<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: metmac</title><link>https://news.ycombinator.com/user?id=metmac</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 10 Jun 2026 02:38:05 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=metmac" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by metmac in "Saying goodbye to asm.js"]]></title><description><![CDATA[
<p>I’ll never forget watching Gary Bernhardt give his talk on JavaScript.[0] Was my introduction to asm.js, and the rabbithole associated with compiling code to run in the browser.<p>12 years on, it’s shocking how much of his fiction became reality.<p>[0] <a href="https://www.destroyallsoftware.com/talks/the-birth-and-death-of-javascript" rel="nofollow">https://www.destroyallsoftware.com/talks/the-birth-and-death...</a></p>
]]></description><pubDate>Wed, 20 May 2026 13:58:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=48207923</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=48207923</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48207923</guid></item><item><title><![CDATA[New comment by metmac in "Michael Rabin has died"]]></title><description><![CDATA[
<p>People keep adding different slurs. Awful and disgraceful.</p>
]]></description><pubDate>Sat, 18 Apr 2026 12:34:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=47815429</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=47815429</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47815429</guid></item><item><title><![CDATA[New comment by metmac in "The future of version control"]]></title><description><![CDATA[
<p><a href="https://loro.dev/" rel="nofollow">https://loro.dev/</a><p>Relevant. Loro a lovely CRDT library, explored implementing VCS semantics with CRDTs.</p>
]]></description><pubDate>Mon, 23 Mar 2026 14:42:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=47490224</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=47490224</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47490224</guid></item><item><title><![CDATA[New comment by metmac in "Netbird – Open Source Zero Trust Networking"]]></title><description><![CDATA[
<p>Do you foresee this changing anytime soon? Would love to contribute but also I think community adoption and contribution would go along way in terms of businesses less worried about single points of failure.<p>It’s hard balance to strike for sure. And it’s getting weirder by the day with agents.</p>
]]></description><pubDate>Sun, 01 Feb 2026 22:39:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=46850145</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=46850145</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46850145</guid></item><item><title><![CDATA[New comment by metmac in "Show HN: WebGPU React Renderer Using Vello"]]></title><description><![CDATA[
<p>This is nuts.
But give me some rope here, how much of react renders in Vello. Like is Vello taking the place of the shadow DOM here or is the entire DOM being render on a WASM thread somehow.<p>I have so many questions.</p>
]]></description><pubDate>Sun, 18 Jan 2026 01:18:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=46663875</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=46663875</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46663875</guid></item><item><title><![CDATA[New comment by metmac in "Show HN: Spliff – Correlating XDP and TLS via eBPF (Building a Linux EDR)"]]></title><description><![CDATA[
<p>Just came here to say this is awesome to see more folks do novel stuff with XDP!<p>After reading loophole labs post [0] a few months ago. I was hoping someone would cook on this for security research.<p>[0] <a href="https://loopholelabs.io/blog/xdp-for-egress-traffic" rel="nofollow">https://loopholelabs.io/blog/xdp-for-egress-traffic</a></p>
]]></description><pubDate>Sun, 18 Jan 2026 00:58:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=46663772</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=46663772</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46663772</guid></item><item><title><![CDATA[New comment by metmac in "Ask HN: Share your personal website"]]></title><description><![CDATA[
<p><a href="https://metmac.dev" rel="nofollow">https://metmac.dev</a><p>Click the ⌘⌥1 on the top right of the terminal or enter it on the keyboard for some fun code golfing.</p>
]]></description><pubDate>Thu, 15 Jan 2026 23:17:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=46640813</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=46640813</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46640813</guid></item><item><title><![CDATA[New comment by metmac in "Arborium: Tree-sitter code highlighting with Native and WASM targets"]]></title><description><![CDATA[
<p>I’m now just curious about your project</p>
]]></description><pubDate>Mon, 15 Dec 2025 12:43:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=46273734</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=46273734</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46273734</guid></item><item><title><![CDATA[New comment by metmac in "iOS 26.2 fixes 20 security vulnerabilities, 2 actively exploited"]]></title><description><![CDATA[
<p>I stand corrected on this front</p>
]]></description><pubDate>Sun, 14 Dec 2025 23:35:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=46268343</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=46268343</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46268343</guid></item><item><title><![CDATA[New comment by metmac in "iOS 26.2 fixes 20 security vulnerabilities, 2 actively exploited"]]></title><description><![CDATA[
<p>Genuinely didn’t know it was hidden behind a beta flag. Ty for this!</p>
]]></description><pubDate>Sun, 14 Dec 2025 23:29:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=46268284</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=46268284</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46268284</guid></item><item><title><![CDATA[New comment by metmac in "iOS 26.2 fixes 20 security vulnerabilities, 2 actively exploited"]]></title><description><![CDATA[
<p>Liquid Glass is now mandatory if you care about security. Sigh.<p>I wanted to like it too, but some of the new UI modals of iOS 26 are just awful.</p>
]]></description><pubDate>Sun, 14 Dec 2025 16:32:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=46264253</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=46264253</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46264253</guid></item><item><title><![CDATA[New comment by metmac in "Linux and Windows: A tale of Kerberos, SSSD, DFS, and black magic (2018)"]]></title><description><![CDATA[
<p>Now do this in containers with gMSAs. It eliminates the need of passing around Admin creds. Which I cannot stress enough. You shouldn’t be throwing your DA credentials into your random Linux machine’s Kerberos cache.<p>Amazon open sourced a project trying to solve similar problems.<p><a href="https://github.com/aws/credentials-fetcher" rel="nofollow">https://github.com/aws/credentials-fetcher</a><p>Nifty, but was clearly made with AWS assumptions and we had to roll our own with the various hooks we needed for our cloud infra.</p>
]]></description><pubDate>Sun, 02 Nov 2025 19:05:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=45792580</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=45792580</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45792580</guid></item><item><title><![CDATA[New comment by metmac in "Uv is the best thing to happen to the Python ecosystem in a decade"]]></title><description><![CDATA[
<p>UV and the crew at Astral really moved the Python packaging community forward.<p>I would love to see them compete with the likes of Conda and try to handle the Python C extension story.<p>But in the interim, I agree with everyone else who has already commented, Pixi which is partly built atop of UV’s solver is an even bigger deal and I think the longer term winner here.<p>Having a topologically complete package manager who can speak Conda and PyPi, is amazing.<p><a href="https://pixi.sh/latest/" rel="nofollow">https://pixi.sh/latest/</a></p>
]]></description><pubDate>Thu, 30 Oct 2025 01:27:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=45755380</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=45755380</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45755380</guid></item><item><title><![CDATA[New comment by metmac in "We saved $500k per year by rolling our own "S3""]]></title><description><![CDATA[
<p>I came here to say, this is exactly what I do also.<p>Unifi accidentally made a fantastic baby monitor.<p>The recent APIs they’ve built makes me hopeful that I could run an AI model against the footage eventually and build those Ai features for myself.</p>
]]></description><pubDate>Mon, 27 Oct 2025 11:26:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=45719718</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=45719718</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45719718</guid></item><item><title><![CDATA[New comment by metmac in "Show HN: Diagram as code tool with draggable customizations"]]></title><description><![CDATA[
<p>I really wish Mermaid would just ratify a layout spec. Make it optional. Use it. Great. Don’t use it. The layout engine does its thing.</p>
]]></description><pubDate>Sun, 26 Oct 2025 02:11:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=45708587</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=45708587</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45708587</guid></item><item><title><![CDATA[New comment by metmac in "Apple A17 Pro Chip Hardware Flaw?"]]></title><description><![CDATA[
<p>For what it’s worth. I have noticed oddities like this where digitizer partial failure and data being unavailable even after unlocking the device.<p>Only thing that fixes it, is a hard reboot.<p>I wonder if that is related to this flaw.</p>
]]></description><pubDate>Sun, 07 Sep 2025 19:22:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=45161331</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=45161331</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45161331</guid></item><item><title><![CDATA[New comment by metmac in "Show HN: Octelium – FOSS Alternative to Teleport, Cloudflare, Tailscale, Ngrok"]]></title><description><![CDATA[
<p>Will DM after I’ve had a chance to dig.</p>
]]></description><pubDate>Mon, 30 Jun 2025 00:55:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=44418083</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=44418083</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44418083</guid></item><item><title><![CDATA[New comment by metmac in "Show HN: Octelium – FOSS Alternative to Teleport, Cloudflare, Tailscale, Ngrok"]]></title><description><![CDATA[
<p>Depends on the industry. But many large enterprises in the Fortune 500 are actively trying to move away from your traditional VPN. (F5, Pulse, Cisco, etc).<p>Even with VPNs the question should be, what are we gating behind that VPN anyway. Does it actually give us the granularity of controls we want or is this all security theater. (Also what about hybrid infra, between the datacenter and cloud)<p>FWIW, my ideal architecture is Wireguard into Corp. (Ala CloudFlare Warp, Tailscale, etc) Corp doesn’t hold a ton of sensitive assets. Or put another way, it’s a lower trust tier.<p>And then using something like Teleport, Octelium, etc to reach production assets.<p>Admittedly no vendor product I’ve come across yet has bridged this gap nicely. The überProxy tend to focus on the application protocols they support. While the wireguard clients cares more about session control of the tunnel.</p>
]]></description><pubDate>Mon, 30 Jun 2025 00:54:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=44418075</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=44418075</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44418075</guid></item><item><title><![CDATA[New comment by metmac in "Show HN: Octelium – FOSS Alternative to Teleport, Cloudflare, Tailscale, Ngrok"]]></title><description><![CDATA[
<p>Reading through the docs. I feel like a lot of people are missing the value here. This could be a diamond in the rough if it actually delivers on its docs.<p>What enterprises want is to move away from perimeter based security models towards the promise that Google überProxy/BeyondCorp popularized many years ago. Which has been lost in the buzzword soup. It’s very simple.<p>1. A clean separation between Prod, Corp, and the public internet. And the UX to hop between them as an employee is as transparent as possible. (Often times network segmentation comes with additional painful friction for engineerings.)<p>2. One pipe to observe, and clearly attenuate permissions as traffic/messages flows between these boundaries.<p>3. Strong proofing of identity for every client, as an inherit requirement.<p>The problem is everyone outside Google has incredibly diverse protocol ecosystems. It makes those three promises incredibly difficult to deliver on as a vendor. (I’ve evaluated many)<p>To build a proxy that is protocol aware, only solves half the problem. It gets you some coarse grain decision making and a good logging story.<p>To build a proxy that is also able to perform type-inference at the request layer, allows for a much richer authZ story. One where businesses can build an authorization layer at the proxy better than their in-house apps could even do natively. (As it turns out, having all the predicates of the request available to a policy engine is super useful).<p>The docs are a little verbose, the marketing maybe isn’t amazing. But this is inherently a complex problem. No one has fully solved.<p>Teleport was first to the market to OSS and commercialize a lot of these ideas. 
StrongDM also is doing really interesting work in this space.
I wish Hashicorp had invested more in this space.<p>Disclaimer: my opinions are my own.</p>
]]></description><pubDate>Sun, 29 Jun 2025 19:36:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=44415706</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=44415706</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44415706</guid></item><item><title><![CDATA[New comment by metmac in "Show HN: Yami – An Open Source Music Player with Spotdl Integration"]]></title><description><![CDATA[
<p>Very nice. You could throw this on a Spotify Car thing.<p>Would love to see this land on a Pi Zero 2 inside a husked out iPod classic and a skinable UI to boot.<p>@gvy_dvpont (@dupontgu ?), did this a few years ago back with a Pi Zero one, but I believe the project has suffered a bit from hardware compatibility decay.</p>
]]></description><pubDate>Thu, 21 Nov 2024 15:21:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=42205146</link><dc:creator>metmac</dc:creator><comments>https://news.ycombinator.com/item?id=42205146</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42205146</guid></item></channel></rss>