HNHacker News
TopNewBestAskShowJobs

kevcampb

2,162 karma · joined November 14, 2012

Contact: kev@diffractive.io
submissionscomments
kevcampb··on Atlassian Rovo Exfiltrates Data, Bypassing Controls
Any recommendations for alternatives for just Confluence and JIRA?

I've been looking at switching to Notion and Linear, but just haven't had the time to complete evaluation.

kevcampb··on Atlassian Rovo Exfiltrates Data, Bypassing Controls
Worth reminding everyone of previous discussion when Atlassian opted-in all customers by default for their data to be used for model training.

https://news.ycombinator.com/item?id=47833247

This goes live on August 17. If you haven't switched it off your company IP will be used to train their future models.

kevcampb··on New Nginx Exploit
They've just been released

https://security.snyk.io/vuln/SNYK-DEBIAN13-NGINX-16732761

https://security.snyk.io/vuln/SNYK-ALPINE323-NGINX-16722461

So it seems that Snyk is taking almost a week to get advisories out for an RCE

kevcampb··on New Nginx Exploit
It seems that Snyk isn't picking this up on our docker images. They have a vulnerability published for the nginx binary itself.

https://security.snyk.io/vuln/SNYK-UNMANAGED-NGINX-16679754

But they've not released any vulnerability for the Alpine or Debian packages.

Does anyone know what's happening here? Seems concerning that there's a 2 day old RCE not being picked up.

kevcampb··on Chrome removes claim of On-device Al not sending data to Google Servers
That's on Google apps, that's not on Chrome. That's not Chrome sending your browsing data or content from inside webpages to Google.
kevcampb··on Chrome removes claim of On-device Al not sending data to Google Servers
This seems somewhat specious - it's also quite possible that they just altered the wording to make it less verbose. Does anyone have access to the link "Learn more about on-device AI"?

If Chrome starts sending data from the browser back to Google, that's going to be a huge compliance issue. If you work for a company that processes customer data in the browser, you're going to need to ban Chrome.

kevcampb··on Atlassian enables default data collection to train AI
"Your available data contribution settings will be available no later than May 19, 2026."

So let me guess, they're hoping that we forget about this by then, so that they can scoop up our data? I can't think any other reason for it.

kevcampb··on Atlassian enables default data collection to train AI
Unfortunately that one has a subheading of "From August 17, the outfit will collect customer metadata by default unless you pay for the top tier"

It's not just metadata, it's all "in-app data"

kevcampb··on Atlassian enables default data collection to train AI
I really wish I could find a better source to link to for this. By default, all free and paid customers are being opted-in to their data being used for AI training.

All your Confluence pages, Jira tickets, etc.

https://support.atlassian.com/security-and-access-policies/d... describes how to disable this, but it also appears that the setting to disable this doesn't exist (it's not visible on any of our instances).

kevcampb··on Show HN: Sheet Ninja – Google Sheets as a CRUD Back End for Vibe Coders
Which works out at $100 USD / year. You might think that's trivial, but when you start provisioning multiple environments over multiple projects it starts to add up.

It's a shame that Google haven't managed to come up with a scale to zero option or serverless alternative that's compatible.

kevcampb··on Updates to GitHub Copilot interaction data usage policy
This is terrifying. Github was the one provider I did not expect to make such an action. We're now playing whack-a-mole with vendors to try and ensure that our company IP doesn't end up being used to train a model.
kevcampb··on Mixpanel Security Breach
That's a mixpanel breach if the unauthorised access was mixpanel staff accounts.

If someone phishes your gmail account, there is no gmail breach.

kevcampb··on Mixpanel Security Breach
Possibly because OpenAI have just made a post stating there has been a breach https://openai.com/index/mixpanel-incident/ and implicating Mixpanel as the cause
kevcampb··on Mixpanel Security Breach
The title here is misleading. The original article does not state breach and at no point have Mixpanel used that term.
kevcampb··on Gmail will no longer support checking emails from third-party accounts via POP
Google converted my mum's Gmail account to a workspace account automatically. Now she can't use her bedroom alarm clock because it's connected to my dad's Gmail account and you can't share access to workspace accounts. It's stupidly maddening.

And yes I realise that an IoT alarm clock is ridiculous, but that's not the point.

kevcampb··on Kagi News
> This is pulling the content of the RSS feeds of several news sites into the context window of an LLM and then asking it to summarize news items into articles and fill in the blanks?

This is awful. It's cutting out any money going to the news agencies that go out there and write news. If they didn't exist, Kagi wouldn't work.

kevcampb··on DARPA solicitation for the Active Social Engineering Defense program (2017)
If you read the proposal, this is for providing automated defences against social engineering attacks - eg: phishing. It's incredibly benign.

That's not how it's presented on Elon's twitter post, certainly. The replies are just layers and layers of conspiracy theories.

kevcampb··on DARPA solicitation for the Active Social Engineering Defense program (2017)
For context, this is likely related to an Elon Musk tweet earlier today https://x.com/elonmusk/status/1887185381797343504 quoting Ian Miles Cheong

> Can someone explain to me why the Department of Defense provided $9,147,532.00 to Reuters for "ACTIVE SOCIAL ENGINEERING DEFENSE (ASED) LARGE SCALE SOCIAL DECEPTION (LSD)"

kevcampb··on A history of Hup, the jump sound of shooting games
https://en.wikipedia.org/wiki/Wilhelm_scream
kevcampb··on Alibaba researchers went rogue and disclosed Log4j now CCP is making Alibaba pay
Submitted previously as https://news.ycombinator.com/item?id=29646949 but didn't get traction. Clearly it needed a punchier title.

There's no suggestion that China gets any first say on 0-days. The law in question re reporting is at http://www.gov.cn/gongbao/content/2021/content_5641351.htm and states that you must immediately notify vendors of security flaws, and then the MIIT within 2 days.

kevcampb··on Log4j: China pulls support from Alibaba for not reporting to government first
The original title was too long for submission, so some cuts were needed. I tried to preserve the meaning as best I could

The SCMP has updated their front-page link to read

"China disciplines Alibaba Cloud for handling of Log4j bug"

kevcampb··on Measuring 'Return on Investment' of Various College Degrees
"If their degree cost them $60,000 to obtain, it would take them four years to recoup their education costs ($60,000 net cost / $15,000 earnings premium)."

They completely omit the time spent getting the degree and associated loss of earning during that period

kevcampb··on Facebook apologises for flagging Plymouth Hoe as offensive term
The Scunthorpe Problem

https://en.m.wikipedia.org/wiki/Scunthorpe_problem

kevcampb··on Falsehoods programmers believe about addresses (2013)
It's strange in that my floor number changes depending on what language you are using. For systems that parse addresses into a structured format it's a real problem, as they need to ensure they are rendered into the original language.
kevcampb··on Falsehoods programmers believe about addresses (2013)
A fun one to add. In Hong Kong, old walk-up buildings often have different floor numbers in English than they do in Chinese.

For example, 2/F in English may be 三楼 (third floor) in Chinese.

kevcampb··on Microservices – Combinatorial Explosion of Versions
It's still possible to do live upgrades without microservices
kevcampb··on Scratch that: Cats film to be 'resupplied' with 'improved visuals'
This isn’t new. The US ending of the big blue was switched to a happy one

https://en.wikipedia.org/wiki/The_Big_Blue#Original_and_alte...

kevcampb··on Chinese telecoms must use "AI and other technical means" to identify phone users
It's not "photo taken"

https://www.hongkongfp.com/2019/12/02/china-tightens-cybersp...

A China Unicom customer service representative told AFP that the December 1 “portrait matching” requirement means customers registering for a new phone number may have to record themselves turning their head and blinking.

kevcampb··on Making Git and Jupyter Notebooks play nice
Jupytext works as an extension in Jupyter. Your work is saved as py automatically whenever you work on the notebook. So it's not a conversion at commit time, unlike say nbstripout
kevcampb··on Making Git and Jupyter Notebooks play nice
Or just use jupytext and only commit the .py files. Works for us. Commits just look like normal python code, with a few comment markers for cells
Page 1 of 4Next →