HNHacker News
TopNewBestAskShowJobs

danweber

72 karma · joined November 16, 2010

I usually comment as danielweber. Accidentally made two accounts at one point.
submissionscomments
danweber··on Perl/Linux, a Linux distribution where all programs are written in Perl
No one has asked yet, so I guess I have to: is the Perl binary written in Perl?
danweber··on Perl/Linux, a Linux distribution where all programs are written in Perl
Anything I would use Perl for, I use Ruby instead.
danweber··on Facebook frees up 60% more shares today
A fall when a bunch of people can suddenly sell is a normal thing.

And those insiders should sell parts of their positions. They are very heavily invested in FB and need to diversify, even if they believe FB is a very wise investment. Many insiders probably have more than 90% of their portfolio in FB stock.

danweber··on How an app with 200,000 downloads led to developer homelessness
All of this "giving away" of stuff has stopped our society from reinventing the wheel.

Unfortunately, the people "giving away" spend a lot of time reinventing fantastically-different but only-very-marginally-better wheels. Every week I see on HN about some new language or framework someone has invented that fragments the market even more. If you aren't being compensated in dollars, being compensated with being "the inventor of X" can come close, so there's a big supply of this.

danweber··on How an app with 200,000 downloads led to developer homelessness
Several times I've been a company that says "the way the rest of the industry does X is stupid."

Sometimes we broke the rest of the market, sometimes we captured a really big piece, sometimes we had to give up and do what they all do.

danweber··on Google's Autonomous cars complete 300,000 miles without an accident
"Missing stop signs" is one place where a google car would be great, since they pre-map the area and would know a stop sign has disappeared. Knowing that would cause them to slow down and be even more careful.

Autonomous cars never get distracted, have 360 degree vision, look at all things all the time, and can react in tens of milliseconds versus hundreds of milliseconds. I'd trust that over a "professional driver."

danweber··on Google's Autonomous cars complete 300,000 miles without an accident
There's a classic science fiction story that I cannot remember now where people do exactly that.

If it becomes a problem, the car can transmit images of the jaywalkers to the police.

danweber··on Google's Autonomous cars complete 300,000 miles without an accident
The people doing this have talked about how their autonomous car met another company's autonomous car. There didn't seem to be a problem.

Really, when there are more autonomous cars on the road, each and every one will get better from their neighbors. They can directly share the data they see and what they are doing. The network effects will be huge.

danweber··on Google's Autonomous cars complete 300,000 miles without an accident
The 4-way stop was something they had to change from the ideal setup. The google car was obeying the law and waiting its turn and never getting it. They made it get more aggressive the longer it waits and now it gets through them just fine.
danweber··on Google's Autonomous cars complete 300,000 miles without an accident
I think $10,000 is a big over-estimate, but even that would be spread out over the life of the car. I'd happily pay $1000 a year to not have to worry about driving.
danweber··on Google's Autonomous cars complete 300,000 miles without an accident
Remember that the "5%" of the time you use your car is probably the same "5%" of the time every one else wants to use their car, i.e. rush hours.
danweber··on Google's Autonomous cars complete 300,000 miles without an accident
From what I know it's always known-course. If you were to get a google car today for your commute (you can't), you would first drive to and from work yourself, probably more than once, so it can map everything.

Knowing where there should be a stop sign and traffic lights significantly reduces risks. The computer still needs to be able to learn when new ones appear, of course.

danweber··on Google's Autonomous cars complete 300,000 miles without an accident
Driving at night and the rain will probably be where autonomous cars really outshine humans. Lidar systems don't care if you are wearing all black during a night at new moon.

Snow is much harder for the time being. A snow drift falling off a car can make a google car think a cooler has appeared in the road.

danweber··on Google's Autonomous cars complete 300,000 miles without an accident
Google's algorithm (which Strum seems to be pollinating everywhere -- and good, because the old algorithms were failing DARPA tests) is to pre-map the road. The car knows exactly where it is and what is supposed to be there, which it also compared with what it sees now.

How will it react to a bicyclist running a red stoplight and into the car's path, when the car has a green light?

It will stop. In fact, the "failure mode" of self-driving cars will be how pedestrians can bully them by stepping in front of them so they stop.

When the car comes across kids playing football/street hockey/baseball in the street, will it stop for them?

There is already video of this. The radar/lidar isn't good enough to see a baseball, but it's definitely good enough to see a kid.

Will these cars have systems to react when they take damage?

It will probably pull over and stop if something is wrong.

danweber··on Google's Autonomous cars complete 300,000 miles without an accident
That doesn't seem right to me. A person driving 10K a year will hit 300,000 miles over the course of 30 years. Does the average person really have less than 1 accident every 30 years? Especially when they are younger?
danweber··on Please turn on two-factor authentication
I've got a 200 message/month plan from AT&T for $5 a month. My only complaint is that I can't share messages across the two lines on the account so each gets billed $5. (Also, no data plan.)
danweber··on Please turn on two-factor authentication
That is very helpful. I'm going to be proposing this to work very soon thanks to you.
danweber··on Please turn on two-factor authentication
Back when cell phones weren't ubiquitous, I once worked at a start-up where one of the really rich technical leads thought it was unfair that he got charged when people called him on his cell phone. I guess he thought that the peons who could only afford land lines were supposed to subsidize him. Which I could have forgiven as plain old selfishness, but he also constantly complained about how unfair society was to the poor.

That specific combination of attributes still bugs me.

danweber··on Please turn on two-factor authentication
I think most people are aware that the passwords saved in their browser are, well, saved in their browser, and if someone unkind gains access to the browser they gain access to all the sites with saved passwords.
danweber··on The weakest link by far is Apple
I think "Security questions" need to be completely destroyed and the earth salted. Then we have a long talk about them before bringing them back in a very careful, limited format.

Bank Of America is horrible in this. First off, if someone else tries to log in using your username 3 times, it locks you out of your account. You need access to your email to get back in.

But it demands you re-create three security questions after that. I chose a simple username so other people stumble across it a lot. So I have to go through this process frequently, and there is nothing I can do to stop it.

How securely are they storing this PII? Probably not at all. I try to give the exact same questions and answers every time to limit what BoA knows about me, but someone compromising by BoA account might be able to learn that information and use it to cascade attacks into other services. (They display by secret questions and their answers to me in plaintext.)

danweber··on The weakest link by far is Apple
Compared to the other things we're talking about, fraud on credit cards is largely a solved problem. (Yes, there are issues, and I'm sure people actively working on the problem don't consider it solved.) Credit card fraud puts out the consumer $50 at most.

But someone got the bright idea to attach other things to your credit card information, like your entire MacBook.

We need to burn down the entire concept of "security questions" and start over from scratch.

danweber··on Curiosity Mount Sharp Photo
In space, in the inner solar system, solar panels are more power dense than RTGs.

The situation might change enough being on planet where the sun is slightly filtered by the thin atmosphere, and the sun doesn't shine ~12 hours a day.

RTGs have many other advantages: they provide heat as well as power (which is really important on Mars) and they don't wear out when covered with dust. If Curiosity stops running within a decade, it won't be because of power.

danweber··on How Apple and Amazon Security Flaws Led to My Epic Hacking
Yeah, one of the points of CIA is to help you identify which problems you want to fix. A lot of business assets do require confidentiality, and you have to spend correspondingly more money and time dealing with it.
danweber··on How Apple and Amazon Security Flaws Led to My Epic Hacking
Once I moved and realized I forgot to cancel my phone and DSL. On the road, I used my cell to call the phone company to cancel. They did it for me immediately.

I was relieved it was so easy, but unnerved at how easy it was.

Maybe they had the cell associated with my land line, but I doubt it, since I got the line before I ever had a cell.

danweber··on How Apple and Amazon Security Flaws Led to My Epic Hacking
Could be. But that's a very different problem.

Old-school computer security breaks things down into the CIA categories:

Confidentiality is for things you want secret. Integrity is for things you want to not be altered. Accessibility is for things you want to be able to reach.

Honestly, very little of data requires confidentiality. Yet that's what encryption is usually used for. I would, by an order of magnitude, rather have a hacker gain access to my family photos than have them deleted beyond my ability to recover.

I hate whole-disk encryption. In nearly everything in my life, the threat of losing access to my data is vastly worse than someone else accessing it.

danweber··on How Apple and Amazon Security Flaws Led to My Epic Hacking
Honestly, the credit cards are the easiest part. I'd much rather someone get my credit card number than my email account.
danweber··on How Apple and Amazon Security Flaws Led to My Epic Hacking
We need people to be able to regain access after losing a password, and we need only the right people to have that. This is a very hard problem.

One thing that we should have is a "cool down" period. If you want to regain access to, say, your GMail account, then it will take 48 hours of waiting, and phone calls and emails will go out to your contacts before that is completed, so the real person has a chance to protest.

I don't understand how the MacBook data was permanently lost. Even if the files were deleted in the OS, they are recoverable by disk utilities. Unless they were encrypted. Which just goes to say that when you think the solution to your problem is encryption, you don't understand your problem.

danweber··on Great work Visa, now I hate you
the thinking behind the "We are proud to only accept Visa" marketing campaign

It's like "for your convenience."

"For your convenience, all toilets have been closed."

danweber··on How the Curiosity Rover's Nuclear Battery Works
Not really. If the rover is on the side of Mars facing away from the Sun, it's almost always facing away from the Earth, too, since the Earth is deeper inside the solar system.

Facing the Earth and facing the sun are highly correlated. Seeing one xor the other is possible, but unusual.

danweber··on HN's Daeken will expose security flaw in 4m hotel room keycard locks
And he hasn't released the source code and hardware specs yet. So, although I think he should have contacted the vendor (even if that could have been inconvenient for him) before going public, he still hasn't made it trivial for a third party to go around robbing unattended hotel rooms. It's his choice but I would appeal to him to not do that.

Full disclosure is a lot of fun, and it increases the status of geeks like us, so it's really to approve of it. I did when I was in college.

Page 1 of 2Next →