HNHacker News
TopNewBestAskShowJobs

lovedswain

367 karma · joined February 19, 2021

submissionscomments
lovedswain··on Ubuntu 21.04
Even if my machine won't boot afterwards?
lovedswain··on Ubuntu 21.04
The 19.10 bump was to get some fresh base libraries to build something as I recall. I think it might have for Remmina. Otherwise totally agree with you, LTS is always preferable
lovedswain··on Ubuntu 21.04
The bootloader was broken for this laptop model in 19.10 and I've been deferring going through the same pain upgrading to 20.04. Totally aware of the support situation and upgrade sequence, but an unsupported machine sure beats a bricked machine
lovedswain··on Ubuntu 21.04
Because I'm running it of course.
lovedswain··on Ubuntu 21.04
Are there any known surprises coming from 19.10?
lovedswain··on IBM to Kernel Maintainer: “You Are an IBM Employee 100% of the Time”
It would probably only take a handful of engineers to mount a solid DoS attack by requesting approval for every shell script they write, home Ubuntu ISO they install, or neighbour's printer they fix to get this policy a little more sensibly refined. In any case whoever wrote that e-mail to him is not someone I would possibly tolerate working for
lovedswain··on Software Infrastructure 2.0: A Wishlist
This sounds like a needlessly strict interpretation of GDPR. Taken from the UK regulator's site:

> The lawful bases for processing are set out in Article 6 of the UK GDPR. At least one of these must apply whenever you process personal data:

> (a) Consent: the individual has given clear consent for you to process their personal data for a specific purpose.

> (b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.

> (f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests. (This cannot apply if you are a public authority processing data to perform your official tasks.)

...

> Legitimate interests is the most flexible lawful basis for processing, but you cannot assume it will always be the most appropriate. It is likely to be most appropriate where you use people’s data in ways they would reasonably expect and which have a minimal privacy impact, or where there is a compelling justification for the processing.

> The processing must be necessary. If you can reasonably achieve the same result in another less intrusive way, legitimate interests will not apply.

> You must include details of your legitimate interests in your privacy information.

I included the legitimate interests bits because they seem most relevant to testing, but even if testing is not considered "necessary" in a particular use case, there still remain at least two more criteria that might satisfy the use of live data in testing, including explicit user consent. Much of the focus of GDPR is on privacy-invasive intrusive processing and prevention of harm, I think a lot of fuss around it can be dispelled when viewed from this angle.

lovedswain··on Ask HN: How do you keep track of releases/deployments of dozens micro-services?
The biggest difficulty I've experienced is "librification", where some common code ends up in a little library, and soon that library is not so little any more, and not long after starts to look like half of every service. I can maintain discipline when working on small systems alone, but on a team there will always be one lazy person or urgent need which means eventually some shared component gains enough gravity to start sucking code out of their nice isolated homes

Giving up and dumping everything into a monorepo, that's not going to help at all. At that point probably better off just giving up any hope of carefully split up and individually managed services

lovedswain··on Turkey Bans Cryptocurrency Payments
https://en.wikipedia.org/wiki/Executive_Order_6102
lovedswain··on Coinbase from YC to DPO
Antithetical? High fees are all but a feature :)
lovedswain··on [dead]
I dislike RMS' opinions, therefore.. the GPL is dead? A little bit of a leap there buddy.

Cloud providers profiting from free software is an important issue, but it is largely orthogonal to the continuing need to protect free works in numerous traditional use cases

lovedswain··on The latest DSM update makes btrfs drives unavailable on budget Synology models
> Is there any technical reason why it is not supported?

No familiarity with these devices, but there is at least a slim chance if it was an embedded device, they needed the flash or RAM for something else. Seen this happen elsewhere before

lovedswain··on Israel may have destroyed Iranian centrifuges simply by cutting power
https://www.youtube.com/watch?v=OPKGbg16ulU
lovedswain··on US agencies call for pause in Johnson & Johnson vaccine
Put another way, you're about 38 times more likely to develop a blood clot than win the UK's national lottery.
lovedswain··on Cloudflare Pages is now Generally Available
Gentle reminder when receiving something for free, it's useful to keep in mind what the other party is receiving from you in return, and in this case, from all your users through your consent. I'm not sure what CloudFlare gain from offering this, but traffic data would seem the most obvious angle.

So I guess from my perspective, I'd treat this with roughly the same scepticism as a free hosting service provided by Google Analytics, at least until the bigger picture is made a little more clear.

lovedswain··on The Black-Scholes formula, explained (2019)
The article is dated and somewhat misleading,

> Since its introduction in 1973 and refinement in the 1970s and 80s, the model has become the de-facto standard for estimating the price of stock options

The only contemporary use for BS by professionals is as a convention for quoting volatility. As a pricing model it does not account for key effects such as the permanent "volatility smile" appearing in the aftermath of the 1987 crash (significantly increased price of downside options), and well understood behaviours like jumps and volatility clustering.

lovedswain··on Cyber Attack on Iran's Nuclear Facility
Seems we're both triggered by this emphasis on "_very_", or even use of that word at all. Obviously Iran has a variety of technical capabilities, such as evidenced by their national firewall and internal infrastructure, but are there any documented offensive campaigns successfully mounted against a foreign target?

The only attacks I know of are low brow phishing, DoS and web site defacements.

lovedswain··on Cyber Attack on Iran's Nuclear Facility
> Compared to 90% of the other nation-states out there Iran is a _very_ competent cyber-actor.

.

> Given your exposure in this geography can you name any of it's neighbors

Saudi Arabia targetted at least Bezos' phone

lovedswain··on Cyber Attack on Iran's Nuclear Facility
> _very_ competent cyber-actor

Please elaborate on this. As someone with direct exposure to this area and in this geography, my experience could not be described this way at all.

Let's not forget Iran's first "military satellite" was launched with an over the counter unencrypted amateur cubesat transponder manufactured by a Californian company

lovedswain··on Clubhouse data leak: 1.3M user records leaked online for free
It's a fabulous resource, I've already used it to identify unknown numbers sending me messages on Signal
lovedswain··on Clubhouse data leak: 1.3M user records leaked online for free
I guess a leak requires private data to be exposed, this is just a collection of public data.
lovedswain··on Vgpu_unlock: Unlock vGPU functionality for consumer grade GPUs
Running certain ML models in VMs

Running CUDA in VMs

Running transcoders in VMs

Running <anything that needs a GPU> in VMs

lovedswain··on Vgpu_unlock: Unlock vGPU functionality for consumer grade GPUs
It instantiates multiple logical PCI adaptors for a single physical adaptor. The logical adaptors can then be mapped into VMs which can directly program a hardware-virtualized view of the graphics card. Intel has the same feature in their graphics and networking chips
lovedswain··on Facebook Down?
In a similar vein, the alternative option for 7 was a cyclical dependency introduced since last restart
lovedswain··on Facebook Down?
The global outage drinking game:

bad DNS config push - 1 shot

routing loop - 2 shots

third party advertising your routes - 3 shots

power outage at data centre it turns out everything depends on despite decades and millions in engineering to avoid precisely that - 4 shots

Wolves ate through fiber - 5 shots

And it was a full moon - 6 shots

Single service failure, but service has not been restarted in 5 years, and no longer restarts in any documented fashion - 7 shots

And service developers left the company to found a startup - 8 shots

Expired internal SSL certificate - 9 shots

Daylight savings changeover-induced database corruption - 10 shots

Windows Update - 11 shots

lovedswain··on 34% of remote workers would quit rather than return to full-time office work
This sounds like a once in a lifetime industrial swamp-draining opportunity.. what do you suppose the correspondence is between folk having a hard time turning up in one location in the morning, and folk with a variety of other square peg/round hole work ethic 'features'.

Don't get me wrong, in this scenario I'd most likely be a drainee, just pointing out the thought must have crossed the minds of a more than a few managers.

lovedswain··on Et Tu, Signal?
It could be nothing, but it seems like it should have been disclosed and the article author neatly avoided it. They're the CTO of something very financ-ey/crypto-ey oriented in the B2B payments space, although the site (adjoint.io) explains little. Going by their GitHub most of their work somehow relates to cryptography.
lovedswain··on Apache Mesos to be moved to Attic
K8s single noder and GKE user here, can confirm I wouldn't remotely even consider going back. Deploying an app takes 5-10 minutes at most first time around, new pushes <1 minute, and when there is ops bullshit involved, it is never wasted work, and never needs to be repeated twice.

I hated Kubernetes ops complexity at first, but there really isn't that much to it, and if it's too much, a service like GKE takes 70%+ of it away from you

lovedswain··on Securing a Postgres Database
> What value is added by using a separate VPC?

Adding more mechanisms on top is pointless when the effort could be invested in, for example, automated auditing of SGs, which is vastly more potent from a hardening perspective than adding additional layers of technical redundancy that are still exposed to the same flawed human processes.

When you reach a team of 10-20 folk on a project, stuff tends to get confusing and/or lazy with elaborate configurations. Security design therefore is about more about managing that outcome through simplicity and process hardening than.. well.. I don't even know what threats a separate VPC protects against

lovedswain··on Securing a Postgres Database
What value is added by using a separate VPC? Equivalent restrictions can more easily be done with security groups, including on the outbound networking
Page 1 of 3Next →