<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: drnick1</title><link>https://news.ycombinator.com/user?id=drnick1</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 27 Jul 2026 23:44:40 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=drnick1" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by drnick1 in "Bitcoin trail, Google cookies and Uber Eats orders help tie man to Steam malware"]]></title><description><![CDATA[
<p>That's nice, but a cell phone isn't a viable gaming platform for anything but very basic games. And Android, at least in its typical Googled form, has its own set of problems; it's a privacy nightmare.</p>
]]></description><pubDate>Mon, 27 Jul 2026 23:34:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=49077060</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49077060</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49077060</guid></item><item><title><![CDATA[New comment by drnick1 in "Bitcoin trail, Google cookies and Uber Eats orders help tie man to Steam malware"]]></title><description><![CDATA[
<p>I sandbox Steam itself for simplicity. My experience with Nvidia and Wayland has been good. I simply exposed /dev/nvidia*, a few networking-related files in /etc and system binaries like /usr.</p>
]]></description><pubDate>Mon, 27 Jul 2026 23:28:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=49077002</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49077002</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49077002</guid></item><item><title><![CDATA[New comment by drnick1 in "Bitcoin trail, Google cookies and Uber Eats orders help tie man to Steam malware"]]></title><description><![CDATA[
<p>Dedicated hardware is definitely the most secure option, but realistically it is even less convenient than a separate user. You can't realistically play graphically intensive games on a Deck, and separate workstations are very unaffordable at the moment.</p>
]]></description><pubDate>Mon, 27 Jul 2026 23:17:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=49076871</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49076871</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49076871</guid></item><item><title><![CDATA[New comment by drnick1 in "Bitcoin trail, Google cookies and Uber Eats orders help tie man to Steam malware"]]></title><description><![CDATA[
<p>This underscores a major issue with commercial software like Steam and games obtained therein. You cannot trust that software not to maliciously scan your device for secrets such as crypto wallets or other information. Ideally, you want to run apps like Steam, Discord, Zoom and whatever else does not come from a trusted distribution repo as a separate user. This is not always convenient however, and the compromise I adopted on my gaming PC is to bubblewrap Steam. Do not mount things like /home and devices games should not be using in the sandbox.</p>
]]></description><pubDate>Mon, 27 Jul 2026 22:56:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=49076629</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49076629</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49076629</guid></item><item><title><![CDATA[New comment by drnick1 in "Securing Services with Rootless Containers"]]></title><description><![CDATA[
<p>Rootless is definitely the way to go. You can forward ports manually on the host if you really need to use privileged ports. I generally expose my containers through a reverse proxy, running bare metal on the host, and that completely bypasses the privileged port issue.</p>
]]></description><pubDate>Mon, 27 Jul 2026 22:42:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=49076458</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49076458</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49076458</guid></item><item><title><![CDATA[New comment by drnick1 in "Google Chrome Arrives on ARM64 Linux, Widevine DRM Included"]]></title><description><![CDATA[
<p>> Firefox supports Widevine Level 1 on Windows 11 devices with the requisite hardware and has for a year or so.<p>I am not familiar with the way Widevine works, but if that is true, there must be a way to hack that support into the Linux version. After all, the code is there and it should be possible to spoof hardware identifiers or whatever is needed to run Widevine on an open platform.</p>
]]></description><pubDate>Mon, 27 Jul 2026 19:28:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=49074489</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49074489</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49074489</guid></item><item><title><![CDATA[New comment by drnick1 in "Show HN: CheapSecurity – Lightweight, Self-Hosted CCTV for Linux SBCs"]]></title><description><![CDATA[
<p>I am not familiar with this particular project, but generally speaking, you don't want a USB camera for CCTV. You want an IP camera with POE and RTSP support.</p>
]]></description><pubDate>Sun, 26 Jul 2026 22:48:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=49063191</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49063191</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49063191</guid></item><item><title><![CDATA[New comment by drnick1 in "Kill The Cookie Banner"]]></title><description><![CDATA[
<p>I think so yes, but Firefox is probably still better.</p>
]]></description><pubDate>Sun, 26 Jul 2026 19:18:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=49061426</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49061426</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49061426</guid></item><item><title><![CDATA[New comment by drnick1 in "Show HN: CheapSecurity – Lightweight, Self-Hosted CCTV for Linux SBCs"]]></title><description><![CDATA[
<p>What is the difference between this and Frigate? Before clicking the link, I thought this would be a hardware solution (build you own camera from open components).</p>
]]></description><pubDate>Sun, 26 Jul 2026 18:54:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=49061171</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49061171</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49061171</guid></item><item><title><![CDATA[New comment by drnick1 in "Lidl Introduces the European Payment Method Wero in Germany"]]></title><description><![CDATA[
<p>But this system is probably tied to Google and Apple's "device attestation." Don't worry, it's in the name of security!</p>
]]></description><pubDate>Sun, 26 Jul 2026 18:47:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=49061097</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49061097</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49061097</guid></item><item><title><![CDATA[New comment by drnick1 in "GrapheneOS protections against data extraction from locked devices"]]></title><description><![CDATA[
<p>> I am wary that I could be targeted at a border just for having a google pixel with grapheneOS.<p>Is that likely to happen at all in a civilized (Western) country?</p>
]]></description><pubDate>Sun, 26 Jul 2026 16:39:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=49059809</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49059809</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49059809</guid></item><item><title><![CDATA[New comment by drnick1 in "GrapheneOS protections against data extraction from locked devices"]]></title><description><![CDATA[
<p>You can already do most of that with GrapheneOS or even an iPhone. My contacts, files, photos, etc. are on my home server, accessed through a VPN. My GrapheneOS phone only runs a handful of open source apps. If I were to lose the phone, I would simply revoke the Wireguard key and there wouldn't be anything valuable left on it.</p>
]]></description><pubDate>Sun, 26 Jul 2026 16:32:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=49059740</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49059740</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49059740</guid></item><item><title><![CDATA[New comment by drnick1 in "GrapheneOS protections against data extraction from locked devices"]]></title><description><![CDATA[
<p>Apple can at any time push a hostile "upgrade" that will remove or disable the claimed security features. You don't control the operating system, and can't trust that it isn't backdoored, especially given Apple's record[0].<p>[0] <a href="https://en.wikipedia.org/wiki/PRISM" rel="nofollow">https://en.wikipedia.org/wiki/PRISM</a></p>
]]></description><pubDate>Sun, 26 Jul 2026 16:21:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=49059634</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49059634</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49059634</guid></item><item><title><![CDATA[New comment by drnick1 in "Kill The Cookie Banner"]]></title><description><![CDATA[
<p>uBlock Origin with all "annoyance" filters enabled. I haven't seen a cookie banner in years.<p>Another good one to have the "hide Youtube shorts" filter, featured on HN a while back.</p>
]]></description><pubDate>Sun, 26 Jul 2026 16:07:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=49059519</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49059519</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49059519</guid></item><item><title><![CDATA[New comment by drnick1 in "A 77-year-old Republican man is staging a solo protest against Flock cameras"]]></title><description><![CDATA[
<p>A sledgehammer would be a better solution.</p>
]]></description><pubDate>Sat, 25 Jul 2026 22:06:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=49052103</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49052103</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49052103</guid></item><item><title><![CDATA[New comment by drnick1 in "Open-weight AI is having its Kubernetes moment"]]></title><description><![CDATA[
<p>> Chinese release open models to drive the state of the art<p>Are you sure it isn't just another form of Chinese industrial policy? China does not have frontier labs, but through distillation and their own work they can get pretty close. It's not enough to be competitive with Anthropic and OpenAI, but there is still money to be made by selling compute (software as a service), and in any case it's  better than being left behind in the AI race.</p>
]]></description><pubDate>Sat, 25 Jul 2026 21:57:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=49052018</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49052018</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49052018</guid></item><item><title><![CDATA[New comment by drnick1 in "Open-weight AI is having its Kubernetes moment"]]></title><description><![CDATA[
<p>> American labs need to release frontier-grade open-weight models under licenses that startups can actually build on.<p>To be fair, OpenAI has released a couple of (then very good) OSS models. I run the 20B version at home and it is excellent for reviewing text and common tasks like drafting bash scripts. There is a larger 120B that you can't realistically run on consumer hardware at reasonable tok/s too. I wish OpenAI updated these models more frequently though.</p>
]]></description><pubDate>Sat, 25 Jul 2026 19:58:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=49050974</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49050974</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49050974</guid></item><item><title><![CDATA[New comment by drnick1 in "Self-host your mail server"]]></title><description><![CDATA[
<p>I also self-host, and it's not nearly as difficult as know-it-all people on the Internet make it out to be. I rolled things out from scratch using Postfix and Dovecot on Debian as I dislike bloated and opaque containers that hide important decisions from the sysadmin. The main requirements are a clean, fixed IPv4 and an aged domain.<p>Absolutely zero maintenance has been required since I set it up (unattended upgrades), until recently when Dovecot updated the configuration syntax. Claude ported the config script to the new syntax in about 2min.</p>
]]></description><pubDate>Sat, 25 Jul 2026 00:39:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=49043371</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49043371</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49043371</guid></item><item><title><![CDATA[New comment by drnick1 in "Nvidia, Microsoft, Meta warn against overregulating open-weight models"]]></title><description><![CDATA[
<p>We are talking about the U.S. here, and no, 40k or 55k are not good salaries at all. It may be OK in Europe with the lower cost of living, etc., but the price of a new car is 50k in 2026, and a basic fast food meal pretty much anywhere is well north of $10.</p>
]]></description><pubDate>Fri, 24 Jul 2026 21:19:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=49041706</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49041706</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49041706</guid></item><item><title><![CDATA[New comment by drnick1 in "IRGC claims it destroyed Amazon's Bahrain data center"]]></title><description><![CDATA[
<p>Germany and Japan surrendered and have done pretty well since.</p>
]]></description><pubDate>Fri, 24 Jul 2026 17:50:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=49039291</link><dc:creator>drnick1</dc:creator><comments>https://news.ycombinator.com/item?id=49039291</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49039291</guid></item></channel></rss>