HNHacker News
TopNewBestAskShowJobs

hvindin

121 karma · joined February 25, 2016

2bd0058e8c294c039c81a3c6a8f10bb0
submissionscomments
hvindin··on Ask HN: Huge enterprise customer wants to see our source code
My 2c as someone who works on the enterprise side of these requests:

There are a couple of reasons reasons we might ask to look at your code:

1. While not a reason to look at your code, instead, if we don't have a valid reason to look or don't have access to technical resources either internal or via external consultants who we are fairly confident could build whatever the software is we are buying given time and resources then we DO NOT WANT TO SEE YOUR IP. This goes as far as shell scripts vendors use for stuff that we don't particularly care about. If they leave them on our boxes we make sure we destroy the data. If the company is worth 50bn then there is it a very small chance their about to make a huge pivot to your particular niche and therefore need your code to solve a problem. The reason companies buy software is because they don't want to pay people to maintain it and in addition they DEFINITELY don't want to get sued for looking at your code. So for no other reason than legal repurcussions you can probably trust them not to do anything sketchy. (Disclaimer: small business units do sometimes go rouge. Make sure youre talking to someone who understands the company wide impacts of fucking this up)

2. If the code is going to be used in sensitive environment (ie. Air gapped networks) we may want to scan for both destructive malware dependencies or just bad code that intentionally or unintentionally might damage systems. Also you would be amazed how many vendors build hooks to call out to the internet in standalone software packages that they "certify" for offline use.

3. If we need to build a bunch of integrations ourselves (ie you would be useless to us in so far as needing to understand legacy core banking systems and the like and therefore are not helpful with your knowledge of the code base, we need someone with knowledge of both code bases at a fairly low level) then depending on the size of the code base we might ask for all of it or just all the external interface implementations. Not the definitions. The actual code.

4. If you are a small company it is not unlikely that we will negotiate a clause which says that if you disappear or all your developers die or whatever, then we are allowed to internally use your code base to build our own stuff since we will end up with dependencies on it and will want to make sure we can still function without you (this is obviously not ideal, we would rather throw money at you to make problems go away, but if you aren't a business any more then we just have to hire people to do it) I actually heard a colleague working at a competing bank in Australia tell me that their agreement with hashicorp gives them ownership of consul enterprise code base for use internally if hashicorp disappears. You just need to make sure your lawyers and on this properly to make sure you clearly define the circumstances in which the large companies expectations of you maintaining the code are no longer met and therefore they can do it if they need to.

5. If we just don't trust you to not be hiding some black magic bullshit behind the scenes. This is usually the result of particularly uninformed sales people making claims that cannot technically be true, and thus out due diligence require that we handle it ourselves. It's also much more likely that we will recommend a bunch of software auditing companies we have used and we trust to audit the code base for us, just so we don't have the liability of your IP in our heads.

6. If we have government financial institution regulations which apply to the thing we want to use your software for and we are required to check of sign off the risk. As an example, an Australian bank running things on cloud platforms that hook back into traditional on prem systems it is mandatory without exception that all data at rest or in flight be encrypted. We trusted a large software company on this and only when we had auditors sniffing traffic over the network did we discover that major data intensive operations relating to backup integrity decrypted everything and then pumped it over the wire between instances using HTTP at which point we where $6m deep in licensing fees so we had a few very difficult conversations about "fix it or fuck off and pay us substantial reparations" because we suddenly needed a lot of technical lawyers (who ate as rare as hens teeth) to explain what had happened to avoid fines that could have cost literally billions.

Summary: there are a bunch of reasons a company might want to see your code. If the person you are talking to is speaking on behalf of the whole organisation (ie. They understand broader business implications of doing anything shady) then you're almost definitely safe. If your a bit on the fence about the whole thing, get a third party auditor in, but the request itself is pretty reasonable.

hvindin··on The cargo cult of versioning
There is one key part of this article which I absolutely support wholeheartedly (the rest of the article is kind of moot if we understand that version management is non trivial)

When a major change is made to something, as in a breaking change, where you as the developer are making the conscious decision that you will cause other people's shit to break if they keep pulling "latest" I absolutely think that the major version number should just be part of the naming scheme, not the versioning scheme.

We've actually implemented a similar system where I'm currently working. For versioning APIs, if you want to bump a major version then we force developers to start working with a whole new git repository, a whole new pipeline etc. If we have to patch some defect fix back to the old version, we can just cherry pick across forks, but most of the time we want to manage the life cycle of two bits of development that no longer do the same thing as being exactly that: bits of developed code that do different things

hvindin··on A Test of Police Body Cameras Defies Expectations
I think the article does, to some extent, address this when it says that the situations that we would most hope for modification in police behaviour are also likely to be the situations where the officer is under significant stress and has defaulted to their most primal response. So while I take your point that police don't think they are doing anything wrong when they misbehave, I think it is more correct to say that police aren't considering moderating their behaviour when they are in those particular situations.
hvindin··on DIY recipes to make your own expensive pharma drugs
Probably should have thought about it a bit more before I put my first point first.

The major problem I have is with the implication that you can make your own drugs at home and it's safe, secondarily it's pretty concerning that there's actually a reader base for this information due to the countries healthcare system.

hvindin··on DIY recipes to make your own expensive pharma drugs
Sorry, I didn't mean to offend. I definitely don't think that the individual citizens of America are in any way inferior to those of any other country, nor do I think that collectively Americans are to blame for their current predicament.

While I don't really understand your point about showing gratitude. 1. Many of the major medical breakthroughs in recent history have nothing to do with "America", sure some of them might have happened there but that's hardly their defining factor. 2. Where in my comment did I imply that it was not disgraceful that American people where not enjoying the drugs we have in the modern world?

In terms of the whole homosexuality thing, no shit. It's also a problem that we are absolutely ruining the lives of the aboriginal population by throwing up barriers to progression and education at every turn and just treating them like second class citizens at best. Even worse that the way we treat our native citizens is how we treat refugees who we send to an unregulated island so we can beat the shit out of them and rape their children.

But just because there are parts of Australia that make me worry for this cesspit of inhumane bullshit, doesn't mean I can't also find it appalling that as a nation it seems impossible that america can't stop killing it's own citizens. Lethal weapons are sold at the local shopping centre, you can't get medical care even if you need it and God help you if your not white, you basically just need to factor "will get shot by police at some point" into your life plan.

Just because two countries are fucked up doesn't mean that you can't notice the stuff about another country and makes it fucked up alongside your own.

hvindin··on DIY recipes to make your own expensive pharma drugs
As an Australian, i.e. someone who lives in a country which doesn't assume that being poor is a good enough reason for someone to be allowed to die. As well as the brother of a scientist who often runs experiments involving the synthesis of new drugs, I had a torrent of extreme reactions to seeing that this site exists.

1. My immediate reaction was holy shit no, if a situation exists where your countrymen are trying to hack together potentially lethal drugs and medical procedures because you don't have facilities in place to save them, then whatever political decisions you are making, whatever trade deals you are signing, whatever wars you are fighting: stop ALL OF THAT SHIT AND FIX THIS FIRST.

2. Oh my god what a terrible way to die. I understand that this site is probably well-intentioned. I know that for someone with access to a pharmaceutical lab and who has experience in the small-scale manufacture of drugs intended for consumption by living creatures (experiments) including humans (clinical trials) it may make sense that we could just synthesise our own drugs. But failing to recognise that there are very real and very likely scenarios where people will die because you (or someone with your expertise) are not on hand to help them immediately if they fuck up.

I can't help but think that the existence of this site is a net harm to the world, there's just no way the risk calculation is the same between a chemical engineer and a regular chap who needs medication as to the possibility of just making it at home. Making it seem like this is a thing you think that you should do just sounds like bad advice.

But on the other hand, I'm so appalled by the ability of America as a nation to do terrible things such as let its citizens die from treatable illness, that this kind of makes sense. It just feels like the wrong problem to be solving.

I mean, how about focusing on fixing the broken medical system, avoiding killing all the people who aren't white and making it just a little harder for insane people to get guns. While you're at it, you might even want to try and drop "racist as shit" from the assumptions of the rest of the world about your country.

hvindin··on Sickness absence associated with shared and open-plan offices (2011)
It's smallish things like this which make me realise how lucky I am not to live in America.

In this particular case though, possibly just how lucky I am to live in Australia. Here it's either just common practice at most companies, or possibly required by law, but everywhere I've seen the leave policies provides 52 weeks a year of sick/carers leave.

Usually this is broken up into ~20 days of leave where one isn't really required to provide any justification beyond "I felt bad that day" and beyond that a doctors certificate may be required.

But that's always entirely separate to annual leave.

hvindin··on Post a boarding pass on Facebook, get your account stolen
But usually when people get to the front of the line they still present both documents, the fact that 9/10 times the passport is ignored just makes it a judgement call by the ground staff.

Having spent some time working on staff management systems in airports I can say with some confidence that (at least in australia) most of the ground staff will immediately flag someone not at least offering their passport, and/or trying to talk their way out of needing to do so as sus.

And let's not forget that if your entire plan was to get on a plane under a fake name, it's a hell of a risk to just hope that you end up in a situation where some chap is squiggling on boarding passes.

hvindin··on What if jobs are not the solution but the problem?
Something thats probably worth pointing out, deciding that you are going to go into a specialty in criminal enterprise doesnt make you wealthy. The same amount of hard work is required to become a drug dealer and make a living as is required to do other jobs and make as adequate living, actually it requires a lot more work.

Obviously this is not relevant to the entire article, but I would suggest doing something like reading freakonomics before making what are imperically wrong statements.

Not that I dissagree entirely with the overall argument made by the article. I just feel like some of the examples could have been researched a little more.

hvindin··on Docker in Production: A History of Failure
To provide some experience I have as someone working for IBM implementing a solution which leverages docker at a large bank - no one I work with is naive enough to think that they can get away with containerising their current systems of record. Where we are significantly leveraging docker is on in-house bare metal clouds that we are using to build out middleware services.

We build all our images on top of rhel containers that have undergone hardening to meet internal + regulatory compliance. The end result is that to some extent we can say to developers "dont worry about getting your applications production ready right away, just write reasonably stable code quickly and we'll strip out all the stuff we dont trust you to do and handle it at the infrastructure level".

End result is that we can start to eliminate some of the unsuitable uses for traditional middleware systems like our datapower infrastructure that, while being great for specific use cases, is usually to difficult to work with for your average front end developer who doesnt give a damn about soap headers and broker clusters.

As far as our architecture leads are concerned, and I'm inclined to agree, docker is a great packaging format for developer outputs because it puts everything you need to run an application naked (ie no complex logging, HA, Networking etc.) Into a single versionable, reviewable, very much disposable asset. But it is not, and should not, be a replacement for proper systems of record that require any measure of stability.

hvindin··on The Toronto Raptors are using IBM’s Watson in the draft
As someone who works for IBM I'd have to disagree with you there. No one has ever told me we are a huge cloud company, I mean obviously I've been told we're investing buckets of money in cloud technologies and that we have made it a key strategy point to focus on growth in the area, but not once has anyone even intimated that we 'are [a] huge cloud company'.

What IBM is, realistically, is a ridiculously large (and I actually mean ridiculous in the sense of 'how are they not under more anti-trust investigations because they seriously own roughly everything") company with an unbelievably large number of very vert wealthy clients who are scared beyond reason of losing their market share if they don't start using <Insert "new" technology here> so internally everything that happens and looks like a publicity stunt is usually met with a response of "Well no shit we could do that. Why the hell didn't our marketing team point out that we had that capability in the 90's when it would have been impressive"

A lot of the Watson hype seems to actually be because a lot of the companies who traditionally would say 'hm, I dunno about this whole analytics thing. Shouldnt we just stick to spreadsheets and man hours' now have a named thing they can buy that really just covers up that they are actually just investing in a platform with some hadoop clustering and some racks full of P8s (obviously theres a little more to it than that).

The fact that watson can do seemingly cool stuff is actually just a nice way of saying 'anyone can do cool stuff if they invest a bit of cash in technologies that have been around for ages but large companies now have a small window where they can start investing in these technologies and they even get to act like they are an early adopter, of course sans-risk'

I find it amusing that our sales pitch to a rugby team in australia to sell them analytics tools and services failed about 4 years ago, so we gave it to them for free then said we would tell them who the next 10 players to get injured would be and how they would be injured. After the predictions were exactly correct at about injury 6 they were suddenly very interested in buying the stuff. Interestingly, if we sold the same thing now it wouldn't be an analytics platform, we would probably use watson (read: not rebuild that thing, just use the existing stuff because its easier) and it would be marketed as a "watson solution".

hvindin··on Did I just win?
Not entirely true, I work at a bank and many of the most critical core banking systems don't have an admin account at all. Yes there are accounts that perform critical system functions, but they dont have passwords and can't be logged on to interactively.

We make changes to those systems by setting up very intricate situations where the changes are all in the right place at the right time and a bunch of approvals sytems have basically got flags indicarinf changes can be made. Then the changes get included as part of the systems normal operations, as in once it gets a bunch of signals for vaious places it pulls in whatever is in a specific clearcase stream.

Obviously the above description is a huge over simplification, but the only way to social engineer that is if you can convince multiple system managers to approve a change which has already been promoted by tech leads in various departments.

Admittedly it makes "hot"fixes a god damn nightmare because 'oh shit, no one noticed a spelling error in the legal disclaimer sent to business customers? Lets get all 150 technical sign offs again... And get me the number of that lawyer who said that we had to include that!'

hvindin··on Namecheap live chat social engineering leads to loss of 2 VPS
I recently changed my phone support password at work to "aaah, f*, I'm not sure is it.." after listening to all my previous support calls and realising that was what I answered with 9/10 times. I suspect its only a matter of time before someone else accidentally guesses it. Its only for my regular user account, for my admin accounts I need to get another domain admin to reset the password, there is no process for anyone to exploit, just an audit every month.
hvindin··on Follow the money: Apple vs. the FBI
While you are empirically correct that banks don't earn the significant amounts of money just from individual savings accounts, it would be logically flawed to assume that savings accounts (a means of collecting temporary use of additional funds relatively cheaply) are designed to be profitable. It's an interesting market where the product you are harvesting is the one which is used to buy that product.

The banks that you or I recognise as every day banks almost certainly don't make their money on corporate loans. The margins aren't high enough. The only point I would agree with from this article is that when companies become large enough they tend towards becoming banks.

The nuance here is that a traditional bank makes the bulk of its money by having control of the bulk of your money so they can sell stuff like homeloans, as you mentioned with the housing market, which aren't glamorous, but do make bucket loads of money.

An organisation that didnt start out as a purely financially focused investment/risk management machine but which does become, technically, a bank is an organisation which grows large enough that it needs to give some money back to fund all the people buying its wares. As an example, look at IBM - who do you think loans money to companies who pay billions for an IBM project? Often its IBMs Global Financial Services business. They can give you a killer rate because everything you borrow is used to fund another part of the business and can be fed back into the cycle.

The more interesting situation with Apple is that they, almost exclusively, sell consumer goods. So they are stuck with customers who probably can't afford to, and aren't at all motivated to, take out large loans to pay for their new gadget (Hence apple partnerships with enterprises ie. the aforementioned IBM as they struggle to get out of the consumer goods market. Note - this is not to imply that IBM is doing better than apple, they just have much wealthier customers)

The only thing that I'm relatively sure about is that apple isn't seeking to trump mastercard and visa, as the article seems to suggest, nor to become the bank of the people, because both options make less financial sense than continuing to be insanely profitable as technical designers and manufacturers in a cross-industry market such as technology.

hvindin··on NPM and Left-Pad: Have We Forgotten How to Program?
I'll admit I'm at least a little tarnished in my practices due to time spent in enterprises where external dependencies require 6 manager sign offs and a security team exemption, but if this were the case that you didnt want updates to the package, just that one version that worked -

If its just a few lines of code, just copy the thing into your code base? throw a comment in saying "came from xxxx" so anyone reading your code knows that it might look like a overly generic function because it is.

hvindin··on Ask HN: How much do you make at Amazon? Here is how much I make at Amazon
It's odd, I have no doubt that you have had these issues, I was talking to a guy who worked for the same company as me, with the same client, just the other day. His entire team where just told they were being made redundant and the company who would be doing the work would be interviewing them all. The new company told everyone to send them either their current pay slip (with all benefits etc) OR their current pay rate (its just a different document with less detail) + the salary they would accept in the new company. So I know that this sort of thing happens and no one was that shocked.

But I've never encountered the issue, I would be interested to see an analysis of what sort of jobs people who deal with dodgy HR reps are applying for (or what route to entry they are taken) vs the jobs people with positive experiences of the hiring process are going for.

I feel like it can't only be luck, presumably there would be some trends (ie. people who respond to advertisements are offered X% against people who are recommended through word of mouth for the same job)

hvindin··on Twitter to keep 140-character limit, CEO says
I have a sneaking suspicion that the ability to connect tweets to get something resembling a longer tweet is probably considered to be a bit of a cop out.

The reasoning behind retaining the 140 character limit seems to be that if it's longer than 140 characters - post it elsewhere, then link to it if you want it on your feed. Trying to cater to the market where you can create messages to your social network that are somewhat untargeted seems like it would make twitter less able to offer the 'of the moment brevity' they want, and really would result in them being a partially implemented feature that already exists on other social media platforms.

hvindin··on The Pentagon’s procurement system is so broken they are calling on Watson
But Siri and Cortana are sold to consumers, I'm happy with my day to day life being made up of over-simplifications because, generally, if those things don't work it doesn't really matter.

However, in large organizations, dealing with fairly critical things, it just seems like over-simplifying the solution is a recipe for disaster.

That's not to say that Watson-type solutions have no place in the world. The recent stuff re: health and diagnostics - awesome. It's complexity you can't fix because people are living organisms so you just need to drag in the data and essentially evaluate your best guess.

But where companies are using Watson to mask their needlessly complex processes or, as an example, banks are using Watson to decipher their needlessly complex loan schemes and agreement terms, those are problems that will only get harder to solve if you don't deal with the cause of the complexity (something within the scope of their control) as soon as possible.

That being said, it's probably good business for IBM because if your multi-billion dollar investment in IBM hardware is insufficient to deal with the mess of policy that has grown unchecked over the years, masked by a more friendly interface, then you can always buy more servers and more hosting...

hvindin··on The Pentagon’s procurement system is so broken they are calling on Watson
Every time I see an article which talks about "Watson" as an individual solution to a problem I find myself wondering what the people paying for it all think that "Watson" is?

Realistically its like 10+ racks filled with POWER systems loaded up with terabytes of RAM running SUSE Linux using Apache Hadoop for distributed computing, then some IBM Proprietary software solutions + a few other open bits and pieces (ie Apache UIMA) cobbled together to get something which behaves as though it understands natural language.

Honestly if you put most data-centric systems on a platform with dozens, if not hundreds, of POWER CPUs with 8-16 cores a piece and 4 threads/core and then put the entire data store into RAM so you could get at it quickly, I suspect that you could fool most people into thinking there was intelligence behind it, not just raw computing power.

hvindin··on Data is a Toxic Asset
Buy the concept of taking data offline or to another network applies to this.

For example, while banks are required to keep tons of data for legal reason, the ones I've worked with have procedures where, for example, tellers are required to shred everything and send it for incineration. Then, the digital copies, once they can only be required if theres legal compulsion going on (ie after x number of years), are transfered by batch jobs which encrypt everything with a key generated by a CA that is offline most of the time, to a tape library which is only online for batch writes and can only be brought online manually by physically going into the data center. Then, after a little more time, but still within legally required reporting periods, the tapes are moved into a warehouse which very much resembles a bank vault.

And as soon as theres a reason that the data isnt mandatorily kept, the tapes are destroyed.

Honestly the security around those tapes is higher than bricks of cash, and they're destroyed even more readily.

hvindin··on Kofi Annan on Why It's Time to Legalize Drugs
While I enjoy the concept that heroin might be in some way similar to nocotine beyond both of the substances being tangible psychoactive, it does frighten me that this is actually an opinion people legitimately have.

Given that when the supply chain of heroin is disrupted the most statistically significant cause of eratic behaviour in users is that it just hurts so much I suspect its a little different to nicotine.

If you are interested in understanding drivers of addiction I would recommend looking at cases where people are forced into withdrawals.

For example: http://www.sciencedirect.com/science/article/pii/S0955395915...

Although I recall another article published ages ago (early 80s) which had an interesting economic analysis of the elasticity of heroin prices, to paraphrase, resulting from what is essentially inflicting pain on users until they will pay yur asking price.

I would love someone to draw the connections to nictonine withdrawals

hvindin··on Apple Is Said to Be Working on an iPhone Even It Can’t Hack
I'm not a lawyer so obviously I'm not exhaustively well read on the law but in the case that All Writs did allow any action to be demanded to help with an investigation it would still require there to be an investigation in the first place.

To preemptively demand a back door is almost akin to guilty until proven innocent, youre assuming that there will be an investigation in the future where a governments ability to hack a device is required.

← PreviousPage 2 of 2