HNHacker News
TopNewBestAskShowJobs

joshchaney

63 karma · joined October 29, 2013

submissionscomments
joshchaney··on Gmail might partially be to blame for receiving emails from other Sean Conners
This blog is wrong. Other Sean Conners are to blame for not knowing their own email address. I know this because every other first initial j, last name chaney on this planet is a moron. I get Jennifer's receipts, Justin's bills, John's rent-2-own upcoming bill notifications, and hundreds more. Please. Make. It. Stop.
joshchaney··on WiFi DensePose: WiFi-based dense human pose estimation system through walls
I've learned that if the project describes itself as "Production-ready", it was definitely vibe-coded.
joshchaney··on The Curious Case of QUEENCREEK
Intel's Ocotillo campus in Chandler, AZ is right off Queen Creek Rd. Pretty sure that's all it is.
joshchaney··on Self-driving Waymos secure final clearance for expansion beyond S.F
They did some driving in some Arizona suburbs too

I think you are really understating it. I believe Chandler, AZ has been Waymo's proving grounds for years, and according to this article (https://www.wsj.com/us-news/waymo-phoenix-arizona-self-drivi...) the Phoenix area is the leader of autonomous vehicle service.

joshchaney··on DeskHop – Fast Desktop Switching
Is there some documentation about this somewhere? I actually own both level1techs DP 1.4 KVM 4-computer/1 monitor switch and that new USB KM switch, so I'm familiar with their products.. but I'm not aware that their KVM does anything special other than support high response rates (where most KVM's only do 60hz) and passthrough USB properly.
joshchaney··on DeskHop – Fast Desktop Switching
One exists already. https://www.store.level1techs.com/products/p/4-port-km-switc...
joshchaney··on DeskHop – Fast Desktop Switching
Not sure why they posted that when Level1Techs does actually have USB KM with mouse roaming. https://www.store.level1techs.com/products/p/4-port-km-switc...
joshchaney··on Discouraging the use of web application firewalls
I think WAF is really a bigger set of tools now (bot protection, IP reputation, L7 DDoS/rate limiting, API restrictions) than just signatures. Virtual patching is also incredibly important and there's really no other security tool that gives you the granularity to restrict something like the values of some param on a specific path of your app, but only when some cookie exists.

I don't think the performance concerns here are accurate. I think these days most people are using vendors own cloud infra (Akamai, Cloudflare, F5, Imperva, etc), but even if you are using WAF on-prem, F5 and Imperva sell purpose built hardware that have no problem handling tons of requests. Most WAF's also have weighted signatures these days and won't just fire on ${jndi. "${jndi" might give 5pts, while "org.apache.*" gives another 5, and maybe their threshold is set for 10 for blocking.

I have plenty of issues with WAF's and I would invest a lot more in developer training, but I think they still have their place.

joshchaney··on Return to Office Is Bullshit and Everyone Knows It
This is exactly what happened to me. I worked from home for Wells Fargo for years prior to the pandemic. This year suddenly my status got changed and I was required to go into the office. First come first serve cubicles and none of my co-workers were even in the same state, let alone office. Years prior to the pandemic when I was in the office I had my own cubicle and could at least expect my chair would be the same and nobody had messed with the monitors on my desk. It's like working from an Internet cafe every day now.
joshchaney··on Ask Wirecutter: Can you recommend a not-smart TV for me?
The one I referred to is a TCL 55S405. It seems the only solution is to never connect it to the internet, or factory reset it and never connect. Once connected if you remove the network details, it will blink indefinitely (at least for many TCL models).
joshchaney··on Ask Wirecutter: Can you recommend a not-smart TV for me?
Amazing that their budget recommendation is the Roku TV. I can tell you from experience if you don't connect them to Wi-Fi there is an LED that will constantly blink on the bottom front of the TV, with no way to disable in software. So unless you like your TV with an electrical tape aesthetic, I would avoid Roku TV's.
joshchaney··on Catalina VM
There's two articles [1] now on the front page of HN from this bit-101.com domain and they both seem pretty basic for HN. The other one is just about some guy installing a third party CPU cooler. No new tech, nothing interesting about the cooler, he just found it works better than the stock one. This article walks through using a shell script he found on GitHub to virtualize MacOS and his install and his very unscientific opinions on performance. Where's the beef?

1. https://news.ycombinator.com/item?id=24599832

joshchaney··on 2018 Mac Mini Review
That's a laptop CPU. The top-end Mac Mini he's using is a 65W TDP i7-8700. Pretty large difference in performance.
joshchaney··on Dell Computers Has Been Hacked
He said his email account has 2FA (convincing us his email was not hacked), I don't think he meant his account on Dell.
joshchaney··on Dell Computers Has Been Hacked
The title should really be changed, there is no confirmation they were hacked. I have an equally plausible theory -- You used the same username and password somewhere else that got hacked, or your credentials were stolen through some infostealing malware. Account takeover is a huge problem these days, it wouldn't surprise me if there is a tool out there written specifically to validate combo lists against Dell's website.
joshchaney··on CircleCI security incident
Customers: stripe, Red Bull, Kickstarter.. and MongoHQ. How meta. This hack could get a lot more interesting depending on how much code they could have obtained from those companies.
joshchaney··on MongoHQ Security breach
At the time this project was put together, IAM didn't exist. But I agree that this would be the best approach going forward.
joshchaney··on MongoHQ Security breach
I was one of those people bitten by this last night. My client called and told me he was getting access denied when trying to upload files through his CMS. After some digging I found the S3 key had been revoked. This was concerning, as I hadn't touched the CMS code I wrote in like 3 years and I've had issues deploying old stuff to Heroku in the past. I really wish MongoHQ had contacted me first about revoking the keys.