<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: geggo98</title><link>https://news.ycombinator.com/user?id=geggo98</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 10 Oct 2026 11:19:03 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=geggo98" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by geggo98 in "Cloudflare acquires Deno"]]></title><description><![CDATA[
<p>Sanboxing makes it more suitable.<p>yt-dlp executes code from the website to get the exact download URLs and header values. The websites obfuscate these to prevent downloading. Running arbitrary 3rd party code in Node or Bun might work, but is risky, especially when that code could potentially come from one of the many ads on that video website.</p>
]]></description><pubDate>Sat, 10 Oct 2026 05:46:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=50029973</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=50029973</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=50029973</guid></item><item><title><![CDATA[New comment by geggo98 in "Why are European countries moving their gold out of North America?"]]></title><description><![CDATA[
<p>> Look at France, they have nuclear and they have energy security. Look at Germany and how foolish they were to deprecate all nuclear stations.<p>They both depend on Russia, one for liquid gas the other for nuclear fuel [1]. They are quite similar on energy security.<p>[1]: <a href="https://en.wikipedia.org/wiki/Nuclear_fuel_cycle_in_France#Uranium_imports" rel="nofollow">https://en.wikipedia.org/wiki/Nuclear_fuel_cycle_in_France#U...</a></p>
]]></description><pubDate>Mon, 07 Sep 2026 04:40:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=49593969</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=49593969</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49593969</guid></item><item><title><![CDATA[New comment by geggo98 in "Shutting down our public encrypted DNS"]]></title><description><![CDATA[
<p>I have no insights in Swedish politics. His actions could be really bad, or mean nothing at all. Without proper context, it’s hard to say.</p>
]]></description><pubDate>Sat, 05 Sep 2026 07:17:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=49573979</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=49573979</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49573979</guid></item><item><title><![CDATA[New comment by geggo98 in "1M context is now generally available for Opus 4.6 and Sonnet 4.6"]]></title><description><![CDATA[
<p>Just make two plans and switch, when one of them is exhausted.</p>
]]></description><pubDate>Sat, 14 Mar 2026 12:58:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=47376227</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=47376227</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47376227</guid></item><item><title><![CDATA[New comment by geggo98 in "EU age verification app not planning desktop support"]]></title><description><![CDATA[
<p>Not sure where gp lives. But most banks here restrict you to 4 digits as the password. So basically a PIN. If you are lucky, you get 6 digits or even letters. But be careful: if you use “fancy letters” (symbols, umlauts, …) you risk locking your account: you will be able to set this password, but the actual login form won’t allow you to enter it. Banks here are highly regulated, so don’t hope for competent competition.<p>They mitigate the obvious security thread with mandatory 2fa (actually mandated by regulation). Some use this as an opportunity to push their apps: no separate 2fa method, but only integrated in their bloated app, that checks for rooted devices and only supports the newest OS.<p>It’s quite hard to find out in advance, what 2fa methods with which fees each bank actually requires. I remember that some of them had funny ideas, what a customer should be billed for 2fa SMS. I think it was 50 cents per SMS.</p>
]]></description><pubDate>Thu, 25 Sep 2025 10:40:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=45371318</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=45371318</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45371318</guid></item><item><title><![CDATA[New comment by geggo98 in "JetBrains releases RustRover IDE for Rust development"]]></title><description><![CDATA[
<p>If you have the time, could you please post the list of plugins you are using?</p>
]]></description><pubDate>Sat, 25 May 2024 14:09:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=40475172</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=40475172</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40475172</guid></item><item><title><![CDATA[New comment by geggo98 in "The xz sshd backdoor rabbithole goes quite a bit deeper"]]></title><description><![CDATA[
<p>That’s true. On the other hand, Apple isn’t some kind of Borg like swarm intelligence. While Apple’s upper management doesn’t want back doors in their products, someone in middle management might have come to a different opinion.</p>
]]></description><pubDate>Mon, 08 Apr 2024 04:08:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=39966136</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=39966136</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39966136</guid></item><item><title><![CDATA[New comment by geggo98 in "Reflections on Distrusting xz"]]></title><description><![CDATA[
<p>That’s a good start. In the long run probably three things are necessary:<p>1) wiring critical software in a language that protects better against such exploits. Might be Rust, Go, perhaps also C# and Nim.<p>2) Making reproducible builds the norm, that start from the original source code repositories (e.g., based on a Git hash)<p>3) making maintainers more resilient against social attacks. This means more appreciation, less demands, and zero tolerance against abuse. If the maintainer can be pressured, I am at risk.<p>The last one is probably the most difficult.</p>
]]></description><pubDate>Thu, 04 Apr 2024 04:52:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=39926664</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=39926664</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39926664</guid></item><item><title><![CDATA[New comment by geggo98 in "Reflections on Distrusting xz"]]></title><description><![CDATA[
<p>You are right, it took quite some time. On the other hand, it looks like the legitimate part of contributing to xz was only a part time job for the attacker. The rest of the time, they either worked on the exploits, or in other things, like infiltrating other projects using a different handle.<p>Basically I can imagine the attackers being a well organized group, using work sharing and pipelining. Some members of the group would be preparing exploits, some would infiltrate projects and some would make sure not to get caught. And since infiltrating takes time, they would make sure to have multiple projects in the pipeline, seine in the early contributor stage, some in the social pressure stage, and some in the exploiting stage.</p>
]]></description><pubDate>Thu, 04 Apr 2024 04:38:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=39926587</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=39926587</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39926587</guid></item><item><title><![CDATA[New comment by geggo98 in "Inside the failed attempt to backdoor SSH globally that got caught by chance"]]></title><description><![CDATA[
<p>Expecting liability coverage for source code people publish for free on their own time has very strong implications on free speech, freedom of arts, and freedom of science. I don’t think this is possible in a liberal society.<p>On the other hand, you can already buy software, where the vendor takes some kind of liability: just buy Windows, AIX, or one of the commercial Linux offerings. Same for software libraries: there are commercial offerings that come with (limited) liability from the vendor. It’s even possible to create software to stronger standards. But outside of some very specific industries (aerospace, automotive, nuclear, defense, …) there doesn’t seem to be a market for that.</p>
]]></description><pubDate>Wed, 03 Apr 2024 08:31:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=39914872</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=39914872</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39914872</guid></item><item><title><![CDATA[New comment by geggo98 in "Chrome Feature: ZSTD Content-Encoding"]]></title><description><![CDATA[
<p>I think there were some open PRs from that account, that got scrubbed from the account after the back door in xz was discovered. But probably nothing got merged.</p>
]]></description><pubDate>Mon, 01 Apr 2024 16:13:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=39895756</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=39895756</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39895756</guid></item><item><title><![CDATA[New comment by geggo98 in "XZ backdoor: "It's RCE, not auth bypass, and gated/unreplayable.""]]></title><description><![CDATA[
<p>My suggestion: Put your SSH behind WireGuard and/or behind a jump host (with only port forwarding allowed, no shell). If you don’t have a separate host, use a Docker container.<p>If you use a jump host, consider a different OS (e.g., BSD vs Linux). Remember this analogy with slices of Swiss cheese used during the pandemics? If one slice has a hole, the next slice hopefully won’t have a hole on the same position. The more slices you have, the better for you.<p>Although for remote management, you don’t want to have too many “slices” you have to manage and that can fail.</p>
]]></description><pubDate>Sun, 31 Mar 2024 07:58:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=39882350</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=39882350</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39882350</guid></item><item><title><![CDATA[New comment by geggo98 in "XZ backdoor: "It's RCE, not auth bypass, and gated/unreplayable.""]]></title><description><![CDATA[
<p>Using a jump host could help, only allowing port forwarding. Ideally it would be heavily monitored and create a new instance for every connection (e.g., inside a container).<p>The attacker would then be stuck inside the jump host and would have to probe where to connect next. This hopefully would then trigger an alert, causing some suspicion.<p>A shared instance would allow the attacker to just wait for another connection and then follow its traces, without risking triggering an alert by probing.<p>The ideal jump host would allow to freeze the running ssh process on an alert, either with a snapshot (VM based) or checkpointing (container based), so it can be analyzed later.</p>
]]></description><pubDate>Sun, 31 Mar 2024 07:47:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=39882293</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=39882293</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39882293</guid></item><item><title><![CDATA[New comment by geggo98 in "Backdoor in upstream xz/liblzma leading to SSH server compromise"]]></title><description><![CDATA[
<p>Actually you have a point. A collection of shell scripts (like the classical init systems) have obviously a smaller attack surface. In this case the attacker used some integration code with systemd to attack the ssh daemon. So sshd without systemd integration is safe against this specific attack.<p>In general, I’m not convinced that systemd makes things less secure. I have the suspicion that the attacker would just have used a different vector, if there was no systemd integration. After all it looks like the attacker was also trying to integrate exploits in owner libraries, like zstd.<p>Still I would appreciate it, if systemd developers would find a better protection against supply chain attacks.</p>
]]></description><pubDate>Sat, 30 Mar 2024 19:55:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=39878053</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=39878053</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39878053</guid></item><item><title><![CDATA[New comment by geggo98 in "Backpressure explained – the resisted flow of data through software (2019)"]]></title><description><![CDATA[
<p>Unix pipes have built in back pressure. A very simplified view, assuming blocking calls and single threads: if the process on the left side of the pipe produces data too fast and fills up the buffer, the operating system won’t give it any additional CPU cycles, until the program on the right side of the pipe caught up with reading and freed up the buffer.<p>Things become more complicated when multi-threading and / or asynchronous IO gets involved. If the producer on the left side of the pipe has multiple threads, e.g., one writer thread and multiple worker threads, producing data for the writer thread. Then it has to invent its own signaling between the different threads, to avoid throwing away data, when its internal buffers fill up. This is effectively a kind of back pressure.<p>In your example with the lever and the parser: if the lexer is multi threaded, you either need unlimited buffer for the tokens or some signaling for the threads, to slow down when the parser cannot keep up. This example is a bit artificial, since most languages don’t allow parallel lexers. But with parallel compilers and one (incremental) linker, this becomes more realistic.</p>
]]></description><pubDate>Wed, 27 Mar 2024 12:29:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=39838151</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=39838151</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39838151</guid></item><item><title><![CDATA[New comment by geggo98 in "Jan: An open source alternative to ChatGPT that runs on the desktop"]]></title><description><![CDATA[
<p>From the screenshots it looks like there is an activation limit, with a maximum of four devices. Reading the license, I could not confirm this. Is there a limit, and if, what is the maximum?</p>
]]></description><pubDate>Sun, 24 Mar 2024 22:43:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=39811201</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=39811201</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39811201</guid></item><item><title><![CDATA[New comment by geggo98 in "We built the fastest CI and it failed"]]></title><description><![CDATA[
<p>While you are here: the Node.js syntax highlights on you QuickStart docs seems to be broken. Tested with Safari and Chrome on a recent macOS. That’s not a huge issue, but makes it a bit harder to grasp what’s going on and how the Dagger SDK actually works.</p>
]]></description><pubDate>Wed, 13 Sep 2023 06:30:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=37492936</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=37492936</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37492936</guid></item><item><title><![CDATA[New comment by geggo98 in "Sitting and standing at work (2015)"]]></title><description><![CDATA[
<p>> But I have been told “video off” is passive aggressive so I don’t know how much longer I can pull this off.<p>“Video off” is often necessary, because your laptop runs low on battery, or has run too hot. Sometimes your Wi-Fi might just be bad, forcing you to audio only. A colleague of mine could not turn on video while the Anti virus was running, or the PC would get overloaded (hint: it was running all the time, as mandated by the security guidelines).<p>You might also not feel well with being watched because of personal reasons. And since it’s personal, it would not be the other person’s business.<p>If you are at home, video might interfere with other people’s privacy. Just think about the neighbor sunbathing while visible from your window. Don’t want to risk streaming things to work that are not safe for work.</p>
]]></description><pubDate>Tue, 19 Jul 2022 07:15:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=32148437</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=32148437</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32148437</guid></item><item><title><![CDATA[New comment by geggo98 in "Insurance is like gambling, don't overdo it"]]></title><description><![CDATA[
<p>> Pension: Germany has a pyramid scheme and it collapsed a while back.<p>The system did just fine, but was plundered by politics. During the German reunification, the people from the former Eastern Germany were added to the public pension fund without ever having anything payed in. This drastically increased the amount of recipients without bringing in additional money.<p>Politics decided that. They also decided to not put any tax money in the pension pool to re-balance it.<p>No matter how you design a pension fund: If you bring in an additional country as recipients without any additional capital, that pension fund won't survive.<p>[1]: <a href="https://www.bpb.de/politik/innenpolitik/rentenpolitik/290963/deutsche-einigung-und-rentenversicherung" rel="nofollow">https://www.bpb.de/politik/innenpolitik/rentenpolitik/290963...</a></p>
]]></description><pubDate>Mon, 21 Jun 2021 12:17:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=27578419</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=27578419</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27578419</guid></item><item><title><![CDATA[New comment by geggo98 in "Do you really need Redis? How to get away with just PostgreSQL"]]></title><description><![CDATA[
<p>The blog post you mentions brings two arguments: first the database would require looking. Second the database would need tradeoffs between reading (polling) and writing (adding and removing to the queue).<p>The original article handles the first argument: Postgres doesn't need polling. Instead it provides a notify mechanism, that informs the application when the table changed (something was added or removed from the queue) via the SQL NOTIFY statement.<p>For the second point it also provides a solution: since optimization for reading is not needed anymore with the NOTIFY statement, the trade-off like different: we now need an efficient way to write. For this the article provides an efficient update statement with special lock behavior. This helps to make writes efficient, too.<p>It looks like both points from the blog post you linked are handled in the original article.</p>
]]></description><pubDate>Mon, 14 Jun 2021 19:33:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=27507149</link><dc:creator>geggo98</dc:creator><comments>https://news.ycombinator.com/item?id=27507149</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27507149</guid></item></channel></rss>