<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: alexfoo</title><link>https://news.ycombinator.com/user?id=alexfoo</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 15 Jun 2026 12:35:27 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=alexfoo" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by alexfoo in "AI agent bankrupted their operator while trying to scan DN42"]]></title><description><![CDATA[
<p>They didn't. Sounds like they gave the robot an AWS key from an account that was already linked to a credit card.<p>The robot decided to spin up an expensive setup prior to getting access, so the setup was sitting there costing money whilst it did nothing.<p>If it had designed the setup but not spun it up until it had authorisation to join the network then it would have been much less costly an exercise.</p>
]]></description><pubDate>Fri, 12 Jun 2026 08:44:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48501538</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48501538</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48501538</guid></item><item><title><![CDATA[New comment by alexfoo in "1k Data Breaches Later, the Disclosure Lag Is Worse"]]></title><description><![CDATA[
<p>It all comes down to where the boundary for data access is implemented, and how strictly.<p>If your webapp has unfettered database access then don't be surprised if it is hacked and someone can do `select * from users` and then posts that dump somewhere.<p>The attack surface changes if your webapp can only do a REST call to pull a single user record at a time. That way you can put some auditing in, you can put rate limiting in to detect that, etc.<p>Obviously the user record REST api endpoint is still vulnerable, but it's a much smaller attack surface, easier to audit, and can be monitored a lot more closely.<p>Yes, ultimately, there will still be a set of vulnerable humans that have access to the database servers themselves and they can always walk out of the place with an SD card hidden in a Rubik's cube but there has to be an element of trust somewhere.<p>The problem is that too many people put that trust boundary way too far out into the big bad Internet. Or don't even consider it at all and just rely on the fact that other targets are more appealing.</p>
]]></description><pubDate>Mon, 08 Jun 2026 12:59:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48444802</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48444802</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48444802</guid></item><item><title><![CDATA[New comment by alexfoo in "1k Data Breaches Later, the Disclosure Lag Is Worse"]]></title><description><![CDATA[
<p>Plus addressing (or movable periods in gmail addresses, etc) is increasingly pointless for a whole host of reasons.<p>It may keep out the bottom x% of spammers/hackers but it doesn't do much for the increasingly sophisticated scams that are appearing.<p>If the bit before the + ends up in your inbox anyway then it'll just get stripped off and used. Spammers seeing this kind of thing across several breach dumps:<p>bob+trello@example.com, bob+spotify@example.com, bob+chase@example.com<p>and will leverage that to target spam at you for other sites, or just email bob@example.com as there's a good chance that'll get through.<p>Years ago I did a test with my own domain where I created who unique aliases with plus addresses, e.g. steve.smith+iawer@example.com, bob.jones+wpoqe@example.com<p>It didn't take long for emails to start arriving to steve.smith@example.com and bob.jones@example.com even though that email address had never been used anywhere ever before.<p>As others have said, you're better off just creating unique emails with `pwgen -s 16` such as wmR5pNhGI8yidU7N@example.com and storing that in your password manager alongside a similarly random password. (Yes, this is roughly what those unique email address services provide.)<p>Also many services/sites/providers simply assume the username is immutable. $DEITY forbid you might have to change your email address at some point in the future.</p>
]]></description><pubDate>Mon, 08 Jun 2026 12:50:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=48444717</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48444717</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48444717</guid></item><item><title><![CDATA[New comment by alexfoo in "1k Data Breaches Later, the Disclosure Lag Is Worse"]]></title><description><![CDATA[
<p>Can confirm it's free. I tried it based on the GP comment. There are various ways to prove it is your domain: token sent to one of a small number of email addresses like {admin,security,webmaster}@, DNS TXT record, place a small file in the root of the website, etc.<p>The only extra bits I saw for the other emails on my domain was a plus address I'd used for last.fm which had been leaked. None of the other emails (wife, kid, family, etc) appear in any breach.<p>I'm slowly moving away from using my own personal domain as it's becoming an ever increasing burden. I'm also concerned that my wife/kid will be left with something they may not have access to, or would stop working at some point, if I suddenly dropped dead.</p>
]]></description><pubDate>Mon, 08 Jun 2026 12:38:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48444581</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48444581</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48444581</guid></item><item><title><![CDATA[New comment by alexfoo in "Ask HN: What was your "oh shit" moment with GenAI?"]]></title><description><![CDATA[
<p>Someone in the house pressed the button to update the printer (Brother DCP-L3550CDW) firmware and the CSV page that was the basis for an existing Prometheus exporter (drum/toner lifespan, page counts, etc) stopped being a thing. Instead there was an HTML page with all of the information buried in various divs/etc.<p>I'd planned on writing something myself to parse the HTML and write a suitable exporter but I thought I'd give Claude a chance.<p>In a sandboxed VM I gave Claude a single static HTML file of the status page from the printer, also in the directory was the equivalent of "hello world" in Go, literally just the minimum needed to do `fmt.Printf("OK\n")`. The directory was called `brother-exporter`. That was it. No other instructions or information. I hadn't told it what it needed to write. I hadn't said what it should do. I hand't told it what language it was supposed to use.<p>Just by doing a `/init` in that directory Claude decided that it needed to write a Prometheus exporter in Go that would fetch and parse the HTML file from a printer (defaulting to 192.168.1.1) and then present the associated metrics in a way that they could be scraped by Prometheus.<p>It did this flawlessly in about 10 minutes.<p>I could have done it in several hours but this was definitely an "oh shit" moment for me. I think the biggest thing was the fact that it guess/assumed so much (correctly) from so little information in the beginning.</p>
]]></description><pubDate>Fri, 05 Jun 2026 23:03:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=48419480</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48419480</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48419480</guid></item><item><title><![CDATA[New comment by alexfoo in "Meta workers can opt out of being tracked at work up to 30 min"]]></title><description><![CDATA[
<p>Dave Eggers' novel _The Circle_ (2013) is looking more and more prophetic every day.<p><a href="https://en.wikipedia.org/wiki/The_Circle_(Eggers_novel)" rel="nofollow">https://en.wikipedia.org/wiki/The_Circle_(Eggers_novel)</a></p>
]]></description><pubDate>Wed, 03 Jun 2026 13:45:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=48384008</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48384008</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48384008</guid></item><item><title><![CDATA[New comment by alexfoo in "10g Upgrade"]]></title><description><![CDATA[
<p>For my own 10G homelab network I jumped the gun and got a couple of Intel X540-T1 cards for my two servers and balked at the cost of the RJ45-SFP+ transceivers (Unifi's version is ~USD60). (I'm sure there are cheaper options for the "not hot" flavour transceivers but I didn't want to have to gamble again.)<p>In the end I just replaced each X540-T1 with a X520-DA2 which are pretty much the same price on eBay (under USD20) and then I can just use a DAC that's a fraction of the cost of the RJ45-SFP+ transceivers.</p>
]]></description><pubDate>Tue, 02 Jun 2026 14:21:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=48370653</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48370653</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48370653</guid></item><item><title><![CDATA[New comment by alexfoo in "Adafruit Receives Demand Letter from Fenwick Legal Counsel on Behalf of Flux.ai"]]></title><description><![CDATA[
<p>Indeed, however:<p><pre><code>    10 x 0.1 = 1</code></pre></p>
]]></description><pubDate>Tue, 02 Jun 2026 11:35:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48368869</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48368869</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48368869</guid></item><item><title><![CDATA[New comment by alexfoo in "The newest Instagram “exploit” is the goofiest I've seen"]]></title><description><![CDATA[
<p>Some companies are purposely obtuse about it.<p>My wife is trying to sort something with a famous Irish airline who are well known for messing people around. She has LPA/POA for her mother but rather than the airline accepting the VCode (this is the UK) the airline are requesting to see the original POA certificate which is just ridiculous. They seem to be moving a little quicker now there is solicitor involved.<p>Given how much back and forth there has been it's probably cost the airline more than just refunding the amount at the first request. We'll keep going to prove a point.</p>
]]></description><pubDate>Tue, 02 Jun 2026 07:45:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=48367220</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48367220</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48367220</guid></item><item><title><![CDATA[New comment by alexfoo in "What Is a Direct Attach Copper (DAC) Cable? (2021)"]]></title><description><![CDATA[
<p><a href="https://communityfibre.co.uk/fibre-deals" rel="nofollow">https://communityfibre.co.uk/fibre-deals</a> for reference<p>[EDIT] The asymmetric supplier is BT via Openreach. Google something like "BT Fibre 500".</p>
]]></description><pubDate>Tue, 02 Jun 2026 07:31:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48367136</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48367136</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48367136</guid></item><item><title><![CDATA[New comment by alexfoo in "What Is a Direct Attach Copper (DAC) Cable? (2021)"]]></title><description><![CDATA[
<p>> Going for a cup of coffee means physical walk. Detaching from focussed mode means your mind gets in diffused mode. This is where/when creativity ensues.<p>Sure, but I want to choose when I do it, not have it forced upon me.<p>> 75 mbit up is pretty good compared to DSL (I bet it is cable)<p>It is FTTP not DSL or cable. BT Fibre 500 in the UK. Almost all of the deals through the legacy/monopoly provider (BT/Openreach) are asymmetric like this.<p>The 2500/2500 at the new property is a different provider that has their own network and so isn't tied into reselling Openreach's GPON infra.</p>
]]></description><pubDate>Thu, 28 May 2026 17:12:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=48312113</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48312113</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48312113</guid></item><item><title><![CDATA[New comment by alexfoo in "I analysed 20 years of my chats"]]></title><description><![CDATA[
<p>The "Sasha" section brought back a load of memories from my childhood. As an Alex growing up in Western Europe with no connections to anything East it was just my Russophile father that used to call me Sandy or Sasha some of the time.</p>
]]></description><pubDate>Thu, 28 May 2026 08:59:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=48306445</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48306445</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48306445</guid></item><item><title><![CDATA[New comment by alexfoo in "What Is a Direct Attach Copper (DAC) Cable"]]></title><description><![CDATA[
<p>Edwardian houses in the UK rarely have that level of access. No basement at all and I can't lift the carpets and floorboards to get to where I might be able to pass things through/around. No AC ducts. No coax to be able to use MoCA either.<p>But, yes, that video is exactly the kind of thing I had in mind for the bend insensitive fibre.<p>It all depends how I set things up (and I can't tell that until I've had more access to the property). The ONT and the rack with the USW-Aggregation switch are 10 yards apart, in terms of absolute distance, but probably 20 yards if you follow the walls/skirting-boards/etc.<p>The FTTP is presented as 2.5GbE Ethernet (apparently) so I can either:<p>a) put my Unifi Express 7 next to the ONT and then need a fibre run (something like <a href="https://uk.store.ui.com/uk/en/category/accessories-modules-fiber/collections/accessories-pro-direct-attach-cables/products/10-gbps-active-optical-cable?variant=uacc-aoc-sfp10-20m" rel="nofollow">https://uk.store.ui.com/uk/en/category/accessories-modules-f...</a>) from the SFP+ port on the Express 7 to the USW-Aggregation in the rack.<p>However this will be sub-optimal in terms of Wifi and I'll probably need extra APs to cover all three floors and out into the back yard.<p>b) put my Unifi Express 7 in the hallway in the middle of the house (which should give me full Wifi coverage with no extra APs). This would mean a short (2m) DAC to connect it to the USW-Aggregation nearby, and I can use a 20m long flat/flexible Cat-6 Ethernet cable to go between the ONT and the Unifi Express 7.</p>
]]></description><pubDate>Wed, 27 May 2026 16:32:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48296716</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48296716</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48296716</guid></item><item><title><![CDATA[New comment by alexfoo in "What Is a Direct Attach Copper (DAC) Cable? (2021)"]]></title><description><![CDATA[
<p>I had a big debate with myself whether to go Mikrotik or Unifi. Being EU based I really wanted to go Mikrotik but ended up with Unifi as I'd had more experience of it when helping out friends/neighbours.<p>Maybe my "last house" (i.e. the one we'll get to see us through to retirement and beyond) will be Mikrotik based. By then I'll probably want as little computing stuff as possible and will just sit in a comfy chair doing crosswords and sudoku with a pencil.</p>
]]></description><pubDate>Wed, 27 May 2026 13:49:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=48294362</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48294362</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48294362</guid></item><item><title><![CDATA[New comment by alexfoo in "What Is a Direct Attach Copper (DAC) Cable? (2021)"]]></title><description><![CDATA[
<p>The limiting factor for me is that I'm renting so I can't put my own cabling in to the property. And with the new place there's no existing cabling, nor any conduits to run anything in, and chasing things into the walls/etc is going to be prohibited by the landlord or just too expensive if I'm only in this place for a year or two.<p>The spools of bend insensitive fibre are pretty cheap and very discreet so I'll probably have a couple of those running along skirting boards/etc in order to connect disparate areas of the house. (The ONT is ~15m away from where the majority of the equipment will live, that's the main bit I have to bridge.)</p>
]]></description><pubDate>Wed, 27 May 2026 13:38:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48294190</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48294190</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48294190</guid></item><item><title><![CDATA[New comment by alexfoo in "What Is a Direct Attach Copper (DAC) Cable? (2021)"]]></title><description><![CDATA[
<p>True, I don't really feel limited by my existing 500Mbps down, but knowing I'll be having 2500Mbps up/down soon means I want to have the infra to handle it.<p>Basing things on 2.5GbE would certainly have been cheaper but some things don't support it (they either do 1GbE or 10G SFP+) so settling on 10G where possible made more sense to me. My future ISP also has a 5Gbps up/down option, but even I can't justify that right now.<p>My wife and kid just want their phones/laptops to work, and to be able to stream stuff to watch, they don't care about the underlying speed.<p>Having a faster network may make some of my work related things run a bit quicker. A few times a day I'll need to pull something big down (either an ISO or a bunch of docker images) and that can take up to 2 minutes with 500Mbps down. Having those take a fifth of that time will make it seem less of a  roadblock to doing work. 2 minutes meant I went and got a cup of coffee and often got more distracted, 30 seconds should keep me at my desk and focused on what I was doing. That's not a big enough reason to justify it on its own obviously.<p>I also want to do offsite backups with/for various family members, so something better than 75Mbps up is going to be a huge boost. Getting 1Gbps+ out will be huge (assuming whatever is at the other end can support that).<p>I don't do any kind of data hoarding, I think I've got something under 4TB of data that I actually care about, and most of that are family photos/videos.<p>Deep down it's mostly because I'm a networking geek so it's fun to play with some new kit and make blinkenlights.</p>
]]></description><pubDate>Wed, 27 May 2026 13:31:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=48294083</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48294083</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48294083</guid></item><item><title><![CDATA[New comment by alexfoo in "What Is a Direct Attach Copper (DAC) Cable?"]]></title><description><![CDATA[
<p>Ha. I meant the rest of the equipment (USW-Aggregation, Unifi Pro Max 16, UNAS Pro, Unifi Express 7) was somewhere around half retail price.<p>I think I paid ~$15 for each X520-DA2 including postage.</p>
]]></description><pubDate>Wed, 27 May 2026 13:17:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=48293861</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48293861</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48293861</guid></item><item><title><![CDATA[New comment by alexfoo in "What Is a Direct Attach Copper (DAC) Cable"]]></title><description><![CDATA[
<p>I'm only planning on using one of the SFP+ ports on each of the cards, the dual port cards were just more common and cheaper on eBay.<p>The specs say they require PCIe v2.1 x8 lane.<p>My Proxmox server is quite old and has a Gigabyte GA-X79-UP4 mobo and has loads of spare PCI slots. One slot is taken up by a generic graphics card as the Mobo has no on-board graphics. (I think I went for this mobo because of the number of SATA ports, but it was over 10 years ago so not entirely sure.)<p>My general Linux server is newer and has an ASUS Prime H610M-A D4 mobo. Only two PCI slots (not used at the moment) and so the Intel X540-DA2 will use up the PCIe 4.0 x16 slot leaving just a PCIe 3.0 x1 slot. But that's fine as this machine is just a CPU (i7-13700), 64GB RAM and a 2TB NVMe. Sticking a good graphics card in it for GPU related fun had been on my list for years but I never got around to it, now the prices are just insane so I'll ignore that for now or something second hand falls into my lap.</p>
]]></description><pubDate>Wed, 27 May 2026 13:14:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=48293821</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48293821</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48293821</guid></item><item><title><![CDATA[New comment by alexfoo in "What Is a Direct Attach Copper (DAC) Cable? (2021)"]]></title><description><![CDATA[
<p>I'm waiting for 3 DACs and a few other bits to arrive today to move closer to 10G networking at home. Moving house soon and the new place will have 2.5Gbps FTTP (both up and down) so I wanted to be prepared for that. Given my existing broadband is only 500/75Mbps FTTP I was fine with a 1GbE internal network and Wifi-6 meshing. I could have planned to move to 2.5GbE but it may have been a bottleneck at some point, so may as well push straight on to 10G.<p>I have a USW-Aggregation with 8 SFP+ ports arriving today too. Just have to install Intel X520-DA2 cards in two of my servers (Proxmox host and a general Linux server), and the NAS also has a 10G SFP+ port, and then connect it all up.<p>Most of it second hand from eBay for half the usual retail price.</p>
]]></description><pubDate>Wed, 27 May 2026 11:54:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=48292886</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48292886</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48292886</guid></item><item><title><![CDATA[New comment by alexfoo in "Dropbox CEO Drew Houston to step down"]]></title><description><![CDATA[
<p>This is almost as good as the classic HN "Putnam" comment: <a href="https://news.ycombinator.com/item?id=35079">https://news.ycombinator.com/item?id=35079</a><p>(Hint: No, he's not replying with AI. Two hyphens are not an em dash. Even then there's no hint of it being an AI response. Also the person is actually the CEO of Dropbox, the very person this thread is all about. You only have to click his username to see his posting history to see he's not an AI bot posting endlessly, his last posts (prior to today) were in 2024.)</p>
]]></description><pubDate>Tue, 26 May 2026 22:47:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=48287054</link><dc:creator>alexfoo</dc:creator><comments>https://news.ycombinator.com/item?id=48287054</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48287054</guid></item></channel></rss>