HNHacker News
TopNewBestAskShowJobs

com

740 karma · joined January 25, 2009

submissionscomments
com··on Why the CrowdStrike bug hit banks hard
Generally, act vs monitor is the segregation of duties that I have seen best working between platform or IT ops and engineering (act) vs security ops (monitor).

For many high privilege operations there are more segregation of duties in the act side of things - these can be down to plan, authorise, configure, activate, validate or some rollups of these. Another is dual control on the act side, since conspiracy is generally quite hard to do especially if it’s just for pocket-change. Different if it’s $$Billions of fungible cash of course at stake.

People often overcomplicate - simple do/check is often enough.

com··on Reimagining China in Tokyo
I’m full of admiration for people like Zhang - holding on to a dream and trying to build communities abroad to keep the dream alive.

My ancestors were political and economic refugees who brought not much more than their favourite books through civil war, temporary asylum, war, more war and ultimately safety. They too dreamed of creating a community around their dreamed-for homeland.

None of their grandchildren in the rich world speak their language, or share their dreams. Their old homeland is further away than ever from being a place you can be proud to be from.

I wish Zhang and all his fellow travellers less heartache and loss than my own grandparents and their refugee friends, and much more success in their project.

We all need a better China.

com··on Stripe acquires Lemon Squeezy
Every single product company acquisition, ever.
com··on Fear of over-engineering has killed engineering altogether
And thus us why large-scale construction companies can bid so low, because most of their revenue and profit come from the inevitable scope and requirements changes later in the projects.
com··on Stripe acquires Lemon Squeezy
Same old pattern, M&A’s are normally destructive of the acquired firm’s value, but remove risk from the acquirer that something new and good is active in the market…
com··on Stripe acquires Lemon Squeezy
And one year later, the product promise is dead, buried and rotten.

I hope not, this time, but if I were a betting man…

com··on Stripe acquires Lemon Squeezy
Based on prior experience: almost certainly bad.
com··on Stripe acquires Lemon Squeezy
And about Stripes internal inability to deliver on the actual product. Lemon Squeezy is laser focussed - Stripe is not.

Smart founders will be looking carefully and observing how Stripe fails to retain clientele and think about creating something that fits the Lemon Squeezy gap in the market.

com··on EU parliament member hit by Israeli Candiru spyware
If I could, I would. Probably the best long term investment of my tax dollars today.
com··on EU parliament member hit by Israeli Candiru spyware
Well, this site is a bit more general than only Russian disinformation but has a fairly interesting database too:

https://euvsdisinfo.eu/

(It’s from the EU’s diplomatic service so it should be considered geopolitically self-interested)

com··on No one expects young men to do anything and they respond by doing nothing (2022)
Maybe more important over decadal spans:

You also need to align housing policy to demographic changes such as family size, length of time that children remain living with parents, relatives or carers, as well as prevalence of work from home, availability of “local” work within affordable commute range, availability of public transport.

In other words, “planning for the future”.

The neo-liberal project destroyed more than western industries, it bankrupted our perception that there are more than just market incentives that can build healthier, happier, more resilient and, yes, wealthier societies.

com··on CrowdStrike global outage to cost US Fortune 500 companies $5.4B
If the liability is capped at the cost of the duration of the incident (70 minutes from Crowdstrike’s PR-messaging perspective) or one month’s service charge - both pretty normal in standard contracts, then it’s only outside of the contracts that some equity could be achieved. Not holding my breath though.
com··on Preliminary Post Incident Review
“Fatbergs” expresses some things delivered by some teams very eloquently for me!
com··on Ryanair wins screen scraping case against Booking.com in US court ruling
Just a quick follow up, I haven’t been able to find Railboard pricing in the UK that is more than 1p cheaper than Trainline, so I’ll probably stick with the latter, which also offers pan-European ticketing, which is fairly important to me.
com··on Preliminary Post Incident Review
It’s endemic in the tech security industry - they’ve been mentally colonised by ex-mil and ex-law enforcement (wannabe mil) folks for a long time.

I try to use social work terms and principles in professional settings, which blows these people’s minds.

Advocacy, capacity evaluation, community engagement, cultural competencies, duty of care, ethics, evidence-based intervention, incentives, macro-, mezzo- and micro-practice, minimisation of harm, respect, self concept, self control etc etc

It means that my teams aren’t focussed on “nuking the bad guys from orbit” or whatever, but building defence in depth and indeed our own communities of practice (hah!), and using psychological and social lenses as well as tech and adversarial ones to predict, prevent and address disruptive and dangerous actors.

YMMV though.

com··on Ryanair wins screen scraping case against Booking.com in US court ruling
Thanks for that! Unfortunately UK only? Do you know of similar no-fee apps for pan-European travel?
com··on Ryanair wins screen scraping case against Booking.com in US court ruling
Just for rail, I quite like trainline.com. It tries to hide the madness that is very poor national/private rail service and their ticketing regimes, but really there’s only so much you can do, so often I get two or more tickets for legs of travel, some of which change as I remain on the same train?!?
com··on The CrowdStrike Failure Was a Warning
Automated CI/CD - many of us already do this hundreds of times a day. If you’re an emergency call centre, join a consortium of similar orgs and standardise tech and do it properly.

Defer updates. Most things can wait 8-12 hours. Even more can wait 3 weeks (did this for all but security-critical npm package updates in one place).

Demand legal changes to ensure fair liability for failure to undertake basic measures by service providers for paid software and services. Demand proper liability for C-suites not ensuring that actual risk management is in place instead of stupid box-ticking.

Design better software. Seriously, the kinds of half-baked stuff that costs so much is incredible. It doesn’t take longer, and it doesn’t cost more to do things right, the only change is that management needs to be engaged with outcomes and have skin in the game. Execs should run the risk of going to jail for egregious failures.

com··on The CrowdStrike Failure Was a Warning
Don’t let remote operation of safety critical systems at oil refineries + removal of physical emergency automatic shutdown systems at oil refineries worry you either. When one of those fails for a stupid reason or is hacked by psychopaths it’ll make Bhopal look like a walk in the park.

Don’t over-egg the Crowdstrike thing - the really poor tech choices are going to deliver between three and six orders more of death when the inevitable happens.

It’s a relatively low-impact warning. We can learn from it or not. I know what I’m expecting.

com··on Joe Biden stands down as Democratic candidate
Thanks, this site is a gold mine. I especially like the optional explanation of panel votes.
com··on Initial details about why CrowdStrike's CSAgent.sys crashed
Economic drivers spring to mind, possibly connected with civil or criminal liability in some cases.

But this will be the work of at least two human generations; our tools and work practices are woefully inadequate, so even if the pointy haired bosses (fearing imprisonment for gratuitous failure) and grasping, greedy investors fear (for the destruction of “hard earned” capital), it’s not going to be done in the snap of our fingers, not least because the people occupying technology industry - and this is an overgeneralisation, but I’m pretty angry so I’m going to let it stand - Just Don’t Care Enough.

If we cared, it would be nigh on impossible for my granny to get tricked to pop her Windows desktop by opening an attachment in her email client.

It wouldn’t be possible to sell (or buy!) cloud services for which we don’t get security data in real time and signal about what our vendor advises to do if worst comes to worst.

And on and on.

com··on Major Developments in Postgres Extension Discovery and Distribution
Good news! It’s high time we had better discovery and metadata around Postgres extensions. Even more importantly, to have an intentional ecosystem community. Well done!

However:

This blog post is dated March 21, 2024.

I wish it had the date somewhere on the page to assist the reader understand the context.

com··on I mapped almost every USA traffic death in the 21st century
Momentum is probably more of a correlation than mode of transport. Real world experience: hit by a bike versus hit by a moped, each time on a “vehicle free” footpath. One was not like the other.
com··on I mapped almost every USA traffic death in the 21st century
Like a lot of things, start with reviewing what works elsewhere, start some pilots, and what works do bigger and bigger rollouts.

Like, use data. If marketers and TikTok can trick us so easily using these techniques we can do the same in socio-technical settings too.

Like most things, “architectural” systems solutions will work better than point behavioural interventions, but it’s always going to be a mix.

Bike safety in The Netherlands was a multigenerational effort ranging from creating standards around roads intersections, bike paths and pavements and slowly remediating old ones while building new ones.

That’s only a tiny part of a society-wide effort to improve quality- and length-of-life measures, but like the US Interstate highway system, has had measurable results in terms of economic and social outcomes.

Some actions taken today will have individual results tomorrow. Some in 30 years. Better get started, right?

com··on Lessons from a Private Equity Earn Out: How I Lost £550K Due to a Lowercase 'C'
Excellent advice.

I’m not convinced that it’s possible to get the 100-day integration to start only after the earn-out is completed.

Anybody managed to get this in the sale agreement?

com··on Ask HN: How do you balance security with fast development?
Make sure that safe defaults exist, don’t expect people to reinvent wheels safely, and try to use collaborative and well-informed validation of choices rather than stage gates with all the normal queuing problems, automate security checks into local build phase if you have it, make sure that nonsense CI based security checks can be overridden by sane people, and keep track of tech debt and try to work it down consistently.
com··on I am not yet ready to switch to Zig from Rust
So, who’s writing the Zig book?
com··on Girls in Tech closes its doors after 17 years
There is a proverb: once bitten, twice shy.

If we want our teams to be broadly representative of our communities and recruiting the best people for the roles, it’s clear that we cannot put the weight of solving the problems that lie behind such experiences and choices on the underrepresented individuals themselves.

I’ve been reading the comments and it seems clear to me that many of the commenters are either unaware or dismissive of the reasons that a woman might say that she would not join a team that was otherwise only men.

Without acknowledging the data, and failing to provide any useful hypothesis for why it is the way it is (apart from “it’s not called design” or some kind of gender-based competency model or perhaps a hand-wavey “but we shouldn’t discriminate; it’s their preference”), resistance to whatever we as professionals and leaders choose to do about it will be the norm.

And it’s hard to force people to deploy critical thinking when they believe they benefit from not doing so.

My own theory is that many men benefit from single gender bro spaces (where other forms of diversity are also highly constrained) and this rather than genuine lack of empathy or creative thinking lies at the bottom of gatekeeping and making teams and working environments toxic enough to drive women who dare to enter away.

The guys who early on in my career were dismissive of women in tech roles who have changed their tunes significantly tend to have had a daughter with an aptitude for STEM. Perhaps they’ve got skin in the game and somebody who shares what it’s like coming into difficult study and work environments?

com··on The Sumerian Game: The Most Important Video Game You've Never Heard Of (2021)
I played HMRABI on a DEC-10 with a teletype and a modem with an acoustic coupler when I was a kid - literally a game changer since affordable 8-bit computers came out shortly after and we could build rubbish games a bit similar to this. It was always a blast to script - in BASIC - the subservient computer advisor!
com··on The magic of small engineering teams
I thought that metaphor would go in a different direction, tbh. I was thinking “praetorian guards”, “imperial decline”, “decadence”, “barbariand resettling inside the limes” etc.
← PreviousPage 7 of 16Next →