HNHacker News
TopNewBestAskShowJobs

ZeroSolstice

81 karma · joined November 13, 2022

submissionscomments
ZeroSolstice··on Autonomous trucking is harder than autonomous rideshare
Correct this is the best path forward. Night time is typically when there is less traffic and we should be able to at least utilize that for autonomous transportation between distribution centers. Then slowing keep upping the advancement as roads are repaired, replaced, etc. If you build a smart road for lets say just trucking, now you can map out the best places for distribution centers, similar to what UPS, Fedex figured out for air transportation and packages.

Its a bit ridiculous that in 2024 we have all these apps that tell you about accidents and obstructions but none that actually help re-direct traffic in a meaningful way. You have to hedge your bets on any "suggested" better route.

With smart roads department of transportation could get real analyze on crowded intersections, best place for future on/off ramps, access roads, etc. Traffic congestion and planning is usually an after thought when housing developments go up and then its a catch-up game.

ZeroSolstice··on Autonomous trucking is harder than autonomous rideshare
No. One form of transportation doesn't have to exist for everything. Rail is the long haul and trucking is the last mile.

Autonomous trucking should start out with its own dedicated part of the highway between distribution centers. We are trying to build autonomous driving to accommodate our current road structure which humans currently drive on. A dedicated / isolated lane with sensors, etc should be the start. Start small and then you can expand after getting feedback data. Everything is always so costly and unattainable because everyone wants to implement it with the current infrastructure but its not needed.

For reference we already do these types of dedicated lanes with ezpass express or HOV lanes.

ZeroSolstice··on [dead]
From your [2] source even the first line is just a numbers game.

  Organized retail crime costs retailers more than $700,000 for every $1 billion in 
  sales on average...

Guess that reads better than 0.07%. It is interesting to see the NRF meeting include cyber risk along side retail theft.
ZeroSolstice··on Maybe you don't need SRE?
I see a clear evolution (and career) path for Sysadmins here. From ssh-ing and rebooting machines to operating higher-level tools and influencing the business.

Is this what people think sysadmins and operations do all day? Any place i've worked with an operations team, they were the group deciding on datacenter sites, switches, routers, architecture, operating systems, configuration management, monitoring, services like DNS, dhcp, network security, access control, on-boarding / off-boarding, etc. If you weren't in operations you didn't deploy or make decisions on production changes. At a few other places this was split into an operations and infrastructure groups that worked closely together as they had to plan EOL replacement and new build-outs together.

"Wisdom arrives to anyone exposed to how systems behave. SRE shouldn’t rob developers this learning opportunity."

SRE has always seemed to just be a push for a dedicated sysadmin that can read/write code to support a specific application in production. As noted in the quote above, you can just replace SRE / developers with development / operations. Its the same circle all over again.

Lastly, on-call is just companies being cheap. For startups this might be a good initial solution but for anything that has to be online you should have 24/7, follow-the-sun support teams. This allows for teams to solve problems within their normal work day and not have someone up all night to fix a problem, brief everyone on the issue, and then if they are lucky have the next day off.

ZeroSolstice··on Tell HN: I salute everyone on call/working support through the holidays
I'm going to be a bit pedantic and say fault and mistake are not equal in the message they convey. Hans says he has 'made a mistake' which is not the same as saying 'I'm at fault.' In the end it might be proven that you are at fault but until then all you know is that something went wrong, isn't working, etc.
ZeroSolstice··on Tell HN: I salute everyone on call/working support through the holidays
I agree. If a part failed or broke unexpectantly it makes no sense to say it was `your fault` or `you made a mistake`. The goal is the solve the issue at hand and following the representative's instructions to either fix it or prove the item is defective is the easiest way to get there. If it was a mistake on your end you learned something new but I don't see any additional benefit by saying you made a mistake when you don't know what went wrong.
ZeroSolstice··on Knowledge is cheap – Skills are all you need
Any company I've worked for has a 60 - 90 day trial period as part of employment. Most that I've seen, never use it due to fear of being sued or it not really being a long enough period to assess how someone will work out.
ZeroSolstice··on Knowledge is cheap – Skills are all you need
Isn't this just a helpful tell though? If the interviewer isn't creative enough to speak off script in their field or the company doesn't allow a bit of flexibility in interviews what makes you think they would do interesting work?

Interviews where people just ask these filtering type questions signals to me that this is just another job. If you already have a job its not worth switching as it will just be more of the same. If I can't get into a some what interesting conversation with the interviewer and this is what the company has put forward as their representative, oh well. If my second call isn't with someone I would be working with or knowledgable in the field then whats the point of even talking to them. I interview quite a bit and the amount of phone calls some start-ups and companies want to have as part of the interview is insane. Most of the time the people doing the interviews would rather be doing something else.

ZeroSolstice··on Why it's taking so long for Americans to get payments instantly
I'm specifically talking about refunds not purchases as in US only a few states have laws relating to returns and refunds.[1] Otherwise its left up to the retailer to set the policy. Most purchasers are not making large amounts of interest on their checking accounts compared to the balance amounts a business would carry. If no settlement happens on the weekends I can see a large advantage to a business holding one million dollars in refunds for two extra days before you complete or run the batch job of refunds.

When I make a purchase I don't get to decide when to run the batch job for it to post/settle. Retailers however can determine when they want to actually process refunds. What can a customer complain about when the posted refund shows up on the following Monday, Tuesday, Friday, two weeks later?

To further my point of retailers not being incentivized to process your refund quickly there was a small study done that delaying refunds had customers "re-spending" the refund before it had fulled settled.[2]

[1] https://www.freeprivacypolicy.com/blog/return-refund-us-laws...

[2] https://hbr.org/2023/06/how-retailers-can-capitalize-on-the-...

ZeroSolstice··on Why it's taking so long for Americans to get payments instantly
I don't know many businesses that would perform processes that don't make them money. Even if we use your example of next business day what happens on a Friday where the refund isn't processed until Monday or Tuesday? Is customer satisfaction really increased if you get their refund back to them in 3, 7 or 10 days?

In instances where you have to ship the defective product back. They don't send you an over-night, next day label to get the product back to them as soon as possible. They send it ground. So you paid for a product, you then wait for the product, you then call to get a refund, you ship it back, they receive and process and then you get refunded your original amount. That could be two weeks, even though your refund was settled next business day.

I'd be surprised if any retailer takes a loss with a refund that they can't send back to the manufacturer or write off.

It also seems that there isn't any set refund time limit and varies per state in the US.[1]

[1] https://www.freeprivacypolicy.com/blog/return-refund-us-laws...

ZeroSolstice··on Why it's taking so long for Americans to get payments instantly
"Large companies and financial institutions also often "play the float" with larger sums for-profit—namely, the interest income they earn on an amount by speeding up its deposit into their accounts or slowing down a presentation for payment[1]."

IMF eLibrary with some example scenarios[2]. Granted they speak of most of the float data being analyzed with checks, it doesn't seem unreasonable to replace "check" with "credit card" transaction.

[1] https://www.investopedia.com/terms/f/float.asp

[2] https://www.elibrary.imf.org/display/book/9781557753861/ch10...

ZeroSolstice··on Why it's taking so long for Americans to get payments instantly
"Fed delays have cost consumers hundreds of billions in overdraft fees, check-cashing fees and late fees, said Aaron Klein, a senior fellow at the Brookings Institution."

Why would banks be incentivized to speed up this process? They make money off the delay and get to blame the Federal government. Its the same reason a purchase can be done instantly but then it takes up-to (10) business days to be refunded. Banks and retailers make interest off the money they hold onto. Being able to make money off the refund is a probable reason why they are even offered. Otherwise it would be all-sales-final.

ZeroSolstice··on Revenge bedtime procrastination
I agree with your point here. It is unclear to me how "lack of sleep" was derived from your initial comment. I'm hoping wiseowise can expand upon their mostly generic comment to clear the confusion.
ZeroSolstice··on Revenge bedtime procrastination
Can you expand on your definition of "lack of sleep"? Since sleep is something that isn't uniformly measurable and is both relative and subjective to the individual what are you measuring to consider it lacking?

Sleep doesn't really work in the realm of arithmetic and there is no way to credit extra sleep because you slept in on Saturday so how can you "lack" sleep because you stayed up longer one night verse the previous night?

What if you did an extra exercise that day are you now lacking sleep because you exerted yourself more?

ZeroSolstice··on Chamberlain blocks smart garage door opener from working with smart homes
Seems that the Home Assistant user base, as determined by Chamberlain, is relatively small. To hardware/software hackers this type of vendor pull-out/lock-out should always be expected. However, since the end user has physical access to the device thinks like ratgdo[1] will always be an option. While the app integration is nice, garage doors still seem to be one of those things that just needs to work in proximity and a smart phone app and alarm.com / amazon integration are superfluous add-ons.

I bought mine from Costco for the simple reason that I could return it if broke.

[1] https://paulwieland.github.io/ratgdo/

ZeroSolstice··on Website hosted on ESP32
> At the registrar level: the .tk registrar was (in)famous for injecting both ads and random JS into websites that were hosted on domains registered against it.

I did a google search for domain hijacking, ad injection, javascript and while it does look like .tk domains had/have this issue it doesn't necessarily point to the registrar. After all they are offering free domain registration which is going to get abused. Its also not surprising when their own website doesn't use HTTPS, however their mission statement isn't about security on the Internet.

> The goal is always more (and more precise) data points. Being able to run JS on the same origin as the request is more valuable than just the rough GeoIP data the ISP already has.

But isn't this what Google, Bing, Amazon, Alibaba, already do when they fingerprint your device? They can't use just an IP addresses due to NAT so they collect unique characteristics to your specific device. My question was more so if advertisers can already get down to the device level when you visit their site, what is the ISP's motivation if their data won't be as unique or specific? or maybe a better question is what organizations would be buying the "less" specific data that an ISP could get from your session data?

ZeroSolstice··on Website hosted on ESP32
The attack you are suggesting is not commensurate to the types of blogs and information that _need_ HTTPS.

If you are operating at a level where your personal blog can have all possible transit paths compromised by a third-party such that they are hosting some or all resources that you provide for download, modifying them and producing new checksums then you have bigger problems than a blog that doesn't have HTTPS. You would also at that point consider using someone else's platform that will absorb or actively be motivated to thwart these exact scenarios. Not to say that always works out[1].

Additionally your concern of checksums being compromised can easily be thwarted by hosting packages on github, gitlab, bitbucket, pastebin, or a google groups mailing list. All of which still don't require your blog to have HTTPS. You don't have to manage getting your own certificate, paying for yearly renewals or setup any auto-90-day let's encrypt auto-bot.

Great grandma's cookbook recipes on a blog don't need HTTPS.

[1] https://www.zdnet.com/article/krebs-on-security-booted-off-a...

ZeroSolstice··on Website hosted on ESP32
I'm sure there is some nuance to what someones static site is serving but someones blog doesn't need to be HTTPS. If they are offering downloads you can provide checksums or verify their data through other sources or contacting them out-of-band.

Anything that needs some form of validation from any site should be verifiable in multiple ways. Just because they have HTTPS doesn't mean the provided information or data is automatically correct.

ZeroSolstice··on Website hosted on ESP32
What example would you have of an ISP or third-party injecting an ad or tracker within the HTTP response? I've certainly seen the DNS query hijacking and while HTTPS will encrypt the transmission, at the ISP level they already have your DNS query and src/dst IP address. Even with HTTPS based on session data it wouldn't be difficult label Netflix/Youtube traffic patterns.

Do you also have any reference to what exactly the collected data is useful for? I could see an ISP selling traffic data for a zip or area but they would already have that based on your billing address.

ZeroSolstice··on What the Goddamn Hell Is Going on in the Tech Industry?
Was there any additional ideas or insights you wanted to expand upon? I'm interested in what operational view points you have which would require more than 50 SRE's.
ZeroSolstice··on What the Goddamn Hell Is Going on in the Tech Industry?
I appreciate the examples but none of these items are difficult regardless of size of the organization. These are standard system and network administrative items or on-site technician work. Unless you have other data about the borg architecture to show, its entire premise from the paper[1] is that it just runs jobs and removes the developers needing to know about the underlying hardware or OS that its running on it.

From the paper I referenced its huge cluster and if its their own software I'm sure with the development experience at google they have accounted for loosing a cluster node. Losing any number of cluster nodes is the same scenario if you were performing an software or hardware upgrade in which case you would be taking a node offline. I would be very skeptical that there are people manually kicking off upgrade jobs for nodes in the cluster. Maybe an A/B deployment or burn-in for a week before fully pushing it out with a pipeline workflow. I'd more so say that their borg implementation probably runs at different minor versions frequently.

Google runs their own data centers, thats the video documentary I referenced[2].

For machine procurement I don't see that as a SRE task. If they are making custom boards and systems they are going to have an entire group supporting that. At the size of google I'm thinking they wouldn't be running into supplier issues that they could figure out easily or account for in their borg software. Again its supposed to be one big abstraction.

For the regulatory changes for services like SEO/advertising, GMAIL, search, etc they all have separate teams for those services and would seem separate from SRE's that are maintaining borg the service which is provided to those groups.

[1] https://research.google/pubs/pub43438/ (research paper on borg)

[2] https://www.youtube.com/watch?v=XZmGGAbHqa0 (documentary at their data centers)

ZeroSolstice··on What the Goddamn Hell Is Going on in the Tech Industry?
If you could expand on which parts you think would take more than 50 people to work on for a search engine that would be interesting to hear about. With the current cloud offerings hardware, processing, storage, high availability, etc are not really barriers to entry anymore and are offered as services.

There look to be a number of search engine startups[1] some big, some small.

[1] https://startupsavant.com/startups-to-watch/search-engine

ZeroSolstice··on What the Goddamn Hell Is Going on in the Tech Industry?
50 SRE's sounds like they could keep borg running. There really isn't that much details on what borg is made up of outside of a 2015 research paper[1].

Just to address the parts you laid out.

1. Keep Borg running

What would entail running? There are plenty of small teams that manage hundreds of servers and virtual machines through monitoring, deployment, networking, decom, etc lifecycle. This seems counter to purpose of cloud computing, commodity hardware and abstracted compute resources that can be deployed on-demand. Not to mention redundant sites, availability zones, <insert your cloud providers name for High Availability(HA) feature here>. Is this the part that SRE's maintain?

2. Machine maintenance

From documentaries[2] and other comparable data center operations this would seem to be handled by on-site datacenter staff. Disk replacement, physical replacement, network cabling, etc. Without any other operational info I would doubt resources would just be dedicated to borg as its a bit of a overall technician site work. As for OS and software updates and again without any other info or insight would seem to fairly automated after passing testing or at least passed to another team that just handles updates.

3. Machine procurement

Again commodity hardware or if its all custom still that would seem to be more of a EE task for build out and accounting for purchasing. Otherwise at Google's scale you would just get pre-populated racks delivered and replace the entire rack when 51% of the machines have failed. This doesn't really seem SRE or developer specific. It would also be happening for other services if they are already aren't abstracted from the underlying hardware/network layer.

4. Regulatory changes

I'm not sure what this would be in relation to a job processing system? Is this checking where you are saving data? Seems like a feature that is built once.

I agree that if you have follow-the-sun and need to be up with 5 (9's) 50 people in one time zone would be hard to ensure that but once the foundation is setup its just (50) people in a different location or timezone there isn't really anything too different about what they are doing.

If you have additional information or insight that would interesting to hear about.

[1] https://research.google/pubs/pub43438/ [2] https://www.youtube.com/watch?v=XZmGGAbHqa0

ZeroSolstice··on What the Goddamn Hell Is Going on in the Tech Industry?
Just an observation but its seems like your points run counter to each other. If I'm reading your idea correctly managing / leading 5, 10, 100, 1000, etc people appears to be (4) things:

1. Shielding the group 2. Provide non-technical analysis of the group/state of product 3. Remove road blocks 4. Provide resources

The industry that you are operating in seems to be adapted to the (4) principals you laid out.

ZeroSolstice··on The Resilience of Costco (2018)
In the event you were unaware of this, angle brackets are a form of quoting in markdown and other forums such as mailing lists. Multiple brackets are intended to show threaded conversations.

You quoted a statement that wasn't part of our conversation and seemed misplaced in our thread.

Based on your displayed reading comprehension level it seemed prudent to include the thread since you were unable to piece a few previous sentences together and were mis-quoting previous statements.

I've also decided to break out my sentences so they are easier for you or your screen reader to work with.

I hope whatever bot this is training works out well and can help improve its comprehension levels. Don't get too tired typing one sentence answers today, drink some water and take some breaks.

ZeroSolstice··on Ask HN: Why is HN not reachable through IPv6?
Agreed. I have seen a good bit of activity on the IETF opsec[1] and IPv6 operations[2] lists related to improvements.

[1] https://datatracker.ietf.org/wg/opsec/documents/ [2] https://datatracker.ietf.org/wg/v6ops/documents/

ZeroSolstice··on Ask HN: Why is HN not reachable through IPv6?
Do you have a reference for when the Internet as a whole was supposed to cut over to IPv6 only?

There are plenty of organizations that have transition mandates but those are self imposed and would easily be delayed for other monetary business objectives. The Internet as we know it was only created/available in 1993[1] and while some RIR's have exhausted their available IPv4 space it doesn't mean IPv4 addresses are not available.

[1] https://www.npr.org/2023/04/30/1172276538/world-wide-web-int...

ZeroSolstice··on The Resilience of Costco (2018)
Maybe you meant this response for another posting but I never stated the item you have quoted(>) above.
ZeroSolstice··on Ask HN: Why is HN not reachable through IPv6?
Yes this is a good observation. They would also be the first to be on the lookout for good deals on IPv4 space, furthering their acquisitions early on before the IP address market took off. Most notably though they would also be the companies working or providing suggestions on needs based policies for their respective RIR.
ZeroSolstice··on The Resilience of Costco (2018)
>I was asking about your experience since you indicated it happened to you. If you don't want to share thats fine

>>I just have written two paragraphs on my personal experience

I see. So you haven't directly experienced being yelled at or having your picture scrutinized, you just observed it happening to other people?

>seem to think that verifying your membership by asking for your card is "being treated like a criminal."

>>not at all what I said, but I think you knew that

I think its disingenuous to cherry pick parts of quotes. I'll list it out again so you see that it wasn't directed at you specifically.

"as quite a few commenters on the thread seem to think that verifying your membership by asking for your card is "being treated like a criminal."

I'll leave it to you to scroll through the thread if you want to see what I was speaking too.

>This will be the scenario you run into when your membership expires

>>Again, gift cards are highly regulated in my state. They don't suddenly lose all value contingent on the buyers standing at the store. You're making that up for some reason.

I think if you read the reviews from the link I referenced[1] there was no mention of loosing the cards value. I said Costco only let them use it once as a non-member. There are a number of different scenarios listed in the reviews that people ran into. If you don't want to read the reviews thats fine, but there is nothing being made up instead you are creating a scenario which wasn't stated. It makes no sense why I would do that and then provide you the link to the source of the information.

> Do you work for Costco?

I pointed you to the Costco site which is where I would go to find out about their policies and because of that I must "work" for Costco now? I was simply pointing out other peoples experiences as "non_members" which you alluded to as your future plan here with the cards.

Here are the reviews incase you missed the link previously, look through the (1) star reviews to see what I was talking about.

[1] https://www.costco.com/costco-shop-card.product.10024438.htm...

>Great, then apply your personal knowledge to where you live

>>That's... what I've been doing this whole time, thanks

Yes and where you live is known to you, not everyone in the thread. We were only granted the illuminating information of cards being "highly regulated in your state" later on in your response post. No one would have known this information prior to that.

← PreviousPage 2 of 5Next →