HNHacker News
TopNewBestAskShowJobs

cdjk

1,370 karma · joined November 13, 2012

email: [HN username]@cs.stanford.edu
submissionscomments
cdjk··on Amazon releases new Kindle products
My dad prefers his full size iPad to the Kindle too. For him the backlit LCD is a feature, and the brightness and contrast on the LCD is better than the kindle display. My eyesight is better, so I prefer the Kindle for reading text.
cdjk··on SSH Tricks
You should be able to do something like:

  Host hosta* hostb* hostc*
  User usera
Assuming you don't have two different machines named hosta with different domain names, it should do what you want.
cdjk··on Install Debian packages without starting daemons
I've used stow to manage installs under /use/local before, which seems like a slightly easier approach. It does something similar but manages the install as a series of symlinks from /usr/local/bin to /usr/local/stow/<packagename>/bin.

It's pretty easy to setup and works the same on any distro.

cdjk··on The vanished grandeur of accounting
This comparison of double entry accounting and calculus may be interesting:

http://www.austintek.com/gnucash/ncsa-gnucash-talk-3.html#ss...

cdjk··on Ask HN: Where did all the Product Managers go?
Even if there aren't people who have "Product Manager" on their business cards there's going to be someone acting as a product manager.

In my possibly overly-simplistic view, PMs should generally focus on what the customer should be able to do, while developers should focus on how it's going to work. Of course, each group needs to be able to understand the position of the other to be useful. I'm worthless as a developer if I have no empathy towards for the customer (i.e. I shouldn't say "we're not going to implement this feature that would be useful to customers because it's too hard"), and PMs are useless if they don't understand the technical constraints of the existing code/infrastructure.

I'd say that PMs are less technical than developers, so developers can do the PM work if necessary (and should be thinking about it a little bit even if there are good PMs).

Project/Program Managers are different. Their job is more focused on making sure all the moving parts of a "project" are coordinated. When it's a small start up there aren't as many moving parts, so it's not a useful role - but in bigger companies it's useful to have someone coordinate between marketing, legal, finance, customer service, etc. And they can make sure everything happens on time.

You run into problems when developers don't care at all about customers, product managers have no sense of what's technically possible or reasonable, and project managers get too hung up on the process and not the final result. Avoid those situations and everyone adds value.

cdjk··on NetBSD 6.1.4 and 6.0.5 released
I believe Apple's AirPort and Time Capsule products run NetBSD, although it's a little difficult to find a source for that.
cdjk··on Laboratory-grown vaginas implanted in patients
Anosmia is much more serious when it's the result of trauma or some other disease - it makes food taste radically different, and is likely to cause depression. That said, I've never had a sense of smell, so I don't know what I'm missing. And the world is much less smell-focused than vision or hearing, so if you have to lose a sense, smell is near the top of the list.
cdjk··on Laboratory-grown vaginas implanted in patients
It's interesting that you should mention smell, since I was born without a sense of smell - the term is anosmia. It is very poorly studied, and most studies deal with people who lose their sense of smell due to neurological diseases or head trauma.

In my case it's clearly genetic (my mom and her dad both can't smell), and almost no one studies it. From what I've read I'd much rather be born without a sense of smell than lose it, since that can be very traumatic.

cdjk··on Ask HN: Who is hiring? (April 2014)
23andMe - Mountain View, CA - https://www.23andme.com

Combining web development, computer science, genetics, social media, and informatics, 23andMe is at the forefront of a new era in personal genetics. This is your chance to join a talented, ambitious team that is creating truly novel technologies and products that will change the way people see themselves and the world.

We're hiring for:

* Software Engineer * Software Engineer in Test * Engineering Manager * Enterprise Security Manager * Mobile Apps Engineer * Storage Systems Engineer

More information is available on our site:

https://www.23andme.com/about/jobs/

Or contact me, cary@23andme.com (personal email is in my profile).

cdjk··on NSA infiltrated RSA security more deeply than thought: Study
Probably something like OATH (as used by google authenticator and similar software) or a yubikey. With yubikey you can even get your own HSM for the authentication server.
cdjk··on Django 1.7b1 released
Dynamic forms in django are difficult. Personally, I think generalized handling of forms is just a hard problem - I have yet to see a library that handles every case, nor do I know how I'd go about writing one.

There is the package wtforms, however, which I've found is more pleasant than django forms.

cdjk··on Google to reportedly kill Voice, integrate it into Hangouts
The most useful feature of Google Voice to me is the voicemail transcription. It's not perfect, but it's good enough it saves me from having to listen to the voicemail about 90% of the time.

There are plenty of other voip/call forwarding services, but are there any that duplicate that functionality?

cdjk··on Why Puppet, Chef, Ansible aren't good enough
I use this - and it's great with my slow internet connection. It's totally transparent, and I only notice it if my vm running it is down.

And despite the name, newer versions work with yum too (although I found I had to disable the fastest mirror yum plugin to get reliable caching).

cdjk··on Django 1.6.2 and 1.7a2 released
It's a minor release. The Django 1.5 and 1.6 release announcements got a lot more comments:

  https://news.ycombinator.com/item?id=5287890
  https://news.ycombinator.com/item?id=6682754
cdjk··on Nissan Sells 100,000 LEAFs, Captures 48% Of Worldwide Electric Vehicle Market
Yes, with the right sticker:

http://www.dmv.ca.gov/vr/decal.htm

cdjk··on FreeBSD 10.0 is here
In this case STABLE refers to the ABI, not the code itself. RELEASE is code that doesn't change, other than security patches and major bugs.

It is confusing, however, but there is some logic to it.

cdjk··on I fought my ISP's bad behavior and won
That's what my ISP does. What's worse is that sometimes their dns servers fail intermittently (something to do with fragmented packets and retrying DNS queries in TCP mode).

It did take a while to figure out what was causing the intermittent DNS failures. "My ISP is hijacking all port 53 traffic" was fairly low on my list of possibilities, I must admit.

Fortunately it's not that hard to run a local resolver that forwards queries to an external resolver on a vps on an alternate port.

I'd switch ISPs, but I live in a remote area and my only other choices would be satellite or cellular, so I'm stuck with them.

cdjk··on Amazon said to launch Pantry to take on Costco, Sam's
I'm pretty sure the costco benefits are fairly good for hourly warehouse employees. Here's the first reference I found:

http://www.fool.com/investing/general/2013/12/08/costco-whol...

cdjk··on Red October crypto app adopts “two-man rule” used to launch nukes
I wonder why they're not using a secret sharing algorithm:

http://en.wikipedia.org/wiki/Secret_sharing

It would reduce the complexity of encrypting the data encryption key multiple times with each pair of keys, and the math behind them is pretty neat.

cdjk··on LG TV logging filenames from network folders
I'm a fan of pfsense:

http://pfsense.org/

It might be a little more complicated than a standard consumer-grade router, but it's powerful enough to do almost anything. It's based on FreeBSD and has a reasonably pretty GUI on top of pf.

I've used it on alix embedded hardware before, and have it currently running on an atom supermicro board - both work great.

cdjk··on You can no longer just leave Syracuse airport [video]
Here's an article about it if you don't to watch the video:

http://www.syracuse.com/news/index.ssf/2013/11/syracuse_airp...

It sounds like it's an electronic one-way gate to exit the secure area of the airport, replacing the TSA agent who used to sit at the exit. Physical one-way turnstiles have been around for a while - I'm not sure I've ever seen one at an airport.

cdjk··on Why I use a 20-year-old IBM Model M keyboard
The parallel arrangement takes a little getting used to. I switched to a Kinesis Advantage, which has parallel keys, and it took me about a month to get up to speed with it - and another month to get comfortable on a "normal" keyboard again. After that I didn't have any problems switching back and forth, however.
cdjk··on Renault ships a brickable car with battery DRM that you're not allowed to own
The entity that leases the car does get the benefit - but then passes it on to the consumer in lower monthly payments.
cdjk··on Renault ships a brickable car with battery DRM that you're not allowed to own
The situation with electric cars is a little more complicated , as there's a $7500 tax credit for them. If I lease an electric car I can get the full value of that $7500 over the 2 or 3 year lease. If I buy it, that value is spread out over the entire life of the car.

Personally I'd prefer to lease an electric car, and am going to soon. Even if it's more expensive than buying one, the extra cost is like buying an option to give at back after 2-3 years, which is worth something, especially with relatively new battery technology.

cdjk··on Adobe credentials and the serious insecurity of password hints
To be more precise, Facebook knows hash(random_salt, facebook_password), and could do a check on the actual facebook_password when a user logs in, but I assume that it's not stored. Everyone knows encrypt(key, adobe_password), since that was what was leaked, and presumably adobe still has the key, so they know adobe_password.

Facebook wants to determine if facebook_password == adobe_password. Without the key, that's impossible. And I think 112 bit keys as provided by 3DES are still secure, even considering an adversary with the resources of Facebook.

A lot of the articles analyzing the adobe passwords seem to be comparing known-common passwords, passwords hints, and the insecurities of ECB-mode, which doesn't really scale. It seems like it would be better for facebook to just have a blacklist of common passwords (123456, password, etc), although then I suppose they don't get credit for pro-actively responding to a password leak (note: I'm not claiming that's why they're doing it - it seems like a good response, and I'm genuinely curious how they're doing it).

Edit: I just thought of way they could do it. Generate a histogram over the first 8 bytes of each encrypted password. Pick a threshold (e.g. 2, or 10, but you'd have to look at the data to get a good number) above which the password is considered "common" and therefore insecure. Go through the list of email addresses in the adobe dump that have a "common" password, and if there's a facebook account with that email address force a password reset. That seems like it would work fairly well, and doesn't require any knowledge of the plaintext passwords.

cdjk··on Adobe credentials and the serious insecurity of password hints
How is Facebook getting the plaintext passwords to compare to their hashed user passwords? Since the passwords are 3DES encrypted, only adobe should be able to do that.

They could just be using email addresses, but that seems rather blunt.

I'm not a huge fan of Facebook, but what they're doing does seem like an excellent idea.

cdjk··on Writing a FUSE filesystem in Python
You should take a look at Plan 9. Everything is a file, and service are implemented as file servers - including the windowing system (rio).

Some of the ideas are available in Plan 9 from User Space.

cdjk··on Namecheap now offer .io domains
Don't give up on DNSSEC just yet. You can use DLV (DNSSEC Look-aside Validation) if your registrar doesn't support it yet:

https://dlv.isc.org/

cdjk··on The Fireplace Delusion (2012)
Mounted police are surprisingly effective. They're highly visible (you noticed them on your way home, for example). They're useful for crowd control, as the officer is above the crowds. And being chased by an officer on horseback is a memorable experience, which may have a deterrent effect.
cdjk··on The Fireplace Delusion (2012)
I think I disagree. For energy density, gasoline is hard to beat. And I'm not convinced that catalytic wood stoves are that bad, without doing more research.
← PreviousPage 4 of 9Next →