Viewing profile — 3np
3np
HN member- Joined
- Thu, Aug 27, 2020, 2:49 PM UTC
- HN karma
- 8,274
- Public activity
- 3,893 items
- HN profile
- View on Hacker News ↗
About 3np
Recent public activity
- comment
-
comment
Comment #46340516
Quadlets aren't what I'd personally use for local dev. They are good for running a local headless persistent service. So I wouldn't use it for your service-under-test but they can …
-
comment
Comment #46309183
> "Write your own Dockerfiles" is not useful security advice. I actually think it is. It makes you more intimate with the application and how it runs, and can mitigate one particul…
-
comment
Comment #46309096
Two paths: - Configuration management (ansible, salt, chef, puppet) - Preconfigured images (NixOS, packer, Guix, atomic stuffs) For a one-off: pssh
-
comment
Comment #46307472
> Not if you run it in rootless mode. Same as for docker, yes? https://docs.docker.com/engine/security/rootless/
-
comment
Comment #46307420
Hey, thanks for taking the time to share your learnings and engage. I'm sure there are HN readers out there who will be better off for it alongside you! (And good to hear you're le…
-
comment
Comment #46307373
Thanks! Would be cool to have it packaged for alpine since firewalld requires D-Bus. There is awall but that's still on iptables and IMO at bit clunky to set up.
-
comment
Comment #46307298
This affects podman too.
-
comment
Comment #46307078
It still says: > IT NEVER ESCAPED. You haven't confirmed this (at least from the contents of the article). You did some reasonable spot checks and confirmed/corrected your understa…
-
comment
Comment #46306974
> I also enabled UFW (which I should have done ages ago) I disrecommend UFW. firewalld is a much better pick in current year and will not grow unmaintainable the way UFW rules can.…
-
comment
Comment #46306781
As sibling mentioned, unless you or the runtime explicitly mount the docker socket, this particular scenario shouldn't affect you. You might still want to tighten things up. Just a…
- comment
-
comment
Comment #46112314
> > Onboarding is bad > Sorry, but you have to run an auth server (matrix-authentication-service) if you want Element X to work. This is a bit outrageous IMO. Actually breaking and…
-
comment
Comment #45237755
The answer seems obvious but one that won't be spelled out in SCMP.
-
comment
Comment #45237398
Great you found something that works for you and that you managed to dodge the parts of the community that somehow managed to turn this into identity politics . Still, the gaps are…
-
comment
Comment #45236986
Cheers! 10% is nothing to scoff at! ...While I have your ear: IME ReThink DNS often runs into bootstrapping problems since 1) preconfigured DNS servers are referenced by hostname, …
-
comment
Comment #45236719
The currently latest stable release of Debian (13.1) ships a broken version of systemd-networkd which may break networking completely for affected users. Maintainer response is les…
- story
-
comment
Comment #45236616
Tried Brave?
-
comment
Comment #45236340
Wayland is great and ready for (idk) 95% of users/use-cases. There is a long tail of more-or-less critical stuff that depend on X11 and do not have working Wayland substitutes. Whi…
-
comment
Comment #45235616
How is this spam not autoflagged by now? https://news.ycombinator.com/from?site=reddit.com
-
comment
Comment #45235543
> The bullet engravings are well known You can read anything you want into those if you want to. To me they reek weeb culture (as opposed to furry like everyone else jumps to - the…
-
comment
Comment #45234075
> I don't think you can get much further right than he was though. Groypers.
-
comment
Comment #45231147
Perhaps the people you see as cynical have more research and/or experience behind their views on OpenAI than you. Many of us have been more naive in the past, including specificall…
-
comment
Comment #45230984
How recently was this experience? TFA frames this all as recent and ongoing learnings and changes at F-Droid. Given the notability of your project (kudos and thanks), perhaps they'…