HNHacker News
TopNewBestAskShowJobs

ideophobia

172 karma · joined November 2, 2016

submissionscomments
ideophobia··on Collaborative projects/case studies to evaluate data science hires
I would hate this for a number of reasons:

1. You say its not about competing against each other, but I can't fathom how else most people would interpret it. Imagine going to a panel interview, but then finding out the panel was everyone else competing against you for the job. It seems like you would actively be rewarding selfish behavior rather than group success. Any flaw or failure or mishap will immediately lead to finger pointing amongst candidates.

2. If the goal is to measure how well people work in a team, why not have them work with the team that's hiring them? The concept as proposed much less assesses someone's teamwork capability as it does assess someone's resilience against incredibly stressful hiring scenarios.

3. This doesn't sound like something someone could accomplish in a few hours, it sounds like a part-time job. This creates a seemingly biased system that will among many other things: Favor people who do your project while "on the clock" on their current job; Favor people who don't have kids or families or otherwise significant time commitments; Favor people with strong and sometimes overbearing personality traits who often gravitate toward group leader roles.

4. This sounds like a long effort for a hiring process, which can already be too long for some people. Unless the role is someone's dream job, or the compensation measures are bar none, you're going to have to provide significant benefits over your competition to keep candidates engaged, otherwise they'll just seek employment elsewhere that has the same pay, benefits, and role, minus this "trial by combat" hiring process.

5. Even with two groups of 3 candidates each, that's six people ("complete strangers") who are going to need oversight, management, and support to get anything remotely recognizable as a product delivered. How many managers or team leads are willing to take that on in addition to their normal work? How capable are your recruiters/HR people in actually supporting a robust service like this? I suspect the answer to either of those is not promising for most companies.

6. This is the kind of thing you do with your final candidate to assess all the things you're seeking to review, but doing this with a group of candidates all mashed together "thunderdome" style sounds cruel and unusual to me. Overall what you've pitched is an intern program, and its great for that, but I can't see this being functional in a hiring scenario, and I think you may run into legal issues unless you make people sign a bunch of weird documents before they even get a job offer, which could further dismay potential quality candidates.

This would, however, make a great reality show; 4/5 stars, would watch on Hulu.

In my honest opinion, what you're really looking for is a "hackathon" model with hiring capabilities built in.

ideophobia··on ATT services down due to bombing in Nashville
What would you consider the IRA to be in lieu of anti-government?

I don't think I said the IRA were a militia, I drew a conclusion that this incident, which I speculate as being tied to anti government militia groups in the US, shares similarities with other destructive anti government groups seen in Ireland and Spain. I don't think I said those groups were militia groups specifically, and I don't think the comparison is such a stretch since there are other commenters making the exact same leap to the IRA.

My contradictory wording is likely to be a subconscious defense mechanism of sharing my opinion on the internet. I have not claimed any specific knowledge or authority over this event or even in defense of my own speculation here. In full transparency, the only reason I posted was because people were going all in on the "heist" theory, which I find ridiculous.

ideophobia··on ATT services down due to bombing in Nashville
First, this isn't an analysis as much as it is pointless speculation on a Y Combinator message board.

I already listed some things that stood out to me in another comment.

I call out the inauguration because it's literally about to happen? Its the next the largest event in American politics on the calendar. And obviously my assumptions that this is tied to anti government efforts means those involved would likely be stirred up by whatever is currently happening in politics. Everyone's bias creeps into everything they do. Neither of us are immune to that. So calling it out here in such a uselessly rhetorical manner isn't some logical fallacy flag, it's a derailment of the discussion. I'm not even sure what bias you're accusing me of, I guess leftist politics?

ideophobia··on ATT services down due to bombing in Nashville
Yep metcalf is why I'm making the leaps here. Also because metcalf is only one of dozens of similar events that occured throughout the US in the past 8-10 years or so, all similarly targeting infrastructure and energy companies, most of which remain unsolved today.
ideophobia··on ATT services down due to bombing in Nashville
Yea when I first saw the coverage my immediate assumption was a crazy anti-5g person. But reading accounts of the events leading up to the explosion made it sound too well executed for that in my mind. Obviously anyone who does this, regardless of motive, is mentally ill in some capacity.
ideophobia··on ATT services down due to bombing in Nashville
Purely my opinion and speculation here, but I'd say the things that stick out to me are the timing and avoidance of random casualties for one. This is a hallmark used by the IRA and the ETA in Spain to inflict damage upon the government without damaging the people, so to speak. The use of an RV also stands out to me, I don't recall many VBIEDs associated with foreign terrorists using that type of vehicle in the US, while I do recall RVs being a common tool in militia groups for movement, travel, storage, etc. Some other things stuck out to me watching videos of the explosion, but it's hard to say anything definitive until more evidence is released.
ideophobia··on ATT services down due to bombing in Nashville
https://www.washingtonpost.com/national/national-digest-whit...
ideophobia··on ATT services down due to bombing in Nashville
I saw a bunch of headlines recently that said the FBI had decrypted one of the popular secure messaging apps (telegram or signal maybe?), which, bizarrely enough, fits my narrative perfectly. Though I saw other headlines stating that was incorrect reporting.
ideophobia··on ATT services down due to bombing in Nashville
Considering the FBI recently foiled a plot by a group who was planning to "take out" parts of the energy grid, it seems likely from my experience that this is another set of people executing a similar plan targeting telecoms. I imagine there is a high probability of more incidents like this happening between now and the inauguration, meant to target various infrastructure and "big government" components throughout the country. This attack screams anti-government militia with it's technique, and we will see in the following days online chats emerging with all the planning details that will likely include someone that had some degree of "insider information" about the ATT facility.
ideophobia··on National Science Foundation reveals details on foreign-influence investigations
I think you're cherry picking here. There were:

16-20 cases handled by the NSF IG's office "regarding the disclosure of foreign ties" since 2018. "They were considered rule violations, but not criminal activity."

Separately, an undisclosed number of criminal cases were referred to the FBI.

Additionally, in the past two months, "seven universities have also contacted the NSF directly with information on faculty who may have violated rules." This represents another number of undisclosed potential cases. All this comes from "the agency’s first chief of research security strategy and policy," who started the job in March. So this clearly a new problem they're still working to fully grasp.

The NIH, which is a separate entity, stated they'd learned of "150 cases in the past 12 months,” according to their head of extramural research. The NIH has been conducting "an ongoing probe that has swept up 399 scientists since NIH received the first allegation in June 2016." [1]

That 93% mentioned in the original article includes 189 scientists investigated by the NIH, at least 54 of whom have been fired or resigned. The 189 scientists represent "285 active grants" totaling "$164 million." It was also reported that "cases involving the alleged theft of intellectual property or economic espionage, he says, are referred to either the inspector general for NIH’s parent body, the Department of Health and Human Services, or to the Department of Justice (DOJ)." So those cases are likely not included in these stats. Additionally, "Of the 189 scientists flagged in its letters to institutions, 133 of them (70%) failed to disclose a grant from a foreign entity, and 102 failed to disclose their participation in a foreign talent recruitment program, such as China’s Thousand Talents Program. "[2]

It also seems like you're discounting the value, purpose, nature, and impact of the research at play within these incidents, much of which is likely considered critical to the U.S. government. Murder is probably the least likely form of crime to occur where you live, but that doesn't make it a trivial issue. The driver across all of this is the continued perceived power of the US government in its technological supremacy in science and defense. China is fast on our heels, and any opportunity they have to "leap frog" research and development, as was seen with the J-31 Fighter Jet made by China [3], gives a perceived "frenemy" a significant edge that U.S leadership would consider a significant and detrimental risk to American power, politics, and foreign policy.

[1] https://www.sciencemag.org/news/2020/06/has-it-peaked-i-don-...

[2] https://www.sciencemag.org/news/2020/06/fifty-four-scientist...

[3] https://www.reuters.com/article/usa-fighter-hacking/theft-of...

ideophobia··on National Science Foundation reveals details on foreign-influence investigations
According to the DOJ press release from January, "under the terms of Lieber’s three-year Thousand Talents contract, WUT paid Lieber $50,000 USD per month, living expenses of up to 1,000,000 Chinese Yuan (approximately $158,000 USD at the time) and awarded him more than $1.5 million to establish a research lab at WUT." [1]

I suspect they had evidence to indicate he was paid, but couldn't produce specific financial records to prove it without a doubt. In cases like this, the FBI typically goes for the jugular by pursuing espionage charges. This can be difficult because it often requires concrete evidence of financial gain from the foreign entity explicitly for the information provided or actions taken. The mere appearance of financial gain is not enough, they'd want to see the literal check stubs and account statements.

[1] https://www.justice.gov/opa/pr/harvard-university-professor-...

ideophobia··on Show HN: Relanote – a note-taking tool to help you connect the dots
There are so many tools like this popping up, I just wish the creators in this space realized the gap in local implementation. I've worked on numerous teams that would benefit from this type of simplified knowledge management and linking, but having it all stored on someone else's server is a hard pass for the security teams I've been on.
ideophobia··on Police are out of control. It’s time to hit them where it hurts: their budgets
Yea 100% true, I didn't think I suggested otherwise but appreciate the clarification. I only mentioned Trump because he is 1. the current president, and 2. seems to support militarization of police. To me this puts him in an ideal spot to directly rebuke the desired impacts of defunding since the departments could just get their money from UASI (Urban Area Security Initiative) DHS grants, that I'm assuming Trump could get funded with at least some ease.
ideophobia··on Police are out of control. It’s time to hit them where it hurts: their budgets
Like some others I'm a little skeptical of the budget argument. A lot of the equipment that one would typically see employed for a protest or riot response (riot gear, crowd control weapons, armored vehicles) are often obtained via funding from federal Homeland Security and DOJ grants. Hitting the local city/county budget wont impact the militarization argument, and with a president like Trump, I can easily see an increase in federal grants swooping in to offset that, at least partially.

My second concern is that pay for police is often considered not great. Hitting the city/county budget will likely impact salaries, pay increases, health care benefits, vehicle maintenance, and many other areas. Sadly the fastest thing to get cut from municipal agencies is often training, so I'm skeptical we can "defund" the police while simultaneously adding additional training requirements around mental health, de-escalation, etc.

I'm not inherently against the defund argument, particularly when it involves shifting those funds toward more community services that would reduce crime and poverty anyways. It just seems like the problem has less to do with the amount of money police departments actually have and more to do with a lack of oversight on how they're spending it.

ideophobia··on Redditor finds unsecured surveillance cameras seemingly placed by US government
Totally agree, which is why I recommended people contact their local Attorney's General if they live in a state or city where one of these are located.
ideophobia··on Redditor finds unsecured surveillance cameras seemingly placed by US government
A lot of statements and theories about these camera's from all sorts of directions, but they're just pole cams. LEA's have been using pole cams since before I was born (I'm 34). I worked in law enforcement as an analyst and spent some time staring at pole cams that were setup to surveil known drug dealers or criminal gang members. To do one correctly (i.e. legally) you typically need a warrant or a court order, but it can vary I guess based on jurisdiction. They're often deployed as an alternative to human surveillance efforts. They're called pole cams because, well, they get thrown up on telephone poles usually, to take advantage of the power source and ease of view. The surprising part of this isn't the cameras, its the fact that these are wide open on the internet. But honestly police are not IT people, and they often have officers or agents that work specifically as "surveillance techs" who are not IT people either.

I imagine this will draw a ton of ire about privacy and such, and I generally agree, but from my limited experience with them, they aren't wide spread, they're typically temporary, and they're usually purged except for the parts that are relevant to the investigation. These cams appear to be the exception, not the norm. If I saw a cam was sitting on an openly accessible server like this I would have filed a complaint with the agency and the OAG. I don't live in a state where any of the ones listed on Reddit are in, but I would encourage people who do live in a state with one of these cams to notify your OAG about it.

ideophobia··on Show HN: SQL Police Department – Learn SQL while solving crimes
I had one before that, asking about all member data from a darknet list. It seemed logical that select * from members would be the answer based, but I couldn't get it to accept no matter how many times I tried. Kept saying failed to fetch after run. I closed and reopened the browser, tried again, and it worked on the first attempt.
ideophobia··on Show HN: SQL Police Department – Learn SQL while solving crimes
I literally can't get past the first level and I have no idea why.
ideophobia··on L.A. Times to Furlough Workers as Ad Revenue ‘Nearly Eliminated’
A Forbes headline from today reads "Sweden: 22 Scientists Say Coronavirus Strategy Has Failed As Deaths Top 1,000"
ideophobia··on Why do some Chinese steal IP from other nations?
I've never heard this argument before. Generally China steals IP because it's faster and cheaper to build something when you can skip years or decades of R&D. I have trouble swallowing the "shared for the good of all" argument because I can't think of any instances where they actually do that. Instead it appears they just use stolen IP to fast track localized versions of things, or offer competitive products that undercut western prices.

China has for many years been relegated to the role of cheap laborious manufacturing for other countries, only to be stuck buying back the same things they helped build. Much of their IP theft supports plans to move away from that model and toward more localized advanced manufacturing and production. See the "Made in China 2025" plan for a literal blueprint of all the areas they plan on bolstering their economy, and you'll realize they overlap with IP theft instances.

ideophobia··on Hiding in Plain Sight: Tracking/Exposing America’s Most Wanted Using OSINT
This is just my 2 cents, but you've already identified the flaw in Michael's books. I have an older version but in my opinion they're screenshot heavy with a reliance on step by step instructions. Gaining an understanding of the general techniques can certainly be applicable but that's really just the "tradecraft" of OSINT, which I would argue is not where this book shines. I also take issue with Michael because he used to offer a law enforcement only version of his book that contained what he claimed to be techniques not made publicly available nor made available to the impacted service providers, which I feel violates the ethos of responsible disclosure.
ideophobia··on Show HN: Switch from Medium to your own blog
I 100% agree. I don't need a Medium alternative that let's me write blog posts from a cloud hosted Python IDE using a color-coded braille keyboard. I just want an efficient editor, clean interface for readers, and as much help as possible getting my posts in front of people. Medium can check all three in my mind. I'd infinitely prefer to see (and pay for) new and different ways to build ecosystems with which my blog could grow readership and exposure, rather than just more tools for blogging itself.
ideophobia··on Should Disney World Have the Right to Build a Nuclear Power Plant?
First, I think the downvote issue is more you making several statements but not providing supporting evidence, and then challenging people to provide evidence for not agreeing with you, which is whack.

I don't necessarily think nuclear energy on a large scale is more viable or more cost effective than renewables, however, I think you're overstating some of the issues you present. Based on the nuclear industry in the U.S.:

You say "No insurance company in the world will insure a nuclear power plant" which is false. Taken directly from the III website, "Nuclear insurance consists of two tiers. The first tier is private liability insurance coverage made available by a pool of U.S. insurance companies, called American Nuclear Insurers. The second tier is made up of an assessment on nuclear power plant operators... which is supplied by the nuclear power industry as a whole. Under the Price-Anderson Act, all reactor owners are committed to paying their share of any damages that exceed the incident reactor owner’s first tier limit of $375 million—up to $111.9 million per reactor. Since [there] are currently 104 reactors in operation, the amount that would be available in the industry pool to pay claims totals $12.6 billion (2011)."[1] Clearly the insurance arrangement for nuclear power plants is atypical, but they certainly do have coverage (both private and public) and really most everything about nuclear is treated as atypical anyway. Hydro dams have similar insurance issues, despite having nothing to do with the nuclear industry, and can't rely on normal insurance companies for worse-case scenario incidents like total retainment failures.

Building costs for nuclear reactors are certainly high, but they significantly drop after the first reactor is built. Each subsequent reactor added to an existing plant creates immense value at a fraction of the cost. I work for an energy company that owns several nuclear plants. A nuclear operator trainer once told me the "first reactor is built to get all the permits and licenses in order, the second reactor is built to print money." The French, who deeply invested into nuclear, enjoy one of the lowest electricity rates in Europe[2], so I would challenge how how are they managing that? An uncited statement from Wikepedia (my favorite type of statement) suggests insurance only accounts for 0.1% of nuclear costs. The upfront capital costs of nuclear are a given, but the point is that the costs are eaten away over the long-term, as the plant operates for 40, 50, or 60 years. The big financial issue here (i.e. political issue) is that the cost recoupment of nuclear is not designed to give the capital investor an ROI 4-10 years after construction, it's meant to pass on the ROI to the next generation 30 years later. This kills the lender. Nuclear is also a cornered niche market that allows major price gouging and lacks a decent-sized pool of experienced construction experts, which accounts for the construction issues and cost overruns that occur.

Regarding China, there is certainly evidence that their build rate has slowed, but this is less caused by nuclear pricing (otherwise why would they have committed to ((I think) 25 reactors!?) but rather caused by supply chain issues with fuel, building materials, and trained personnel who can operate and maintain the plants.[3]

I'm self-admittedly not a power pricing expert, but I do know that most cost calculations for energy do not account for site maintenance, decommissioning, waste management, and other similar long-term issues, with the exception for nuclear. Nuclear pricing often does have a lot of this built into its pricing models because these are all actions that are (1) highly regulated by the government, (2) legally required to be planned for, (3) will cause a company to incur fines if not managed correctly, and (4) have enough of an impact on price that they front-load the costs into nuclear pricing schemes specifically to avoid balloon pricing issues later in life (long-term lifecycle planning is a staple of nuclear management). So unless you can provide some specifically sourced dollar-to-dollar comparisons of energy commodity prices, I choose not to believe your statement on this. I would personally argue that nuclear is comparable in price to on-land wind generation, and slightly more expensive than solar at the $/kwh level. However, nuclear can produce significantly more power than solar in a similar physical space.

All of this ignores the low-carbon footprint of nuclear, and also assumes that battery and storage technologies that turn "renewables" into "reliables" are present (from my view they're barely here, and they're super expensive). Nuclear fears have also deterred nuclear R&D, which has left the industry slagging behind where it could have been by now. Nuclear also has one of the most fuel-efficient "burns", where the amount of mass required to "burn" to get energy is orders of magnitudes lower than other sources. The amount of waste from nuclear is also significantly lower than amounts generated by other sources, but obviously it can be highly hazardous. Though nobody really ever asked what power companies were doing with all that CO2 they were producing as a byproduct, it literally just floated away, and it was by volume significantly more than the amount of spent nuclear fuel sitting around right now. How much actual realized damage have we caused by CO2 emissions vs radioactive byproducts? I genuinely don't know.

[1] https://www.iii.org/article/insurance-coverage-nuclear-accid... [2] https://en.selectra.info/energy-france/guides/electricity/co... [3] https://www.bloomberg.com/news/articles/2011-01-11/china-sho...

ideophobia··on Ask HN: Pay and Specializations in Security?
This is probably the most narrow and poorly organized list of security specializations I've ever seen. If you literally just google "cyber security specializations" you will see a lot more options and insights available. Fun, prestige, pay, and progression are obviously four very different things, and honestly they are pretty subjective except for maybe pay, but that could be wildly different depending upon the area/region/country. So asking for so many facets of a career with such a poorly developed list of career options is not going to net you very useful answers. Instead, focus on researching and understanding the whole of security better rather than trying to find the most fun high paying prestigious job in the lot.
ideophobia··on Gophish: An open source phishing toolkit
This has always felt like a core unwritten rule for github projects from my experience, and much to my frustration.
ideophobia··on Palantir is using War on Terror tools to track American citizens
We used a variety of 3rd party records databases (think Lexis Nexus, TLO, etc.), government/police databases (NIPR, SIPR, HSIN, NCIC, LEO.gov, etc), internal databases, and state public records systems (think DMV). We only had databases which we owned or had access to. Palantir did not provide any actual data for my department. They did have pre-built connectors for certain data sources, and pre-built attribute models for tagging data, which I assumed were developed for previous customers. But the initial install of Palantir was empty, and only populated with our data sources. To my knowledge Palantir does not provide any data. I actually recall walking into a room and finding 3-4 Palantir engineers doing nothing but migrating data from our old intelligence software into the new Palantir system, mostly by hand.

I can say with 100% certainty that they did not cross-reference our data with other customers, because the software not sending any data back to Palantir was a primary stipulation of our purchase. I was always under the impression that no data was shared across customers, just code, connectors, and best practices. Our installation of Palantir was 100% local, none of the infrastructure sat in a vendor cloud environment or on Palantirs home servers.

ideophobia··on Palantir is using War on Terror tools to track American citizens
I don't specifically remember an option to weed out searching, but I'm reasonably certain there were advanced options that included "does not equal" or "does not contain" type boolean searching. From my experience though, it wasn't common practice to weed out from the start, but rather to start with a general search and slowly narrow it down to the targeted data. A lot of data sources weren't automatically imported, they were more like extended queries. So if I wanted employment records, for example, I had to initiate that as a custom search to query that external system, and pull back the data for the specific individual I was investigating, it was not available in the database by default. But once it was imported and tagged, it was available in any future searches for the remainder of the data retention period.
ideophobia··on Palantir is using War on Terror tools to track American citizens
Not drinking too much. Regular exercise at the gym, three days a week.
ideophobia··on Palantir is using War on Terror tools to track American citizens
This is probably my favorite question, and the reason why I like Palantir, but tell everyone not to bother buying it. The most common "low-tech" tools used by analyst's across the board are IBM's I2 Analyst's Notebook, ArcGIS (or something similar), Excel, various external databases, and Microsoft word. To super dumb-it-down: You use external data bases and excel to collect initial data, you use i2 to visualize it, you use ArcGIS to map it, then you use Word to write a report about it. Palantir does all these things on it's own, so in theory you'd only need to buy and utilize one product vs multiple. The problem is that it does each one fairly sub-par as compared to the more common "low-tech" options. You have to deeply invest in Palantir, and have them build in the customization necessary to really make it shine within your department. Unfortunately that ups the price significantly, so many agencies are buying essentially the off-the-shelf version and then complaining that it doesn't do what they need it to do.
ideophobia··on Palantir is using War on Terror tools to track American citizens
It is. I did not work for palantir though, I worked as an intelligence anaylst in public sector who used Palantir in my job. Palantir does not provide analysts, generally, they just sell the software. The forward deployed engineers help install and instruct, and sometimes they have people come on site to walk through analytical use cases, but generally they don't employ many, if any, actual full-time intelligence analysts, from what I saw.
Page 1 of 2Next →