HNHacker News
TopNewBestAskShowJobs

e_d_e_v

126 karma · joined May 12, 2017

submissionscomments
e_d_e_v··on The Best Cities for Generation Z
Do you live there? Is it that bad?
e_d_e_v··on Developers can't fix bad management (2020)
> which is obviously nonsense.

I think I've observed enough of this sentiment over the years, from some very smart and successful people, to come to the conclusion that, if it is nonsense, it is non-obvious.

> I never diminish anyone

Perhaps you never _intend_ to diminish anyone, but to some, your statements may reasonably appear to be diminishing some cohort.

e_d_e_v··on Paper maps, two-way radios: how firefighting tech is stuck in the past
Well, it seems ridiculous to say that, because there have been 3g microcells (openbsc, for example) forever. It seems bizarre that we couldn't have a switch in every truck that turns it into a mobile microcell for <$100. The backhaul is the problem, because normal microcells are connected to the internet via hardline IP communication . . . . which could be done with modern satellite. The problem is that if you are selling anything to any kind of government agency, you absolutely want them _not_ to be able to use any commodity component like a "cell phone"
e_d_e_v··on The Long-Term Stock Exchange Opens for Business
It seems that perhaps you have some idea of what these perverse outcomes look like. D) seems to be "a company reinvests in its employees (training, etc) and E) is someethign like "a Company rewards employees and stakeholders for long-term company success."

What does the perverse scenario look like for you?

e_d_e_v··on Google starts testing its replacement for third-party cookies
If you are interested in the context and generally unfamiliar with the W3C, maybe these articles will help:

https://www.eff.org/deeplinks/2017/07/amid-unprecedented-con...

https://www.defectivebydesign.org/blog/w3c_sells_out_web_eme...

e_d_e_v··on Tips from Poland on Old-School Zero Waste (2019)
Here is an interesting and recent article which captures some of that motive: https://theintercept.com/2019/10/18/coca-cola-recycling-plas.... The truth is, that these businesses which externalize the costs are also huge interests in the areas where they are prevalent. Coke is synonymous with Georgia, so it is unlikely they will ever have a bottle deposit there. So is Waste Management (NYSE:WM) . Regarding externalities, many people believe that generating disposable things as a practice is fundamentally externalizing costs.
e_d_e_v··on Danish bank launches negative interest rate mortgage
> the lenders will only lend up to 80% of the value of the house (an ordinary bank loan must be used for the remaining fraction)

From olau's explanation, it seems that there is enough money flowing, that more than 80% can be financed (in some way) even if it is not in a single or collateral-backed loan.

e_d_e_v··on Lithium levels in tap water and psychotic experiences in adolescents
If you've never heard of it, not far from Atlanta, there's this: https://en.wikipedia.org/wiki/Lithia_Springs,_Georgia . Interesting history there, about "restorative" lithia water springs.
e_d_e_v··on TLDR Stock Options
In my limited experience, stock options have significant differences from other typical investments in the following ways: 1) You can be prevented from effectively selling stock options prior to a liquidity event 2) Partly due to 1) , stock options are much harder to price than other investments that _could_ be bought and sold freely. 3) Due to the additional requirements as a byproduct of vesting, it is often impossible to pursue options at multiple similar organizations simultaneously. 4) Due to the caveats of even being a shareholder in a company, sometimes there are complications and risks. This is why there is a significant multi-page document to sign when exercising options typically.
e_d_e_v··on Avo: Better X86 Assembly Generation from Go
We actually had Marat come to the Go meetup in Atlanta when he was finishing up his PHD at GT. He had done some preliminary work on SIMD. It was a small meetup ( I think only ~6-7 in attendance) and went over many folks heads, since a lot of people were focused on breaking up Ruby monoliths into Go. SIMD would have been nice, but really we were still reveling in the benefits of getting the hell out of ruby for high-throughput networked services. https://docs.google.com/presentation/d/1MYg8PyhEf0oIvZ9YU2pa...
e_d_e_v··on The Bare Minimum You Should Do to Protect Your Family's Data
Link to archive: http://web.archive.org/web/20181127021739/https://blog.mozil...
e_d_e_v··on Xero reveals the impact of mammoth Amazon Web Services migration
> The forgotten / underestimated cost is the salaries of these people to set things up well in the first place, be on call to fix things when they break, and perform those upgrades in the same way that cloud providers do.

The thing is, you need this equivalently for any cloud provider as well. People who know how to operate and run a cloud account effectively are not a dime a dozen, and given the migration going on now are actually in higher demand than some qualified datacenter operators.

e_d_e_v··on Life as a Nonviolent Psychopath (2014)
A Voigt-Kampff machine?
e_d_e_v··on Issue with TLS-SNI-01 and Shared Hosting Infrastructure
I think IP ownership does = stewardship of all domains using that IP from a DV certificate perspective. The moral of the story is don't point a domain you value at a sketchy host's IP. The list of the things that need to happen to work around poorly managed hosting providers in this scenario is overblown. No one should host anything they think is important on shared hosting. Full stop. That is about as much of a reality as the above statements around SNI, but it is something individuals can actually act upon.
e_d_e_v··on Issue with TLS-SNI-01 and Shared Hosting Infrastructure
Ok, in this scenario, we have a web host with an adversarial entity on its server, that commits a crime.

By the same token, if that web host were hacked and used to obtain a nefarious certificate, would the CA be accountable? It seems to me that, as a customer, if you point your domain (which you must do somehow) at a hosting provider, then any DV issued with that hosting providers' infrastructure should be considered to be the responsibility of the hosting provider and domain owner. I think you and rgbrenner are making perfectly valid points for high-value infrastructure, which has in my view very little to do with these hosting providers. The fact that people can upload certificates at all for domains which they have not proved (to the hosting provider) ownership of is disturbing in and of itself, even if it is quite common.

e_d_e_v··on Issue with TLS-SNI-01 and Shared Hosting Infrastructure
So would a whitelist of providers/ip's be sufficient? Whitelists can be much easier to maintain.
e_d_e_v··on Issue with TLS-SNI-01 and Shared Hosting Infrastructure
I came here to say this. What's more, the spec was agreed upon, in relatively public forums, with a voice from the community. Crappy shared hosting providers are going to mostly ignore their customers and perpetuate insecure scenarios while they continue to bill exorbitant rates that exploit the customers' ignorance or inertia. That has been the case for some time, and will continue to be the case, this is just another symptom.
e_d_e_v··on Issue with TLS-SNI-01 and Shared Hosting Infrastructure
> You're assuming you can scour the internet and find every shared hosting provider affected, and add them to a list. And then you're also going to keep that list updated. That's crazy.. an impossible task.

I think you underestimate the capabilities of modern infosec tooling. Essentially the whole of the internet can be scanned in some ways in durations measured in hours. What is more, some systems are being constantly updated (such a certificate transparency), and there are relatively easy ways to identify bad actors via whitelists and behavioral monitoring. All that being said, if you have a legitimately better idea, voice it in a meaningful way, and I am sure they will at least listen. That was the part _in_their_post_ about "taking community feedback" you must have missed.

e_d_e_v··on Show HN: Encrypt your home-lab server disks using AWS Key Management Service
Came here to say this. Load up on $20 2TB SAS drives in an R510 or something like that, and you'll use a little more power, but also be beating the pants off AWS for cost/GB purposes.
e_d_e_v··on Kata Containers – The speed of containers, the security of VMs
Right, in many cases, small is beautiful! I think that's what contributed so heavily to the massive success of the Xen platform. Is that what you mean?
e_d_e_v··on Kata Containers – The speed of containers, the security of VMs
How is this better than using rkt with an lkvm stage1[1], which also uses the work done by the Clear Containers team? It looks like Kata packages QEMU as well, which seems a bit overkill.

[1]https://coreos.com/rkt/docs/latest/running-kvm-stage1.html

e_d_e_v··on People Who Speed-Listen to Podcasts
I agree that the idea of mindwandering while paying attention is foreign. I think I had a slightly different response than the grandparent, which is to drag the rest of the people in the seats along with me. I am sure there were many people who were bothered by my questions and hand-raising (in 200 person lectures), but sometimes my questions were real questions silently shared by others in the class. I think it isn't uncommon that students treat lectures as very inconvenient 3D video explanations, and many professors are so bored and detached that to veer slightly off course is to disgruntle them significantly. I think of it this way: as the student, paying tuition, your instructor is effectively working for you. If you left, they would not be able to do this part of their job (which some would prefer). If your professor isn't facilitating your task at hand (conveying a holistic understanding of the topic under discussion), then they aren't being effective at what you are paying for them to do, and it might behoove one in such a position to take active corrective action (drag a better explanation of the topic at hand out of the professor). This is all somewhat cavalier as I haven't been in school for a long time, but I feel like it was an approach that helped me, given it is hard for me to multitask as described, and would have helped others whom I have known.
e_d_e_v··on Bank of Canada increases overnight rate target to 1 per cent
You could set the rate for lending new money algorithmically based on a set of other observed statistics of the credit markets. Then it would not be artificial or fiat. The algorithm might be artificial but the rate itself would not. This is not (to my understanding) how it usually works.
e_d_e_v··on Breaking up the Container Monolith
> They literally say that a Dockerfile isn't necessary in the same sentence as the broken link you mention.

They say "It has been four years and we still have to use Dockerfile, which is a horrible version of bash." They say "we still have to use Dockerfile". They _never_ _had_ to use Dockerfile.

e_d_e_v··on Tesla Model S Hits 300k Miles with less than $11k maintenance costs
I mean, if you have a $100,000+ vehicle, you probably also have a couple other $40k-$60k vehicles you can drive for that month, right?
e_d_e_v··on Breaking up the Container Monolith
They complain about Dockerfiles and have a broken link to some project with 288 commits, without even acknowledging that a Dockerfile isn't needed to build a docker image. It is just as easy to build from a regular old disk image, a chroot, etc. I don't blame RedHat for trying to capitalize on the container frenzy, but this doesn't reflect well on them. Also, kind of expected more from the SELinux Coloring Book.
e_d_e_v··on Let's Encrypt is down
Nope.
e_d_e_v··on Let's Encrypt is down
The idea here is that the server can't be scaled up or down. I suggest googling "cattle vs pets". If you know how to make a single process scale horizontally across additional hosts or scale up in alternative datacenters with a chef service notification, I'd pay you money to tell me how.
e_d_e_v··on Let's Encrypt is down
I moved from Caddy to Traefik (https://traefik.io/) several months ago. Granted, nginx has years (decades?) on some of these newer webserver/reverse-proxies, but I have been happy with all the built in niceties of traefik so far (single binary, etc), and haven't really experienced any negatives.
e_d_e_v··on Let's Encrypt is down
This goes wholly against most cattle-not-pets devops philosophy though, right?
Page 1 of 2Next →