Hacker Newsnew | past | comments | ask | show | jobs | submit | Panino's commentslogin

Mailing list archive software is a constant rug pull: today you link to a post about something relevant, and next month the link goes to a different message about a different subject.

> Ask anyone who has had a system installed.

This didn't happen to me or anyone else I know with rooftop solar in multiple states, and I've never heard of it. What citations do you have?


I hadn't read that so I looked it up to verify, and it appears true:

https://www.eff.org/deeplinks/2016/04/ciscos-latest-attempt-...

Cisco looks to have made money from repression and torture.

Meanwhile a large fraction of neo-nazis, credit card thieves, and DDoS-for-hire sites are on Cloudflare. It takes serious talent (not morals) to attack humanity at scale.


> sites are on Cloudflare

And robbers can hire cars, buy battery angle grinders, and charge the batteries from the electricity network then drive on roads to your house.

Are Cloudflare supposed to be the police?

Does the UN provide a registry list of criminal domains that should not be livened?


Doesn't even matter who CF is hosting - the fact they're sending all our HTTP requests to the NSA should be enough reason already!

Capitalism With American Characteristics

Americanism

From the linked release announcement:

> Improvements to the npf(7) firewall, including layer 2 and user/group filtering

That's a valuable, useful feature

> New MICROVM kernel for x86... it can boot in about 10 ms

That could open some doors, nice

There are some good hardware improvements too.



i really want to use one on my Linode, wondering if is it possible

Don't bother with cookies at all unless they serve the interests of the user. And in that rare case, only do a cookie banner if required by law, and here's how to do it: just pretend it's "fine print." Make it functionally invisible, but good enough to get away with it. Nobody will complain about your cookie banner not being annoying enough.


The EU cookie directive, at least, does _not_ require notification if the cookies are functionally necessary.


Among other changes 10.4 adds post-quantum keys (composite ML-DSA 44 and Ed25519), not enabled by default.

When pq key agreement was added in 2019, it took almost 3 years for it to become enabled by default. This isn't criticism, just an observation. I don't have a pressing need for pq sigs. Always happy for new OpenSSH releases though!


> Among other changes 10.4 adds post-quantum keys (composite ML-DSA 44 and Ed25519), not enabled by default.

The draft was only published a few months ago:

* https://datatracker.ietf.org/doc/draft-miller-sshm-mldsa44-e...

The draft is a 'personal document', so not associated with the IETF/WG.


I recently added ml-dsa-44 to solokeys, both piv and fido2. To my understanding ssh+fido2 doesn’t support pq yet, but if anybody’s reading and knows how to make it happen, I’d be really interested.


> It's always the most insufferable people that make the biggest hullabaloo about a project they have nothing to do with and have never contributed to.

Agreed, and similarly, as a hobbyist programmer who loves Rust and Go, I've always felt that the people who command others to "rewrite it in xyz" are not themselves developers, they're "ideas people." There's a mass of these people whose main interactions with the world are through the dramatic forcing of their correct opinions.

> I run a smallish project with ~1k stars and I've stopped maintaining it last year because people feel like they're absolutely owed features or bug-fixes or whatever.

That's a bummer and it's something I'm fearful of. I post some code on my website, not on a github type site, and don't interact with people about it. It's nice and plenty of people do it. Is that something you'd consider?


Will Prowse has a very active, high quality Youtube channel about DIY solar where he talks about all things solar: generation, safety, cabling, inverters, batteries and more.


It's been a while now but once out of curiousity I tested the text to speech functionality (with my eyes closed) on an iPhone and another device (a laptop maybe?), and found iOS to be more advanced but still lacking. I don't know much about this but it's nice to see improvements. GrapheneOS seems to be a high value project in terms of dollars-to-output.


Yeah I've never regretted a Monero donation to them.

They accept more than 11 different payment methods[1] for donations and pay most of their devs in Monero.

[1] https://grapheneos.org/donate


I'd like to donate with Monero, despite my misgivings about the privacy guarantees of RingCT, because I support the spirit of both projects. but I don't want to raise a red flag to my banking institutions or government. what's the least sketchy-looking way to acquire Monero to donate to projects like this?


Least sketchy? Haveno[2] is one of the exchanges that the getmonero.org site recommends. However, the platform with the most "institutional support" (if that's what you meant by least sketchy) that allows you to buy XMR is probably Kraken[2], but IIRC they have KYC that takes a few days before you can buy.

[1]: https://haveno.exchange/

[2]: https://www.kraken.com/


I have never purchased Monero anonymously, I just buy it straight from fiat on Kraken.

What I do:

Fiat-->Kraken-->Monero-->Self-custody Monero Wallet

If you don't want anyone to know you purchased Monero(which is not necessary for most people because once you have the Monero, it's untraceable and all anyone can know is that you bought Monero, similar to how anyone can know you have cash once you withdraw from the ATM, but it's untraceable) then the easiest way would be to buy a different crypto (that you are okay with bank/govt knowing you bought) and then swapping it to Monero.

Now, I don't know the extent to which you would be passively traced if you bought a traceable crypto like Bitcoin on Kraken, withdrew to CakeWallet and swapped on Trocador. It would depend on if the instant exchange on Trocador shares info with Kraken or they both use the same Chainalysis company.

What you could do to break the link is buy ZCash on a CEX like Kraken, withdraw to CakeWallet, shield it(I think it's automatically shielded, but Ive never used ZCash), and then swap on Trocador for Monero.

The idea here is that ZCash is more friendly to govt so they still know you bought ZCash, but after you bought it, it vanishes from their analysis.

Haveno/Retoswap is great, but I would not encourage it for your first time obtaining Monero because it is not easy for beginners and can be complicated. Also there was an exploit recently. I do think long-term it will be awesome.

> despite my misgivings about the privacy guarantees of RingCT

Yeah well fortunately we are upgrading to FCMP++[1]. Also, a lot of Chainalysis's tracing from this leaked video[2], highly recommend you watch, was based on malicious nodes. They implemented an IP blacklist for malicious nodes, but you can also use Tor for more protection. The best thing for would be to run your own node.

I have a node I host and if you contact me I can give you the URL–it's really fast.

I've given info about buying Monero in the past[3], but not your specific situation. You might find it informative.

[1] https://www.youtube.com/watch?v=jc8Kc0WogAI

[2] https://odysee.com/@tuxsudo:6/chainalysis_XMR:69

[3] https://news.ycombinator.com/item?id=47858801


>The idea here is that ZCash is more friendly to govt so they still know you bought ZCash

Not when it's shielded which is why nobody uses it that way so you might as well just directly buy the superior private currency monero.

>similar to how anyone can know you have cash once you withdraw from the ATM, but it's untraceable

Contrary to popular belief cash is very much not untraceable. Serial number tracking is a thing but probably unlikely to be used against low level targets at scale (yet).


> Not when it's shielded which is why nobody uses it that way so you might as well just directly buy the superior private currency monero.

The person I replied to asked how to buy it without "raise a red flag to my banking institutions or government". I don't think buying Monero would raise a red flag and I would absolutely recommend buying it directly. Unfortunately, it's delisted in many countries so the only option is to buy a different crypto and swap it. For most people Litecoin is fine for that, but if you wanted to prevent anyone from knowing you bought XMR, than I think ZCash is a good choice.

If you swap from a transparent coin to Monero and the exchange that you swapped on shares data, than they could know that you bought Monero. If you use shielded ZCash, I assume that link is broken and all they know is that you shieled your ZCash.

Really, I don't think they have much of a problem with buying XMR as much as depositing and exchanging back to fiat.

>Contrary to popular belief cash is very much not untraceable. Serial number tracking is a thing but probably unlikely to be used against low level targets at scale (yet).

Likely similar with Monero right now. Highly resistant to mass surveillance, but must be used with good OPSEC to remain anonymous against targeted attacks.

As we saw from the leaked Chainalysis video, targeted attacks on Monero users have been done, although it's likely due to the malicious nodes. FCMP++ will greatly mitigate the attack and Monero will gain back footing equal to shielded ZCash for sender privacy.


Even if you don’t value this particular function and even if it’s not as good as Google or Apple, I think it’s important to have viable free alternatives so if Google and Apple rapidly become (significantly more) actively hostile there are viable alternatives.


TBF my only problem with GoS is that Google is actually hostile (as in the seemingly targeted way), that some institutions (like certain banks) are actively hostile, so both of these things create friction or issues for me, and my only personal issue is that they could use someone less abrasive to communicate (I was on the receiving end of someone who could be described as illegitimate child of Linus Torvalds, Leonard Poettering and a lesser basilisk in terms of politeness in response to me asking a normal user question on the discussion forum. Grim)

So, would recommend in general.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: