HNHacker News
TopNewBestAskShowJobs

mazone

44 karma · joined February 14, 2020

submissionscomments
mazone··on Revealing the details of how OpenAI agents hacked Hugging Face
Anyone know the details of the actual exploit to get access into huggingface environment. Was it anything novel or they left things wide open? Too much noise around this incident because it happened to be a llm that did it.
mazone··on "That's not SOC 2 compliant"
Every company is different, with different risks but here is the change management i have implemented successfully.

Minor, medium, major change category depending on potential impact with documented guidelines when each apply.

First release of a service always recommend to be major. (They are few vs daily changes and can be redtaped more to get many stakeholders requirements. Functional and non functional) Author of the change and his team decide the category.

- Minor need one more reviewer outside author. Team decide everything.

- Medium need min one more, and usually QA team or other affected team.

- Major change need CAB meeting with all major stakeholders to sign off.

CAB is responsible for the process and high level monitor the program, see if any cheating goes on, performance metrics such as number of changes per category etc. Help support people what could be considered minor vs major changes.

Overall rel flexible and balanced. Pushes people towards making smaller changes with less risk and at the same time increase velocity while still protect reasonable against bad actors, mistakes etc.

It is not perfect, medium changes tends to be more difficult to coordinate, some changes are missclassified etc but that is okey. It is not only about the process, communication matters and ci/cd have to be robust etc.

This balanced approach works for many.

mazone··on Security through obscurity is not bad
In a corporate setting my experience is that it is rarely worth it to add any obscurity on top of security. Your biggest challenge is getting peoples time and resources, and you need to use that time to implement security controls. A secondary objective you have is to build security culture over time and teach people too see patterns where more security is needed, so it is important to select what to teach to get maximum impact.
mazone··on I'm OK being left behind, thanks
Many companies usually want to compare themselves to Apple and at the same time say they are disruptors and innovators but Apple is probably the best company at being okey with being left behind. Many think about them as experts in products but for me they always been best att copy what others are doing and refine it, maybe not neccassary better technical but always seen the market fit better then others. Like poker, the later you need to take your decision the more information you have.
mazone··on Don't make me talk to your chatbot
How about the trend that people just copy paste AI responses back to you in slack.
mazone··on Start your meetings at 5 minutes past
I don't remember the last time i had a meeting that was productive. Last time i worked in the office, the hallway discussions where the productive ones and now working remote most of the time is just being able to work with good people that understand text and work by messages that works good. Even video meetings with good people tends to be waste of time.
mazone··on Dell admits consumers don't care about AI PCs
I wonder if Dell will ever understand why consumers don't care.
mazone··on Privacy doesn't mean anything anymore, anonymity does
You are correct. Would need something like distributed ledger to fully prove things.

It might not be possible to verify 100% but the more transparency the better i guess. Seeing the 3 way handshake and connection information, the timings, location of the server. Would need to be quite elaborate to fake. Just thought was a fun idea. Have the customer allowed in to production. A lot more difficult then publish privacy page, source code, fake audit reports.

mazone··on Privacy doesn't mean anything anymore, anonymity does
I wonder if it would be possible to allow people to ssh into the edge servers with enough access to verify no access logs are stored but not enough to cause any problems. Admit i have not thought it through but would be cool having people verify the live environment while running.
mazone··on KDE going all-in on a Wayland future
I love kde and it is what i use but still having the bug from time to time that the panels dissapear and have to relaunch plasmashell, also i wish they merged the virtual desktops and activities into one concept and allowed different wallpapers on each.

The theme settings is also confusing because of gtk apps, global theme etc. Feels everything around theming could be made nicer.

Prob some more nitpicks but overall it is a really great desktop environment.

mazone··on I don't care how well your "AI" works
Does the author feel the same way of running the models locally?
mazone··on Chess grandmaster Daniel Naroditsky has died
Trying not to sound too cold, he seemed like a very nice guy and i did not know him. It was not surprising for me. I remember seeing interview with him when he took things very personal and could not let things go some year back. Thought at that time that he was at high risk of suicide. He seemed to have a self loathing personality / depression and obsessive behaviors.

Staying on the Internet and be dependent on it in some way financially working as a streamer with all the short form communication and negativity online. Together with cyber bullies etc. A lot of things creating a perfect storm for what seemed to be a sensitive and very nice guy. Easy to say that his family and real life friends should have seen it too and make him change path but in reality it is difficult. Especially since things that make it worse like sitting down and playing chess all day / night and not getting enough sleep, together with cyber bullies is also the things that you love, you earn money on and you have many of your friends there.

mazone··on Are touchscreens in cars dangerous?
The most dangerous about the touch screen in my car is a warning message that come up first when the entertainment system boots, warning about using the screen while driving that i need to accept.
mazone··on iPhone Air
Recently got a iphone 16 pro to my mom. First thing i reacted on when opening the package was. Damm that is a thick phone. Compared to my S25 and older android phones i have the iphone 16 feel old and clunky, like from another era.
mazone··on Frequent reauth doesn't make you more secure
It is not about MFA or not but to demonstrate the process is secure for the purpose.

It can be complicated but a example. TOTP that is very common used with passwords is regarded as MFA (tho most of the time software based on phone) but have many problems regardless

- many time replayable - can be intercepted - implementations look different - recovery code reuse problems etc.

On the other hand, using only passkeys dont have those problems but with passkeys, many times you cannot decide on what device a user have registrated the passkeys in a enterprise setting. example they could be apple passkeys, chrome passkeys, windows, hardware key(yubikey) etc and all of them behave different when it comes how they ex can be copied/ synced between users devices. So from where they can be used.

So for any authentication flow, you need to look at the full picture. What is the process when credentials are lost? How do user onboard etc.

Is a good entry point to say. We should use MFA or similar but the details matter.

mazone··on Frequent reauth doesn't make you more secure
PCI DSS from 4.0 actually have something called customized approach for everything. If you can prove and the QSA agrees that you fullfill the goal of a requirement, you can be quite flexible. Example i am doing things like not using passwords at all and only passkeys, or only ssh keys protected by hardware security key etc. Together with agents trying to verify the devices connected are company owned and hardened in different ways. Your milage might vary depending on how good your auditor is but PCI DSS standard do have quite a bit of flexibility in it.
mazone··on What a developer needs to know about SCIM
I like the way IR remotes work for your aircon. Sending the full state every key press. Think it many times is a lot better then supporting PATCH.
mazone··on Persuasion methods for engineering managers
Working at Google (and similar companies) seems to be such a chore is what i got from this article.
mazone··on Should managers still code?
I do managing, coding, design, governance and overall what i call "improve the company" within my areas of expertise and context switching and commitments are the most challenging things. Need to be very disciplined and know the other areas are currently very stable and under control to carve out time for the other things. It is not impossible but it have to be very focused and the problem domain need to be quite good understood before jumping in. Example, writing a internal tool that in worst case get delayed for later is easier to start working on then being part of customer facing product development as all of a sudden i would need to jump into some urgent management tasks or overall just let the governance and long term company quality go down.
mazone··on Sweden is a nearly cashless society – how it affects people who are left out
One example is flee markets, or different type of second hand. Christmas markets etc. Some do accept debit / credit cards but a lot is swish only.

For cards, depends on the bank. I know my bank at-least do send the card abroad to my current home and as long as i keep my digital authenticator ID (bank ID) i am able to access that, renew cards. Do most banking services etc.

I also managed to get a new bank authenticator by going to the embassy and get signed papers etc, however it took about 5 months or so if you don't have any cash that might become a issue. :)

mazone··on Sweden is a nearly cashless society – how it affects people who are left out
As a Swede living abroad this creates a headache when going back. When combined with swish needs a phone number but to get a phone number you need to have a registered address, etc.
mazone··on In my life, I've witnessed three elite salespeople at work
When sales people post that picture of a saleperson with a round wheel and the "customers" too busy on the side of the road to switch from the square wheel as too justify something for themselves.
mazone··on DOOM CAPTCHA
on mobile phone. Just back up directly from the start to the door behind you so you dont get shoot then snipe them from a distance. captcha solved.
mazone··on Ask HN: What is the most useless project you have worked on?
Worked 5 years as a contractor for a system made to be used for all of the healthcare in a country. Payed by tax payer money. Some serious money. I never understood what the system actually was supposed to do during those 5 years. Started as some custom authorization server for new healthcare laws and then ended up as some kind of desktop app that had a launcher to launch apps. No idea what the purpose really was and heard it got cancelled a couple of years after i left.
mazone··on It‘s been 9 years since Valve rolled out the Steam Linux beta
You basically just install steam from within your linux distributions package manager. I use and recommend some arch based distro but for Ubuntu it should be apt-get or some gui tool like synaptic.

After you installed steam it will probably just work. You might need to go into settings -> steam play and enable proton. that's it.

mazone··on It‘s been 9 years since Valve rolled out the Steam Linux beta
Play only on linux since the last year or so and got away from the dedicated windows machine i had to have for only gaming. I had some bugs in the beginning but with recent versions of proton it feels a lot more stable. I don't have any bugs anymore in any games and don't notice any slowdowns or degraded performance. It is quite amazing.
mazone··on Ask HN: What does one look for in a laptop these days?
The Razer Blade stealth looked okey, looked like good quality build? Still chiclet keyboard and unnecessary few ports.
mazone··on Ask HN: What does one look for in a laptop these days?
1. 13" , 14" laptop

2. IPS matte good quality display with similar resolution to 2560x1440p, Superb colors and peak brightness.

3. At-least 32GB RAM but pref up-gradable RAM to 64GB

4. Linux full support, preferable AMD

5. Keyboard similar to old thinkpad 7 row style. General going back to retro style with proper keys, Topre switches or why not a mechanical keyboard if possible.

6. Trackpad of high quality. Atleast similar to Apple. Not seen any that have it yet on pc. If not possible, add a trackpoint and remove the trackpad.

7. Ports! Please have many ports. As many as possible.

8. Hardware quality. hinges, case and overall. Make it durable.

9. Battery time, make it last.

10. No spyware or bloatware. Published schematics of the laptop and help the open source community.

11. Good quality parts in chipset for wifi, bluetooth, sound. Latest AMD. Should not be a issue.

12. No intel inside stickers or other stickers on my laptop. If have to put a logo on it, make the logo very small and not in your face.

Okey, so what can i be without to make the above possible and

- No frills or extras. - No touch display. - Medium powered CPU. ( think road warrior not full fledged desktop replacement ) - No discrete GPU needed if it makes my laptop warmer, or make battery go down faster. Integrated GPU is "good enough" - No need for fingerprint sensor, even if convenient. - No magic bars or other innovation someone thought would be good. - Weight and thickness is less important then manufactures seem to think. To a degree. Slim laptops get warmer, rather have it a bit ticket with more room for battery etc.

Do the basics correct. A modern take on the Thinkpad x220. Remove things that don't matter and make a classic awesome laptop for the ages.

mazone··on Facebook quitters report more life satisfaction, less depression and anxiety
Now i am addicted to hacker news instead.