Live data from Hacker News

🥺: the best sudo replacement

xeiaso.net

531–540 of 559 posts

Re: 🥺: the best sudo replacement

#531

Earlier quoted context omitted.

Yeah, sorta proves my point. I expected it.

Here we go, I'm at -3 and you are faint grey.

Hint: If you make a comment that is confrontational but makes no other points, many (if not all) of the people downvoting you are not your opponent, they're someone unrelated who thinks you made an annoying comment. Those downvotes prove absolutely nothing about your opponent.

Re: 🥺: the best sudo replacement

#532
Is this not so microaggression really necessary at the top of every post? it sounds rude and it is not an efficient way of communicating the relevant information.

>Hello. Before commenting about the author, please read this page that explains >the >pronouns that you should be using. tl;dr: the author of this website is NOT >male. >Please do not use "he" or "him" when referring to the author.

How about

> Hi. I am nonbinary. > I prefer the following gender identity pronoun pairs >(xe/xer),(they/them),(she/her) >If you would like to know more here is a link.

(based on blog post and https://www.reddit.com/r/transprogrammer/comments/ox7aef/chr...)

I am autistic and all I want is an efficient way to address this issue I dont care about the politics. Just give me a universal, drama free, efficient way of addressing you and I will do so.

We should just make that a HTML Meta tag or microschema

Given that there are over 72 different genders now listed here: (https://www.medicinenet.com/what_are_the_72_other_genders/ar...)

Plus: There is no fixed number of gender identities. They occur on a spectrum, which really means that the possibilities are infinite. https://www.medicalnewstoday.com/articles/types-of-gender-id...

HTML will need ways to convey such information in an orderly and efficient manner.

Or we could just reduce infinite to 1 One pronoun pair to bind then all. . Hu? (For HuMAN) (so only Hu)

In some languages you address people in different a different manner depending on age. and some based on age and perceived status. (and in most some variant if married or not).

All of that can be removed.

Age,Married Status and so on is not required knowledge. Gender identify is also not required knowledge.

Hu / Hua ?

Re: 🥺: the best sudo replacement

#533

Is this not so microaggression really necessary at the top of every post? it sounds rude and it is not an efficient way of communicating the relevant information. >Hello. Before commenting about the author, please read this page that explains >the >pronouns that you should be using. tl;dr: the author of this website is NOT >male. >Please do not use "he" or "him" when referring to the author. How about > Hi. I am nonb…

Hi, author of the site here.

It only shows up for people that visit via Hacker News with ads disabled. If you don't want to give me ad impressions, then when you visit it gives you a nudge to be civil when commenting on the article.

Is there anything I can do to change it so that it's better?

If you don't want to see that message, please disable your ad blocker.

Re: 🥺: the best sudo replacement

#534
post #259
post #123

Earlier quoted context omitted.

The main problem with SSH keys is that they are good at small scales, but at larger scales the abstractions start to be really leaky. Distributing SSH keys across hundreds of machines is a nontrivial task. Not to mention the lack of audit logging in opensshd and the lack of session recording (these requirements suck but acronym compliance means you need them anyways). It's also kind of the wrong tool for the job anyw…

> It's also kind of the wrong tool for the job anyways. I'd love to see tools that are more built to purpose for what you are _actually doing with the servers_ instead of giving people a REPL and telling them to go nuts. On the other hand, if you knew what I'd need to do with the servers, I probably wouldn't need to do it. It's really hard to investigate problems without tools. Nobody is going to make a graph for how…

Ah the dream of easy to administer, perfectly adapted fine grained access permissions that can predict the future of exactly what an authorized user can run and needs to do.

It never works because of the lack of precog, ticket walls, escalation over policy requiring reviews, and other bureaucracy.

What they end up replacing ssh with (teleport or aws ssm are the two I've been forced to use) are slow, spotty, crash frequently, and who knows what vulnerabilities they have.

If all these companies trying to get rid of sshd want to slap their own daemon on to replace it, why not keep sshd and simply have a deamon that manages the keys and not throw out the entire tool chain?

The most fun thing with teleport and aws-ssm: to use it you had to bring up a web page to authenticate. There goes any hope of automation at scale. Because in a world where you're supposed to treat servers like cattle, let's impose (and I mean impose) a regime that forces you to access them one at a time manually, especially in critical situations.

Re: 🥺: the best sudo replacement

#535
post #533

Is this not so microaggression really necessary at the top of every post? it sounds rude and it is not an efficient way of communicating the relevant information. >Hello. Before commenting about the author, please read this page that explains >the >pronouns that you should be using. tl;dr: the author of this website is NOT >male. >Please do not use "he" or "him" when referring to the author. How about > Hi. I am nonb…

Hi, author of the site here. It only shows up for people that visit via Hacker News with ads disabled. If you don't want to give me ad impressions, then when you visit it gives you a nudge to be civil when commenting on the article. Is there anything I can do to change it so that it's better? If you don't want to see that message, please disable your ad blocker.

Interesting, was there a reason to target that specific user group with the message, or is it just filling space that would have been populated by an ad?

Re: 🥺: the best sudo replacement

#536
post #528

Earlier quoted context omitted.

My bank requires a password of exactly 8 digits. In 2023.

A bank I used until about 2018 (no idea if they've fixed this yet - I left) had an exactly 6 character password, and when you used telephone banking it just needed the 6 digits that corresponded to that word. Those 6 numbers also worked online, so at best they were turning all passwords into numbers before hashing them, ensuring there are less than 900000 different possible passwords, which was trivially easy to brut…

Bruteforcing should not work as the attempts are either throttled, or lock the account. Provided that they are in place, otherwise the account is wide open.

This i what happens with the 4 digits of a CC PIN and the 3 attempts before the card switches into PUK mode.

Re: 🥺: the best sudo replacement

#537
post #533

Earlier quoted context omitted.

Hi, author of the site here. It only shows up for people that visit via Hacker News with ads disabled. If you don't want to give me ad impressions, then when you visit it gives you a nudge to be civil when commenting on the article. Is there anything I can do to change it so that it's better? If you don't want to see that message, please disable your ad blocker.

Interesting, was there a reason to target that specific user group with the message, or is it just filling space that would have been populated by an ad?

Normally that has a "please disable your ad blocker to help this blog be self-sustaining or donate on patreon" message. But Hacker News users spew so much venom and vitriol (see OP in this thread) that I am a bit more pointed and blunt with the nag messages. Going by the numbers of hits vs as impressions my hypothesis is that the biggest assholes block ads.

I did the math for last year and somehow my blog actually made a small profit! It's nowhere near enough to make me want to quit my dayjob, but it's at least enough that the excess can pay for all my video game purchases. I need to finish that article detailing the blog's finances for 2022.

Re: 🥺: the best sudo replacement

#538
post #437

Earlier quoted context omitted.

Password character limits are important. They reveal that the back-end service probably doesn't hash the passwords, which is a good time to GTFO.

My bank requires a password of exactly 8 digits. In 2023.

I know of banks which, in 2023, requires exactly 8 digits, the first four being numbers, the other four later letters. No digit can be repeated. Also no consecutive numbers.

It's like they're deliberately trying to reduce the pool of valid inputs.

Re: 🥺: the best sudo replacement

#539

Earlier quoted context omitted.

The meaning can also be inferred from… the face.

Judging just from that, I'd have taken the meaning as "verge of crying" or "my pet just unexpectedly died" Until I read that comment I was having real trouble figuring out WTF it had to do with running commands. I thought it might be some practical joke tool that automatically modifies your commands such that they'll make you sad when they run.

I also interpreted it as eyes watering up on the verge of crying.

Re: 🥺: the best sudo replacement

#540

Earlier quoted context omitted.

My bank requires a password of exactly 8 digits. In 2023.

I know of banks which, in 2023, requires exactly 8 digits, the first four being numbers, the other four later letters. No digit can be repeated. Also no consecutive numbers. It's like they're deliberately trying to reduce the pool of valid inputs.

Not only this, but they also have a sadistic trait against their users. My password on another site (a bank too, IIRC) requires the password not to have my email username and consecutive, or repeated letters. My email username is "u" (as is u@example.com) and I usually generate a 50 or 70 characters long password. There is usually a "u" (they check the case, too). And come characters are repeated in the whole password.

So I reduce the length, significantly, sometimes to 8 characters.

The people who make rules in security in some areas are complete idiots.

Post reply on HN