HNHacker News
TopNewBestAskShowJobs

dopylitty

2,236 karma · joined November 29, 2018

submissionscomments
dopylitty··on After private equity takes over hospitals, they are less adept of providing care
>They are typically not the cause but a symptom of a failing company.

This isn't true in most cases. PE has killed many profitable companies by taking deliberate steps which resulted in the companies directing their incomes to servicing unsustainable debts rather than running or improving the businesses.

For example the eldercare company ManorCare was profitable and successful prior to being bought and destroyed by a PE group. The PE firm loaded ManorCare with the debt that the PE firm used to buy it in the first place and then sold ManorCare's real estate and forced ManorCare to rent it back, causing ManorCare to spend $500 million/year on rent[0]

Forcing companies to take on debt and sell their assets is a standard part of the PE playbook and inevitably ends in the death of the company regardless of how it was performing prior to being taken over.

0: https://skillednursingnews.com/2018/11/washington-post-blame...

dopylitty··on After private equity takes over hospitals, they are less adept of providing care
They aren't trying to run the businesses. They're trying to extract the value from the businesses. What happens to the business afterwards and what happens to the businesses customers in the process is not important because they've structured their ownership in such a way that they profit regardless.
dopylitty··on After private equity takes over hospitals, they are less adept of providing care
I've been reading a book called "Plunder"[0] which covers private equity's impact on several sectors including eldercare, medical, housing, finance, and retail.

It lays out how the PE firms' MO is to destroy companies while extracting every ounce of value from them leaving a husk that quickly falls apart. There are several different strategies used by PE firms such as selling off property and renting them back to the companies they own, forcing companies to take on debt to pay the PE firms, and strategically breaking the law because the PE firms are not liable for the broken laws. It also covers how PE firms buy up all companies in a particular region and sector so that competition is not possible and consumers have no choice but to use the PE owned providers.

It shows that the impacts PE has on hospitals such as those in this study are not side effects but are the known and intended goals of PE firms as they extract the value from the company.

These firms need to be regulated out of existence but unfortunately the book also covers how many high profile government movers and shakers are tied up with private equity. For instance former secretary of the treasury Geithner now runs a PE firm and former president Trump is good friends with a PE exec (CEO of Blackstone).

0: https://www.hachettebookgroup.com/titles/brendan-ballou/plun...

dopylitty··on CrowdStrike's outage should not have happened
This is a nice idea but the problem isn't the individuals in the system but the system itself. As long as shareholder value/profit is the only factor companies consider this is the end result you will get.

Management is just making decisions based on what the companies value and companies are just valuing what their shareholders value which is more money for the shareholders.

The best way to fix it would be to reform the stock market system so that companies aren't beholden to uninvolved third parties looking to make a quick buck. Only active employees should own stock in companies and sit on company boards.

This would also require reforming the retirement system so retirement money isn't just dumped into the stock market. It needs to instead go somewhere safe and just sit. Retirement funds being in the stock market creates a huge inflationary feedback loop by demanding constant increases in profits which cause companies to raise prices which causes retirement funds to need to be bigger which causes them to demand more profit increases.

dopylitty··on More than a week without power leaves Houston-area residents feeling abandoned
Most of America could be considered a developing country.

Only a few places in the Northeast and West Coasts along with isolated cities in the interior really qualify as modern when you look at metrics like good governance, maternal mortality, access to healthcare, and health of democracy.

dopylitty··on CrowdStrike debacle provides road map of American vulnerabilities to adversaries
Or don't use an OS at all. We need to think about minimizing the use of software in critical infrastructure. If that means less efficiency because you have to be near something to maintain it then so be it. That would be good for jobs anyway.
dopylitty··on Siblings miss crucial life-extending treatment because of CrowdStrike outage
Yes
dopylitty··on Garage: Open-Source Distributed Object Storage
I read that curl recently added sigv4 for what that’s worth[0]

0: https://how.wtf/aws-sigv4-requests-with-curl.html

dopylitty··on CrowdStrike Update: Windows Bluescreen and Boot Loops
This sounds a bit like someone just got ran over by a truck because the driver couldn’t see them so people ask why trucks are so big that they’re dangerous and the response is “you just don’t know how trucks work” rather than “yeah maybe drivers should be able to see pedestrians”.

If modern medicine is dangerous and fragile because of network connected equipment then that should be fixed even if the way it currently works doesn’t allow it.

dopylitty··on CrowdStrike Update: Windows Bluescreen and Boot Loops
Maybe if all the profit seeking entities were removed from healthcare that money could instead go to the development of useful offline systems.

Maybe a handheld device for scanning in drugs or entering procedure information that stores the data locally which can then be synced with a larger device with more storage somewhere that is also 100% local and immutable which then can sync to online systems if that is needed.

dopylitty··on CrowdStrike Update: Windows Bluescreen and Boot Loops
It was Windows in this case but nothing is stopping it from happening with any other widely used system that gets online updates. CrowdStrike has root on Linux/MacOS as well after all.

The problem is relying on networked computers for critical infrastructure with no contingency plan. This sort of thing will happen whether because of a bug or because of ransomware. The software and hardware industries are incapable of producing reliable and safe products in our economic system.

Important services such as hospitals, groceries, water treatment plants, and electric grids should be able to operate in offline mode when this sort of thing inevitably happens.

dopylitty··on Modern Luddites: On Being a Digital Minimalist Family in a Tech-Saturated World
Another vote for the book linked in the article. It gets into the history of how machines were introduced into the textile industry in England. Wealthy mill owners forced child laborers to run the machines while simultaneously making the artisan workers unable to sustain themselves or their families by producing shoddy low quality items in bulk.

As always the problem wasn't necessarily the machines but that they were controlled by wealthy mill owners who reaped all the profits and left the rest of society to starve. England really was patient zero for the toxic economic system still being used in the US.

dopylitty··on Five people infected as bird flu appears to go from cows to chickens to humans
Paul’s great but this is a little outdated. The variant in Colorado has both alpha-2,3 and alpha-2,6[0]

0: https://www.nature.com/articles/s41586-024-07766-6

dopylitty··on 'The new normal': work from home is here to stay, US data shows
That's one reason the in office vs remote debate is challenging. Working in person with others can be beneficial some times for collaboration and socialization but if it requires a dangerous and environmentally devastating car based commute then those benefits are negated. We shouldn't have to commute long distances in cars to get to the office but most communities are designed in a way that makes it impossible to live close to work.

I wouldn't mind working in the office if it meant walking 15 minutes down the street in the morning but around here I would have to make 4x what I make to live near the office and even then it would be a commute because the offices are sequestered in these maze like office parks with no sidewalks.

So on days I'm in the office it's a choice between a 30 minute drive with terrifyingly bad drivers focused on their cell phones while careening around at 80mph or a peaceful but much longer train ride followed by a 20 minute walk crossing streets with those same dangerous drivers.

I guess it's yet another thing where the root problem is the design of our communities.

dopylitty··on AT&T says criminals stole phone records of 'nearly all' customers in data breach
I’d take it a step further. If a technology is impossible to secure it shouldn’t be used. Maybe it’s time to rethink all the parts of our lives we’ve handed over to software.
dopylitty··on AT&T says criminals stole phone records of 'nearly all' customers in data breach
Not only that they blew $8 billion/year on dividends that could've gone into the business or to employees instead of being extracted and given to people who have nothing to do with the business.
dopylitty··on Awsviz.dev simplifying AWS IAM policies
It’s a little more complicated than that. I’ve run into many instances where a particular Action involves many different Resources.

If you’re trying to do fine grained permissions you have to know every resource that might end up in the request context and then have an entry in a Resource section of a policy for that Resource type. For instance just creating an EC2 (RunInstances) might involve Subnet, Security Group, EBS, image, volume, snapshot, and a few other resource types.

This gets even more complicated when you’re using Condition operators because the conditions are checked against every resource in the request context but each resource type has different valid conditions (eg some resources have tags and some don’t) so you have to split up the policy into numerous statements specific to each resource type.

All of that would be fine if there was any way to actually reliably get the context of a request so you can see exactly what was denied. Sometimes you can get the context via the encoded authorization message in a failed API call but this is usually truncated in CloudTrail or if you’re using IaC tools like Cloudformation.

They’ve done a lot in the past few years to explain why a particular call was denied but none of it beats seeing the context and seeing exactly which part of the policy did or didn’t apply.

dopylitty··on New Research Finds Differences Between Male and Female Brains
The article seems to conflate sex and gender while the study is paywalled so I can't tell how they defined male and female. The study does seem specific to sex and doesn't mention gender at all in the abstract.

Without those definitions it's basically saying "things we grouped a certain way ended up grouped that way" which isn't really a useful result.

dopylitty··on Advantages of incompetent management
> the pool of available CPU/Memory resources is effectively unlimited.

This isn't true. Every CPU you use is sitting in a physical server somewhere. Every server is sitting in a rack in a building that's sitting on land that used to be nature. It's using electricity that could be used instead for cooling or heating a person or just not generated at all. It's cooled using fresh water that is needed by every living thing and is in short supply in many places.

The idea that compute is unlimited is a horrible myth that cloud companies have sold which has effects and externalities that will be seen as on par with the myth of unlimited fossil fuels.

dopylitty··on Jeffrey Snover and the Making of PowerShell
Python's default REPL is godawful. It's also just not designed for the kind of console work that PowerShell excels at because you have to do things like managing file handles rather than just getting the file content and piping it to another command.

PowerShell is great because it's a swiss army knife that has a very nice REPL with autocomplete, no weird whitespace behavior, readline[0], and can do anything .NET can do if you need to do anything more complicated.

Plus it's object oriented so you can focus on doing the tasks you actually need to do rather than trying to figure out how to use archaic utilities to parse the text based output of other archaic utilities.

0: https://learn.microsoft.com/en-us/powershell/module/psreadli...

dopylitty··on Are rainy days ahead for cloud computing?
> If you are a 50 year old Fortune500 that was cargo culted into "we must migrate to cloud", it turns out that lift-and-shift to VMs is hideously expensive. But also, re-architecting 50 years of internal software is also hideously expensive.

One underappreciated aspect of this is that it really isn't possible to control cloud costs in a large enough enterprise even aside from the costs of running your actual applications.

You can have all the tagging and chargeback and finops as you want but at the end of the day trying to manage cloud costs is a losing battle.

Not only do you have the costs of running the applications you actually need which are far beyond the costs to run them on prem because suddenly your app that could run on a single server is running on a 12 node EKS cluster spread across several AZs. You also have the additional costs of all the additional grey matter resources that can't be traced to owners anymore but might still be used somewhere.

There will be 50 dev EKS environments that nobody knows for sure who owns or whether they can be shut down. There will be non-compute resources with monthly charges like the 5000 kms keys at $1/key/month without any easy way to know if there's an object in S3 somewhere that used that key and is subject to a legal retention policy. They all add up.

Sure you can say "Well just be more disciplined" but discipline and large enterprises are orthogonal concepts, especially when the people who start cloud migrations are the type who don't think ahead and usually bounce to another job before the costs of their poor decisions come due.

None of this would really matter if it were just enterprise companies padding Amazon's bottom line but the expansion of data centers has real world costs in the destroyed ecosystems and usage of energy and water for all these unused and useless resources.

dopylitty··on Remembering the LAN (2020)
I think you're looking for the Tailscale subnet router[0]

0: https://tailscale.com/kb/1019/subnets

dopylitty··on OpenEMR: Open-source medical record software
Sometimes it feels like the pursuit of digitization has actually made them less efficient and lower quality overall.

Instead of just having a doctor providing medical care and a government giving them a check suddenly you have a thousand programmers, data center management, managers of programmers, information security teams trying in vain to secure the whole mess, etc.

And that's before you get into the fact that the doctor suddenly can't practice at all when some teenager decides to ransomware the whole business.

dopylitty··on The Aftermath of a U.K. Cyberattack: Blood Shortages and Delayed Operations
Does anyone really believe it's possible for regular enterprises and government agencies to improve computer security to the extent that it's impossible to be attacked? Event CISA was owned due to one of the many Ivanti bugs[0]

The only real way to resolve this problem is to for critical services to stop relying on networked computers for their functions or to have a mandated and audited business continuity plan that is routinely practiced for when the computers inevitably stop working either due to an attack or just routine failures.

0: https://therecord.media/cisa-takes-two-systems-offline-follo...

dopylitty··on LedgerStore Supports Trillions of Indexes at Uber
Having seen the results of everyone being able to spin up a VM (or an EMR cluster, or an EKS cluster) I can say a little more bureaucracy is probably a good thing.

You end up wasting huge amounts of money on resources that are just sitting around idle (no your fancy automation to shut them down won't work because maybe that dev cluster is actually needed at 2am on Sunday. It's an org problem, not a technical problem).

But more importantly you give the cloud providers an excuse to destroy another square mile of pristine forest and build a giant 4 story grey box that wastes enormous amounts of already limited water and energy.

dopylitty··on Mathematical Optimization for Cargo Ships
>As an employee at a terminal, you have a) no reason to trust some software people who may have never seen one of them steel boxes up close, b) if this works, you or your colleague gets laid off, and c) if it doesn't work, you're now stuck cleaning up the mess the computer will inevitably make for you, which is way less fun than planning things yourself.

Also d.) It works sometimes so you get forced to use it and then it gets ransomwared and you're completely unable to work because they laid off so many people you can't fall back to manual operations.

dopylitty··on In Virginia, Data Centers Collide with Zero-Carbon Goals
Nobody ever asks if these data centers are actually providing any value to society. There's just this assumption that ever growing compute capacity is a good thing. Then you get into this sort of induced demand situation where more compute capacity exists so people feel like they can use ever more compute capacity for increasingly pointless things.

But it's time we look at each and every workload and decide if it's really worth increasing our energy and water usage as well as devastating our land for it to be possible. Modeling proteins for healthcare? Sure. Generating useless multimedia content that nobody will ever look at? Probably not. Training yet another glorified autocorrect? Definitely not.

People think when they hoard data in ~the cloud~ or waste enormous amounts of resources on things like LLM training there's no harm but it has real impacts.

dopylitty··on Study finds 268% higher failure rates for Agile software projects
Several years after a project completes when the system is finally sort of working and the end users know what to expect new management will come in at a high enough level and demand everything be rebuilt using their tech stack of choice because they need the resume entries.

Then of course you'll get a buggy second system that is back at square 0 which the business doesn't understand/hates and the developers hate because they're constantly fighting fires.

dopylitty··on Debian's /tmpest in a teapot
I believe I speak for all when I say I keep all my most important files in /tmp and ~/Downloads
dopylitty··on Encryption at Rest: Whose Threat Model Is It Anyway?
In a way when people talk about encryption what they really mean is authorization to access data.

The actual facts of whether or not data are encrypted using some whiz bang algorithm are irrelevant as long as some intermediary is ensuring that the data are only accessible by the intended clients.

Sometimes I wonder if all the focus on encryption is actually wasting cycles that could be spent instead making sure the authorization model is bulletproof.

For instance if a DBMS could ensure that only client A can access client A's data then does it matter if the data are stored encrypted in the DB?

You might say, well if they aren't encrypted then anyone with root can just read the data directly but it may be the case that anyone with root will be able to access the data regardless of whether it's encrypted because they can just pull it from the memory space of the DB engine.

There are a lot of considerations but it does seem like people get caught up in the "how" of encryption because of all the fancy maths and cool sounding algorithms rather than focusing on the "what" they're actually trying to accomplish which is usually "prevent clients from accessing data they shouldn't be able to access".

← PreviousPage 3 of 12Next →