<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: egberts1</title><link>https://news.ycombinator.com/user?id=egberts1</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 22 Jul 2026 00:58:09 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=egberts1" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by egberts1 in "Most Supreme Court Rulings Are Secretive Votes with Little Justification"]]></title><description><![CDATA[
<p>Little Sisters v United States became that inflection point around late 2013 to early 2014.<p>The mechanism: emergency injunctions against executive implementations.<p>The “switch” was not Congress changing SCOTUS authority. It was the Court becoming more willing to use existing tools:<p>* Supreme Court Rule 22 emergency applications<p>* All Writs Act (28 U.S.C. §1651)<p>* stay/injunction authority pending appeal<p>The important doctrinal shift was that the<p>Old model:<p>“We need to prevent irreversible harm while the courts finish deciding.”<p>Emerging model:<p>“We will temporarily block a major government policy while litigation continues.”<p>That distinction is what later became controversial.<p>Several forces converged:<p>ACA litigation created repeated emergency applications<p>The Affordable Care Act produced many disputes where:<p>* federal agencies were implementing rules,<p>* plaintiffs sought immediate relief,<p>* district courts and circuits disagreed.<p>Little Sisters (2013-2014) became THAT template, not the Clean Power Act of 2016.</p>
]]></description><pubDate>Thu, 16 Jul 2026 14:56:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=48935482</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48935482</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48935482</guid></item><item><title><![CDATA[New comment by egberts1 in "Who's running all those tiny RPKI servers?"]]></title><description><![CDATA[
<p>More accurately, running web sites using latest RFCs.</p>
]]></description><pubDate>Thu, 16 Jul 2026 02:14:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48929646</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48929646</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48929646</guid></item><item><title><![CDATA[New comment by egberts1 in "Who's running all those tiny RPKI servers?"]]></title><description><![CDATA[
<p>17.6% of assigned BGP-able IP address space are assigned but not actively broadcasting BGP packets???<p>(Deep-breath in, warning: rant)<p>This makes for a very problematic of continual hijacking AS link pathways between two hosts, notably between two countries.<p>BGPsec is well designed but remains largely unused (due to high-speed carrier-grade router's unwillingness to update firmware for new packet datagrams within BGP, not to mention requiring the addition of expensive de-crypt/re-crypte chipsets.<p>Interim SW-based solutions like BGP-ROA and BGP-ASPA are like HTTPS CAs, need to do PGP-style "trusting your friends' trusting other friends', ad naseum.<p>Alice trust Bob who trust Charles who trust Dave but Dave stabs Alice in the back. Um, no.<p>27 years of hosting my websites and DNSSec, but I can't prevent an island of Antigua to hijack my very own AS ... without all engaging in BGPSec.  Unless all participate in BGPSec.<p>Crappy workaround such as the self-hosting of a RPKI API server is the HTTPS CA for that BGP AS hijack problem and it's still a wild, wild Internet.<p>Even then, that boondoggle infrastructure (Google/CloudFlare/DigiCert/LetsEncrypt) of mass Certificate Transparency (CT) monitoring station is trying to do fingerprint imprints of all the CAs' hash values for all websites; that design approach is time-sensitive and is a glaring weakness for not using dTLS/mTLS (where web servers ALSO authenticates its clients as well as the standard TLS client also authenticates web servers.<p>It is a lame brain scheme to ensure expansion of CT.<p>The correct architectual security stance is to prevent expensive audit scenario and ensure that the complexity moves from after-the-fact detection (CT) into stronger identity enrollment and authorization (DNSSEC, policy records, key continuity, CA constraints, possibly multi-CA approval).<p>People making more useless work, yet profit massively.<p>By doing individual CA with each websites, browser can then ditch the cookie tracking. And privacy restored (it leaks only to that website what you say)<p>But the $710B data collection industry will have questions.<p>I absolutely love the idea of auto-creating mTLS/dTLS for each client-website pairing at account creation time.<p>Ancillary infrastructure crumbles. Backends simplified. Things are faster and simpler for all parties involved (except those evil 3rd party scrapers/sniffer/email-reading scourges.<p>AI responded as: Benefits:<p>* eliminates password reuse<p>* reduces phishing surface<p>* eliminates many cookie-tracking mechanisms<p>* allows per-site identity isolation<p>* improves API/service authentication<p>the endpoints own the trust relationship; intermediaries provide transport, not identity.<p>Exactly how a well-designed military or critical-industrial equipment in the field should behave (to prevent inadvert usage of captured/hijacked endpoints)<p>/end-of-rant</p>
]]></description><pubDate>Wed, 15 Jul 2026 16:36:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48923442</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48923442</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48923442</guid></item><item><title><![CDATA[New comment by egberts1 in "Why narcissistic leaders resist remote work"]]></title><description><![CDATA[
<p>Hard working.  Need more of that</p>
]]></description><pubDate>Sat, 11 Jul 2026 17:34:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48873944</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48873944</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48873944</guid></item><item><title><![CDATA[New comment by egberts1 in "Show HN: Getting GLM 5.2 running on my slow computer"]]></title><description><![CDATA[
<p>I'm running an archaic Dell PowerEdge T710 dual-Xeon E5690 (6/12 CPU, 3.73GHz turbo) with 192GB DDR3-800 (was 288GB but now PassMark 14,328).<p>Token rate is 0.091 per second.<p>Good for an overnight job.</p>
]]></description><pubDate>Sat, 11 Jul 2026 15:52:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48873109</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48873109</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48873109</guid></item><item><title><![CDATA[New comment by egberts1 in "California bans 'sell by' labels, hoping to cut food waste"]]></title><description><![CDATA[
<p>Can't rip the plastic wrap off to smell for rottenness.<p>Absorbent pad adds to the price also hides the "purge".<p>Harder to find meat without thousand poked holes (tenderizing)<p>Can't tell if meat are colorized to hide browness.<p>Time for me to visit my local butcher for a quarter cow, butchered.<p>Also a bigger freezer chest too!<p>"Packed On" or "Processed On" is the most accurate way to label meat, IMHO.</p>
]]></description><pubDate>Sat, 04 Jul 2026 17:50:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=48787312</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48787312</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48787312</guid></item><item><title><![CDATA[New comment by egberts1 in "Why I Stopped Arguing with People"]]></title><description><![CDATA[
<p>This ASCII character '|' is a bar.</p>
]]></description><pubDate>Wed, 01 Jul 2026 14:25:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=48747386</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48747386</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48747386</guid></item><item><title><![CDATA[New comment by egberts1 in "Why narcissistic leaders resist remote work"]]></title><description><![CDATA[
<p>Shorter title: why lazy workers resist on-site work.</p>
]]></description><pubDate>Wed, 01 Jul 2026 13:52:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=48746804</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48746804</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48746804</guid></item><item><title><![CDATA[New comment by egberts1 in "No Systemd"]]></title><description><![CDATA[
<p>Disclaimer: original RedHat investor here.<p>My home lab requires:<p>* Option 42 (custom NTP configuration)<p>* Option 66/67 (TFTP/PXE boot)<p>* Option 119 (Domain Search List)<p>* Vendor-specific options (43)<p>* Option 121 (Classless Static Routes)<p>* Custom enterprise options<p>+ DNS name Regex replacement (iPod/WII/Lucent DSLAM)<p>In RedHat dominated network, NetworkManager remains the dominant choice for:<p>* Enterprise desktops<p>* Laptops<p>* Many enterprise servers<p>* Complex managed networking in the Red Hat ecosystem<p>RedHat is still struggling to replace my network-manager's ultimate stackable network interfaces (VxLAN-VLAN-Bond-GRE-IPSec).<p>Furthermore, it isn't about hate. It is about KISS: it is about keeping PID 1 as simple as possible, something that all embedded systems and secured system should still aspire to do.<p>PId 1 should be pro forma and semantically secured as possible with minimal dependencies.<p>And process certainly should not be default all-privilege.<p>Simplicity of integration over complexity.</p>
]]></description><pubDate>Wed, 01 Jul 2026 13:08:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48746130</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48746130</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48746130</guid></item><item><title><![CDATA[New comment by egberts1 in "Why problem statements aren't enough"]]></title><description><![CDATA[
<p>Problem Statement<p>Think hard (time, money, resources)<p>Write down solution<p>Profit!</p>
]]></description><pubDate>Wed, 01 Jul 2026 11:54:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48745268</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48745268</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48745268</guid></item><item><title><![CDATA[New comment by egberts1 in "Solving Wordle using information theory"]]></title><description><![CDATA[
<p>I have a tree.<p>I always started with 3 words<p>POINT
LASED
CRUMB<p>This eliminates not only the most frequent letters but least frequent letters (Bloom filter), leaving rest of infrequent letter set to guess by narrow deduction.<p>Never failed me.</p>
]]></description><pubDate>Thu, 25 Jun 2026 12:17:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48672272</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48672272</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48672272</guid></item><item><title><![CDATA[New comment by egberts1 in "The worthlessness of Vitamin D is mildly exaggerated"]]></title><description><![CDATA[
<p>methylcobalamin B-12 plus Vitamin D3 is the preferred form.<p>Skip the D2 vitamin.</p>
]]></description><pubDate>Wed, 24 Jun 2026 13:39:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=48659657</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48659657</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48659657</guid></item><item><title><![CDATA[New comment by egberts1 in "UK set to announce social media ban for under-16s"]]></title><description><![CDATA[
<p>Is it just me or did I missed a notice that Bluesky is not on the list of UK's banned social media?</p>
]]></description><pubDate>Sun, 14 Jun 2026 17:34:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48530106</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48530106</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48530106</guid></item><item><title><![CDATA[New comment by egberts1 in "AI agent bankrupted their operator while trying to scan DN42"]]></title><description><![CDATA[
<p>You need a slave driver to whip those AI in line.<p>Or a psychiatrist to tame the craxy LLMs<p>Or an elected leader to lead the Luddites.<p><a href="https://github.com/vishal-dehurdle/state-harness" rel="nofollow">https://github.com/vishal-dehurdle/state-harness</a></p>
]]></description><pubDate>Fri, 12 Jun 2026 12:39:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48503379</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48503379</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48503379</guid></item><item><title><![CDATA[New comment by egberts1 in "Oh good, screwworms are back (2025)"]]></title><description><![CDATA[
<p>Other than chronic South America and Libya outbreaks, screwworm has been around forever.<p>Coupled with SIT, pyrethroid, doramectin, ivermectin, debriding, dressing are just about 100% effective.<p>Thanks to our enlarged 230-strong Federal-contracted field workers.</p>
]]></description><pubDate>Fri, 12 Jun 2026 12:34:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=48503330</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48503330</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48503330</guid></item><item><title><![CDATA[New comment by egberts1 in "Ask HN: Why is the HN crowd so anti-AI?"]]></title><description><![CDATA[
<p>I am guarded on today's LLM after much unit testings myself.<p>For as long as LLM use the probabilistic predictive next-token for an algorithm, there shall be glaring errors when encountering a complex-logic (or even compound-logic).<p>In short, use AND, OR, NOR, XOR sparingly when doing AI prompt. Elevate your err-dar when doing so.</p>
]]></description><pubDate>Sat, 06 Jun 2026 14:15:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=48425344</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48425344</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48425344</guid></item><item><title><![CDATA[New comment by egberts1 in "Capstone – multi-platform, multi-architecture disassembly framework"]]></title><description><![CDATA[
<p>As one who helped improved Capstone and its even more wonderful partner, Unicorn, I actually found an exploit in QEMU using Capstone/Unicorn.<p>Unicorn is a nearly-true software-based CPU emulator for ARM, AArch64, M68K, Mips, Sparc, PowerPC, RiscV, S390x, TriCore, X86 CPU (and memory) architecture.<p>This pair-up is arguably the best set of software tools out there.<p>QEMU? No worry, that's way back in QEMU v1.4 days (emulation of Intel IMUL lb/DWORD OPC_IMUL_GvEvlb opcode getting tripped up by XOR opcode doing self-modified operand and TLB cache didn't flush, resulting in a double XOR; ROT13x2 anyone?)<p>Fabrice fixed it then and is still blazing at QEMU 10.0 now. Ain't he awesome?<p>Yeah, I actually ran portion of TLB of QEMU thru unicorn back then.<p><a href="https://github.com/unicorn-engine/unicorn/issues/364" rel="nofollow">https://github.com/unicorn-engine/unicorn/issues/364</a></p>
]]></description><pubDate>Wed, 03 Jun 2026 13:03:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48383462</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48383462</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48383462</guid></item><item><title><![CDATA[New comment by egberts1 in "As researchers age, they produce less disruptive work"]]></title><description><![CDATA[
<p>Balderdash!!!</p>
]]></description><pubDate>Wed, 13 May 2026 18:58:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48125963</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48125963</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48125963</guid></item><item><title><![CDATA[New comment by egberts1 in "Stop MitM on the first SSH connection, on any VPS or cloud provider"]]></title><description><![CDATA[
<p>Correct. Very insecure unless your client app goes out of its way to perform DnSSEC.<p>But wait, there's more: SSH config, resolv.conf, DNS RR setup.<p>A lomg checklist for successful SSHFP deployment:<p><a href="https://egbert.net/blog/articles/dns-rr-sshfp.html" rel="nofollow">https://egbert.net/blog/articles/dns-rr-sshfp.html</a></p>
]]></description><pubDate>Mon, 11 May 2026 18:42:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=48098968</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48098968</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48098968</guid></item><item><title><![CDATA[New comment by egberts1 in "DNSSEC disruption affecting .de domains – Resolved"]]></title><description><![CDATA[
<p>Resolved ... after recovering from a mass German DNSSEC drinking party?<p>Ok.</p>
]]></description><pubDate>Wed, 06 May 2026 14:25:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48036663</link><dc:creator>egberts1</dc:creator><comments>https://news.ycombinator.com/item?id=48036663</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48036663</guid></item></channel></rss>