HNHacker News
TopNewBestAskShowJobs

andersonmvd

539 karma · joined August 4, 2014

Working at https://devops.security (from https://kakugo.ch)

--

about me & contact: https://dadario.com.br

best pic ever: https://jayub-intercomm.weebly.com/uploads/6/0/2/8/60283505/1443822731.png

--

I kinda like to code. I more or less like to do product management. But I'm always delighted to ship products that people love.

--

"If you want to set off and go develop some grand new thing, you don't need millions of dollars of capitalization. You need enough pizza and Diet Coke to stick in your refrigerator, a cheap PC to work on and the dedication to go through with it." - John Carmack (quote stolen from HN user nchelluri)

--

"when the rubber meets the road", love this quote

--

"(...) you want to do projects that are inspiring and that make people excited about the future. my life's got to be about more than just solving problems who want to get up in the morning and say yes I'm looking forward to that thing happening (...)" mr musk

-- loginwithhn

wX4oPqNdLt

submissionscomments
andersonmvd··on Show HN: I made a site that lets you punish yourself
Related thread: Boss as a Service – Hire a boss, get stuff done (bossasaservice.life) https://news.ycombinator.com/item?id=18512197
andersonmvd··on Show HN: I made a site that lets you punish yourself
Does it impact your friendship? I'd guess you may resent them if they kept a lot of money, especially when you need the money. Or you may start avoiding them completely when you're aware that you didn't achieve a given goal, no? I guess for small amounts it may work but on the long run it seems like a trap.
andersonmvd··on No star, No fix
I fail to see a reason where it would be a violation because of the following reasons:

1) it's a response to a user's request, i.e., not initiated by the repo author

2) it depends on consensus of the user.

3) it's not automated (most of the items from the policy are related to automation).

4) the repo author has no obligation whatsoever of maintaining the project. He is not paid or forced to do it.

5) if the user really wants to apply this change or disagrees with this practice, he/she can always fork it.

That said, I understand that it may still not feel "fair" compared to other projects that don't follow this practice. Or the feeling of "wanting to help but you're asked to do some things first".

Companies already do that to accept your pull requests though [0], which takes way longer than giving a star - and I didn't see a complaint about it on HN

[0] https://github.com/google/eddystone/issues/258

andersonmvd··on Cybersecurity Isn't Special
The goal of cybersecurity should be to align cybersecurity with existing processes, but minimizing friction. What the author experienced seems to be a high friction security program, which is the result of a suboptimal cybersecurity program.

This is unfortunately the reality in many companies because cybersecurity is implemented as a subset of a high level information security framework without qualified people to connect the high and low level requirements.

In the past, security departments were the "firewall gatekepeers", choosing who to allow or deny access. They started to change over time from gatekeepers to support the business but this transition is not complete as we know from experience.

The CISO has also has the dillema of having to support the business but will also be held accountable for any hack, which increases the tension on reducing friction vs increasing friction (and increasing control).

This is not an easy problem to fix, but I particularly think it's very productive to see posts like this so we can bring this topic to light and find the right balance.

And for those interested in learning how to add security to their organizations with minimal friction (security by design, especifically), I'm creating some webinars (free on youtube) here: https://devops.security/webinars.html

andersonmvd··on Launch HN: Infisical (YC W23) – Open-source secrets manager for developers
previous discussion 2 months ago https://news.ycombinator.com/item?id=34055132
andersonmvd··on Caroline Ellison, CEO of Alameda Research, pleads guilty to seven offences
The 7 offences are not detailed individually in the news, or I couldn't find it.
andersonmvd··on Plaid Layoffs
> Macroeconomic conditions have changed substantially this year. Despite being well-diversified across every category of financial services, we are seeing customers across the industry experiencing slower-than-expected growth.

sry for the stupid question, but does anyone have a good breakdown/video/article/explanation on the market change? I have some idea, but I'm not a pro.

andersonmvd··on Meta fires a software engineer two days after he relocated from India to Canada
imho, 3 months at least, 4 would be nice and 6 great
andersonmvd··on Ask HN: Comment here about whatever you're passionate about at the moment
I see. You definitely could learn japanese ... if you want to. If you don't want it's another story xD. In any case, about FF14, trial works still (I had no problems) and I recommend this client for Mac https://github.com/marzent/XIV-on-Mac - which is better than the official hehe.
andersonmvd··on Ask HN: Comment here about whatever you're passionate about at the moment
Another FF fan hehe. Btw if you still play, FF14 online is a banger to enjoy some nostalgia. I'm having a great time at least :) About working, well Square Enix is always hiring, but you need to speak japanese. Their offices are in Tokyo if I am not mistaken.
andersonmvd··on Ask HN: Comment here about whatever you're passionate about at the moment
Hello from Switzerland (I'm not swiss though). I am passionate about reducing the suicide rates in Japan (I'm not japanese though). To contribute the way I envision, I'm building a business (one man show) to fund this endeavor. Easier said than done. First it starts by covering my costs, then moving on to this ambition. It's a journey so gotta enjoy the day-to-day, so I am happy to do a business on what I love, which is cybersecurity. I just got started, but I am already all in :) wish me luck lol. As for why this mission .. gosh it's a book to explain, but in short I want to give back what I received all over the years. If you have ideas to contribute about Japan, please write to me. Info on profile. Peace and love :)
andersonmvd··on Postgres WASM
It's complicated indeed. A simple "clear browsing data" would make him lose the data forever hehe. And if you keep the key in the server, it would be "hackable", which is what I was trying to avoid. I haven't looked at it but https://solid.mit.edu/ looked promising.
andersonmvd··on Postgres WASM
I was trying to find a way to make apps "data-leak resistant" and one step into this direction was to let the user store the data by bringing his/her own database. I even made a poc https://github.com/andersonDadario/byoda (explanation in the blog post link found on the readme) - but no user would manage his own database. Having a database in the browser opens more possibilities though. I will give it some thought. Looking forward to what else will be built on WASM.
andersonmvd··on Ask HN: What are examples of companies dying due to many people quitting?
Do you have a source? I couldn't find it in English at least
andersonmvd··on Tell HN: I've browsed a website from 2000s and it felt great
Probably because of nostalgy, I couldn't help but feel joy when looking at this page. It was potentially created on MS Frontpage. So cool to look at the "home" button in the end of the page and the meta tag <meta name="GENERATOR" content="[Netscape]">. There is also an old fashioned "visit counter" as well. What a strange feeling, like finding a treasure trove. I guess I missed that somehow.
andersonmvd··on Brickit scans your pile of bricks and gives you ideas, with instructions
For kids I guess it kills creativity, but using the same idea for (house?) decoration would be very neat. Scan your messy things and suggest how you can rearrange them to make it beautiful.
andersonmvd··on Can the Visa-Mastercard duopoly be broken?
Credit card is still common, all good. I've seen an exception though.

If you're in a "tourist destination" area, then no worries, I'm sure they will offer credit card as a payment option to keep you in business, but it's likely to be more expensive than paying using PIX.

When I was in the south of Brazil I used the "iFood" app (biggest food delivery app in Brazil) and I could only pay using PIX. In other regions, other options were available such as credit card.

Even if you need to do a PIX as a traveller, you can simply pay in cash to some person (hotel recepcionist I guess) so they can use their account to pay the PIX for you. Technically this person will scan a QR code and pay using their bank account.

If you want to have a PIX account yourself, at the moment you need to have a bank account in brazil afaik. After having your account, you have to register it using specific types of identifier, for example your mobile phone. Non-brazilian numbers are accepted in the standard, but not all banks accept them for now. It certainly will go over changes. It's a relatively new technology.

andersonmvd··on Can the Visa-Mastercard duopoly be broken?
PIX does have a chargeback-like mechanism. It was introduced a year later its release though. PIX is actually more than just instant payment, it includes other things like Pix Saque (withdraw) and Pix Troco (change).

Src (pt only) https://www.poder360.com.br/economia/bc-libera-mecanismo-de-... and https://www.in.gov.br/web/dou/-/resolucao-bcb-n-103-de-8-de-...

andersonmvd··on Can the Visa-Mastercard duopoly be broken?
In Brazil many stores are dropping credit card and allowing only PIX (instant debit transfer) cause it's cheaper for business (0,22% avg transaction fee vs 1%-2% of credit cards - src (pt-only) https://g1.globo.com/economia/pme/noticia/2022/03/23/pix-e-m...).

The President of Brazilian Central Bank recently said that "credit cards will soon cease to exist" src (pt only) https://www.poder360.com.br/economia/campos-neto-diz-que-car...

andersonmvd··on Tell HN: After 10 years of experiments, custom username emails receive no spam
Usually event organizers keep selling your e-mail address after you gave it to them. Some events are explicit about it, others not really. It's not like they really ask you, it's more or less a condition to join the event in most cases.
andersonmvd··on Toptal trying to sue us for saying there are Toptal alternatives that cost less
HN question: at the moment, this post has 31 pts in 1 hour and is on the 2nd page. Why other posts with less points are on the first page? E.g., post with 28 pts 5 hours ago (4-Die Chess). Edit: typo
andersonmvd··on Many software companies are a joke
Focusing on the author instead of the discussing the topic really misses the point imho. We don't get good discussions from it. The point is the amount of inefficiences in big corps and how people react to it. This post has so many upvotes for a reason.
andersonmvd··on George Hotz against the institutions
Reading hint: if you prefer to listen instead of reading when the article is big, at least on iphone I use safari -> reader mode -> scroll 2 fingers from top to bottom and it starts the dictation (I think I had to enable in accessibility). There may be something for android.
andersonmvd··on A simple system I’m using to stay in touch with hundreds of people
The problem is when you know someone contacted you because of their 'system'. I feel less compelled to reply. It feels more that the person is doing their chores and you are just helping them to get the task done. Somewhat similar because people only reminded of you because facebook displayed on their timeline that it was your birthday. No right or wrong here, but when it's not genuine it's not genuine and period.
andersonmvd··on Tibia (1997) is one of the earliest and longest-running MMORPGs
There are other long running MMORPGs that are worth mentioning like RuneScape (https://en.wikipedia.org/wiki/RuneScape). A few years ago they realized they changed the game so much that they decided to 'restore a backup' from the good old times and launch it as 'Old School RuneScape'. If I'm not mistaken this retro version has more users than the 'main version', currently called RuneScape3. This game has a documentary on youtube and such. The main problem I found about being a 'long lived running MMORPGs' is that although the game still exists, the company was bought twice as far as I am concerned, and that changes a lot of things in a game, specially regarding to monetization. For example adding some gambling features and not standing much for ethics inside the game (e.g., bug exploitation) as a measure to keep paying customers. In the documentary the founder & ceo (Andrew) explicitly regret selling the company after seeing how the game (or at least some part of it) turned out to be.
andersonmvd··on Ask HN: Security Awareness Training
If it's a general course, you can even pay a udemy course to each employee for 15 bucks each (or even less for companies?) like https://www.udemy.com/course/security-awareness-training/? Haven't tested it, but for box ticking it may be enough.

If it's for developers or engineers, I've been working on the approach that you get security awareness when working with security engineers. The idea to have a security person close to your team that will teach in practice what it's hard to absorb with some courses out there. Not a replacement for a course, but another way to learn. For more details on this, the info is on my profile.

andersonmvd··on Nuanced communication usually doesn't work at scale
Look at how many details this guy (Carl Sagan) conveyed in his 15' speech: https://www.youtube.com/watch?v=Wp-WiNXH6hI in a way that potentially everyone understood. I wonder if every explanation was like his, if nuance wouldn't be well communicated, even to large groups.
andersonmvd··on Make Front End Shit Again (2018)
Old thread: https://news.ycombinator.com/item?id=17060303
andersonmvd··on Make Front End Shit Again (2018)
I guess the point is to make you feel something different, to explore and try to figure the website out. I remember accessing the "hack websites" with black background and red texts in comic sans while thinking "is it a dangerous website?" haha. Today we mostly take some template because it's "cost-efficient" and end up all looking the same with flat design, call to actions everywhere "buy" "talk to sales" "schedule demo", chat on the right bottom corner and so on.

When I wrote my last website (https://kakugo.ch) I factored in how to balance in trying to making it interesting yet presentable for the everyday audience. I don't know if I achieved that but I tried. A few things one can notice there: two easter eggs, a text written from the heart and some peculiar images. If you also have any more ideas, let me know, thanks :)

Recently I've also stumbled upon three.js which is awesome to build sites like this https://bruno-simon.com/. 3D modeling for websites is pretty neat. As the owner of this website said "i like to build websites that look like videogames".

andersonmvd··on New data: What developers look for in future job opportunities
> How developers discover companies

Surprised not to see "recruiter getting in touch" as an option

Page 1 of 6Next →