<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: Sae5waip</title><link>https://news.ycombinator.com/user?id=Sae5waip</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 24 Apr 2026 21:15:50 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=Sae5waip" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by Sae5waip in "[dead]"]]></title><description><![CDATA[
<p>Or not.</p>
]]></description><pubDate>Tue, 29 Jul 2014 18:17:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=8103885</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=8103885</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=8103885</guid></item><item><title><![CDATA[New comment by Sae5waip in "Scientists have developed a material so dark that it can't be seen"]]></title><description><![CDATA[
<p>0, in a suitable color space.</p>
]]></description><pubDate>Mon, 14 Jul 2014 13:55:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=8030900</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=8030900</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=8030900</guid></item><item><title><![CDATA[New comment by Sae5waip in "EA is File Snooping with the Origin Client"]]></title><description><![CDATA[
<p>> If this is what EA is doing then they had better have a really good explanation.<p>Or?</p>
]]></description><pubDate>Sun, 13 Jul 2014 14:58:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=8027491</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=8027491</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=8027491</guid></item><item><title><![CDATA[New comment by Sae5waip in "What will it take to get people using PGP for email?"]]></title><description><![CDATA[
<p>The problem with S/MIME is that it is strictly hierarchical. That already hasn't worked well for TLS.<p>The aim of email encryption is in a large part to prevent government-level parties from reading the emails. It doesn't really make sense to then go back to a system controlled by the very same parties.<p>OpenPGPs web-of-trust model seems more appropriate.<p>But both approaches share a significant number of problems, so...</p>
]]></description><pubDate>Sun, 08 Jun 2014 15:54:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=7864980</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7864980</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7864980</guid></item><item><title><![CDATA[New comment by Sae5waip in "What will it take to get people using PGP for email?"]]></title><description><![CDATA[
<p>Here are some problems, from the top of my head, in no particular order:<p><pre><code>  - Subjects can't be encrypted.
  - Encrypted mailing lists are complicated. Do you reencrypt in the middle?
    What software do you use? The mailing list manager you use right now probably doesn't support it.
  - Enigmail still doesn't support storing e-mails decrypted*. As a consequence, full-text search doesn't work.
  - There's also S/MIME.
  - Theres no software to manage public/private keys enterprise-wide.
  - Legitimate server-side email retention requirements for enterprises
  - Many people are quite alright with "most other people won't be able my email; maybe governments can".
  - Most emails quite simply aren't that important.
  - How do you deal with lost keys?
  - Webmailers
  - Often, as a sender at a company, you can not afford to inconvenience contacts.
  - No easy way to synchronize keyrings.
  - Server side spam filtering not possible
  - Out-of-office auto-forwarding
  - The other side uses gmail.
  - Your mother keeps asking why you aren't on Whatsapp.
  - The "metadata" (who mail whom? when? how long are the emails?) is quite telling.
</code></pre>
Please solve all of these.<p>Sorry for the unreadable list. Thank pg for the shitty markup format.</p>
]]></description><pubDate>Sun, 08 Jun 2014 15:40:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=7864939</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7864939</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7864939</guid></item><item><title><![CDATA[New comment by Sae5waip in "Inside the FBI's Fight Against Chinese Cyber-Espionage"]]></title><description><![CDATA[
<p>As a German, I feel very much the same.</p>
]]></description><pubDate>Mon, 02 Jun 2014 10:56:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=7832808</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7832808</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7832808</guid></item><item><title><![CDATA[New comment by Sae5waip in "What if Ansible used XML for configuration management?"]]></title><description><![CDATA[
<p>Because modern configuration management tools like Ansible (or Puppet, or Salt, or whatever) allow you to do more things more easily.<p>Also, because Bash is a particularly horrible language. I have a lot of experience writing bash scripts, and I hate bash.</p>
]]></description><pubDate>Mon, 02 Jun 2014 10:46:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=7832777</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7832777</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7832777</guid></item><item><title><![CDATA[New comment by Sae5waip in "Show HN: Where Adblock+ injects 20K CSS rules, HTTPSB injects one"]]></title><description><![CDATA[
<p>HN is a YC marketing tool, it pays for itself quite easily.</p>
]]></description><pubDate>Mon, 19 May 2014 11:31:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=7766914</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7766914</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7766914</guid></item><item><title><![CDATA[New comment by Sae5waip in "How the FBI Cracked a Chinese Spy Ring"]]></title><description><![CDATA[
<p>The article has nothing to do with Snowden. At all.</p>
]]></description><pubDate>Fri, 16 May 2014 23:48:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=7758594</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7758594</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7758594</guid></item><item><title><![CDATA[New comment by Sae5waip in "SSH Kung Fu "]]></title><description><![CDATA[
<p>Yes, but it's easier to teach admins to never use "PermitRootLogin yes" "because it's bad for security" than to teach them to never use weak passwords.</p>
]]></description><pubDate>Fri, 02 May 2014 15:23:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=7686219</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7686219</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7686219</guid></item><item><title><![CDATA[New comment by Sae5waip in "SSH Kung Fu "]]></title><description><![CDATA[
<p>Automated 0-day attack: fair point.<p>Though direct remote code execution is probably much, much more likely than authentication bypass.</p>
]]></description><pubDate>Fri, 02 May 2014 15:18:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=7686185</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7686185</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7686185</guid></item><item><title><![CDATA[New comment by Sae5waip in "SSH Kung Fu "]]></title><description><![CDATA[
<p>@Passwordless sudo: Because then you have effectively made your user root, and compromising your user account is enough to get root access immediately. If you do that, then why have a seperate user at all?[3]<p>@Partitions: Seperating /home and / prevents normal users from filling up /. (And if you put both on LVM, you can grow them as needed.) Yes, I've only had this on some of the servers I've run.<p>@Impractical: it's one additional command for something I do quite often[4], and I still don't see the benefit (reminder: I fully agree with never using "PermitRootLogin yes").<p>[3] Granted, it does provide some context seperation in the sense that if you want to perform an administrative task, you have to explicitly use sudo. But it doesn't increase security, and it offers no advantage over "direct root access + normal user account".<p>[4] Not just scp, but also things like "less /var/log/messages" or "git clone root@host:/etc".<p>And again: what does "PermitRootLogin no" gain you over "without-password"? Why restrict it for no additional benefit?</p>
]]></description><pubDate>Fri, 02 May 2014 12:11:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=7685177</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7685177</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7685177</guid></item><item><title><![CDATA[New comment by Sae5waip in "SSH Kung Fu "]]></title><description><![CDATA[
<p>tl;dr: "disallow root login entirely, everything else is bad" is cargo culting.<p>I said "impractical", not "impossible". Of course I can use sudo. But it's more work. I require root access a lot. It adds up quickly.[2]<p>And I hate typing passwords/passphrases. In fact, many of my passwords I can't remember. I've got an SSH agent for that, which reduces passphrase entry to yes/no (tab-space/space, actually).[1]<p>Also, I prefer my normal user account not to be a sudoer at all.<p>Besides, please consider that disallowing root access actually only gets you protection against root password guessing anyway. The "stolen key + passphrase" scenario in a sibling subthread is so absurd I felt the urge to bang my head against my desk. Sudo won't help you there either.<p>[1] Now please don't suggest "passwordless sudo".<p>[2] And there is another inelegance: /home is usually on a different partition than /, so your way will involve an additional copy. If /home is even large enough to fit that file.</p>
]]></description><pubDate>Thu, 01 May 2014 18:34:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=7681792</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7681792</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7681792</guid></item><item><title><![CDATA[New comment by Sae5waip in "SSH Kung Fu "]]></title><description><![CDATA[
<p>Did you ever stop and think about this or are you just repeating something you read on "Hacker""news"?<p>Getting by /without/ direct SSH root access is often impractical (think about scp), and without-password is a secure way to have it.<p>Also, the more people know about "without-password", the less people will set PermitRootLogin to "yes".</p>
]]></description><pubDate>Mon, 28 Apr 2014 10:36:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=7659114</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7659114</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7659114</guid></item><item><title><![CDATA[New comment by Sae5waip in "SSH Kung Fu "]]></title><description><![CDATA[
<p>Because then root login would be disabled entirely. With "without-password" SSH-key based login is still possible (and no, that's not much of a security risk).</p>
]]></description><pubDate>Mon, 28 Apr 2014 10:30:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=7659102</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7659102</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7659102</guid></item><item><title><![CDATA[New comment by Sae5waip in "Hack Rifle"]]></title><description><![CDATA[
<p>Electrically powered multicopters can carry DSLRs quite easily. If it's supposed to carry expensive equipment, you'll want to use a hexa- or octocopter though.<p>Of course multicopter flight times, especially with payloads, are problematic.</p>
]]></description><pubDate>Sun, 20 Apr 2014 19:59:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=7618271</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7618271</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7618271</guid></item><item><title><![CDATA[New comment by Sae5waip in "Could folks please help me get DigitalOcean onto wikipedia? (deleted thrice)"]]></title><description><![CDATA[
<p>Wikipedia is an encyclopedia, not a company index.</p>
]]></description><pubDate>Fri, 18 Apr 2014 18:28:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=7610530</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7610530</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7610530</guid></item><item><title><![CDATA[New comment by Sae5waip in "Tptacek's Review of "Practical Cryptography With Go""]]></title><description><![CDATA[
<p>I don't. So is mine, but resizing it for each individual website is unnecessary work. And some websites have a legitimate need for a wider format, so you can't even say "all websites should be like this".</p>
]]></description><pubDate>Wed, 16 Apr 2014 11:23:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=7597099</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7597099</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7597099</guid></item><item><title><![CDATA[New comment by Sae5waip in "A French labor agreement bans work emails after 6 PM"]]></title><description><![CDATA[
<p>Anyone want to host their mission critical project with a team so small that individual employees have to be on call 24/7?<p>If the company requires more than what can be done in a 40-hour work week, it should hire more employees.</p>
]]></description><pubDate>Thu, 10 Apr 2014 23:01:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=7570253</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7570253</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7570253</guid></item><item><title><![CDATA[New comment by Sae5waip in "Heartbleed should bleed X.509 to death"]]></title><description><![CDATA[
<p>That's precisely why you only use <i>subkeys</i> in daily life and only use the root key for keysigning (and ideally store it safely and offline).</p>
]]></description><pubDate>Wed, 09 Apr 2014 21:06:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=7562394</link><dc:creator>Sae5waip</dc:creator><comments>https://news.ycombinator.com/item?id=7562394</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=7562394</guid></item></channel></rss>