HNHacker News
TopNewBestAskShowJobs

TrueDuality

2,337 karma · joined July 21, 2016

submissionscomments
TrueDuality··on LinkedIn wins court order blocking mass scraping of user data
Huh. Well, federal court so national precedent against creating accounts to scrape registration only content. Probably a good thing IMO. I would put money on the public statement by a LinkedIn official saying "Your profile is yours" will bite them in the future as they certainly don't treat it that way.
TrueDuality··on AI coding has made CI a bottleneck, so we reworked ours to keep up
Internal costs are rising directly due to AI spend, we're still figuring out cost control and budgeting around this but are expecting this to basically become a new per-employee cost to factor in.

I would say internal morale and productivity has improved. We have explicit policy guidance and a general collective distaste of pasting AI responses which is what usually sours me on interactions with people that are fully gargling the kool-aid. My CI experience has gone down from ~1.5 hours to less than five minutes and I can actually run our entire platform locally on my laptop again. My personal experience has improved at least.

Externally, you're probably right that we're not really capturing user sentiment well about how our company's changes are impacting them. I can concretely say that there were several customers that were disappointed that our public change log notes have been about the same length. They were expecting us to go through our feature backlog faster because we we're starting to use AI.

On the other hand, we have had fewer outages, reached our fifth 9 consistently over the past four months which is a new company record in the 11 years its been tracked. We have had fewer support tickets, our customer retention rate is the highest it has ever been in the company's history, and we're growing our internal teams. Based on the evidence I have available to me, I would say that we're healthier than before both from a user sentiment perspective and an internal morale perspective.

TrueDuality··on AI coding has made CI a bottleneck, so we reworked ours to keep up
A good chunk of what my company has been doing with AI falls into either burning down our known tech-debt and "easy wins" that no one ever had the bandwidth to approach... And improving / automating our processes. The former is having a direct and meaningful impact on the quality and availability of our services.

Our QA, formerly a fairly frequent blocker of all our releases, are doing more in-depth reviews and catching issues earlier in our release process. They have become unblocked to the point they are actively chasing down work that starts to slip.

We have cleaned up and tuned both our security alerts and operations logs and improved our tenant isolation in our service in a way that makes customer and formal audits SIGNIFICANTLY easier.

We're setting ourselves up for faster human development of the hard-things. Our development environment and infrastructure are faster, cleaner, more auditable processes, and cheaper overall to operate.

These fixes mostly don't show up in our product change logs, and definitely don't fall into "new features". It would largely be invisible to the outside world, but our costs are going down (though to be fair, not offsetting the spend on AI to date), internal productivity has improved, operational incidents are down, and customer satisfaction is up.

TrueDuality··on Being ambitious and being a dad
I have a kid with my partner and I'm still not sure it was the right decision for me. They do become a full-time job in their own right and there is a whole set of skills that you can kind of learn through books but is going to be unique to your little one.

The first couple of months were especially hard as they don't have much of a personality, don't really react much to the world around them, they're just feeding, sleeping, and growing. Starting at the beginning of the third month for me it started changing and every baby is kind of unique.

I now _detest_ most of the books/articles/child-rearing advice I've encountered. Most of all of their content is fluff to pad pages, a blog roll, and are frequently superseded by more modern research backed evidence. There is a lot of toxic advice in those books and systems as well, usually for parents that are prioritizing restoring their prior social lives over the well-being of their children.

It's time-consuming and exhausting, but I haven't found it to be _hard_ yet. Waking up in the middle of the night and giving your kid a hug and maybe reading to them a bit when they have a nightmare isn't a challenging task. The challenging tasks are exceptions (surprise medical issues, your daycare closing down with two days notice, etc). The baby and child industry put a cost premium on the clothes targeting them and they don't last very long due to the child's growth. I _saw_ this coming but not to the extreme it has actually manifested and you'll find it replicated in every child/baby sized item.

There are a lot of surprising upsides and my motivations have definitely changed since we had a kid. I will flip a mountain to see my kid smile and laugh, it hits deep. I enjoy spending time with her and I'm terrified of missing her achievements and milestones. When she comes to me and asks me to show her how something works, wants a book read to her, or just wants a hive five I get a double whammy of that serotonin once for being a Dad that she wants to engage with and once for getting to spend time with her.

I still, and unfortunately kind of frequently, miss what I have effectively sacrificed to have her. I am slower at staying on top of emerging trends, hobbies have been left by the wayside that I did for decades, I gave up running conferences and with it I drifted away from whole treasured social groups. None of this was really a surprise, but I didn't realize how much what I gave up was really part of who I was.

TrueDuality··on Responding to the next frontier of critical cyber capabilities
You should go read the actual technical reports of the incidents and the follow on reports about the capabilities of smaller models in similar kinds of environments. This isn't new. The things exploited are still pretty basic in old and poorly maintained software or in gaps in architecture that were intentionally poked against security policies.

Are the findings valid? Yeah they're still doing security and they're still finding real zero-days. I think the internet is going to be bleak not because these models can ALL do basic security research but rather that the baseline quality of all deployed software is so low.

TrueDuality··on Responding to the next frontier of critical cyber capabilities
Ah yes let the FUD continue. This is a real problem but so far not nearly as severe as any of the marketing has made it out to be to the overall detriment of everyone including these companies announcing these scary capabilities. These announcements always included half hearted attempts at security layers which has now been demonstrated to benefit attackers more than defenders.

I wish I had a real solution to this beyond a dark age of the Internet where people have to finally come to terms with the general poor quality all modern software tends to normalize at.

TrueDuality··on Stateless MCP has recaptured my interest
What you're describing is a harness implementation detail not something specific to the MCP protocol or even how skills behave. Both of those are effectively providing the same level of information to the harness. Harnesses have traditionally (and still generally do) exposed enabled MCP servers and their actions ahead-of-time in the system prompt directly instead of doing progressive disclosure.
TrueDuality··on Optimization Solver as a Service
Really not trying to be cheeky... but why? Who is the audience here? I can see maybe academics with small grants and want to do the absolute minimum spend on compute... But that is an audience you will have to fight for every cent.

This doesn't solve or provide guidance for the subtle problems in these otherwise opensource solvers... The first example requires the client to manually disambiguate equivalent variables to get a stable solution... Sure that's a pretty common problem everyone working with optimizers should be familiar with but they're also one of the hardest things to track down in a complex derived model.

TrueDuality··on Ask HN: Are systems ready for the first negative leap second?
The problem frequently crops up in order-deterministic systems that use time and haven't accounted for the edge case of all the vagaries related to time-keeping of this being only one.

I've worked on some extremely sensitive systems that had thousands of lines of C dedicated to handling skewing a time gap across an hour-per-second when necessary. I know that code assumed only "missing" time (jump-forwards)... Even knowing what I know as a developer now, if I was re-implementing that system from scratch and didn't have this top-of-mind, I'd bet I would miss "overlapping" or "duplicate" time entirely.

Maybe that is more of a me problem than others, but I'd bet there are some safety critical systems out there where the responsible engineers, QA, and specs all missed this as well.

TrueDuality··on Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
Do you want to trust your company's legal commitment on the output of modern LLMs?
TrueDuality··on An incoherent Rust
The article itself covers the specific reasons that has led to that exact problem and the potential solutions available in the ecosystem with their various trade-offs.
TrueDuality··on Illinois Introducing Operating System Account Age Bill
A big chunk of the problem with this kind of legislation for me is that it inherently indicates a failure to govern to me. I disagree with the premise of the solution, but even more so this is trying to legislate a specific engineering solution for our current systems rather than any form of financial, objective guidance, or have reasonably actionable and enforceable consequences.

While laws that target engineering decisions are sometimes reasonable, they are always accompanied with specific guidance from a credible academic based institution (e.g. mechanical and civil engineering use private licensing bodies and develop specific curriculum and best practices).

The only time this law will ever be enforced is punitively for other crimes against major actors who are extremely limited in number. It is unenforceable for Linux, trivial for Apple, Microsoft, and Google to add to their OS. Presumably easy to spoof, the law describes it as minimal but once again, there isn't a specification so who knows. Websites won't be liable, they're getting a sweetheart deal here.

In practice what this law does is absolve abusive platforms an from any responsibility. It adds extra meaningless work and overhead for legitimate adult platforms while opening themselves up to new potential legal challenges, and ultimately doesn't replace the responsibility its removing.

This doesn't make children safer. This doesn't make the internet safer. This kind of legislation makes it easier to abuse children online by removing responsibility from platforms that are known to be dangerous to them yet profit from their presence the most.

TrueDuality··on DNS-Persist-01: A New Model for DNS-Based Challenge Validation
This is publicly publishing the account ID. There is an optional extension in RFC8659 that extends it but it isn't required by any implementer. This puts that ID into a public well known location that is easy to scrape and will be (this is exactly the kind of opsec info project like Maltego love to go lookup and pull in).
TrueDuality··on DNS-Persist-01: A New Model for DNS-Based Challenge Validation
The accounturi is an optional extension. Email, and phone are also optional. This is the first challenge that publicly requires you to specify your account ID publicly. There may be implementations that require it but neither Let's Encrypt or the protocols require them.
TrueDuality··on DNS-Persist-01: A New Model for DNS-Based Challenge Validation
I think this is solving a real operational pain point, definitely one that I've experienced. My biggest hesitation here is the direct exposure of the managing account identity not that I need to protect the accounts key material, I already need to do that.

While "usernames" are not generally protected to the same degree as credentials, they do matter and act as an important gate to even know about before a real attack can commence. This also provides the ability to associate random found credentials back to the sites you can now issue certificates for if they're using the same account. This is free scope expansion for any breach that occurs.

I guarantee sites like Shodan will start indexing these IDs on all domains they look at to provide those reverse lookup services.

TrueDuality··on IP Addresses Through 2025
I'm not sure the distinction matters, and attribution is inherently hard and easy to get wrong. I frequently read Country X is doing Y, less as a indicator of government action and more of a single that we can't be more specific of who within the country is performing an action but we know the behavior is occurring there.

In the case of IP address purchases, these are publicly tied to specific public and private entities and can be easily queried through the regional registries. These private entities are frequently the same kind of shell company you'll get with hiding shady financial details.

TrueDuality··on Slate AX: Wi-Fi 6 Gigabit travel router
Pretty unlikely in my book. This runs OpenWRT out of the box. Given, there are still closed source binary blobs in these things, especially around WiFi 6 and frequently the customizations for the kernel isn't released, but those tend to be more expensive locations to place backdoors especially when the system is very open to inspection. These kind of devices are VERY frequently torn down by security researchers and used in WiFi shoot-outs leading to much higher potential increased detection of anything present.

A lot of this these "backdoor" style hypothesis' still need a motive justification for the cost. Who would they be targeting? What is the potential value of the backdoor?

Given the visibility and complex locations required for the firmware, this would be an expensive backdoor to put in place for any amount of time. The attack is completely untargeted, at best you may be able to say tech enthusiasts that travel. You probably can't count on executive targeting, this device requires a separate battery pack as well as per-site configuration as opposed to pairing to their iPhone and not carrying all that extra stuff.

What are the chances of an expensive, high-visibility backdoor showing up in a dirt cheap product line for a high-risk untargeted attack? Pretty low in my book but your threat model may vary.

TrueDuality··on Coarse is better
I love the inherent wonder and joy in this post around the original images.
TrueDuality··on Claude Opus 4.5
Now THAT is great news
TrueDuality··on FBI tries to unmask owner of archive.is
This is a false equivalency I'm surprised no one else has brought up. An archive of a site preserves attribution inherently, the scraping and training are not.
TrueDuality··on Normalize Identifying Corporate Devices in Your Software
Yeah you're 100% right that it's optional. It's usually only required to allow company data such as email, slack, file sharing etc on your personal device. If you're on-call it is VERY rare for an employee to win a fight on making the company provide a dedicated device for that purpose (which can inherently make it a condition of your job but that's an exception).

Most employees tend to not care about the why and are happy to just do it making "you" (the one bucking the trend) the oddball. The one not being the team player. It's not legally required, and you won't be fired for it, but its strongly socially encouraged and that makes it mandatory for anyone not willing to put up that fight.

TrueDuality··on Normalize Identifying Corporate Devices in Your Software
Having a device enrolled in an MDM package does not make it a corporate device. Many corporations require personal devices be managed to support remote wiping. If I install a productivity or developer tool on my personal phone or laptop for personal non-corporate use I would get mistaken as a corporate user by this process.

If you want to collect this information you should be clear about it and know and understand your edge cases before you start attempting enforcement actions based on it if that is the intent.

In general in my experience, personal tools are a VERY hard market to sell into for corporate environments (I took a peek at what the software on OPs site requires a commercial license to use). I would bet most if not all of what you're catching here is unauthorized installs in a corporate environment and you're more likely to loose interested users than sell more commercial licenses.

TrueDuality··on The human only public license
I haven't decided my opinion on this specific license, ones like it, or specifically around rights of training models on content... I think there is a legitimate argument this could apply in regards to making copies and making derivative works of source code and content when it comes to training models. It's still an open question legally as far as I know whether the weights of models are potentially a derivative work and production by models potentially a distribution of the original content. I'm not a lawyer here but it definitely seems like one of the open gray areas.
TrueDuality··on MIT physicists improve the precision of atomic clocks
Another commenter mentioned that this is needed for consistently ordering events, to which I'd add:

The consistent ordering of events is important when you're working with more than one system. An un-synchronized clock can handle this fine with a single system, it only matters when you're trying to reconcile events with another system.

This is also a scale problem, when you receive one event per-second a granularity of 1 second may very well be sufficient. If you need to deterministically order 10^9 events across systems consistently you'll want better than nanosecond level precision if you're relying on timestamps for that ordering.

TrueDuality··on Kairos: Immutable Distro for K8s at the Edge
That is also what I came here to find out. Would love to hear from the creators of the project how it compares and contrasts to Talos. We've been running Talos for a few bare-metal and air-gapped cluster deployments with pretty good success but do have some pain-points.
TrueDuality··on WASM 3.0 Completed
The irony for me is that it's already slow because of the lack of native 64-bit math. I don't care about the memory space available nearly as much.
TrueDuality··on Run Erlang/Elixir on Microcontrollers and Embedded Linux
You don't necessarily need on-package RAM for this. I'm not sure I'd build a project around this, but 16MiB of RAM would hardly be BOM killer.
TrueDuality··on A blog does not need “analytics”
I write primarily as a means to collect my thoughts and outcomes around projects. I keep analytics on my site not to optimize for any particular audience but because it feels validating and that I'm contributing in another form.

I still see high traffic on a post explaining oddities in some of Route53's unintuitive behaviors and hope I'm making someone's day a little better in giving them a solution.

That drives me to write more.

TrueDuality··on About Containers and VMs
LXC far predates docker regardless of size or impact. It's not disingenuous if you were literally the foundation docker was able to package into a shiny accessible tool.
TrueDuality··on Internet Access Providers Aren't Bound by DMCA Unmasking Subpoenas–In Re Cox
Remember that under the last reign of the current present, information services were removed from Title II regulation. Biden did vote to restore the net neutrality status last year but that was challenged in court and never went into effect. It was ultimately overturned in January and we're left without net neutrality protections.
Page 1 of 17Next →