HNHacker News
TopNewBestAskShowJobs

EricMausler

286 karma · joined October 1, 2020

submissionscomments
EricMausler··on $20k bounty was claimed
2088 potential work hours in a year Less 88 hours holiday Less 80 hours vacation Less 56 hours sick =1864 hours (these are federal guidelines under the Service Contract Act regs)

232/1864 is a base increase of 12.5% for PTO

Payroll taxes, Medical, workers comp, etc add about 30% - though medical is flat so at higher wages like discussed here the % increase it represents goes down further

I did not have to factor in increasing skill on the job or time between jobs - but I did have to account for overhead and g&a which would be similar to time between jobs since those would be for bills

Big companies would have a lot of markup on OH/g&a/fee, but a software dev working remote for themselves on contract could competitively go down to 5-10% or less here to simply cover the minor added burden to bills.

That totals up to about a 50% increase on the salary rate. You can't outright bill someone for time you spend looking for a new job or improving your skills. You may charge a premium that you use to do such things but that would have to go under fee which tends to top out at 15% with the government, not something that can be expected to be accounted for. In my experience at least.

Again though, this was for service contracts - particularly with the US government, subject to certified cost and pricing data disclosures.

I was genuinely curious about the 2.5 number though, as i have spent a lot of time dealing with market rates in various conditions I was interested to know the context. I could see a few ways that could happen, but I wouldn't want to speculate too much

EricMausler··on $20k bounty was claimed
Is the 2.50:1 just a broad estimate or based on something?

When I was doing pricing for service contracts it was usually around 1.50:1 burdened billing rate vs direct labor (income)

EricMausler··on LLMs cannot find reasoning errors, but can correct them
wouldn't this effectively be using a "model" twice the size?

Would it be better to just double the size of one of the models rather than house both?

Genuine question

EricMausler··on Ask HN: What are the most interesting takes on Generative AI you've come across?
"We're sorry but this role is looking for someone with BrickBreak AI prompting experience and we don't think your experience in PONG-AI prompting is a fit here. We'll reach out if something comes up we think you would be a better fit for"
EricMausler··on I skipped to the ending
Are you saying Google is currently trying to offer more value to society and they can't find the funds?

My core stance probably comes down to: I don't see how putting money into payroll can be considered a waste to society. It's distributing money directly into the bank accounts of the working class.

They are in a position to provide value to society. They have as large a team of vetted professionals as they can. A bit cliche, but the horse has been lead to water

EricMausler··on I skipped to the ending
Eh. The purpose of a job is to do the job.

Creating value feels more like the purpose of the business. Google is creating value, and I dont see the problem with them creating a bunch of easy jobs for people as a means of distributing that value

EricMausler··on I skipped to the ending
Would being tighter with their budgets and reducing headcount give them more incentive to build more useful things?

They built the useful thing already. It prints money. Let them house and feed a bunch of people as employees. Idk maybe I'm missing something

EricMausler··on I skipped to the ending
Isn't that a good thing? It promotes creating jobs and sharing some of the wealth
EricMausler··on Can you use your "free will"? Try your hand
Does it count if you allow the test to be accurate but you still maintain control over when it is wrong?

I just spammed F and randomly hit D and it pretty much never predicted the D.

Which I think captures a fundamental flaw in algorithms vs humans. Humans know how to mask their signals within noise. I'm inclined to believe the generalization that algorithms that aim for accuracy are highly susceptible to being manipulated by humans who are allowed to have free will over the inputs.

EricMausler··on I've overlayed stays on a light pollution satellite map
Any thoughts on how someone would do something similar for water?
EricMausler··on RealFill: Image completion using diffusion models
I feel like this will be great for wedding photographers
EricMausler··on Philips allegedly hid 3700 complaints about sleep apnea machines from U.S.
I posted directly to the original comment, but there is very strong evidence that sleep apnea was severely (~90%!) undiagnosed in 2008. 10 years ago was 2013, so hopefully that number improved between 2008 and 2013, but I'd imagine it was still a large problem.
EricMausler··on Philips allegedly hid 3700 complaints about sleep apnea machines from U.S.
There was a study done in 2008 where surgeons wanted to find out how many surgical patients were undiagnosed with sleep apnea, presumably because it had an impact on the operating table.

The results were that 20% of patients had sleep apnea and 90% of them were not diagnosed.

Source: https://pubmed.ncbi.nlm.nih.gov/19186102/

Additionally, let's assume a person has a 15% likelihood of being a surgical patient

Source: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5765448/.

That means in 2008, when the population of the US was about 300 million, there were between 8.1 million and 54 million people undiagnosed with sleep apnea. The range being dependent on how representative the surgical patient study is on the general population (from assuming ALL people with sleep apnea are also surgical patients to assuming surgery is completely independent of apnea), so likely closer to 50 million than 8 million imo.

20% of today's population is 68million.

Informal Google searching puts yearly CPAP sales at 8million per year in the US. Recommended use is for 5 years. This puts 8million sales per year in line for treating 40 million people with sleep apnea.

Looks to me like we actually might have room to increase our prescription rate still.

Fun fact, I am part of that diagnosis statistic. I was diagnosed in 2016, and estimated to have had it pretty much my whole life, so I was undiagnosed in 2008 and I also never had surgery. Turns out you don't need to be medically obese to have sleep apnea either.

I'd say we are actually fixing one of the countries major medical problems and not overprescribing CPAP machines at all.

EricMausler··on Hackers selling hacked police emails to request user data from TikTok, Facebook
The government is not providing my internet.

I believe the internet should be treated like the mail, but until the government actually steps in and takes ownership of it, they have no business having access to the metadata necessary to route packets, let alone the logs of those routings, and certainly not any additional Metadata that is not part of the routing function

EricMausler··on I made a transformer to predict a simple sequence manually
I am still learning transformers, but I believe part of the issue may be that the weights do not necessarily correlate to things like "orangeness"

Instead of a transformer for each color, you have like 5 to 100 weights that represent some arbitrary combination of colors. Literally the arbitrariness is defined by the dataset and the number of weights allocated.

They may even represent more than just color.

So I am not sure if a weight is actually a "dial" like you are describing it, where you can turn up or down different qualities. I think the relationship between weights and features is relatively chaotic.

Like you may increase orangeness but decrease "cone shapedness" or accidentally make it identify deer as trees or something, all by just changing 1 value on 1 weight

EricMausler··on Unlimited Kagi searches for $10 per month
I used pinterest and still hate(d) when it popped up on search.

Without too much conjecture I think the problem is search-related web crawlers and users have very different experiences with pinterest. To the web crawler, the information is there and easily accesible. To a user, it might be behind a login, or part of an image description, or a sidenote, or whatever. The page doesn't exactly load with what you are looking for front and center

Additionally, I don't use it through a browser, I use it in an app, so im not logged in on my browser.

EricMausler··on Philips Hue will soon force users to create an account
If A then B does not imply If B then A

But, "If A then B" & "B" together do create a signal for A. The strength of that signal is dependent on the statistics involved.

In this context, A is a bad boss and B is getting an MBA.

Relevant statistics would be the distribution of degrees among bad bosses, the frequency of good boss vs bad boss, the proportion of degree holders that are bad bosses, etc

There is a valid signal, the question is how strong it actually is and how much it is overplayed.

This is an incredibly widespread issue when generalized beyond MBAs and bad bosses. I think people fall into roughly 4 stages with it:

1) people do not know its a logical fallacy to begin with, and treat the signal as a full on implication

2) people learn of the fallacy and think the technicality of it as a fallacy means the signal cannot exist at all

3) people acknowledge the signal exists but dont know how to influence their opinion with it

And 4) people try to understand the statistics involved in each instance to form a personal intuition on the signal strength

Imo I feel like the large majority of people are 1 (hence widespread stigmas that are overplayed) and then the large majority of anyone who isn't a 1 is a 2 and a smart-ass (meaning the 2s are not convincing the 1s to change). 3 is probably where most thinkers end up on most subjects, and 4 is very tedious to keep up with and has questionable reward value for doing so.

I've seen someone do the math on working out the probability for A|B when If A then B for some chosen example, but unfortunately I don't have the reference. Would be cool to see again.

To give a simple example though, assume A is English is the primary language someone knows and B is a preference for speaking and writing in English. If someone only knows English it follows they will speak and write in English. If someone speaks and writes in English, it does not follow that English is the only language they know.

If you see someone speaking and writing in english, there is obviously some signal there that they might only know English.

That signal changes depending on the % of English speakers who know a second language. And in fact, if 0% of English speakers spoke another language then suddenly If B then A does become a true statement.

I really wish I could instill this insight into everyone on Earth tbh. Misunderstanding that signal causes so many problems

EricMausler··on The brain is not an onion with a tiny reptile inside (2020)
I'm not sure which side you are arguing for?

Is the simple metaphor of 3 layers in the brain equivalent to saying gasses want to be together and solids want to rest?

I think part of the debate in the comment section is on what kind of order / pattern we are trying to capture with the analogy. Does it make more sense to be analogous to the structural observations, or a more functional equivalency?

You could say an ocean is like a desert in that they are vast and empty with respect to surface structures observed by a human traveller, but obviously from a functional /environmental perspective the two almost couldn't be more dissimilar

EricMausler··on Show HN: Conway's Game of Chess
I'm just a wannabe game designer, but what comes to mind for me would be to apply an entire board Conway update every X (4?) turns.

I think it would be a bit easier to mentally manage than having every piece on its own count

Might give an edge to whoever goes second, because they will have more control on creating overpopulation conditions right before an update, which would offset first move advantage

EricMausler··on Gmail and Instagram are training AI, and there’s little you can do about it
Ethical Defaults is something I've been casually supporting for a long time.

I think the statistics around organ donation are what got me started on it.

We really should have legislation mandating minimum consent by default options, and then additional legislation that creates allowances for non-minimum consent on a case-by-case basis. So we can allow, if we want, for organ donation to be consented to by default if the general public feels it is more ethical to default to consent on that option than not. And if harvesting everyone's data for AI is going to be default, then we would need a similar public consensus

The more work a company needs to do to get consent from its users, the less bullshit they are going to create and try to get away with because they'll need to actually convince people to care enough to change their defaults.

It will better align incentives between consumers and companies imo

EricMausler··on A DIY near-IR spectrometer
Sounds like you want a curated feed. There are some email mailing lists that aim to achieve this, usually for a specific domain (like stock market, or AI, etc)

Maybe a group chat or discord of like minded people who casually share things they come across that pass a high standard

One way or another it seems like you're going to need to rely on another person to sift through all the daily published content and mark potentially interesting ones

EricMausler··on Ask HN: What cool desk ideas do you have for a home office?
I did exactly this about 4 - 5 years ago

I bought spring-based (not electric) height adjustable legs / frame and then went to home depot with a friend and cut a 70" x 30"ish x 1" piece of wood. Added a rounded edge to one side, sanded, stained it, then screwed it into the frame.

I love it. It's huge compared to a typical desk, and although I haven't done anything unique with it, it's been solid.

I dont really know what I'd add to it that would be worth giving up desk space, tbh. The conveniences / tools I use work fine being on the desk rather than part of the desk

EricMausler··on Asking 60 LLMs a set of 20 questions
One of the jokes: "I'm going on vacation, but I'm not sure if I should take my laptop. It's such a pain in the neck to lug it around with me." User

I feel like this bot mocking us

EricMausler··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
I agree on the subject, but I think we can leave port scans out of the discussion because they are not an issue as you suggest and still apply everything I am saying to other issues.

There would still be upside of potentially addressing the scan spam as well, though

EricMausler··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
Yes exactly with the weirdness. Which is why I am leaning heavily into being a proponent of it needing some laws created explicitly for this situation that will clarify what's considered fair activity between researchers, companies, repairers, etc.

Sticking with the example, there is not reason a company cannot have terms that you can't open the walls, while the state also has laws that regardless of what the terms are - you are allowed to open the walls for maintenence purposes, renovations, etc, but maybe you have to notify the company about what you are doing.

It feels like territory somewhere in between the complete freedom of ownership and the total lockdown of renting.

I'd imagine there is a whole legal tug of war that would need to happen to know where the lines would or should fall, but the main point is that both sides are at the table and no one needs to be keeping their activity in the dark because of how uncertain they are about how the law is going to treat them

EricMausler··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
I proposed a preference for systemic solutions over a soft dependence on white hat hackers who operate identically to black hat hackers right up until they have a vulnerability to exploit and decide what to do with it.

In this thread I expanded the detail to include the system to do this could (and imo should) be a legal framework that creates effective communication between companies and researchers.

I also try to adapt my language to try to parallel what the person I'm speaking with is trying to say, rather than telling them they didn't mean what they are telling me they meant. I apologize if created a misunderstanding with my word choice.

Yes I did mention requiring consent from the company as the ideal goal of the model. I am not suggesting the implementation of the model full stop at that just that sentence. In other areas of law, if you can prove a message was received by a company that can sometimes be considered implied consent if they do not respond to it.

We can also require that companies cannot simply refuse for no reason, but leave legal room here for any legitimate reasons to deny should they exist.

And so on and so forth.

It makes the intent of the researcher very clear.

Declining is obviously less pressure for the company in this situation, I agree. But it is not less pressure compared to the current situation. Companies currently have no obligations at all to researchers, and they certainly do not build security out of concern that white hat hackers will out them. They fear black hat hackers. Those are not going away, and if a legal framework exists for companies to work with researchers and better arrange fair conditions for both sides, I would bet companies will be MORE willing to allow research than less.

Because right now they company gets the research for free and then gets to decide whether or not they want to throw the researcher a Starbucks gift card or not. Or just press charges because they are assholes.

I dont really care what the market decides to do. The point of this is to protect the researchers regardless of what the market does. Because to your point, the market has already chosen poorly which is why we have issues on this subject to begin with.

Does this clarify my stance?

EricMausler··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
I agree liability should be part of the discussion. If we create a legal framework around the subject and clearly identify what's allowed or not allowed by independent researchers and what the ownership model actually is, then this part of the discussion becomes easier and more easily applied to past precedents
EricMausler··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
The Ship has not sailed. The ship is still on its way to port. Complete internet surveillance is arguably an unstoppable force on the way to shore.

I think when it gets here there is going to be a lot more trouble for cybersecurity experts due to a lack of clear understanding around what is considered legal activity or not from them. Right now the obscurity is something they hide in - they can choose whether or not to reveal they found a vulnerability.

But what if that's not always the case? What if you get "caught" before you are able to show you had no intentions of doing anything malicious?

We can have the trial by fire we usually do, and let a round of innocent people face unjust consequences and use them as martyrs to create new laws - or we can use some foresight and build some legal frameworks in advance that enable researchers to be "by the book" and not worry at all about legal repercussions

EricMausler··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
I think you're getting way ahead of the conversation, and there is no way to know what the implementation would be like and how communication would go between researchers and companies because if you can think of the communication problem today, then we can consider a solution for that problem in the implementation tomorrow.

At the end of the day, I am arguing for promoting people to try to work with companies, and to put out to the public a process for making that effort effective.

I feel like we agree but our solutions are opposite. The current laws are insufficient, so we need adjustments to the laws.

You (and others) propose we make hacking into systems fully legal, presumably because we can target malicious activity based on what they do with that access instead of the access itself. Is that correct?

I also disagree that a ban is equivalent to shooting an intruder. The connection is not the actor, the person using it is. If a person chooses to enter into a protected space they do not have permission to be in, then they are susceptible to consequences to that. I think just because it is easy to do it from your bedroom doesn't change it. Much like how virtual bullying is still bullying; virtual breaking and entering is still breaking and entering.

If we formally adopt this attitude then we also enable ourselves to pressure other jurisdictions to raise their standards to match.

An uncontrolled internet appareny has 1 outcome - malicious spam. That is what everyone in this thread seems to agree on, and the arguments against what I suggest all seem start with the assumption "there is nothing we can do about it" and the corollary "there is nothing we need to do about it"

I think we can actually do something about it, and I think we ought to. But before all of that, I think the first place to start is making a clear legal relationship between security researchers and the private sector and debate the laws that should be in place to facilitate that in a fair way

EricMausler··on Device offers long-distance, low-power underwater communication
This is cool. I'm not sure if I missed it, but did they address how a signal is generated by the array in the first place?

My current understanding is that the device will echo a signal back to the source, not propagate it forward or create a signal.

Is it right to assume low power sensors exist and would be hooked up to this array, and then when the sensor triggers the array echos the signal to the other receiver?

← PreviousPage 2 of 6Next →