HNHacker News
TopNewBestAskShowJobs

nerdile

288 karma · joined June 9, 2018

submissionscomments
nerdile··on Costco’s butter recall, explained
Equally disappointing: the situation being described, the quality of TFA.
nerdile··on Costco’s butter recall, explained
This article must have been written by AI. I suppose it's my fault for clicking through a Forbes link.
nerdile··on Understanding Round Robin DNS
It's putting reliability in the hands of the client, or whatever random caching DNS resolver they're sitting behind.

It also puts failover in those same hands. If one of your regions goes down, do you want the traffic to spread evenly to your other regions? Or pile on to the next nearest neighbor? If you care what happens, then you want to retain control of your traffic management and not cede it to others.

nerdile··on Spotify HR chief – remote staff aren't 'children', reaffirms work-from-anywhere
But why?
nerdile··on The Forest Service Is Losing 2,400 Jobs–Including Most of Its Trail Workers
I would like to share this link with my outdoorsy friends, but the inability to opt out of cookies triggers my morals.

Dark pattern: "To opt out, click the link in the footer that you can't reach because this popup blocks it until you accept all the cookies"

nerdile··on iOS 18 breaks IMAPS self-signed certs
TOFU for invalid/untrusted certificates is the equivalent of "go there anyway" in a browser Very different than explicitly trusting a Private CA. It means that skilled attackers can rely on unskilled users clicking the "trust me, it's fine" button. All so that someone skilled enough to set up their own email server and certificates doesn't have to configure their system securely?

This is about making bad things harder for unskilled users at the cost of raising the standard for service providers. If you can set up an email server, you can use easyrsa or step-ca or some manual openssl to create your own root CA. Or, register your self-signed email server as a trusted root CA.

Personally, I use easyrsa for my internal CA (with domain path constraints because I'm paranoid) and letsencrypt for my mail server, but I require VPN access to the user ports on the mail server.

nerdile··on iOS 18 breaks IMAPS self-signed certs
So in summary: iOS used to accept untrusted certificates, yikes! Now, it validates the server cert, and people are upset? This blatantly insecure thing is broken now and the posters don't want to set it up securely?

It seems like these people are just struggling with how to properly set up their email server and clients when using a private CA. If you're going to use your own CA, then configure your client to trust it. The rest of us should be able to enjoy secure defaults and not have to worry about our less informed family members being tricked into bypassing basic security protections like TLS validation.

nerdile··on Air Con: $1697 for an on/off switch
I'm thankful my husband knows I would never allow such a system to be installed in my home.
nerdile··on Rabbit data breach: all r1 responses ever given can be downloaded
Casually writing code and writing code that securely handles customer data and maintains availability for something you're selling are two different things.
nerdile··on Multiple Regions, Single Pane of Glass
I can see why nobody's really discussing this.

TL;DR: "infra" product trades off availability for convenience instead of letting their customers decide

> any unavailability of Aurora in the primary hub region would prevent customers from creating new clusters in all regions, but existing clusters would continue working just fine. We felt like this was an acceptable trade off.

Ok. At least you're upfront about it.

nerdile··on Microsoft breached antitrust rules by bundling Teams and Office, EU says
By charging the same amount for a bundle of Office + Teams and a lesser amount for Office without Teams.
nerdile··on Gilead shot prevents all HIV cases in trial
The point is that in the scenario being described, where the woman feels she needs "permission", the man's perspective is... if you were taking this, what does that say about ME? What does that say about what you think about ME? The decision would be about him, not her. How could it be about her? Wait, if it's not about ME, who else do you need this for? MY wife would never need such a thing.

It is easy to avoid stigma and shame through denial. The woman would be well aware that he would not approve such a thing and would take it in secret.

nerdile··on Microsoft Issues New Warning for 70% of All Windows Users
Idk I just installed Debian on a new laptop and installed Steam and had to ask my friends, how do I turn on Proton to get more of my games to run? I figured it was complicated... It was a checkbox O_O

Edit: but yeah, peripherals will be the tricky part

nerdile··on Microsoft Issues New Warning for 70% of All Windows Users
This is Forbes gracefully telling you that if you won't take their ads, then they don't want to give you their sloppy resummarization of someone else's article.

Also, lol: Microsoft: Windows 11 is an essential update to Windows 10 Forbes: Ads are an essential part of our articles

nerdile··on I made an open source Windows app to rewind and search everything on screen
The easiest way to find an app that does X, is to build a new one and then post it to HN and check the comments.
nerdile··on German state ditches Microsoft for Linux and LibreOffice
When the reverse happens, it generally doesn't make the news.
nerdile··on Why isn't the <html> element 100% supported on caniuse.com?
Hint: check the blog posts. As recent as October 2023.
nerdile··on The Undercover Generalist
Are you a tech generalist, or a failed specialist? Are you a Renaissance man, or a dilettante?

It's easy to identify as a generalist. How do you know if you're a good one? How can a hiring manager figure out if you're a good one?

You're being hired to do specific work, unless you're coming through a recent-grad or other entry-level pipeline. You will be evaluated on specific technical competencies, because that's harder to fake. You need to show your ability to master at least one stack, language, framework, system, or technical area.

Your specialized skills demonstrate prior mastery and an ability to do the kind of work they need you for. Your generalist skills will show through in the quality of your work and ability to influence broadly.

So no, nobody's hiring someone who specializes in being a generalist. But, they are promoting them.

nerdile··on NSA Buys Americans' Internet Data Without Warrants, Unclassified Letter Says
Why would it be legal for a person or company to buy this publicly offered information but illegal for the government?
nerdile··on The X220 ThinkPad is the best laptop
Anecdotal, but my X220 Tablet suffered a complete system board failure within five years. Shortest usable life out of all the ThinkPads I've owned and repaired. Loved the form factor but just didn't last very long.
nerdile··on Invisible Bunnies That Power World of Warcraft (2017)
For Android, Edge and Opera both have ad blocking built-in. It's comments like these that remind me what I'm (not) missing.
nerdile··on The surprisingly subtle ways Microsoft Word has changed how we use language
> "Take the word "trialing/trialling" for instance. "Trialing" is considered the US-English spelling."

That would be like saying that "lory" is considered the US-English spelling of "lorry". "Trialling" is not something people say in the US. We say "trying out".

nerdile··on Cloud, why so difficult? (2022)
> I disliked C++ because abstractions are leaky. So I am building a new abstraction on the cloud.

Oh boy, buddy. Let me know how that works out for you.

I've worked on app code, OS code, on-prem services, datacenter services, cloud on Azure and AWS. No matter what your platform, someone has to do the hard work to make the inner loop quick and the deployment process reliable. But no matter what, the abstractions are leaky, and the engineers who grok the underlying platform have the fast cycle times, and the ones who don't, are frequently blocked and need help from those who do.

Building on CDK now, I can build my code and run all my unit tests in under a minute, and deploy via CDK and run all my integration tests in under five. Since I'm focusing on microservice components with independent delivery, that's ok. Obviously, the monoliths are more complex and tougher.

I'm not sure how a new language and abstraction are going to help here. (Sorry, that's what I would say to a new hire on my team to be gentle. What I mean is, sorry this won't help.)

(Also, CDK is a mess because the underlying CFN techs are inconsistent in their adoption. SNS being one of the worst offenders.)

nerdile··on What you give up by moving into engineering management
I think the author's experience is more true in smaller companies or startups. In the big tech companies especially, high-band senior or principal engineers are expected to lead through influence (without being anyone's boss) and have to make these exact same tradeoffs effectively to succeed. You can coast as a senior in many places if you want to just deliver by yourself, but you won't get further.

Also note that the author points out that he chose to make many of these tradeoffs not from being a manager, but when he got older and chose to refocus on his family. This is a tradeoff many people have to make whether they are a people manager or not.

nerdile··on Amazon’s big dreams for Alexa fall short
Why this story? Why now? Nothing new, no new insight from FT. I assume people just really want to share their opinion about voice assistants and Alexa?
nerdile··on My daughter's school took over my personal Microsoft account
Yes, it's confusing that the UI doesn't highlight that "Jeff's MSA" and "Jeff's MSA at This School" are different accounts when it makes statements about the school owning the account. By adding him, the school set up a "Jeff at This School" account (a unique ID inside their Azure Active Directory) which Jeff can access using his MSA account. They didn't take any ownership over his MSA, but they do control the data for his school account (i.e. anything he creates in their Azure Portal, SharePoint, etc.)

And then Jeff is confused about the state of his account. Keep in mind that he's using a developer tool (the Azure portal) and account federation is not a beginner-level feature of Azure AD. There are sharp edges. He just jumped to a lot of conclusions and wow the Fud level on this comments thread is off the charts.

I know this because I set up an OAuth2 based web portal for my friends to access my Minecraft server using Azure AD B2C and by god the hardest part was figuring out how to explain the login experience to users, and disable the secondary 2FA requirements for MSA/Gmail users (because I know my friends are smart enough to use 2FA)

nerdile··on My daughter's school took over my personal Microsoft account
No
nerdile··on My daughter's school took over my personal Microsoft account
If you want to see a real mess:

* Create a consumer MSA based on a Gmail account

* Invite that MSA into an AzureAD directory

* Try to sign in as that user to that directory.

Good luck!

nerdile··on My daughter's school took over my personal Microsoft account
Why didn't you just click Change Directory in the Azure portal and go back to your personal AzureAD where you can create your app registrations?

What has happened here is that you have essentially two accounts: One is your consumer MSA, and the other is an account in the school's Azure AD instance that uses federated sign-in with an external account (your MSA). Except, the real mess comes from the fact that there's one login page for both, and sites such as the Azure portal that support both identities and can't really tell which one you expect to assume. Plus, the Azure portal lets you switch between Directories at any time.

You can:

* Sign out completely (login.microsoftonline.com/logout.srf) and sign back in. The reason the sign-in page asks for your sign-in email first is because then it uses that to decide which directory (MSA or someone's AAD) to sign you into

* Change directories - (in fact I'd recommend creating your own Directory instead of using the one that was automatically created for you from your MSA name)

nerdile··on My network home setup – v4.0
In the US when a device is "on the fritz" it is failing intermittently, and the classical solution is to smack it firmly until it works. I suppose a Fritzbox might be perpetually on the fritz.
← PreviousPage 2 of 3Next →