HNHacker News
TopNewBestAskShowJobs

lasdfas

87 karma · joined May 1, 2015

submissionscomments
lasdfas··on Against Cop Shit
How does a good instructor, syllabus, and/or academic institution not need this? I went to an Ivy League school with hopefully above average teachers and saw a lot of plagiarism.
lasdfas··on Against Cop Shit
I saw multiple instances of my classmates plagiarizing. It's very rampant in colleges. Removing that tech would be a mistake in my opinion.
lasdfas··on Show HN: Twingate – A modern solution for remote access
This looks very interesting. Very similar to Cloudflare Access. How does it handle auditing? Is there an ability to log SSH or HTTP traffic?
lasdfas··on Post Mortem on Salt Incident
I agree. I would like to seem more details of how they determined it was only crypto mining. Finding only mining scripts in your logs doesn't mean they were not running other code once they had root.
lasdfas··on Show HN: Layer – Get a dozen staging servers per developer
I may be misunderstanding the product, but it seems to be able to run a webserver on each "server".
lasdfas··on Show HN: Layer – Get a dozen staging servers per developer
You should probably be selling that if it works well. That is something I have not seen.
lasdfas··on Show HN: Layer – Get a dozen staging servers per developer
How is this even possible for $35?

50 staging servers per seat ($1450 Value) 11GB RAM per server 8 CPUs per server

lasdfas··on TracePrivately – open-source sample app using Apple's contact tracing framework
This is great. My only worry is that people shouldn't be allowed to self diagnose Covid-19. It will lead to trolls and cause tons of people self isolating unnecessarily, then eventually not using it once they realize the abuse. Maybe have the sever validate the diagnosis or have the person required to enter a code signed by the server's private key.
lasdfas··on First look at Apple/Google contact tracing framework
Because it can abused. The easier you make it upload, it also allows bad actors to upload invalid data to cause people to go into quarantine unnecessarily. It only works well if you can trust the data, so I think it should error on the side of validating the data instead of openness.
lasdfas··on Some auto insurers are sending refunds to customers as crash rate falls
It's normally not a fixed amount. It's generally a percentage above costs. If all costs increase, they increase their revenue. They get the same percentage of a bigger pie.
lasdfas··on The dark side of GraphQL: performance
Having youtube tutorials on something does not make you an expert on the subject. He appears to not have the skills to do basic JS debugging. It's great to ask for help, everyone needs help at some point. The issue I see is starting with "The dark side of GraphQL". If you haven't found the actual issue, how do you even know what the cause is? Just because your SQL query is fast doesn't mean there is some inherent problem in GraphQL or Apollo. That argument doesn't follow. It could be user error.
lasdfas··on The dark side of GraphQL: performance
Not sure why you are getting downvoted. The person actually states that they don't know how to debug, "honestly, I'm not 100% sure the best way to debug from here." They are just looking at Datadog stats and not finding the root cause. They could do some basic JS debugging of the open source library to figure out the issue. Blaming Apollo would be a stretch (which may not even be the issue since they haven't done any debugging), but the protocol of graphql is way too far.
lasdfas··on Ask HN: How comfortable do you feel using cloud-based password managers?
Yeah absolutely. But have you audited the mobile apps or the chrome extensions, etc. (Extensions can update in the background without interaction)? Every time a new release happens? Those products are created by completely different developers.

Not saying that a company could not have a malicious release. It could. I just think the odds are much lower because their release process has better security controls and is generally audited better.

lasdfas··on Ask HN: How comfortable do you feel using cloud-based password managers?
It really surprises me that people are using pass or any other password manager developed as open source.

Yes, the code is open source, but unless you download the code yourself and compile it, which not many people do on desktop and no one does for mobile clients, you have to trust the deploy process of a random group of people. None of the people even have to be malicious. They just have to have an insecure deploy process (which allows an attacker to insert code), which is extremely common in open source. Very few if any open source projects have audited their deploy process and have monitoring for vulnerabilities or exploits happening. It's just too time intensive/expensive for a side project someone isn't getting paid for.

I prefer to trust an organization that has gone through tons of audits. Not just on whether the client is secure (can encrypt securely), but that their software development lifecycle is secure. They also have a huge financial incentive to keep things secure, which is not the case in open source.

lasdfas··on Securing Infrastructure at Scale with Cloudflare Access
We have been using it at my company (100 employees) for 2 internal services for about 6 months with Google SSO. It has been working great. There has been 1 outage where it was down for a couple hours.

My only complaint is the security of it is not perfect. When you launch the tunnel, you declare the domain you want it to use. I can be any domain on the account and can't limit it to specific domains. It's a little dangerous if you have sensitive domains on your Cloudflare account that you don't want to use Argo.

lasdfas··on An ‘extraordinarily severe’ emergency: the radioactive leak at Harborview
Definitely, I was just very naive to think somehow this platform was immune from general human behavior
lasdfas··on An ‘extraordinarily severe’ emergency: the radioactive leak at Harborview
I think "some" is very few (if any at all) in my experience. If you are generally looking for knowledge or not sure, you preface with "I may be wrong", "I am not an expert" or other such phrases, but most often people state wrong information as facts with no caveats. It's probably some combination of over confidence and ignorance.
lasdfas··on An ‘extraordinarily severe’ emergency: the radioactive leak at Harborview
It took me a while to realize this. It wasn't until there was a post about something I was an expert on. I finally realized people respond here often with little knowledge or even no knowledge at all. It made me question everything I read before on this site.
lasdfas··on Trump’s cell phone use is security “nightmare” waiting to happen, lawmakers say
This is called whataboutism. If you are correct, it was wrong in both cases. https://en.wikipedia.org/wiki/Whataboutism
lasdfas··on Google and HTTP
Let's Encrypt just like every other certificate authority validates that you own the domain before giving you a cert. They do that by sending a request to the domain from their servers (via looking up the nameservers via domain registries) and validating the response matches a unique message generated.

You could impersonate google.com on wifi, but you couldn't get a valid cert for google.com because you don't own the nameservers or any of the servers that google.com points to.

lasdfas··on Show HN: Sslhash: SSL without a certificate authority
One of the main reasons for the library is no need for cert authority. Why not just create a regular cert Authority certificate and put the trusted authority cert on the clients. That makes it so you almost never have to change the clients certs. Also, it's supported by standard TLS libraries and clients.
lasdfas··on Show HN: Sslhash: SSL without a certificate authority
How does expiration work? What happens if an TLS/SSL cert is leaked/compromised? Change the clients as well?
lasdfas··on I've Just Liberated My Modules
@nj48 is just some troll who took all the names. Not sure the intention of @nj48. The hijacked modules are not dangerous at this point, but that could easily change and cause serious issues.
lasdfas··on San Bernardino County tweets it reset attacker iCloud password at FBI's request
The FBI wasn't asking for the device to be decrypted. They were asking for a new operating system to be installed that circumvented the 10 wrong tries and the phone is erased.

My original question still stands

lasdfas··on San Bernardino County tweets it reset attacker iCloud password at FBI's request
Why can't the FBI just work directly on the phone hard drive (removed the hard drive from the phone and connect it to another computer)? Why are the going through IOS operating system?
lasdfas··on Show HN: Laboratory, a Python port of GitHub's Scientist library for refactoring
I imagine this can only work on getters? How do you use this when code makes state changes?
lasdfas··on Youtubify, a Spotify clone with YouTube as back end
The site completely breaks the back button
lasdfas··on On a brother’s suicide: ‘I wish I had never told him to go to counseling’
If the student is at risk of suicide, there are times when they need to seek professional help away from school. He could be a danger to himself or others. I think you are making it black and white. "If the student wants to stay at school, let them." It is not as simple as that. Think about it from the other perspective. If he killed himself at school and they knew he had serious mental health issues, people would be way more up and arms. "The school did nothing!"
lasdfas··on On a brother’s suicide: ‘I wish I had never told him to go to counseling’
I don't see how W&M did anything wrong here. It is very common for students to take time off because of mental health issues. Especially if he was at risk of committing suicide. I know several students at my college who were forced to take time off and it ultimately helped them. They didn't have to worry about the stress of school.

The school didn't call to see how he was doing? I have never heard any school doing that. He was only out of school for less than 2 months.

The last suggestion that he killed himself because he was not readmitted in a timely matter. Remember, de was admitted less than a month later. This wasn't some year long process.

It is a very sad story and the sister is looking for someone to blame, but I see the school did nothing wrong here. The implication that you shouldn't seek college counseling for fear of taking time off is very dangerous. It is important for people to seek counseling as soon as they feel they need it.