Hacker Newsnew | past | comments | ask | show | jobs | submit | intsunny's commentslogin

> Linux has this too, it's called Devuan. 90% of the reasons you'd want to move from Linux to BSD can be addressed by getting rid of everything associated with FreeDesktop.org.

Ironically even FreeBSD core members have spoken about adopting some of what systemd does: https://papers.freebsd.org/2018/bsdcan/rice-the_tragedy_of_s...


Suddenly I realize why so many games didn't have a real pause feature, but a view maps feature that did the same.


Even before I clicked on the article, I had a strong feeling this person was using CloudFlare DNS and the related API. (They are.)

Given the immense popularity of Cloudflare DNS + API + ACME DNS-01 challenge, why are not other DNS providers stepping into this foray?


Cloudflare is not the only DNS provider supported for DNS-01 challenges, even if you restrict yourself to only using Certbot: https://community.letsencrypt.org/t/dns-providers-who-easily...


Perhaps I'm missing something but what's special about Cloudflare here?

You can use a boatload of providers for automated DNS-01.


There's a relatively short list supported by certbot out of the box.


One tool that can be used in a deployment hook which supports the API of several dozen DNS providers:

* https://github.com/dns-lexicon/dns-lexicon


The list of API integrations provided by the lego project looks quite impressive. https://go-acme.github.io/lego/dns/index.html


I have not used Cloudflare for ages, but remember the Cloudflare API key couldn't be restricted to just one domain, so if someone could get hold of the key, they could have gotten access to all your domains. So that made me not use them. Has anything changed?


Yes, API keys can now be linked to zones or domains.


Its funny, this is another of the billions of reasons why Mullvad should be the VPN of choice. But so many fucking people can't ever get over that their favorite social media influencer/Youtuber is offering a code for 200% off of NordShark VPN, now with extra AI.


Mullvad is great for privacy. But it's blocked by pretty much every VPN block list. NordVPN at the very least bypasses all the ones I regularly encounter.

I do use Mullvad for most web browsing though. But Imgur for example is blocked on it, and it's blocked in the UK, so I need NordVPN if I want to see any images there.

Most people's VPN usage is literally just geolocation restrictions and Nord is really good at that.


I regularly go to imgur via mullvad, exit Netherlands.


Aren't proxies good enough for that purpose?


The user experience differs for proxies.

System wide proxy configuration doesn’t actually always work system wide.

A VPN tends to have more success in encapsulating all application traffic (or all desired application traffic, if you’re so inclined to configure your system)


I love and use mullvad myself but I don't think they are very competitive for the average person. They mostly just care about getting around geo blocks on websites and streaming services, which mullvad puts 0 effort into facilitating.


It became less of a choice for many after they sadly had to disable port forwarding.


Yeah, their reasoning is solid (easy to abuse) but it is still a very useful feature.

AFAIK, at the moment your choices are AirVPN and ProtonVPN. AirVPN has static port forwarding and Proton has UPNP port forwarding.


private internet access has port forwarding too


PIA is not to be trusted after their buyout, IMHO


Currently using airVPN, but ye gods, their eddie client is atrocious on linux. I wind up using wg / nmcli, but then have to block traffic going outside of the vpn with iptable rules because it leaks for some reason.

I miss mullvad dearly, and I might try proton after my 3y sub is up.


Not only Eddie, their account control panels and site in general look like something from the 90s, and it seriously hampers their business. I can't recommend them to anyone that isn't highly technical. And even then, as a technical user, why do I manually have to select one of 10-20 servers within a city or region, why am I being asked to manually load balance? Why is there no Wireguard over port 53 or 443?

It makes more sense when you know they're privacy activists first, businessmen second. But Mullvad shows you can be pro privacy and still offer great UX and a sleek site and client.

Btw, if you're managing things in CLI, you could take a look at their Hummingbird Suite. AFAIK it has a killswitch.

What sucks with Proton is that you can't share the VPN account with friends, because it is tied to your Proton account. They should create a vpn.proton.me subdomain that you can create a special managed account on that can only touch the VPN settings.


>Btw, if you're managing things in CLI, you could take a look at their Hummingbird Suite. AFAIK it has a killswitch.

Hummingbird doesn't support wireguard iirc, which is a deal breaker


They're planning to introduce OpenVPN Data Channel Offload (DCO) support to more servers once Linux 6.18 starts becoming more mainstream.

With DCO, OpenVPN can perform almost as well as Wireguard, sometimes even better. Although with more performance overhead so not the best choice for laptops and phones.

Tangentially related but I kind of wish Wireguard looked more toward the future and had included AES as alternative to ChaCha20. At the time of development, many ARM devices didn't yet have AES acceleration which is why ChaCha20 was needed for wide hardware support, but they do since ARMv8 which became widespread in 2015. Intel and AMD have had AES acceleration for a long time. And then ChaCha20 would have been the fallback on MIPS and RISC-V.


I wish I could use Mullvad. But their IPs are banned from many streaming services and they don't change them often enough so I am stuck with Nord.


I would just pirate at that point. You're paying for the streaming service anyways. Use mullvad to download the torrent :). I'm pretty sure they ignore dmca requests. Not that they even know their customer's names if you pay with Mullvad amazon card.


Been buying mullvad for the last 4-5 years but oftentimes I can’t even browse the fucking New York Times website due to low bandwidth, let alone stream anything. At this point, I just keep adding time to my account just in case, without using it.


Not to mention holding companies which snap up 15 competing VPNs and whitelabel most of them.


Mullvad seems to care and be competent about privacy, but most average VPN users aren’t seeking the most extreme privacy. They just want something cheap that lets them do geolocation things or access the most websites.


The average VPN user is knowledge-less. At best their internet usage data is being sold to third party analytics companies. At worst third parties are routing their own bots through their local connection.


You do know that NordSec maintains its own rust fork of BoringTun: https://github.com/NordSecurity/NepTUN ? :)



They're excited about putting the spec behind a notoriously closed paywall??

Us older nerds will remember how Microsoft corrupted the entire ISO standardization process to ram down the Office Open XML (.docx/.xlsx/etc) unto the world.

The original Office ISO standard was 6000+ pages and basically declared unreproducible outside of Microsoft themselves.

There is an entire Wikipedia article dedicated to the kafkaesque byzantine nightmare that was that standardization. [0]

ISO def lacks luster, and maybe even relevance.

[O] https://en.wikipedia.org/wiki/Standardization_of_Office_Open...


100000% Agree.

Here in Germany, I'm convinced the Police simply don't care about motorcycles with modified mufflers. The sound is deafening. In the last decade the noise has gotten worse and worse.

Once one of those small penis motorcycle owners saw that I was covering my three year old child's ears as he passed by, and only then did he put his bike into neutral and walked it by us.


As a biker, I hate these types of riders with a passion. All street legal bikes come out of the factory with reasonable sound levels, they have to go out of their way to specifically make it uncomfortable for everyone else. Pretty much every one of them is exactly the type of person you'd expect as well, insecure with an intelligence level comparable to a wooden spoon. Personally I tell nearly no one that I ride bikes, because the first assumption is always that you're one of those loud assholes.


Problem with motorcycles in Germany is, they are usually too fast for the police to catch with their car, and the helmet prevents usable photos of the driver. But unfortunately the laws require that the driver committing the speed/noise/redlight offense is identified and fined, fining the owner by license plate doesn't work (except if the bike was modified).


Is that why some YouTubers started to make ads for a "sue your motorcycle speeding tickets invalid" company as if this is really working, because it is?

Germany has such a specific way of making laws with holes.


I'm not so sure that's actually true, because when you get a speeding ticket, the owner absolutely is fined. He has a right to identify the driver or just take it on himself.


The owner also has the right to refuse saying anything, in which case it is on the police to prove who the driver was. For cars, that's usually easy, because they just compare the ticket photo to your drivers license photo or passport photo on file. For motorcycles, the ticket photo is usually useless, so if the owner refuses to identify himself or someone else, and the police cannot prove anything, the motorcycle owner goes unticketed.


If you Google "geblitzt anzweifeln" or something you find several companies doing exactly that. Most claim something like 50% of speeding tickets are wrong. One site claims they make 12% of their cases invalid.

I really have no idea about all that. Just some absurdity I recently noticed.


Not every inconsiderate person is compensating for something. Some people just have different opinions from you about how to behave in public.

And no, I don't have a loud motorcycle.


Well, no, but, you know, common things are common.

These, along with various other obnoxiously loud and/or big vehicles, are _strongly_ coded 'insecure man'. Not necessarily insecure about that in particular, of course, but insecure about something.


The headline is not great because Google will obviously appeal the ruling to the appeals court of DC, and if they have to, the Supreme Court.

A lot can happy from now and then. And this may take many years to grind through the court system.

I wonder if there exists AI models of all the super senior and important judges so we can venture how this will play out through the court system.


Why would they appeal? This appears to be a huge win. What more could they reasonably wish for?


The judge hasn't issued a formal apology to Google... yet.


So Google has to appeal they're an illegal monopoly but the judge still thinks it's ok for them to keep Chrome?


Could the final vertict be worse for Google?


There are ways if could be, such as new evidence coming to light, but generally no. You don't want a system where people are punished for appealing.


I definitely anal but I am curious if this applies to civil lawsuits. This is a civil antitrust lawsuit, right? We never were seeking prison time for the CEO?


Yes; presumably their appeal will not raise issues where that is likely, but as is often the case in high-stakes civil litigation where neither side got what they wanted at trial, both sides are appealing this decision, and the government’s appeal no doubt will attenpt to raise issues that would present the possibility of things being worse for Google.


> The headline is not great because Google will obviously appeal the ruling to the appeals court of DC, and if they have to, the Supreme Court.

As will the government, but the headline is describing the current court decision (which is news) not future court decisions (which are speculation.)


Just as a reminder, the HDMI Forum is forbidding AMD from releasing an open source HDMI 2.1 driver for Linux:

https://www.phoronix.com/news/HDMI-2.1-OSS-Rejected

Displayport is the better technology in every way possible.


The article about the study writes: `The study has not yet been peer-reviewed.`

We should just stop reading the article then and there. This is a major method of how a single study can perpetuate fake science and fake news.


> This is a major method of how a single study can perpetuate fake science and fake news.

It's a feature, not a bug.


Clickbait is a bug tagged with WON'T FIX


We should, but we don't.

People want the news now. They don't want to wait for it to be peer reviewed, or even cursorily checked. There is an infinite maw for information, and it has already consumed every single known fact.

If you want science, you'll wait a month, because it's not actually urgent. These species waited hundreds of millions of years and it'll still be there in a few weeks.

If you want entertainment, you want it right this instant. And that's what LiveScience exists to do.

So you really should have stopped reading as soon as you saw the URL.


I always thought the begging for support by critical infrastructure open source projects would eventually not be a thing. I, could, not, have, been, more, wrong.....


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: