HN2new | past | comments | ask | show | jobs | submit | rfmoz's commentslogin

Vis editor [0] also has multicursor and powerful sam's structural regular expression

[0]: https://github.com/martanne/vis


Yes, "everything is a file" but the mouse on Rio is written in stone.

Aside of that, plan9 wins on the theoretical side, it was a research OS, but in the practical one... it's opinionated.


Linux Firewalls by Steve Suehring covers nftables. It’s a good book to know the basics.


Give a try to Meshcore, their design has proven to be reliable in realworld use.


Chinese AI is doing large amounts of request in the past weeks.


how is this showing up for you? site you host or bigger scale? I'm not surprised but rather curious.


They had pretty neat infra, maybe it still runs in the same clever way. https://meta.stackexchange.com/questions/10369/which-tools-a...


Recently they've chucked out their own servers:

https://stackoverflow.blog/2025/12/24/the-great-unracking-sa...


Notably the default Redis client for most .NET developers is still StackExchange.Redis.


Quora, sadly, is a good example of enshittification.


Adding more security headers every year feels like strapping seatbelts onto a collapsing roller coaster. It would be better to stop this "sec headers stack" in favour of simpler, secure by default browser primitives with explicit opt-out. Getting an example from https://securityheaders.com the list nowadays is as follows:

- Strict-Transport-Security - Content-Security-Policy - X-Frame-Options - X-Content-Type-Options - Referrer-Policy - Permissions-Policy - Cross-Origin-Embedder-Policy - Cross-Origin-Opener-Policy - Cross-Origin-Resource-Policy


Yeah, redoing the defaults would probably be good.

On the other hand, I tried doing a Google search with javascript disabled today, and I learned that Google doesn't even allow this. (I also thought "maybe that's just something they try to pawn off on mobile browsers", but no, it's not allowed on desktop either.)

So the state of things for "how should web browsers work?" seems to be getting worse, not better.


Wow, I used to be able to search google even from terminal browsers like 'elinks'


I used elinks once to find a solution to an issue where the login screen was broken after an upgrade. I was able to switch to a virtual console, find out about the issue, identify the commands to fix the issue, and use them to resolve the issue.


I think it still works if you set your user agent to something like lynx. I had a custom UA set for Google search in Firefox just for this purpose and to disable AI overviews.


I just tried with the "links" browser and I get a "Update your browser. Your browser isn't supported anymore. To continue your search, upgrade to a recent version"


The reference of robots.txt offer a good way to define specific behavior for the whole domain, as example. Something like that for security could be enough for large amount of websites.

Also, a new header like “sec-policy: foo-url” may be a clean way to move away that definitions from the app+web+proxy+cdn mesh to a fixed clear point.


I reply myself because I've found that idea already porposed:

"Origin policy was a proposal for a web platform mechanism that allows origins to set their origin-wide configuration in a central location, instead of using per-response HTTP headers." - https://github.com/WICG/origin-policy

But their status is "[On hold for now]" since, at least, three years ago.


These files are just ignored by everything. We dont need .txt files, we need good defaults.


This is an extremely common approach across industries. Look into diesel engine emission control systems sometime if you aren't familiar. The last few decades has been bolting one new system on every dew years because the ones already added continue to cause unintended reliability problems.


CDNs manage user TLS certificates and that is one of the advantages of using them.

A node server could negociate https close to the user, do caching stuff and create an other https connection to your local server (or reuse an existing one).

Https everywhere with your CDN in middle.


They do in some way because the LaLiga blocking problems in Spain don’t affect the paid accounts=large websites.

An other suggestion is to do it along night shift in every country, right now they only take into account EEUU night.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: