HNHacker News
TopNewBestAskShowJobs

dsuth

465 karma · joined February 28, 2013

submissionscomments
dsuth··on Hackers Remotely Attack a Jeep on the Highway
Ethics isn't relative. You don't get to point to some other perceived problem and say "well that's worse, so what I'm doing is fine in comparison!".

Vulnerabilities in cars is an issue that needs to be fixed. Performing dangerous tests in uncontrolled environments is not a reasonable way to bring about change.

If they HAD caused an accident, how would you go about consoling the victims? "Oh, that sucks for you, but hey maybe your pain/death will convince the car companies to finally do something! Cool right!". It is not acceptable to introduce hazards to the general public to prove a point.

dsuth··on Hackers Remotely Attack a Jeep on the Highway
When it comes to industrial safety, the main question when facing accusation of negligence is "what would a reasonable person have done in that situation". It takes into account things like: - would a reasonable person have identified this feature as having an exploitable vulnerability? - was it reasonably practicable to protect against it?

In this case, the manufacturer could argue that, in their review of the risks associated with their remote connection system, it was not reasonable to expect that it could be compromised and lead to a hazard.

Obviously, now that it has been demonstrated, there will be a much greater expectation that car manufacturers secure their remote access pathways.

dsuth··on Hackers Remotely Attack a Jeep on the Highway
This will change as awareness of these attacks reaches the general public.

According to the article, US politicians are looking at introducing legislation to enforce cybersecurity measures. At that point, it will just be another safety rating that manufacturers can and do use to promote their vehicles.

dsuth··on What Is Code?
Writing software is not what (many) companies do. Companies exist to create things of value for their clients. Software is one aspect of the secondary functions that enhance this value creation.

In the article, the VP worked at a company that sold things on the internet. The things they produced were their primary function; internet platform development is a secondary function, much like marketing, hiring, business development etc etc.

So the theoretical VP's core competency should not have been software dev, or even technology - that's what CTOs and technical leads are for. In fact his core competency probably wasn't product development anymore, if it ever was. He was a manager, and his role was managing resources within the company to optimise their primary function.

Hence the disconnect, and hence why articles like this (and audiences for them) exist.

dsuth··on Chef Grills Steak, Volcano-Style, with Molten Lava
If I had to guess - the astronomical energy requirements to heat stone up to 3000 degF.
dsuth··on Code Review Best Practices
You should not really be arguing about design and architecture in a code review - that should be done in design review.
dsuth··on Integer Overflow Bug in Boeing 787 Dreamliner
It's essentially the v model [1] for software development. It's commonly used in systems engineering and the industries that implement it, so military, avionics, medical, safety engineering etc. I work on industrial safety systems, and would echo the other posts here - it's a requirement of the industry, but it's rarely done well due to the cost to implement, and the difficulty in implementing tools like Doors.

NASA and the U.S. Military have good guides and white papers on it, which you should be able to find online with a bit of digging.

[1] http://en.m.wikipedia.org/wiki/V-Model_(software_development...

dsuth··on Ask HN: I am the dumbest person in the room. What should I do?
First off, a suggestion: leave. It's not worth staying in a toxic environment full stop. On to your questions:

1. Self-confidence is fine, as is the expectation that you will receive mentoring, especially if it has been made known that you are lacking in experience. In your immediate situation, ask open questions after trying to figure it out yourself, and be firm in the knowledge that there is NOT an expectation upon you to know all this stuff already. Some of the best engineers I know ask dumb questions all the time. It is expected, outside your area of expertise, and healthy. As a junior your area of expertise is... minimal.

2. Not in a good company, with strong leadership. Junior personnel are there to be molded and guided. You can expect to be set problems outside your comfort zone, but someone should be stepping in at some point to lend a hand.

3. Absolutely not. In my experience, supposed rock-stars with shitty attitudes are not as good as they think they are. Poor attitude is often a cover for ineptitude and/or severe self-esteem problems. People who are genuinely good are usually willing to help someone who can show that they are motivated, and not wasting their time.

dsuth··on The Go Programming Language by Brian W. Kernighan, Alan Donovan
Great, now I have to learn Go to justify getting this book!
dsuth··on Magic
That's all well and good from the consumers point of view. It doesn't help people who are spending their working hours at a place that cannot support them. It's not about doing things less efficiently, so your 'building with shovels' example is facile. The point is that companies alone cannot be entrusted with the welfare of their employees - this is why minimum wage and works rights / entitlements exist in the first place. The concern is that these companies are using loopholes to skirt the laws, to the detriment of citizens.

I'm sure you'd agree that citizens rights should trump those of consumers who want cheap stuff.

dsuth··on Magic
Poor metrics win again!
dsuth··on Magic
> Any such service would immediately be outcompeted by one which doesn't provide all that - it's trivial to clone an on-demand service, and if you have lower costs you can be cheaper.

In other words, it's the classic 'race to the bottom' problem, which is exactly what the OP is talking about. It's not helpful at a societal level to out-compete each other into the ground.

I don't agree that companies should become safety nets, but there absolutely should be a liveable minimum wage, that companies are expected to adhere to.

dsuth··on Magic
In your home town, it's probably not a big deal. But if you're travelling in random towns, I could definitely see this being useful. Bonus points if you can tie it into a 'what's cool to do around here right now' service. Or 'what's the best craft beer place near here'. That kinda thing.
dsuth··on “Equation Group” ran the most advanced hacking operation ever uncovered
No, I don't believe that handing weapons to people turns them into fundamentalist terrorists, and I don't believe the Iraq war created a group whose modus operandi has been the same since the 1800's.

Take a look at the article I linked above; this form of religious extremism has been a powerful ally to those seeking political power in the Middle East for a long time. Saudi Arabia was built on the back of Wahhabism, which it then tried to subvert into a conservative institution to ensure its rule.

In short, these guys like to play with fire to further their ambitions, and ISIS is the latest explosion. If you reduce ISIS to 'this happened because we did this', then you're missing a whole lot of narrative, not to mention understanding of the situation.

Why do you think they're so well-funded, and well-organised? This is not the result of a corrupt war that decimated Iraq's population, it's an ambitious power play that appears to be getting out of hand (again).

dsuth··on “Equation Group” ran the most advanced hacking operation ever uncovered
> b) We don't need political capital to do it.

The US's unilateral declarations of war have caused a huge amount of tension, globally. To do what you propose would be a log breaking the back of many a diplomatic camel.

Contrary to your opinion, the US is not superman, it's just another country that is currently on top of things. Take a look at what has happened to empires who over-stretched historically. Hint, it's not pretty and they're not around anymore.

dsuth··on “Equation Group” ran the most advanced hacking operation ever uncovered
Do you have links to support this?
dsuth··on “Equation Group” ran the most advanced hacking operation ever uncovered
> There's no point in praising anything the NSA does unless you are perfectly happy with them destroying security for the entire world and spying on everybody at all.

That is a ridiculously absolutist statement. Do you really stand by this? It's not possible that some things the NSA does are good and beneficial, because other aspects of that organisation are questionable?

I'm sorry, but your entire post comes off as very partisan - and quoting Greenwald plays into this as well. Hell, I am left-leaning by nature, but I've had to unfollow him on twitter recently, as he portrays everything in the worst, most dramatic light possible. Don't get caught up on the hate train.

dsuth··on “Equation Group” ran the most advanced hacking operation ever uncovered
1. I don't think the scope of these efforts are based solely around terrorist activity. They are very wide-ranging in scale, and seem to be a natural extension of the USA's foreign policy. In an ideal world it would be nice if neighbours didn't spy on each other, but in the real world, everybody spies.

2. Yes, clearly they do, and also alter the course of some very dangerous activities a la Stuxnet and Iran's nuclear program. Just because it's possible to circumvent these measures, doesn't mean they shouldn't be use either. Firstly, you've made it more difficult for terrorists and other parties to communicate effectively, which is already a win. Secondly, they will of course be updating their methods as well. I doubt very much that what we're seeing here is the be all / end all of NSA's capability. This is implied in the article, where the group hands down certain exploits / technologies for actual implementation, but tends to keep things back. A blow, to be sure, but I doubt we've seen it all yet.

3. ISIS are not the result of the Iraq war. It's very important to understand that ISIS are simply the most recent manifestation of a fundamentalist Islamic sect known as Wahhabism [1]. As convenient as it is to blame them on simple cause and effect, the reality is, as always, far more complex. Essentially this is a group of ultra-fundamentalist muslims, who have for a long time been part of Saudi's political structure. What we are seeing now is a return to their radical roots, backed by disenfranchised and poorly educated muslims across the Middle East. These are people who were left out of the massive oil money influx during Saddam's regime, and are now fighting tooth and nail against any and all transgressors - muslim and Westerners alike.

If anything this makes a case for the NSA's activities, not against it. It's not the US's meddling that caused these issues (although it certainly hasn't helped); these are deeply ingrained philosophies in Middle Eastern culture. I don't know about you, but I'd rather have a very good understanding of their power structure and where they're putting out feelers, than not.

[1] http://www.huffingtonpost.com/alastair-crooke/isis-wahhabism...

dsuth··on Inside a Chinese Bitcoin Mine That's Grossing $1.5M a Month
No, gold miners have incentives to maximise their profit, which is different from maximising their efficiency. Take, for example, the typical refining process for low grade ore[1]. This occurs in a lot of developing countries, and involves chucking all of the ore on the ground, then leaching it with cyanide... which then runs off into the nearest river.

Gold mining and refining can be nasty stuff.

[1] http://en.wikipedia.org/wiki/Gold_cyanidation

dsuth··on “Anthem was the target of a very sophisticated external cyber attack”
Don't lose heart - working in the industrial safety business, the 'just check the boxes' tactic is very familiar. Things are finally coming around after many years (and many, many incidents) though, as companies, and the courts, realise that ticking boxes isn't the be all and end all.

At the moment, it's very easy for companies like Anthem to claim that they were the victim of a 'very sophisticated' cyber attack, when in reality they were probably just wilfully negligent. As understanding seeps into the regulators and law-makers minds, businesses will start to comply with the spirit of security / HIPAA, not just the boxes. In the mean time, the best you can do is continue to advise clearly and calmly why things should be done. If the management doesn't accept your reasoning, at least you have done your due diligence.

dsuth··on A Software Engineer’s Adventures in Learning Mathematics
> Most people don't bother any more, which has lead to a much smaller number of PE-Engineers many of whom are relegated to being mere license-holders who sign drawings for others, who do the actual engineering.

To some extent this happens in Australia as well, although there is a movement both to require things to be signed off by a PE (or CPEng here), and to have those engineers provide documented supervision of the work they sign off on.

> As far as that goes, I've met a number of pedigreed folks who can't engineer their way out of a wet paper bag.

No argument there, certification is never proof positive of competence. I've met very good engineers who aren't Engineers with a capital E, and very bad Engineers who knew enough to fool a test board, but not much more.

The existence of these licensing schemes is far from perfect, but better than nothing IMO. Applying the concept to general purpose software is another discussion entirely!

dsuth··on Ross Ulbricht Convicted of Running Silk Road as Dread Pirate Roberts
I think a lot of people here sympathise with him because geeks have a libertarian bent. We believe that we know what's best for ourselves, and assume that other people do as well.
dsuth··on A Software Engineer’s Adventures in Learning Mathematics
Since we're getting pedantic, once you are employed straight out of uni, you are still not an engineer. You are a graduate, or cadet engineer. Typically its not until you've have several years of experience in an engineering capacity, and have passed your government's regulatory body's requirements, that you are actually an engineer. Usually this involves submitting a number of essays on your work, and then passing an oral review board.
dsuth··on A Software Engineer’s Adventures in Learning Mathematics
There's more to it than that. In most places, the title 'Engineer' is a legal entity. In Australia, signing off on a design as an engineer makes you legally responsible for guaranteeing that it has been correctly designed, and is safe for public use. This includes personal liability in the case that it fails (bridge, software, whatever), and can be shown that it was not designed according to appropriate standards, or what should 'reasonably' have been done.

So basically, don't call yourself an engineer unless you're willing to sign off on something, and be legally bound by it. This implies a strong background in problem solving and structured design processes, to remove as much risk (both personal and to the public) as possible, which is also vital to engineering.

dsuth··on A Software Engineer’s Adventures in Learning Mathematics
Ironically, EE had by far the most maths and maths-related courses of the other degrees, at my Uni. But we were still required to study those ones, along with the civil and chemical engineers.
dsuth··on A Software Engineer’s Adventures in Learning Mathematics
This is an absolutely beautiful book, aesthetically, and does a good job of conveying some of the wonder of mathematics.
dsuth··on A Software Engineer’s Adventures in Learning Mathematics
One doesn't optimise prematurely, and one never discusses it 'out of class'.
dsuth··on A Software Engineer’s Adventures in Learning Mathematics
As an electrical engineer, I like to quip that 99% of the work I do requires only V=IR, or slight variations / derivations thereof.

Of course, it's that remaining 1% that will fuck you if you don't have the maths chops. And this is as a consulting engineer, which arguably uses the least maths. Once you get into actual design or analysis, that number becomes a sliding scale in the other direction very quickly.

dsuth··on Ask HN: I got let go this morning. What should I do next?
Risk vs reward. When you are young, it makes a lot of sense to take risky ventures with potentially huge payoffs, as you tend to have less responsibilities. As you get older, you tend to become naturally more risk averse, and look for more reliable income streams to keep your responsibilities filled.
dsuth··on Ask HN: What to do if you are ridiculously burnt out?
I recently worked on a project similar to this. Based on my experience, these are the things you need to do:

- Take a break for 3 days minimum. Go cold turkey, preferably not in the same city you are in. Just get out of there. It'll feel crazy, like you don't have the time, but trust me: at this point you're endangering your own health and the project. If you're a single point of failure, and it sounds like you are, things could go very pear-shaped if you keep this up and really fry your noggin. Which leads to my next point;

- You need help. You're trying to do too much, and it's just not possible within your apparent timeframe. See if you can get someone else in to help, or get one of the other team members to pick up some slack. It's completely unfair to expect 7 x 10 hour days from you, and anything less from the others. I'd state your reasoning calmly and clearly (after you've had a break; use the time to reflect on your work and where the project is going, trust me it will look different), and let the team know it's just not feasible unless you come back at significantly reduced hours + extended timeframe, or get some else on + extended timeframe to bring them up to speed. These are the realities of where you are, and the sooner you fess up to them (to yourself, and the team), the more chance you will have of salvaging what you've got.

Just my 2c.

← PreviousPage 2 of 10Next →