What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

0
0
0
0
0
0
0
0
0
0
0
1

A few days ago, a client’s data center (well, actually a server room) "vanished" overnight. My monitoring showed that all devices were unreachable. Not even the ISP routers responded, so I assumed a sudden connectivity drop. The strange part? Not even via 4G.

I then suspected a power failure, but the UPS should have sent an alert.

The office was closed for the holidays, but I contacted the IT manager anyway. He was home sick with a serious family issue, but he got moving.

To make a long story short: the company deals in gold and precious metals. They have an underground bunker with two-meter thick walls. They were targeted by a professional gang. They used a tactic seen in similar hits: they identify the main power line, tamper with it at night, and send a massive voltage spike through it.

The goal is to fry all alarm and surveillance systems. Even if battery-backed, they rarely survive a surge like that. Thieves count on the fact that during holidays, owners are away and fried systems can't send alerts. Monitoring companies often have reduced staff and might not notice the "silence" immediately.

That is exactly what happened here. But there is a "but": they didn't account for my Uptime Kuma instance monitoring their MikroTik router, installed just weeks ago. Since it is an external check, it flagged the lack of response from all IPs without needing an internal alert to be triggered from the inside.

The team rushed to the site and found the mess. Luckily, they found an emergency electrical crew to bypass the damage and restore the cameras and alarms. They swapped the fried server UPS with a spare and everything came back up.

The police warned that the chances of the crew returning the next night to "finish" the job were high, though seeing the systems back online would likely make them move on. They also warned that thieves sometimes break in just to destroy servers to wipe any video evidence.

Nothing happened in the end. But in the meantime, I had to sync all their data off-site (thankfully they have dual 1Gbps FTTH), set up an emergency cluster, and ensure everything was redundant.

Never rely only on internal monitoring. Never.

0
0
0

Finale!

Blaubeere
vs
Erdbeere

Die Blaubeere ist eine echte Beere.
Saison ist hier von Ende Juni bis September, Waldheidelbeeren oft kürzer im Juli und August, Kulturheidelbeeren bis in den Herbst.
Außerhalb besser zu Tiefkühlware greifen, "frische" Blaubeeren werden dann nämlich aus Südamerika importiert.

Die Erdbeer-Saison von Mai bis Juli mit Höhepunkt im Juni ist dank der vielen Erdbeer-Stände kaum zu übersehen.
Die Erdbeere ist eine Sammelnussfrucht.

0
0
0
1
0

Information about Aggressive, Racist, & Ableist Bluesky User Moving to Mastodon

I was informed that a user who harassed me & others on Bluesky has moved to Mastodon, claiming she was "chased off". For transparency, I'm copy-pasting my TLDR post from Bluesky.

Mizokaya (Mizore Nakaya) is prone to aggressive behavior & violent language and, in my case, she was racist and ableist towards me. She also implied that I'm being transphobic for sharing an article from The Guardian.

A screenshot of Mizore Nakaya's main account, mizokaya.tech.lgbt. Her bio states: "She/her, Trans. British Streamer. Twitch Industry critic. Photographer, Former owner of the Vsky Discord."A screenshot of Mizore Nakaya's alternate account, mizokaya.vt.social. Her bio states: "22, She/they, Autistic/Neurodivergent. Streamer. Twitch Industry critic and Aerospace lover. VCG Leader."A screenshot of Mizore Nakaya's claim that she got chased off Vsky Bluesky. She states: "Guess who got chased off Vsky Bluesky. So much for a united community against bigotry."
0
0
0
0
1
0

This New York Times video journalism -- caution, it's graphic -- about Trump goons' murder of a Minneapolis woman is essential. No both-sides bullshit when one party -- the regime and its vile propagandists -- is relentlessly and provably lying.

I'm often hard on the Times for its relentless failures to properly cover this regime, but this piece is the real thing.

nytimes.com/video/us/100000010

0
0
0
0
0
0
0
0

It's hard to make sense of stories about how AI code generation doesn't work when my default PDF reader is now one that ChatGPT wrote for me after 30 years of dissatisfaction with every other PDF reader. (Based on PDFKit of course.)

I didn't ask for a lot. Small features like:

I wanted right click on *internal* links to open the target *in the same document* in a new window so I can read linked notes without upsetting my main reading flow.

Super-light persistent bookmarks modelled on vi's <m> and <'>.

0
0
0
0
0

My two cats love watching birds come to my window feeder, but when they get excited and jump at the window, the birds get scared and fly away.

This disappoints my cats.

Squirrels, on the other hand, appear to understand glass, and show no fear as they sit in the feeder for anything up to an hour, while two predators stare at them and try to scratch through the glass to murder them.

0
0
0
0

Has anyone compiled the privacy policies of various LLM platforms, ideally in a comprehensive way? OpenAI said today that private health data and conversations shared by ChatGPT Health won't be used for training purposes. Does this mean OpenAI won't sell it either or give it to law enforcement when presented with a warrant? What about other AI chat services.

I'm looking for responses from experienced privacy professionals or advocates with empirical data. Please, no responses airing cynicism or grievances about AI privacy in general, no matter how valid.

openai.com/index/introducing-c

0
1
0
1
0

It only took me a few days to be fed up with mailbox.org and cancel, which I couldn't even find in the UI and had to (sigh) ask a plagiarism machine.

- Painfully slow.
- Endless UI glitches.
- Confusing payment, plan upgrade, and renewal process.
- Support UI is partly not even in the language I selected.

Let's see if Fastmail is better. Luckily the switch was easier, although the alias setup in the UI was extremely confusing, so off to a bumpy onboarding. Hopefully it's the only hurdle.

0
0
0
0
0
0
0

@zkatkat today I learned that Zod, a schema validation library for JS/TS, has CLAUDE.MD, AGENTS.MD, and .cursorrules in its GitHub repo. It is also sponsored by multiple AI startups.

github.com/colinhacks/zod

Unfortunately, I don’t know of any good alternatives off the top of my head

0
0
0
0
0