568 karma · joined May 12, 2011
And Delve isn't an auditor. Though they were apparently in cohoots with equally criminal third party auditors. So I guess I'm going to be looking more closely at just exactly who exactly are auditing our vendors in the future...
With ISO27001 or SOC 2, I have more information about the other party's ability to manage those risks than just taking their word for it. I'm trusting a third party auditor to vouch for them.
Fraud undermines all kinds of relationships and yes LLMs make it worse. The last job we opened I got hundreds of perfect cover letters asserting the candidates met all of the criteria. Bah.
My perhaps naive hope is that a few of these companies involved will face criminal fraud charges and we will start to develop new reflexes as a society that just bc LLMs making lying very very easy, there are still consequences.
I am a founder, and my ambition includes meeting the highest possible standards for my customers.
I think it took us a good hour and a few hundred tickets to get the helpdesks to stop fighting with each other!
One thing that strikes me is the relationship with architecture. A monolithic, vertically scaled app can run ANYWHERE where I can rent a VM, whether in Norway with Upcloud or on a VPS in Kenya. It's only when you start stitching together managed DBs with autoscaled instance pools etc that vendor lock in begins.
All of these nice toys make our service highly available. But while the overall risk is lower, it is far more correlated between customers. If our service would go down because of a political event, it would go down for all our customers at once.
What about a control plane that manages a fleet of per-customer VMs across an array of cloud providers? Has anyone ever tried this?
The javascript version does exist! The fact that it's produced by a compiler doesn't undermine it's existence.
What's interesting here is not that it's slower than the equivalent running on the JVM but that it was _faster_ than a version compiled to wasm.
Well written and useful article if you would like to learn about what type of optimizations are effective in targeting the wasmgc runtime.
It's an extremely timely and interesting topic.
The performance of a third compilation target - JVM bytecode provides a useful baseline.
One thing that makes my gradle experience more pleasant I think is that I assiduously avoid plugins, and just write the meat of my tasks in Java. Adding a new source set is a one-liner, then just put your code generation logic in src/generator/java.
Add a JavaExec task to run your main class and, optionally define inputs and outputs to enable up-to-date checking. Painless, simple, powerful.
Here's an example: https://gist.github.com/akbertram/1d543c8648ddf322f9866c3738...
> If being bilingual does have benefits over and above the _broader social, employment, and lifestyle gains_ that are available to speakers of a second language, then it should manifest as a cognitive advantage in the general population of bilinguals.
You could write a PhD on the biases absorbed into this image.
If there was something of value (besides excellent software) behind the signup form maybe we would need different strategies.
[1]https://www.bloomberg.com/opinion/articles/2023-01-12/jpmorg...
We apply a few strategies...
1. Require oauth-based sign up for gmail.com, hotmail.com, and live.com addresses. No emails sent until after authentication.
2. Drop obvious spam. If your name contains "http://" or "Whatsapp" or your User-Agent is "python-requests" than you get a 400.
3. Manual approval for suspicious sign ups. High Abuse IP DB scores, statistically unusual names, etc generate a help desk ticket that someone from our staff approves before an email is sent. Persistent bad actors are blocked by IP for 2 weeks.
4. Rate limiting by IP. This prevents bad actors from spamming our help desk.
All together this seems to have largely solved the problem... for now.
Not a banker, but this strikes me as absurd. Surely this is part of soneone's key responsibilities?