Live data from Hacker News

Viewing profile — oneplane

oneplane

HN member
Joined
Sun, Jan 03, 2016, 12:51 AM UTC
HN karma
6,820
Public activity
2,774 items

About oneplane

self-hosting toolbox

Recent public activity

  1. comment
    Comment #49034821

    It's been extensively reported on, and any AWS user that clicks on the health dashboard would also have seen it, even if they don't consume from news outlets. As for use it gets: p…

  2. comment
    Comment #48575472

    How is it crazy? It's perhaps not granular (the repository is the boundary, and that's that), but you can definitely restrict who can pull or push as easy as you can make rules for…

  3. comment
    Comment #48391166

    What are you even talking about. Every M1 Mac and earlier runs Linux. Even all the way back to PowerPC. Granted, the M1 and up are not 100% covered yet (driver-wise), but they aren…

  4. comment
    Comment #48391112

    Since SIP, it's MDM with DDM and you can basically leave engineers be local admins as it has no impact on the system state anymore.

  5. comment
    Comment #48212376

    I'd rather go back to bare metal than use Azure.

  6. comment
    Comment #48122054

    Those local options exist, and have been around forever, but the problem is nobody is doing it without cutting corners and with pay-as-you-go elasticity (and the 'call an API, get …

  7. comment
    Comment #48121977

    Not really, some of the IP is core to the product and it cannot function without it. In theory if you do something like come up with a complete replacement for EUV, you could, but …

  8. comment
    Comment #47750686

    Which is why I wrote about running the exact UI that was referenced, with the same window server, window manager and desktop environment.

  9. comment
    Comment #47743705

    That statement makes no sense. X11 works fine on macOS and running it in rootful mode with Gnome essentially works the same way it would work on an OS that uses the Linux kernel. G…

  10. comment
    Comment #47717227

    It does, it's called FreeIPA (or RedHat IdM). The only GPO parts it doesn't do are those that are not related to policy in the IAM sense (i.e. configuring some application related …

  11. comment
    Comment #47586952

    Oh yeah, you got the same process down pretty much yourself, wasn't an RTFM dig or anything like that. It was more aimed at others who might end up here, more tools, more better! I…

  12. comment
    Comment #47581264

    There is a lot of documentation from Apple on how all of this works, but this is indeed expected behaviour. A way to make this smoother would have been: 1. Doing the password reset…

  13. comment
    Comment #47535290

    Run it in a restricted VM, which is not joined to AD and cannot talk to it either. PAM will not save you, either will Airlock Digital or something like ATP or anything else like it…

  14. comment
    Comment #47304051

    That online builder is very cool, well done! I've been trying out similar things to help internal teams to use systems and languages like Rego (for Open Policy Agent) to have a vis…

  15. comment
    Comment #46995833

    When they shrank the disc it just became minidisc ;-) But that was technically MO, not just optical. And: it was in a cartridge so I suppose they really should have called it minid…

  16. comment
    Comment #46820047

    Don't enable anything you don't need. Use the OS-native priority modes; i.e. no Slack messages after 18:00, no general message notifications unless from specific contacts, disable …

  17. comment
    Comment #46275340

    I think the comment mainly pointed out the distinction between education using digital methods, vs. educating about digital things.

  18. comment
    Comment #45980083

    It's not a counterpoint, it's a display of your factually incorrect statement.

  19. comment
    Comment #45947680

    > In other words, you're completely fucked if you brick your install. I consider iBoot a direct user-hostile downgrade from UEFI for this reason. That's a bit of a creative perspec…

  20. comment
    Comment #45945702

    Only if you boot into macOS and connect it to the internet. iBoot2 never changes by itself, you, the user, decides if you want to boot into recovery or macOS and run an update. So …

  21. comment
    Comment #45616863

    Gee, another "we did not need cloud, so by not using cloud, we stopped spending on something we did not need"-story. Duh. The real story is why someone who doesn't need cloud servi…

  22. comment
    Comment #45545718

    The problem was that the user's credentials were revoked but because the root account was a shared credential it wasn't revoked. Was the break-glass account also a user-specific ac…

  23. comment
    Comment #45532278

    Not using root means not bypassing policies. There is no way to not bypass all policies. So yes, never using root makes that issue go away completely. As for all the other stuff: w…

  24. comment
    Comment #45532259

    No, a massive amount of CloudTrail logs.

  25. comment
    Comment #45531378

    You don't need the root account, unless you need to bypass all policies. In such a scenario, you a use the root access reset flow instead, reducing standing access. As for other fl…