<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: hermanb</title><link>https://news.ycombinator.com/user?id=hermanb</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 04 May 2026 20:49:45 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=hermanb" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by hermanb in "The smelly baby problem"]]></title><description><![CDATA[
<p>Our baby was capable of sending these signals when she was a few weeks. So most pees she does hanging above the sink. This saves so many diapers, crazy. And much more comfortable for her to never have a wet butt, not even a minute. Would recommend!<p>I think within the next few months we can actually get her to go to the potty by herself. She’s 15 months now.<p>This industry wasn’t just good. It did destroy babies sensitivity to soiling.</p>
]]></description><pubDate>Sat, 02 May 2026 00:19:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=47982017</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=47982017</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47982017</guid></item><item><title><![CDATA[New comment by hermanb in "Vouch"]]></title><description><![CDATA[
<p>I had this idea / pet project once where I did exactly this for email. Emails would immediately bounce with payment link and explanation. If you paid you get credit on a ledger per email address. Only then the mail goes through.<p>You can also integrate it in clients by adding payment/reward claim headers.</p>
]]></description><pubDate>Sun, 08 Feb 2026 20:51:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=46938390</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=46938390</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46938390</guid></item><item><title><![CDATA[New comment by hermanb in "Kargo, a multi-stage application lifecycle orchestrator"]]></title><description><![CDATA[
<p>If Kargo requires R/W access to GitHub, and auto updates charts/images, isn’t that asking for your production environment to be infected by a change prepared and cultured in your dev environment and then auto updating / hiding itself into prod freight?<p>We disallow writing back to GitHub to avoid this issue, and manage stages through branches, combined with directories for overlays. Things can get out of sync, but comparing branches is easily automated.</p>
]]></description><pubDate>Mon, 18 Sep 2023 17:58:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=37559566</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=37559566</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37559566</guid></item><item><title><![CDATA[New comment by hermanb in "Microsoft government email compromised (and quietly fixed)"]]></title><description><![CDATA[
<p>It would be pretty interesting if they shared some more detail on this indeed. I was wondering the same when I read “forged” elsewhere.<p>How can you forge a token? Did they use quantum machinery to retrieve a JWT Private Key? Did they factor RSA keys?<p>But no, they used a bug/weakness to exchange a token.</p>
]]></description><pubDate>Wed, 12 Jul 2023 20:27:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=36701159</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=36701159</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36701159</guid></item><item><title><![CDATA[New comment by hermanb in "Hardware microphone disconnect (2021)"]]></title><description><![CDATA[
<p>It is not disconnected by “a chip”. It is disconnected by something that closely resembles a physical switch.<p>This is the point of the article. There is no software involved. It can’t be hacked.</p>
]]></description><pubDate>Tue, 07 Mar 2023 20:11:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=35060523</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=35060523</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35060523</guid></item><item><title><![CDATA[New comment by hermanb in "Germany opposes EU plans for client-side scanning"]]></title><description><![CDATA[
<p>If the image doesn’t leave the device and only the hash does… What is stopping one from uploading existing public images, banning a whole lot of innocent people?</p>
]]></description><pubDate>Thu, 02 Mar 2023 22:32:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=35003027</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=35003027</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35003027</guid></item><item><title><![CDATA[New comment by hermanb in "Analysis on Docker Hub malicious images: Attacks through public container images"]]></title><description><![CDATA[
<p>Honestly, this seems like little. We should be wary of the source we try to pull, but given how easy it is to upload something malicious you’d expect thousands of images of this kind. Maybe DockerHub is already detecting and deleting these packages?<p>Or why aren’t more people interested in this?<p>Not sure, but maybe injecting into commonly used libraries via subdependencies is seen as a more effective method, getting more focus. Would be interesting to have a broader analysis of malicious artifacts!</p>
]]></description><pubDate>Wed, 23 Nov 2022 17:53:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=33722357</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=33722357</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33722357</guid></item><item><title><![CDATA[New comment by hermanb in "Circadian lighting with Home Assistant: Like f.lux, but for your house"]]></title><description><![CDATA[
<p> <a href="https://hueblog.com/2022/07/16/natural-light-new-function-now-available-in-the-hue-app/" rel="nofollow">https://hueblog.com/2022/07/16/natural-light-new-function-no...</a></p>
]]></description><pubDate>Mon, 07 Nov 2022 21:36:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=33512861</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=33512861</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33512861</guid></item><item><title><![CDATA[New comment by hermanb in "Circadian lighting with Home Assistant: Like f.lux, but for your house"]]></title><description><![CDATA[
<p>It is a feature of the Hue bulbs being worked upon, see: <a href="https://hueblog.com/2022/07/16/natural-light-new-function-now-available-in-the-hue-app/" rel="nofollow">https://hueblog.com/2022/07/16/natural-light-new-function-no...</a></p>
]]></description><pubDate>Mon, 07 Nov 2022 21:35:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=33512849</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=33512849</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33512849</guid></item><item><title><![CDATA[New comment by hermanb in "Flutter 3"]]></title><description><![CDATA[
<p>Philips Hue is fully Flutter since a while now (v4). There were issues with (pre-rendering of) animations but those have been resolved in Flutter.</p>
]]></description><pubDate>Wed, 11 May 2022 21:41:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=31346213</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=31346213</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31346213</guid></item><item><title><![CDATA[New comment by hermanb in "Implementing a Merkle Tree for an Immutable Verifiable Log"]]></title><description><![CDATA[
<p>I’ve been wondering about this too and always used full sha’s until now. But recently I’ve made an action myself: You actually need to publish the action to the marketplace with each tag manually. It feels like there might be more going on.<p>Is GitHub storing those published tags and avoiding tampering by only letting you use those tags once? Are they warning or blocking runs if you tamper? …<p>I’m really curious because it seems like SUCH a giant risk otherwise.</p>
]]></description><pubDate>Fri, 06 May 2022 19:55:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=31289061</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=31289061</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31289061</guid></item><item><title><![CDATA[New comment by hermanb in "Subdomain Takeovers"]]></title><description><![CDATA[
<p>Happens with GitHub Pages too. You can crawl for repos with CNAME file and if any of those repos is removed or CNAME is removed, you can takeover.<p>I believe this is now hardened a bit by setting the CNAME to a GitHub domain with the user/org as subdomain.</p>
]]></description><pubDate>Wed, 27 Apr 2022 12:02:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=31178838</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=31178838</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31178838</guid></item><item><title><![CDATA[New comment by hermanb in "Show HN: FlyCode – Git-Based Copy and Translations Editor for Web Apps"]]></title><description><![CDATA[
<p>Really sounds like an awesome tool. Fits right into the serverless / JAMStack kind of systems too. Just like Netlify CMS.<p>I was actually in the process of tweaking Netlify CMS to be more easily hostable yourself without depending on the Netlify Pro plans as much. Basically involves hosting a combination of Netlify Identity and Git Gateway compliant backends in GCP CloudRun or AWS Lambda. Maybe even making it easy to configure a build pipeline on CloudBuild.<p>I wanted to use this for small business websites, but also configuration management and translations for projects at work. Sounds like FlyCode is a great (not self-built) alternative I can recommend. Great business model as well. Almost no databases needed (auth only?) and easy to host stateless on serverless offerings. Scales linearly</p>
]]></description><pubDate>Tue, 26 Apr 2022 18:55:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=31171587</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=31171587</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31171587</guid></item><item><title><![CDATA[New comment by hermanb in "'Freeze-thaw battery' stores electricity long-term for seasonal release"]]></title><description><![CDATA[
<p>Original article is a good read too:<p><a href="https://www.cell.com/cell-reports-physical-science/pdf/S2666-3864(22)00091-1.pdf" rel="nofollow">https://www.cell.com/cell-reports-physical-science/pdf/S2666...</a></p>
]]></description><pubDate>Thu, 07 Apr 2022 04:21:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=30940572</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=30940572</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30940572</guid></item><item><title><![CDATA[New comment by hermanb in "Software Architecture Patterns: 5 minute read"]]></title><description><![CDATA[
<p>Interesting architecture and I really would like to understand better the virtualized part: how does that scale?<p>If processing units store all data in memory, it doesn’t scale linearly. Maybe sharing is assumed?<p>I’d like to see some better examples of this if anyone has any!</p>
]]></description><pubDate>Fri, 29 Oct 2021 20:34:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=29043245</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=29043245</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=29043245</guid></item><item><title><![CDATA[New comment by hermanb in "Making Sense of Redis’ Scan Cursor"]]></title><description><![CDATA[
<p>And here is my friend-link: <a href="https://medium.com/q42-engineering/redis-scan-cursor-e5dc30326474?source=friends_link&sk=f390cfaab93db5a5000c4db418d969b7" rel="nofollow">https://medium.com/q42-engineering/redis-scan-cursor-e5dc303...</a></p>
]]></description><pubDate>Tue, 16 Jul 2019 14:03:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=20450079</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=20450079</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=20450079</guid></item><item><title><![CDATA[New comment by hermanb in "Debugging data flows in reactive programs"]]></title><description><![CDATA[
<p>It would work, and actually that is a great idea for the situations where applications are actually deployed and running in production, if it can be enabled on demand.<p>The advantages of RxFiddle above Zipkin-likes are:
- the means to extract the right information. The tool integrates with RxJS, and the format is universal accross Rx’s of other languages.
- the visualization which is a better fit, compared to trace spans. I didn’t use Zipkin in practice though, does it have other visualizations than spans?<p>Of course RxFiddle is nothing like zipkin in terms of how polished it is and how much it is carried by the community. RxFiddle so far has been my research result and while it is open source, I’ve not received contributions, so feel free to share more insights or efforts!</p>
]]></description><pubDate>Sat, 30 Jun 2018 12:08:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=17430550</link><dc:creator>hermanb</dc:creator><comments>https://news.ycombinator.com/item?id=17430550</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=17430550</guid></item></channel></rss>