Hacker Newsnew | past | comments | ask | show | jobs | submit | encrypted_bird's commentslogin

> but sadly many websites have botched their password input so even with a password manager you may still need to manually copy and paste

Exactly this. I use KeePassXC and the number of sites where auto-input doesn't work even if the URL is 100% correct in the entry properties is _frustratingly_ high.


As someone who's looking into possibly getting a YubiKey 5 NFC actually, I would like to ask: if you can't export the entries, if you make a backup of the YubiKey (perhaps with the magic of buying two of them), then how would one ensure redundancy?

They accept anonymous payment? I could've sworn they require an account...

You can literally mail an envelope of cash to them and they'll credit your account. Probably the best way to remain anonymous. At worst, they'll have the zip code from where it was mailed from and potential fingerprints. But since an envelope isn't really a financial record, I doubt they would hold onto it.

Okay I think I just misunderstood. I guess I was assuming "paying for the service anonymously" meant "paying such that the person using the service is anonymous", not "anonymously paying for the service". Haha. Syntax is fun!

Just out of curiosity, what is a cold boot attack?

https://en.wikipedia.org/wiki/Cold_boot_attack

tl;dr they pull the decryption keys from your computer while it's still running, which of course it is because your mail server has to be up 24/7.


Simple solution: put your server inside of a cabinet or enclosure that immediately powers it off if opened with a hidden micro switch. Additionally, write a little udev rule to immediately power off if any new USB device is connected or Ethernet is unplugged.

So a trip-switch for the server?

How would one access it if one needed to do config changes or, really, anything the server for legitimate purposes?


ssh in and shut down first (and/or just use a properly reliable filesystem).

Mail transfer can tolerate multi-hour interruptions. Imagine the drama if it couldn't!


If you can ssh in, couldn't they ssh in?

That is fascinating! Thanks for sharing!

I let my subscription expire and my account was never locked down or emailed held for ransom. I suspect there is another piece to the story you're either neglecting to mention or don't know.

Yes, this happened 5-6 years ago, I've publicly complained before, and I paid with bitcoin. Those are the only details not included in my previous comment.

Oh see I didn't pay with bitcoin. Maybe they have a differeny policy with that? Hmm...

xz backdoor? What's that?

https://news.ycombinator.com/item?id=47166473

- the video is well worth a watch.


Thanks, I'll give it a watch! <3

> I'm a bit ashamed to have to explain this on HN.

Don't be. Like it or not, this is a site run by venture capitalists and populated most heavily by software engineers, both of which have historically been treated well by capitalism.

Although it's improved in recent years, I've noticed there's still a lot of corporate bootlickers on this site.

Yes, it saddens me too.


I think you're getting downvoted because of your slightly strong language. Well! We will know that soon, based on how this post fares! The problem I find is that some people argue on the basis of outright weird logic, while neglecting the obvious. I really can't tell if they're talking on behalf of someone else's commercial interests, or if they really believe what they say.

You're probably right about why I'm getting downvoted. But, you know, in my honest opinion, those people are just further demonstrating my point. They're probably actually paid well, or at least are afraid to badmouth the hand that feeds them.

But people need to realize that most of the population aren't treated well or paid well. Most of us don't have the luxury of being SWEs, or even white-collar workers for that matter. Most of us struggle to even put food on the table and have to scrounge week to week, let alone month to month.

So, I'm not bothered by the bootlickers downvoting me. At best, they're fooling themselves; at worst, they're class traitors.

If you ask me, the time for tactful language is long over.


> But people need to realize that most of the population aren't treated well or paid well. Most of us don't have the luxury of being SWEs, or even white-collar workers for that matter. Most of us struggle to even put food on the table and have to scrounge week to week, let alone month to month.

+1

> If you ask me, the time for tactful language is long over.

Sadly, I reached the same conclusion a while ago. Subtlety seems to have lost all value and too much is at stake to keep on appealing to everyone's sensibility.


OpenMeteo is pretty amazing too, and doesn't require an account or API key, which is nice.

I incorporated OpenMeteo into a project recently and got frustrated with their aggressive rate limiting. If in the US, weather dot gov has an excellent, free API. Or, OpenWeatherAPI which works internationally and has support for more things that weather dot gov does not. OpenWeatherAPI will also synthetically provide weather data based on their models if there is missing station data

> I incorporated OpenMeteo into a project recently and got frustrated with their aggressive rate limiting

Which one? They seem to do 600 calls / min, 5.000 calls / hour, 10.000 calls / day, 300.000 calls / month, how many times do you need to look up the weather for personal use? Fine, maybe you want 3 different locations, you can still call each of those sufficiently with those rate limits, no?


I have to sample multiple lat/lon across the world all at once

For what purpose? And multiple times per hour for each of those? Sounds like not a personal project already.

It’s for a hobbyist project and non commercial use.

Right, but less "I want to know what the weather is locally and maybe in my summer house" and more "I'm curious about sampling global weather/temperatures", right? I don't think the intention of the API is for the latter, but more for the former.

a redis geospatial index + redis distribution locks you can build a performant cache layer that is consumed by a ton of people and stay well under that rate limit.... the weather data only updates every 5 minutes too, so you can use that for your cache ttl.

Using your own weather station is another option

> I haste Flock Safety cameras.

Was this a typo? If not, what does "haste" mean in this context? (I'm not messing with you; I'm genuinely wondering.)


It was a typo. Fixed.


Apologies, but I'm having a hard time parsing your sentence.

What exactly are you saying?


The GP is using a snowclone of the original: "It couldn't have happened to a nicer guy".

For example, if your boss is very rude and disparaging, but then he gets fired, you would say, sarcastically, "It couldn't have happened to a nicer guy", implying there's some element of karma at work.

By analogy, GP is saying these tarrifs were an undeserving act of vengeance. I assume "undeserved" in the sense that it wasn't deserved by those on the receiving end.


Roger. Surely it's twisted a bit more with the kind of things Trump spews, but for instance a great leader wins a well-deserved Nobel Prize, and you say it couldn't have happened to a more deserving contender.

You say the same thing when a complete moron fails to win the same prize.

Equal fairness to all ;)


Ah.

Thank you. :)


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: