<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: lgeek</title><link>https://news.ycombinator.com/user?id=lgeek</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 14 Sep 2026 08:19:04 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=lgeek" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by lgeek in "I'm being cyberattacked by Tesla, Inc"]]></title><description><![CDATA[
<p>If you do run an NTP server, please make sure it's not vulnerable to DDoS amplification (monlist, readvar, etc need to be disabled) and apply some rate limiting to make it less useful for reflection attacks. And be proactive about monitoring its traffic volume.<p>If you see high packet rate from a specific IP address or prefix, it's very likely not them abusing your service, but rather you attacking them by responding to spoofed requests.</p>
]]></description><pubDate>Sun, 13 Sep 2026 19:44:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=49687894</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=49687894</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49687894</guid></item><item><title><![CDATA[New comment by lgeek in "Meta problem with URPF our bundle in Boca raton"]]></title><description><![CDATA[
<p>I hate it when I can't get in touch with the right engineers at a large company. This (especially the highly targeted ad mentioned on the page) is a very creative way to try to solve that problem.<p>Not associated with Meta, but this piqued my interest. That being said, I found some parts confusing and hard to follow. For example what does URPF (Unicast Reverse Path Forwarding) in the title of this submission have to do with the contents?<p>And is the packet loss supposedly happening at specific times only? It's not mentioned anywhere, but one screenshot highlights the time. I couldn't reproduce the packet loss using any of the looking glasses and dest IP addresses in the screenshots. At this point, if this was a report I had received about one of my services, I would have probably bumped down the priority to low and asked for a reproducible test, because in my experience even issues that affect a single path in an ECMP group are not <i>this</i> hard to reproduce. I think it's way more important to give the engineer who will process the report an easy way to check that there is indeed a problem than to start to teach how traceroute works.<p>TBF, there does seem to be an issue somewhere, because sticking 129.134.80.234, one of the Meta IP addresses from a screenshot, on ping.pe does definitely show significant packet loss from more locations than you'd expect to see for an address with no connectivity issues.</p>
]]></description><pubDate>Wed, 25 Feb 2026 11:57:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=47150371</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=47150371</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47150371</guid></item><item><title><![CDATA[New comment by lgeek in "Google confirms 'high-friction' sideloading flow is coming to Android"]]></title><description><![CDATA[
<p>I'm only familiar with this as a user and not a developer, but I've had multiple Android phone where not all camera features available in the Camera app were available to other apps via the APIs:<p>* not all cameras being available<p>* stabilisation not working<p>* 60 FPS unavailable</p>
]]></description><pubDate>Sun, 25 Jan 2026 13:37:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=46753975</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=46753975</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46753975</guid></item><item><title><![CDATA[New comment by lgeek in "Cloudflare CEO on the Italy fines"]]></title><description><![CDATA[
<p>BunnyCDN don't run their own network, most of their servers are hosted at DataPacket(.com), but they use some other hosting companies too.<p>DataPacket has a very large network though and is kind of, sort of EU-based. AFAIK most operations are in Czechia, but the company is registered in UK. And there's also the Luxembourg-based Gcore.</p>
]]></description><pubDate>Sat, 10 Jan 2026 07:21:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=46563566</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=46563566</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46563566</guid></item><item><title><![CDATA[New comment by lgeek in "Guarding My Git Forge Against AI Scrapers"]]></title><description><![CDATA[
<p>> Worryingly, VNPT and Bunny Communications are home/mobile ISPs<p>VNPT <i>is</i> a residential / mobile ISP, but they <i>also</i> run datacentres (e.g. [1]) and offer VPS, dedicated server rentals, etc. Most companies would use separate ASes for residential vs hosting use, but I guess they don't, which would make them very attractive to someone deploying crawlers.<p>And Bunny Communications (AS5065) is a pretty obvious 'residential' VPN / proxy provider trying to trick IP geolocation / reputation providers. Just look at the website [2], it's very low effort. They have a page literally called 'Sample page' up and the 'Blog' is all placeholder text, e.g. 'The Art of Drawing Readers In: Your attractive post title goes here'.<p>Another hint is that some of their upstreams are server-hosting companies rather than transit providers that a consumer ISP would use [3].<p>[1] <a href="https://vnpt.vn/doanh-nghiep/tu-van/vnpt-idc-data-center-giai-phap-luu-tru-du-lieu-toan-dien-cho-doanh-nghiep.html" rel="nofollow">https://vnpt.vn/doanh-nghiep/tu-van/vnpt-idc-data-center-gia...</a>
[2] <a href="https://bunnycommunications.com/" rel="nofollow">https://bunnycommunications.com/</a>
[3] <a href="https://bgp.tools/as/5065#upstreams" rel="nofollow">https://bgp.tools/as/5065#upstreams</a></p>
]]></description><pubDate>Sat, 13 Dec 2025 20:28:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=46257690</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=46257690</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46257690</guid></item><item><title><![CDATA[New comment by lgeek in "DNS LOC Record (2014)"]]></title><description><![CDATA[
<p>These days RFC8805[0] is pretty widely supported. But as far as I understand, it's not entirely trusted and geolocation providers will still override that data if it doesn't match traceroutes and whatever other sources they use<p><a href="https://datatracker.ietf.org/doc/html/rfc8805" rel="nofollow">https://datatracker.ietf.org/doc/html/rfc8805</a></p>
]]></description><pubDate>Sat, 29 Nov 2025 19:06:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=46089915</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=46089915</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46089915</guid></item><item><title><![CDATA[New comment by lgeek in "Cloudflare outage on November 18, 2025 post mortem"]]></title><description><![CDATA[
<p>If you're buying transit, you'll have a hard time getting away with less than 10% commit, i.e. you'll have to pay for 10 Gbps of transit  to have a 100 Gbps port, which will typically run into 4 digits USD / month. You'll need a few hundred Gbps of network and scrubbing capacity to handle common DDoS attacks using amplification from script kids with a 10 Gbps uplink server that allow spoofing, and probably on the order of 50+ Tbps to handle Aisuru.<p>If you're just renting servers instead, you have a few options that are effectively closer to a 1% commit, but better have a plan B for when your upstreams drop you if the incoming attack traffic starts disrupting other customers - see Neoprotect having to shut down their service last month.</p>
]]></description><pubDate>Wed, 19 Nov 2025 14:06:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=45979643</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=45979643</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45979643</guid></item><item><title><![CDATA[New comment by lgeek in "DDoS Botnet Aisuru Blankets US ISPs in Record DDoS"]]></title><description><![CDATA[
<p>From having worked on DDoS mitigation, there's pretty much no difference between CGNAT and IPv6. Block or rate limit an IPv4 address and you might block some legitimate traffic if it's a NAT address. Block a single IPv6 address... And you might discover that the user controls an entire /64 or whatever prefix. So if you're in a situation where you can't filter out attack trafic by stateless signature (which is pretty bad already), you'll probably err on the side of blocking larger prefixes anyway, which potentially affect other users, the same as with CGNAT.<p>Insofar as it makes a difference for DDoS mitigation, the scarcity of IPv4 is more of a feature than a bug.</p>
]]></description><pubDate>Tue, 14 Oct 2025 02:06:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=45575502</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=45575502</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45575502</guid></item><item><title><![CDATA[New comment by lgeek in "DDoS Botnet Aisuru Blankets US ISPs in Record DDoS"]]></title><description><![CDATA[
<p>This is very challenging, in about one year the biggest recorded DDoS attack has increased from 5 Tbps to almost 30.<p>Almost all of the DDoS mitigation providers have been  struggling for a few weeks because they just don't have enough edge capacity.<p>And <i>normal</i> hosting companies that are not focused on DDoS mitigation also seem to have had issues, but with less impact to other customers as they'll just blackhole addresses under larger attacks. For example, I've seen all connections to / from some of my services at Hetzner time out way more frequently than usual, and some at OVH too. Then one of my smaller hosting providers got hit with an attack of at least 1 Tbps which saturated a bunch of their transit links.<p>Cloudflare and maybe a couple of the other enterprise providers (Gcore?) operate at a large enough scale to handle these attacks, but all the smaller ones (who tend to have more affordable rates and more application-specific filters for sensitive applications that can't deal with much leakage) seem to be in quite a bad spot right now. Cloudflare Magic Transit pricing supposedly starts at around $4k / month, and it would really suck if that became the floor for being able to run a non-HTTP service online.<p>Something like Team Cymru's UTRS service (with Flowspec support) could potentially help to mitigate attacks at the source, but residential ISPs and maybe the T1s would need to join it, and I don't see that happening anytime soon.</p>
]]></description><pubDate>Tue, 14 Oct 2025 01:36:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=45575315</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=45575315</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45575315</guid></item><item><title><![CDATA[New comment by lgeek in "The Therac-25 Incident (2021)"]]></title><description><![CDATA[
<p>It was taught in a first year software ethics class on my Computer Science programme. Back in 2010. I'm wondering if they still do</p>
]]></description><pubDate>Wed, 27 Aug 2025 08:56:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=45037049</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=45037049</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45037049</guid></item><item><title><![CDATA[New comment by lgeek in "Linode / Akamai US-EAST is down"]]></title><description><![CDATA[
<p>Update: it's finally up again after around 25.5 hrs of downtime</p>
]]></description><pubDate>Mon, 28 Jul 2025 12:30:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=44710185</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=44710185</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44710185</guid></item><item><title><![CDATA[New comment by lgeek in "Linode / Akamai US-EAST is down"]]></title><description><![CDATA[
<p>Over 22 hours of downtime for the one VPS I have in that region.<p>My infrastructure is redundant and spread out among hosting providers and DCs so there's no real impact, but I'm pretty sure this is the longest outage I've ever had with any provider. And the communication level has been so dissapointing. 4 hrs to say it's a power / HVAC issue? Updates that basically just say <i>we're still working on it</i> since then.</p>
]]></description><pubDate>Mon, 28 Jul 2025 09:28:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=44708955</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=44708955</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44708955</guid></item><item><title><![CDATA[New comment by lgeek in "I use zip bombs to protect my server"]]></title><description><![CDATA[
<p>On Firefox on Android on my pretty old phone, a blurry preview rendered in about 10 seconds, and it was fully rendered in 20 something seconds. Smooth panning and zooming the entire time</p>
]]></description><pubDate>Wed, 30 Apr 2025 02:39:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=43840659</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=43840659</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43840659</guid></item><item><title><![CDATA[New comment by lgeek in "FOSS infrastructure is under attack by AI companies"]]></title><description><![CDATA[
<p>> One crawler downloaded 73 TB of zipped HTML files in May 2024 [...] This cost us over $5,000 in bandwidth charges<p>I had to do a double take here. I run (mostly using dedicated servers) infrastructure that handles a few hundred TB of traffic per month, and my traffic costs are on the order of $0.50 to $3 per TB (mostly depending on the geographical location). AWS egress costs are just nuts.</p>
]]></description><pubDate>Thu, 20 Mar 2025 14:32:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=43424054</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=43424054</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43424054</guid></item><item><title><![CDATA[New comment by lgeek in "25 Years of Dillo"]]></title><description><![CDATA[
<p>Now that's a name I haven't heard in many years! I remember running Dillo on my HP Jornada 720 back in 2006 or 2007.</p>
]]></description><pubDate>Mon, 16 Dec 2024 13:17:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=42430687</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=42430687</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42430687</guid></item><item><title><![CDATA[New comment by lgeek in "Uber's Dark Descent: How Abandoning Innovation Hurt Drivers and Gouges Riders"]]></title><description><![CDATA[
<p>Anecdata, but I've been in Romania for a couple of weeks recently and Uber was cheaper than Bolt for all rides except one. I think I only used Bolt while I had  40% off voucher active, and sometimes even with that it wasn't much cheaper than Uber.<p>But I believe in the past Bolt used to be cheaper than Uber indeed.</p>
]]></description><pubDate>Mon, 02 Dec 2024 13:56:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=42296230</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=42296230</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42296230</guid></item><item><title><![CDATA[New comment by lgeek in "Reversing UK mobile rail tickets"]]></title><description><![CDATA[
<p>It doesn't need to be a phone running iOS and Android, you just need an email client and a PDF viewer for UK train etickets</p>
]]></description><pubDate>Sun, 05 Feb 2023 02:43:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=34661178</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=34661178</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34661178</guid></item><item><title><![CDATA[New comment by lgeek in "Valve is paying open-source developers to work on Proton, Mesa, and more"]]></title><description><![CDATA[
<p>You can change the root parameter in extlinux.conf to point to whatever block storage you want it to<p>Or reconfigure U-Boot to load extlinux.conf (and the kernel image, initrd, etc) entirely from other type of media. IIRC NVMe, USB and external SDs are all supported</p>
]]></description><pubDate>Sat, 17 Dec 2022 19:07:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=34031035</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=34031035</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34031035</guid></item><item><title><![CDATA[New comment by lgeek in "Why the second wave of the 1918 Spanish flu was so deadly"]]></title><description><![CDATA[
<p>> It's dawning on me that what China and South Korea are achieving, although impressive, leads to a lengthy stalemate that makes life impossible for millions of people.<p>It's not a stalemate, they're still getting new cases at a pace that allows their medical system to cope.<p>> In the absence of a vaccine<p>It's a pretty safe bet one will become available pretty soon. Meanwhile, more is being learned about how to handle infections and improve the outcome.<p>>  the aim is to flatten the curve but still get the whole thing over and done with in about 6 months<p>There are 4000 ICU beds in the country in total, most of which will be in use due to other kind of cases at any one time. [1] But let's assume you can make that number available for coronavirus patients for 6 months. So you have 4k*26 = 104k ICU bed-weeks available. There's been talk of 60% of the population getting infected to build up herd immunity [2] (somehow ignoring that there seems to be a nontrivial reinfection rate [3]), so almost 40 million people. It's not very clear how many infected people end up needing intensive care. In Italy, it was 10% of the people who tested positive [4]. But only the worst cases get tested once the epidemic is widespread, so let's say maybe 0.5% of the infected people need ICU (wild guess here since no country with a large number of infections is testing people with mild symptoms, but I think I'm being conservative). 0.5% of 40 million is 200k patients. If each of them need an ICU bed for 2 weeks, that's 400k bed-weeks.<p>Basically we're talking about most of the 6 months period of the NHS being overwhelmed and coronavirus having a high mortality rate.<p>[1] <a href="https://www.bbc.com/news/health-51714498" rel="nofollow">https://www.bbc.com/news/health-51714498</a><p>[2] <a href="https://www.independent.co.uk/news/health/coronavirus-herd-immunity-uk-nhs-outbreak-pandemic-government-a9399101.html" rel="nofollow">https://www.independent.co.uk/news/health/coronavirus-herd-i...</a><p>[3] <a href="https://www.reuters.com/article/us-china-health-reinfection-explainer/explainer-coronavirus-reappears-in-discharged-patients-raising-questions-in-containment-fight-idUSKCN20M124" rel="nofollow">https://www.reuters.com/article/us-china-health-reinfection-...</a><p>[4] <a href="https://www.statnews.com/2020/03/10/simple-math-alarming-answers-covid-19/" rel="nofollow">https://www.statnews.com/2020/03/10/simple-math-alarming-ans...</a></p>
]]></description><pubDate>Fri, 13 Mar 2020 11:08:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=22566330</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=22566330</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22566330</guid></item><item><title><![CDATA[New comment by lgeek in "OcherBook: Open-source replacement Kobo firmware"]]></title><description><![CDATA[
<p>> In case you mean the .fw file used in that driver, that's a misnomer. There is no CPU inside the EPDC. That .fw file is a plain voltage waveform file that defines voltage vs time waveforms to get pixels to appropriate graylevels. "Liberating" that would be akin to "liberating" the content of a .wav file. ie: just use hexdump -C.<p>I meant the waveform data at offset 0x700000 on the internal storage of the Kobo devices (which is similar but not the same as the .fw files in firmware/imx/). It's not clear whether distribution is allowed.</p>
]]></description><pubDate>Tue, 11 Apr 2017 08:32:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=14085861</link><dc:creator>lgeek</dc:creator><comments>https://news.ycombinator.com/item?id=14085861</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=14085861</guid></item></channel></rss>