<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: eldridgea</title><link>https://news.ycombinator.com/user?id=eldridgea</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 28 Apr 2026 18:21:00 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=eldridgea" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by eldridgea in "Ask HN: Share your personal website"]]></title><description><![CDATA[
<p><a href="https://blog.eldrid.ge" rel="nofollow">https://blog.eldrid.ge</a></p>
]]></description><pubDate>Wed, 14 Jan 2026 18:00:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=46619592</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=46619592</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46619592</guid></item><item><title><![CDATA[New comment by eldridgea in "Quill OS: An open-source OS for Kobo's eReaders"]]></title><description><![CDATA[
<p>Thank you!</p>
]]></description><pubDate>Tue, 16 Dec 2025 08:36:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=46286171</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=46286171</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46286171</guid></item><item><title><![CDATA[New comment by eldridgea in "Quill OS: An open-source OS for Kobo's eReaders"]]></title><description><![CDATA[
<p>I got a Boox Go Color 7 as a less locked in alternative to my Kindle a while back, and overall I've really enjoyed it.<p>It's apparently rootable, although I haven't done that personally. It's Google Play certified so anything from the Play store works, and side loading Android apps works too. I use it with the open source KOReader app and in tandem with Calibre Web Automated. I did a writeup[0] with some details if you're interested.<p>[0]  <a href="https://blog.eldrid.ge/2025/03/12/self-hosted-ebook-management/" rel="nofollow">https://blog.eldrid.ge/2025/03/12/self-hosted-ebook-manageme...</a></p>
]]></description><pubDate>Tue, 16 Dec 2025 05:14:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=46285025</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=46285025</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46285025</guid></item><item><title><![CDATA[We Manage Cloudflare with Infrastructure as Code]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.cloudflare.com/shift-left-enterprise-scale/">https://blog.cloudflare.com/shift-left-enterprise-scale/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46209612">https://news.ycombinator.com/item?id=46209612</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 09 Dec 2025 19:43:37 +0000</pubDate><link>https://blog.cloudflare.com/shift-left-enterprise-scale/</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=46209612</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46209612</guid></item><item><title><![CDATA[How Cloudflare runs more AI models on fewer GPUs]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.cloudflare.com/how-cloudflare-runs-more-ai-models-on-fewer-gpus/">https://blog.cloudflare.com/how-cloudflare-runs-more-ai-models-on-fewer-gpus/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45051869">https://news.ycombinator.com/item?id=45051869</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 28 Aug 2025 13:24:14 +0000</pubDate><link>https://blog.cloudflare.com/how-cloudflare-runs-more-ai-models-on-fewer-gpus/</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=45051869</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45051869</guid></item><item><title><![CDATA[Message Signatures Now Part of Cloudflare Verified Bots Program]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.cloudflare.com/verified-bots-with-cryptography/">https://blog.cloudflare.com/verified-bots-with-cryptography/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44447419">https://news.ycombinator.com/item?id=44447419</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 02 Jul 2025 18:50:39 +0000</pubDate><link>https://blog.cloudflare.com/verified-bots-with-cryptography/</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=44447419</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44447419</guid></item><item><title><![CDATA[New comment by eldridgea in "That 'unsubscribe' button may be a scam"]]></title><description><![CDATA[
<p>I believe it strips everything after a "+" so you can use youraddress+servicename@gmail.com.<p>It ignores periods so you could also use your.address@gmail.com or y.ouraddress@gmail.com or whatever.<p>Some sides block plus addressing but that's what I use a lot of the time.</p>
]]></description><pubDate>Sun, 15 Jun 2025 14:38:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=44282514</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=44282514</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44282514</guid></item><item><title><![CDATA[Start auditing and controlling the AI models accessing your content]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.cloudflare.com/cloudflare-ai-audit-control-ai-content-crawlers/">https://blog.cloudflare.com/cloudflare-ai-audit-control-ai-content-crawlers/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=41631253">https://news.ycombinator.com/item?id=41631253</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 23 Sep 2024 22:27:09 +0000</pubDate><link>https://blog.cloudflare.com/cloudflare-ai-audit-control-ai-content-crawlers/</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=41631253</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41631253</guid></item><item><title><![CDATA[Leaving Google Voice but Taking My Messages with Me]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.eldrid.ge/2024/09/21/leaving-google-voice-but-taking-my-messages-with-me/">https://blog.eldrid.ge/2024/09/21/leaving-google-voice-but-taking-my-messages-with-me/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=41613337">https://news.ycombinator.com/item?id=41613337</a></p>
<p>Points: 6</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 21 Sep 2024 23:10:45 +0000</pubDate><link>https://blog.eldrid.ge/2024/09/21/leaving-google-voice-but-taking-my-messages-with-me/</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=41613337</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41613337</guid></item><item><title><![CDATA[New comment by eldridgea in "DOJ sues realpage for algorithmic pricing scheme that harms renters"]]></title><description><![CDATA[
<p>~2019 I led a team of highly qualified security R&D folks inside Cisco (we were part of an acquisition), these folks were effectively highly specialized SWEs. But because the title was something like "security researcher" it was compared against the closet Radform ladder which was closer to to compliance officer.<p>This meant the specialists were on a ladder with often <i>lower</i> pay than a standard SWE, and I couldn't shift the bureaucracy enough to change that. People left for all sorts of reasons but a big part was being able to get 2x-4x the total compensation at other companies.</p>
]]></description><pubDate>Mon, 26 Aug 2024 19:02:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=41360534</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=41360534</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41360534</guid></item><item><title><![CDATA[Cloudflare Cloud Connector]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.cloudflare.com/cloud-connector">https://blog.cloudflare.com/cloud-connector</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=41267490">https://news.ycombinator.com/item?id=41267490</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 16 Aug 2024 15:54:24 +0000</pubDate><link>https://blog.cloudflare.com/cloud-connector</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=41267490</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41267490</guid></item><item><title><![CDATA[Eliminating Hardware with Load Balancing and Cloudflare One]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.cloudflare.com/eliminating-hardware-with-load-balancing-and-cloudflare-one">https://blog.cloudflare.com/eliminating-hardware-with-load-balancing-and-cloudflare-one</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=40978834">https://news.ycombinator.com/item?id=40978834</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 16 Jul 2024 18:09:22 +0000</pubDate><link>https://blog.cloudflare.com/eliminating-hardware-with-load-balancing-and-cloudflare-one</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=40978834</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40978834</guid></item><item><title><![CDATA[New comment by eldridgea in "Ask HN: Those running K8s in house, can you please explain your architecture?"]]></title><description><![CDATA[
<p>I use a single node microk8s instance mainly so I can stay familiar with syntax and things for work rather than an actual high availability system.<p>But I use Portainer and store my files on Github so Portainer can auto-update a deployment if I submit a code change, so kind of rudimentary CI/CD which could be fleshed out more with some GitHub Actions probably.<p>I use iSCSI mounted storage from my NAS on the host and k8s volumes storing configs there. Actual app data is on the NAS accessed via NFS from the relevant apps.<p>So a new deployment is usually test locally on my laptop, once it's good commit the code to github and either let the deployment auto update or go to Portainer and do it manually if it's a new deployment. Ingress traffic is done via Cloudflare Tunnels deployed in k8s.<p>I keep most apps in a single namespace called prod unless they need more than 1-2 pods. If I was doing this again I'd use a namespace per app, I do use a dedicated namespace for anything with a Helm deployment or needs a lot of pods (e.g. Immich)</p>
]]></description><pubDate>Sun, 23 Jun 2024 16:55:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=40768814</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=40768814</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40768814</guid></item><item><title><![CDATA[New comment by eldridgea in "Addressing Visibility Challenges with TLS 1.3 Within the Enterprise"]]></title><description><![CDATA[
<p>The biggest difference I'm aware of is TLS 1.3 encrypts the initial handshake[0] in a way to prevent eavesdropping the hostname of the destination. Prior to that, you could get the hostname via network monitoring if you wanted. Encrypting the TLS handshake didn't maker sense to prioritize though as DNS requests were sent in the clear.<p>However with DNS increasingly being encrypted with DoH and DoT, the TLS handshake was one of the only places you could eavesdrop on the destination hostname, until it was removed in 1.3.<p>Of course network monitoring will still give you the destination IP, but those are increasingly overwhelmingly destined for a major cloud or CDN provider which doesn't provide much context about the actual destination.<p>If you'll forgive the shameless self-promo, I covered a decent amount of this in my Blackhat talk about encrypted DNS a few years back: <a href="https://www.youtube.com/watch?v=XCnE2o2pfxs" rel="nofollow">https://www.youtube.com/watch?v=XCnE2o2pfxs</a><p>0: <a href="https://blog.cloudflare.com/encrypted-client-hello/" rel="nofollow">https://blog.cloudflare.com/encrypted-client-hello/</a></p>
]]></description><pubDate>Thu, 28 Mar 2024 14:51:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=39852310</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=39852310</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39852310</guid></item><item><title><![CDATA[Cloudflare WARP Connector: paving the path to any-to-any connectivity]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.cloudflare.com/introducing-warp-connector-paving-the-path-to-any-to-any-connectivity-2">https://blog.cloudflare.com/introducing-warp-connector-paving-the-path-to-any-to-any-connectivity-2</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=39767616">https://news.ycombinator.com/item?id=39767616</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 20 Mar 2024 15:03:09 +0000</pubDate><link>https://blog.cloudflare.com/introducing-warp-connector-paving-the-path-to-any-to-any-connectivity-2</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=39767616</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39767616</guid></item><item><title><![CDATA[Cloudflare Warp: Tunneling with Masque]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.cloudflare.com/zero-trust-warp-with-a-masque">https://blog.cloudflare.com/zero-trust-warp-with-a-masque</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=39643376">https://news.ycombinator.com/item?id=39643376</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 08 Mar 2024 17:27:25 +0000</pubDate><link>https://blog.cloudflare.com/zero-trust-warp-with-a-masque</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=39643376</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39643376</guid></item><item><title><![CDATA[New comment by eldridgea in "Tell HN: Google Drive for Mac deleted all my files"]]></title><description><![CDATA[
<p>I'm not certain but might be related to the desktop client deleting files issue they had in Dec?<p><a href="https://www.theverge.com/2023/12/6/23991183/google-drive-lost-files-desktop-fix" rel="nofollow">https://www.theverge.com/2023/12/6/23991183/google-drive-los...</a></p>
]]></description><pubDate>Tue, 13 Feb 2024 21:17:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=39362956</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=39362956</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39362956</guid></item><item><title><![CDATA[Privacy Pass Standard]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.cloudflare.com/privacy-pass-standard">https://blog.cloudflare.com/privacy-pass-standard</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=38927532">https://news.ycombinator.com/item?id=38927532</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 09 Jan 2024 15:55:45 +0000</pubDate><link>https://blog.cloudflare.com/privacy-pass-standard</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=38927532</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38927532</guid></item><item><title><![CDATA[New comment by eldridgea in "Ask HN: Why SSL certs are not decentralized?"]]></title><description><![CDATA[
<p>I asked a cloudflare engineer this and the answer was a bit vague but amounted to the failure rate being something like 0.5% which was too high for the amount of TLS sessions being initiated all the time.<p>Although I always thought it would be a nice feature for security conscious folks to be able to ennable. Or go ahead and use it on more sensitive sites only, e.g. banks.</p>
]]></description><pubDate>Mon, 18 Dec 2023 01:50:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=38678417</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=38678417</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38678417</guid></item><item><title><![CDATA[New comment by eldridgea in "Firefox 120 Ready with Global Privacy Control, WebAssembly GC on by Default"]]></title><description><![CDATA[
<p>They work with Firefox for me on desktop (mac/linux). This is _very_ recent though.<p>Passkeys in Firefox also work for me on mobile but not with Bitwarden, Bitwarden's blog says passkey sync on mobile is "coming soon".</p>
]]></description><pubDate>Mon, 20 Nov 2023 20:49:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=38354505</link><dc:creator>eldridgea</dc:creator><comments>https://news.ycombinator.com/item?id=38354505</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38354505</guid></item></channel></rss>