HNHacker News
TopNewBestAskShowJobs

brianpgordon

3,290 karma · joined March 17, 2013

[ my public key: https://keybase.io/brian; my proof: https://keybase.io/brian/sigs/pOrpc9JT66_CJmX_oqQuOqqrcN8TB3Iv6Qsu-Ev_pFg ]
submissionscomments
brianpgordon··on Migrating to CockroachDB
> if you want password-authentication, you must configure your cluster to communicate using certificates. You can start each node in "insecure" mode, but then can't use password authentication. There's a issue about this. Like the people posting there, our network is already secured, so this requirement is just an unnecessary nuisance.

Eh, I'm not sure how I feel about this. Obviously you should secure your network as best you can, but how confident are you really that a bad actor will never find a foothold anywhere in your network? I think I would advocate for your services to all communicate securely (TLS et al), even internally, and if your database supports mutual client/server auth like it sounds like Cockroach does then you should use that as well. Particularly if you're depending on at-rest encryption handled transparently by the DBMS to protect your users' data - that won't do you much good if someone can just sniff/MITM network traffic and wait until a bunch of your data has been queried.

brianpgordon··on Bocker – Docker implemented in around 100 lines of Bash (2015)
I think the idea is to show how much container functionality is actually available out-of-the-box from the operating system. It raises questions about Docker's billion dollar valuation when someone can come along and reproduce a bunch of it with a short shell script. Next someone needs to take on orchestration and show how silly it was for IBM to pay $34 billion for OpenShift. :P
brianpgordon··on C# Pattern Matching
I don't think anyone has mentioned yet that this exact feature (with the "is" keyword) is actually coming to Java as a preview feature in Java 14-

https://openjdk.java.net/jeps/305

brianpgordon··on The strange properties of the infinite power tower
That technique on page 3 of splitting off one of the powers and taking the result to be equal to the original reminds me of the proof that 0.999...=1

https://i.imgur.com/ECYa380.png

brianpgordon··on Visa Buys Plaid
I'm interviewing with them this week. Any advice/warnings I should know going in?
brianpgordon··on Linus: Don't Use ZFS
That's a good point, though Synology (my brand of NAS) claims that they've developed analogous corruption checks operating at the LVM level, so you get the benefits of btrfs (including checksum checks and RAID scrubbing) without having to actually use its RAID implementation.

https://www.synology.com/en-global/knowledgebase/DSM/help/DS...

brianpgordon··on Linus: Don't Use ZFS
My home NAS runs btrfs in RAID 5. The key is to use software RAID / LVM to present a single block device to btrfs. That way you never use btrfs's screwed-up RAID 5/6 implementation.
brianpgordon··on When good ideas make bad business
Presumably the government will be incentivized to try to save lives in a way that simply doesn't exist for doctors and insurance companies trying to make a profit.
brianpgordon··on Why Windows 10 Sucks or Everything Wrong with Microsoft Windows
> Wrong. For people who disabled Cortana, it kept re-enabling itself automatically after updates. I think that problem is mostly gone now, but it was definitely an issue all the way up till earlier this year.

I'm pretty sure this only applies if you disabled it through the UWP configurator applet. I vaguely remember this happening to me once. I disabled Cortana in group policy or the registry editor and it never happened again. And you're undermining your own argument by admitting that the problem doesn't actually exist anymore anyway...

> The article has one tiny line-item about fragmentation and it was about architecture. I agree that it's not an issue for most people, but OP is making a comment about a design problem. You are mis-representing the argument by talking past it.

The article's brief mention of fragmentation issues was wrong. It doesn't get a pass just because it was a brief mention. A huge list of issues looks impressive until someone breaks it down and points out how many of the issues aren't valid.

I have no idea what you mean by "architecture" or "design problem." The article claimed that disk fragmentation is an issue, and it's not.

> When Windows 10 first came out there were a TON of devices, including very popular printers and scanners, which had no support.

This was a big issue with Vista, but much less so with 10. Even at its absolute worst, Windows 10 was vastly better than Linux for driver support on the desktop. MacOS doesn't really count because of all their first-party hardware. If there's no superior alternative I don't see a valid point against Windows here.

> when the author wrote this, it was true. He should probably update the site.

Oh... I was assuming it was just published since there's no date in parens in the HN story title. I felt like the article was being disingenuous in repeatedly mentioning old issues that have since been fixed, but if the article is older then that changes a lot.

brianpgordon··on Why Windows 10 Sucks or Everything Wrong with Microsoft Windows
Check out https://github.com/Disassembler0/Win10-Initial-Setup-Script/...
brianpgordon··on Why Windows 10 Sucks or Everything Wrong with Microsoft Windows
5. I police my startup items so that's correct, I've never had this issue. But yeah I know about Autoruns; that's an option too. Are you saying that since it's not built into Windows then it shouldn't count? I don't really agree. It's not like other popular OSes have such tools built in either. And Autoruns is even first-party since Sysinternals was acquired by Microsoft.

6. Yes it can. My current Windows 10 system has been installed since March. I disabled the store immediately and no update since then has restored Windows Store or any Store app. You can uninstall the Store (https://github.com/Disassembler0/Win10-Initial-Setup-Script/...) or just disable access/updates through group policy (https://i.imgur.com/ZRxbwNt.png).

brianpgordon··on Why Windows 10 Sucks or Everything Wrong with Microsoft Windows
I've always been skeptical of the Windows security model as a user but I didn't think it was that porous. Thanks for setting me straight. I found these articles explaining why it's so bad:

https://tyranidslair.blogspot.com/2017/05/reading-your-way-a...

https://tyranidslair.blogspot.com/2017/05/reading-your-way-a...

https://tyranidslair.blogspot.com/2017/05/reading-your-way-a...

brianpgordon··on Why Windows 10 Sucks or Everything Wrong with Microsoft Windows
I'm no Windows fanboy but there's a lot of misinformation here. In the spirit of bullying the reader with a big list of points, here are some examples of incorrect claims in TFA:

1. It's not hard to disable Cortana and internet-assisted start menu search completion. I assume that's what they mean by "keyboard scanning and voice recording" because I don't think there's anything else like that in the OS. It is possible to disable telemetry. In general Windows 10 does come with a ton of cruft but it can be disabled with e.g. https://github.com/Disassembler0/Win10-Initial-Setup-Script

2. Disk fragmentation hasn't been an issue for awhile. Defrag runs as a scheduled task in all versions of Windows 10.

3. I like UAC. The article claims that giving users a dialog box to permit admin access is good for malware, but the alternative is taking admin away from users altogether on their own computers. I don't think this is an acceptable tradeoff.

4. Windows has arguably the best plug-and-play driver support of any operating system. It's not hard to find drivers as the article claims.

5. The article claims that it's difficult to figure out why your startup is so slow, but task manager has a "Startup" tab now which tells you which startup items are consuming a lot of CPU at login.

6. The article claims that you can't disable Windows Store apps, Windows tips, and ads in the start menu. That's untrue. I don't even have Windows Store installed as a Windows component, I have no idea what "Windows tips" even is, and my start menu is devoid of ads https://i.imgur.com/xy69BWe.png

I think Windows is pretty bad and most users would probably be better off running Lubuntu or something, but there's no need to resort to exaggeration to make that case.

brianpgordon··on Slack have blocked using the website on mobile
Were you using the same HipChat that I was? I recall the engineers at my employer (including me) clamoring to get off HipChat and onto Slack. Search was terrible, integrations/automation were clunky, and it was difficult to post code into chat. Slack was a breath of fresh air when we switched.

Also, I think Slack's threads are useful. You can have channels where you just post a single message for your question/issue and then have people reply in a thread, so that messages are naturally grouped together by topic instead of being a firehose of interleaved messages. Combined with good search, this makes Slack more of a valuable knowledge store than just an ephemeral chat tool.

brianpgordon··on I set up an available-anywhere development environment, and so can you
LXD looks really neat. The reason I didn't mention it is because I didn't know about it! What's the consensus on how mature/stable it is for real-world use?
brianpgordon··on How Is NordVPN Unblocking Disney+?
Well isn't the whole article asserting that NordVPN is routing traffic through residential endpoints to confuse would-be VPN blockers? I thought that the allegation is that there's no distinction between the Oxylabs network and the NordVPN service.
brianpgordon··on How Is NordVPN Unblocking Disney+?
It works perfectly for me.

https://i.imgur.com/PFITtZT.png

brianpgordon··on Crinkle Crankle Wall
Funny-named type of wall? This reminds me of the ha-ha wall:

https://en.wikipedia.org/wiki/Ha-ha

brianpgordon··on Curl to shell isn't so bad
To some extent, sure, but I think that extent is greater with Homebrew. It's my understanding that package maintainers for Debian, RHEL, etc are typically experts in the packages that they maintain. They overlay their own patches to ensure compatibility and submit patches upstream. With Homebrew there's only a small number of committers who maintain the homebrew-core repository, accepting PRs from thousands of people in the community. It's just a different situation.
brianpgordon··on Curl to shell isn't so bad
I suppose it comes down to whether the Homebrew maintainer who accepts the formula PR containing the hash is actually examining the upstream code in detail. I think that is unlikely; there's too much code for Homebrew maintainers to be experts on everything contained in homebrew-core and follow every single patch.

So yes, the hash prevents the upstream project from switching out the code at any time, but if they wanted to add some malicious code all they have to do is file a homebrew-core PR and hide it in a legitimate change.

brianpgordon··on Curl to shell isn't so bad
Ah, I found it. On MacOS they rely on sandbox-exec which uses the sandboxing mechanism provided by the kernel:

https://github.com/Homebrew/brew/blob/e2c76cce8e01fd80e0910d...

https://github.com/Homebrew/brew/blob/master/Library/Homebre...

brianpgordon··on Curl to shell isn't so bad
How exactly is the file going to get tampered with if you're using curl-to-sh? Everyone uses HTTPS nowadays. Validating the hash is not really doing anything significant.

As for ensuring that the package is well-behaved, could you elaborate on that? I'm not aware of Homebrew doing something like chrooting to /usr/local before running the install script. And the install script can do anything as your local user, same as curl-to-sh. Perhaps the Homebrew maintainers would catch something nefarious in the formula itself, but given that most formulas download code from the Internet and run it, that's not much help.

brianpgordon··on Curl to shell isn't so bad
It seems like you're assuming that there's someone vetting these packages. For enterprise distros like Red Hat that's certainly true. Community package maintainers in, for example, the Debian project provide some safety as well. But there are plenty of package managers where that's just not the case. In the case of Homebrew, the package manager pulls down the program directly from upstream and installs it. It's exactly the same as downloading a tar file from the developer's website over HTTPS. Same with npm. Some package managers like Maven and NuGet will rehost artifacts but if the project owner is malicious or compromised then that won't help - so the risk profile is again basically the same as downloading a tar file from the website.
brianpgordon··on Nuclear energy is a vital part of solving the climate crisis
I don't think the Earth is going to literally run out of anything, sure. We can always dig deeper, or prospect for more resources out in Siberia, or whatever. But there's something to be said for being concerned about being responsible with this golden age we find ourselves in, when resources are so extraordinarily cheap and abundant. It's not a given that it will be like this forever. Imagine lithium being as rare as gold, and think about whether something like the phenomenon of ubiquitous smartphones would even have been possible.
brianpgordon··on Nuclear energy is a vital part of solving the climate crisis
> If renewables are so cheap then why is German and Californian electricity costs so damn high considering their respective investments into them? It's because they're paying more on other parts of their grids to keep everything stable.

I'm not sure that necessarily follows. It seems just as likely, at least in California's case, that high energy prices are due to our stringent emissions standards. If fossil-based power plants are required to invest more in exhaust scrubbing technology or cleaner-burning fuels or more efficient processes to keep the air clean, that raises prices.

brianpgordon··on I Got Access to My Secret Consumer Score
> When I told Mr. Tan that I was alarmed to see my Airbnb messages and Yelp orders in the hands of a company I’d never heard of before, he responded by saying that Sift doesn’t sell or share any of the data it has with third parties.

What a line to say with a straight face. They are the third party that he's uncomfortable sharing his data with!

brianpgordon··on One Page Dungeon Generator
I got "A mundane-looking door, pleads to be killed when the knob is touched." Hahaha
brianpgordon··on Where is Notepad in Windows 10? (2015)
Is it in a weird place though? Notepad has been under Start -> Accessories since the debut of the start menu in Windows 95. The only change is naming the folder Windows Accessories instead of Accessories.
brianpgordon··on Ghost 3.0
> The hard part is the publishing platform to integrate with the subscriptions and the billing - that's the part nobody else is doing - and we were getting pretty good at building a flexible, modern publishing platform.

Doesn't Medium sort of do this? I get that you can't run your own instance or bill specifically for just your content, but otherwise it seems very similar.

brianpgordon··on DoNotPay app waits on hold for you
Schwab pays interest on checking balances, offers instant transfer between your brokerage and checking accounts, and waives all ATM fees. No reason to stick with BoA.
← PreviousPage 2 of 33Next →