HNHacker News
TopNewBestAskShowJobs

jpleger

1,848 karma · joined September 18, 2017

Security nerd. Father.
submissionscomments
jpleger··on uBlock Origin Is Giving Up the Fight to Keep Ads Off Facebook
I mean you are both right, it's been a few years since I have been in adtech, and it isn't black and white. There are few places that will pay for stuff that isn't clicked through, but there are places that are willing to pay on an impression basis for things like video or images. It's just like not worth it to most places to throw those ads on their property since it's fairly low quality advertisers.

More to the point though, if there isn't ads rendered, you can't even get accidental clicks.

jpleger··on Easyduino: Open Source PCB Devboards for KiCad
The really awesome thing about these being in simple reference designs, is how easy it is to swap out things like that. I really like how they have things laid out, and will be using this as a reference for jr. folks on how to lay out logical blocks in KiCad.

I have often thought how awesome it would be to have a bunch of proven / validated / supported open source blocks for common things like power supplies, sensors, etc. I think that at some point digikey or someone had a modular board that you could mix and match stuff into a reference design, but I can't remember the details.

jpleger··on Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
Ah yes the incredibly common practice of... checks notes backporting security packages in node packages.
jpleger··on Incident with multple GitHub services
I wonder if there is any correlation between them moving towards Azure.

https://thenewstack.io/github-will-prioritize-migrating-to-a...

jpleger··on Rivian R2 won't have A/C buttons followed by CEO's decision
That seems kinda dumb. I would never purchase a car without physical controls for key things. It is such a distraction to pull your eyes off the road for common tasks.
jpleger··on Build123d: A Python CAD programming library
This is cool, seems like a next gen cadquery, which was really cool to see.
jpleger··on Trump to impose $100k fee for H-1B worker visas, White House says
K, but if these are experts that literally do not exist in the US, why are the salaries not higher than median? It wasn't meant to fill junior level positions.

This program was meant to allow talent that is not available in the US, so that gaps could be filled with experts from overseas.

jpleger··on Tech hiring slows, unemployment rises, jobs report shows
Things feel like the 2008/2009 time period for hiring, but stock valuations and earnings are still extremely high, which is kinda odd. It feels so strange right now for employment prospects.

I don’t know if anyone else feels it, but the constant under resourcing and do more with less mindset since 2021/2022 have probably made things worse too.

jpleger··on S&P 500 Current Drawdown
This year, I started actively day trading S&P 500 because of all the volatility. Maybe its biased because I have been staring at charts more diligently than in the past, but IMHO you can almost feel the tension in the charts right now.

2023/2024 would have small swings of like $2-$4, with $5-10 movements on a maybe 1 out of 20 days. Since Trump took office, it has been almost daily $6-$10 moves, with the rare day of only $3-$5.

Its great for day trading, but I don't know how I feel about it in general. I almost feel like this is the oscillation before the car starts to shake itself apart.

jpleger··on CVE Foundation
Hahaha, CVE was created because industry refused to track and report on things in a consistent and transparent manner. When given the option, business will almost always choose the easy path, and things like vulnerability management programs will be set back years if not decades when the external accountability goes away.

In general, lawyers and CTOs would probably love to see CVE go away or be taken over by industry.

Source: been working in security for 20+ years.

jpleger··on So you want to build your own data center
Makes me remember some of the days I had in my career. There were a couple really interesting datacenter things I learned by having to deploy tens of thousands of servers in the 2003-2010 timeframe.

Cable management and standardization was extremely important (like you couldn't get by with shitty practices). At one place where we were deploying hundreds of servers per week, we had a menu of what ops people could choose if the server was different than one of the major clusters. We essentially had 2 chassis options, big disk servers which were 2u or 1u pizza boxes. You then could select 9/36/146gb SCSI drives. Everything was dual processor with the same processors and we basically had the bottom of the rack with about 10x 2u boxes and then the rest was filled with 20 or more 1u boxes.

If I remember correctly we had gotten such an awesome deal on the price for power, because we used facility racks in the cage or something, since I think they threw in the first 2x 30 amp (240v) circuits for free when you used their racks. IIRC we had a 10 year deal on that and there was no metering on them, so we just packed each rack as much as we could. We would put 2x 30s on one side and 2x 20s on another side. I have to think that the DC was barely breaking even because of how much heat we put out and power consumption. Maybe they were making up for it in connection / peering fees.

I can't remember the details, will have to check with one of my friends that worked there around that time.

jpleger··on So you want to build your own data center
Are there any alternatives these days? Or just that you weren't expecting to have systems boot off the network?
jpleger··on Ask HN: Good book to learn modern networking?
What are you talking about? TCP/IP hasn't changed in the last 20 years... like, at all.

There might be best practices which have changed around NAT, software defined networking and load balancing, but it's all on top of existing protocols.

If you are talking about subnetting practices, it has always been an operational thing... that's not what these books are talking about.

jpleger··on Ask HN: Private yet Modern Smartphone?
Also, I haven't looked at the Fairphone5, but they are 99% likely going to be using a qualcomm, mediatek or broadcomm modem, which is a black box and are some of the most vulnerable components of modern smartphones.
jpleger··on Intel Itanium IA-64 Support Removed with the Linux 6.7 Kernel
I worked on a large scale project that was itanium based and let me tell you, the compilers / software toolchains were an absolute dumpster fire. We were planning on being between 500 and 2000 processors in our cluster.

We used HP boxes and I want to say it was around 2002/2003 when this was going on. We were supposed to be a huge public showpiece client for both intel and HP. It… did not go very well. I remember the absolute defeated looks of the HP / Intel people when we pulled the plug and told them the discounts / free hardware still couldn’t justify the engineering efforts we had gone through for the last 18-24 months. This was right as opterons were coming out and that project jumped ship to them.

jpleger··on Putting out the hardware dumpster fire
I think one of the primary reasons that it is such a dumpster fire is there traditionally hasn't been an "open" ecosystem in the hardware world, though now they are being forced towards that direction kicking and screaming.

Every part of the hardware ecosystem has traditionally been done in closed, NDA ridden environments and only over the last 5-10 years has that even started to change.

Designing chips has required NDA-based PDKs. Designing complex PCBs has required closed-source EDA tools. Interacting with any of the IC peripherals often requires binary or non-redistributable firmware.

Hell, even with the modern "open" switch architectures, like Trident3, you can't get software or detailed datasheets from broadcom without an NDA. Same thing with some of the ARM based stuff like with the Raspberry Pi.

jpleger··on IDA cybersecurity software provider Hex-Rays acquired
I was a heavy ida pro user from 2008-2012. I have probably been responsible for or directly approved giving them 35-40k at different places over the years.

I wanted to do some pic disassembly a while back and out of curiosity asked if they had a low cost personal license for non commercial use and basically got told to pound sand. They said the price for the full version was what it was, no discounts. Then they came out with their ‘home’ edition which is an insult at $365 per architecture and not all architectures are available.

I don’t care how much better it is than open source stuff, until they have a full featured personal version and lower their price, they won’t be getting a dime of my (or my companies) money. It isn’t 2008 anymore.

jpleger··on A Big Week for RISC-V
Just curious, where aren’t they complying with the ISA? I know they use a couple registers in specific ways, but IIRC, the way they use it was left to the implementer so they aren’t diverging from the architecture.
jpleger··on IoT hacking and rickrolling my high school district
Are you me?! This basically was my experience working for a very large school district in the early 2000's. My favorite was they asked me to train a school bus driver to be the newest member of the IT staff because "they wanted to learn computers", it also just so happened that this person was the only person their budget could afford (less than 40k/year).

I worked for them as a contractor for a while and one of the big issues they had was they had tons of money to implement new technology (mostly from grants and things like that), but nearly nothing to maintain old tech. They could buy new computers all day long, but if something needed to be repaired/updated/maintained, there was no budget or resources to do it. So there were all sorts of fun issues, like they would buy computers and before they could get deployed their warranty would expire (since they weren't allowed to buy 3 year warranties on the computers) and computers with bad HDDs would get disposed of, even though the fix might be $50 and 10 minutes of time.

jpleger··on Jaguar Land Rover to suspend output due to chip shortage
Well, its the truth.

You don't have to be a rocket scientist or have a PHD in supply chains to understand there are second/third order consequences by cancelling significant amounts of your forecasted production and then expecting your suppliers to magically pick up where you left off.

Its why you keep production/manufacturing warm rather than do stops (which is what they essentially forced their suppliers to do by cancelling purchases).

This is BCP 101 and I give the auto industry no sympathy since most of this pain was entirely self inflicted. They tried to push all the risk to their suppliers, left them holding the bag and had a shocked Pikachu face when they couldn't ramp back up to prior levels.

jpleger··on Intel benchmarks say Apple's M1 isn't faster
This also looks like they are comparing running Windows versions of software to the OSX version of the software on M1.

So there are 2 MAJOR variables, which they combined... performance of OSX vs Windows and performance of M1 vs i7.

IMHO this benchmark doesn't mean anything just based on that alone.

To accurately compare, they need to run the benchmarks on same processors on Windows vs. OSX to establish the OS performance. Once that is done, you can infer performance between the M1 and current gen mobile i7 processors.

To be honest, this is the reactionary responses that you would expect from someone who is extremely behind. The other thing that is really important to keep in mind is how long and how well established x86 has been for desktops. Apps/frameworks/compilers have definitely optimized for this wherever possible and only in the last few years has ARM has been picking up critical mass for desktops/laptops. Sure over there have been tons of phones/tablets but there haven't been many daily drivers.