HNHacker News
TopNewBestAskShowJobs

jauer

2,164 karma · joined March 5, 2009

MTS on infra sec at some AI lab.

Former principle engineer working at the intersection of Network and Security infra at FB/Meta.

Former SysAdmin at a small dialup/wireless/fiber/colo ISP in the US Midwest. Full stack where the stack went from datacenter power and cooling, fiber in the ground, to BGP, database perf tuning, and dev on backoffice/accounting/billing systems.

https://jade.wtf / https://github.com/jda/ / jade@jade.wtf

[ my public key: https://keybase.io/jda; my proof: https://keybase.io/jda/sigs/-MAdRvws8lprdF6WKGMur4GHTbctlG5hOtJvctF_rWg ]

submissionscomments
jauer··on OpenAI agents carried out an undisclosed attack on RubyGems
I don't think you are missing anything. There's zero actually traceable evidence in this report.

Where are the web server access logs with source IP addresses and timestamps?

That's the kind of evidence that is needed to go to a provider's abuse department or sue to unmask the user behind a given IP, not attacker controlled (and falsifiable) strings.

jauer··on New Bedford police officer accused of using Flock cameras to track ex-partner
I think this or similar accountability measures is where we'll need to end up with this kind of technology. It's too useful for catching vehicle theft rings and similar kinds of highly disruptive criminal networks to abandon the technology entirely.

LOVEINT has been a thing for as long as electronic surveillance has existed. We fire and/or prosecute people for it. We didn't turn out back on those capabilities.

I'd like to see someone using systems not available to the general public to to look up info on people without a legitimate purpose be treated as a kind of aggravated stalking.

Government employees should be held to a higher standard because they are in a position of public trust, but TBH people at companies like Google, Meta, Verizon, Comcast abusing internal tools for this should be similarly held accountable because they have access to resources far beyond e.g. one hobbyist logging TPMS IDs on passing vehicles.

jauer··on Remove-AI-Watermarks – CLI and library for removing AI watermarks from images
Information is default low-trust unless you have reason to extend trust to the source and that's been the case for thousands of years, if not the entirety of human existence.

We now have the tools to increase trust in specific information, for example: by signing images that need high trust for things like news reporting using camera hardware root of trust with time and geo stamping. If signatures are removed, that's back to a default low-trust state.

jauer··on 7 in 10 Americans oppose data centers being built in their communities
and the xAI data centers are uniquely dirty and polluting because they don't have sufficient grid connectivity and are running on generator 24x7.

This isn't a problem for the vast majority of datacenters, and won't become a larger problem unless the anti-civilization mindset blocks infrastructure investment that's eventually needed even if the datacenter isn't built.

jauer··on Innocent woman jailed after being misidentified using AI facial recognition
AI or not, it's unconscionable that victims of compulsory legal processes by way of mistaken identity are not made whole.
jauer··on Wisconsin communities signed secrecy deals for billion-dollar data centers
Unlike enterprise datacenters, systems inside these datacenters are tightly coupled to compute system design to eke out PUE, so network cabling, electrical, and cooling to a lesser degree gets reworked every 3-5 years. On a campus with several data halls this means that there’s work for those trades well beyond initial construction. Sure, you don’t have the steel and concrete work happening that went into the shell, but it’s more than a handful of operations people.

From the 00s to mid 2010s I did fiber splicing in factories from Kenosha to Beaver Dam and even then they were fairly well-automated to the extent that I’d see just a few people on the factory floor moving carts of metal between machines or handling shipping and receiving.

jauer··on AWS CEO says replacing junior devs with AI is 'one of the dumbest ideas'
I've worked in various teams on the infrastructure side of a FAANG from early career/L4 to sr staff eng/L7 and have always been encouraged and rewarded for asking questions, even when those questions have led to unexpected multimillion dollar costs and in one case a loss of ~1% of fleetwide compute capacity.

I think this comes down to how you go about asking. You have to take the time to understand what is and how it's seen by others by being curious, reading docs, etc instead of rolling in making assertions disguised as questions to assert authority like so many are wont to do.

I suppose it's possible that I'm the designated court jester and that's why I can get away with questioning, but I don't think that's the case :)

jauer··on Cancer is surging, bringing a debate about whether to look for it
at the same time you have endless stories of people losing family and friends to cancer because a doctor dismissed complaints as anxiety or needing to exercise more leading to cancer not being discovered until it was too late to treat.

The answer can't be to put our collective heads in the sand.

jauer··on Hunting for North Korean Fiber Optic Cables
IPv4 continues to be available to entities that have a need that fits a particular policy shape, just most people don't. Specifically, you can get IPv4 /24s for IPv6 transition purposes. This includes anycast DNS, MX, etc for legacy clients on other networks, v4-side of CGNAT, etc.

E.g. I was able to get a /24 in the ARIN region in 2021 and could justify 2 more for a _logical_ network topology similar to what NK presents to the world.

APNIC similarly has a pool available for IPv4 allocations: https://www.apnic.net/manage-ip/ipv4-exhaustion/#the-situati...

jauer··on Synology reverses policy banning third-party HDDs
Trivially on their (and qnap's) amd64 systems at least. There are some quirks where they are more similar to an embedded system than a PC, but it's not a big deal. Things like console over UART (unless you add a UART) and fan control not working out of the box, so you set it to full speed in bios or mess with config.

Debian has docs on installing on at least one model of their arm boxes: https://wiki.debian.org/InstallingDebianOn/Synology

I run Debian on a few different models of qnap because their hardware occupies a niche of compact enclosure, low noise, and many drives.

jauer··on Keeping secrets out of logs (2024)
There’s secret from an adversary and then there’s internal compartmentalization.

You could have 100s of people who have a business need to look at syslog from a router, but approximately nobody who should have access to login creds of administrative users and maybe 10s of people with access to automation role account creds.

jauer··on The future of large files in Git is Git
TFA asserts that Git LFS is bad for several reasons including because proprietary with vendor lock-in which I don't think is fair to claim. GitHub provided an open client and server which negates that.

LFS does break disconnected/offline/sneakernet operations which wasn't mentioned and is not awesome, but those are niche workflows. It sounds like that would also be broken with promisors.

The `git partial clone` examples are cool!

The description of Large Object Promisors makes it sound like they take the client-side complexity in LFS, move it server-side, and then increases the complexity? Instead of the client uploading to a git server and to a LFS server it uploads to a git server which in turn uploads to an object store, but the client will download directly from the object store? Obviously different tradeoffs there. I'm curious how often people will get bit by uploading to public git servers which upload to hidden promisor remotes.

jauer··on Google will let companies run Gemini models in their own data centers
They don't sell them. But, if the developer / hotelier had a sufficiently large network, think providing service equivalent to the number of rooms at a US state university system network (multiple universities), then they might qualify: https://openconnect.netflix.com/en/
jauer··on DARPA solicitation for the Active Social Engineering Defense program (2017)
Reuters builds software for a variety of fields and maintains datasets that would be useful in identifying if, say, an email with an invoice purporting to be from a specific company aligns with the invoicing practices of that company.

It would be more accurate to compare that side of Reuters to LexisNexus, Wolters Kluwer, or perhaps Bloomberg.

jauer··on Helsing at Eurorust and the Oxidation of Defense
I've never worked in defense. Why do you equate working in those regions with working in defense?
jauer··on Helsing at Eurorust and the Oxidation of Defense
I'm curious how well this article resonates with people outside a particular bubble (vs. being puzzling if you are inside a different bubble.)

The statement that Anduril sponsoring a NixOS conference was inherently damaging as opposed to the reaction causing the damage, "When did defense work stop being taboo" etc.

I've worked in the US Midwest->SFBay->US West and defense work never seemed particularly taboo in my circles, moreso that the work was boring and constricting.

Traditionally cautious sectors adopting a particular technology seems like a sign that a technology is viewed as having a particular level of dependability. That's a good thing.

jauer··on Windows Kills SMB Speeds When Using Tailscale
Tailscale intentionally overrides your device's routing table to force traffic between hosts in the same subnet to go over a Wireguard tunnel instead of bypassing it. They do this because they believe that the presumption that a local subnet is trustworthy is false.
jauer··on Windows Kills SMB Speeds When Using Tailscale
> Because, for whatever reason I’ve yet to grasp, homelab folks like to implement Tailscale as some sort of “secure virtual network” abstraction layer - think something similar to zScaler ZPA - on top of their local LAN.

This is Tailscale's intended behavior, not a matter of how homelab folks like to implement it: https://github.com/tailscale/tailscale/issues/659#issuecomme...

jauer··on Four Thieves Vinegar Collective – Harm Reduction for the Living
Could you elaborate on what you find “vile and disgusting“ about that meme?
jauer··on I'm the hacker that brought down North Korea's Internet for over a week. AMA
It works for me? That's normal behavior if you aren't signed into Twitter :(

Summary of thread: Society doesn't handle 2nd order consequences well. NK cryptolocker attack on healthcare-involved systems in British hospitals disrupted treatment to the extent that hundreds of people died who probably wouldn't have.

Expanding on that: Organized crime groups located in and sometimes tasked by RU SVR & GRU (not to mention NK state groups) have caused sufficient disruption to US healthcare systems to have indirectly caused more US Citizen deaths than the Sept 11 attacks. Right now cyber that does not directly cause destruction such as making buildings blow up or poisoning water supply is treated as just an annoying white collar crime.

I don't think anyone wants the US Government to be in a position where their options are to admit powerlessness or get proportional against nuclear armed states.

Somewhat related: https://blogs.icrc.org/law-and-policy/2023/10/04/8-rules-civ...

jauer··on I'm the hacker that brought down North Korea's Internet for over a week. AMA
"the West" has to keep some degree of not officially caring to avoid being backed into a policy corner and has no incentive to take law enforcement action when threat actors in those other countries operate with impunity.

We're already well into causus belli territory with NK, but nobody wants to go there: https://x.com/tarah/status/1798036415932187127

jauer··on How Meta trains large language models at scale
and deceptive if not inaccurate. Meta's Model Cards specifically call out that they were trained on publicly available datasets and NOT any Meta user data.

For example: https://github.com/meta-llama/llama3/blob/main/MODEL_CARD.md

jauer··on How Meta trains large language models at scale
and so is Meta: https://ai.meta.com/blog/next-generation-meta-training-infer...
jauer··on Lynn Conway has died
She was one of the people who literally built the technical foundation of the world we know. That alone justifies all the upvotes.

The fact that she did that on top of basically starting life over at 30 due to the constraints around transition at that time? That's winning a marathon with a cinder block chained to your ankle.

As far as the concentration of trans people in computing, AFAIK there are two predominant theories: First, survivorship bias involving careers that are often non-customer-facing and well-paying. Second, that there's common cause or comorbidity with other developmental differences (like ASD or 2SD+ IQ) that are unusually common among people who end up in computing.

jauer··on Brain overgrowth dictates autism severity, new research suggests
I'm normally on a very minimal dose. I have, prior to getting timer tops and forgetting that I'd already taken med, taken >100mg of dextroamphetamine without feeling high and without titrating up. Instead, I got very focused and methodical to an uncomfortable degree, but there's absolutely zero high or euphoria.

Across ~4 doctors (1 PCP, 3 pysch), none have titrated up. They've ballparked and said things like "let me know and we'll reduce if you can't sleep and increase if it doesn't work. If you want, try doubling up or cut it in half (for non-XR)".

Given the variation in dosage visible in the literature (such as this case report of megadosing: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3407707/ ) I'd suggest that there are multiple underlying physical causes for the condition described as ADHD to the extent that sweeping statements like that aren't accurate. E.g. my (very different) experience and your experience being different indicates that we probably have different underlying causes, not that one is a myth or misperception and the other is the real take.

jauer··on Brain overgrowth dictates autism severity, new research suggests
Maybe addictive to people without ADHD…

They are so unaddictive to people with ADHD that remembering to take them can be challenging.

jauer··on CO2 helps viruses stay alive longer in the air
I have several CO2 monitors including some from AirThings, Aranet4, and a industrial sensor in the form of a Vaisala GMP252 CO2 probe. They all track closely enough that I don't worry about it. The Vaisala is rated to +/- 40PPM which is accurate enough for living space environmentals.
jauer··on Reclaiming IPv4 Class E's 240.0.0.0/4
> Automation is all very well once the network link is up and working so you can reach the automation

With properly constructed automation and modern* hardware, you don’t need to do any manual config on-box for automation to be reachable. Zero-Touch Provisioning is a wonder to behold.

Modern being relative. I saw this work on routers terminating telco circuits nearly 20 years ago and had servers netboot and install the OS with basic config before that (though automation was far more tedious back then)

jauer··on Reclaiming IPv4 Class E's 240.0.0.0/4
I’m a NetEng for a large (>1M servers, >100 POPs) network that is IPv6-only internally.

It’s not hard to remember IPv6 addresses for DNS servers assuming your addressing plan reserved the right subnets for anycasted services.

Remembering IP addresses stops being a thing pretty quickly. If anything the challenge shifts to remembering airport codes.

If you are typing them by hand that often even in IPv4 networks I'd be worried about typos and insufficient automation.

I think it’s more that small and medium organizations just don’t have any incentive to change (and plenty of incentive to not take the risk of change) leading to the numbers we see at https://ipv6-in-real.life/

jauer··on Internet of Desks: How I Connected My Standing Desk to the Internet
This. It's not Ethernet. This article has some dissection of the data going over those ports: https://hackaday.io/project/4173-uplift-desk-wifi-link
Page 1 of 16Next →