Live data from Hacker News

Viewing profile — wejn

wejn

HN member
Joined
Wed, Feb 17, 2021, 9:53 PM UTC
HN karma
29
Public activity
34 items

About wejn

[ my public key: https://keybase.io/wejn; my proof: https://keybase.io/wejn/sigs/Q5ZKPYzRZhM3jYAgyQuflCM46bgQ05ZifJpxHT1bIRk ]

Recent public activity

  1. story
  2. comment
    Comment #39381149

    Svalboard is the next generation Datahand. In other words, a keyboard with zero hand movement, optical switches, and mostly querty layout (or Dvorak, Colemak, if you want it). Unli…

  3. story
  4. comment
    Comment #37688043

    Why don’t you get a svalboard.com then? (It’s a commercialized next gen of lalboard)

  5. comment
    Comment #37547775

    Yup. Been running my own for past two decades, still works.

  6. comment
    Comment #37545548

    If you destroy the CA, how do you issue new certs via ACME?

  7. comment
    Comment #37544999

    This isn’t strictly true. If you want to uphold the name constraints in your CA cert, mark the field as critical. At that point clients that don’t understand them should fail valid…

  8. comment
    Comment #37543259

    Thanks, I've incorporated the name constraints into the article now. (it is indeed supported by Apple and FF just fine)

  9. comment
    Comment #37542098

    "only" out of scope. But based on the comments here, I guess you could use the smallstep CA with Nitrokey HSM if that's your jam...

  10. comment
    Comment #37542085

    Because: 1. ACME is a dumpster fire prone to mitm attacks. 2. without HSM (an additional investment) it's super bad idea to host your root CA signing key somewhere.

  11. comment
    Comment #37538519

    That's really neat, thanks for the pointer. ;)

  12. comment
    Comment #37538447

    And yet, my homegrown root CA cert with 3650 days of validity hums along just fine... [edited: but since I also want to have host certs that are on various internal servers, the sh…

  13. comment
    Comment #37538417

    A friend of mine runs dns01 thusly: https://ipng.ch/s/articles/2023/03/24/lego-dns01.html

  14. story
  15. comment
    Comment #27274407

    Hmm, that's an interesting point. I would encourage them [= someone who only spent a couple of hours on Unix] to dig further... broader. Mostly by demonstrating that there are real…

  16. comment
    Comment #27269415

    True. Just a couple of hours. On the other hand... is walltime the only criterion worth considering?

  17. comment
    Comment #27269089

    Interesting. I thought that I was tearing down the fact they took the brilliant new idea, and bastardized it beyond recognition, and in multiple ways. I loved the promise of Urbit,…

  18. comment
    Comment #27268886

    And there I was, thinking that the first four paragraphs pretty much summed up the frame of mind with which it was written.

  19. comment
    Comment #27268857

    Ehm, nope: ivmmeta.com

  20. comment
    Comment #27268843

    That'd be no (for natural immunity). Even SARS-1 survivors have immunity to COVID, all these years later. Maybe for the synthetic immunity (who knows). But in any case, SARS-1 and …

  21. story
  22. story
  23. comment
    Comment #27054298

    Thank you for the compliment. I can wholeheartedly recommend starting. Just about anywhere, really. I'm a total noob when compared with real electronics engineers... but it doesn't…

  24. comment
    Comment #27054179

    :-) I so wish I could lay claim to that phrase. In any case, I wholeheartedly recommend giving "Screen Rant Pitch Meeting" a watch (on YT).

  25. comment
    Comment #27054151

    If I were in your shoes (and I often am, in various other contexts), I'd get the cheapest SDR dongle, and then use your favorite search engine for tutorials (there's plenty). First…