<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: merpkz</title><link>https://news.ycombinator.com/user?id=merpkz</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 30 Jul 2026 06:42:52 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=merpkz" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by merpkz in "Securing Services with Rootless Containers"]]></title><description><![CDATA[
<p>That privileged port thing is not true anymore for Docker created containers, since it lowers that limit and unprivileged containers can listen on any port.<p><pre><code>  docker run -ti --rm --user 1000:1000 --privileged=false alpine:latest
  ~ $ cat /proc/sys/net/ipv4/ip_unprivileged_port_start
  0
  ~ $ id
  uid=1000 gid=1000 groups=1000
  ~ $ nc -lvp 80
  listening on [::]:80 ...
</code></pre>
Also the iptable rules Docker creates is for routing traffic to container with destination NAT, to actually limit traffic you have to do it yourself by inserting rules in DOCKER_USER chain.</p>
]]></description><pubDate>Tue, 28 Jul 2026 11:06:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=49082119</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=49082119</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49082119</guid></item><item><title><![CDATA[New comment by merpkz in "Securing Services with Rootless Containers"]]></title><description><![CDATA[
<p>That is what I have been thinking too about recent linux vulnerabilities in context of container escape, but upon brief research I am not convinced it's all that straightforward. For example here <a href="https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC" rel="nofollow">https://github.com/Percivalll/Dirty-Frag-Kubernetes-PoC</a> relies on sharing same container layers with other privileged workloads, which is quite a stretch to find in the wild and moreso it says that having a seccomp enabled breaks the exploit - "The default seccomp policy disables the unshare syscall." Other thing is that temporary remedy to lot of these exploits is to blacklist esp4, esp6, algif_aead modules, but how on earth are they going to be loaded in host kernel, which they are not by default, from unprivileged container in first place?</p>
]]></description><pubDate>Tue, 28 Jul 2026 10:53:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=49082032</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=49082032</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49082032</guid></item><item><title><![CDATA[New comment by merpkz in "Google Books (or similar) all book scans – $200k bounty (2025)"]]></title><description><![CDATA[
<p>Copy data into extra large capacity micro sdcard and hide it in your rubiks cube, nobody will suspect a thing</p>
]]></description><pubDate>Sat, 04 Jul 2026 18:56:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=48787873</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48787873</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48787873</guid></item><item><title><![CDATA[New comment by merpkz in "EU to legislate about Chat Control behind closed doors"]]></title><description><![CDATA[
<p>What's in there for these people to push for chat control of all things?</p>
]]></description><pubDate>Tue, 30 Jun 2026 10:33:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48730710</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48730710</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48730710</guid></item><item><title><![CDATA[New comment by merpkz in "Framework's 10G Ethernet module exposes USB-C's complexity"]]></title><description><![CDATA[
<p>Raspberry Pi 4 doesn't need a fan. People just like to put them on because because micromanaging CPU temperature is part of the hobby for some. Yes it might throttle its CPU speed when going full tilt for some time, but lets be real how many workloads require poor Raspberry Pi to be loaded 100% for prolonged periods of time?</p>
]]></description><pubDate>Fri, 26 Jun 2026 06:27:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=48683042</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48683042</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48683042</guid></item><item><title><![CDATA[New comment by merpkz in "How we run Firecracker VMs inside EC2 and start browsers in less than 1s"]]></title><description><![CDATA[
<p>It's not. Fertile land is as valuable as ever and all bought up. Every season you are at the mercy of weather, new government regulations and subsidy rules, corporate overlords with repairs of your agricultural machinery and in the end price of your produce being dictated by same speculative market assholes ruining everything. It sucks, software people have it easy in comparison.</p>
]]></description><pubDate>Fri, 19 Jun 2026 06:39:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=48595526</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48595526</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48595526</guid></item><item><title><![CDATA[New comment by merpkz in "Stop Killing Games fails to secure EU law despite 1.3M signatures"]]></title><description><![CDATA[
<p>Ah, the same guy who promised to end wars, that sounds good</p>
]]></description><pubDate>Wed, 17 Jun 2026 07:07:42 +0000</pubDate><link>https://news.ycombinator.com/item?id=48566853</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48566853</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48566853</guid></item><item><title><![CDATA[New comment by merpkz in "Humiliating IIS servers for fun and jail time"]]></title><description><![CDATA[
<p>"This is the brute-force fallback when the smart approaches fail, and honestly, it works more often than you’d expect."<p>Found the LLM generated part.</p>
]]></description><pubDate>Wed, 17 Jun 2026 06:12:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=48566412</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48566412</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48566412</guid></item><item><title><![CDATA[New comment by merpkz in "The Pirate Bay Remains Resilient, 20 Years After the Raid"]]></title><description><![CDATA[
<p>Isn't that just Cloudflare? thepiratebay.org resolves to CF IPs at the moment.</p>
]]></description><pubDate>Tue, 02 Jun 2026 14:48:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48371003</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48371003</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48371003</guid></item><item><title><![CDATA[New comment by merpkz in "Removing the modem and GPS from my 2024 RAV4 hybrid"]]></title><description><![CDATA[
<p>There is no way that is true, basic cars have always existed, like Dacia with bare minimum features to pass all requirements and they are far from being popular. The fact of the matter is, is that people just like fancy things and cars especially</p>
]]></description><pubDate>Fri, 15 May 2026 10:19:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48146809</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48146809</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48146809</guid></item><item><title><![CDATA[New comment by merpkz in "Removing the modem and GPS from my 2024 RAV4 hybrid"]]></title><description><![CDATA[
<p>I honestly can't either. A lot of people drive around with navigation set on their phones which also track every movement and knows your exact location and travel speed, might even know how aggressive you drive based on accelerometer data and all that info can be uploaded from navigation app like Waze which is very popular</p>
]]></description><pubDate>Fri, 15 May 2026 10:16:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=48146787</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48146787</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48146787</guid></item><item><title><![CDATA[New comment by merpkz in "Removing the modem and GPS from my 2024 RAV4 hybrid"]]></title><description><![CDATA[
<p>How will they get access to this data? Hax into Toyota to track this one specific Rav4?</p>
]]></description><pubDate>Fri, 15 May 2026 10:14:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=48146767</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48146767</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48146767</guid></item><item><title><![CDATA[New comment by merpkz in "Poland is now among the 20 largest economies"]]></title><description><![CDATA[
<p>First time I hear this explanation of why demographics is in decline in Europe and it kind of makes sense, every so often having this discussion about having children people bring up that they wont be able to enjoy things anymore, like travel, which in itself is a form of consumerism - buying the "experience"</p>
]]></description><pubDate>Fri, 08 May 2026 14:25:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=48063723</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48063723</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48063723</guid></item><item><title><![CDATA[New comment by merpkz in "Nintendo announces price increases for Nintendo Switch 2"]]></title><description><![CDATA[
<p>What a wild statement, how much you have to eat in Japan to offset the airline ticket prices?</p>
]]></description><pubDate>Fri, 08 May 2026 11:40:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=48061701</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48061701</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48061701</guid></item><item><title><![CDATA[New comment by merpkz in "Valve releases Steam Controller CAD files under Creative Commons license"]]></title><description><![CDATA[
<p>I played through whole Half-Life 2 on steam deck with aiming and shooting using right touch pad and it was alright. Strongly suspect though the game should have a support for it properly otherwise it feels janky in everything else I tried with it. No idea what's the use case for left pad though - I sometimes play with it during loading screens due to nice sound it makes, that's about it</p>
]]></description><pubDate>Thu, 07 May 2026 10:13:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48047580</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48047580</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48047580</guid></item><item><title><![CDATA[New comment by merpkz in "Should I Run Plain Docker Compose in Production in 2026?"]]></title><description><![CDATA[
<p>Well, as an example we usually set incoming rules to filter SSH only from administrator IP addresses, TCP 10050 only from zabbix monitoring server and leave few icmp types required and rest is dropped and logged.<p>For forward chain we set docker network ranges to route between themselves and only services actually used in containers. Allow container outgoing connections to our DNS servers, centralized HTTP proxy server and monitoring - nothing else containers are allowed to route to.<p>And for output is similar, only allow our DNS servers, NTP, HTTP proxy, centralized rsyslog where everything goes and zabbix monitoring server and a few icmp types - nothing else gets out and is logged.<p>With the advent of these supply chain attacks we read about often here it's just a matter of time some container is compromised and this seems like only viable way to at least somehow limit impact when such an event occurs.</p>
]]></description><pubDate>Tue, 05 May 2026 12:33:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=48021612</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48021612</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48021612</guid></item><item><title><![CDATA[New comment by merpkz in "Should I run plain Docker Compose in production in 2026?"]]></title><description><![CDATA[
<p>How do you guys, who run Docker in production deal with managing nftables firewall on hosts running containers? By design docker daemon creates and manages a set of firewall rules to forward traffic between containers and ingress traffic into containers as well as masquarades the outgoing container traffic. That is all well until admin needs to alter hosts firewall to allow and deny other traffic unrelated to docker - and restarting nftables or even applying new nftables rules usually ( flush ruleset in /etc/nftables.conf ) purges all the docker created rules and effectively breaks everything until docker daemon is restarted and rules re-created. I have partially solved this by using nftables filter chains with different names - admin_input/admin_output and using input hook with negative priority - so that traffic I choose to block is evaluated before docker rules are applied - that feels a bit like hack, but so far is the only way I have found. It is good practice in this day and age to run local firewalls on all hosts with policy deny, so that only traffic explicitly allowed can pass, that can severely limit blast radius during compromise.</p>
]]></description><pubDate>Tue, 05 May 2026 11:56:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=48021239</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=48021239</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48021239</guid></item><item><title><![CDATA[New comment by merpkz in "IPv6 traffic crosses the 50% mark"]]></title><description><![CDATA[
<p>As if people doesn't already carry always online machine in their pockets</p>
]]></description><pubDate>Thu, 16 Apr 2026 11:19:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47791461</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=47791461</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47791461</guid></item><item><title><![CDATA[New comment by merpkz in "IPv6 traffic crosses the 50% mark"]]></title><description><![CDATA[
<p>How does IP bans work in IPv6 case? One just blocks whole /64 or /56 address range?</p>
]]></description><pubDate>Thu, 16 Apr 2026 11:10:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=47791388</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=47791388</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47791388</guid></item><item><title><![CDATA[New comment by merpkz in "Meta Platforms: Lobbying, dark money, and the App Store Accountability Act"]]></title><description><![CDATA[
<p>> Some kids will be trafficked with the help of all these tech solutions, because they know exactly where your kids are at every moment.<p>What the hell are you talking about? They already know where my kids are! At school which is funded by government.</p>
]]></description><pubDate>Tue, 17 Mar 2026 14:10:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=47412923</link><dc:creator>merpkz</dc:creator><comments>https://news.ycombinator.com/item?id=47412923</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47412923</guid></item></channel></rss>