Hacker Newsnew | past | comments | ask | show | jobs | submit | softfalcon's commentslogin

This is why I like fountain pens… I regularly write down the things that are important to me.

Things I need to do, ideas I want to ponder on, people I need to remember or get respond to.

Writing is learning. Writing is understanding.

I have so many conversations with people who are always telling me I’m “retro” or “old school” for doing this.

I don’t even bother explaining the psychology behind it anymore. I’ve got no time for the ignorance.


Sharing my small bit of wisdom about burn out:

Burn out isn’t caused by putting in too many hours at work. It’s a symptom of forcing yourself to do work you don’t align with.

Forcing yourself to care about KPI’s and goals you don’t give a hoot about will usually result in collapse.


That sounds very interesting to hear about!

What diminished the day-to-day difficulty for you? Is it because the ecosystem became more mature, or did you "crack the code" for how to interface with everything you needed from your phone? Is your use-case for a phone wildly different from that of a typical user?

It's really cool to hear that someone is successfully daily driving it and making this ecosystem work for them!


> What diminished the day-to-day difficulty for you? Is it because the ecosystem became more mature, or did you "crack the code" for how to interface with everything you needed from your phone?

Neither! I just got accustomed to doing without stuff. That’s an effect I wildly underestimated.

Many things are still difficult (looking at you, CloudFlare [0] and DataDome [1]!) but I think I’ll manage.

> Is your use-case for a phone wildly different from that of a typical user?

Not really, I guess.

[0]: https://news.ycombinator.com/item?id=45816826

[1]: https://news.ycombinator.com/item?id=48921224


Except for a large part of Europe, the relative humidity is quite high. So, they're suffering more than most. I say this as someone who once lived in a desert and is well accustomed to 40-50 C summers.


I agree with you that you can't rely on hydro alone to power your country. It also seems like you're trying to be reasonable and suggest that any new nuclear production in your country needs to be done as ethically and environmentally friendly as possible.

Your statement about "We can't be buying France's nuclear energy all the time" really stood out to me.

Are Swiss folks maybe acting a bit NIMBY by not allowing nuclear in their own country, but are fine with buying French nuclear power? It seems a tad hypocritical to be against nuclear, while simultaneously using it as long as it's "not in my country".


Switzerland has nuclear reactors. They just stopped building new ones.


I tend to agree with you.

In my opinion, as long as the majority of their profits come from people continuing to buy the self-host devices, it is fairly unlikely they'll ever stop offering those devices. Why change a working business model?

Yes, subscription models are enticing for that recurring revenue... number must go up, right? /s

If a majority of your sales are not in subscription products though, I think it would be foolish for a business to blow off its own leg trying to chase that particular dragon.

Then again... businesses have made dumber calls in the past out of nowhere...


They can sell subscriptions to people who buy them and allow self contained as possible. For securities sake requiring off-site storage of a security system is a non-starter.


Yeah, that's also a very good point. I imagine they're going to need to support that use case indefinitely. Hence their edge/IoT line of managed switches.


I have heard others say the same as you about Ubiquiti devices. I genuinely curious what bottlenecks you've hit.

I've only been using Ubiquiti as a pro-sumer, but it has held up well for my use case of Plex and little game servers.

I use a Synology NAS for my storage though, which is a slightly beefier mobile AMD chipset.

I'd be very interested to know what I should and shouldn't expect from my ARM based network stack though!


> I genuinely curious what bottlenecks you've hit.

1. My UDM Pro absolutely chokes and stalls with intrusion detection enabled on the firewall and 8 cameras connected. Network goes down, cameras disconnect, devices disconnect from Wi-Fi every time a car drives past a camera due to AI features triggering, etc.

For something meant for small businesses I wish they would just shove an Intel i5 or something in it. They make great switches, great APs, great everything else, just too stingy on processors on the few pieces of central equipment that people would actually be willing to spend more on.

And for a $3999 enterprise NAS with dual 25 Gbps SFP ports and 16 drives? It could surely use something more beefy than a Neoverse N2. I'd say an i7 or even i9 is warranted here.

3. The UNAS 8 I don't own but I believe it would struggle with >1Gbps links and encryption enabled


I have to agree. I only have a consumer UDM (four years old) and it's on its last legs. From day one it was using 90%+ of its RAM and hit the CPU ceiling during large file transfers. Successive updates have pushed it well beyond its limits. I have had to disable many features like VPN and IDS/IPS. I was considering upgrading to the newer Dream Router 7 but the processor is not much of an upgrade, and it only has 3GB of RAM vs my current 2GB. I don't have space for a Pro and I'm not even sure I want one. I already have an Unraid server running with more than enough compute and RAM, and I'm going to try using OPNsense. I would prefer dedicated hardware but for the cost, it's just not worth it.


1. Same here - but it's only become a problem as protect has gained features (# of cameras stayed the same). I got a UNVR Instant and all the issues went away (I have been waiting for an updated 1U NVR but still not out yet). It sucks, but otoh protect is light years better than it had been.

I dont mind using ARM for NAS, but (to be fair I have not looked in a while) the issue is they tend to not have many pcie lanes. Looks like the N2 can have up to 64 @pcie5 so if it's built well, I don't think the CPU will be too much of a bottleneck.

Hell I'll put it out there - some company should make a NAS-specific ARM chip line to make lines of way less expensive (well pre the current troubles) base NAS enclosures with lots of NVMe etc.


Yeah mine solved once I got a UNVR as well but I would have rather paid for a better processor in the UDM Pro and not needed to buy a separate UNVR.


Unifi docs say that the AI feature run directly on the camera or via optional devices like the AI Port or AI Key. Odd that it impacts your UDM Pro and wifi.


I'm sure even if the camera runs the neural net, the detection itself triggers clips to be stored, re-encoded, indexed, etc. and the UDM Pro's processor is underpowered even for this.

It's even underpowered for streaming -- I found Protect to be extremely laggy, taking often 30+ seconds to open the camera stream when 3-4 stream receivers were connected.


Yeah . Sounds like horseshit to me to be frank.

I have a udm se, 10 g3 cams, 4k bullet+ai, door entry + cam +ai, couple of the display viewports running all day and a nano hd access point and symmetric gig with intrusion etc turned on. I also have wireguard users connecting in remotely.

No problems with performance whatsoever at this point.

Ok its not enterprisy its just a small business with 20 people but seems fine to me. I run synology servers.


He did say intrusion detection so that's probably it. That, and if you're using any kind of complicated firewall rules, those aren't HW accelerated like enterprise gear, so throughput tanks.

This is worse with the older devices.

For example: https://www.youtube.com/watch?v=p4yKf044meY

https://community.ui.com/questions/UniFi-Gateway-Intrusion-D...


Yeah the older devices were notoriously bad when intrusion was on.

I also have it on on my unit .

I do agree though nonharm in giving a bit more power. Why skimp on the cpu.


Turn off the intrusion detection and your throughput should be significantly better.


If something has features I expect to be able to use them. They should put enough CPU to make the advertised features usable in tandem.


I echo what the others say in that it's much more important to know what portions of your traffic are going to need to be processed by the CPU than it is to know how beefy the CPU is. E.g., just to give an example of the usual investigation process:

- The EdgeRouter 12P is ancient and had a weak CPU for even the time

- However, the EdgeRouter 12P has a good selection of hardware offloads for things like routing/NAT & even a hardware switch chip. These functions will often run at (or very near) line rate without touching the CPU much, and the latency/jitter/buffer handling will often be better than when even fast CPUs handle the traffic on other products.

- Buuuut there are oddball restrictions. E.g. on the newer 2.x or 3.x software streams (i.e. for the last ~5 years) hardware offload for VLAN tagged traffic on the switch does not work, and the CPU cannot switch a full 1G of traffic without choking (it gets close, but not quite). Also the hardware switch only covers a certain range of ports, some ports can only be routed or software bridged.

- Even then, if you add a bunch of advanced firewall inspection rules it's gonna run out of CPU. Quicker if it didn't have offloads for some of the work, but still easy to make it go from a solid full gigabit WAN NAT box to 100-200 mbps depending on what you enable. This can repeat for a lot of features, like VPN and so on.

As far as host networking (i.e. a server sending data out of its NIC rather than trying to be a network switch/router/firewall between segments) usually the CPU will be a limitation for other things before it's the limitation for sending things out the NIC. And a quality NIC (which these particular ones seem to be) can make that even more true in a similar, but less extreme, way as the switching/routing hardware offloads on the EdgeRouter. E.g. ZFS can be CPU heavy with all of the parity/encryption/deduplication features you can enable and trying to do that on top of using SFTP to transfer the data to a remote host in a single encrypted stream can stress the CPU even more... but this CPU also doesn't look like a typical bargain basement ARM CPU you'd find in cheaper Ubiquiti products and would probably do fine for what it has.


Basic routing and switching - expect line speed. Don't expect analysis features to run at line speed - 30-50% penalty could be normal depending on throughput.

Stay away from IPS and complicated firewall rules which usually are done in CPU, and you should be fine. HW acceleration for those (esp. TLS decryption) is a major reason fancy firewalls are very expensive. You're better off building an IDS or picking up a smaller FortiGate or Palo Alto firewall if you really want to get serious there.


The Cloud Key Gen 2 is underpowered depending what you do with it, and it runs hot. UniFi seriously needs to refresh it. (At least it’s better than the Gen 1. The Gen 1 was disastrously bad.)

The ENAS looks like fairly nice hardware. It even has ECC RAM. Not cheap, though.


I'd be surprised if Cloud Key gets another revision, it's a dead product line as I see it. The main purpose was to provide an appliance alternative to running the controller on your own server, which is now unnecessary for most users because the routers and NVRs can all host their own controllers.

The remaining market for such a product is people who are running UniFi switches and/or APs but not the router and yet still want an appliance, which is not a large space. Most of that market either has a random server they can run it on or is willing to throw together a Raspberry Pi controller.


Considering how long it has been I don't think we will ever see a Cloud Key Gen 3/3+.

Ubiquiti's Cloud Gateway Max or Fiber seems to be the modern replacement since they do the job of the Cloud Key while also serving as your router and firewall.


I’m confused. Docker Desktop isn’t supported on Linux?

I just followed Docker’s docs [0] to get Docker Desktop installed on Ubuntu.

Maybe I’m missing some specific point you’re making about some lower level detail, but they support and have instructions for Docker Desktop on Linux in their own docs.

[0] https://docs.docker.com/desktop/setup/install/linux/


The naming is bad here.

On Linux, most people only install the Docker Engine, unless they want the GUI.

On MacOS or Windows you have to install Docker Desktop which spins up a VM running linux.

You installed Docker's "Docker Desktop" which will spin up that VM by default, but you would get better performance by using `docker context` and running natively.

Docker depends on Linux, specificly namespaces/unshare()/clone() etc..., that is why MacOS and Windows installs require desktop and spin up a VM by default.

But on Linux, containers with engine (native) are just processes.

Sorry if that isn't clear but I am actually unwilling to install docker desktop as podman fits my needs better and they conflict.


Still own multiple TG-16’s. The CD-ROM attachment plus Ys: Book I & II was a modern technical marvel at the time.

Hearing full hi-fi stereo anime rock and roll instead of chip tunes blew my mind back in the day.


Many TG CD-Games had their code in track one, and the other tracks were just redbook audio. So you pop the CD into a regular player, skip the first one or two tracks so your speakers don't blow out with static, and then enjoy the game soundtrack.


Actually, I think most had the code in track 2. Track 1 was an audio track warning you that the disc is only designed to a play on the system. More details at https://retrocomputing.stackexchange.com/questions/27518/did...


Yes, this is correct. When you put the CD into a regular player, a strikingly beautiful (but monotonous) woman’s voice would say:

“This CD is made for the Turbografx game system. Please place it into the CD drive on your Turbografx to play.”

My brother and I thought this was really cool when we were kids. We thought the CD player must “know” that it’s a game.


As someone who owns a SNES and a TG-16, I think I disagree. The TG-16 graphics really pop compared to the SNES.

The SNES can only render 256 simultaneous colours. The TG-16 could do twice that at 512. Its video processor was also full 16-bit.

I’m not sure where you’re getting that the video was the weakness of the TG-16. At the time, that was the Turbografx’s whole claim to fame in that it was superior graphically to the SNES.

Source: Old enough to remember the commercials and bought both consoles to compare like nerds did back then


The PC Engine could theoretically do more colours on screen (though things like colour math and mid-screen palette changes do complicate that a bit...), but only had 9-bit wide palette entries compared to the SFC's 15-bit colour depth, which allowed for a lot more subtlety and richness.


That's the biggest Achilles' heel of the Genesis/MD, too. The lack of color resolution. I helped make the palette more accurate for that MD port of Super Mario Bros, and I made two palettes - one to simulate the composite PPU palette, and one to simulate the RGB PPU palette. The composite palette was closer, and what Mairtrus ended up shipping with (the RGB palette, no matter which "side" of mid-values I chose, wasn't quite right due to the lack of color bits)


Its big weakness is that they didn't realize how much multilayered backgrounds made things pop.

The sprites look really good, but the single background layer makes things look flat compared to the SNES / Genesis. Devs started working around that by updating some of the background tiles on each frame or using some of the sprites.

The SNES also could do layer blending effects. So while all of the input data could only be 256 colours, the PPU was spitting out a high colour signal after the effects were applied.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: