Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
3np
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
3np
9mo ago
Quadlets aren't what I'd personally use for local dev. They are good for running a local headless persistent service. So I wouldn't use it for your service-under-test but they can be a good fit for supporting dev tools like a
2.
▲
by
3np
9mo ago
> "Write your own Dockerfiles" is not useful security advice. I actually think it is. It makes you more intimate with the application and how it runs, and can mitigate one particular supply-chain security vector. Agreeing that
3.
▲
by
3np
9mo ago
Two paths: - Configuration management (ansible, salt, chef, puppet) - Preconfigured images (NixOS, packer, Guix, atomic stuffs) For a one-off: pssh
4.
▲
by
3np
9mo ago
> Not if you run it in rootless mode. Same as for docker, yes? https://docs.docker.com/engine/security/rootless/
5.
▲
by
3np
9mo ago
Hey, thanks for taking the time to share your learnings and engage. I'm sure there are HN readers out there who will be better off for it alongside you! (And good to hear you're leaving the LLMs out of the writing next time <3)
6.
▲
by
3np
9mo ago
Thanks! Would be cool to have it packaged for alpine since firewalld requires D-Bus. There is awall but that's still on iptables and IMO at bit clunky to set up.
7.
▲
by
3np
9mo ago
This affects podman too.
8.
▲
by
3np
9mo ago
It still says: > IT NEVER ESCAPED. You haven't confirmed this (at least from the contents of the article). You did some reasonable spot checks and confirmed/corrected your understanding of the setup. I'd agree that it look
9.
▲
by
3np
9mo ago
> I also enabled UFW (which I should have done ages ago) I disrecommend UFW. firewalld is a much better pick in current year and will not grow unmaintainable the way UFW rules can. firewall-cmd --persistent --set-default-zone=block
10.
▲
by
3np
9mo ago
As sibling mentioned, unless you or the runtime explicitly mount the docker socket, this particular scenario shouldn't affect you. You might still want to tighten things up. Just adding on the "rootless" part - running the co
11.
▲
by
3np
10mo ago
> > Onboarding is bad > Sorry, but you have to run an auth server (matrix-authentication-service) if you want Element X to work. This is a bit outrageous IMO. Actually breaking and deprecating the classic auth and requiring a new s
12.
▲
by
3np
1y ago
The answer seems obvious but one that won't be spelled out in SCMP.
13.
▲
by
3np
1y ago
Great you found something that works for you and that you managed to dodge the parts of the community that somehow managed to turn this into identity politics . Still, the gaps are there and don't seem to be filled anytime soon, despi
14.
▲
by
3np
1y ago
Cheers! 10% is nothing to scoff at! ...While I have your ear: IME ReThink DNS often runs into bootstrapping problems since 1) preconfigured DNS servers are referenced by hostname, not IP 2) I can't find a way to separately configure se
15.
▲
PSA: systemd-networkd segfault regression in Debian 13.1 for some users
(lists.debian.org)
4 points
by
3np
1y ago
|
1 comments
16.
▲
by
3np
1y ago
The currently latest stable release of Debian (13.1) ships a broken version of systemd-networkd which may break networking completely for affected users. Maintainer response is less than encouraging: https://bugs.debian.org/
17.
▲
by
3np
1y ago
Tried Brave?
18.
▲
by
3np
1y ago
Wayland is great and ready for (idk) 95% of users/use-cases. There is a long tail of more-or-less critical stuff that depend on X11 and do not have working Wayland substitutes. While the tail has been shrinking for every year, it will
19.
▲
by
3np
1y ago
How is this spam not autoflagged by now? https://news.ycombinator.com/from?site=reddit.com
20.
▲
by
3np
1y ago
> The bullet engravings are well known You can read anything you want into those if you want to. To me they reek weeb culture (as opposed to furry like everyone else jumps to - there are overlaps but they are distinct), 4chan trolling an
21.
▲
by
3np
1y ago
> I don't think you can get much further right than he was though. Groypers.
22.
▲
by
3np
1y ago
Perhaps the people you see as cynical have more research and/or experience behind their views on OpenAI than you. Many of us have been more naive in the past, including specifically towards Altman, Microsoft, and OpenAI.
23.
▲
by
3np
1y ago
How recently was this experience? TFA frames this all as recent and ongoing learnings and changes at F-Droid. Given the notability of your project (kudos and thanks), perhaps they'd appreciate your input.
24.
▲
by
3np
1y ago
Seems a bit vulnerable to subversion of the host (and/or its government) once they decide to pay attention (or even through negligence; imagine a minister being banned because of some ML false-positive). If the format is to be sustaina
25.
▲
by
3np
1y ago
My personal systemctl clunk pet-peeve is "get list of all currently (active/running) (units/services)". Something like a "systemctl ps". Consider this a feature request, I guess :)
26.
▲
by
3np
1y ago
Considering how obviously in the wrong he is, it might not be too off calling that a win for him.
27.
▲
by
3np
1y ago
Very scant on details. Who built it? Who operates it? Is it using existing proprietary LLM platform(s) or using their own tech?
28.
▲
by
3np
1y ago
I'm usually on the other side of these things but here I think most of the actual (some might be artificial...) outrage and concern come from a misunderstanding of the product and services Huntress are selling and how their EDR product
29.
▲
by
3np
1y ago
Food for thought: Perhaps it wasnt't the money as much as Stripe itself being the barrier? Maybe you would have gotten better turnout with other payment options (especially for a platform like Trello, crypto like BTC/XMR might be
30.
▲
by
3np
1y ago
> As a technology, it is just database joins. As a business, it is far more. Their FDEs are intrinsic to unlocking capabilities for customers.
More ›