HNHacker News
TopNewBestAskShowJobs

abadpoli

789 karma · joined September 26, 2023

submissionscomments
abadpoli··on GitHub cuts AI deals with Google, Anthropic
This presumes that it will be real humans that have to “take care” of the code later.

A lot of the people that are hawking AI, especially in management, are chasing a future where there are no humans, because AI writes the code and maintains the code, no pesky expensive humans needed. And AI won’t object to things like bad code style or low quality code.

abadpoli··on People Are Sick and Tired of All Their Subscriptions
Electricity and water are things that we don’t mind (or even want) people using less of. The same can’t really be said for Spotify etc.
abadpoli··on Boeing 787s must be reset every 51 days or 'misleading data' is shown (2020)
Airbus A350s had the same issue: https://www.theregister.com/2019/07/25/a350_power_cycle_soft...

We’re just going to see more and more issues like this as more and more software is used in applications like this. I would be willing to bet that a Tesla would also spontaneously crash if left on for hundreds of hours, but they just rarely if ever are left on that long.

abadpoli··on Internet Archive breached again through stolen access tokens
There never will be an adequate industry-wide certification. There is no universal “good enough” or “when to stop” for security. What constitutes “good enough” is entirely dependent on what you are protecting and who you are protecting it from, which changes from system to system and changes from day to day.

The budget that it takes to protect against a script kiddy is a tiny fraction of the budget it takes to protect from a professional hacker group, which is a fraction of what it takes to protect from nation state-funded trolls. You can correctly decide that your security is “good enough” one day, but all it takes is a single random news story or internet comment to put a target on your back from someone more powerful, and suddenly that “good enough” isn’t good enough anymore.

The Internet Archive might have been making the correct decision all this time to invest in things that further its mission rather than burning extra money on security, and it seems their security for a long time was “good enough”… until it wasn’t.

abadpoli··on U.S. Judge Asked to Collect $1.4M Moldovan Judgment Against Cloudflare
None of what you just said about US law is relevant here. Yes, Cloudflare has to abide by international law where it operates. This is established and every company across the globe is subject to it.

Cloudflare operates in and has a physical data center presence in Moldova, serves content owned by Moldovan citizens, and serves content to Moldovan citizens. Thus, they are subject to Moldova law. If they don’t want to be subject to it, they can remove their operations from the country and remove any interactions with Moldovans.

abadpoli··on Hetzner Object Storage
If us-east-1 ever suffered a “FULL” data loss, it would be a company-ending event for so many companies that it would practically end society as we know it.

OVH’s failure was a single building. That’s the problem with a lot of server hosters - even Google has their availability zones all co-located in the same building, so a physical event like a fire could take down an entire region. AWS has AZs in physically separate locations, each with 1+ separate DCs.

abadpoli··on Google says it won't follow Amazon's lead with a return-to-office mandate
> AWS ProServe never had a RTO mandate

Before Covid, no team had an RTO mandate, so ProServe wasn’t really special here. In ProServe you were still expected to be in an office regularly, but it was just understood that you wouldn’t be in an Amazon office all the time because you’re likely at a client’s office instead.

Post-covid, it’s mostly the same, although now even many clients aren’t requiring consultants to come in. But when they do, you’re expected to be there.

abadpoli··on Our container platform is in production. It has GPUs. Here's an early look
This undersells the fact that there’s a lot more to infrastructure management than “janitoring”. You and many others may want to just say “here’s my code, ship it”, but there’s also a massive market of people that _need_ the customization and deep control over things like load balancers, because they’re pumping petabytes of data through it and using a cloud-managed LB is leaving money and performance on the table. Or there are companies that _need_ the strong isolation between regions for legal and security reasons, even if it comes with added complexity.

A lot of developers get frustrated at AWS or Azure because they want to deploy their hobby app on it and realize it’s too difficult dealing with stuff like IAM - it’s like trying to dig a small hole in your garden and someone suggests you go buy a Caterpillar Excavator, when all you needed was a hand trowel. The reason this persists is because AWS doesn’t target the hobby developer - it targets the massive enterprise that does need the customization and power it provides, despite the complexity. There are, thankfully, other companies that have come in to serve up cloud hand trowels.

There is no “one size fits all” cloud. There probably never will be. They’re all going to coexist for the foreseeable future.

abadpoli··on Working in the office 5 days/week to build company culture is a myth: PwC report
You’re completely off the mark here. I’ve worked at a Big4 company before on reports like this. These reports aren’t paid for by other companies at all. They’re internally funded and done by the internal research teams. The motivations behind them are numerous: marketing, having artifacts to help rank at the top of stuff like Gartner reports, and even because believe it or not the people that work there sometimes genuinely enjoy researching and publishing reports. Reports like this are the consulting company equivalent of a tech company’s engineering blog bragging about their new scalable infrastructure or whatever.

If you see a report published by a company that says “PwC did research for us”, then yes, it has likely been influenced by that company. But a report like this that is entirely PwC branded is not that.

abadpoli··on Dokku: My favorite personal serverless platform
Can we not do this? Everyone knows that “serverless” doesn’t actually mean there are no servers. It’s not productive to do this “haha gotcha!” trope every time someone uses the serverless term.

Serverless refers to the fact that you can launch individual workloads on the platform while abstracting away the underlying infrastructure. Yes, to set up dokku you still need to provision a server. But to deploy an application onto dokku after it’s been set up, you do that without worrying about provisioning new infra for your app. That’s what is “serverless” about it, and it’s a perfectly acceptable use of the term.

abadpoli··on Continuous reinvention: A brief history of block storage at AWS
> whether I'm managing 100 of the same thing or 1,000 - if I've built proper automation my only additional overhead is replacing failed hardware

Hahahah surely this is a joke, right?

If it’s so easy and you already had solved all these problems, why didn’t someone already build it? Why didn’t you build EBS, since you apparently have all the answers?

abadpoli··on Schwab users are unable to log in
Ah, yes, my original comment was a little unclear. I actually wasn’t logging in on new device vs existing device, it was that I had logged in to one device before 9:30est (presumably before the surge began) and just had an existing already-logged-in-session.
abadpoli··on Schwab users are unable to log in
It’s the largest trading volume day in years and everyone that isn’t living under a rock is trying to log into their banks to check their portfolio. The banks can’t handle the surge logging in.

It’s not that suspicious. Not everything is a conspiracy.

abadpoli··on Schwab users are unable to log in
I’ve been a Schwab user for years, and was a TDA user as well before the merger. TDA had just as many issues like this. Don’t let your recency bias fool you.

Schwab is overall a great bank and brokerage. Fidelity’s user experience quite frankly is much worse, as is E-Trade’s. Vanguard is even worse than those. IBKR looks nice, but the hassle hasn’t been worth it to me. Schwab has been great for me so far.

abadpoli··on Schwab users are unable to log in
I’m not sure how the inability to login is “more complex”. I clearly state in my comment that logging in wasn’t working.
abadpoli··on Schwab users are unable to log in
Both Fidelity and Schwab were fine for me on devices where I was already logged in, but logging into a new device wasn’t working.

This seems like a common issue - even if backend systems can take the load, login systems all seem to have a lower TPS limit and have a lot of trouble during big surge events like this. It reminds me a lot of when a new video game releases where the issue is often the login servers being overloaded.

abadpoli··on Launch HN: Roame (YC S23) – Flight search engine for your credit card points
> corporate travelers actually do not get the most value/benefit from points travel because corporate travelers already fly on business. Flying on business class is just a given.

I’m not sure what your background is, but this seems like a starkly false assumption to me. I’ve worked in multiple industries, including consulting (the one most famously known for frequent corporate travel) and I wouldn’t even come close to saying it’s a “given”. Only very high levels executives or the very elite companies fly their employees business class. In my years and years of weekly travel for consulting, my company paid for business class a grand total of 0 times (I’ve flown business a handful of times, but always upgraded with my own points). My colleague has only flown business paid for by the company once on a particularly long international flight.

I think you’re really shooting yourself in the foot by not paying more attention to corporate travelers. Corporate travelers are by _far_ the most likely to have credit card or loyalty points to spend, but it seems like you’re just brushing them off.

abadpoli··on What would it take to recreate Bell Labs?
My take is that it’s related to the parent commenter’s thoughts on the relative monopoly that Bell had.

If you’re a monopoly with no practical competition, sharing your accomplishments gets you good will and has little downsides. But if you’re Microsoft, and one of your big moats and competitive advantage is the massive fleet of data centers you’ve been building up over the years, you don’t want to hurt yourself by giving your competition the information they need to build new, more efficient data centers.

abadpoli··on What would it take to recreate Bell Labs?
I imagine they would do something like this: https://news.microsoft.com/source/features/innovation/datace...

These innovations don’t always have to be “marketed” to be shared. Things like this get developed and used internally, and then sometimes the company likes to brag about their accomplishments, even if it’s not an externally facing product.

abadpoli··on What would it take to recreate Bell Labs?
There is an insane amount of innovation happening at Google and Microsoft et al. The amount of investment going into efforts like making data centers more power efficient, making better cooling systems, reducing latency or using fiber more efficiently etc is incredible and rivals the work done at Bell Labs back in the day. You just don’t hear about it because these private companies have no incentive to share it.

And that’s entirely separate from the fact that Generative AI wouldn’t even be a thing if not for the research that Google published.

abadpoli··on AWS Secrets Manager Agent
The motivation is in the project’s readme, down at the bottom.

The tl;dr is that this is for legacy software where you can make HTTP calls to retrieve a secret, but for some reason cannot use the AWS SDK. If you can use the SDK, you should use that instead of this proxy.

abadpoli··on AWS Secrets Manager Agent
The extent of the “conversion” required would pretty much just be taking one form of JSON output and transforming it into a different JSON output, which is pretty easy to do in a few lines of Python or a single jq command. It would likely be more work and hassle to have to install and manage a secrets proxy, rather than just writing a few transformation lines, or better yet just using the SDK of the service you’re using.

Even this secrets manager proxy that the OP is about is explicitly to be used in legacy situations where you can’t use the AWS SDK, which is preferred because it does all of the stuff you mentioned for you.

However, this is Hacker News! If you think you see a problem that can be solved that other people don’t, why don’t you build it?

abadpoli··on Linksys Velop routers send Wi-Fi passwords in plaintext to US servers
The article and source material are light on details here. My guess is that it is using HTTPS, but the researchers saw the plaintext password in the request and assumed “password in plaintext always bad”.

If the app isn’t using HTTPS, then the story would be much bigger than just the password being plaintext.

abadpoli··on Linksys Velop routers send Wi-Fi passwords in plaintext to US servers
The router itself has an internet connection but that doesn’t necessarily mean that all of the other stuff required to actually route traffic or connect other devices is configured (like DHCP).

It’d be possible to have some sane defaults in there to make it work, but I wouldn’t count on them to be 100% out in the field of who-knows-what-crazy-settings-this-consumer-has.

> sending the wifi credentials plaintext that is not secure

If the connection between the app, router, and cloud server are all HTTPS, then it’s probably more secure to do it that way than it would be to send it over an unconfigured, insecure WiFi network (which typically uses HTTP or unsigned certificates for the management interface).

abadpoli··on Linksys Velop routers send Wi-Fi passwords in plaintext to US servers
> But the experience of using a speical-purpose WiFi network is janky on many common devices so I understand not taking that choice.

Yea, this is my hunch as well as to why this works this way. Consumers are easily confused, and asking them to disconnect from their currently working internet connect and connect to a router that hasn’t yet been set up (and might not be able to provide an internet connection) can get confusing. I know I’ve been in this situation before where I’ve been connected to a special-purpose network without internet connect, need to look up some instructions online, but then remember I can’t because I’m not connected to the internet…

abadpoli··on Linksys Velop routers send Wi-Fi passwords in plaintext to US servers
Is this actually plaintext, or is this plaintext-inside-HTTPS? The article and source material don’t say.

It’s pretty normal for passwords to be “plaintext” inside an HTTPS request. That’s how practically every login to a web app works. If it’s not HTTPS, there’s a whole slew of other issues along with putting a plaintext password in the request.

If it is HTTPS, then the issue really is just that the password gets sent anywhere rather than staying local. This is a lot more debatable as a practice, but unfortunately is also common for a lot of routers to support their cloud/app management functionalities.

abadpoli··on Elixir Anti-Patterns
I was a python main before I started using elixir and I had similar thoughts, but after becoming more familiar with it, I actually think elixir is far less verbose than python.

They’re different enough languages that it’s really difficult to just open up an elixir codebase and try to read it. Elixir, like ruby, has a lot of syntactic sugar that just won’t make sense if you approach it with a Python mindset. Elixir is also functional, which can be a pretty big mind bender.

It’s really a language that you need to start from the basics and go through the tutorials to learn the basic syntax, operators, etc and write your own small programs. If you’re like me, you’ll just end up discouraged if you expect to be able to learn Elixir just by reading existing code.

abadpoli··on Elixir Anti-Patterns
Part of this story is a self fulfilling prophecy. If devs like you avoid using Elixir because you’re afraid it isn’t popular enough, then it isn’t going to become more popular!
abadpoli··on Astronauts take shelter in Starliner, other spacecraft after satellite breakup
No, that isn’t the case at all. The issues with Starliner do not affect its ability to return to earth or function as an “escape pod” if that were necessary. There’s no safety issue or concern at all with using Starliner as a return craft. The issues with Starliner, as has been mentioned many times over the last few weeks, are to do with other parts of Starliner that don’t affect its return (it’s literally the thrusters that aren’t even part of Starliner that _will_ return).
abadpoli··on Astronauts take shelter in Starliner, other spacecraft after satellite breakup
I don’t see what that has to do with this story, though. Starliner’s issues have nothing to do with the breakup of a satellite nor do the issues affect Starliner’s usage as a shelter.

This article and headline just reek of the author grasping at straws to try and shoehorn Starliner into this story. The headline could’ve easily said “shelter in Soyuz” and nothing would’ve changed about the actual story at hand.

Page 1 of 5Next →