HNHacker News
TopNewBestAskShowJobs

deaps

332 karma · joined March 23, 2018

submissionscomments
deaps··on Mumbai bans plastic bags, bottles, and single-use plastic containers
> Do you expect me to carry the wrapper back to my home or carry a small dustbin along with me every time?

Yes...That's what I would do, and I don't even remotely consider myself an 'environmentally-conscious' person whatsoever.

deaps··on Braces Have Made Snoring a Modern Health Problem
Good point - not sure I thought it through to be honest.
deaps··on Braces Have Made Snoring a Modern Health Problem
The jaw seems like a pretty complicated joint in its function. Not necessarily as complicated in movement as some of the other joints, but as far as clamping force required, and necessity to have proper alignment to function (pain-free).

I don't think that surgery on the jaw itself should be an option in cases other than severe pain limiting function of the joint. If the teeth are crowded, remove a couple - that definitely seems like the choice with the least potential for complications that could essentially ruin someone's everyday life anyway.

deaps··on NTSB: Autopilot steered Tesla car toward traffic barrier before deadly crash
I think one of my main concerns with "autopilot" is that for a lot of drivers, it will absolutely make the roads safer for them and those that use the roads around them. Consequently, for some safer and more-alert drivers, it has the potential to make driving less safe.
deaps··on How The New York Times Uses Software to Recognize Members of Congress
> I don't actually believe that any such system could ever reach any reasonable level of actual effectiveness due to the fundamental complexities of human behavior and circumstance...

Absolutely it could - that would all be factored into the percentage. Human behavior and chance encounters are the exact reason you could never say 0% or 100%, however.

deaps··on Things to know about the GDPR, Mozilla and Firefox
I've gotten emails from sites I signed up for at least a decade ago. I find it troubling that that many sites I've signed up for had to actually change their privacy policies because of this. But I guess in the end, it's a good thing that they're all changing.
deaps··on Senator requests better https compliance at US Department of Defense [pdf]
That's odd - the VA pretty much leads the way with compliance on this...

It's literally the only agency listed with over 15 sites that is greater than 99% compliance.

https://pulse.cio.gov/https/agencies/

deaps··on HTTP headers we don't want
Right - then IETF adopts approved RFC's and publishes them as internet standards. What we're discussing in this thread are accepted / approved internet standards - not just some random RFC that some dude tossed up on a work group.
deaps··on HTTP headers we don't want
So then re-write and submit an RFC...or go to IETF and join a WG - be open to discussion and speak up about what needs changed.

A MUST is a MUST, in my opinion - and too often there are serious issues in (web) communication because people ignore them as they see fit.

In either event - no one is saying that you should wait to change an RFC (or wording in an RFC) until it's fully deprecated and completely not in use - but a lot of people use RFC's for researching issues, especially in areas they are not 100% familiar with. Coming across a MUST and seeing that some software vendor or hardware vendor doesn't follow it is all too common. This delays certain projects by weeks, sometimes longer, and costs the involved companies lots of money. RFC's exist for a reason...because the approved standards are just expected to be followed when creating new things.

deaps··on CS 189: Introduction to Machine Learning
You're right.

I looked into this a little further. The data is encrypted with Github's private key (thus decrypted with their public cert). I then wondered how he got a copy of Github's private key...but as it turns out, the IP does belong to Github.

In either event, definitely misconfigured, but I added an exception as it all seems legit in the end. It looks like he's just hosting his site (with his own DNS) on github's server and didn't get an ssl cert yet.

deaps··on The World’s Safest Source of Energy
The use totally fits the definition:

adjective: said

1. used in legal language or humorously to refer to someone or something already mentioned or named.

deaps··on A Recycled IP Address Caused Me to Pirate Books by Accident
I'm not very security minded. I have old domains and subdomains that I used to use that have long since passed - that lived on server IP's that have also long since passed on from my ownership as well.

I just double checked all of my old stuff - and there's not a trace left out there. Apparently, I cleaned up all my old DNS entries as things moved on, even though none of those domains are my 'brand' (as the author states it is his). As a non-security minded person, I find it hard to believe a security-minded person, whose good at his trade, forgets to do this.

deaps··on Conversations with a six-year-old on functional programming
I enjoyed it.

I spend a lot of time listening to people ramble in meetings or troubleshooting, where I wish they understood the subject matter enough to explain it as if talking to a six year old.

deaps··on How much does Apple know about me? The answer surprised me
<Your Siri requests —"Show me how to get to PF Chang's," or "What year was Steve Jobs born?" go back to Apple — but it uses a random identifier to mask your identity. So a Siri search for the closest Chipotle restaurant will only tell Apple that a user requested the data, but not associate it with me.>

I find that comforting. In fact, if I was a large organization and processed a ton of user data, I'd want to store that data anonymously too, due to the sheer risk of having that personal data.

deaps··on Python startup time: milliseconds matter
I totally understand that milliseconds matter in the use case described in the article.

For me, personally, I use python to automate tasks - or to quickly parse through loads and loads of data. To me, startup speed is somewhat irrelevant.

I built a micro-framework that is completely unorthodox in nature, but very effective for what I needed - that being a suite of tools available from an 'internet' server, available to me (and my coworkers) over port 80 or 443.

My internet server, which runs python on the backend (and uses apache to actually serve the GET / POST) literally spits out pages in 0.012 seconds. Some of the 'tools' run processes on the system, reach out to other resources, and spit the results out in under 0.03 seconds (much of that being network / internet RTT). To me, that's good enough - adding 30 or even 300 milliseconds to any of that just wouldn't matter.

I totally get that if Python wants to be a big (read bigger?) player then startup time matters more...but for my personal use cases, I'm not concerned with the current startup time one bit.

deaps··on New Optical Form Factors for 400 Gigabit Ethernet
I've seen some 160GbE links in datacenters - 4x40's - how much they were actually utilized, I have no idea.
deaps··on New Optical Form Factors for 400 Gigabit Ethernet
Network Engineer here as well - I support one of the world's largest enterprise organizations (although my area of 'expertise' is pretty far down the stack - somewhere between the internet and the WAN circuits) - I can see no personal use for a 400 GbE port on anything.

As far as my organization goes, there will always be a bottleneck somewhere else (speaking location to location across the WAN).

The only applications I could see this being useful would be maybe huge ISP interconnects or maybe some big players in the video streaming world. That doesn't mean that future-proofing is a bad thing - of course cost will probably be a very large concern in the case of 400GbE...I see a lot of 40 gig ports that go completely unused, personally.

deaps··on I switched from iPhone to the Pixel 2: One-week report
My mother switched to an iPhone about a year ago - mainly so that she could 'text' with my son who has an iPod.

Overall, that being her first 'smart phone' (she used to have a blackberry), she's made quite the transition, seamlessly. She doesn't have any problems and was even able to get CarPlay working with just a short phone call walking her through the first plug-in process.

We FaceTime, she's been using emoji's, group messages just fine (she used to not realize if she was sending a group response/personal, etc), sharing pictures (live photos), etc. My point is, she's not very 'technical' - but the iPhone seemed to ease her into 'tech' smoothy. Now that's not saying an Android couldn't also have done the same - just one anecdotal point where the iPhone was successful in a technology-based transition.

deaps··on Ask HN: What has been your most rewarding job or project and why?
My worthwhile project was when I really stepped outside of my comfort zone to lead a complete redesign / overhaul of a datacenter over the course of 9 months.

I had the knowledge, and the desire, but probably lacked confidence in my ability to be the lead design engineer for such a large project. I had always worked in a NOC/operations role where I excelled at any task that was put in front of me, but I had a lot of questions, always.

Fast forward a few years - I took a leap and went for it. I got hired on for a 9 month contract to replace racks and racks of networking equipment, an entire replacement of everything layer3 and layer2 in this datacenter, complete with remote monitoring/management facilities.

I went full bore - I didn't sleep much. I ran the systems I was working on at home in my lab, virtually, and basically taught myself Juniper and Arista from the ground up - having only worked on Cisco devices previously.

Long story short, the conversion was finished ahead of schedule...but the contract had me there for a while longer, so I got tasked with a bunch of crazy 'stuff' - things that I've never touched. Load balancers, traffic shapers, linux servers (that actually did 'stuff') - just a ton of stuff to learn, understand, plan, and implement. Around this time is when I also got my introduction to the Python language (but that's more of a way to make things simpler to me, rather than what actually pays the bills).

It was through those 9 months, that I became so confident in myself and my abilities. I no longer doubted myself. I no longer thought that my questions were stupid. Because of that, I flourished. I've been in a senior network engineering role ever since...and finally feel like myself. It's great. Literally changed my outlook on life.

deaps··on Ask HN: What do you nerds spend your money on?
Honestly, save / invest as much as you possibly can.

I have a wife and children, we have everything we need, most things that we want, nothing spectacular (sensible, yet very nice, vehicles, bicycles, home with interior upgrades, extra amenities, etc) - our taste is fairly plain. We take a vacation with family every year to save money there.

I guess the point is, live comfortably, get the extra stuff, sensibly, but save. Because you just never know.

deaps··on Interns with toasters: how I taught people about load balancers
I was going to say something similar. I get that this was a very basic explanation of what load balancing can be but very rarely have I seen it implemented in such a fashion, as described - that is, 'serving toast, when finished with the toast, that toaster gets more toast, etc.'

There are so many types of load balancing, and so many different ways to guard, simply with best practices, against what this story explains.

I also found the 'quadruple hump' in a graph reference difficult to follow without more of a backstory of what the graph was representing.

I also don't understand why it would be so difficult to grep through the logs of that load balancer (or load balancers) and find that common fault on the backend.

deaps··on ODNS: Oblivious DNS
Let's take the case that it's a local machine - on your local network - acting as the ODNS Stub. The DNS request is then encrypted from your machine to the trusted ODNS Stub - but then from that ODNS Stub out to some resolver on the internet, there exists the DNS query (whether encrypted or unencrypted) - sourced from your same public IP that your machine would have sourced it from in the first place, correct?

I'm certain I don't understand the entirety of ODNS - but the basics still have to exist - something still needs to make a query on behalf of the initial user to some authoritative server (unless the answer is already cached). I guess, what I'm picturing in this case, is that if the trusted resource (ODNS Stub) exists in your local infrastructure, then the source outgoing to the internet might as well just be your local machine in the first place - because that's how 'the internet' sees it anyway.

Anyway, I'm all for making DNS more secure...and this seems to be one way to change where your trust lies, but not a definitive solution, to me.

deaps··on ODNS: Oblivious DNS
It still seems to have the same problem as DNS over TLS - that is that someone in that pipeline sees your query.

In the case of 'standard' DNS (unencrypted port 53 traffic) - anyone can 'snoop' (ISP, internet routers, etc) and the resolver can retain that information.

In the case of DNS over TLS - it's the box the performs the decryption that can retain that information.

In this case, the ODNS Stub can retain that information.

The only question is who do you want to be able to view your queries. AKA who do you trust the most (or possibly, who do you trust the least).

deaps··on Apple’s Stumbling HomePod Isn’t the Hot Seller It Wanted
The article hits the nail on the head for me. My son got a google home mini for Christmas last year for free with the chrome book we bought him.

Now we have a home mini on every floor, and we are happy with the relatively cheap price we paid.

Apple’s version either needs to come down in price or offer a lot more for its current price - if it wants a larger share of the market, in my opinion.

deaps··on Ban Targeted Advertising
As an outsider to the business entirely, I couldn't help but become frustrated the other day with the lack of targeted marketing on Sling TV. I must have watched an ad for Colo Guard 15 times - As a 36 year old, spending that much time watching an ad for people only 50+ it just seemed like a waste of their money and my time. While I'm sure they get some 'discount' for simply throwing the ads out there, if the had a way to more specifically target audiences/demographics, I feel like they could charge more for their ads.

That being said - maybe it should be an opt-in...that is to say, users provide the information they want to be targeted as. AKA, maybe I feel ok putting my race, my age, my location - and maybe another user doesn't - and that's fine.

I think most people's problems with ads are, more than likely, the 'deceptive' ways that corporations go about obtaining our personal information.

← PreviousPage 4 of 4