HNHacker News
TopNewBestAskShowJobs

doctorsher

252 karma · joined January 27, 2016

Software engineer in computer networking space.
submissionscomments
doctorsher··on Show HN: Krep a High-Performance String Search Utility Written in C
I am interested in the CPU intrinsics detection in a single header file, if you don’t mind dropping the link.
doctorsher··on T-Mobile begins blocking iPhone users from enabling iCloud Private Relay in US
This does not seem to be the case. Elsewhere in the comments, neurobashing said their private relay works fine for an MVNO on T-Mobile.
doctorsher··on Millions of AMD PCs affected by new CPU driver flaw need to be patched ASAP
Am I missing something, or is this article making a big fuss out of a relatively mundane privilege escalation? "MILLIONS AFFECTED, PATCH ASAP!" If you already have access to the machine, you can read physical memory and break KASLR.
doctorsher··on How percentile approximation works and why it's more useful than averages
This is excellent information, thank you for posting this! I was not familiar with this example previously, but it is a perfect example of summary statistics not capturing certain distributions well. It's very approachable, even if you had to limit the discussion to mean and variance alone. Bookmarked, and much appreciated.
doctorsher··on How percentile approximation works and why it's more useful than averages
I heavily caution against the feeling that "standard deviation is a simple way to essentially include percentiles." The usefulness of the standard deviation depends on the distributions that you are working with. Heavy tailed distributions appear a fair amount in practice, and the combo of summary statistics mentioned would not do well on those. Also, Madars' comment in this thread is a beautiful example of this: 4 completely different distributions, with identical mean and standard deviation (among other things). Histograms and percentiles, and if necessary their approximations, are more desirable for the above reasons.
doctorsher··on The Apple vs. Epic Decision
Solid analysis, and a great read. I'm happy you posted this, as I was disappointed by the other Apple v Epic article that was making its way around HN today [0]. This article is significantly more substantive IMO.

The author makes some wise predictions on Apple's response to the lawsuit. Particularly on whether Apple will appeal the injunction because it was based on the UCL, but the injunction applies nationwide. Though no matter what happens, I hope consumers and developers get a fair shake.

[0] https://news.ycombinator.com/item?id=28507747

doctorsher··on Apple announces first states to adopt driver’s licenses and IDs in Apple Wallet
Probably not what you were going for, but an entirely digital wallet would substantially reduce the ‘pain in the ass’ factor of getting robbed.
doctorsher··on Toxic ‘forever chemicals’ contaminate indoor air at worrying levels
J Kenji Lopez-Alt has a lot of great wok content for American kitchens. In [0], he uses a butane torch to get the smoky wok flavor (wok hei) in a standard kitchen. He also reviews outdoor wok setups for those who want something close to Chinese street vendor-type vibe.

[0] https://youtu.be/iac_idcz6XE

doctorsher··on Toxic ‘forever chemicals’ contaminate indoor air at worrying levels
When you tried the carbon steel pan, was it properly seasoned? They stick like hell before they are well seasoned, but seasoning them gives the carbon steel its non-stick properties. Woks are the ultimate tool for this, as they are carbon steel (so non-stick when seasoned) and their shape minimizes the amount of oil necessary to fry the rice. It is ubiquitous for fried rice across almost all of Asia.
doctorsher··on Twitter starts to require login to view tweets
I don't have an account, and the change has been noticeable and annoying. It's more than just clicking on another tweet, though from what I can tell they've been A/B testing this behavior (sometimes I get it and sometimes I do not). On mobile, you can't click through to someone's profile from the tweet without creating an account. If the tweet chain is more than 4 or 5 tweets, you cannot read the rest without creating an account. It's prevented me from normal browsing habits multiple times, like reading the ASML twitter thread that was posted on HN a couple of days ago.
doctorsher··on TSMC’s Speciality Technologies
A choice they are allowed to make N years from now, when their current Broadcom terms expire, otherwise they forfeit their preferred pricing.
doctorsher··on Windows Defender blocks qBittorrent
I agree completely. I have Windows at home for gaming, and Windows at work (because those are the laptops we get). It's rough. The only thing that makes this bearable is Windows Subsystem for Linux.

Side note: if you end up dual booting your gaming PC, please learn from my mistakes and disable Fast Startup before you do. Otherwise you're going to have a bad time.

doctorsher··on Salesforce completes acquisition of Slack
Agreed, but that is not exactly difficult to do. Teams is a total dumpster fire.
doctorsher··on Valve Steam Deck
Source? The console market (~45 billion) is larger than the PC market (~37 billion) [0], but I wouldn’t describe PC as ‘fairly small’. Maybe you have different data though?

[0] https://newzoo.com/insights/articles/newzoo-games-market-num...

doctorsher··on Ask HN: How to learn how to sell?
I completely agree, and I am surprised your comment was the only that mentioned sales engineering. Like you, I took a sales engineering role for a technical product, and it was by far the best way for me to learn sales (coming from a software background).

Plus, while there is an abundance of sales materials out there, none of them will prepare you as well as actually doing the thing. I'm not scared of talking to customers, no matter what impressive titles they may bring to the table -- I've already spoken with dozens of other CTOs, CISOs, COOs, etc. from the deals I worked on. I'm acutely aware of the art of a pitch, and have a mental model for which techniques are crucial and which are to be avoided. After practicing the pitch/demo enough, I was able to start analyzing my choice of words, flow, etc. during the actual call (as opposed to after the fact). I also learned the art to managing deal cycles, and an immediate "no" is vastly preferable to a "no" after being strung along for a year. Perhaps most importantly, I learned how to be the trusted technical advisor to the customer -- the sales rep may want every deal to close, whether or not it's a good fit, but that's not the way to happy customers and good integrity in the sales process.

I only did the sales engineering role for a little under a year, but it provided me with incredible value.

doctorsher··on P4: Open-Source Programming Language for Protocol-Independent Packet Processing
You are exactly right. In fact, there are a number of approaches in this space: p4c-ebpf [0], p4c-xdp [1], and p4c-ubpf [2].

[0] https://github.com/p4lang/p4c/blob/main/backends/ebpf/README... [1] https://github.com/vmware/p4c-xdp [2] https://opennetworking.org/news-and-events/blog/p4c-ubpf-a-n...

doctorsher··on P4: Open-Source Programming Language for Protocol-Independent Packet Processing
Primarily based out of Santa Clara, California. All of the Santa Clara roles on this page [0] are in the Barefoot Switching Division (BXD) of the Data Platforms Group. It makes sense given the Barefoot Networks headquarters were in Santa Clara.

[0] https://jobs.intel.com/page/show/US-Connectivity-Jobs

doctorsher··on P4: Open-Source Programming Language for Protocol-Independent Packet Processing
I would expect to see Intel pushing P4 heavily over the next year. P4 will almost certainly be involved in the roadmap for their recently released IPU (a SmartNIC needs some type of programmable substrate). Also, their data platforms group had been recruiting heavily around the Barefoot Networks / P4 angle. AND, just this morning, Pat Gelsinger announced the data platforms group is being split into two groups —- one of which (the Network and Edge group) to be headed by Nick McKeown, former chairman and cofounder of Barefoot Networks, as senior vice president [0].

[0] https://www.lightreading.com/5g/intels-reorg-puts-nick-mckeo...

doctorsher··on Teach Yourself Computer Science
Computer Systems: A Programmer's Perspective: around 2012 / 2013, I went through this book because I took a coursera course based on it. In fact, many universities base their systems courses around this book. It is really well written, has a great choice of topics, and phenomenal exercises [0] for practice (some are legitimately fun).

Operating Systems: Three Easy Pieces: In 2013, I found this book because I was frustrated with the textbook assigned for my operating systems class (Silberchatz). OSTEP has incredibly clear and concise descriptions without skimping on necessary details. It's wonderfully written. I was so jazzed up about this book that I ended up sending a lot of edits / improvements, and the authors gave me a very kind shoutout in the acknowledgements section.

Computer Networking: A Top-Down Approach: In 2013, this was the assigned textbook for my computer networking class. I already owned Tanenbaum & Wetherall which is good, but preferred this book. It is a more approachable treatment of networking (without sacrificing any crucial topics), so better for a first course.

I've heard glowing reviews of The Algorithm Design Manual, Designing Data-Intensive Applications, and Structure and Interpretation of Computer Programs over the years, but I haven't personally gone through them. For the TeachYourselfCS categories that I know the textbook landscape, I find their selections spot-on and pretty refreshing.

[0] https://csapp.cs.cmu.edu/3e/labs.html

doctorsher··on Cuckoo++ – High-Performance Hash Tables for Networking Applications (2017)
The submitted link is a pre-publication draft of this conference paper published at the 2018 Symposium on Architectures for Networking and Communication Systems (ANCS): https://dl.acm.org/doi/10.1145/3230718.3232629
doctorsher··on Folly – Faceboook’s open source C++ library
Both are quite similar at a high level. They provide generic utilities for improving synchronization, strings, random number generators, high performance containers, etc. Both are no stable ABI guaranteed, live at head encouraged.

At a more detailed level, I find Folly much more substantial than Abseil. For example, both provide high performance hash tables. Abseil also provides a BTree-based map, which Folly does not. But Folly provides concurrent skip lists, LRU evicted hash maps, a high performance MPMC queue, etc. And that's just talking about data structures. Folly also has asynchronous I/O tools, futures, reference-counted buffers for IO, and many other things outside the scope of Abseil.

Personally, I am loving the asynchronous I/O mechanisms in Folly. It feels more expressive and results in cleaner code than boost ASIO. Just a first impression though, I am relatively new to the library.

doctorsher··on Folly – Faceboook’s open source C++ library
It may not be "standard", but Conan is a C++ package manager which IMHO is quite nice to work with. Not affiliated in any way.
doctorsher··on OSSU: A path to a free self-taught education in computer science
GP stands for grandparent.

In case you need an explanation: in the context of a forum, the parent comment is the one you are replying to, and the grandparent comment is the one your parent comment replied to.

doctorsher··on NSA Said to Have Used Heartbleed Bug for at Least Two Years (2014)
Bloomberg was rightfully dragged through the mud (IMHO), and like the parent I am immediately distrustful of any technical stories they put out. The issue was not that the BMC hack was implausible, but rather Bloomberg's refusal to supply solid evidence backing up their claims in the face of strong denials and perceived issues with the reporting.

A subset of the perceived issues with the reporting:

- How do the exploited servers phone home to China, when they were not connected to the open Internet? Not impossible, but it's asking for a lot of trust without more information. [0]

- One of the only named sources, Ryan Fitzpatrick, saying the details in their big hack article are identical to an example he constructed for the journalists to show that type of attack is plausible. The entire podcast is a great listen, but here is a direct quote: "In September when he asked me like, 'Okay, hey, we think it looks like a signal amplifier or a coupler. What’s a coupler? What does it look like?' […] I sent him a link to Mouser, a catalog where you can buy a 0.006 x 0.003 inch coupler. Turns out that’s the exact coupler in all the images in the story." [1]

- An accusation that the journalists who authored the Big Hack have had a previous story that made a big claim, they had many anonymous sources that back up their claims, but in the end there were extreme doubts of the veracity from people in the know. [2]

- Bloomberg sent another reporter, completely separate from the Big Hack article, in their tracks to discreetly talk to sources / involved parties to figure out the truth. [3]

Sources:

[0] https://daringfireball.net/2018/10/bloomberg_the_big_hack

[1] https://risky.biz/RB517_feature/

[2] https://threadreaderapp.com/thread/1049617855396933632.html

[3] https://www.washingtonpost.com/blogs/erik-wemple/wp/2018/11/...

doctorsher··on TurboTax Uses Dark Patterns to Trick You into Paying to File Your Taxes
Same thing happened to me! A few years ago, in addition to my normal job I had some 1099 Misc income. It was the first year I had taxes that I wasn't familiar with, since I wasn't sure how the 1099 Misc would come into play. As I was filling it out, TurboTax prompted me to upgrade to a paid plan, and they estimated they could get me an additional $1200 dollars back on my refund. Even if they are overestimating, paying $80 and getting $400 back is worth it. So I went with it and filled out the new information. I got absolutely nothing added to my refund: $0. It's a ridiculous dark pattern, and I'll never give TurboTax another dime.
doctorsher··on Ask HN: What's the latest on that “Big Hack” story by Bloomberg?
It depends what you mean by "drop the whole thing." The latest reporting I saw with fresh conclusions is from the Washington Post in late November [0]. Essentially, Bloomberg sent out a reporter completely independent of the Big Hack article to ascertain whether or not it was accurate. Additionally, Apple did a secondary investigation to see if their senior director of information security had written any internal documents about the Big Hack -- no such documents existed, corroborating their initial denial. So both Apple and Bloomberg have taken additional steps since the original article was published. However, in terms of public statements, it does seem that they have dropped it.

Pertinent quotes from the article [0]: "The goal of this effort, Elgin told the potential source, was to get to 'ground truth'; if Elgin heard from 10 or so sources that 'The Big Hack' was itself a piece of hackery, he would send that message up his chain of command. The potential source told Elgin that the denials of 'The Big Hack' were '100 percent right.'"

"According to the potential source, Elgin also asked about the possibility that Peter Ziatek, senior director of information security at Apple, had written a report regarding a hardware hack affecting Apple. In an interview with the Erik Wemple Blog, Ziatek says that he’d never written that report, nor is he aware of such a document. Following the publication of Bloomberg’s story, Apple conducted what it calls a 'secondary' investigation surrounding its awareness of events along the lines of what was alleged in 'The Big Hack.' That investigation included a full pat-down of Ziatek’s own electronic communications. It found nothing to corroborate the claims in the Bloomberg story, according to Ziatek."

[0] https://www.washingtonpost.com/blogs/erik-wemple/wp/2018/11/...

doctorsher··on AMD Announces 7nm Rome CPUs and MI60 GPUs
Non-AMP link: https://www.tomshardware.com/news/amd-new-horizon-7nm-cpu,38...
doctorsher··on Facebook open-sources new suite of Linux kernel components and tools
Thank you for the insight! Your post adds helpful context / corrections. Very exciting times, indeed! :)
doctorsher··on Facebook open-sources new suite of Linux kernel components and tools
Disclaimer: I am not an expert in this, so any corrections are welcome. But here's my intuition.

XDP = eXpress Data Path. It is a new packet processing mechanism in the Linux kernel, which is in some ways an answer to DPDK and other userspace networking frameworks that skip the kernel in pursuit of high performance. It was originally proposed by Cloudflare, when they achieved poor scalability (in terms of packets per second) for something as simple as a packet drop rule in the kernel. The principle behind XDP is to leverage packet processing rules as early as possible in the packet processing pipeline (no wasted work). However, only certain types of rules are simple enough to be done in a high performance way -- complex rules would still be left to netfilter / ebtables.

The rules which XDP leverages, called extended Berkeley Packet Filters (eBPF) are a new take on an old technology. eBPF is a mechanism that allows userspace BPF rules to be inserted on-the-fly into the kernel. Essentially, matching rules which meet certain simplicity requirements (e.g. loop free) can be compiled into a bytecode that is executed by the kernel in a very efficient way. This is an extremely flexible technology, and one domain which it is well suited for is packet processing. BCC is just the set of compiler tools for creating your own eBPF bytecode.

doctorsher··on One of Bloomberg’s sources told them Chinese spy chip story “didn’t make sense”
The article is a clunky representation of the original material. I would highly recommend listening to the podcast that is being quoted from [0]. It is only 20 minutes long, and both the interviewer and the named source Joe Fitzpatrick have thoughtful commentary on the matter.

[0] https://risky.biz/RB517_feature/

Page 1 of 3Next →