HNHacker News
TopNewBestAskShowJobs

netdog

110 karma · joined January 16, 2010

submissionscomments
netdog··on Ask HN: Who wants to be hired? (May 2019)

  Location: TX, USA
  Remote: Yes
  Willing to relocate: Yes, to MX, CL, or AR.
  Technologies: Linux, C++, Python, TCP/IP, 3G/4G networks, PostgreSQL
  Résumé/CV: Not published to the world. I will provide to inquirers.
  Email: hg@netdog.org
I have 20 years of experience in systems and engineering software development, system design, data modeling and telecom networks. This includes managing engineering projects and teams, and related business efforts such as proposal development, product management, and technical support.

The last 8 years have been in the telecom industry, the last 4 in wireless/mobile.

I'm interested in a Lead/Principal/Staff/Architect role, where my years of experience are needed.

I'm also open to contract work, and travel to LatAm.

Please don't contact me about opportunities related to: Ads, Bitcoin, Scraping, User tracking, Gambling.

netdog··on The Last Invention of Man
The doomsday title reminded me of the world's last C bug:

  while (1)
  {
      status = GetRadarInfo();
      if (status = 1)
          LaunchMissiles();
  }
netdog··on An update on our commitment to fight terror content online
Bibles don't kill people. People kill people.
netdog··on Things Unix can do atomically (2010)
The GCC Atomic Builtins mentioned in the article are not specific to Unix. They are compiler constructs, and depend on specific architecture hardware support. All x86 CPUs have such support for some years now. So these atomic operations can also be used in non-Unix software running on x86 CPUs.

The GCC documentation lists other non-intel architectures which also have the features required to support the atomic built-ins.

netdog··on TTIP explained: The secretive US-EU treaty that undermines democracy
> The world is not run by mustache twirling villains who get sustenance from the tears of "the people."

Actually, yes, about half of it is. Cuba, China, North Korea, Viet Nam, almost all the Middle East, two thirds of Africa, Russia, ...

See https://en.wikipedia.org/wiki/Democracy_Index for an overview

netdog··on Firefox Bugzilla: Remove Pocket Integration
A remembrance of Zawinski's law seems apropos here.
netdog··on Tmux has left SourceForge
> I'm not saying github will be around forever, but I highly doubt they'll make the same mistake sourceforge is making now.

Github could be sold, just like Sourceforge was sold, and the new owners could behave very differently from the current owners.

netdog··on DEFCON Router Hacking Contest Reveals Major Vulnerabilities
Every SoC has a different kernel, heavily patched, with drivers specific to the SoC. The SoC vendor has an army of paid programmers developing this software for every SoC they make.

These Soc vendors have to start working on a new kernel long before the chip is released, as they need working software by the time the chip goes to market (to offer the router makers). Broadcom's business depends on this. They will not simply hope some loose-knit group of volunteers will timely produce software which will help them sell their new chips.

And it's not realistic for the open router project to do this much work. It would require cooperation from the SoC vendors, providing free and early access to their kernel driver source and complete documentation for their chips. I don't see this happening.

At best the open router project could release software for hardware which is already a year or two old.

Sorry to be such a pessimist, but the incentives to make this work are just not there for the businesses involved.

netdog··on DEFCON Router Hacking Contest Reveals Major Vulnerabilities
I think the widespread insecurity of home routers will not improve anytime soon.

Background: I work at a company which makes a "home router". It's not one you will find at a big box store, but internally it's not much different.

Most of these routers are built from a MIPS SoC manufactured by Broadcom, Atheros, or Marvell. Since their business is selling chips, not routers, these SoC companies need to make it easy for your LanWan Company startup to choose to use their chipset.

So these SoC companies will give you a reference hardware design. They will also give you a completely functional software package with Linux kernel, drivers for all the peripherals (Wi-Fi, ethernet, etc.), all the necessary user space utilities, a complete GCC cross-compiler toolchain binary which runs on Ubuntu, and a bad web app. You can literally unzip this package, run 'make', and end up with a functional filesystem image ready to flash onto the reference board.

So LanWan startup can start manufacturing routers with only one or two software devs who know some C and a part-time hardware engineer. Manufacturing is contracted out to China.

The vendor-supplied C code is not written by expert programmers. It's obvious when you (try to) read the source. It's also a huge and messy pile of code.

Where I work we use the vendor-supplied kernel but we wrote all the user space ourselves. All this stuff is written in C. The software devs here have more than a few years of experience writing C, but are very uneducated about how to write secure code. They don't think about it. And management does not think about it. The only thing that matters to management is that the box passes the tests.

I've been around long enough to have figured out that things are like this in most places. Whether small companies or big companies doesn't matter.

netdog··on Verizon's accidental mea culpa
> That's not how the internet works. Nobody PUSHES data. People PULL data.

There's more to "the Internet" than just "the WWW". While HTTP could be considered a "pull data" protocol, there's plenty of application protocols which involve "pushing" data over TCP/IP transport.

netdog··on Using Vim as a writing environment
I find par to be very useful. http://www.nicemice.net/par/

Works great for re-wrapping code comments too.

It's been packaged in Debian for ages.

netdog··on Ask HN: What encryption algorithms should we take as compromised?
> In general you should prefer crypto constructions which are a result of global competitions. For example AES and SHA3.

The judges who chose AES and SHA-3 as the "winners" of the global competitions are the NSA.

> You should avoid at all costs anything that has been standardized by NIST...

That would include AES and SHA-3.

netdog··on Unpythonic Python
My for-real-not-humor implementation:

    def fizzbuzz(i, n):
        while i <= n:
            yield i%15 and (i%5 and (i%3 and i or 'fizz') or 'buzz') or 'fizzbuzz'
            i += 1

    for x in fizzbuzz(1, 100):
        print x
netdog··on Systems Past: The software innovations we actually use
See David Wheeler's page, The Most Important Software Innovations <http://www.dwheeler.com/innovation/innovation.html>.

The page has been online and refined for 12 years. It lists things such as the Stack, Packet-Switching Networks, Spelling Checker, Relational Model and Algebra (SQL), and quite a few other useful and important software innovations.

netdog··on Which hashing algorithm is best for uniqueness and speed?
It's not surprising, and it is not peculiar to FNV-1a. Most of these hashes will exhibit this same behavior.

Since the hash iterates over the characters in the string, once you find two colliding strings S and T, if you append any other string to both S and T, the hashes of S' and T' will also be identical. Try it yourself:

    #include <stdio.h>
    #include "hash_32a.c"
    int main(int argc, char* argv[])
    {
        const char* s[] = {
            "altarage",
            "zinke",
            "altarage_foo",
            "zinke_foo",
            "altarage_xyzzy",
            "zinke_xyzzy"
        };
        int i;
        for (i = 0; i < sizeof s / sizeof (char*); ++i)
        {
            Fnv32_t x = fnv_32a_str(s[i], FNV1_32A_INIT);
            printf("%s: %08x\n", s[i], x);
        }
    }


    $ ./test_fnv1a
    altarage:       e460d8b6
    zinke:          e460d8b6
    altarage_foo:   3d8619c5
    zinke_foo:      3d8619c5
    altarage_xyzzy: 2a6373cf
    zinke_xyzzy:    2a6373cf
netdog··on The new Galaxy Note 3 is region-locked
Samsung's customers are the carriers. The carrier asks Samsung for specific features or changes in the firmware build for the phones they buy from Samsung. Samsung satisfies their customer by giving them what they want.

The carrier is who you should gripe for the firmware misfeatures which you don't like in their phones. But due to the monopoly situation, they don't have to care very much what their subscribers think.

netdog··on Fab stops sending you emails you don’t read, even when you don’t ask them to
> most [email] users have no idea what HTML even is.

For most users email is something you do in a web browser. They've never used it any other way.

netdog··on Can websites personally identify visitors?
There was a time, in the not-too distant past, when the Internet was mostly about sharing educational information.

Sadly, the Internet is now full of companies who want to use it as a vehicle for advertising and who are obsessed with building up a dossier on as many people as possible, to exploit for financial gain. Your privacy means nothing to these companies; they will collect as much information about you as possible, with no regard for your wishes.

I take active countermeasures against these hostiles. I browse with javascript disabled. I don't have flash installed. I don't accept cookies blindly. I adjust my user agent. I run my own DNS server and cache and have hundreds of sites blackholed, including facebook, google analytics, and all the major ad servers.

It's some trouble to set all this up, and inconvenient at times. But unfortunately it's a jungle out there, and the default setup of browsers leaves you like a naked person in a mosquito-infested swamp.

netdog··on Why Django and Rails CMS Are So Rare
> Django ... it is wrong to expect a CMS to be built using them.

Django was originally developed to build a CMS, for the Lawrence Journal-World

netdog··on Napolitano: I don't use email at all
email is a useful messaging system.

However, email is not: 1) a reliable messaging system, 2) a secure messaging system, 3) a private communication conduit.

netdog··on ISPs Improve Their DNS Hijacking And How To Stop It
You might be surprised to learn that the Internet Protocol and the DNS are used for many other things besides serving web pages to browsers.
netdog··on Firefox: Not A Good Citizen on OS X Lion
wow, this page sets 20 cookies, loads 16 external javascripts, and has a 280kB image file in the banner. Just to deliver 7 paragraphs of text.
netdog··on No I won't sign your NDA, here's why.
A few years ago a potential client produced a similar contract, wherein they wanted me to indemnify them against any future litigation regarding possible copyright/patent infringement. I explained my position this way:

You want me to produce a work for hire, which you will own. Since you will own it, you will also own all the potential profits you may be able to derive from the work. Therefore, it is appropriate that you also own all the potential risk of losses. You are asking me to carry a share of the potential risks, but without any share of the potential profits.

They decided to look for someone else.

netdog··on Email is not broken: It’s a framework, not an application
I think part of the problem is that many, if not most people using email don't have a good understanding of what email is and is not.

Email is not a reliable messaging system. It gives enough of an appearance of reliability that most people using it think it is reliable. But if you have ever had a very important message disappear into a black hole with no notification, you learn not to treat email as reliable.

Email is not private. But most people do not realize this, and act as if it is. The quantity of proprietary business information and very private personal information transmitted by email is astounding. Governments can, and many do, slurp all email messages. Email "providers" such as ISPs, Google, Yahoo, et al have all your emails, even those you think you may have deleted. PGP/GPG are attempts to add a privacy layer, but have failed because they are too difficult for almost everyone.

Email is useful, for what it was intended for. If you expect it to be something it was not designed to be, then of course you might think "email is broken".

Today there is a need for a reliable and private global messaging system. SMTP is not such a system, but it is still used as one because it's "good enough" and so widespread that nothing better has been able to displace it.

netdog··on Sometimes the bug isn't in your code, it's in the CPU
Matt Dillon, Linus Torvalds, Theo De Raadt, Jony Ives, Zed Shaw, John Gruber

One of these guys is not like the others.

netdog··on Ron was Wrong, Whit is Right
So what the researchers did, apparently, was to gather all the RSA public keys they could find (6 million or so) and then calculate the gcds of all pairs of keys.

Apparently not. The number of unique pairings among 6 million is 5,999,999 factorial. Which is a _really_ large number.

netdog··on A Duck & a Wiki Team Up Against the Content Farms
> Google has mentioned they're working on the content farm problem.

The irony is that is Google's own AdSense program is the incentive for the creation of airburger web sites, which otherwise have no reason to exist.

netdog··on Why Plenty Of Fish Stores Passwords in Plain Text
> Hash based challenge-response authentication does require the server to know the plain password.

Not true. Read up on HTTP Digest authentication. It's described in RFC2617.

netdog··on [dead]
Someone here derided the idea of declining to do business with people you don't trust: "...modern financial and legal infra-structure is designed so that we can make business with people we don't trust."

Since the beginning of mankind the world has been full of people who will take advantage of others who are not as smart or experienced or powerful as they are.

It's not always easy to discern these kinds of people. Some are very smooth and skilled manipulators. You describe yourselves as "young founders". I suggest you seek out someone "old" (over 50) who you know well and whose judgement you trust, and ask them for counsel. I'm not necessarily referring to business or legal counsel, I'm talking about someone who's been around the mountain enough times that they can discern when someone is trying to blow smoke up your dress. It should be someone who has your best interest at heart. Maybe your own father or grandfather might be a good choice.

I am not being condescending about you being young and inexperienced. Nobody is born knowing everything. I'm old now, but I was young once, and I remember how it was. Get someone with the long fangs of many years who is on your side. Bring him to meetings with this company's people, introduce him simply as one of your "advisors". He doesn't need to say anything in the meetings, he may just observe and listen, and perhaps ask a few questions which unmask any propaganda.

I've been doing consulting for 30 years. When contemplating a job, if I don't have enough trust in the client's integrity (and he in me) that I feel we could do the deal on nothing more than a handshake, I'll walk away. For most jobs I do have a paper contract, because having things written down is good, but I don't expect any contract to turn a snake into a good guy.

If someone is intent on cheating you, all the contracts in the world aren't going to make much difference.

Over the years I've ignored my snake radar a few times, and in each case I regretted it.

Any contract must be equitable. What you've described so far sounds rather inequitable. Consider what that might indicate about the integrity and good faith of your potential purchasers.

As someone else here said, a bad deal is far worse than no deal. You may think this is the only offer you will ever get, but you don't know that. Many amazing things can happen in life which you would never have imagined.

netdog··on Gift HN: Anybody want a subdomain of ww.com?
I read

> ... if you want a subdomain of ww.com...

and naturally understood "subdomain" to mean "subdomain".

Perhaps what you meant to write was

"... if you want a hostname in ww.com..."

ww.com is a nice 2nd level domain. A 3rd level domain zyx.ww.com would be pretty nice too, in which one could create several hostnames, such as blog.zyx.ww.com, hg.zyx.ww.com, etc.

Yes, if you delegated the DNS for the subdomain, it would not be as easy for you to see what hostnames are in that subdomain.

Page 1 of 2Next →