HNHacker News
TopNewBestAskShowJobs

mtabini

437 karma · joined January 2, 2012

Feel free to contact me at hello@t76.org!
submissionscomments
mtabini··on Your intellectual fly is open (2025)
You are not. I am in agreement with you :-)

My thought is that perhaps there is some utility to using AI to help in routine scenarios, such as for example when a language barrier prevents someone from explaining themselves well, or when they are struggling to find the right words to express themselves.

Primarily, I was trying to stay away from an absolutist view of the problem to see if there are circumstances in which AI can be useful even considering all its shortcomings. There seems to be a lot of “all or nothing” perspective on its use right now, and I was simply wondering whether it might be a better idea to take a more pragmatic approach.

We do this with a lot of tech in real life: You don't need to be an MD to decide to take an aspirin, or an F1 driver to take the car to the grocery store (well, maybe in some cities, but that's beside the point). The problem is not with using technology, but with abandoning your judgment to it.

mtabini··on Your intellectual fly is open when you use an LLM to author a post (2025)
I think it's good to be pragmatic about these things. To me, it's similar to wondering whether we insist that doctors learn to write well, or we just give them a computer so that the pharmacist doesn't have to play philologist with their scripts. The vast majority of communication is routine, and can probably be improved with automated tools.

Now, I also see the counterargument that, in the doctor example, the computer is simply a tool that improves a process rather than a crutch that replaces the underlying knowledge, but I suspect that, in a lot of cases, that's probably OK.

mtabini··on Your intellectual fly is open when you use an LLM to author a post (2025)
I published a magazine for ten years, and this was by far the hardest editing challenge we had; our authors were from all over the world, and some of them had to be pretty heavily edited because English was very much not their first language. Thankfully, we had really good editors who did a fantastic job of it… nothing would have killed us faster than a heavy-handed attempt at “normalizing” the content to a house style.

That said, context is also important. The vast majority of content of social media is of both low quality and marginal importance; style and character are important to make an impact, and AI is clearly not going to improve either.

On the other hand, functional communication, when the goal of the content is to simply pass information across and style is not as important, can, in my opinion, benefit from an AI polish, because so many people struggle with writing clearly. In those cases, I'd rather read slop I can understand than original content that is hard to parse, much like I'd rather read naïve code that you can easily follow than cleverly optimized code that is incomprehensible.

mtabini··on An Engineer's Guide to USB Typе-С (2024)
It's hard to make a sweeping statement, but I can tell you that I more or less use USB-C exclusively in all my hardware designs now, and I've found that most of these “decoy boards” work well enough. The model I use[1] most often supports basic the USB-C protocol well, is easy to solder to (and remove from) an existing PCB, and is pretty robust.

I cannot stress enough how convenient being able to “plug and play” USB-PD power in an existing project is. Whenever I send a finished device to a client, I no longer have to worry about having to source a compatible power brick, or about them misplacing it. Not to mention that, for the simpler projects, I can literally get a 20W power puck from IKEA that has really good performance and costs all of $5 (Canadian). On top of that, if I find that I need more voltage, I can just change a jumper on the decoy board and I'm ready to go.

The only thing I wish more of these boards came with is better overcurrent protection; with PPS so common these days, it would be pretty easy to let the user choose an appropriate current cutoff. Oh well!

[1] https://www.amazon.ca/dp/B0CNVN1N3J?ref_=ppx_hzsearch_conn_d...

mtabini··on An Engineer's Guide to USB Typе-С (2024)
Thank you! No videos yet, though both I and out beta testers have used Dr. PD to troubleshoot a bunch of devices. One of our testers actually develops USB-C sources, so it was very interesting to interact with them (and they found oh-so-many bugs :-) ).

There are some screenshots of the UI on the Github page[1], and I wrote a little bit about trying to figure out the mess of USB-C cables that I have accumulated over the years[2] to see which supports what capabilities.

I think some videos are a great idea… now that the device is done and we're starting to send review units out, hopefully I will have some time to actually shoot them :-)

[1] https://hackaday.io/page/399874-silence-the-usb-c-cable-spea... [2] https://hackaday.io/page/399874-silence-the-usb-c-cable-spea...

mtabini··on An Engineer's Guide to USB Typе-С (2024)
Bit of self-promotion: I spent the last year or so designing an open-source USB-PD protocol analyzer[1], and the complexity of the protocol can be mind-boggling. Most of the time, the communication between source and sink is really straightforward, but it can get amazingly complicated when both devices are dual-role or come from the same vendor[2].

As messy as it is, however, it's also a very useful protocol that allows even small players to take advantage of the same economies of scale that large companies can take advantage of. Pity that the communication often requires dedicated chips, though thankfully those are relatively inexpensive. I was able to get an RP2350 (the same MCU that's in the Raspberry Pi Pico 2) to interface directly with USB-PD, but they could have made it easier and more accessible.

[1] https://github.com/T76-org/drpd or https://www.crowdsupply.com/t76-org/dr-pd [2] https://hackaday.io/page/399885-a-mac-and-an-ipad-walk-into-...

mtabini··on An Engineer's Guide to USB Typе-С (2024)
Not only that, but EPR contracts must be actively maintained in order to remain in effect. The sink needs to send a ping to the source every ~500ms, or the source pops out of EPR mode and forces a renegotiation. This ensures that, if the sink crashes, the source doesn't keep pumping power into a device that can't take it anymore.
mtabini··on USB Power Delivery: Plugging into the Benefits
Can I offer a counterpoint? Much like OG USB put a 5V supply within everyone's reach, USB-PD has made programmable, higher power supplies available to everyone. That's a big deal, because PSUs are an expensive portion of a product, especially for small manufacturers and hobbyists. Having a dedicated standard that supports multiple voltages and currents allows small players to take advantage of the same economies of scale as the largest electronics manufacturers.

Case in point, IKEA will happily sell you a very well built 20W power supply that provides 5, 9, 12, or 15V for less than $5 here in Canada, and you can get a similar price from legitimate Asian distributors, even when buying in limited quantities. If you're working on a small-batch electronic product, that's a boon to your BOM; if you had to go out and source a dedicated barrel-jack PSU with the same capabilities, it'd cost much more, and you don't know what kind of quality you'd be getting.

Where the standard really falls on its face, IMO, is in its opacity. You can get a chip that does the PD negotiation for pennies, but there is no way to inspect the protocol without shelling out thousands for a dedicated analyzer, so when things don't work, it's really hard to troubleshoot the reason.

(Disclaimer: I'm working on an open-source protocol analyzer, so this probably colours my view on the matter a little.)

mtabini··on USB Power Delivery: Plugging into the Benefits
I did, you're absolutely right. Thanks for the correction!
mtabini··on USB Power Delivery: Plugging into the Benefits
USB-PD 3.1 provides both a Get_Battery_Cap message, which asks the sink to tell the source the capacity of its battery) and a Get_Battery_Status message, which asks the sink to inform the source about the current charge of its battery.

Here's an example capture of an exchange between my MacBook Pro and iPad: https://imgur.com/a/8rZlN9X

The iPad responds to Get_Battery_Cap with Battery_Capabilities, which reports the total capacity in Wh:

USB Vendor ID: 0x05AC Product ID: 0x0000 Design capacity: 280 Last full-charge capacity: 280 Battery reference: valid

And then when the MBP asks for battery status, the iPad returns a Battery_Status message:

Battery is present. Present capacity: 14.2Wh Charging state: charging.

Later on, as the charging continues, the iPad will issue an Alert message:

Reported alerts: Battery status changed. Affected batteries: Fixed battery slots: 1

And then the MBP will send a Get_Battery_Status again, and so on. (Example capture here: https://imgur.com/a/TI5maV0

What's really cool is that this exchange happens both ways—the iPad also sends a Get_Battery_Cap message to the MBP, because it is also capable of acting as a source, and, if the laptop's battery drops sufficiently low, the source/sink roles may swap (using a DR_Swap message) so that the iPad ends up charging the MBP!

mtabini··on Ask HN: What Are You Working On? (April 2026)
https://www.crowdsupply.com/t76-org/dr-pd

Dr. PD is an open-source USB-C Power Delivery analyzer and programmable sink. It can sit inline between a USB-PD source and sink to show you the communication between them, or connect directly to a source and emulate a sink so you can characterize chargers and power supplies.

The goal of the project is to make serious USB-PD analysis more accessible. The hardware, firmware, and host software are all open source. The control software runs locally in Chrome or Edge with no drivers or installation required, and the platform also provides Python, JavaScript, SCPI, and USBTMC interfaces for automation.

(Sorry that I don't have a link to the GH repo yet, but you can follow the project on https://hackaday.io/project/205495-dr-pd. Also, if you read this far, I'm looking for a few beta testers. Reach out if you're interested!)

mtabini··on Ask HN: Who is hiring right now?
Noom | Senior Data Science/Full Stack/Backend/Android/iOS/QA positions | REMOTE or HQ | FULL-TIME | https://noom.com

At Noom, we use scientifically-proven methods to help users get a handle on chronic medical conditions like obesity, diabetes, and heart disease. We use a variety of technologies, and get to work on hard problems that range from data warehousing to running experiments on mobile devices.

Our engineering team is expanding, and we have openings for a number of positions that include backend and mobile engineering. Our offices are in NYC, but we are a remote-first organization (some 90% of our team is remote) and are happy to consider candidates anywhere.

Here are some links where you can apply:

- Sr Data Scientist - https://grnh.se/2850e1a91

- Sr Full Stack Engineer - https://grnh.se/4cd542051

- Sr Backend Engineer - https://grnh.se/bcdd69491

- Sr iOS Engineer - https://grnh.se/8009698e1

- Sr Android Engineer - https://grnh.se/ff4d1d451

- Mobile QA Automation Engineer - https://grnh.se/1677c07a1

Our stack includes Python, React, Kotlin, Swift, and Go, all hosted on AWS.

I'm Noom's VP of Engineering -- feel free to drop me a note if you have questions; I'm mt at noom dot com.

mtabini··on Ask HN: Who is hiring? (March 2020)
Noom | Senior Data Science/Full Stack/Backend/Android/iOS/QA positions | NYC or REMOTE | FULLTIME | https://noom.com

At Noom, we use scientifically-proven methods to help users get a handle on chronic medical conditions like obesity, diabetes, and heart disease. We use a variety of technologies, and get to work on hard problems that range from data warehousing to running experiments on mobile devices.

Our engineering team is expanding, and we have openings for a number of positions that include backend and mobile engineering. Our offices are in NYC, but we are a remote-first organization (some 90% of our team is remote) and are happy to consider candidates anywhere.

Here are some links where you can apply:

- Sr Data Scientist - https://grnh.se/2850e1a91

- Sr Full Stack Engineer - https://grnh.se/4cd542051

- Sr Backend Engineer - https://grnh.se/bcdd69491

- Sr iOS Engineer - https://grnh.se/8009698e1

- Sr Android Engineer - https://grnh.se/ff4d1d451

- Mobile QA Automation Engineer - https://grnh.se/1677c07a1

Our stack includes Python, React, Kotlin, Swift, and Go, all hosted on AWS.

I'm Noom's VP of Engineering -- feel free to drop me a note if you have questions; I'm mt at noom dot com.

mtabini··on Ask HN: Who is hiring? (August 2019)
Noom | Data/Backend/Android/iOS/Staff positions from Jr. to Director | NYC or REMOTE | FULLTIME | https://noom.com

At Noom, we use scientifically-proven methods to help users get a handle on chronic medical conditions like obesity, diabetes, and heart disease. We use a variety of technologies, and get to work on hard problems that range from data warehousing to running experiments on mobile devices.

Our engineering team is expanding, and we have openings for a number of positions that include backend and mobile engineering. Our offices are in NYC, but we are a remote-first organization (some 90% of our team is remote) and are happy to consider candidates anywhere.

Here are some links where you can apply:

- Dir of Data and Platform Engineering - https://grnh.se/ce83d4a91

- Data Engineer - https://grnh.se/fa9f2f811

- Full Stack Engineer - https://grnh.se/7ee80e091

- Staff Engineer - https://grnh.se/1c6640381

- Sr Android Engineer - https://grnh.se/98b810ee1

- Sr iOS Engineer - https://grnh.se/1de847dc1

- Sr FrontEnd Engineer - https://grnh.se/e06087021

- Sr Backend Engineer - https://grnh.se/1c8844bb1

Our stack includes Python, React, Java, and Go, all hosted on AWS.

I'm Noom's VP of Engineering -- feel free to drop me a note if you have questions; I'm mt at noom dot com.

mtabini··on Ask HN: Who is hiring? (July 2019)
Noom | Data Engineer, Staff Engineer, Sr. Android Engineer | NYC or REMOTE | FULLTIME | https://noom.com

At Noom, we use scientifically-proven methods to help users get a handle on chronic medical conditions like obesity, diabetes, and heart disease. We use a variety of technologies, and get to work on hard problems that range from data warehousing to running experiments on mobile devices.

Our engineering team is expanding, and we have openings for a number of positions that include backend and mobile engineering. Our offices are in NYC, but we are a remote-first organization (some 90% of our team is remote) and are happy to consider candidates anywhere.

Here are some links where you can apply:

- Data Engineer - https://grnh.se/fa9f2f811

- Staff Engineer - https://grnh.se/1c6640381

- Sr. Android Engineer - https://grnh.se/98b810ee1

Our stack includes Python, React, Java, and Go, all hosted on AWS.

I'm Noom's VP of Engineering -- feel free to drop me a note if you have question; I'm mt at noom dot com.

mtabini··on Ask HN: Who is hiring? (May 2019)
Noom | Fullstack, Frontend, DevOps, QA | NYC or REMOTE | FULLTIME | https://noom.com

At Noom, we use scientifically-proven methods to help users get a handle on chronic medical conditions like obesity, diabetes, and heart disease. We use a variety of technologies, and get to work on hard problems that range from data warehousing to running experiments on mobile devices.

Our entire engineering team is expanding, and we have openings for a number of positions that include backend and frontend engineering, data analysis, and product management. Our offices are in NYC, but we are a remote-friendly organization (some 90% of our team is remote) and are happy to consider candidates anywhere.

Here are some links where you can apply:

- Dev Ops engineer - https://grnh.se/c1da8a701

- Full Stack engineer - https://grnh.se/3f36d0b01

- Sr Front End engineer - https://grnh.se/f0a3b8271

- Data Engineer - https://grnh.se/17738f841

- Sr Technical Program Manager - https://grnh.se/94cc07e01

- Sr Product Manager - https://grnh.se/5fd621321

Our stack includes Python, React, Java, and Go, all hosted on AWS.

I'm Noom's VP of Engineering -- feel free to drop me a note if you have question; I'm mt at noom dot com.

mtabini··on Ask HN: Who is hiring? (April 2019)
Noom | Fullstack, Frontend, DevOps, QA | NYC or REMOTE | FULLTIME | https://noom.com

At Noom, we use scientifically-proven methods to help users get a handle on chronic medical conditions like obesity, diabetes, and heart disease. We use a variety of technologies, and get to work on hard problems that range from data warehousing to running experiments on mobile devices.

Our entire engineering team is expanding, and we have openings for a number of positions that include backend and frontend engineering, data analysis, and product management. Our offices are in NYC, but we are a remote-friendly organization (some 90% of our team is remote) and are happy to consider candidates anywhere.

Here are some links where you can apply:

- Fullstack: https://grnh.se/3f36d0b01

- Sr. Frontend: https://grnh.se/f0a3b8271

- DevOps: https://grnh.se/c1da8a701

- QA Analyst: https://grnh.se/b56b27e51

Our stack includes Python, React, Java, and Go, all hosted on AWS.

I'm Noom's VP of Engineering -- feel free to drop me a note if you have question; I'm mt at noom dot com.

mtabini··on Ask HN: Who is hiring? (January 2019)
Noom | Fullstack, Backend, Android | NYC or REMOTE | FULLTIME | https://noom.com At Noom, we use scientifically-proven methods to help users get a handle on chronic medical conditions like obesity, diabetes, and heart disease. We use a variety of technologies, and get to work on hard problems that range from data warehousing to running experiments on mobile devices.

Our entire engineering team is expanding, and we have openings for a number of position that range from frontend to backend work. Our offices are in NYC, but we are a remote-friendly organization (half of our engineering team is remote) and are happy to consider candidates from anywhere.

You can see our openings (alongside a brief description of some of our perks, like our on-site chef, flex hours, and much more) at https://www.noom.com/careers-listings/?department=engineerin...

I'm Noom's VP of Engineering -- feel free to drop me a note if you have question at mt at noom dot com.

mtabini··on Ask HN: Who is hiring? (October 2018)
Sorry, the URL got weirdly truncated. It should be https://web.noom.com/careers-listings/?department=engineerin...
mtabini··on Ask HN: Who is hiring? (October 2018)
Noom | Fullstack, Backend, iOS, Data Analysis, Product Management | NYC or REMOTE | FULLTIME | https://noom.com

At Noom, we use scientifically-proven methods to help users get a handle on chronic medical conditions like obesity, diabetes, and heart disease. We use a variety of technologies, and get to work on hard problems that range from data warehousing to running experiments on mobile devices.

Our entire engineering team is expanding, and we have openings for a number of position that include backend and frontend engineering, data analysis, and product management. Our offices are in NYC, but we are a remote-friendly organization (some 90% of our team is remote) and are happy to consider candidates anywhere.

You can see our openings (alongside a brief description of some of our perks, like our on-site chef, flex hours, and much more) at https://www.noom.com/careers-listings/?department=engineerin....

I'm Noom's VP of Engineering -- feel free to drop me a note if you have question at mt at noom dot com.

mtabini··on Ask HN: Who is hiring? (August 2018)
Noom | Fullstack, Backend, iOS | NYC or REMOTE | FULLTIME | https://noom.com

At Noom, we use scientifically-proven methods to help users get a handle on chronic medical conditions like obesity, diabetes, and heart disease. We use a variety of technologies, and get to work on hard problems that range from data warehousing to running experiments on mobile devices.

Our entire engineering team is expanding, and we have openings for a number of position that range from frontend to backend work. Our offices are in NYC, but we are a remote-friendly organization and are happy to consider candidates from anywhere.

You can see our openings (alongside a brief description of some of our perks, like our on-site chef, flex hours, and much more) at https://www.noom.com/careers-listings/?department=engineerin....

I'm Noom's VP of Engineering -- feel free to drop me a note if you have question at mt at noom dot com.

mtabini··on [dead]
I'm impressed with the clarity of the interview. As it happens, the host sounds like he's been doing radio for many years. I predict this year more radio professionals start to jump ship from radio into podcasting.
mtabini··on Facebook lurking makes you miserable, says study
I have to agree and this is the main reason why I went extreme and deleted my profile. My life was at a low point and seeing everybody's high point of the day made it even worse; it was a decision that took less than a second and 90 seconds later my profile was deleted. To be honest, I regret it a bit now.
mtabini··on Ask HN: Who is hiring? (December 2016)
The Muse | Fullstack Engineer, Data Engineer | New York City, Remote, Visa | Full-time | NYC

At The Muse, we offer advice, coaching, and a job experience that's actually engaging and doesn't suck; we reach millions of users every month with an engineering approach that is grounded in data analysis and best practices.

We're looking for full-stack and data engineers. For more info, drop me an e-mail at marco@themuse.com, or apply here:

https://www.themuse.com/jobs?company=The%20Muse&filter=true&....

We use a number of technologies like Python 3, Tornado, Go, React, but are happy to consider engineers with experience in Rails, Java, devops and data platforms like Redshift, PostgreSQL, and ElasticSearch.

Our engineering team is growing all the time, with plenty of opportunities for leadership and mentorship roles, funding for conferences and training, or to pick up new skills if that interests you.

We frequently contribute to open-source, give our engineers a great deal of agency in picking the problems they want to work on, and have a strict no-asshole policy.

mtabini··on Our IQs have never been higher – but it hasn’t made us smart
> why should I read?

Because reading is not just a utilitarian activity. Reading widely—things that may not be immediately useful, things that may be against your belief, things that may just turn out to be completely wrong—is an important step towards forming a critical appreciation of anything you may encounter.

Personally, I've long come to realize that much of my attitude towards everything from work to politics has been shaped by reading materials that often covered wholly unrelated topics. More importantly (and much to my chagrin), it seems that many crucial lessons came from works that I outright hated and was forced to drudge through against my will.

I don't mean to discount your conclusion: Almost always, almost everybody doesn't know what they're talking about. But almost always, almost everybody is a little right, and bits and pieces you pick up from the most unusual places will inform your solution to a problem many years down the road, or at least remind you that every story has more than one side.

mtabini··on Ask HN: Who is hiring? (April 2016)
The Muse | NYC | Fullstack, Backend (onsite or remote) | Frontend, BI (onsite only)

At The Muse, we offer advice, coaching, and a job experience that's actually engaging and doesn't suck; we reach millions of users every month with an engineering approach that is grounded in data analysis and best practices.

We're looking for engineers across our entire stack—backend, full stack, and frontend. For more info, drop me an e-mail at marco@themuse.com, or apply here:

https://www.themuse.com/jobs?company=The%20Muse&filter=true&...

We use a microservice infrastructure based on Python 3 and Tornado, Mithril, and CoffeeScript. We are happy to consider engineers with experience in Rails, Java, and Go, as well as devops and data science specialists.

Our engineering team is growing all the time, with plenty of opportunities for leadership and mentorship roles, or to pick up new skills if that interests you. We frequently contribute to open-source, give our engineers a great deal of agency in picking the problems they want to work on, and have a strict no-asshole policy.

mtabini··on Ask HN: Who is hiring? (February 2016)
The Muse | NYC (onsite, remote, visa)

At The Muse, we offer advice, coaching, and a job experience that's actually engaging and doesn't suck; we reach millions of users every month with an engineering approach that is grounded in data analysis and best practices.

We're looking for engineers across our entire stack—backend, full stack, and frontend. For more info, drop me an e-mail at marco@themuse.com, or apply here:

https://www.themuse.com/jobs?company=The%20Muse&filter=true&...

We use a microservice infrastructure based on Python 3 and Tornado, Mithril, and CoffeeScript. We are happy to consider engineers with experience in Rails, Java, and Go, as well as devops and data science specialists.

Our engineering team is growing all the time, with plenty of opportunities for leadership and mentorship roles, or to pick up new skills if that interests you. We frequently contribute to open-source, give our engineers a great deal of agency in picking the problems they want to work on, and have a strict no-asshole policy.

mtabini··on Ask HN: How to Be a Good Technical Lead?
In no particular order:

1. Listen before you speak. The people you manage are prone to giving your opinion more weight than it deserves.

2. Give your subordinates problems, not solutions. People like to own a task, not to be told what to do; treating them like adults and professionals empowers them and brings out their potential. Besides, if one person only ever makes all the decisions, no decision can be better than that one person's knowledge. If you're afraid of delegation, institute a tight review loop to ensure that people don't go off-track.

3. You're a facilitator, not a doer. People will come to you with their problems, and you must be available at all times to help them through it. As someone else has pointed out, your productivity is secondary to that of the team. It's your job, among other things, to ensure that your team has a good working environment, including good tools, practices, and access to uninterrupted “flow” time.

4. Be aware of politics. The moment you manage a team, politics become a part of your daily job. This is not a bad thing—“politics” just means managing interpersonal relations; it becomes a bad thing when you ignore it.

5. Never be in a position to take. Success belongs to your teammates; failure is all yours.

6. Face problems head-on. People don't like confrontation, and let problems fester until it's too late to fix them. Instead, provide frequent one-on-one time with all your teammates, exhort them to confide in you, and show them that you're trustworthy. Also see #1.

7. Offer clarity. Explain what you expect others to do in a measurable way to make it possible for both you and your team to understand how well everyone is doing. You can use a method like OKR[0] to track your goals internally.

[0] https://en.wikipedia.org/wiki/OKR

mtabini··on Good Product Manager, Bad Product Manager (1996) [pdf]
> Won't nail down the customer's actual problem, describe it clearly to you and let you come up with a solution. They will just pass on the customer's proposed solution and insist that you build it.

It's actually a bit worse than that. Customers almost never know their problems; instead, they understand their problems through the accumulated knowledge of their profession, and have a very hard time stepping out of “the way things are done” to nail down their ultimate goals.

One of our biggest challenges as developers is that software engineering is very much a meta-profession: Being fully competent in computer science is only useful if you can apply that competence to real-world problems, and that inevitably means having to become expert enough in a field to which you may never have had any exposure.

A good PM understands this and turns development into an iterative process in a tight loop with customer feedback: You push the project forward a little, check with customers, apply their feedback, and lather-rinse-repeat until you've come up with a good solution—one that typically innovates on the status quo.

A bad PM tries to spec everything ahead of schedule and never really gets off the ground, her best possible outcome being automating existing processes at the tail end of a waterfall-induced nightmare.

A worse PM is overwhelmed and avoids nailing down details, seeks no customer involvement, and leaves things to fester for weeks without any feedback. I don't know anyone who enjoys being on the poor team tasked with dealing with that kind of work.

Incidentally, this is what I've always taken agile development to mean: It's not about stand-ups and kanban boards, but rather about acknowledging and embracing the fact that programming is an inherently inexact science.

mtabini··on Hackers Remotely Attack a Jeep on the Highway
I don't think this has necessarily anything to do with engineering competence.

From a business perspective, security isn't a marketable feature until it becomes a problem—you don't install safety belts, or airbags, or protection against malware until after people start suffering from their absence in a vehicle.

Why? Because while you're busy building a well-secured system, your competitors are busy implementing new features that give them an actual advantage in the marketplace. As unfortunate as it might be, consumers tend to understand things like “remotely start your car with your phone” better than “your ability to brake won't be taken away from you while you're barrelling down the highway at 70 mph.”

It's sad and more than a little scary, but it's also nothing really new. Computer security, at least in the consumer sector, wasn't really a feature until viruses started showing up in the Eighties, and Internet security wasn't really a feature until the average Windows user's PC was getting taken over remotely the moment it was connected to the Net. Even Apple has only been able to tout security and privacy as a feature in its products by juxtaposing it to Google's business model—had the latter not existed and its data grab become part of public discourse, I doubt that Cupertino would have been able to make so much noise about it.

So, it's perfectly possible that every engineer and manager who worked on these systems is really quite competent and perfectly aware of the potential for security flaws (indeed, I doubt that they would have been able to make something so complex work otherwise), and still the sum of all the decisions made and market pressures applied caused the resulting product to be so vulnerable despite everyone's best intentions. It's not because people don't care or don't know, but rather because there are only so many resources available, and the market has pushed them all in a specific direction that happens to be away from security.

But this is also why we need this kind of research. Now that these problems are out in the open, and politicians are starting to take notice, security will become a feature that the public will care about, and, hopefully, car manufacturers will start adopting (or be forced to adopt) better standards.

Page 1 of 2Next →