<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: omh</title><link>https://news.ycombinator.com/user?id=omh</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 30 Apr 2026 10:08:32 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=omh" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by omh in "IPv6 traffic crosses the 50% mark"]]></title><description><![CDATA[
<p>I'll take that bait ;-)<p>IP filtering is a valuable factor for security. I know which IPs belong to my organisation and these can be a useful factor in allowing access.<p>I've written rules which say that access should only be allowed when the client has both password <i>and</i> MFA <i>and</i> comes from a known IP address.
Why shouldn't I do that?<p>And there are systems which only support single-factor (password) authentication so I've configured IP filtering as a second factor. I'd love them to have more options but pragmatically this works.</p>
]]></description><pubDate>Thu, 16 Apr 2026 10:46:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=47791220</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=47791220</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47791220</guid></item><item><title><![CDATA[New comment by omh in "UK House of Lords attempting to ban use of VPNs by anyone under 16"]]></title><description><![CDATA[
<p>Thanks. That wasn't clear from the Mail article above.<p>But the Times article also says:<p>> A spokeswoman for Leicestershire police said crimes under Section 127 and Section 1 include “any form of communication” such as phone calls, letters, emails and hoax calls to emergency services.<p>So I think the categorisation is a mess, and probably not even consistent across forces</p>
]]></description><pubDate>Thu, 11 Dec 2025 22:48:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=46238412</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=46238412</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46238412</guid></item><item><title><![CDATA[New comment by omh in "UK House of Lords attempting to ban use of VPNs by anyone under 16"]]></title><description><![CDATA[
<p>This is based on statistics for the Malicious Communications Act. That includes people sending, for example, threatening messages to an ex partner.<p>Not all of them are online posts, in fact probably a minority</p>
]]></description><pubDate>Thu, 11 Dec 2025 22:36:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=46238268</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=46238268</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46238268</guid></item><item><title><![CDATA[New comment by omh in "Want to piss off your IT department? Are the links not malicious looking enough?"]]></title><description><![CDATA[
<p>And Microsoft own the client, so they are the one company who don't need to do this!<p>If you <i>really</i> want to check every time someone clicks on a link then you can do this in the client and keep the visible link the same for the end user.<p>But instead there are different teams working on this in Outlook, Teams, Exchange, Defender and god knows where else.<p>(I'm one of the people in corporate IT trying to turn this <i>off</i> and often struggling)</p>
]]></description><pubDate>Fri, 19 Sep 2025 12:05:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=45300658</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=45300658</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45300658</guid></item><item><title><![CDATA[New comment by omh in "Coffeematic PC – A coffee maker computer that pumps hot coffee to the CPU"]]></title><description><![CDATA[
<p>Many years ago we used a hot P4 to heat mulled wine.<p><a href="https://imgur.com/a/mulled-wine-pc-WW1pW" rel="nofollow">https://imgur.com/a/mulled-wine-pc-WW1pW</a><p>It could get to 60°C which is a bit low for coffee but was great for mulled wine</p>
]]></description><pubDate>Sat, 02 Aug 2025 15:22:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=44768370</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=44768370</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44768370</guid></item><item><title><![CDATA[New comment by omh in "Perceptually lossless (talking head) video compression at 22kbit/s"]]></title><description><![CDATA[
<p>One use case might be if you have limited bandwidth, perhaps only a voice call, and want to join a video conference. I could imagine dialling in to a conference with a virtual face as an improvement over no video at all.</p>
]]></description><pubDate>Fri, 08 Nov 2024 11:55:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=42086144</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=42086144</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42086144</guid></item><item><title><![CDATA[New comment by omh in "Canarytokens: Honeypot for critical credentials, get notified when they are used (2015)"]]></title><description><![CDATA[
<p>Spying how?<p>If you embed a URL in emails then a lot of corporate email gateways will blindly follow the link, trying to check it for malware.<p>This may or may not be a useful security measure but it has many issues. One of which is that it could look like spying.</p>
]]></description><pubDate>Tue, 30 Jul 2024 14:19:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=41109461</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=41109461</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41109461</guid></item><item><title><![CDATA[New comment by omh in "Second factor SMS: Worse than its reputation"]]></title><description><![CDATA[
<p>Good point.<p>But what's the threat model here?<p>I didn't think of 2FA as being protection against password reuse. People should still avoid reusing passwords and change them if they know of a breach.<p>Are there really attackers who are picking up breach databases and then sim-swapping to get the 2FA as well?</p>
]]></description><pubDate>Thu, 11 Jul 2024 15:18:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=40937652</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=40937652</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40937652</guid></item><item><title><![CDATA[New comment by omh in "Second factor SMS: Worse than its reputation"]]></title><description><![CDATA[
<p>The article conflates two issues that have different security implications.<p>The "1-click login" links are a concern and just having access to the SMS would be enough to take over things like WhatsApp.<p>But 2FA codes seem notably less worrying.
They are the <i>second</i> factor and require an attacker to have the password too. 
For these cases I'm much more relaxed about the use of SMS and the risks of interception.</p>
]]></description><pubDate>Thu, 11 Jul 2024 15:10:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=40937580</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=40937580</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40937580</guid></item><item><title><![CDATA[New comment by omh in "Gavin Newsom wants to take smartphones out of schools"]]></title><description><![CDATA[
<p>I agree that it would be fine to not have phones - we'd all cope.<p>But when my daughter hasn't got home on time if I can check her GPS and see that she's in the park then I can relax a little.<p>If she needs to say she's staying out late, using a group chat to let the whole family know is easier than trying to phone mum, then dad, then grandma.<p>Or she can include a photo showing how much fun she's having.<p>My life is richer because of communication on things like family group chats. 
It would be a shame to throw the baby out with the bathwater and lose that</p>
]]></description><pubDate>Tue, 18 Jun 2024 15:37:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=40719063</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=40719063</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40719063</guid></item><item><title><![CDATA[New comment by omh in "Gavin Newsom wants to take smartphones out of schools"]]></title><description><![CDATA[
<p>There is a potential clash here between control and privacy.<p>A few years ago Apple blocked[1] some parental control apps because "they put users’ privacy and security at risk"<p>This actually came up with our school. They tried to use an app to control student phones but it was fundamentally limited by these Apple restrictions.<p>[1] <a href="https://www.apple.com/uk/newsroom/2019/04/the-facts-about-parental-control-apps/" rel="nofollow">https://www.apple.com/uk/newsroom/2019/04/the-facts-about-pa...</a></p>
]]></description><pubDate>Tue, 18 Jun 2024 15:33:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=40719022</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=40719022</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40719022</guid></item><item><title><![CDATA[New comment by omh in "Gavin Newsom wants to take smartphones out of schools"]]></title><description><![CDATA[
<p>This debate seems to conflate two or three different issues.<p>1. Use of phones in classrooms
2. Having phones present in schools, but unused
3. The impact of social media on schoolchildren<p>(1) is undeniably bad and should be banned everywhere.<p>(2) raises some issues. I don't want (1) but I would like my child to have a phone for the journey to and from school. And a smartphone is much better at this than a dumb phone (group chats are really good!)<p>(3) is a concern but it seems almost totally unrelated to the other issues.
The children who are banned from having a phone at school will use the same social media when they're at home and schools will still have to deal with bullying.<p>Our school current bans (1) and is consulting on more bans. But from parent discussions it feels like both the school and parents are mixing up these issues and just coming back with "phones are bad".</p>
]]></description><pubDate>Tue, 18 Jun 2024 15:21:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=40718828</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=40718828</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40718828</guid></item><item><title><![CDATA[New comment by omh in "My insulin pump controller has a bug"]]></title><description><![CDATA[
<p>Also it would be very possible to misread the confirmation.<p>If I've just entered "0.21" then when the confirmation screen reads "21" it's not immediately obvious that it's wrong.</p>
]]></description><pubDate>Fri, 01 Dec 2023 14:29:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=38487053</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=38487053</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38487053</guid></item><item><title><![CDATA[New comment by omh in "My insulin pump controller has a bug"]]></title><description><![CDATA[
<p>Yes.<p>A typical pump will contain enough for several days. My pump right now has 100 units and is only half full.</p>
]]></description><pubDate>Fri, 01 Dec 2023 13:08:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=38486241</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=38486241</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38486241</guid></item><item><title><![CDATA[New comment by omh in "My insulin pump controller has a bug"]]></title><description><![CDATA[
<p>I've got this Tandem pump and we discussed this exact bug when I received the pump.<p>To my understanding this isn't the same type of bug.
Tandem are just saying "it can be confusing to enter fractional rates".<p>This bug is for a different pump and is "when you enter a fraction rate it will <i>change the rate</i>". That is much worse</p>
]]></description><pubDate>Fri, 01 Dec 2023 13:06:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=38486226</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=38486226</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38486226</guid></item><item><title><![CDATA[New comment by omh in "My insulin pump controller has a bug"]]></title><description><![CDATA[
<p>A clearer description of the bug is here:<p><a href="https://twitter.com/Tims_Pants/status/1730515134731182490" rel="nofollow noreferrer">https://twitter.com/Tims_Pants/status/1730515134731182490</a><p>It's wild that this sort of bug got through testing.<p>As a diabetic it feels like our insulin pump software is very conservative and lacking in features especially compared to what some of the "closed loop" things would like to do.<p>That seems reasonable if the manufacturers are having to do lots of safety testing.<p>But if bugs like this are getting through then the testing obviously isn't anywhere near as robust as we'd like.</p>
]]></description><pubDate>Fri, 01 Dec 2023 13:03:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=38486206</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=38486206</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38486206</guid></item><item><title><![CDATA[New comment by omh in "London Street Trees"]]></title><description><![CDATA[
<p>As a slightly more frivolous use of this website - we're approaching conker season!<p>Last year my kids wanted to go collecting conkers and I used a similar website (<a href="https://www.treetalk.co.uk/" rel="nofollow noreferrer">https://www.treetalk.co.uk/</a>) to find a local place with lots of horse chestnuts.<p>It worked brilliantly and the kids thought I was some kind of genius for finding so many.</p>
]]></description><pubDate>Fri, 08 Sep 2023 10:09:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=37431718</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=37431718</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37431718</guid></item><item><title><![CDATA[New comment by omh in "Ask HN: Indoor air quality sensors and other IoT that's local-first and not DIY?"]]></title><description><![CDATA[
<p>I have the Awair Element and I'm reasonably happy with it.<p>The primary interface is through their app and I think you might need to use this to get it up and running initially.
But they have a supported local API feature[1] that has so far worked as I'd expect.
In the end I've been happy with their app so have primarily used that so far. The data seems good.<p>They're quite expensive new.
But they were involved in some sort of cryptocurrency (!) that failed. So there are a <i>lot</i> of them available as nearly-new on eBay. In the UK I picked one up for about £60, I think.<p>[1] <a href="https://support.getawair.com/hc/en-us/articles/360049221014-Awair-Element-Local-API-Feature" rel="nofollow">https://support.getawair.com/hc/en-us/articles/360049221014-...</a></p>
]]></description><pubDate>Mon, 28 Nov 2022 15:23:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=33774700</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=33774700</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33774700</guid></item><item><title><![CDATA[New comment by omh in "UK government ban for Chinese Hikvision CCTV cameras"]]></title><description><![CDATA[
<p><i>Even in this dual-homed setup, there is still the potential for the cameras to infect, or otherwise compromise the recording server</i><p>I agree that this is a potential risk.<p>But if the cameras themselves can't route to the internet in this scenario then how are they infecting the recording server?
Is the suggestion that they come shipped from the factory with code to compromise common recording servers? It seems like that would be very significant and something that we'd be able to see in action.<p>My biggest concern with CCTV networks that I manage is some sort of backdoor access to the cameras themselves. So the dual-homed server design is exactly what I'd choose in order to control things.</p>
]]></description><pubDate>Fri, 25 Nov 2022 16:59:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=33744340</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=33744340</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33744340</guid></item><item><title><![CDATA[New comment by omh in "Show HN: Tracking my local bus with a RaspberryPi"]]></title><description><![CDATA[
<p>I love the form factor of this and the ambient data.<p>TFL do have some quite good APIs so you could use those rather than scraping the HTML.<p><a href="https://tfl.gov.uk/info-for/open-data-users/api-documentation" rel="nofollow">https://tfl.gov.uk/info-for/open-data-users/api-documentatio...</a><p>I think you need to register but they seem happy to have amateurs and enthusiasts using them and they work quite well.</p>
]]></description><pubDate>Fri, 04 Nov 2022 12:32:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=33465507</link><dc:creator>omh</dc:creator><comments>https://news.ycombinator.com/item?id=33465507</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33465507</guid></item></channel></rss>