<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: oneplane</title><link>https://news.ycombinator.com/user?id=oneplane</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 30 Jun 2026 08:08:47 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=oneplane" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by oneplane in "Lore – Open source version control system designed for scalability"]]></title><description><![CDATA[
<p>How is it crazy? It's perhaps not granular (the repository is the boundary, and that's that), but you can definitely restrict who can pull or push as easy as you can make rules for SSH.<p>Plenty of not-very-granular "enterprise" systems out there, it's not exactly unique to not always have full ACLs on the smallest of objects.</p>
]]></description><pubDate>Wed, 17 Jun 2026 19:23:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=48575472</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=48575472</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48575472</guid></item><item><title><![CDATA[New comment by oneplane in "MacBook Neo is so popular that Apple doubled production"]]></title><description><![CDATA[
<p>What are you even talking about. Every M1 Mac and earlier runs Linux. Even all the way back to PowerPC.<p>Granted, the M1 and up are not 100% covered yet (driver-wise), but they aren't EOL either. And if they were, Linux would still run anyway. Take a 20 year old Mac and you'll run Linux just fine. 10 year old Mac, Linux still runs fine. Take an M1 and it's a joy to use with Linux. Taken an M2 and it will boot and you can be pretty sure it will run very well long before it's EOL too. And even if it's EOL, it's not going to prevent you from running Linux later.<p>As for the PC example: definitely EOL problems there. Try getting your EDK2-based UEFI stack patched on an old computer. At some point you won't be getting certificate updates and if you either forget to install a local override or if the vendor didn't add it, you're SOL, especially on laptops where you can't disable secure boot.</p>
]]></description><pubDate>Wed, 03 Jun 2026 22:48:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=48391166</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=48391166</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48391166</guid></item><item><title><![CDATA[New comment by oneplane in "MacBook Neo is so popular that Apple doubled production"]]></title><description><![CDATA[
<p>Since SIP, it's MDM with DDM and you can basically leave engineers be local admins as it has no impact on the system state anymore.</p>
]]></description><pubDate>Wed, 03 Jun 2026 22:41:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=48391112</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=48391112</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48391112</guid></item><item><title><![CDATA[New comment by oneplane in "Ask HN: Shouldn't Google need to give a public statement about Railway incident?"]]></title><description><![CDATA[
<p>I'd rather go back to bare metal than use Azure.</p>
]]></description><pubDate>Wed, 20 May 2026 18:56:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=48212376</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=48212376</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48212376</guid></item><item><title><![CDATA[New comment by oneplane in "I Moved My Digital Stack to Europe"]]></title><description><![CDATA[
<p>Those local options exist, and have been around forever, but the problem is nobody is doing it without cutting corners and with pay-as-you-go elasticity (and the 'call an API, get a VM instantly' effects that go with it).<p>Most on-prem deployments were trash and a lot of them still are. Not because it couldn't be better but because it's easier to just have some random hypervisor department do this work manually and not do the work to create it as an internal product. Even VMware with vrealize failed and that's about as 'customisable cloud platform in a box' as COTS enterprise software can get.<p>Maybe it's because IaC and APIs were just not in the vocabulary of the average system integrator or on-prem operating team (it's still lots of clickops and copy-paste).</p>
]]></description><pubDate>Wed, 13 May 2026 14:04:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=48122054</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=48122054</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48122054</guid></item><item><title><![CDATA[New comment by oneplane in "I Moved My Digital Stack to Europe"]]></title><description><![CDATA[
<p>Not really, some of the IP is core to the product and it cannot function without it. In theory if you do something like come up with a complete replacement for EUV, you could, but everyone with deep pockets has already been trying to do that without success. Same goes for the supply chains, most companies (including ASML) don't manufacture everything themselves; so components that come out of the US would need non-US suppliers, which don't always exist.<p>I suppose it's a case of 'technically possible, realistically infeasible'.<p>A more likely scenario might be either a from-scratch not-as-good machine that you can source locally (supply-chain wise) or a novel finding (which is hard to predict if it will happen and if so, when).</p>
]]></description><pubDate>Wed, 13 May 2026 13:58:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=48121977</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=48121977</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48121977</guid></item><item><title><![CDATA[New comment by oneplane in "Show HN: boringBar – a taskbar-style dock replacement for macOS"]]></title><description><![CDATA[
<p>Which is why I wrote about running the exact UI that was referenced, with the same window server, window manager and desktop environment.</p>
]]></description><pubDate>Mon, 13 Apr 2026 11:49:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=47750686</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=47750686</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47750686</guid></item><item><title><![CDATA[New comment by oneplane in "Show HN: boringBar – a taskbar-style dock replacement for macOS"]]></title><description><![CDATA[
<p>That statement makes no sense. X11 works fine on macOS and running it in rootful mode with Gnome essentially works the same way it would work on an OS that uses the Linux kernel.<p>Granted, it will not integrate with anything hardware-wise by itself (unless there's a package for it - if not, macOS still handles it, and Aqua/Quartz will keep running in the background anyway), but if what you wanted was something that is KDE or GNOME running with its own WM on its own X11 server, doing the exact same thing you'd get if you're running a Linux distro, that's been natively possible for over 15 years.<p>If a power user loses their power based on what GUI happens to be in front of them, how much of a power user was the power user to begin with?</p>
]]></description><pubDate>Sun, 12 Apr 2026 19:51:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=47743705</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=47743705</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47743705</guid></item><item><title><![CDATA[New comment by oneplane in "France to ditch Windows for Linux to reduce reliance on US tech"]]></title><description><![CDATA[
<p>It does, it's called FreeIPA (or RedHat IdM). The only GPO parts it doesn't do are those that are not related to policy in the IAM sense (i.e. configuring some application related thing). There's other systems for that, just like on Windows you practically never run GPO without anything else. On top of that, you can pay RedHat or Canonical to host it all for you on any cloud or non-cloud.</p>
]]></description><pubDate>Fri, 10 Apr 2026 12:39:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47717227</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=47717227</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47717227</guid></item><item><title><![CDATA[New comment by oneplane in "Recover Apple Keychain"]]></title><description><![CDATA[
<p>Oh yeah, you got the same process down pretty much yourself, wasn't an RTFM dig or anything like that. It was more aimed at others who might end up here, more tools, more better!<p>It's interesting how with some systems/engineering thinking you'll pretty much always get there in the end anyway, which is also why articles like yours are pretty neat. (sadly, not everyone takes the time to write things down and share them these days)</p>
]]></description><pubDate>Tue, 31 Mar 2026 13:18:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=47586952</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=47586952</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47586952</guid></item><item><title><![CDATA[New comment by oneplane in "Recover Apple Keychain"]]></title><description><![CDATA[
<p>There is a lot of documentation from Apple on how all of this works, but this is indeed expected behaviour. A way to make this smoother would have been:<p><pre><code>  1. Doing the password reset
  2. Reboot straight back into recovery
  3. Update your new password back into your old password
  4. Boot into macOS, your default keychain will unlock but you'll still have to re-authenticate to iCloud since your machine-user identity combo will no longer match with what iCloud expects. (not sure if this is part of Octagon Trust, but there are various interesting layers to this)
</code></pre>
Check the escalation path of key revocation for example where you don't just have longer time delays but also stricter environments where new attempts can be made (near the end): <a href="https://support.apple.com/en-gb/guide/security/sec20230a10d/1/web/1" rel="nofollow">https://support.apple.com/en-gb/guide/security/sec20230a10d/...</a><p>There are a number of much more in-depth technical guides and specs, but just listing out random articles (or the Black Hat talk(s)) would probably rob someone of a nice excursion into platform security.</p>
]]></description><pubDate>Tue, 31 Mar 2026 00:14:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=47581264</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=47581264</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47581264</guid></item><item><title><![CDATA[New comment by oneplane in "Ask HN: Running legacy IE/ActiveX clients without local admin rights?"]]></title><description><![CDATA[
<p>Run it in a restricted VM, which is not joined to AD and cannot talk to it either. PAM will not save you, either will Airlock Digital or something like ATP or anything else like it.<p>Software for running VMs is free.<p>> Giving users local admin rights is a massive security risk we can't take.<p>Sounds like you made your endpoints into pets and bastions, that's an architecture that is guaranteed to fail. Work towards a design where the endpoint no longer matters.</p>
]]></description><pubDate>Thu, 26 Mar 2026 20:26:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=47535290</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=47535290</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47535290</guid></item><item><title><![CDATA[New comment by oneplane in "Agent Safehouse – macOS-native sandboxing for local agents"]]></title><description><![CDATA[
<p>That online builder is very cool, well done!<p>I've been trying out similar things to help internal teams to use systems and languages like Rego (for Open Policy Agent) to have a visual and more 'a la carte' experience when starting out, so they don't have to jump straight to learning all syntax and patterns for a language they might have never seen before.</p>
]]></description><pubDate>Mon, 09 Mar 2026 02:08:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=47304051</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=47304051</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47304051</guid></item><item><title><![CDATA[New comment by oneplane in "What's the difference between a "disc" and a "disk"? (2023)"]]></title><description><![CDATA[
<p>When they shrank the disc it just became minidisc ;-) But that was technically MO, not just optical. And: it was in a cartridge so I suppose they really should have called it minidisk.</p>
]]></description><pubDate>Thu, 12 Feb 2026 21:57:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=46995833</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=46995833</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46995833</guid></item><item><title><![CDATA[New comment by oneplane in "Ask HN: Notification Overload"]]></title><description><![CDATA[
<p>Don't enable anything you don't need. Use the OS-native priority modes; i.e. no Slack messages after 18:00, no general message notifications unless from specific contacts, disable web browser notifications universally etc. no notifications for unknown sources (seems to be an issue in some countries).<p>It also really depends on how you perceive the alerts on a device; some people have lots of feelings when they see a dot or a number on an icon, others might not care or give it any attention. If such things are a distraction for you, turn them off. Unless they give you value or have an important meaning, they are not worth your attention.<p>Depending on your hardware/software vendor, it might be capable of synchronisation between multiple devices so you don't end up getting notifications anyway, and it might have multiple profiles with time boxes, or location-aware or event-aware profiles. Some of them are self-learning (to various degrees of usefulness), but either way, reduce the device to what you need it for.</p>
]]></description><pubDate>Fri, 30 Jan 2026 02:58:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=46820047</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=46820047</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46820047</guid></item><item><title><![CDATA[New comment by oneplane in "Adafruit: Arduino’s Rules Are ‘Incompatible With Open Source’"]]></title><description><![CDATA[
<p>I think the comment mainly pointed out the distinction between education using digital methods, vs. educating about digital things.</p>
]]></description><pubDate>Mon, 15 Dec 2025 14:58:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=46275340</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=46275340</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46275340</guid></item><item><title><![CDATA[New comment by oneplane in "Linux on the Fujitsu Lifebook U729"]]></title><description><![CDATA[
<p>It's not a counterpoint, it's a display of your factually incorrect statement.</p>
]]></description><pubDate>Wed, 19 Nov 2025 14:39:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=45980083</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=45980083</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45980083</guid></item><item><title><![CDATA[New comment by oneplane in "Linux on the Fujitsu Lifebook U729"]]></title><description><![CDATA[
<p>> In other words, you're completely fucked if you brick your install. I consider iBoot a direct user-hostile downgrade from UEFI for this reason.<p>That's a bit of a creative perspective, isn't it? You have no control over the UEFI implementation of your vendor, same can be said for AGESA and ME, as well as any FSP/BSP/BUP packages, BROM signatures or eFused CPUs. And on top of that, you'll have preloaded certificates (usually from Microsoft) that will expire at some point, and when they do and the vendor doesn't replace them, the machine might never boot again (in a UEFI configuration where SecureBoot cannot be disabled as was the case in this Fujitsu - that took a firmware upgrade that the vendor had to supply, which is the exception rather than the rule). For DIY builds this tends to be better, Framework also makes this a tad more reliable.<p>If anything, most OEM UEFI implementations come with a (x509) timer that when expires, bricks your machine. iBoot2 is just a bunch of files (including the signed boot policy) you can copy and keep around, forever, no lifetimer.<p>Now, if we wanted to escape all this, your only option is to either get really old hardware, or get non-x86 hardware that isn't Apple M-series or IBM. That means you're pretty much stuck with low-end ARM and lower-end RISC-V, unless you accept AGESA or Intel ME at which point coreboot becomes viable.</p>
]]></description><pubDate>Sun, 16 Nov 2025 19:27:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=45947680</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=45947680</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45947680</guid></item><item><title><![CDATA[New comment by oneplane in "Linux on the Fujitsu Lifebook U729"]]></title><description><![CDATA[
<p>Only if you boot into macOS and connect it to the internet. iBoot2 never changes by itself, you, the user, decides if you want to boot into recovery or macOS and run an update.<p>So can Apple stop signing new iBoot2 versions? Sure! And that sucks. But it's a bit of FUD to claim that Apple at arbitrary points in time is going to brick your laptop with no option for you to prevent that.<p>Granted, if you boot both macOS and Asahi, then yes, you are in this predicament, but again, that is a choice. You can never connect macOS or recovery to the internet, or never boot them.</p>
]]></description><pubDate>Sun, 16 Nov 2025 15:16:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=45945702</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=45945702</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45945702</guid></item><item><title><![CDATA[New comment by oneplane in "Migrating from AWS to Hetzner"]]></title><description><![CDATA[
<p>Gee, another "we did not need cloud, so by not using cloud, we stopped spending on something we did not need"-story. Duh. The real story is why someone who doesn't need cloud services starts using them anyway.<p>If you need it, use it, if you don't need it, don't use it. It's not the big revelation people seem to think it is.</p>
]]></description><pubDate>Fri, 17 Oct 2025 13:54:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=45616863</link><dc:creator>oneplane</dc:creator><comments>https://news.ycombinator.com/item?id=45616863</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45616863</guid></item></channel></rss>