<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: 8organicbits</title><link>https://news.ycombinator.com/user?id=8organicbits</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 01 Oct 2026 08:10:04 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=8organicbits" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by 8organicbits in "When did Google get so weird?"]]></title><description><![CDATA[
<p>This is a really good time to do a head-to-head comparison of different search engines. The last time I checked Google does not provide search results above the fold, instead showing AI overview, ads, and YouTube search results. Try a different search engine to see which one is giving you the highest signal results and what other junk they put on the page. Personally I use duckduckgo with AI turned off in settings, but it's best to try the experiment for yourself.</p>
]]></description><pubDate>Sun, 27 Sep 2026 21:20:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=49870981</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49870981</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49870981</guid></item><item><title><![CDATA[Creating Client Certificates for Kubernetes Pods]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.hardill.me.uk/2026/09/24/creating-client-certificates-for-kubernetes-pods/">https://blog.hardill.me.uk/2026/09/24/creating-client-certificates-for-kubernetes-pods/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49852152">https://news.ycombinator.com/item?id=49852152</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 26 Sep 2026 01:14:30 +0000</pubDate><link>https://blog.hardill.me.uk/2026/09/24/creating-client-certificates-for-kubernetes-pods/</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49852152</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49852152</guid></item><item><title><![CDATA[New comment by 8organicbits in "Show HN: Whiteboard (YC W26) – An open-source IDE for thoughtful software design"]]></title><description><![CDATA[
<p>One concern about accuracy of the diagrams. In the example, there is a transition back to the session service labelled "wait for release" after the "no" decision. I'm not seeing that in the shown diff.<p>Looking at the code the "no" seems to relate to the context expiring, so you wouldn't want to wait more if the context already expired, you'd want to stop. Is there a reason that label exists?<p>I'm pretty wary of LLM development tools hallucinating and wasting my time, is that whats happening in the lease broker example?</p>
]]></description><pubDate>Thu, 24 Sep 2026 20:43:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=49836507</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49836507</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49836507</guid></item><item><title><![CDATA[New comment by 8organicbits in "Disney+ and Hulu raise prices by up to 13 percent after doubling profits"]]></title><description><![CDATA[
<p>The Kanopy model is fascinating. Library members get free views but there are limits as the library has to pay for those views. Our county library system has a Kanopy subscription at each library and county residents are eligible to become members at every location. Kanopy supports adding multiple library cards, so you can boost your limit.</p>
]]></description><pubDate>Thu, 24 Sep 2026 16:08:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49832718</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49832718</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49832718</guid></item><item><title><![CDATA[New comment by 8organicbits in "Measure internet censorship"]]></title><description><![CDATA[
<p>The platform is quite open, so you can build whichever tests you want. Personally I run a dockerized ooni via scheduled GitHub actions, which shows blocks impacting GitHub runners. You should be able to see logs from that here, which shows three blocked websites <a href="https://github.com/robalexdev/ooni-unattended-action/actions/runs/33824187064/job/100873202754" rel="nofollow">https://github.com/robalexdev/ooni-unattended-action/actions...</a><p>You can build your own lists and share them using ooni run: <a href="https://run.ooni.org/" rel="nofollow">https://run.ooni.org/</a></p>
]]></description><pubDate>Sun, 20 Sep 2026 18:55:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=49778812</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49778812</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49778812</guid></item><item><title><![CDATA[New comment by 8organicbits in "Measure internet censorship"]]></title><description><![CDATA[
<p>Many of the partners are country focused but the Tor Project, Citizen Lab, and Internet Society are well known to me.</p>
]]></description><pubDate>Sat, 19 Sep 2026 22:26:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=49770602</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49770602</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49770602</guid></item><item><title><![CDATA[New comment by 8organicbits in "google.com/goto: Google's anti-scraping update"]]></title><description><![CDATA[
<p>For some of that, you don't need to crawl. Wikipedia offers database dumps which you can download in one go. Lots of programming docs are managed in repos, so you can clone the repo instead. Even stackoverflow seems to have a snapshot dump (<a href="https://archive.org/details/stackexchange" rel="nofollow">https://archive.org/details/stackexchange</a>).</p>
]]></description><pubDate>Sat, 12 Sep 2026 22:42:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=49677984</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49677984</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49677984</guid></item><item><title><![CDATA[New comment by 8organicbits in "bzip3"]]></title><description><![CDATA[
<p>How did I miss zstd?<p>Here are my benchmarks for 2.3 GB of jsonl, on a laptop. Compressed size, compress time, decompress time; using defaults.<p><pre><code>    gzip  7.3%  21s  9s
    bzip2 4.6% 251s 50s
    bzip3 3.3%  82s 69s
    zstd  6.9%   2s  3s
    lzma  4.7%  51s  3s</code></pre></p>
]]></description><pubDate>Mon, 07 Sep 2026 17:05:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=49600507</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49600507</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49600507</guid></item><item><title><![CDATA[New comment by 8organicbits in "bzip3"]]></title><description><![CDATA[
<p>I was processing compressed .jsonl files recently (JSON lines format). I found that lzma gave a much better compression than gzip or bzip2, which helps for archival costs, but it's challenging to work with as software support is lacking. I do duckdb processing which supports gzip transparently. There's an extension for bzip2, but not for lzma or bzip3.<p>I ended up using gzip because it's best supported by the software I use and most likely to have support in software I adopt. But it gave the worst compression results of the options I tried. These bzip3 numbers certainly give me FOMO...</p>
]]></description><pubDate>Mon, 07 Sep 2026 15:34:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=49599558</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49599558</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49599558</guid></item><item><title><![CDATA[New comment by 8organicbits in "deSEC – Free Secure DNS"]]></title><description><![CDATA[
<p>That's a bummer.<p>It looks like they are open to adding the feature and open to outside contributions: <a href="https://github.com/desec-io/desec-stack/issues/579" rel="nofollow">https://github.com/desec-io/desec-stack/issues/579</a></p>
]]></description><pubDate>Fri, 04 Sep 2026 17:48:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=49567866</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49567866</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49567866</guid></item><item><title><![CDATA[New comment by 8organicbits in ".name Termination"]]></title><description><![CDATA[
<p>> simply permanently end all service to the concept of subdomains at all<p>That doesn't sound simple at all.</p>
]]></description><pubDate>Fri, 04 Sep 2026 15:31:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=49566107</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49566107</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49566107</guid></item><item><title><![CDATA[Hugging Face Easter Egg]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.johndcook.com/blog/2026/09/03/hugging-face-easter-egg/">https://www.johndcook.com/blog/2026/09/03/hugging-face-easter-egg/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49564922">https://news.ycombinator.com/item?id=49564922</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 04 Sep 2026 14:11:05 +0000</pubDate><link>https://www.johndcook.com/blog/2026/09/03/hugging-face-easter-egg/</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49564922</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49564922</guid></item><item><title><![CDATA[New comment by 8organicbits in ".name Termination"]]></title><description><![CDATA[
<p>I think DMARC works well because email tends to blindly trust DNS (opportunistic encryption). On the web we expect authenticated TLS, often strictly enforced (organization policy, HSTS). So it would feel weird if a website changes how it handles HTTPS cookies based on an insecure DNS record, perhaps delivered by the resolver on an untrustworthy WiFi router.<p>Specifically, if I register subdomain attack.co.uk and set up a malicious WiFi router, I trick some *.co.uk cookies to get set on co.uk and then steal them from attack.co.uk by tampering with the (proposed) SVCB record.<p>I think the signal needs to be secure, which means DNSSEC. Adding a hard requirement for DNSSEC validation in all web browsers is a huge change from where we are now.</p>
]]></description><pubDate>Fri, 04 Sep 2026 12:34:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=49563693</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49563693</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49563693</guid></item><item><title><![CDATA[New comment by 8organicbits in "P99 0 ms* autocomplete for 240M domain names"]]></title><description><![CDATA[
<p>There are limits to how accurate you can make this. Zones like .xyz renew at 18%, so you'd expect 0.2% of those domains to expire without renewal each day. The tranco list is based on a 30 day look-back and I've seen a small percent of those domains lack name servers, even for the latest list.<p>Similarly, domains can be registered since the last time you downloaded your lists. So you never have a complete or accurate list.<p>I think it's perfectly reasonable to suggest names that have recently expired or domains that could have been recently registered. The alternative requires an NS lookup.</p>
]]></description><pubDate>Mon, 31 Aug 2026 12:49:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=49509084</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49509084</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49509084</guid></item><item><title><![CDATA[New comment by 8organicbits in "Omarchy: Any User Process Can Escalate to Root"]]></title><description><![CDATA[
<p>Official docs cover those:<p><a href="https://docs.docker.com/engine/network/firewall-iptables/" rel="nofollow">https://docs.docker.com/engine/network/firewall-iptables/</a><p><a href="https://docs.docker.com/engine/install/linux-postinstall/" rel="nofollow">https://docs.docker.com/engine/install/linux-postinstall/</a></p>
]]></description><pubDate>Mon, 31 Aug 2026 00:03:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=49504138</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49504138</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49504138</guid></item><item><title><![CDATA[New comment by 8organicbits in "Select * from Internet.blogposts"]]></title><description><![CDATA[
<p>> Here's a stream of standard.site blog posts coming in over a firehose hosted in Chennai. Every single one.<p>This stream lacks any blog posts that haven't been specifically published to atproto. Conversely, I see RSS feeds for the content in the stream, like <a href="https://bsky.app/profile/did:plc:byf7jvh3yvhffackiumpddtf/rss" rel="nofollow">https://bsky.app/profile/did:plc:byf7jvh3yvhffackiumpddtf/rs...</a> (if RSS feeds exists for every profiles then I'd argue that atproto is a strict subset of RSS, but I'm not certain how that feature works). The stream may give you every blog post that was published to atproto, but that's already a small subset of long-form content on the web.<p>> Notably this is not possible with RSS,<p>The web supports blog discovery so well that people forget it exists. A simple Google search can find a very large amount of content, much available over RSS/Atom. Many web-based feed readers index the subscriptions across all their users to help with discovery. Here's the Feedland firehose, for example: <a href="https://feedland.com/?everything=true" rel="nofollow">https://feedland.com/?everything=true</a><p>I don't think its helpful to argue how complete the Google index is vs a bluesky firehose though. Most users are drowning in content and discovery is about search and filtering. There's lots of interest right now in vouching for the content of others: <a href="https://susam.net/wander/wander.js" rel="nofollow">https://susam.net/wander/wander.js</a>, <a href="https://codeberg.org/robida/human.json" rel="nofollow">https://codeberg.org/robida/human.json</a>, <a href="https://www.manton.org/2024/03/11/recommendations-and-blogrolls.html" rel="nofollow">https://www.manton.org/2024/03/11/recommendations-and-blogro...</a>, etc.</p>
]]></description><pubDate>Fri, 28 Aug 2026 18:47:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=49482768</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49482768</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49482768</guid></item><item><title><![CDATA[New comment by 8organicbits in "Select * from Internet.blogposts"]]></title><description><![CDATA[
<p>I wouldn't say the others lack that feature, they do it differently.<p><a href="https://docs.joinmastodon.org/user/moving/#move" rel="nofollow">https://docs.joinmastodon.org/user/moving/#move</a></p>
]]></description><pubDate>Fri, 28 Aug 2026 11:52:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=49477222</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49477222</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49477222</guid></item><item><title><![CDATA[New comment by 8organicbits in "Select * from Internet.blogposts"]]></title><description><![CDATA[
<p>> more ease of exploration<p>Absolutely. One good thing going for this approach is that anyone can grab the OPML export (the URL is stable) and build their own frontend, I'd love to see more.<p>Could be a fun weekend project for frontend folks.</p>
]]></description><pubDate>Fri, 28 Aug 2026 02:45:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=49473751</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49473751</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49473751</guid></item><item><title><![CDATA[New comment by 8organicbits in "Select * from Internet.blogposts"]]></title><description><![CDATA[
<p>For blog posts, I'd look to RSS instead. That's where that content is traditionally published. Instead of SELECTing from bluesky's index, you can use OPML subscription lists. There are a bunch of places that curate feed lists, so it's significantly less likely to face API death like twitter did.<p>There are multiple sites that support follower semantics over RSS. Feedland tracks subscriptions publicly, so you can see the blogs I read (<a href="https://feedland.com/?username=robalexdev" rel="nofollow">https://feedland.com/?username=robalexdev</a>), and who reads my blog (<a href="https://feedland.com/?feedurl=https%3A%2F%2Falexsci.com%2Fblog%2Frss.xml" rel="nofollow">https://feedland.com/?feedurl=https%3A%2F%2Falexsci.com%2Fbl...</a>).<p>I run another variant which collects OPML blogrolls via crawling, so you can find out who else likes your favorite blog and what else they recommend. Here's the page for  Simon Willison's blog (<a href="https://blogroll-network.alexsci.com/discover/feed-a34ee2a885866974aa1f1f41131ac7b6/" rel="nofollow">https://blogroll-network.alexsci.com/discover/feed-a34ee2a88...</a>). Thinking of RSS and blogrolls as a network feels much more resilient than blueskys Jetstream api endpoint.</p>
]]></description><pubDate>Fri, 28 Aug 2026 00:45:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=49473082</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49473082</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49473082</guid></item><item><title><![CDATA[New comment by 8organicbits in "Launching Route 53 Files"]]></title><description><![CDATA[
<p>I'll recommend dnscontrol as well, although the post is an unseasonal April fools joke, so helpful suggestions may be out of place.<p>The is-a.dev project uses dnscontrol to manage a subdomain registration service in GitHub, which is really clever. See <a href="https://github.com/is-a-dev/register" rel="nofollow">https://github.com/is-a-dev/register</a></p>
]]></description><pubDate>Thu, 27 Aug 2026 22:22:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=49472064</link><dc:creator>8organicbits</dc:creator><comments>https://news.ycombinator.com/item?id=49472064</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49472064</guid></item></channel></rss>