<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: dchest</title><link>https://news.ycombinator.com/user?id=dchest</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 01 Sep 2026 20:54:14 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=dchest" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by dchest in "“I just chose words carefully”"]]></title><description><![CDATA[
<p>Indeed:<p><a href="https://hart.pglaf.org/" rel="nofollow">https://hart.pglaf.org/</a><p>From Wikipedia:<p>"Michael Hart's email messages and blog posts had equal line length paragraphs in monospaced font: he chose the wording in such a way that each line had the same number of characters."</p>
]]></description><pubDate>Mon, 31 Aug 2026 07:18:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=49506619</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=49506619</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49506619</guid></item><item><title><![CDATA[New comment by dchest in "Firefox 157 will include JPEG XL by default on all platforms"]]></title><description><![CDATA[
<p>It probably used pixel-by-pixel conversion (decode input format -> encode output format), which is lossy, not the libjxl native way to convert JPEG (it needs to know about the original JPEG data, not the raw image data).</p>
]]></description><pubDate>Tue, 25 Aug 2026 21:17:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=49440775</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=49440775</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49440775</guid></item><item><title><![CDATA[New comment by dchest in "Run OpenBSD on DigitalOcean for $4/month"]]></title><description><![CDATA[
<p>A warning about openbsdhandbook[.]com - this website has completely incorrect information for some things. Like hallucinated, even though I think it was created before LLMs.</p>
]]></description><pubDate>Tue, 25 Aug 2026 19:36:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=49439465</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=49439465</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49439465</guid></item><item><title><![CDATA[New comment by dchest in "People of ACM – Russ Cox"]]></title><description><![CDATA[
<p>I recently learned that Russ also wrote software for The On-Line Encyclopedia of Integer Sequences (<a href="https://oeis.org" rel="nofollow">https://oeis.org</a>) and is the president of the OEIS Foundation.</p>
]]></description><pubDate>Fri, 21 Aug 2026 19:24:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=49392760</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=49392760</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49392760</guid></item><item><title><![CDATA[New comment by dchest in "Windows brings out the Rorschach test in everyone (2003)"]]></title><description><![CDATA[
<p>The original: <a href="https://www.youtube.com/shorts/uaQyaBRaM9w" rel="nofollow">https://www.youtube.com/shorts/uaQyaBRaM9w</a></p>
]]></description><pubDate>Thu, 20 Aug 2026 07:21:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=49371471</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=49371471</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49371471</guid></item><item><title><![CDATA[New comment by dchest in "Tell HN: Cloudflare silently injects its analytics when you switch nameservers"]]></title><description><![CDATA[
<p>> measure and improve your website speed<p>inserts 31KB JavaScript into tiny HTML pages.</p>
]]></description><pubDate>Mon, 17 Aug 2026 03:48:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=49326380</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=49326380</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49326380</guid></item><item><title><![CDATA[New comment by dchest in "Tell HN: Cloudflare silently injects its analytics when you switch nameservers"]]></title><description><![CDATA[
<p>Indeed, <a href="https://blog.cloudflare.com/the-rum-diaries-enabling-web-analytics-by-default/" rel="nofollow">https://blog.cloudflare.com/the-rum-diaries-enabling-web-ana...</a></p>
]]></description><pubDate>Sun, 16 Aug 2026 19:32:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=49322910</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=49322910</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49322910</guid></item><item><title><![CDATA[New comment by dchest in "Xorshift Generators"]]></title><description><![CDATA[
<p>Lua 5.4 and 5.5 use xoshiro256**: <a href="https://www.lua.org/manual/5.4/manual.html#pdf-math.random" rel="nofollow">https://www.lua.org/manual/5.4/manual.html#pdf-math.random</a></p>
]]></description><pubDate>Sat, 15 Aug 2026 22:51:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=49315031</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=49315031</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49315031</guid></item><item><title><![CDATA[New comment by dchest in "Single log line is 49KB+ (ext4) / 110KB+ (btrfs) of systemd-journald disk writes"]]></title><description><![CDATA[
<p>Yes, WAL by definition means it writes the data at least twice.</p>
]]></description><pubDate>Fri, 14 Aug 2026 05:07:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=49294923</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=49294923</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49294923</guid></item><item><title><![CDATA[New comment by dchest in "Single log line is 49KB+ (ext4) / 110KB+ (btrfs) of systemd-journald disk writes"]]></title><description><![CDATA[
<p>Write-Ahead Log for... logs?<p>WAL means it will write the same data at least twice. Similar issue, but even worse, with LevelDB -- it will just delay the inevitable huge rewrites for later. Funny to hear those proposals in the write amplification thread.<p>I believe journald log rotation is basically: close file - open a new one. How is it not completely different?</p>
]]></description><pubDate>Fri, 14 Aug 2026 04:29:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=49294766</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=49294766</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49294766</guid></item><item><title><![CDATA[New comment by dchest in "FreeBSD: Missing Mac validation in wg(4) packet decryption"]]></title><description><![CDATA[
<p>Looks like it was caused by result confusion: crypto_dispatch returns errors in two different ways:<p><a href="https://man.freebsd.org/cgi/man.cgi?query=crypto_dispatch&apropos=0&sektion=0&manpath=FreeBSD+15.1-RELEASE+and+Ports.quarterly&format=html" rel="nofollow">https://man.freebsd.org/cgi/man.cgi?query=crypto_dispatch&ap...</a><p>"crypto_dispatch() returns an error if  the  request  contained  invalid fields, or  zero  if the request was valid."<p>However, on an actual error from the crypto driver (e.g. invalid MAC), crypto_dispatch result is successful and the error is returned in crp_etype structure field.<p><a href="https://cgit.freebsd.org/src/commit/sys/dev/wg?id=34271824525e18d82c051177de265c8d8a113fb8" rel="nofollow">https://cgit.freebsd.org/src/commit/sys/dev/wg?id=3427182452...</a></p>
]]></description><pubDate>Thu, 30 Jul 2026 07:35:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=49107040</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=49107040</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49107040</guid></item><item><title><![CDATA[FreeBSD: Missing Mac validation in wg(4) packet decryption]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-26:52.if_wg.asc">https://www.freebsd.org/security/advisories/FreeBSD-SA-26:52.if_wg.asc</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49107031">https://news.ycombinator.com/item?id=49107031</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Thu, 30 Jul 2026 07:33:28 +0000</pubDate><link>https://www.freebsd.org/security/advisories/FreeBSD-SA-26:52.if_wg.asc</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=49107031</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49107031</guid></item><item><title><![CDATA[New comment by dchest in "Forth"]]></title><description><![CDATA[
<p>FORTH LOVE? IF HONK THEN</p>
]]></description><pubDate>Mon, 27 Jul 2026 21:53:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=49075964</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=49075964</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49075964</guid></item><item><title><![CDATA[New comment by dchest in "TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access"]]></title><description><![CDATA[
<p>With CGO disabled, it only reads /etc/passwd, while the glibc getpwnam(3) can query LDAP etc.</p>
]]></description><pubDate>Wed, 15 Jul 2026 16:56:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=48923781</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=48923781</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48923781</guid></item><item><title><![CDATA[New comment by dchest in "TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access"]]></title><description><![CDATA[
<p>Which uses libc via CGO or parses /etc/passwd with no CGO, which won't work for some cases.<p><a href="https://github.com/tailscale/tailscale/blob/e4144230f410204aa2f43a07a57182c751239597/util/osuser/user.go#L144-L148" rel="nofollow">https://github.com/tailscale/tailscale/blob/e4144230f410204a...</a><p><pre><code>  // userLookupGetent uses "getent" to look up users so that even with static
  // tailscaled binaries without cgo (as we distribute), we can still look up
  // PAM/NSS users which the standard library's os/user without cgo won't get
  // (because of no libc hooks). If "getent" fails, userLookupGetent falls back
  // to the standard library.</code></pre></p>
]]></description><pubDate>Wed, 15 Jul 2026 16:52:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=48923700</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=48923700</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48923700</guid></item><item><title><![CDATA[New comment by dchest in "An update on residential proxies and the scraper situation"]]></title><description><![CDATA[
<p>I did something like this using fail2ban for some time, but 1) it didn't help much due to the larger number of IPs, 2) it blocked widely used VPN services.</p>
]]></description><pubDate>Sat, 11 Jul 2026 14:22:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48872330</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=48872330</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48872330</guid></item><item><title><![CDATA[New comment by dchest in "Potential session/cache leakage between workspace instances or consumer accounts"]]></title><description><![CDATA[
<p>Can be malware? Something like <a href="https://news.ycombinator.com/item?id=48667495">https://news.ycombinator.com/item?id=48667495</a></p>
]]></description><pubDate>Sat, 04 Jul 2026 15:57:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=48786323</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=48786323</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48786323</guid></item><item><title><![CDATA[New comment by dchest in "Underarm bowling incident of 1981"]]></title><description><![CDATA[
<p><a href="https://www.youtube.com/watch?v=E_6d3JBBo4s" rel="nofollow">https://www.youtube.com/watch?v=E_6d3JBBo4s</a></p>
]]></description><pubDate>Sat, 27 Jun 2026 16:05:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48699410</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=48699410</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48699410</guid></item><item><title><![CDATA[New comment by dchest in "Stop Using JWTs"]]></title><description><![CDATA[
<p>Being able to quickly reject invalid sessions identifiers is a useful property in some cases and is normally done by authenticating stateful session tokens with a MAC using a global app key. This can be used for DoS protection if the cost of a database lookup is more than the cost of MAC, and the complexity is justified. It ensures that the random numbers a user is trying to present as their session token are the numbers generated by the server if the key is not leaked.<p>Because you're trying to bolt things on top of JWT, you're creating a worse version of that stateful authentication pattern:<p>1. You lost the statelessness of JWT by making database queries. Your claim that "you  don't need to verify against user's secret immediately" is false, as you need to do that in all cases immediately after verifying the JWT signature to get the benefits of your system (token invalidation). Sure, you reject completely invalid tokens early, but you still need the statefulness to authenticate users properly (if your goal is to be able to invalidate tokens).<p>2. In your version, getting a read-only access to the user database (leaking per-user secrets) completely destroys token invalidation, and all your authentication now depends on one key. If, in addition to that, the JWT signing key leaks, user authentication is completely destroyed and can be bypassed by the attacker, who now can sign in as any user. (A common way to leak all this is by failing to properly secure backups).<p>Compared to a stateful session system with split-tokens, where the database stores tokenId => verifier, where verifier is Hash(randomToken), and user's token is id||randomToken, read-only access to the database doesn't let the attacker authenticate as any user. If the tokens that users presents are in the form of id||randomToken||HMAC(serverKey, id||randomToken) for early rejection as above, leaking serverKey still won't allow the attacker to authenticate as any user. The attacker needs write access.<p>> Is author's brain stateless -- my bad, I thought this was not reddit<p>I didn't realize that you were the author, I thought you were a reader who was misled by this blog post. Even better: you can go and edit it, removing "stateless" everywhere! It's fun to invent various protocols, but when someone points out the errors, surely you'd want to fix them -- no shame in making mistakes if you correct them.<p>Usually, when I think of a protocol, after writing down "Benefits" (as in your blog post), I write "Drawbacks" and then try to come up with downsides and compare it with existing protocols. I'd suggest you do the same.<p>PS. Find yourself in this picture: <a href="http://cryto.net/%7Ejoepie91/blog/2016/06/19/stop-using-jwt-for-sessions-part-2-why-your-solution-doesnt-work/" rel="nofollow">http://cryto.net/%7Ejoepie91/blog/2016/06/19/stop-using-jwt-...</a></p>
]]></description><pubDate>Wed, 17 Jun 2026 07:20:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=48566932</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=48566932</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48566932</guid></item><item><title><![CDATA[New comment by dchest in "Stop Using JWTs"]]></title><description><![CDATA[
<p>WTF:<p>> Each user has a secret: Stored securely in the database.<p>> Stateless Validation: The core validation remains stateless. We only need to consult the database for the user's secret, which we'd likely do anyway for authorization checks.<p>Is "stateless" the same as "serverless" now? Is author's brain stateless?</p>
]]></description><pubDate>Tue, 16 Jun 2026 22:23:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=48563046</link><dc:creator>dchest</dc:creator><comments>https://news.ycombinator.com/item?id=48563046</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48563046</guid></item></channel></rss>