HNHacker News
TopNewBestAskShowJobs

GregoryVPerry

272 karma · joined December 24, 2017

Consultant. Machine learning and computer vision, network and information security, enterprise cloud & datacenter architecture.
submissionscomments
GregoryVPerry··on Trump suspends H1B, H4 visas till year end
Great, thanks for your one line nothing.
GregoryVPerry··on Trump suspends H1B, H4 visas till year end
YC is fucking bullshit, what is a flagged post? This has upvotes, not downvotes, but based on "flagged post" this doesn't show up unless I login?

My post again, and stop flagging it you angry H1B workers that leave 20 pairs of shoes outside of your hovel:

-----

There is no question H1B visa holders can escalate through the ranks and make a bunch of cash in the United States.

And that's exactly what is wrong with the entire thing. That entire teams of Indian H1B visa holders will immediately get whitey off the project, every single time, while making sure that the hiring manager and technical team leads are always Indian. This is the caste system, re-invented here the U.S. And you cannot get shit done if you are a competent engineer dealing with an offshore team or onshore H1B team. They will not do what you tell them to do. They will argue about every single point. They will trash your credibility and refuse to implement anything, using groupthink that controls the entire project. Managing a team of onshore H1B workers is nothing but interoffice politics that they completely control in all aspects. It's blatantly racist and has destroyed U.S. worker opportunity in the engineering fields, all of them.

H1B is a complete scam, especially in the Beltway / Northern Virginia area where everything is a billable contract. Headhunters get their fee and/or a large chunk of the first year's hourly revenue. The company hiring the H1B worker is on some federal project or grant and is making the spread between what the headhunter charges and the hourly rate on the contract. The hiring company couldn't give a shit less about the quality of work provided by Indian H1B workers, nor is a college degree granted from an Indian university anywhere near what is required in the U.S. from an engineering perspective - there is no comparison in the quality of education, nor have I ever met a single H1B engineer that was better than anything but a limited segment of technology that they specialize in, by design, because that requires their team in order to complete the project.

Makes total sense if you're the headhunter and hiring company, both of whom only care about having a warm body in a seat that is billable, and you can get three warm bodies in the seat for the price of one market rate position using H1B. It's complete bullshit, a scam on the taxpayer and attack on U.S. workers. Worthless 99% of the time, and the 1% of H1B engineers that actually do know what they are doing are not worth the damage the H1B program has done to the entire U.S. technical space.

GregoryVPerry··on U.S. Army Awards Pocket-Sized Drones $20.6M Contract
Good for FLIR. A really revolutionary drone platform actually, super expensive though.
GregoryVPerry··on Trump suspends H1B, H4 visas till year end
That's not the reality of H1B. The reality of H1B is a recruiting industry completely dominated by Indian headhunters, who submit only Indians and not native U.S. citizens to their corporate clients. Followed by Indian H1B recipients then moving into two or three bedroom apartments they share with 10 - 15 H1B visa recipients, everyone splitting the rent and utilities, and sending the majority of their cash back to India.

U.S. workers in the engineering and technical disciplines cannot compete with H1B visa applicants who are submitted at probably 30% market rates and wages, and openly discriminate in the work place if you're the token white dude U.S. citizen working in the same office. H1B is miserable, corporate welfare for Zuckerberg and Bezos.

GregoryVPerry··on 5G is perfectly fine
Completely not true. 5G is picocell deployment due to 95Ghz millimeter wave. There will be thousands of these things in each town, everywhere.
GregoryVPerry··on 5G is perfectly fine
Again, as mentioned in my previous comment Becker's scientific work with The Body Electric documented numerous instances of cellular mitosis being accelerated and other ill effects from electromagnetic fields much less powerful than what we are holding up to our ears these days.

These 5G picocells are phased antenna arrays that can perform beamforming with pinpoint directed energy. And they are coupled with Software Defined Radios that can be remotely upgraded with firmware updates.

Hitler almost took over the world, and we have significantly more advanced technology available to us these days since World War II. Depending on the RF front end of these picocells, what's to stop some potential next world dictator from turning all of these picocells into a global active denial system to prevent riots and civil unrest - because provably 95Ghz is already being used for ADS - especially if the picocell output power can be controlled via firmware update?

So here's your question back to you: how much output power are these picocells actually capable of?

And with active beamforming capability, what's to stop a government from turning these picocells into highly directional ADS nodes to prevent riots and protests?

These things are popping up next to tunnels and public transit ingress/egress in NYC, and public officials are refusing to comment on what they are being used for other than "it's something to do with Homeland Security":

https://newyork.cbslocal.com/2017/09/27/mysterious-metal-tow...

All of this SDR-enabled 5G picocell gear from all vendors need to go through extensive teardown analysis from the technical community, to determine what amplifier components are being used. China wouldn't think for two seconds about rolling out that type of capability in their country to prevent civil unrest, and having remotely-upgradable amplifiers on every light pole that provably can interact with human tissue doesn't sound like a fun future to me.

GregoryVPerry··on 5G is perfectly fine
>The mm-wave signal is safer than wifi.

This is completely not true, and the foregoing article ignores numerous aspects of the potential health concerns of millimeter wave radiation in the 95Ghz area of the spectrum.

1) 95Ghz millimeter wave provably and without question has the potential for adverse affects on human tissue. Active Denial Systems (https://jnlwp.defense.gov/About/Frequently-Asked-Questions/A... for example) use 95Mhz directed energy for so-called Non Lethal Weapons technology. This is not complex.

2) Based on poor signal propagation and inability to permeate through common materials used in most building construction, 95Ghz picocells are being deployed every couple hundred feet in areas with large buildings and superstructures. This is not something that can be opted out of, especially in densely populated urban areas.

3) The adverse effects of electromagnetic fields on biological tissue was extensively researched by Dr. Robert Becker and documented in his published scientific research as well as his book The Body Electric. All of this information was suppressed by academia and big pharma, he proved exponentially increased cellular mitosis rates, damage to DNA, and a host of other ill effects from EM fields at powers significantly less than today's mobile telephones and WiFi access points. There is a massive profit motive associated with mobile telephony, the Federal Communication Commission is one of the only, if not the only, self-funded government agencies in the U.S. and if you've ever consulted for them it shows. Armani suits, 7 Series in the parking lot, the FCC has loads of cash from spectrum allocation auctions where they receive billions of dollars for each chunk of the spectrum they auction off for use by mobile carriers.

Millimeter wave 5G should be completely stopped in its tracks until conclusive studies have been conducted. Hundreds if not thousands of scientists at this point have signed public letters to this effect, I am really surprised this is even a 5G positive topic of discussion on YC.

GregoryVPerry··on In Amazon’s Bookstore, Orwell Gets a Rewrite
It would be great if you manbun faggots would not post paywalled articles.
GregoryVPerry··on Low-Latency Video Processing Using Thousands of Tiny Threads [pdf]
Very interesting paper. Did you settle on a method for NAT traversal with future revisions?

It looks like the Lambda worker limit is now bumped up to 1000, and with the possibility of automatic worker limit upgrades upon request if things like S3 triggers are being used.

Any idea what upper limits AWS is now allowing upon request?

GregoryVPerry··on I Got Paid $0 from the Uber Security Bug Bounty
Initially JavaScript was being escaped with their WAF.

The second POC demonstrated the ability to evade both their WAF and XSS_Auditor.

Their development team then verified the ability to execute arbitrary JavaScript from any *.cloudfront.net host.

That's pretty much the whole story.

GregoryVPerry··on I Got Paid $0 from the Uber Security Bug Bounty
Yeah that's a big one, and an issue with the core of their entire authentication workflow that they cannot fix without invalidating tens of millions of apps or forcing everyone to upgrade. Whenever you sign off of their mobile app there is no communication with the network, they are just erasing the token on the client side.
GregoryVPerry··on I Got Paid $0 from the Uber Security Bug Bounty
If those were vulnerabilities discovered prior, then surely they could cite to the prior report or an internal ticket to that effect. These weren't previously discovered issues, especially the certificate pinning Surface app one. Their own Bug Bounty Treasure Map specifically states that all requests to that mobile endpoint are certificate pinned, but aren't in the Surface app.

But the best part is, when I was reporting various issues to the Bug Bounty, their staff is actively fixing stuff on the backend (I was getting different application responses after the initial report was filed, but only until I gave them more info on the WAF and XSS_Auditor evasion stuff did they finally pull the whole application offline). And then they still didn't pay anything on the bounty.

Yeah I sent HackerOne a bunch of mediation requests, each response was a different excuse why they won't get involved with it. My "Signal" is too low or it's within Uber's discretion to close out the reports etc. Then they disabled completely the Uber Report Issue button. Yawn.

GregoryVPerry··on I Got Paid $0 from the Uber Security Bug Bounty
Their bug bounty is definitely fishy. If you pull their reports for the last few months, every single one of them at HackerOne have been redacted/locked with no information published. According to HackerOne their vulnerability reports become public after 30 days, but they've given Uber the ability to lock them which keeps everything private.