HNHacker News
TopNewBestAskShowJobs

mdb31

484 karma · joined May 12, 2012

submissionscomments
mdb31··on Ask HN: Is a PhD a hint that you have tried to avoid working in industry?
EU perspective here: no, a PhD indicates that you're interested in research, and are capable of jumping through organizational hoops to make such happen.

I've hired PhDs as (very) successful product managers twice. In both cases, the candidates were very eager to look into all existing research around the product line, as well as perform interviews to determine any gaps.

That, for me, was and is extremely valuable. But, on the other hand, if you're looking for a 1000x Rockstar Coder<tm>, a recent PhD hire may not be for you.

mdb31··on More stories about stacks of modems
Nah, Portmasters were actually pretty cool. The brand that caught fire, was a briefly-very-popular one that had ISDN-2 routers that had the charming feature of having proxy-ARP turned on by default (so that all traffic on your LAN would egress over that ISDN link...) as well as ISDN-30 rackmounts that, well, melted down when too many people dialed in at the same time.
mdb31··on More stories about stacks of modems
The journey from "whatever works" to "this needs to scale" described here is very, very recognizable.

In the early days of the internet, this is what pretty much every ISP looked like. The author doesn't seem to like their USR ISDN solution very much, but it was pretty much the best you could get at the time.

I forget the brand of the kit that actually caught fire, but that was definitely something that was happening for real in the data closets of the period. My employer at the time was using Cisco 5500s, which had to be upgraded to 5600s (or was it 5700s?) pretty quickly, due to the potato-like qualities of the CPU and RAM on the former model, and the rapid increase in modem speeds.

Good times? Maybe... We've definitely come a long way since the start of the century, and despite all the hand-wringing around "tech stagnation", turning up a 10Gb/s link these days is definitely more enjoyable than getting a T1 or E2 link to do its thing at the time...

mdb31··on A short conversation with a bank
Yeah, this is why I don't miss living in the US, like, at all. Sure, you can make mad cash and all, but the overall infrastructure is just way-below-third-world.

My particular moment of truth was when I noticed that my Pacific Bell cell phone bills stopped arriving. The first month, the USPS could possibly be to blame, but the second month, I called Customer Service to figure out what was going on.

So, first question, last 4 digits of your SSN. Answer, as ever: 1234. Eh, no, WRONG, try again!? Eh, yes, my SSN ends in 1234?! No, sorry, it does not, I cannot talk to you, bye!

Eh, yes, okay... So, try again the next day, hopefully that agent will be more clued in? Nope, no way, disconnected again.

So, visited the PacBell store near my office. Same thing, the person in the store is, like, visibly shaken after checking my account. can't do anything to help me, can't tell me what is wrong.

TL;DR: my cell phone got disconnected (most likely for nonpayment) after another month or so. Tried to sign up with AT&T, but got denied, because my 'nonpayment' was already recorded on my credit file, so, yeah.

Ended up calling every number in the PacBell SoCal range, and finally got through to someone who took pity on me and was willing to listen to me, and got my account and credit restored.

A few months later, PacBell drained my account by issuing hundreds of direct debit orders for my monthly cellphone bill. They eventually stopped doing that, but never reimbursed me for any overdraft fees. I was almost evicted due to bounced checks because of this, but nobody cared.

I've lived most of my life therefore and after in the EU, and while life here definitely is not perfect, I've NEVER had trivial issues like the above almost cause me to be homeless. So, I guess there's a startup idea in there somewhere? /s

mdb31··on Early peek at C# 11 features
Although not every new C# feature is as... pragmatic... as I would perhaps like, the language is continuing to evolve quite nicely. And the .NET framework doubly so.

One thing I would really like to see, is JSON literals on par with the XML literals that are available in VB.NET. Combined with LINQ, that makes for a quite interesting experience.

(Although the extent of the breakage in various tools, not just third-party solutions like Re# and Rider, but also VS.NET itself, possibly goes to the wrong side of 'interesting'...)

mdb31··on Things you notice when you quit the news (2016)
"Quit the news" is not the answer.

Quit the 24-hour news cycle? Sure. Quit doomscrolling on Facebook or Twitter? Yeah, most definitely quite good for you.

But, "quit the news" as in "remain uninformed"? No way! The invention of the press enabled modern democracy, and no matter what you think of that, all the alternatives so far have pretty decisively turned out to be worse.

So, here's my take: consume the news, but in moderation. And, like consuming alcohol in moderation (which I also wholeheartedly condone), I can't tell you exactly how to do it, just that I've seen it done successfully.

For me, it's a (dead-tree) subscription to The Economist. World events, long-form analysis, some light fare, all with a mild(ish) libertarian touch, delivered to my doormat every week.

A time-saver it is not: a single copy of the (weekly) newspaper takes at least eight hours to digest, often longer. But I don't feel compelled to hit 'refresh' (the newspaper is what it is for the next week), and there is no way to embarrass myself by hitting 'reply': a Letter To The Editor takes some careful consideration, which is great.

mdb31··on Neuroscientists have recorded the activity of a dying human brain
Via news.ycombinator.com: Actual title of the post is "A replay of life: What happens in our brain when we die?" -- please respect the submission rules...

Via reddit.com: How vile of the liberulz to mis-characterize Trump's new social network like that -- please don't do that here...

[Edit: and yes, downvoted within 2 minutes... How. Surprising]

mdb31··on IRS to adopt Login.gov as user authentication tool
Thanks for the passive-aggressive accusation there!

So, what more is there, exactly, to my story? My name is pretty simple, but, like many European names, has 3 parts, as well as some 'unexpected' letter combinations.

As far as I know, you can only request an ITIN by phone. Possibly, this can also be done online now, but that wasn't the case in the 1999-2009 period that I'm talking about here.

Also, the person that answers the phone... how do I say this? Is not exactly fluent in English... Or Spanish (which I can at least spell my name in as well)... Or any human language?

So, you get a new ITIN, with a random ASCII string as a name. And, to file a valid tax form, your ITIN needs to match your name... Which you provide in a PDF.

See where the problem lies here? You want me to upload a few scans of US government letters/forms with my actual name horribly misspellt? You want to see my attorney invoices? Certified PDFs only, I assume?

What, exactly, is the burden of proof you place upon me here?

mdb31··on IRS to adopt Login.gov as user authentication tool
Sorry, I'm not blurring my ITIN with immigration status or whatever. I have not visited the US since 2004, I have no desire to return, and I have not done any business there since 2002.

I just want an ITIN that is, like, actually in my name. Plus the IRS to agree that I do not owe any taxes in the 20-or-so ITINs that they have issued in various misspelled variations of my name.

But yeah, to get any clarity, I apparently need to go to Austin, Texas, in 2020.

And time machines are "easy to deal with", apparently?

mdb31··on IRS to adopt Login.gov as user authentication tool
OK, I understand that some/many Americans dislike paying taxes. I do not exactly like it either.

But, it seem like a particular US infliction to make paying taxes as hard as possible? Plus, they sanction you in extreme ways if you don't manage to jump through all the hoops?

I pay taxes in many jurisdictions. Here is my experience: Netherlands (my home country): the tax authorities send me a proposal about payable taxes. This includes income from my business, my partner's job, our common investments, and some investments/business interests that are exclusive to me. I correct whatever is required (with the deadline being April 1st), and I'll get my final settlement sometime in June/July.

Germany/France: I provide the tax authorities with my Dutch tax identification number, and they confirm they're fine with that in 3-4 months time. Rwanda, Nigeria and Zimbabwe: I also provide my native tax details (sometimes using my mobile number, sometimes using my NL 'SSN'), and they're fine with that, sometimes after billing me a small percentage over some income.

US: I honestly have non idea where I stand. The IRS refuses to talk to me, yet summons me to physical meetings in the past that I cannot legally attend. I have hired several attorneys, none of which seem to be able to help.

I probably owe several HUNDREDS of dollars in US tax. I've not visited the US since 2004, and have not done any business there since 2002.

Yet... I'm apparently a much-wanted tax fugitive in the US. Does that count on a FAANG-inbound resume?

mdb31··on IRS to adopt Login.gov as user authentication tool
Yes, but WHY?

I mean, I'm happy to pay my US taxes. Heck, I'm even happy to pay someone to pay my US taxes. But... neither of those options seem to work?

I mean, just to back to Rwanda: it's an east-African country that is pretty much a dictatorship and had a real-life genocide less than 20 years ago.

Yet, in Rwanda, I can just use my native cell phone number as my tax identifier, pay then what I need to pay, and be done with it.

In the US, I am probably known under a dozen ITINs, and literally none of that is my fault: it's just that the IRS agents that created those ITINs were unaware of, like, any spelling alphabet ever. Even ITINs created using a fax (that's a TIFF-over-POTS, for you millennials) got completely misspelled.

And now I'm supposed to spend tens of thousands of dollars to prove I've paid my taxes?

OK, now I now the answer to my initial question...

mdb31··on IRS to adopt Login.gov as user authentication tool
I'm a foreigner (yes, I know, sorry, sorry) who is a "US Person" and thus needs to (and, to be perfectly clear, is happy to, I'm sorry, I'm not-sorry, I'm sorry about being not-sorry?) pay US income tax.

The IRS system is, by far, the worst I've ever had to deal with, and in this I'm comparing the US to countries like Rwanda, where, for some weird reason, I'm also required to pay taxes.

Getting an ITIN (sort-of like a SSN, except you're not supposed to use it like that, otherwise they will send Ted Cruz after you...) is an absolute pain, mostly because you can only request it by phone, and literally nobody you talk to is able to spell your name right, DESPITE you repeating it endlessly in just about any spelling alphabet possible.

So, you now have a dozen-or-so ITINs (again, like SSNs), all in different names, none of them yours. So, you file your taxes using the ITIN in the names that is closest to yours, and specify this on your tax forms.

You send in your forms, and your check, which is cashed immediately. Repeat the next year, and so on.

Now, after FOURTEEN years or so, you get sent a letter, informing you of a tax audit, and demanding you are physically present in Austin, Texas, two weeks from the postmark of the letter (never mind it reached you three months after that, and never mind you're located in Europe, which at that time was denied access to the US due to COVID-19).

So, you get a lawyer, which costs close to US$ 8000. The lawyer contacts the IRS, which continues to insist on an in-person interview in the past.

So, now you're out US$ 8000, and can never travel to the US again.

But, yeah, lovely that they now allow additional login tools...

mdb31··on Ukraine Conflict Live Map
Oh, this definitely seems very useful.

But, the immediate reflex on HN is to downvote such tools into oblivion. When I 'vouched' for this submission, it was flagged, I assume for immediate deletion.

It's quite interesting that 'free speech' advocates are so, eh, limited in what they actually consider to be such...

mdb31··on Ukraine Conflict Live Map
So, yes, political, but on the other hand a cool piece of tech?

I've not seen this kind of visualization of a developing situation publicly available before, and a cursory glance shows that the data sources are at least one level beyond 'naked propaganda'...

Bookmarked!

mdb31··on Slack System Status
[deleted, it's quite obvious HN is not interested in actual discussion]
mdb31··on ZX Spectrum at 40: a look back
I sort-of get what you're saying here, I think, but I'm not sure you're right.

As an inquisitive young person, you are, quite likely, at some point confronted with something that seems like magic.

If you're truly (or perhaps excessively?) inquisitive, you try to dissect that magic. Sometimes that leads to true understanding, sometimes just to confusion, or at best the understanding that you don't understand.

The "home computers" of the 1980s were still simple enough to allow "true understanding". But only up to some point: I could find my way around a ZX Spectrum memory map just fine, but could I have built such a machine from scratch? No way!

In hindsight, I only understood a very small portion of the technology I was working with, even though that understanding was absolutely mindblowing at the time. Today, that portion would very likely have been "higher up the stack": let's say, I would be an absolute master of the DOM using Javascript, instead of a master of the ZX Spectrum ROM using Z80 assembly.

But would that portion be less "worthy" or less useful? I'm not so sure...

mdb31··on ZX Spectrum at 40: a look back
Yeah, that seems to have been a pretty popular book, but I've literally never seen it. At the time, no library near me had it available, and ordering it from the UK was just too expensive for 13-year-old-me. I did have my own ROM disassembly, in two school notebooks, that I still keep to this day. Mu handwriting was pretty bad already then, though, so I prefer to think of all this as "lost in time" anyway.

Decades later, I did (pre-)order and read "The ZX Spectrum ULA", which documents, in painful detail, the inner workings of the custom Ferranti chip that powered most of the Spectrum.

This really did drive home the message that, no matter how much I thought I understood the low-level workings of my Speccy, there were still many lower-level layers left to explore. Which, I guess, is the central lesson of IT...

mdb31··on ZX Spectrum at 40: a look back
I have very fond memories of the ZX Spectrum. By modern, or even contemporary, standards, it's a weirdly under-powered machine, yet it introduced a (mostly "continental") generation to gaming, programming and much more.

The built-in BASIC made the Spectrum very accessible. But it was also quite limited, mostly due to being very slow. But: the great thing was, all the machine code that processed said BASIC was right there, in the ROM, just waiting to be examined.

I still remember disassembling the machine code responsible for handling the "LOAD" and "SAVE" commands, which were an interface between memory and the tape deck (the only long-term storage available). It was surprisingly small and elegant, and easily modified to perform certain tricks, such as varying the baud rate of the cassette interface, the order in which bytes were loaded (allowing for cool effects like "the screen is populated, but not from top-to-bottom, but the other way around), and many other things.

And this was all waaaaay before the Internet, relying on (photocopies of) library books about the Z80 and magazine articles, which arrived late-if-at-all. At some point, I'm pretty sure I had memorized the purpose of every "OS-related" memory location of the Spectrum (all 16384 bytes of it).

The complexity of today's systems makes all of that impossible. But that's mostly nostalgia talking: the capabilities of the Spectrum would be laughed away (and rightfully so) these days.

mdb31··on React Native for Windows is helping Settings improve more quickly
The days when every new Windows feature came with a snazzy UI to configure it are long gone.

Realistically, Server 2012R2 was the last release that had full parity between features and matching configuration 'screens'.

Since that time (so: Server 2016, 2019 and 2022, and to a lesser extent the consumer SKUs), configuring new features has required PowerShell and/or WMI. This trend is unlikely to reverse anytime soon. Mostly because features are increasingly complicated.

With Windows 10 and, especially, 11, the GUI parts of the configuration have been redone on a "whatever looks good and is usable for 80% of non-advanced users" basis.

That this now requires "web" technologies is disappointing, but unsurprising. There just isn't a good "native GUI" story right now: not in the open source world, but especially not with Windows or macOS.

mdb31··on Where Did CP852 Come From?
It's quite likely that CP852 came from IBM, since they were the source of most localization/internationalization (L8N/I8N) data at the time.

Microsoft, basically, had no clue: they relied on local partners to request L8N-related features. Then, they tried to figure out if those requests made any sense. For some markets, like Japan, there were existing industry standards that made this easy-ish, but for most other markets, it was pretty much guesswork, and, based on expected dollar-value, they would send out consultants to try to figure things out.

So, why was IBM a valuable/likely data source? Simple: they had been selling typewriters into most markets since, like, forever. So, they had to manufacture Selectric "typing elements" (the wheels and/or balls that produced the actual characters) to match the local market needs.

CP852 is most likely a more-or-less literal mapping of the Selectric typing elements that were most popular in the "Eastern European" markets.

mdb31··on MikroTik authentication revealed
Yes, Mikrotik MAC-telnet works regardless of the IP configuration: it's technically broadcast UDPv4 to port 20561, but the address information in the protocol data is the only thing that's required for it to work.

So the IP addresses can be something invalid like 0.0.0.0, in which case you both need to be on the same L2 segment (bridged). But, it's also entirely possible to use valid IP source/destination addresses (which don't need to be exactly your addresses, just a combination that works in both directions across any routers involved, so Ethernet packets end up on the right segment -- this requires some NAT tricks, but in the end it does work...) for the same protocol to work in a L3 environment. Also, on an all-Mikrotik network, there's https://help.mikrotik.com/docs/display/ROS/RoMON, which, once you set it up, allows for even more interesting traffic flows.

My use case for MAC-telnet is "remote hands" provisioning of new/replacement routers and switches. The only thing the local IT resource needs to be able to do, is connect the equipment to a correct uplink port, after which things will usually work (if not, a factory defaults reset may be required).

At the moment, some minor manual configuration work using another Mikrotik box is still required to enable IPv6 and configure the correct VLAN, after which my scripts take over. If MAC-telnet authentication can now be automated as well (and testing that is next on my to-do list...), provisioning could be fully automated in most cases.

mdb31··on MikroTik authentication revealed
Oh, this is long-awaited, if it works. For context: Mikrotik uses some (semi-)proprietary, but pretty nifty protocols to manage their gear.

One of these protocols, MAC-telnet, has been reverse-engineered pretty extensively previously. But, due to a (not unreasonable) security-related upgrade, the login phase was changed, and 3rd-party implementations stopped working. Mikrotik has refused repeated requests to document this protocol.

The linked repository looks like it may re-enable MAC-telnet logins, which would be great for 3rd-party scripts and management solutions.

(Why? Because it allows you to connect to, and properly provision, any Mikrotik gear using your own scripts, just based on Layer-2 presence. This is very cool for many use cases...)

mdb31··on 20 Years of .NET
Really? You never had to change a single line of code in a servlet due to JRE/host environment changes?

I've had to migrate my server-side Java code at least twice in the last decade. But possibly I'm just not understanding the needful?

mdb31··on 20 Years of .NET
Well, I don't know what you consider "significantly sized enterprise platforms", so I can't really refute you on that. Maybe, possibly, include a small example here?

Your complaints about the "MVC middleware stack implementation" only underscore the fact that you're making unsourced allegations here. DotNET middleware has been remarkably stable, only requiring some minor adjustments to source code.

So, really, can you give me one, just one concrete example of how .NET has "costs big money for clients"?

Software maintenance costs money, yeah. In Java, in Golang, in (dare I say it?) Rust, in C#. But is the latter platform really that much worse than any of the former?

mdb31··on 20 Years of .NET
Your response is not only hyperbole, but also not very consistent with, like, reality.

If you've really used .NET "from beta", you'll know that the platform became a snoozefest around 4.5, only to be revived around Core 3.0. "Insanely rapid platform churn" it is not.

And abandonware? Silverlight, sure, not much future in that (although it still runs fine on its own) but how is Adobe Flash doing these days, talking about "other platforms".

Or Java Servlets? In-browser applets?

mdb31··on Span – An abstraction over all types of memory available to .NET programs
You can already pass big arrays to unmanaged code without copying just fine: allocate a GCHandle of type Pinned, and pass AddrOfPinnedObject as the pointer.

The use case for Span is more within the managed realm: it allows pointer-like manipulation of memory, without having to special-case it for each type.

And although anything with pointers is of course asking for trouble to some extent, you don't lose any safety in most scenarios (those not involving obvious giveaways like 'unsafe'...)

mdb31··on We are Microsoft. We are here to learn. How can we help you build mobile apps?
From the linked page: "Open only to legal residents of the 50 U.S. and D.C". So, no, apparently I can't...
mdb31··on Ask HN: A botnet may be attacking our site right now, how should we respond?
No personal experience with deploying Cloudflare, but they're pretty widely used (including by the very site you're on right now), so if you're really having urgent issues, I'd definitely give them a call.
mdb31··on Ask HN: A botnet may be attacking our site right now, how should we respond?
50-100 requests per second doesn't sound like an attack (or at least not a very scary one, depending on request size...), more like a crawler or prefetcher gone haywire.

Anyway, best way to figure out what's going on, is to generate a distinct list of IPs originating the bad traffic from your logs, and block those addresses at your firewall. If this doesn't stop the strange requests in 15 minutes or so, you may want to get some expert help.

Your hosting provider may be able to be of some assistance here, but that greatly depends on their level of clue: many budget providers will just drop you at the first sign of denial-of-service related trouble, so do keep that in mind.

Signing up for a specialized service like Cloudflare is probably your best bet, and should be pretty affordable as well (their web site lists their business plan with "advanced denial of service attack mitigation" as $200/month, and they suggest that if you call them they can have you protected pretty much immediately).

mdb31··on Who Are the H-1Bs?
Referring to people by their US visa class is, eh, a little demeaning. I’m not a H1-B, B-1 or L-1: I’m your coworker, a tourist, or just plain a human being.
← PreviousPage 3 of 4Next →