Hacker Newsnew | past | comments | ask | show | jobs | submit | polard2's commentslogin

Since Ubuntu doesn’t come with a firewall enabled by default, your postfix server is listening on all interfaces for mail immediately. The mynetworks configuration should prevent relaying, but any potential vulnerabilities in your postfix daemon are exposed to the network without your consent. I would prefer to configure postfix first before I ever allow it to run on my server

Technically, if security is your focus, then shouldn't one of your first actions after setting up a new machine be to set iptables default action to drop all incoming new,invalid packets anyway? I mean, I generally install server with nothing. Set up iptables. Then install packages and open ports.


> Technically, if security is your focus, then shouldn't one of your first actions after setting up a new machine be to set iptables default action to drop all incoming new,invalid packets anyway?

But why expect the user to do that themselves? Shouldn't security be the default, with a secure configuration provided out of the box?

Giving the user a secure configuration which they can then opt out of if they wish does better by the user than giving them an insecure configuration and then asking them to opt in to security does.


If the user can't do that, then the user is not going to have the chops to configure Postfix anyway.

Seriously, Debian is the upstream distro does this, and it's the other linux grandparent with RHEL. It's been around for decades, used in production the same way RHEL and BSD are, and we haven't had debian-based boxes compromised left, right, and centre with these 'insecure' defaults. The threat is imaginary, and not born out in real world numbers.


> Since Ubuntu doesn’t come with a firewall enabled by default, your postfix server is listening on all interfaces for mail immediately.

But Ubuntu doesn't come with a postfix server enabled by default, so that's not really a concern, is it?


Ubuntu does, however. Here is its guide:

* https://help.ubuntu.com/lts/serverguide/postfix.html

Here is where it is enabled by default:

* https://git.launchpad.net/postfix/tree/debian/postfix.postin...

And here is where the installation process auto-starts the server:

* https://git.launchpad.net/postfix/tree/debian/postfix.postin...


Well I never. TIL. I've always installed and started it because I assumed it wasn't already running.

Thanks!


Here's their release of how they made it as well. Super interesting read. It's shaders all the way down.

http://www.iquilezles.org/www/material/function2009/function...


Ha, that's my exact comment from the related reddit thread. Kinda cool, I wonder how often that happens?

https://www.reddit.com/r/programming/comments/4msf41/elevate...


Spammers, presumably trying to build up karma on HN. Needless to say we've banned them and will continue to.

Watchful users can help out with this a lot. If you or anyone notice comments being cross-posted in the future, please alert us at hn@ycombinator.com.


And that indeed is what we have to look forward to in online forums over the next 5+ years, as machine learning cuts its teeth on places like reddit, HN & disqus, and spammers try to find new irritating ways of getting eyeballs.


I'm not a fan of quoting XKCD, but... https://xkcd.com/810/


With how many XKCD responses their are, it seems a straight forward ML experiment to auto-relevant-xkcd


Someone made something like that! https://www.reddit.com/user/relevantxkcd-bot


One of his better ones.


You do realize he copied your comment, don't you?


That's been happening a bit recently.

https://news.ycombinator.com/item?id=11837687

(I think there are others, but I can't find them now.)


Both usernames end in 2


Yeah, but I still wonder how often people copy comments around like that. It's not like that was some great writing or anything, but it was copied word for word.

Maybe it was some bot, but that's an odd bot.


I've seen it happen on YouTube (not to me); highly upvoted comments get copy/pasted a month or two later to "steal" upvotes for someone else.

It could be a bot tactic to build accounts with karma that can later be used for astroturfing, using proven comments from elsewhere. Maybe governments and organized astroturfers have automated that sort of thing more than we think.


Nail, meet hammer.


Hopefully in this case the nail is comment plagiarism and the hammer is more careful pattern matching in moderation systems.


Yep, happened to me in the Inferno thread yesterday.


Do you know if there is a video for these slides?


Complete with creative tensions:

> With cinematic look, like taken with a real camera. We had some dissagreements here

> • I absolutelly wanted to avoid the CG look - the danish part of the team wanted something sharp and shinny

> • I wanted a hand-held TV camera - they wanted a sts04 like smooth lovely cameras

> • I wanted a realistic scenery - they wanted more action in the scene..

And exploiting impressionism as a compression technique:

> The idea is NOT to render perfect snow, but to draw something that evoques snow, and let the viewer’s brain to trick the viewer.


His website is full of great resources: http://iquilezles.org/www/



Reddit reminds me of the Google, Don't be evil bullshit mantra with shenanigans like this almost every week. I understand the fucking "monetize, grow, and get bought out" mentality that every web business adopts, but it is pathetic when it comes to places founded by guys like Swartz.


> when it comes to places founded by guys like Swartz.

He had nothing to do with the founding of reddit, and also had no problem collecting the payout when it was sold.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: