HNHacker News
TopNewBestAskShowJobs

InitialBP

293 karma · joined May 5, 2020

submissionscomments
InitialBP··on My business card runs Linux
That's a very unrealistic view of how that works. If you plug a USB into your computer and your computer is compromised, the next time you log into bank account your cookies are snagged and they do something with your money.
InitialBP··on No Refrigerant Left Behind
One thing to realize is that "wind chill" also has a reverse effect that occurs when it's hot outside.

As a human, with a normal body temperature of 98.6 degrees F. If the outside air temperature is 100 degrees F, then having your windows rolled down will actually increase the speed at which your body heats up to match ambient temperatures.

This makes driving motorcycles in desert areas where air temp is > 100 degrees especially dangerous as it can quickly lead to dehydration and heat stroke.

InitialBP··on At the Bored Ape restaurant, your ApeCoin is no good now
Wifi access does not universally mean the ability to receive texts, it can depend on your particular device and mobile carrier.
InitialBP··on Sleeping longer than 6.5 hours/day can help you lose weight: study
Definitely recommend the technique noted here as a good exercise.

Just _Intentionally_ relaxing the muscles in your face can make such a profound difference when trying to get to sleep. Especially when you don't even realize those muscles are not relaxed by default when laying around in bed.

InitialBP··on “Google” programmers. How one idiot hired a couple more idiots
Similar term although with a slightly different meaning that I use "analysis paralysis", when you get so caught up in trying to figure out the "correct" answer that you get stuck.
InitialBP··on Microsoft will include pay ranges in all U.S. job postings
> It can't be that hard to follow this law in specific places.

Directly from the article: "Pay experts have long predicted companies would not want to mess with different practices in different states. Doing so not only complicates hiring practices for human resources departments, ..."

There is probably a lot more nuance and qualifications of when it's necessary to disclose and from a company that employs more than 150k employees (according to a quick google) there's probably even more complexity and chaos.

InitialBP··on The case for expanding rather than eliminating gifted education programs (2021)
If you increase or decrease the pay of the teachers, I would expect to see an outcome on student educations over the long term.

For example, if District X pays better than neighboring district Z, District X will most likely have greater chance of hiring teachers in both districts, letting them choose the most qualified. Resulting in the school with higher salaries naturally getting more teacher candidates to choose from.

While some expenditures might not have a direct impact on student educations, they still have some effect. Another one would be - a school investing in a new Air conditioning and filtration system, students are probably going to have an easier time learning when they don't have to worry about being too hot or too cold in their classrooms.

InitialBP··on Zero-Day Exploitation of Atlassian Confluence
Sorry if I misunderstood the question, sounds like you are asking if there are some common tools that do auth outside of the application before passing traffic back.

Google IAP is a big one, and Cloudflare Access can let you do similar things (link an internal service to Cloudflare network and Cloudflare will deny someone ability to talk to that service until they've validated their identity to cloudflare and it matches your rules somehow.

InitialBP··on Update on Hiring Plans
Your argument hinges upon the fact that one company or person's opinion would hold enough sway to actually ruin your entire reputation.

Even if this individual or this company was exceptionally vocal about your betrayal, do you really think it would "prevent having visibility into your life as a possibility?"

The arguments for this are all over the spectrum, but I think _Most_ people fall into a moderate stance of, if you accept and offer and something substantial and unexpected changes your situation (an incredible competing offer, an unexpected opportunity, health or spousal related issues) then you should do what's best for you and not let loyalty to a business and a people that you don't even have an established relationship with yet have a negative impact on you.

As evidence by the Post here - Companies will make the same decisions when exceptional circumstances arrive.

I would also argue that anti-corporation/anti-business sentiment in the USA has never been more prevalent with r/antiwork in the spotlight, ridiculous inflation, a new outburst of unionization (e.g. starbucks) and CEO's under fire (Elon/Bezos) that a reputation for making tough decisions for yourself and not exhibiting loyalty where its not deserved might gain you more fame. Especially if some "SV Startup CEO" corroborated your story for you.

InitialBP··on Snort – Network Intrusion Detection and Prevention System
For a home network that might be feasible but for a business/shared network you have to be careful about terminating all incoming traffic since you might deal with HIPPA or finance privacy issues.

In my professional opinion requiring insecure internal connections is also a bad idea.

InitialBP··on Impacket – collection of Python classes for working with network protocols
Not an issue I experienced at my old company (a consultancy) but this is a huge factor on security teams that I think is often overlooked.

"Old" style security teams often have a "you (wrote bad code|bad config|picked bad libraries), now go fix it" attitude that really doesn't do them any favors. A big part of being on any security team is building rapport with other teams and making sure that the security team is seen as a part of the company and not "the assholes who make us do extra work."

Anecdotally it seems like the more the other teams have a strong relationship with security - the more likely they are to consult the team early on and get some input on design decisions and recommendations that reduce the overhead of fixing vulns later on.

InitialBP··on Impacket – collection of Python classes for working with network protocols
At the time I was working for a consulting company. After a few years of grinding through assessments over and over I wanted to take a stab at actually helping improve the security of a company rather than simply telling them what they were doing wrong. I still get to do _SOME_ offensive work, but now I also get to follow up and help design/implement a good solution to the issue.
InitialBP··on Hiring technical talent: An exercise in clarity, patience, and preparation
When you say "test" are you referring to technical coding challenges in the interview process? An interview is essentially a test, regardless of whether it contains a whiteboard coding assignment, a presentation, or even just a conversation. At the end of the day an interview is designed for a company to decide whether or not they should extend an offer to a candidate and (hopefully) for a candidate to learn about the company before potentially accepting an offer. The point of this process is for both parties to decide if they would be a good fit together. They are literally "testing" each other.
InitialBP··on Impacket – collection of Python classes for working with network protocols
I was a professional penetration tester focusing on network security for a couple of years and Impacket was an Essential piece of tooling that I used constantly. The "examples" folder in this repo contains enough utility that you could successfully pwn a bunch of windows environments with no other tools.
InitialBP··on Ask HN: Cloudflare broke my domain's DNSSEC making it unreachable since 4 days
Sorry to hear about your problem, a quick recommendation would be to keep the temporary DNS name you bought and simply redirect to your previous name once you have the issue resolved (or vice versa if the branding is less important to you.) This way your users won't need to know or care about the change anymore aside from this temporary setback.
InitialBP··on Launch HN: Infra (YC W21) – Open-source access management for Kubernetes
> you typically have the budget for an enterprise license.

Not all enterprises are the same and not all companies with more than 100 engineers are ready to dedicate a significant amount of capital to yearly costs for access control. Especially when you can "Make do" with an open source solution and spend the cash on a product that is less replaceable or more necessary. I would also add that this is the Only open-source solution that I've seen that would actually support blanket oidc integration and more specifically with Google workspace etc. Most competitors like Teleport, cloudflare, etc have proper oidc integration for an idp locked behind a pay wall. (Would love to know of any that dont)

> isn't that the central proxy service?

Teleport offers authentication AND a proxy that will let you connect back to your services via their proxy. The certificates that get issued for those backend services are usable as long as you can talk to the service but the proxy acts as an identity aware proxy locked behind your idp or whatever authentication you are using with teleport. From what I can tell infra does not offer a proxy to connect you back to your network. You would host it somewhere and expect users to be able to directly route to infra.internal.company and k8s.internal.company

IMO the fact that they are actually offering a fully open source product without locking any features behind a pay wall makes them worth watching. Obviously they aren't at parity with Teleport, and they don't support SSH or other protocols currently but I expect they'll have a lot of support in the community.

InitialBP··on SEC charges Nvidia with inadequate disclosures about impact of cryptomining
This isn't really a "practical use for blockchain tech". Rather it's just a positive way to use the side-effect that blockchain tech requires computing components that generate a lot of heat.

Ultimately the heat output has nothing to do with how the tech is used (like bitcoin). If Bitcoin (or other cryptocurrencies) stopped holding value people wouldn't heat their homes like this because it would cost more than traditional heating methods (as someone pointed out above about heat pumps.)

InitialBP··on The growing discontent behind Nintendo’s fun facade
I've worked for plenty of places that facilitate alcohol during work hours. For 99% of people that work there they enjoy a beer after lunch while they knock out some evening work or internal meetings, or just choose not to participate. Some people like to casually drink and while that isn't true of all individuals, depending on your team that might be a big morale boost for people that can drink responsibly in the workplace.
InitialBP··on New links found between musical training and cognitive ability
Hillbilly doesn't mean stupid, generally just isolated and sometimes uneducated.

And I know plenty of them who play a banjo and a guitar exceptionally well.

InitialBP··on Abcdesktop – a cloud native desktopless system
Care to elaborate?
InitialBP··on U.S. forgives 40k student loans
Demanding "even-stevens" all the time doesn't help the situation at all. The people that were able to pay off their loan debt were people who chose a degree that would be able to make significant money, were talented enough to land a great job in a field without a lot, or had the circumstances that let them finish a degree where others were unable to.

Do some people make bad decisions about degree choice? - Yes

Do some people drop out of school because it's too hard or because of other circumstances (unexpected baby, financial hardship, etc) - Yes

Do those people who either have made bad decisions, had less fortunate circumstances than others, or a combination of both deserve to live under a mountain of debt for the rest of their life? - No

One other thing people don't consider is that Most 18 year olds don't have a good grasp on money or what they want to do in general and in my hometown (poor county in WV) there was a TON of pressure to go to college if you didn't know what you want to do. Kids don't know better to not get into debt for a degree because everyone tells them not to worry about it. There is a serious problem with financial education in the US.

You can help out people who made a bad decision or had bad luck without being so uptight about how everything has to be complete "fair". The world isn't fair from the time we're born till the time we die.

InitialBP··on Canada to ban foreigners from buying homes
I would add that Uber has traditionally operated at a loss, and on top of that they don't provide the same level of benefits and payment to their "contractors".(whether or not they should is a different question)

While they did disrupt the taxi market, they are also setting false expectations about what sort of model is viable in the space since _Eventually_ they will need to bring in revenue or could potentially be forced to pay their drivers more which would lead to a big hike in prices and would probably have an impact on how it functions now.

InitialBP··on Dim, a self-hosted media manager
Binaries would be nice, but the docker solution is an easy win for most platforms. If you don't use it I would highly recommend giving it a shot. In general it makes trying out or playing with new tools really easy.
InitialBP··on The Personal Security Checklist
Definitely a good threat I hadn't considered. I imagine from someone who is less educated about technology in general, having a list of "example threats" that those items might protect against would be beneficial to help offer some more incentive to follow this list other than just "Good Security".
InitialBP··on The Personal Security Checklist
Definitely agree with you, there's no need to waste resources on protecting against threats that would never target you - like attempting to capture your face from CCTV and spending real money and resources to get a mask and then stealing your device... etc like you noted.

The author does have face unlock listed as "Advanced" priority. The wording is a bit weird but I take it to mean, only someone who has "very advanced" security concerns would need to follow that recommendation.

If I were going to recommend this to a friend/family member I would just tell them to stick to the basic priority items and not worry about the higher pieces.

InitialBP··on My own phone number is now spam texting me
Hopefully this will help some others deal with spam SMS.

A few months ago I started getting huge group text spam to hundreds of emails that were almost identical to my own

(changed obviously) if my number was : 123-454-9938 then i would get in a group chat with numbers from 123-454-9900 all the way to 9999. They were using email -> sms specifically which is a relatively new feature that allows you to text mobile devices on carriers that support email to SMS. [1]

Super annoying - but AT&T at a minimum allows you to call and request that they disable this feature for your account. If anyone else is getting constant sms spam from email addresses this is the way.

Disclaimer: I don't know and have not run into any issues where legitimate companies are using this feature yet. If so, then obviously you won't be able to receive those texts. At the moment there is no capability with carriers (that I've seen) that would allow you to create an "allowlist" of domains to accept texts from, but until that exists I won't be dealing with email to sms as it's just a huge cesspit of spam.

1 - https://www.att.com/support/article/wireless/KM1061254/

InitialBP··on Today Google is turning on tracking for many users that previously turned it off
There are numerous other breaches of companies that people continue to shop/work with literally weekly if not daily.

Wikipedia might not be the best source but they have a list of companies that have had data breaches, but there is a huge list of companies that have had public breaches.

Just to name a few and their sources that you people everywhere still use because the majority of people don't care about privacy or security.

Apple - https://www.theguardian.com/technology/2013/jul/22/apple-dev... AT&T - https://www.theguardian.com/technology/2010/jun/10/apple-ipa... Barnes and Noble - https://www.nytimes.com/2012/10/24/business/hackers-get-cred... Capital One - https://www.cnn.com/2019/07/29/business/capital-one-data-bre...

There's plenty of other examples on here - but I agree with the parent, Google could implode and leak everything and the average person could not be bothered to change their emails or stop using Google.

InitialBP··on What You Can't Say (2004)
"Deleted from social media" is a pretty weak definition of "being cancelled".

Regardless of whether you agree or not "cancelling" is more about large scale boycott of a person and the media or services associated with them. It's not "Just" about blocking someone on social media, and it often has significant impacts on the business or the individuals who are being cancelled.

InitialBP··on Zelensky video deepfake
Disclaimer: I know basically nothing about ML.

I think the idea is that data needed to imitate a _specific person_ would require less data. Overall a model like that might have orders of magnitude more data in general and maybe a smaller amount required to imitate the features of a particular one.

I imagine it like - A master cabinet maker can make new variations of cabinets super easily once they've made hundreds of similar cabinets?

InitialBP··on Cities should not pay for new stadiums
> In addition to the local population, many people travel to cities where sports matches, concerts, and other events (e.g., conventions, auto shows, etc.) are held in the stadiums.

The article directly addressed this point by saying:

While counter-intuitive, tourism does not see an increase as the result of a sporting event, as often a similar amount would be spent by that city’s residents in a different city, thus creating no real net gain.

Now this may not be true for concerts or other events held in the stadium, but in general I think the idea is that the study indicates sports events don't generate significant tourism, instead drawing a primarily local crowd.

I would also argue that most people would have no issue(or minor issues) with local governments subsidizing _Some_ of the cost of a new stadium and other forms of entertainment. I think the issue comes in when the financial cost is extraordinary (> 1 billion USD).

← PreviousPage 3 of 5Next →