HNHacker News
TopNewBestAskShowJobs

insertcredit

178 karma · joined July 23, 2018

Traveling the world. Homebase Berlin.
submissionscomments
insertcredit··on Hexyl: A command-line hex viewer
It's not written in Rust.
insertcredit··on Thank u, next
If you asked your engineer peers how they would feel if you were paid an equivalent salary, I am confident some of them would admit that they would not like it. Privately, I think most of them would definitely not like it but would probably refrain from publicly admitting as much.

Which to me is the crux of the matter. If I was your manager at Mozilla and looking to maintain team cohesion and minimize talent loss, engineers would always come first. In my experience it is very common for managers with an engineering background to think that anyone can be a technical writer. Same for evangelizers. People do it for free if they like the technology that they are using. These are not strong bargaining foundations.

insertcredit··on Thank u, next
Nobody said anything about what Steve should have been doing. Given that money is the core issue in his post and he's mentioned sweet SV dollars in this thread, it doesn't hurt to note the prevailing attitude these days which (largely) favors engineering and 'show me the code'. Good engineers have tremendous leverage and can command extremely good salaries. Evangelizers not really and as I said they _are_ often looked down upon by engineers.

Looking at Steve's 177 'source' repositories @ Github and disregarding documentation and presentations, there is absolutely nothing that can be described as substantial engineering. Throwaway code, small sample projects and tiny tutorials and more often than not, skeletons and incomplete beginnings. Yes the Rust book is excellent but at the end of the day, nobody who is in the position to give out SV $$ really cares. Had Steve spent his years using Rust to solve hard problems, he'd have recruiters banging on his door 24/7 but the fact is that documentation and hype on HN and reddit is not a good recipe for a solid career.

I don't know Steve personally and I have no dog in the Rust race, merely expressing what I have personally experienced working in SV for over a decade.

insertcredit··on Deriving Traits in Rust with Procedural Macros
Rust is morphing into a complexity beast that rivals C++. When the cognitive load require to read and write Rust code far exceeds that required of other, more popular languages, the future does not look rosy.
insertcredit··on IQ is largely a pseudoscientific swindle
Given that not even Taleb disputes IQ effectiveness on the left-end of the spectrum, meaning the low end, letting waves of refugees in from sub-saharan Africa (average IQ below 70 [1][2]) would definitely be a net loss for a first-world country.

His first sentence in linked article starts with: '“IQ” is a stale test meant to measure mental capacity but in fact mostly measures extreme unintelligence'. Why would any developed country want hordes of "extremely unintelligent" immigrants?

Which is why there exist countries with extremely harsh immigration policies that are first-order eugenic. Singapore is one of them.

[1] There are many studies that report similar values, https://www.sciencedirect.com/science/article/pii/S016028960...

[2] Anecdotal but informative: https://undark.org/article/in-south-africa-decolonizing-math...

insertcredit··on From Buffer Overflow to JIT-Spray-ROP [pdf]
There is a lot of unnecessary fluff in this piece. Suggestion to the author: Focus your writing on the main points and try not to dilute them. The majority of what you have written here drops the SnR significantly and takes away from what you are trying to say. When I do this, I am left with essentially a small paragraph of useful information which can be further condensed into "You can spray gadgets".
insertcredit··on Show HN: Next Browser native on Linux
I saw your post at lisp.reddit.com today and there was a redditor there that brought forth webkit security concerns that IMV you did not properly address.

Thread is here (https://old.reddit.com/r/lisp/comments/a3b8m0/browsing_with_...)

I am an ex-Googler and I happen to know the effort that the Google security team expended when designing the Chrome security model was quite significant. We would all like more competition in the browser arena but running webkit without any security protections like Next browser does is putting yourself at risk, unnecessarily. I urge you to spend some time understanding the security implications of what you are doing.

insertcredit··on Not Lisp again (2009)
Lisp always catered to people with a certain state of mind. It was never a language positioned for popular appeal, and by that I mean the masses of 9-5 "brogrammers" we have today. Looking at how many people fall in love (or not) with SICP, today, and the reasons they give validates this line of reasoning. Lisp and SICP are meant for inquisitive thinkers and hackers who are willing to go DEEP. If you can superficially dismiss Lisp (and all the geniuses that worked with and improved it over the years) in the manner that you do, then certainly, Lisp is clearly not for you. You are not an artist. You are most definitely not a hacker.

You seem to think that popularity should be the prime consideration when it comes to programming language design. This is what gave us PHP and Javascript. I dare say that the people that use Lisp today (and there are plenty of those) do so because nothing else will be as good to them. They love the language. I've known people who moved jobs and got less money in order to work with Lisp. What does that say about the language?

insertcredit··on Not Lisp again (2009)
There is no difference between Scheme and Common Lisp when it comes to parentheses and beauty. Everything you mention (simplicity, regularity, few basic principles) apply just the same to Common Lisp. The differences between the two are mostly standard library related (irrelevant to matters of beauty) and lisp-1 vs lisp-2 (no clear winner in terms of beauty I would say).
insertcredit··on Not Lisp again (2009)
Most "other" languages don't have Lisp-like macros, so I'm not sure what you are talking about here.

I don't think Lisp is much more difficult to like, on the contrary, out of all the languages I know well (C, C++, Python, Java, Common Lisp) not only do I find CL _by far_ the easiest to write but also that it puts me in a state of flow (= unparalleled mental clarity, focus and productivity) which doesn't easily happen with the others.

Credentials: I spent close to 10 years writing C++ at Google.

I certainly think that Lisp is very different to most popular programming languages today and that difference is immediately obvious. This makes it very easy for people who do not like leaving their comfort zone to dismiss Lisp simply because it "feels" too strange to what they're already familiar with.

insertcredit··on Systemd is bad parsing
Not quite true: There would not exist exploitable buffer overflows if that was the case.
insertcredit··on Former Googlers on how they knew it was time to quit
I worked at Google for close to 10 years. I resigned when I had made enough money to retire comfortably (for the next 40 years) in a European city.

The first two years were enjoyable but then it started going downhill, fast. Some close friends and co-workers had major implosions on the job and I was burned out. Once I realized that Google would suck me dry if I let it and that reality was completely different to the expectations I had going in, I found ways to drastically reduce the number of hours I actually worked and spent the rest (company time) doing things that contributed to my self-development (side projects and reading books, mostly).

I spent the last ~5 years doing no more than two hours of actual work per day. Needless to say, these were some of the best, most carefree years of my life. My mind rebounded and it felt great knowing that I was screwing the company that only viewed me as a commodity whilst getting paid top dollar. I am pretty sure I wasn't the only one doing it, either.

insertcredit··on Ask HN: What are some of the best technical talks you've heard?
If that's the best technical talk you've ever seen, I have to feel sorry for you. Cantrill may rant all he wants about Oracle but he's not exactly doing better, with all the peddling of node.js to the masses. It is rare for me to see someone come up with so much bullshit in one talk: https://vimeo.com/230142234

Since I don't want to end with a negative note, here is a personal favorite as far as best technical talks go:

https://tinyurl.com/hzpccxj

insertcredit··on We can no longer leave online security to the market
I'm stating the following since I've seen you appeal to your work history and say "trust me, I've been in this for a long time" far too many times to give you a pass here. There are plenty of tptacek posts on HN, where it is crystal clear to anyone with similar years in the domain as yours that you're either entirely wrong or deliberately misleading. You need to make a proper argument if you want to convince me.

There were computers, telecommunications, dial-up modems, X.25 and private networks in the 90s but the degree of cohesion, sublimation and intra-connectivity wasn't anywhere close to what we have today. Consequently, the actor domain looked very different and concepts such as cyberwarfare weren't even in the public eye. Morris worm vs NotPetya. Sure, barrier to entry was very low compared to now. But, as Dan Geer has repeatedly shown, risk has grown tremendously even if the field has gotten a lot harder. You don't think that completely disproves you?

insertcredit··on We can no longer leave online security to the market
It's clear to me that this is nowhere near accurate and I'm not sure why you insist on making these sort of claims.

One only has to look at self-driving cars to disprove you.

Dan Geer also entirely disagrees with what you wrote [1] [2] and you're no Dan Geer, sorry to say..

[1] http://geer.tinho.net/geer.indiana.19x17.txt

[2] http://geer.tinho.net/geer.uncc.5x16.txt

insertcredit··on We can no longer leave online security to the market
You don't agree at all that increasingly critical parts of society have been subsumed by the Internet during the last _28_ years? What planet are you living on?

Please elaborate because I don't see how you can even remotely defend what you wrote.

insertcredit··on Georgia Tech Creates Cybersecurity Master’s Degree Online for Less Than $10k
Having done 25 myself, I was willing to get hired as an employee doing reveng a long time ago. But that was before 2010 and you're probably right today. Good reverse engineers can print money and don't have to work for pointy hair bosses. Good point.
insertcredit··on Georgia Tech Creates Cybersecurity Master’s Degree Online for Less Than $10k
What I'm referring to is the core of cybersecurity:

Reverse engineering & vulnerability research.

insertcredit··on Georgia Tech Creates Cybersecurity Master’s Degree Online for Less Than $10k
I'm not currently in a position to hire people, see my previous reply to danesparza.

Doing these and other similar challenges and reading and understanding phrack articles would give you a solid foundation to start doing reverse engineering and vulnerability research and reap the rewards that come from successfully doing so.

insertcredit··on Georgia Tech Creates Cybersecurity Master’s Degree Online for Less Than $10k
I'm not currently in a position to hire people, but having served in that role in the past, I would given the opportunity not hesitate to follow through with what I said (practical concerns aside such as figuring out if someone went through the challenges on his own).

So my comment was mostly trying to illustrate that the skills one learns by going through these kind of challenges are extremely useful in practice and the skills one learns by doing an Msc of the sort advertised here pretty much completely useless, assuming one wants to do reverse engineering and vulnerability research and not just push paper, point at his Master's and call himself a "security expert".

insertcredit··on Georgia Tech Creates Cybersecurity Master’s Degree Online for Less Than $10k
This is a complete waste of time and money with the usual bullshit material taught by people who don't really have a clue and completely-out-of-touch-with-reality academic focus (write a buffer overflow!).

If you really want to learn invaluable cybersecurity skills, start playing wargames. I suggest (1) which is one of the best. If you manage to reach level 25 on your own, then you are elite and the knowledge you gained doing so is not only extremely valuable but something you can be proud of.

(Sidenote: I would hire anyone who reached vortex level 25 on the spot and pay him a six figure salary, without looking at any of his other qualifications/degrees/past experience)

Additionally, read every single phrack (2) magazine from the past 20 years and try to understand most of the material within.

(1) http://overthewire.org/wargames/vortex/

(2) http://phrack.com

insertcredit··on Compiling Lambda Calculus
If you're not making any money from selling your books, why not make them available for free? They will reach a much wider audience.
insertcredit··on Jason's Machine Learning 101
Can't download or print (chrome/safari). Working for anyone else?
insertcredit··on What was it like to be a software engineer at NeXT?
I was 40 years old and had enough money to comfortably retire from the daily grind. This was something I always wanted to do.
insertcredit··on What was it like to be a software engineer at NeXT?
I was reading on the computer or, away from my desk. I don't want to spell out exactly what I did, in terms of management, but I'm certain I wasn't the only one doing it.

When you're a software engineer, you get a lot of leeway in terms of expected behavior. Especially in silicon valley companies the size of Google, it's easy enough to seem like you're working your ass off, while doing your own thing on the side. It's all about cultivating an image in the beginning and projecting it. People are mostly busy with their own anxieties and career concerns to scrutinize you.

insertcredit··on What was it like to be a software engineer at NeXT?
Why not do both? I got to work on things I really cared about and got to keep a high salaried job and all the perks that come with it (I quit on my terms, not theirs, once I had enough to retire).

My employer may not have cared about the things I worked on but that's fair game. After all they hired me and they were happy to have me there for years. I don't see the 'extreme' in what I did, more like common sense or self-optimization.

insertcredit··on What was it like to be a software engineer at NeXT?
When I was working at Google (now retired living in Germany), I spent my first year there working insane hours and pushing myself beyond self-imposed limits. However, after dealing with burnout and having some close friends implode on the job, I soon realized that I was nothing more than a cog in a machine that would, if I let it, chew me up and spit me out.

I started gradually reducing the number of hours I worked for 'real' until, a few years later, I found myself working for two hours a day, choosing to spend the rest on things that contributed to my sanity and self-development (on company time). To fill the gap, I would work on my own software projects, socialize with co-workers, do research on things I found interesting and read books.

Needless to say, nobody noticed. I kept this up for a number of years and then I quit. Looking back on it now, those were some of the best, most carefree years of my life. There is nothing like getting paid a competitive six figure salary to mostly do the things you enjoy and not care one iota about corporate management structures.

← PreviousPage 2 of 2