with urgency.

This issue here isn't surveillance as per a signed warrant. I don't think anybody's really arguing against that.

The problem is mass data collection without suspicion, probable cause, or warrants whatsoever. That's a brand new thing, other than the places in the world unfortunate enough to have roving gangs of police going door to door and searching homes without warrants. This facilitates it on a scale that's never really been seen before in human history.

While there might be some benefit, most of them are snakeoil. Effectively they're just sending polite emails to "people search" websites to remove you from search results. The real, very harmful, data brokers are background check systems (LexisNexis), credit bureaus (Equifax), and insurance industry registries, which there is effectively no way to opt-out short of faking your death.

Obviously "physical access is full access", but it's shockingly easy to break into a Windows box if you have access to the unencrypted drive. I learned with I was a teenager how to use the recovery partition to mount the C: drive, then copy "cmd.exe" to "utilman.exe" or "sethc.exe" and get an instant root shell on the login page. Takes about 2-3 minutes, can be done in the time somebody leaves their laptop to go to the bathroom at Starbucks.

To me that's the main thing about disk encryption, it's to stop a nasty rootkit from being installed trivially as much as it is about stopping the guy at the pawn shop from getting your tax info. Whether you're on macos, linux, or windows, it's really quite easy to fully compromise a machine if you have hands on it.

I do this on long drives, but always have to put it back to normal when it's time to park. It would be neat if cars would implement some sort of automatic switch between this configuration and the straight-back mode when reversing.

The situation out west is indeed rough. Saskatchewan still burning coal and Alberta... Being Alberta. It's not to say we can't fix it, those are both places where you can build plenty of solar and wind power for very cheap.

These problems are very political, but also very fixable. I think (well, hope) once it becomes clear that cheap Chinese EVs are here to stay the tide will begin to turn. In terms of total lifetime cost, you can either spend 200K CAD on a Silverado or 50K CAD on a Dolphin.

Seems like a good plan. Canada has the third largest hydroelectric power production in the world, and quite a bit of nuclear, so let's use it properly. People talk about transmission infrastructure like it's difficult, but we're the ones who made the ~5,000 KM HVDC system that feeds the northern US from James Bay! I don't see why we can't quickly electrify transportation, it's the kind of project Canada seems to be pretty good at.

https://en.wikipedia.org/wiki/Quebec_%E2%80%93_New_England_T...

I'm curious how this might help with our biggest downtime-causer with postgres, which is major version upgrades. Poolers do a great job for failover and load balancing, but we consistently need ~10-20 minutes of downtime once or twice a year to do upgrades. Logical replication between old->new versions could probably help, but it would still require flipping everything over to the new cluster without partial writes or anything silly. Anybody have experience with this?

Claude for Legal 2 months ago

Who's accountable when it does something wrong? Surely Anthropic Inc won't take the fall for you. There's no errors or omissions insurance, no legal accountability, no attorney-client privilege, and no bar association to handle disciplinary action.

I think we should be realistic here, this is a more advanced version of those "will kits" that spit out a PDF. The legal system will not look fondly upon this stuff until something fundamentally changes.

And like, I would love if we didn't have to spend thousands of dollars to defend ourselves in a culture as litigious as ours. But I wouldn't put my life and well being on this thing.

It's crazy that they're using radio frequencies that are within the range of human hearing... Obviously sound and RF are different things, but it puts into perspective how a "high" sound is a very "low" frequency ;)

I get the allure, but it's not for me and my partner.

We live in a small apartment. We drive a small car. The pantry has a good amount of dry bulk & canned food, but we largely shop one week at a time.

Sure, we could "lock in" on two or three foods, buy weeks worth of them at a time, and save some money. But like most people we like a bit of verity. It's just not possible to buy such massive quantities of things with nowhere to store them.

What I want is an anti-costco. More like a bodega. Still curated, maybe a larger mark-up, but smaller quantities of everything. Half loaves of bread, small bags of frozen veg, enough sugar or flour to bake just a couple batches.

For the vast majority of human civilization, all taxes were based on wealth. Your emperor, pharaoh, czar, or whoever was in charge sent a dude around to take a bit of everybody's stuff. Not how much income they made but how much stuff they actually had. It's only been the last 120-ish years that the idea that wealth and income were totally different things as far as taxation is concerned emerged.

I think almost everybody would be better off if taxes were something like 1% of total assets rather than off the top of your income.

"move fast and break things" only sounds good when it's not breaking things in a serious and unfixable way. Maybe we shouldn't take hype mantras as instructive means to an end.

It feels like people are more willing to give their agent a prompt than search the web for existing solutions.

I've noticed a crazy amount of clearly AI coded projects that do a small subset of an already existing and very trusted open source project. Comments usually point this out, and the OP never responds. I'm not sure what the end goal is, but the whole thing feels like a waste of time for everybody involved.

The folks that run the colo I keep our servers in would beat me to death with a shoe if I did either of these things:

- Mount something in a rack not firmly attached to brackets or a shelf

- Install anything with a battery larger than you'd find in a RAID card

Not to mention all the other ways this is sub-par in terms of airflow, density, serviceability, out-of-band management, etc.

I get the allure of it, but I wouldn't really want my gear anywhere near a bunch of laptops stuck in a cabinet.

That kind of seems crazy to me, considering OpenBSD has worked perfectly fine with every wifi capable device I've tested it on. Granted, most of them were older machines.

Is this just an artifact of FreeBSD primarily focusing on server hardware rather than consumer/end-user stuff?