<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: moviuro</title><link>https://news.ycombinator.com/user?id=moviuro</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 18 Apr 2026 14:39:25 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=moviuro" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by moviuro in "SSH certificates: the better SSH experience"]]></title><description><![CDATA[
<p>That sounds like a lot of extra steps. How do I validate the authenticity of a signing request? Should my signing machine be able to challenge the requester? (This means that the CA key is on a machine with network access!!)<p>Replacing the distribution of a revocation list with short-lived certificates just creates other problems that are not easier to solve. (Also, 1h is bonkers, even letsencrypt doesn't do it)</p>
]]></description><pubDate>Fri, 03 Apr 2026 16:51:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=47629045</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=47629045</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47629045</guid></item><item><title><![CDATA[New comment by moviuro in "SSH certificates: the better SSH experience"]]></title><description><![CDATA[
<p>All those articles about SSH certificates fall short of explaining how the revocation list can/should be published.<p>Is that yet another problem that I need to solve with syncthing?<p><a href="https://man.openbsd.org/ssh-keygen.1#KEY_REVOCATION_LISTS" rel="nofollow">https://man.openbsd.org/ssh-keygen.1#KEY_REVOCATION_LISTS</a></p>
]]></description><pubDate>Fri, 03 Apr 2026 15:40:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=47628040</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=47628040</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47628040</guid></item><item><title><![CDATA[A Shared Vision of Software Bill of Materials (SBoM) for Cybersecurity [pdf]]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.cisa.gov/sites/default/files/2025-09/joint-guidance-a-shared-vision-of-software-bill-of-materials-for-cybersecurity_508c.pdf">https://www.cisa.gov/sites/default/files/2025-09/joint-guidance-a-shared-vision-of-software-bill-of-materials-for-cybersecurity_508c.pdf</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45127281">https://news.ycombinator.com/item?id=45127281</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 04 Sep 2025 13:51:15 +0000</pubDate><link>https://www.cisa.gov/sites/default/files/2025-09/joint-guidance-a-shared-vision-of-software-bill-of-materials-for-cybersecurity_508c.pdf</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=45127281</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45127281</guid></item><item><title><![CDATA[Remote code execution in CentOS Web Panel – CVE-2025-48703]]></title><description><![CDATA[
<p>Article URL: <a href="https://fenrisk.com/rce-centos-webpanel">https://fenrisk.com/rce-centos-webpanel</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44367046">https://news.ycombinator.com/item?id=44367046</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 24 Jun 2025 15:05:51 +0000</pubDate><link>https://fenrisk.com/rce-centos-webpanel</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=44367046</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44367046</guid></item><item><title><![CDATA[New comment by moviuro in "Some Fritz!Box modems might have been hijacked"]]></title><description><![CDATA[
<p>Search forums local to your country and write documentation on how to use Linux or BSD as a modem.<p>For OpenBSD on Orange France FTTH: <a href="https://lafibre.info/remplacer-livebox/remplacer-sa-livebox-par-openbsd-128033-7-2-dual-stack/" rel="nofollow">https://lafibre.info/remplacer-livebox/remplacer-sa-livebox-...</a> or <a href="https://try.popho.be/securing-home2.html" rel="nofollow">https://try.popho.be/securing-home2.html</a></p>
]]></description><pubDate>Sun, 21 Apr 2024 16:02:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=40106794</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=40106794</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40106794</guid></item><item><title><![CDATA[New comment by moviuro in "Sudo for Windows"]]></title><description><![CDATA[
<p>OpenBSD's team has already reacted and added Word to OpenBSD<p>* <a href="https://marc.info/?l=openbsd-tech&m=170742832804260&w=2" rel="nofollow">https://marc.info/?l=openbsd-tech&m=170742832804260&w=2</a><p>* <a href="https://news.ycombinator.com/item?id=39309638">https://news.ycombinator.com/item?id=39309638</a></p>
]]></description><pubDate>Fri, 09 Feb 2024 08:43:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=39312761</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=39312761</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39312761</guid></item><item><title><![CDATA[New comment by moviuro in "AdGuard Home: Network-wide ad- and tracker-blocking DNS server"]]></title><description><![CDATA[
<p>Unbound with tags?<p>* <a href="https://unbound.docs.nlnetlabs.nl/en/latest/topics/filtering/tags-views.html" rel="nofollow">https://unbound.docs.nlnetlabs.nl/en/latest/topics/filtering...</a><p>* <a href="https://try.popho.be/securing-home3.html" rel="nofollow">https://try.popho.be/securing-home3.html</a><p>* <a href="https://git.sr.ht/~moviuro/moviuro.bin/tree/master/item/lie-to-us" rel="nofollow">https://git.sr.ht/~moviuro/moviuro.bin/tree/master/item/lie-...</a></p>
]]></description><pubDate>Tue, 06 Feb 2024 18:03:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=39277929</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=39277929</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39277929</guid></item><item><title><![CDATA[The Performance Inequality Gap, 2024]]></title><description><![CDATA[
<p>Article URL: <a href="https://infrequently.org/2024/01/performance-inequality-gap-2024/">https://infrequently.org/2024/01/performance-inequality-gap-2024/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=39201648">https://news.ycombinator.com/item?id=39201648</a></p>
<p>Points: 39</p>
<p># Comments: 14</p>
]]></description><pubDate>Wed, 31 Jan 2024 09:09:25 +0000</pubDate><link>https://infrequently.org/2024/01/performance-inequality-gap-2024/</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=39201648</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39201648</guid></item><item><title><![CDATA[New comment by moviuro in "A data corruption bug in OpenZFS?"]]></title><description><![CDATA[
<p>It's a very rare race condition, odds are very low that you were impacted. If you were, you would have noticed (heavy builds with files being moved around where suddenly files are zero).<p>[0] <a href="https://bugs.gentoo.org/917224" rel="nofollow noreferrer">https://bugs.gentoo.org/917224</a><p>[1] <a href="https://github.com/openzfs/zfs/issues/15526">https://github.com/openzfs/zfs/issues/15526</a> (referenced in the article)</p>
]]></description><pubDate>Tue, 26 Dec 2023 10:13:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=38770413</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=38770413</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38770413</guid></item><item><title><![CDATA[A data corruption bug in OpenZFS?]]></title><description><![CDATA[
<p>Article URL: <a href="https://despairlabs.com/blog/posts/2023-12-25-openzfs-data-corruption-bug/">https://despairlabs.com/blog/posts/2023-12-25-openzfs-data-corruption-bug/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=38770168">https://news.ycombinator.com/item?id=38770168</a></p>
<p>Points: 220</p>
<p># Comments: 111</p>
]]></description><pubDate>Tue, 26 Dec 2023 09:21:11 +0000</pubDate><link>https://despairlabs.com/blog/posts/2023-12-25-openzfs-data-corruption-bug/</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=38770168</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38770168</guid></item><item><title><![CDATA[New comment by moviuro in "Using Goatse to Stop App Theft"]]></title><description><![CDATA[
<p>See the explanation on the blog itself [0]<p>[0] <a href="https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQMQLbgFe%2BtjDytnXtZNF1EmSdAEEQIJTE3WE9GqozlGX56wuOZCMtiu7LXmbEc%2BEhdw9WCpxgcKjA9rEsiveiQA8UR3UcdrCCIbKSXdtKnE4A%2B4Yp1FS%2BHEuAFsMIKh3X6Q0o1S6Il914BHXvtY90BFcuclLGwDoeASmgL4viE9USavaGpo4SQcOpw4hKczlIBkt%2BBM8ta4L2ZwpLBXWcoBMOegQauULPqTXKScBhbBYDR2qAgwosW4pcY3imBWrq1RFsI7ZGQrYggeytHYFSwjGZvuxSyzunUBFgAA5B6l76NNGEimppydiGhMoS0IO6KP3OQUVW2RCogWq0yrXErk8ZTR1F6PrKcz0DlkVxZ6IqLzsTEmSAzd3y7np9vdmUcOcIKChHgk5SbmItQZFDlpnlfP60nrSN0gNGggdOrEYjyFDC0ntj8coQXj1DcAKcHKuloQZa5AAd7maXZowEnsO9yc7oCVZQe%2BQWsFcnMTnuQLYlfNhCLX1M9vT%2F8yWsnTkx9T9XL4tiGeYQWrsqgh0Fslg04ChSCV%2BlNwDfWCwDOKs8Sh9BhjA5l1n3iXJkBqqSZRVNZKTQUKQIvM0GRULvRxgwWH2V0mYj9V0n0QKH8b6RIZRFsdr33shM7fIjRPKEyWi2ln%2Fx5ssz1YnG509ry6KEElYTnOFM9xSSYjRQwujHLG1%2FnsmdUI5eb1wX6mjhRJqyKE5LuKNHhS37HNRnU20YlUIJn1Of9SDcztTz3SOo%2BikQk28qmq9F6iIlCjpnsUHFxVZii5rML6VHLYuzEm4MkBO8feKuo6Y4L%2BE3TPTrBThMuYV2MvFqsaFp5tAcWFCYQpU0mlsHSWzpDBLvM0a%2BdFhclLCZLnQea2oAt0oRfpjE4x8WFgu2bOFPSa5O3LYSUllLWxR7e3DDobFnP%2BZcDqwOriya1CyWL%2BEsiuu8xrJrOSKrl4a8tPU%2FEg2eHyjBvC6%2BRRGdQmubhpW%2BHzjVLr05Pv43t8OXxtsgRsJMEv%2FBwOEDTag2EwoDew9e5B4839O843BH5SxOttCH%2B2Ct%2FYllroLwreE01YrPfFWyBvtoZb4fHGdL312k1XJ%2BvT67OV%2Ff%2FnX59HFz%2BmX1xK%2FPbt5vvrxbba4e1182u4eRh25Tn979cRtW65uvMl5d9id0ezU%2F%2B%2Frs5vL35dvIdH7i7bfDMjdlbVs7b8RUFNY9T2GnroRbfMzdnL5bb69clDYn7Ozk8hxqhxFrpZhgAWcnv1zMaTAnU1%2BpHWZFjeRVhaGBKL3mf6ZGwr6COQQU8hbGSnoFJwPU0lriE9tizwlUmcYsqRWxO9nxFrt8ZhOwmHnaDLFCImrzWWXLLQPYXyRCchJ1WuRl8TcAAAD%2F%2FwMA1onjg2UHAAA%3D" rel="nofollow noreferrer">https://joshcsimmons.com/post/H4sIAAAAAAAA%2F3xV227cRgx911cQ...</a></p>
]]></description><pubDate>Tue, 17 Oct 2023 20:50:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=37921402</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=37921402</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37921402</guid></item><item><title><![CDATA[Pixel 8 and Pixel 8 Pro]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.google/products/pixel/google-pixel-8-pro/">https://blog.google/products/pixel/google-pixel-8-pro/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=37767340">https://news.ycombinator.com/item?id=37767340</a></p>
<p>Points: 25</p>
<p># Comments: 4</p>
]]></description><pubDate>Wed, 04 Oct 2023 16:16:05 +0000</pubDate><link>https://blog.google/products/pixel/google-pixel-8-pro/</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=37767340</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37767340</guid></item><item><title><![CDATA[Mashing Enter to bypass [FDE] with TPM, Clevis, dracut and systemd]]></title><description><![CDATA[
<p>Article URL: <a href="https://pulsesecurity.co.nz/advisories/tpm-luks-bypass">https://pulsesecurity.co.nz/advisories/tpm-luks-bypass</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=37347392">https://news.ycombinator.com/item?id=37347392</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 01 Sep 2023 06:08:41 +0000</pubDate><link>https://pulsesecurity.co.nz/advisories/tpm-luks-bypass</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=37347392</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37347392</guid></item><item><title><![CDATA[New comment by moviuro in "Factorio: Space Age"]]></title><description><![CDATA[
<p>> The signals required a lot of patience to learn and I'm not entirely sure I still understand them.<p>Chain signals before an intersection; regular signals after those, and on the track to split the track for multiple trains simultaneously.<p>See: <a href="https://wiki.factorio.com/Tutorial:Train_signals" rel="nofollow noreferrer">https://wiki.factorio.com/Tutorial:Train_signals</a> if you haven't already.</p>
]]></description><pubDate>Fri, 25 Aug 2023 13:58:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=37261798</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=37261798</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37261798</guid></item><item><title><![CDATA[New comment by moviuro in "Google will add E2E encryption to Authenticator backups"]]></title><description><![CDATA[
<p>> they lose the master password<p>The threat model for every lambda user having a password manager does not cover breaking and entering[0]: they should write down their master password and keep it at home in their bedroom drawer.<p>Use biometrics where possible (e.g. bitwarden on Android has that option)<p>[0] maybe it does for you, working on some DoD-confidential docs, but your computer-illiterate aunt doesn't.</p>
]]></description><pubDate>Thu, 27 Apr 2023 16:24:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=35730498</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=35730498</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35730498</guid></item><item><title><![CDATA[Usable systemd Timers for Mortals]]></title><description><![CDATA[
<p>Article URL: <a href="https://try.popho.be/systemd-timers.html">https://try.popho.be/systemd-timers.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=35133483">https://news.ycombinator.com/item?id=35133483</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 13 Mar 2023 10:00:45 +0000</pubDate><link>https://try.popho.be/systemd-timers.html</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=35133483</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35133483</guid></item><item><title><![CDATA[New comment by moviuro in "Initial support for guided disk encryption in OpenBSD installer"]]></title><description><![CDATA[
<p>It's only now added as an interactive step in the install script. It has ~always been possible to create a crypto device with the install medium by dropping to a shell: <a href="https://www.openbsd.org/faq/faq14.html#softraidFDE" rel="nofollow">https://www.openbsd.org/faq/faq14.html#softraidFDE</a></p>
]]></description><pubDate>Wed, 08 Mar 2023 08:43:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=35066711</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=35066711</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35066711</guid></item><item><title><![CDATA[New comment by moviuro in "Pure Storage Teases 300 TB Ultra-Large NVMe SSD with Tentative 2026 Launch"]]></title><description><![CDATA[
<p>> You can stack storage to your heart's content<p>Unless you actually hit the maximum your building can sustain (heat, volume). Building datacenters is incredibly expensive, so reusing existing infrastructure and packing it with more is actually important.</p>
]]></description><pubDate>Tue, 07 Mar 2023 17:45:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=35058464</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=35058464</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35058464</guid></item><item><title><![CDATA[New comment by moviuro in "Ask HN: How do you start over with 2FA after losing your phone?"]]></title><description><![CDATA[
<p>As specified when activating MFA, did you download (and print) your backup codes? If so, use them to re-enroll a new device into MFA.<p>If not, you can try reaching out to customer service after you get a new SIM card.<p>For banking and everything else IRL, you can just walk up to the teller with your ID.</p>
]]></description><pubDate>Tue, 07 Mar 2023 13:39:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=35055177</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=35055177</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35055177</guid></item><item><title><![CDATA[New comment by moviuro in "ssh whoami.filippo.io"]]></title><description><![CDATA[
<p>To make use of one different key per host, you can use some ssh_config(5) magic[0]:<p><pre><code>    IdentityFile ~/.ssh/keys/%h
</code></pre>
See also <a href="https://try.popho.be/ssh-keys.html" rel="nofollow">https://try.popho.be/ssh-keys.html</a> , discussed: <a href="https://news.ycombinator.com/item?id=32510475" rel="nofollow">https://news.ycombinator.com/item?id=32510475</a><p>[0] <a href="https://man.openbsd.org/ssh_config.5" rel="nofollow">https://man.openbsd.org/ssh_config.5</a></p>
]]></description><pubDate>Mon, 09 Jan 2023 09:08:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=34308314</link><dc:creator>moviuro</dc:creator><comments>https://news.ycombinator.com/item?id=34308314</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=34308314</guid></item></channel></rss>