HNHacker News
TopNewBestAskShowJobs

bhr_mov

2 karma · joined September 29, 2026

submissionscomments
bhr_mov··on Management is forcing us to use AI
I'm not saying it's not useful or what won't be the end result, but people sure love to jump to conclusions on this one. From the day ChatGPT came out, everyonen been telling doomsday stories... Also note that there's also room for innovation still. LLMs don't really innovate, they regurgitate. Having no human coders anymore will mean that we will never advance our algorithms and methods beyond where they already are.
bhr_mov··on Management is forcing us to use AI
But the thing is that nobody has actually proven or provided concrete, peer-reviewed evidence that AI actually results in higher revenue, growth, and profits to businesses. Everyone is just imagining or assuming this.

For example, at my day job, they pushed it on us, but speed of coding and technical work was not the thing that was bottlenecking productivity. Until someone gets 2 businesses in the same market doing more or less the same thing, one which does it without any AI coding, and another which uses almost exclusively AI coding, and demonstrates that the one that uses AI almost exclusively A) Has more reach B) Makes more money C) produces better quality products and D) Can actually sustain that over a long period of time, nobody has any business forcing this and claiming that "its inevitable" or "we have to use this" etc...

But that's not what's happening. These seemingly otherwise somewhat bright, so-called scientific people are not using any science at all in their conclusions and statements. Science teaches us to question, to not take something for gospel, to develop hypotheses, to test these hypotheses, to challenge. It doesn't teach us to go "Oh well, this is inevitable, let's just throw in the towel." To that end, I'm see multiple entrepreneurs and founders who feel the same way start making a difference here by starting their own businesses using ethics and scientific/engineering principles to approach it, which excites me. I don't mind leaving big tech, big moneybags behind. We should have never worshipped them in the first place.

bhr_mov··on Management is forcing us to use AI
This is happening at several (typically big tech) companies. Not all companies and orgs are doing this, however. I'm very firm when I say that any type of "forced AI" usage is a huge mistake and it's also a slap in the face to the employees whom were presumably hired for their skill and talent and should be trusted to make such tool decisions, especially engineering and technical teams, to not trust their judgement on when AI should and should not be used. This is the first time in my career where I've seen leaders who are too high to understand what their folks in the trenches are doing, try to force them to use a tool. The architects and building engineers have a very interesting job, but telling the construction workers which hammer or heavy equipment to use is not and should not be one of them, for a reason. In my experience, engineers will use AI when they need to use AI, but at a handful of companies, AI is being pushed as a solution to problems where it doesn't even make sense, then the companies are backpedaling afterwards because their token costs are through the roof... So they get their employees hooked on using as much AI as possible, then have to come back and say "actually, we need to cap you at $XXX per month." So all of the AI automation that was developed with no limit now can hardly operate effectively and needs to be re-designed... It's completely absurd.

Start looking for a different job, or better yet, build your own business.

bhr_mov··on Ask HN: How do you deal with cyber attacks once you scale?
I'm a I've been a malware researcher, lead security engineer, software engineer, and pentester. Correct me if I'm wrong here, but this post seems to contain two different types of security concerns:

1. The security of your product, aka Product Security (you mentioned "users", MFA, the dev team, etc...) 2. The security of your internal company networks, endpoints, etc used by employees and systems to operate the business, often called Information Security (you mentioned "non-tech folks in the company", pwned passwords etc...

The biggest thing that comes to mind that you've not mentioned here is security training for both the Information Security side of things (e.g. all employees), and the software developers (technical training about the various vulnerabilities, secure coding best practices, supply chain attacks and how to mitigate them, etc...). I used to teach security training courses for past employers to software engineers and other colleagues, and we did see improvement from those who were trained. Many organizations will have that 1-2 people who just won't cooperate, listen, or play dumb and unfortunately click that link, or do something untoward that puts the whole org at risk, but this sort of thing can also be partially mitigated by proper network segmentation and in the case of product security, proper security controls in the CI/CD and build & release pipelines, amongst other things. Unfortunately, there is no way to achieve "perfect security" and I've found that as a business grows and brings more people into the mix, the likelihood of something getting lost in translation and going unnoticed grows as well.

Another big point - You can't secure what you don't know about. The first thing a pentester will do is scan your entire domains and pages for other domains and pages, and we will build a big list... So for example if you have employeehub.yourcompany.com, I'm going to scan and dig up like 50 other subdomains, and if I find dev1.employeehub.yourcompany.com, I'm going to go there and see what's exposed to the public... Maybe your team forgot that was left up and exposed, and maybe since it was supposed to be a temporary or a test endpoint, it has less security features than employeehub.yourcompany.com does and it may be a way in, etc... So, a pentesting firm will provide you with all of this recon information about your site in addition to trying to actively find and exploit vulnerabilities on it. Certain security companies also offer whats called "Attack Surface Management" which is software that helps you to identify your assets and the attack surface as well... Those are often quite large dashboards with many options, but as a pentester, I can get a list of practically your entire attack surface in a matter of seconds using some of my tools. The point is, you have to inventory everything you expose externally, internally, and in your products. Your products and dependencies should also have SBOMs and vulnerable dependencies should be patched, etc... I don't know the size of your business, you may not need a CISO, but at least one proficient engineer who can handle much of this depending on the size.