HNHacker News
TopNewBestAskShowJobs

bedatadriven

568 karma · joined May 12, 2011

submissionscomments
bedatadriven··on Ice water drowning survival of young patient (2025)
There was some medical terminology that I didn't understand. The NotebookLLM podcast version is disturbingly good: https://notebooklm.google.com/notebook/21c5eddb-ada4-4726-85...
bedatadriven··on Dropping Cloudflare for Bunny.net
We switched from Wistia to their video streaming offer and literally decimated our video hosting costs. Exactly what we needed with none of the upselling B.S.
bedatadriven··on Iran-linked hackers breach FBI director's personal email
Uh yeah, the locale in the link is specifically an Indian locale. If you find it it disorienting you can change en_in to en_us:

https://landing.google.com/intl/en_us/advancedprotection/

bedatadriven··on Delve – Fake Compliance as a Service
Compliance with what requires KYC? Nothing in ISO-27001 requires you to collect any information about your customers. Unless there are laws that require you to. Knowing your vendors is another story.
bedatadriven··on Delve – Fake Compliance as a Service
The standards are very sensible. If you can't be bothered to provide even simple evidence that your employees are using basic harddrive encryption, use password managers, and your product has backup in place, I don't want to do business with you.

And Delve isn't an auditor. Though they were apparently in cohoots with equally criminal third party auditors. So I guess I'm going to be looking more closely at just exactly who exactly are auditing our vendors in the future...

bedatadriven··on Delve – Fake Compliance as a Service
Well, yes, but that's the point of many contracts, they are often designed to shift risk to parties that are better equipped to handle those risks. We run our app on GCP because as a 20 person company I don't want to be responsible for physical security and a million other risks.

With ISO27001 or SOC 2, I have more information about the other party's ability to manage those risks than just taking their word for it. I'm trusting a third party auditor to vouch for them.

Fraud undermines all kinds of relationships and yes LLMs make it worse. The last job we opened I got hundreds of perfect cover letters asserting the candidates met all of the criteria. Bah.

My perhaps naive hope is that a few of these companies involved will face criminal fraud charges and we will start to develop new reflexes as a society that just bc LLMs making lying very very easy, there are still consequences.

bedatadriven··on Delve – Fake Compliance as a Service
I don't want to work wherever you do your thing. Software as a service means you provide a service, and you should take your responsibility to protect your customer's data super seriously. Compliance frameworks are one useful tool among many to support this effort. It helps us identify gaps, identify risks, make improvements. It also give us a way to communicate what we do to our partners. The behavior described in the medium post is fraud, pure and simple.

I am a founder, and my ambition includes meeting the highest possible standards for my customers.

bedatadriven··on It looks like the status/need-triage label was removed
I can remember something like this a few years ago when a customer emailed our helpdesk with their own internal IT support desk in copy. Our helpdesk at the time sent a complete new email acknowledging the request, which the customer's desk ALSO acknowledged in a new thread...

I think it took us a good hour and a few hundred tickets to get the helpdesks to stop fighting with each other!

bedatadriven··on Evaluating the impact of AI on the labor market: Current state of affairs
One thing that is real is companies using LLMs to fill roles they couldn't afford to spend on before. Like the tourist who uses Google Translate on a trip to Japan: in principle they are saving 10k on the cost of a professional interpreter. On the other hand they never would have had the resources for a professional interpreter.
bedatadriven··on Configuration files are user interfaces
Came across hocon recently and prefer over both yaml and kson. https://learnxinyminutes.com/hocon/
bedatadriven··on It is no longer safe to move our governments and societies to US clouds
I've been looking at this a lot, for ourselves (multitenant saas app running on gcp) and for our customers, who are starting to be curious about something between fully self-managed (too costly) and centralized/multi-tenant/american cloud.

One thing that strikes me is the relationship with architecture. A monolithic, vertically scaled app can run ANYWHERE where I can rent a VM, whether in Norway with Upcloud or on a VPS in Kenya. It's only when you start stitching together managed DBs with autoscaled instance pools etc that vendor lock in begins.

All of these nice toys make our service highly available. But while the overall risk is lower, it is far more correlated between customers. If our service would go down because of a political event, it would go down for all our customers at once.

What about a control plane that manages a fleet of per-customer VMs across an array of cloud providers? Has anyone ever tried this?

bedatadriven··on Direct Sockets API in Chrome 131
This a very early draft I'm following: https://wicg.github.io/local-peer-to-peer/
bedatadriven··on The Internet Archive takes over foreign dissertations from Leiden University
You are off by one f.
bedatadriven··on Show HN: I Wrote a Book on Java
A record's fields are final, so records are immutable (though they can include immutable pointers to mutable objects)
bedatadriven··on How we sped up Notion in the browser with WASM SQLite
This honestly sounds like a nightmare: multimegabyte wasm downloads, data corruption in production and byzantine hacks to coordinate writes between tabs. I am very grateful that we chose IndexedDB instead for our application!
bedatadriven··on Google Sheets ported its calculation worker from JavaScript to WasmGC
I'd encourage you to take another look at the article because I don't think your criticisms are well founded.

The javascript version does exist! The fact that it's produced by a compiler doesn't undermine it's existence.

What's interesting here is not that it's slower than the equivalent running on the JVM but that it was _faster_ than a version compiled to wasm.

Well written and useful article if you would like to learn about what type of optimizations are effective in targeting the wasmgc runtime.

bedatadriven··on Google Sheets ported its calculation worker from JavaScript to WasmGC
The primary point of the article is to compare two compilation targets for a single codebase: JS and WasmGC.

It's an extremely timely and interesting topic.

The performance of a third compilation target - JVM bytecode provides a useful baseline.

bedatadriven··on Cloudflare took down our website
Ok, I have to ask: are you a Random Number Generator (RNG) supplier, or a Renewable Natural Gas (RNG) supplier, or some other kind of supplier??
bedatadriven··on ChromeOS is Linux with Google’s desktop environment
I just recently switched from Ubunto to ChromeOS Flex and my quality of life has gone way up. I had so many frustrations with Ubuntu when switching displays, unlocking, sharing screens... all gone with ChromeOS flex and I get to keep my linuxdev tools. So happy!!
bedatadriven··on Ask HN: Why are there no traditional language compilers that target the JVM?
I have written one (gcc-bridge). Fortran is actually a really good fit for JVM byte code. C/c++ is doable, but only with some unpleasant trade offs that others have mentioned here.
bedatadriven··on Gradle still sucks
I work with a large project built with gradle that includes a lot of custom code generation and other automation very specific to our project. Strong disagree with this article.

One thing that makes my gradle experience more pleasant I think is that I assiduously avoid plugins, and just write the meat of my tasks in Java. Adding a new source set is a one-liner, then just put your code generation logic in src/generator/java.

Add a JavaExec task to run your main class and, optionally define inputs and outputs to enable up-to-date checking. Painless, simple, powerful.

Here's an example: https://gist.github.com/akbertram/1d543c8648ddf322f9866c3738...

bedatadriven··on Bilingualism affords no general cognitive advantages: Study
It's an academic paper with an intentionally narrow focus.

> If being bilingual does have benefits over and above the _broader social, employment, and lifestyle gains_ that are available to speakers of a second language, then it should manifest as a cognitive advantage in the general population of bilinguals.

bedatadriven··on NewsNotFound: An open-source, unbiased news company
Yikes. There are many many issues here, but the images for the articles are the creepiest. Take a look at this article on conflict in Sudan: https://newsnotfound.com/conflict-in-sudan-causes-concern-fo...

You could write a PhD on the biases absorbed into this image.

bedatadriven··on Gezellig – a word that encompasses the heart of Dutch Culture
Yes convivial is the perfect translation for gezellig. I don't understand why articles about gezelligheid always claim that it is somehow untranslateable!
bedatadriven··on My sign up form was abused to send spam. Is yours safe?
So far all "my" spammers seem indescriminate. I have the feeling that our form is just another URL on a very very long list, and I see no evidence of adaptation.

If there was something of value (besides excellent software) behind the signup form maybe we would need different strategies.

bedatadriven··on Frank founder allegedly defrauded JPMorgan out of $175M hit with federal charges
I read in an earlier report that their own developers refused to do the task. [1] Not clear if the professor knew what the fake data was being used for.

[1]https://www.bloomberg.com/opinion/articles/2023-01-12/jpmorg...

bedatadriven··on My sign up form was abused to send spam. Is yours safe?
Removing user-controlled input indeed removes the incentive, but for reasons beyond my comprehension, our sign up form _still_ gets periodically blasted. Without additional countermeasures, our sending reputation would be at risk.

We apply a few strategies...

1. Require oauth-based sign up for gmail.com, hotmail.com, and live.com addresses. No emails sent until after authentication.

2. Drop obvious spam. If your name contains "http://" or "Whatsapp" or your User-Agent is "python-requests" than you get a 400.

3. Manual approval for suspicious sign ups. High Abuse IP DB scores, statistically unusual names, etc generate a help desk ticket that someone from our staff approves before an email is sent. Persistent bad actors are blocked by IP for 2 weeks.

4. Rate limiting by IP. This prevents bad actors from spamming our help desk.

All together this seems to have largely solved the problem... for now.

bedatadriven··on SVB employees blame remote work for bank failure
> “Ideas like hedging interest rate risk often come up over lunch or in small meetings.”

Not a banker, but this strikes me as absurd. Surely this is part of soneone's key responsibilities?

bedatadriven··on Cal.com: Open Scheduling Infrastructure
Another vote for savvycal, happy customer here.
bedatadriven··on KeenType: Pure Java typesetting system
Looks like it was inherited from an upstream project that has a long history: https://github.com/jamespfennell/new-typesetting-system#lice...
Page 1 of 4Next →