HNHacker News
TopNewBestAskShowJobs

Thriptic

3,517 karma · joined February 3, 2014

submissionscomments
Thriptic··on Amazon Ring went from a smart doorbell company to a surveillance network
You set your camera system up yourself. A lot of people aren't going to be willing or able to do that if we are being real. Do you see the average person wiring up a bunch of cameras or troubleshooting networking, configuring a DVR, standing up a web server to view things, setting up off site backups, ensuring their cameras don't go down if power is lost, configuring mobile alerts, etc?

People want a plug and play solution. At least systems from Google and Amazon will probably be reasonably secure so they won't get roped into the next botnet when their owners forget to change default creds.

Thriptic··on Amazon Ring went from a smart doorbell company to a surveillance network
A. It's a detective and corrective control so you can more easily claim losses with insurance and the police, see what has been taken, and know that someone was there.

B. It's a preventive control. People doing recon on your place will see that visible security is in place and that you have done some level of risk management. Perhaps you have other security measures there as well such as an alarm, or maybe you secure your valuables with a safe or they are stored off site which they can't know until they get in. It makes you a less appealing, higher risk target. Additionally, in most neighborhoods you can't walk around in a ski mask without attracting attention, so many burglaries will be done with faces exposed. If someone bursts in and sees they are on camera, maybe they leave without taking anything.

Thriptic··on Clear backpacks, monitored emails: U.S. students under constant surveillance
I agree, let's look at the numbers. ~ 300 school shootings in ten years averages out to 30 a year. There are about 100,000 schools in the US. That's a risk rate of 0.03% per school per year risk. Considering that very few people within a given school die per attack, this means that your risk of being killed in a school shooting is basically negligible. Further, your article talks about ANY shooting on school grounds including gang shootings, domestic violence (adults), and accidental firearms discharges so A. almost certainly incidents will be clustered and a middle class school in some random place like what's in the article will have far less overall risk, and B. the actual number of real shootings of the kind that would make the news is far less than 300 over ten years.

The risk of being involved in every other incident class I listed is higher, so that is where we should be focusing our efforts because ultimately a death is a death regardless of what people are scared of. This is basically the terrorism problem: terrorism in the US is this big scary boogieman until you actually look at the data and realize that there's very little terrorism. The school shootings make the news precisely because they are very rare and surprising (and because some media outlets have readership that is in favor of strict gun control so it will play well).

If you want controls to stop school shootings anyway then why not just put in place general healthy population controls: stop bullying, keep a cop visibly on school grounds to deter criminality, engage with parents, and create a healthy environment for learning. All of that costs basically zero dollars and would likely do far more overall good than these silly, expensive, and invasive surveillance systems.

Thriptic··on Clear backpacks, monitored emails: U.S. students under constant surveillance
Poor, emotion driven risk management as usual. School shootings kill very few people per year and are rare events (especially in places that can afford this tech) despite what the New York Times would have you believe. Why not focus efforts on things that actually do kill young people, namely:

* Car crashes (teach people to drive more defensively)

* Suicides (provide better mental health services)

* Violence that occurs outside of school (intervene to stop conflict before it becomes an issue, which would also help prevent these shootings)

* Opiods

Thriptic··on Senate takes another stab at privacy law with proposed COPRA bill
If you don't force that then users will simply say "well I really love Instagram..." and click ok. An average user can't place a value on their privacy because they can't see the long term threat from using these services. This is where we need regulations in the same way that we needed cigarette regulations back in the day to deal with long term health threats.
Thriptic··on Senate takes another stab at privacy law with proposed COPRA bill
Fair enough. This is why we have lawyers and subject matter experts (which I am not). I am just expressing a general sentiment. Codifying that into an actionable set of laws and regulations requires much more work.
Thriptic··on Senate takes another stab at privacy law with proposed COPRA bill
Once again we continue to look at data privacy and identity theft in the wrong way in my opinion. To me the solution is very simple. If you are reselling my data, allowing access to my data, or deriving data / servives from my data that identifies me in any way and then selling that to a third party for a profit or giving it to them as part of a license so that they can generate profit from it (including ad targeting or analytics) then when I visit your site or use your service there should be a big box in simple to understand English, not legalese or a lengthy EULA, that says "we [do one of the things listed above], are you ok with that?" If I say "no", then you cannot descriminate against me and you cannot do those things. You still have to let me use your site or service; you still have to provide me with identical services; etc. You can still show me ads (non-personalized), charge me a bit more money commensurate with the value of my data, or introduce a different monetization method, but you can't deny me service all together.

Further, if you collect my data, YOU are liable for it. Breaches should not be the user's problem. Meaning, if someone walks off with the contents of your database containing my PII using anything less than a crazy number of zero days, you are liable for a set financial penalty per user's info lost (in the way HIPAA does it) and / or you are liable in perpetuity for protecting against identity theft with an insurance policy. I don't need to prove attribution. If I ever have a problem that could plausibly be linked back to the data exposure, you are liable for damages.

Finally, it should not be the user's problem to clean up identity theft, ever. If a bank opens an account in my name without properly authenticating me, that is the bank's problem, not mine. It should be up to them to conclusively prove it was me that did it, not up to me to prove that I didn't. Does this mean it will be more complicated to open up various accounts and credit? Yes. Does it mean that there will be lost business for these institutions? Yup. Tough luck; that is the price we have to pay.

The entire point of this should be to heavily disincentivize collection of PII unless absolutely necessary for core business function.

Thriptic··on I'm not burned out, I'm pissed off
I agree with everything you said. To expand on point 3, when you are pitching a security change, know your audience. Most people hear security change and they think another inconvenient pain in the ass that I'm going to have to deal with. That changes if you can show them benefits to people or to the business that are not security related. For example, traditional approach:

Boss: You are advocating spending a lot of money on a configuration management solution, why?

Sec: Well it can help prevent heterogeneity in our environment which can lead to different versions of software being run, some of which may be old and buggy and therefore exploitable.

Dev team: So now we need to do change management meetings and institute even more controls? No, this will slow us down!

Ops: Sigh, another fad system we will have to support, learn, and test.

Boss: This seems like a lot of money and inconvenience for a theoretical problem, no.

Better approach:

Boss: You are advocating spending a lot of money on a configuration management solution, why?

Sec: Because it's a win for the business. Our Dev teams can avoid dependency hell and be confident that code they develop on their machines is going to work in production because our production environment will mirror the development environment. This will let them ship faster and spend more time doing real work. Ops will be able to scale much faster and spend less time dealing with configuration issues. Imagine being able to develop a config and spin up 50 servers with it at the same time while you sit back and sip a soda! No more fixing damaged boxes, just replace them! No more fighting with the dev teams! Oh yeah, we also get a security benefit for free while making our lives easier as we won't have to deal with heterogeneous software running on our boxes which presents a security vuln. The ROI for the business will be large.

Everyone: wow sounds great, let's do it!

Thriptic··on Before buying Ring, WEMO or Roku, consider privacy issues
That's not my point. If we want to talk about the societal impact of mass security camera adoption, fine, but that has little to do with picking a Ring camera for personal use specifically. The only thing that differentiates this from other security camera products is that it's marginally more convenient for police to get access to data if the user wants to submit it. The advice in the article is silly because it doesn't say "don't get a camera because it's helping to create a police state", it's saying "just don't get this one camera".
Thriptic··on Before buying Ring, WEMO or Roku, consider privacy issues
I'm confused about the issue with Ring here. The primary complaint seems to be that users can share data with police if they want and that police can then save that data. Ultimately that's product agnostic; someone could easily take footage from any camera and show it to police voluntarily, and users could always be compelled to hand over footage of a crime with a warrant. People have zero control over how neighbors use their personal cameras and I don't see why that should impact personal buying decisions, even if you decide to never share data with police. What's the problem?
Thriptic··on Personal and social information of 1.2B people discovered in data leak
It's a legit service. I use them and they did ensure that my data was removed from the services they specified. Obviously I'm just some person on the internet so my statement has no intrinsic credibility, but I believe they were also validated in a nyt article awhile back.
Thriptic··on Personal and social information of 1.2B people discovered in data leak
> I want someone to start an opt-out service, where I send them $20, and they send a book of names by registered mail for opt-outs every month

This exists but it's not cheap: https://www.abine.com/deleteme/

Thriptic··on The trouble with VPN and privacy review sites
This is somewhat a non-value adding comment, but thanks for your work man! I'm using a VPN set up with Algo now for day to day use and I love it!

I am going to try to figure out how to deploy a home VPN solution using it this weekend.

Thriptic··on Hospitals pledge to fight admin price transparency plan in court
I'm not justifying the situation, I'm simply saying this is how it works which is why the situation plays out how it does.
Thriptic··on Hospitals pledge to fight admin price transparency plan in court
Lab tests are particularly complicated to price because usually they are being processed by someone else. Usually labs won't even try to get an authorization from insurance until they get your sample and start working on it as it affects their turnaround time which is one of their main differentiators, and each insurer will have different rules about what they will pay for under what conditions (insurers also have separate deals with each individual hospital and potentially individual doctors or groups of doctors). The short answer is they can't tell you because they don't know.
Thriptic··on Hacker Publishes 2TB of Data from Cayman National Bank
Sorry where are you seeing that from that link?
Thriptic··on Hacker Publishes 2TB of Data from Cayman National Bank
Please see the other child post
Thriptic··on Hacker Publishes 2TB of Data from Cayman National Bank
These are the ones I am aware of:

https://pastebin.com/0SNSvyjJ

http://pastebin.com/raw.php?i=cRYvK4jb

https://m.youtube.com/watch?v=oI_ZhFCS3AQ

Thriptic··on Hacker Publishes 2TB of Data from Cayman National Bank
She also attacked the Barcelona police department, the Turkish government, and stole money from various Bitcoin wallets to donate to the Kurds iirc. Her write-ups are always really great reads and very enlightening.
Thriptic··on A Week with Chauffeurs Showed the Major Flaw in a Self-Driving Car Future
It probably could increase quite a lot because more people might be willing to live far away and enjoy cheaper / more housing if it means that commuting won't be dead time. With self driving cars you could actually work during your commute. As you point out, a number of existing commuters might also transfer from train to car travel.
Thriptic··on Why scientists need to be better at data visualization
I agree with everything you said and can confirm that in our (translational vascular bio) lab the bulk of effort spent on paper drafting was concerned with creation of high quality figures. Many scientists (myself included), will read a paper abstract and then head straight for the figures as they usually contain the highest density of data for the reader.
Thriptic··on Diamonds Keep Getting Cheaper
I categorically disagree with this, but let's run with the logic. If we are talking about financial commitment and signaling to a partner, why not gift a house, a car, a long term bond, cash, expensive clothing, a watch, literally any other piece of jewelry, etc? Why does it have to be a diamond which is literally the worst possible use of the money short of burning it? Why does it have to be publicly displayed on a ring if the intention is personal signaling? Why does it have to be the guy that does it; shouldn't the wife also signal equal levels of commitment or is she incapable of that?

Also, we can bypass this kind of thing and did up until the last century. Further, certain couples bypass this type of thing all the time routinely. You don't see gay male couples giving each other diamond engagement rings and yet their marriages aren't exploding in spectacular fashion.

It doesn't even make sense from a financial penalty standpoint. Anyone who is on an upward trajectory would be able to bounce back from losing a month or two of salary relatively quickly in which case it's not really forcing long term commitment.

There is no real point to this ritual other than showing off. The guy gets to show off how much cash he has and the woman gets to show off to everyone else that she has a guy with a lot of financial resources. It is completely arbitrary and we have arbitrarily converged on a diamond as a mechanism to do this. Sure giving rings makes people feel good; receiving and gifting any present makes people feel good; but it's absolutely not a necessary requirement for a healthy relationship.

Thriptic··on As L.A. ports automate, some workers are cheering on the robots
Yes you could which is why you have contractors. However, it turns out that with "creative" work it's a lot harder to implement that payment model without having an incentives problem.
Thriptic··on As L.A. ports automate, some workers are cheering on the robots
Because then they might take excessively long breaks and get paid for not working. It would be extremely difficult to audit time spent working while being plagued by inefficiencies vs time spent messing around. Paying per delivery aligns incentives and is easy to audit. It also incentivizes truckers to push on dock workers to be more efficient which is in the entire supply chain's best interest.
Thriptic··on As L.A. ports automate, some workers are cheering on the robots
Should developers keep their job if they fail to deliver every sprint and miss deadlines? At the end of the day we are all judged by output; it just so happens that output is more easily measured in trucking (ie the status is binary) than in development.
Thriptic··on Hospitals are a weak spot in U.S. cybersecurity
It's really tough. You have a function which is viewed purely as a cost center; you have a totally porous environment where you're required to admit tons of minimally-verified people into confidential spaces; staff and affiliates need different levels of access from all over the world; there are critical availability demands where temporary denial of service for security reasons is unacceptable; device development is optimized for safety and fault tolerance as opposed to security which isn't ever really tested for; patients need to be able to submit tons of data in myriad forms; there are few central clearing houses for transmitting data so people are all calling each other with minimal validation; etc
Thriptic··on Netflix, HBO and Cable Giants Are Coming for Password Sharers
In my comment I explicitly note that I am not stealing content and am in fact probably paying for more content than most users. I am expressing my annoyance at the current business model, not advocating or admitting to piracy.
Thriptic··on Netflix, HBO and Cable Giants Are Coming for Password Sharers
> It's fairly clear to me that these complaints, while real, aren't the core issue which is: people would rather get content for free than pay for it. So a lot of the time they will.

That's not a fair framing. It's not that people want everything for free, it's that they aren't willing to pay an arm and a leg to get everything. I'm happy to pay for 2-3 networks (and do) for 30-50 or so a month but in return I want EVERYTHING meaning live sports and all the shows with no region blocking. I am not willing to pay 150 per month for that and I am not willing to pay 50 for a small subset of content which comes and goes. Sorry, the product was overpriced as a bundle and is still overpriced as an a la carte offering. I don't currently torrent but I understand why other people do as the current setup is highly irritating. You can say I'm being unreasonable and maybe I am, but it is how I feel.

Thriptic··on How to Steal a Billion
I don't think it's that simple. Sure, money in a billionaire's possession probably isn't going to be used for consumption, but it's not like that money is chilling in a matress somewhere; it is invested. Those funds are a source of capital for public companies, seed funding for small businesses, VC investments for growing companies, charitable contributions potentially, even funds for countries through bonds etc. I'm going to stay away from making pronouncements on how this money ought to be used; I'm merely pointing out that the situation is more nuanced than how you have framed it.
Thriptic··on Googlers Are Protesting Company’s Deals with Big Oil
You do a basic background check and investigation which I'm sure Google already does and just add strong political opinions as a parameter to flag. If you're willing to protest against your employer then you are probably already sharing strong opinions on things like social media so these individuals should be detectable.
← PreviousPage 5 of 29Next →