HNHacker News
TopNewBestAskShowJobs

Nextgrid

29,786 karma · joined February 21, 2019

Old man yelling at the cloud.

Contact: hi@rjevski.io

submissionscomments
Nextgrid··on Resizing windows on macOS Tahoe – the saga continues
Attach a generator to him and the AI datacenter energy needs are solved. Even better, the more trash that AI produces the more energy is generated.
Nextgrid··on Show HN: Geo Racers – Race from London to Tokyo on a single bus pass
I think the "limited budget" mechanic should be scrapped - instead make the budget unlimited but rank the submissions based on the lowest budget.
Nextgrid··on Spotify: Our best developers haven't written a single line of code since Dec
Anna's Archive recently tested that successfully.
Nextgrid··on TikTok is tracking you, even if you don't use the app
They can just ignore it and get away with it: https://noyb.eu/en/microsofts-xandr-grants-gdpr-rights-rate-...

The "success" of GDPR is greatly overstated here. In practice, breaching it is the winning strategy.

Nextgrid··on Reports of Telnet's death have been greatly exaggerated
SSH without proper key management offers marginal benefits compared to telnet.
Nextgrid··on Google Fulfilled ICE Subpoena Demanding Student Journalist Credit Card Number
A prepaid SIM or burner phone can still be purchased no? I believe the CC requirement can be bypassed if you create your Apple ID from trying to "purchase" a free app (or for the accounts that do require payment, I wonder if a gift card can be used).
Nextgrid··on Google Fulfilled ICE Subpoena Demanding Student Journalist Credit Card Number
Alternatively, use them pseudonymously? There's little reason any of these companies need to know your real identity. This will both reduce the likelihood of ICE finding your account from a real-life interaction, as well as reduce the likelihood of ICE finding your real-life identity if they do get your account data (they'd at least need to dig through it more than just going by first/last name on the account itself).
Nextgrid··on ClawHub
VirusTotal is completely useless for this though? You need enough people to be pwned by that particular piece of malware for it to be flagged as dangerous, by which point the attackers would've already repacked it so it doesn't match the previous signature.
Nextgrid··on Vercel's CEO offers to cover expenses of 'Jmail'
To be fair, computers are slow if you intentionally rent slow & overpriced ones from really poor-value vendors like cloud providers. For people who started their career in this madness they might be genuinely unaware of how fast modern hardware has become.
Nextgrid··on Vercel's CEO offers to cover expenses of 'Jmail'
Tech bros and VCs need to eat, that's how.
Nextgrid··on Vercel's CEO offers to cover expenses of 'Jmail'
Isn’t it just serving static content and the content fitting in RAM? If so your laptop can serve it just fine even.
Nextgrid··on AT&T, Verizon blocking release of Salt Typhoon security assessment reports
Even if let's say lawful intercept is done away with and calls are end-to-end encrypted, the telco would still be in control of key management and distribution... and if those clowns can't secure lawful intercept, why do you think the key distribution infrastructure would fare any better?
Nextgrid··on Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM
Corporate security is beyond merely making sure software itself is secure.

Phishing for example requires no security vulnerabilities, and is one of the primary initial attack vectors into a company.

You need proper training and the right incentives for people to actually care and think before they act.

Nextgrid··on Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM
Defense in depth and multiple layers of security should ideally protect against zero-days; see the Swiss cheese model of accidents for an example; most aviation accidents are rarely caused by a single factor but an improbable combination of factors.

This is why I also think “zero trust” and internet-accessible SaaS has done so much damage to the industry. Before, if your version control server has a vuln, the attackers still need to get on your VPN to even be able to scan for that vuln. Now, your version control server is on the internet and/or is an SaaS and all it takes is an exploit or a set of phished credentials for anyone anywhere in the world to get in.

Nextgrid··on GitHub is down again
> have you considered moving or having at least an alternative

Not who you're responding to, but my 2 cents: for a popular open-source project reliant on community contributions there is really no alternative. It's similar to social media - we all know it's trash and noxious, but if you're any kind of public figure you have to be there.

Nextgrid··on Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM
The purpose of cybersecurity products and companies is not to sell security. It's to sell the illusion of security to (often incompetent) execs - which is perfectly fine because the market doesn't actually punish security breaches so an illusion is all that's needed. It is an insanely lucrative industry selling luxury-grade snake oil.

Actual cybersecurity isn't something you can just buy off-the-shelf and requires skill and making every single person in the org to give a shit about it, which is already hard to achieve, and even more so when you've tried for years to pay them as little as you can get away with.

Nextgrid··on Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM
> How they haven't been sued into bankruptcy is something I'll never understand.

Isn't most off-the-shelf software effectively always supplied without any kind of warranty? What grounds would the lawsuit have?

Nextgrid··on Stories from 25 Years of Software Development
I think the problem is the legacy Unix-style concept of shared libraries and how anything touching native code is deeply intertwined with the OS itself.
Nextgrid··on OpenClaw is changing my life
I find that security, architecture, etc is exactly the kind of skill that takes 10-15 years to hone. Every boot camp, training provider, educational foundation, etc has an incentive to find a shortcut and we're yet to see one.

A "basic" understanding in critical domains is extremely dangerous and an LLM will often give you a false sense of security that things are going fine while overlooking potential massive security issues.

Nextgrid··on Italy Railways Sabotaged
80k is 6.6k/month. That’s pre-tax, but for the benefit of the doubt let’s go with this figure instead of the post-tax.

Have you seen the prices of stuff nowadays? Whether energy, cars, technology or rent? 6.6k doesn’t go far at all anymore. Of course the post-tax is even lower.

> which would indicate you are living near the edge of your means

Real-estate being an investment means its price will adjust to extract maximum value. There’s an entire industry there that makes sure you can’t just work around this problem by adjusting your living standard or eating less Starbucks & avocado. Move to a farther away place? Well now you’re spending that rent reduction on transport instead. Move to a lower quality place? Well now you’re spending it on higher energy bills trying to keep the house warm. Willing to sacrifice all your social life and move in the middle of nowhere with ultra-cheap rent? Most roles are “hybrid” to prevent this very scenario, so can’t do that either.

Nextgrid··on Italy Railways Sabotaged
The bad actors here are the social media platforms who host and promote divisive content since it generates more engagement thus ad revenue. Those are very much in reach of law enforcement and regulations can be passed to forbid such engagement-maximizing behavior. Simply moving back to chronological feeds of accounts the user explicitly chose to follow would be a big first step in curbing the spread of propaganda.
Nextgrid··on Italy Railways Sabotaged
50% tax is absolutely not typical in the US as far as I know unless you can provide sources? I thought it was around 30% thanks to all the various schemes and deductions one can use?

I live in Bulgaria. My effective tax rate here is around 20%. Next destination is Dubai which is even lower, because again, if rich politican assholes’ kids are going there to live the good life, why not follow them in their grift?

(Would I recommend Bulgaria? Well the tech money you make is enough to live like a king and privately pay for all the services a government is supposed to provide… but then again it’s no different from the UK where I also had to pay for everything privately except I could barely afford it because I also had to burn 50% of my income on taxes with nothing in return, so from that perspective Bulgaria wins. Make of it what you will. Switzerland appears to be the only place with a functioning government and fair taxes, except the property Ponzi is reaching such breaking points that whatever you save on taxes is getting burnt immediately on rent, so you’re no better)

Nextgrid··on Italy Railways Sabotaged
“Decent” in the form of hopefully not dying while you’re on the waiting list.

And bankruptcy is only a problem when you actually have significant assets, something not easy to acquire in western EU countries. If you’re the average under-30 western EU resident, bankruptcy won’t make a major difference in your lifestyle, it’ll be shit either way.

Nextgrid··on Italy Railways Sabotaged
Only if you can’t fly to a neutral low-tax country and enjoy low tax and not being sent to war. But you do you, I do me.

(And of course, if they don’t have a problem with stealing over half of the fruits of your labor, do you really think they won’t send you to fight for them when the chips are down anyway?)

Nextgrid··on We mourn our craft
You hire the junior developer because you can get them to learn your codebase and business domain at a discount, and then reap their productivity as they turn senior. You don’t get that with an LLM since it only operates on whatever is in its context.

(If you prefer to hire seniors that’s fine too - my rates are triple that of a junior and you’re paying full price for the time it takes me learning your codebase, and from experience it takes me at least 3 months to reach full productivity.)

Nextgrid··on We mourn our craft
An LLM isn’t (yet?) capable of remembering a long-term representation of the codebase. Neither is it capable of remembering a long-term representation of the business domain. AGENTS.md can help somewhat but even those still need to be maintained by a human.

But don’t take it from me - go compete with me! Can you do my job (which is 90% talking to people to flesh out their unclear business requirements, and only 10% actually writing code)? It so, go right ahead! But since the phone has yet to stop ringing, I assume LLMs are nowhere there yet. Btw, I’m helping people who already use LLM-assisted programming, and reach out to me because they’ve reached their limitations and need an actual human to sanity-check.

Nextgrid··on Italy Railways Sabotaged
With social media encouraging and promoting divisive bullshit it’s really not hard for a hostile power to influence local groups to do their bidding.

Social media should be the main target of all these defense groups, but sadly politicians themselves derive their power from it so it’s unlikely anything tangible will be done.

Nextgrid··on Italy Railways Sabotaged
Anyone can fly a quadcopter though? You can buy one right now for a couple hundred bucks off Amazon (and strap explosives to it if you wanted to).

If anything, the fact we’re not seeing random drones carrying explosives and diving into groups of people on a daily basis shows the vast, vast (99.999%) majority of people is actually well-meaning and has no desire to kill or hurt anyone.

If you’re legitimately baffled by a random guy being able to fly a quadcopter around without any kind of government approval or oversight, I encourage you to buy one and play around (without explosives please!), just make sure to not fly it over places where people could be standing - terminal velocity is real and even a light one could cause serious injury if it were to lose control and fall on someone’s head.

Nextgrid··on The F Word
LLMs could be a good option to navigating this sludge. Fight fire with fire.

Another option is work smarter (not harder, because nothing I do is anywhere near “hard work”) to get into a position where you can tell them to get fucked. Don’t want to pay my hotel bill? Oh well, good luck finding someone else to rework your auth system. Call me back when the outsourced monkeys you hire end up putting you in the news for a security breach. But at least you saved a few hundred bucks on hotel fees, great job!

This is something management and executive positions do on a continuous basis - using their position and “prestige” to commend respect and bend the rules. But as an engineer with context of a critical system you often have more leverage, it’s just a matter of using it strategically (as engineers we initially start out playing the good game, but the thing is that everyone else is trying to fuck you - the challenge is learning to fuck back).

I keep a beginner’s Python book in reserve for those conflictual meetings where some idiot beancounter or manager has a problem with me. When I’m ready to walk (and at this point I have a very short fuse for obvious bad faith), I offer it to them as a tool to help them finish my job; not a single soul has yet to take me up on that offer. Some idiots suggested me the way to the door a few months later (offer gladly accepted, and replacement gig acquired) and watching from a distance it’s clear they would’ve been better off actually taking that book off me - either for themselves or the idiots they tried to hand my tasks to.

The only way to enact change is to actually make the noxious behaviour costly. If you take on the costs yourself there’s no reason for them not to persevere with their misguided strategy.

Nextgrid··on We mourn our craft
If you’re repeatedly prompting, I will defer to my usual retort when it comes to LLM coding: programming is about translating unclear requirements in a verbose (English) language into a terse (programming) language. It’s generally much faster for me to write the terse language directly than play a game of telephone with an intermediary in the verbose language for it to (maybe) translate my intentions into the terse language.

In your example, you mention that you prompt the AI and if it outputs sub-par results you rewrite it yourself. That’s my point: over time, you learn what an LLM is good at and what it isn’t, and just don’t bother with the LLM for the stuff it’s not good at. Thing is, as a senior engineer, most of the stuff you do shouldn’t be stuff that an LLM is good at to begin with. That’s not the LLM replacing you, that’s the LLM augmenting you.

Enjoy your sensible use of LLMs! But LLMs are not the silver bullet the billion dollars of investment desperately want us to believe.

← PreviousPage 4 of 34Next →