2,337 karma · joined July 21, 2016
I would say internal morale and productivity has improved. We have explicit policy guidance and a general collective distaste of pasting AI responses which is what usually sours me on interactions with people that are fully gargling the kool-aid. My CI experience has gone down from ~1.5 hours to less than five minutes and I can actually run our entire platform locally on my laptop again. My personal experience has improved at least.
Externally, you're probably right that we're not really capturing user sentiment well about how our company's changes are impacting them. I can concretely say that there were several customers that were disappointed that our public change log notes have been about the same length. They were expecting us to go through our feature backlog faster because we we're starting to use AI.
On the other hand, we have had fewer outages, reached our fifth 9 consistently over the past four months which is a new company record in the 11 years its been tracked. We have had fewer support tickets, our customer retention rate is the highest it has ever been in the company's history, and we're growing our internal teams. Based on the evidence I have available to me, I would say that we're healthier than before both from a user sentiment perspective and an internal morale perspective.
Our QA, formerly a fairly frequent blocker of all our releases, are doing more in-depth reviews and catching issues earlier in our release process. They have become unblocked to the point they are actively chasing down work that starts to slip.
We have cleaned up and tuned both our security alerts and operations logs and improved our tenant isolation in our service in a way that makes customer and formal audits SIGNIFICANTLY easier.
We're setting ourselves up for faster human development of the hard-things. Our development environment and infrastructure are faster, cleaner, more auditable processes, and cheaper overall to operate.
These fixes mostly don't show up in our product change logs, and definitely don't fall into "new features". It would largely be invisible to the outside world, but our costs are going down (though to be fair, not offsetting the spend on AI to date), internal productivity has improved, operational incidents are down, and customer satisfaction is up.
The first couple of months were especially hard as they don't have much of a personality, don't really react much to the world around them, they're just feeding, sleeping, and growing. Starting at the beginning of the third month for me it started changing and every baby is kind of unique.
I now _detest_ most of the books/articles/child-rearing advice I've encountered. Most of all of their content is fluff to pad pages, a blog roll, and are frequently superseded by more modern research backed evidence. There is a lot of toxic advice in those books and systems as well, usually for parents that are prioritizing restoring their prior social lives over the well-being of their children.
It's time-consuming and exhausting, but I haven't found it to be _hard_ yet. Waking up in the middle of the night and giving your kid a hug and maybe reading to them a bit when they have a nightmare isn't a challenging task. The challenging tasks are exceptions (surprise medical issues, your daycare closing down with two days notice, etc). The baby and child industry put a cost premium on the clothes targeting them and they don't last very long due to the child's growth. I _saw_ this coming but not to the extreme it has actually manifested and you'll find it replicated in every child/baby sized item.
There are a lot of surprising upsides and my motivations have definitely changed since we had a kid. I will flip a mountain to see my kid smile and laugh, it hits deep. I enjoy spending time with her and I'm terrified of missing her achievements and milestones. When she comes to me and asks me to show her how something works, wants a book read to her, or just wants a hive five I get a double whammy of that serotonin once for being a Dad that she wants to engage with and once for getting to spend time with her.
I still, and unfortunately kind of frequently, miss what I have effectively sacrificed to have her. I am slower at staying on top of emerging trends, hobbies have been left by the wayside that I did for decades, I gave up running conferences and with it I drifted away from whole treasured social groups. None of this was really a surprise, but I didn't realize how much what I gave up was really part of who I was.
Are the findings valid? Yeah they're still doing security and they're still finding real zero-days. I think the internet is going to be bleak not because these models can ALL do basic security research but rather that the baseline quality of all deployed software is so low.
I wish I had a real solution to this beyond a dark age of the Internet where people have to finally come to terms with the general poor quality all modern software tends to normalize at.
This doesn't solve or provide guidance for the subtle problems in these otherwise opensource solvers... The first example requires the client to manually disambiguate equivalent variables to get a stable solution... Sure that's a pretty common problem everyone working with optimizers should be familiar with but they're also one of the hardest things to track down in a complex derived model.
I've worked on some extremely sensitive systems that had thousands of lines of C dedicated to handling skewing a time gap across an hour-per-second when necessary. I know that code assumed only "missing" time (jump-forwards)... Even knowing what I know as a developer now, if I was re-implementing that system from scratch and didn't have this top-of-mind, I'd bet I would miss "overlapping" or "duplicate" time entirely.
Maybe that is more of a me problem than others, but I'd bet there are some safety critical systems out there where the responsible engineers, QA, and specs all missed this as well.
While laws that target engineering decisions are sometimes reasonable, they are always accompanied with specific guidance from a credible academic based institution (e.g. mechanical and civil engineering use private licensing bodies and develop specific curriculum and best practices).
The only time this law will ever be enforced is punitively for other crimes against major actors who are extremely limited in number. It is unenforceable for Linux, trivial for Apple, Microsoft, and Google to add to their OS. Presumably easy to spoof, the law describes it as minimal but once again, there isn't a specification so who knows. Websites won't be liable, they're getting a sweetheart deal here.
In practice what this law does is absolve abusive platforms an from any responsibility. It adds extra meaningless work and overhead for legitimate adult platforms while opening themselves up to new potential legal challenges, and ultimately doesn't replace the responsibility its removing.
This doesn't make children safer. This doesn't make the internet safer. This kind of legislation makes it easier to abuse children online by removing responsibility from platforms that are known to be dangerous to them yet profit from their presence the most.
While "usernames" are not generally protected to the same degree as credentials, they do matter and act as an important gate to even know about before a real attack can commence. This also provides the ability to associate random found credentials back to the sites you can now issue certificates for if they're using the same account. This is free scope expansion for any breach that occurs.
I guarantee sites like Shodan will start indexing these IDs on all domains they look at to provide those reverse lookup services.
In the case of IP address purchases, these are publicly tied to specific public and private entities and can be easily queried through the regional registries. These private entities are frequently the same kind of shell company you'll get with hiding shady financial details.
A lot of this these "backdoor" style hypothesis' still need a motive justification for the cost. Who would they be targeting? What is the potential value of the backdoor?
Given the visibility and complex locations required for the firmware, this would be an expensive backdoor to put in place for any amount of time. The attack is completely untargeted, at best you may be able to say tech enthusiasts that travel. You probably can't count on executive targeting, this device requires a separate battery pack as well as per-site configuration as opposed to pairing to their iPhone and not carrying all that extra stuff.
What are the chances of an expensive, high-visibility backdoor showing up in a dirt cheap product line for a high-risk untargeted attack? Pretty low in my book but your threat model may vary.
Most employees tend to not care about the why and are happy to just do it making "you" (the one bucking the trend) the oddball. The one not being the team player. It's not legally required, and you won't be fired for it, but its strongly socially encouraged and that makes it mandatory for anyone not willing to put up that fight.
If you want to collect this information you should be clear about it and know and understand your edge cases before you start attempting enforcement actions based on it if that is the intent.
In general in my experience, personal tools are a VERY hard market to sell into for corporate environments (I took a peek at what the software on OPs site requires a commercial license to use). I would bet most if not all of what you're catching here is unauthorized installs in a corporate environment and you're more likely to loose interested users than sell more commercial licenses.
The consistent ordering of events is important when you're working with more than one system. An un-synchronized clock can handle this fine with a single system, it only matters when you're trying to reconcile events with another system.
This is also a scale problem, when you receive one event per-second a granularity of 1 second may very well be sufficient. If you need to deterministically order 10^9 events across systems consistently you'll want better than nanosecond level precision if you're relying on timestamps for that ordering.
I still see high traffic on a post explaining oddities in some of Route53's unintuitive behaviors and hope I'm making someone's day a little better in giving them a solution.
That drives me to write more.