HNHacker News
TopNewBestAskShowJobs

nstart

3,936 karma · joined June 23, 2014

[ my public key: https://keybase.io/kiriappeee; my proof: https://keybase.io/kiriappeee/sigs/96k3PXwMa2aveYHJWNbYvfGtJsqHVZ36pFm-4iN3HPM ]

Blog at https://adnanissadeen.com/blog

submissionscomments
nstart··on Reflecting on 18 Years at Google
If I recall past discussions on this topic correctly, it wasn’t just about profits. I believe the incentive structures are setup around launches and not maintenance. If that’s correct, then that would lead to people launching, collecting rewards (bonuses, promotions, etc) and then abandoning.
nstart··on Help HN: Google has blocked our entire domain for harmful programs
I checked on this and that's not true. The public suffix list applies to anyone who lets out subdomains anyways and google drive is not a service to which this applies. Blogspot on the other hand is in the list.
nstart··on Help HN: Google has blocked our entire domain for harmful programs
Quick update here: The block has been lifted and our domain has been marked as safe. This was a way better timeline than I could have hoped for given that it's still Sunday night in the American and European markets and it's still early morning in Asia. Australia, New Zealand and anything further than +7 GMT would have been minimally affected.

I really appreciate the community here sharing thoughts, similar experiences, and ideas on what to do. First time I've heard of the public suffix list for this.

A quick question to anyone who happens upon this: How does one prevent this issue affecting an entire site in general? Is there a grace period that Google gives a verified (via search console) site with a security issue? If not, then I'm curious how to protect a site which is targeted by malicious groups via comment widgets or if they host content using paths instead of subdomains. Eg: medium.com uses paths to go to user generated content. How would they defend from having their entire domain blocked if someone created a publication that linked out to malware?

Cheers all!

nstart··on Help HN: Google has blocked our entire domain for harmful programs
That’s awesome. It also sounds relatively trivial to implement I think. Do you have any reference though? Source code, write ups etc? Would love to learn from others.

In this case it would be tricky since the link is to google drive and we can’t block those. Also we’ve seen people work around url blocks by either using short links or by using html pages hosted for free to redirect using JS instead of an HTTP redirect. Always another mole to whack :,)

nstart··on Help HN: Google has blocked our entire domain for harmful programs
I really do wish that was the case but it's just not something that I've come across. I don't want to make excuses here and do take responsibility for it but sometimes I feel like we learn important lessons like this in the fire. Still, this one is on me for not knowing about it till today.

On that note though, I'm perplexed as to how people would manage this kind of thing if using paths instead of subdomains. So instead of <user>.start.page if we used start.page/user. In the latter case, I'm not sure how one would prevent their entire domain from being taken down if malicious users kept linking to malware hosted on file hosting/sharing sites. Is there something similar to the PSL for this?

At its core the issue in my head is user generated content linking out to malicious software being a point of trigger for entire sites being blocked. Does this mean that an entire publication site could be blocked if someone used a comment widget to link out to malware and the site got reported? That seems like an effective DoS mechanism at some point.

I guess what I'm struggling with is why the domain gets blocked instead of the actual url that contains malware (or even the single path that links out to it). Fwiw the google drive link hosting the malware is still active.

nstart··on Help HN: Google has blocked our entire domain for harmful programs
To clarify here, we did think through this and start.page is not our primary business domain. It's the URL we used to host user generated content. You are 100% correct that it's a bad move to host user-submitted content on our primary business domain and we did intentionally avoid that.

Where we, and in this case, I, missed a very important step by the looks of it is in adding ourselves to the public suffix list. I have done research on subomdain content management but for whatever reason, today is the first day I've come across the PSL. Something I definitely take responsibility for and makes me wonder what other stuff I might be missing that is obvious to other folks who've done this at scale.

nstart··on Help HN: Google has blocked our entire domain for harmful programs
Thanks for sharing those gotchas. I’ll be keeping them in mind when adding our domain. Thankfully we’ve utilized start.page as a separate domain to only host the pages. This does mean that we should be able to add ourselves to the PSL without too much fuss once we’ve got the basics in place.
nstart··on Help HN: Google has blocked our entire domain for harmful programs
Definitely. Something new we learn everyday. Thanks for sharing
nstart··on Help HN: Google has blocked our entire domain for harmful programs
This does make for a really tricky future though tbh. It’s trivial for folks to password protect a zip file containing malware and for it to be uploaded to google drive or Dropbox and then be linked to from a start page.

If there’s a risk that each time that happens the entire domain could be blocked, that’s a lot of risk to try and mitigate. Especially seeing that many of the bigger providers also struggle to mitigate this kind of content despite having technical teams that are larger by an order of magnitude (or more).

nstart··on Help HN: Google has blocked our entire domain for harmful programs
Thanks. I do feel confident that this will be cleared within 72 hours but in the case of the business that does feel like an eternity since we host customer generated content.

Also, this is bound to happen in the future where people are going to link to malware that’s hosted elsewhere.

I’m trying to wrap my head around how to mitigate the risk of the entire site being blocked vs a single subdomain.

Will update here though when it is resolved in case there are any lessons to be shared with folks

nstart··on Help HN: Google has blocked our entire domain for harmful programs
Thanks so much for sharing thoughts. In our case all our start pages are delivered via cloudflare's web workers so we are safe from dangling DNS records being poisoned in that way.

In our case, Google's search console shows clearly what subdomain was guilty of the issue and that subdomain has been cleared now. Just really want to expedite the review process since Google's safe browsing has decided to block the entire domain instead of the offending subdomain :-/

I've submitted a review but they do say that reviews related to malware take a few days to process. This is a little hard to be honest given that it's not even our site that is hosting the malware. It was a page linking to google drive which is where the malware actually is hosted.

Hoping we get a response soon. Appreciate the supportive chime in.

nstart··on Munich court tells Netflix to stop using H.265 video coding to stream UHD
Can someone help me understand how big of a deal this is?

Is this a global ban on using HEVC to stream UHD?

What does Netflix use to stream 1080p?

Assuming Netflix turned HEVC off tomorrow how would UHD streams happen on a random smart tv from almost a decade ago?

Feeling very confused because I wasn’t even aware that this was something on the horizon and video codecs isn’t a topic I know anything meaningful about honestly.

nstart··on You Paid $1k for an iPhone, but Apple Still Controls It
I wish someone could ask Apple about the middle ground. You want to protect consumers? Fine. Alert customers to the use of non official parts but don’t brick any functionality then.

I want Apple to tell me when that shop that promises original parts is actually giving me an original which I can track.

I don’t want them stopping me from using it unless it’s genuinely incompatible at a firmware level.

nstart··on Collection of "Today I Learned" notes
Fun fact: I discovered the original thread had a comment from the folks at hashrocket that they made an app for themselves. They are not only still running the app, it’s still being actively added to (I think by just 1 person though?). Pretty neat.
nstart··on Oh-Auth – Abusing OAuth to take over millions of accounts
Hang on... So this means that when I check the token as per the guide at https://developers.facebook.com/docs/facebook-login/guides/a... , it returns the information regardless of the access_token parameter matching the app id or not? My assumption without reading the docs would have been that if the input_token was from another app, FB would refuse to debug it if the access_token was not associated with the app id.

What's the point in asking for the access_token at all for that endpoint otherwise?

Am I misunderstanding the bug? This feels like a foot gun that was happily handed over to a lot of people all this time.

nstart··on Show HN: Keep – GitHub Actions for your monitoring tools
I'm looking at this and thinking, "you know what, this could be an awesome personal tool as well".

This is definitely outside of the use cases described but I can definitely see myself hooking this up in an IFTTT style to funnel things into my todo systems using the HTTP provider.

Will poke around this soon.

nstart··on The global trading system is starting to rearrange itself
That’s really sad. And also logical especially when thinking of it from the perspective of it being a magazine. So definitely not the publication for me. I still want to be caught up on global news on a slow basis like reading an edition once a week. Any recommendations?
nstart··on The global trading system is starting to rearrange itself
From the article, wrt how the economist claims that decoupling is phoney because the underlying export by china in the process remains the same:

> Startlingly, however, The Economist provides no actual data to support this claim.

Ha! This was a reason I unsubscribed from the economist. A lot of times it makes broad claims and then leaves out the details to support said claim. Almost like it expects the reader to treat the economist like a first hand source and therefore no citation needed.

Good on the author for calling this out and then rebutting with details of their own (not necessarily supporting author’s claims though since I haven’t had time to really think about it just yet).

nstart··on Ask HN: Why did Python win?
Definitely. Forgot to mention this one. I remember running scripts through the IDLE till I learnt how to run stuff in the command prompt. So darn friendly.
nstart··on Ask HN: Why did Python win?
If you think about it from the perspective of people learning programming, python is dead dead simple. In Unix like systems it comes preinstalled most of the time. For so many students in many parts of the world who use an HP/Lenovo laptop for university work the OS is windows and python installation is again, dead dead simple.

Ruby starts off by saying you should have a version manager. And windows installation is not straightforward (from a student perspective it’s important to note that something that looks like it isn’t officially supported makes it feels like the entire language is going to be a compatibility slog). This is not dead dead simple. It’s not hard. But it requires more than one concept to be learned to start.

Then the docs. Ruby has so many ways of getting started. Python puts up one main way. Same for the api reference. Python has a single link and they even say “keep this under your pillow”. As a beginner I know what I should do. Ruby? Many links that say arcane stuff (beginner perspective) like rdoc and what not. Python is super clear in their breakdown of reference too. I cannot stress enough how simple this page (https://docs.python.org/3/library/index.html) makes it to find what you want.

Overall Ruby and it’s documentation feels like it’s made for people who know Ruby or something more than the bare minimum. Python is made for people who’ll be trying out programming itself for the first time.

To me, that’s what made Python win. They just seemed like they thought more about folks starting out for the first time.

nstart··on Show HN: Open-source obsidian.md sync server
And especially awesome is that all their enhancements like properties and daily notes make use of markdown or json rather than closed binary/hard to reverse xml formats. Any app could replicate the functionality if it wanted to and it would be portable next minute. The only thing that is kind of locked is the plugin but that’s outside of scope.
nstart··on Lemmy now has over 2M users across 915 instances
I second the other comment just made in reply to yours. I also want to add that this would kind of happen on Reddit as well where occasionally there’ll be more than one community for the same topic. Sometimes it’s different themes (there’s standard mature f1 and there’s the f1 that just wants to shitpost and meme). Sometimes one community exists but hasn’t gotten enough attention or growth moderation so people join a more well managed one. Sometimes one community exists for general purpose discussion and one for more specific stuff (like cycling vs randonneuring)

I feel like similar things will happen in the forum fediverse (it’s what I call the fediverse alternatives to Reddit). There’s going to be a period of thrashing and churn. And then it’ll settle down with each community having its own vibe and we members get to try it out and settle where we want.

nstart··on Edge sends images you view online to Microsoft
I raise you the languages tab which by default sends text typed in “certain text boxes” to Microsoft for grammar assistance and text prediction.
nstart··on The odd appeal of absurdly long YouTube videos
Into this ring I throw Kevin AKA Purge's ridiculously long patch analysis notes for Dota https://www.youtube.com/watch?v=tK8OjcRmERQ
nstart··on The metaverse was never alive in the first place
One thing I can never get over is the fact that despite all their claims of going all in, Meta never seemed to actually be invested in the Metaverse themselves.

If they really believed in it, the first priority of the company would have been to make it so that every non hardware unit of their physical offices was shut down and people were told to go work from the metaverse within the spaces of their homes, beach houses, coffee shops or wherever they physically were. Every meeting would have been held in the metaverse. Every all-hands, in the metaverse. Every employee in charge of people would have been working with the product and engineering to create experiences for the team to bond and share time in within the Metaverse. Meta should have lived and breathed as a company within the metaverse. Pre layoffs that would have been more than 86,000 concurrent users who would have a daily direct impact on the product.

Instead, Mark wanted people to come back to the office.

The Metaverse by Meta died when their people touted it as the future of work and play but then did absolutely nothing to use it that way themselves.

nstart··on Microtiming in Metallica's “Master of Puppets” (2014)
Re Lars as a drummer, my first encounter with the band was both late and epic. It was via a double disc dvd set of their live symphony and Metallica performance. Watching Lars drum himself to exhaustion was goosebump inducing. 10/10 would love him again for his performances.

That said, I’ve watched some comparison videos of his drumming vs more expressive and I can understand where people are coming from :,)

nstart··on 85% of jobs are filled via networking
I never referred them in the sense where I made a recommendation for them or mentioned that I had asked them to apply. I just pointed them to the job. The statement that they have a connection at the workplace would still be true in the cases where they were hired.

Also, just in case it’s helpful, the zero weight statement was related to the folks I connected with. Not referrals in general.

Basically, as your comment reveals to me, there’s a lot of nuance here and the article generalizes it away into a statement that doesn’t feel accurate.

nstart··on 85% of jobs are filled via networking
Thank you! Whenever I see an extraordinarily broad claim I immediately go looking for references.

Imo the article has been referenced well even if the references are mostly second hand; it repeats claims made by other articles which may also be repeating claims made by others.

To me, the key fact that I wanted to check in on was this

> Up to 70% of employees received their current company position through networking.

The reference for this probably comes from a 2017 linkedin survey[1] which polled 15,905 linkedin members in 2016 and received this as one of their answers

> ... 70 percent of people in 2016 were hired at a company where they had a connection

I find that this kind of stands at odds with the words "received their current company position *through* networking." That makes it sound like the networking was the reason they were able to get the job. The linkedin statement makes it seem like that's just how they may have found out about the job. I won't accuse the article of directly saying what I'm assuming it means. But I also think the rewording changes the meaning too much for me.

Wherever I have worked, whenever there's been a job opening I have forwarded it to friends who might be interested. For the ones who got into the job, they had a connection, but that had absolutely zero weight on whether they got hired or not. I was just a more efficient job board promoter.

Not to take away from everything in the article but I definitely would encourage people to break any numbers they find interesting down into what they might actually mean by visiting the sources and trying to read into the claims fully.

[1]: https://news.linkedin.com/2017/6/eighty-percent-of-professio...

nstart··on Go with PHP
In general I think there’s something to be said for sticking with languages that match your model of approaching a problem. DHH gave a good, albeit a bit rambly, keynote on this topic once. He compared some of the tools selection conversations to the equivalent of people comparing gaming consoles purely by specs when in reality, picking a console mostly boiled down to what you subjectively enjoyed more. I like that idea as a rule of thumb and encourage people to start there and go with what feels right for them before making deeper choices. (Lots of nuance here, don’t want to delve too deep so please view from that context :) )
nstart··on When you lose the ability to write, you also lose some of your ability to think
> For this invention [writing] will produce forgetfulness in the minds of those who learn to use it, because they will not practice their memory. Their trust in writing, produced by external characters which are no part of themselves, will discourage the use of their own memory within them. You have invented an elixir not of memory, but of reminding;

That is correct. I mean, some of that is exactly why I write at least 5000 words a day of journal notes while working. Because I want to offload everything from memory to a written form that is indexed.

> and you offer your pupils the appearance of wisdom, not true wisdom, for they will read many things without instruction and will therefore seem to know many things, when they are for the most part ignorant...

This part is where we veer into prediction of how it will alter people and it is both right and wrong. I think the education system has shown us it's possible to have a great memory and to remember many facts and still be ignorant. At the same time, there's so much material that can be consumed and people have surface knowledge of many things and once you dig into a conversation with them on it, the ignorance pops up and it turns out that they don't know much about the topic. I know this. This has been me on many occasions and is still me on some occasion.

>... and hard to get along with, since they are not wise, but only appear wise.

Again, there's some truth to this. I think about the times where I've jumped into a conversation about politics with some half baked knowledge that I read somewhere but failed to understand or recall correctly and I think I must have a looked a fool at those times.

But then again, I've course corrected here and there and I've spent time writing and sharing thoughts with others where I've used previous writings to pull up facts and my own synthesis, and I feel like I've been a better participant at times like that. In that way, writing has helped me steer away from ignorance.

I can't comment further though on the quote because I've never read the rest of the context so I may be missing out on some stuff.

I think Paul is on to something here though. I can't count how many thoughts I've had that I thought were clever but when I started to write the thoughts down and organize it on my own, I discovered for myself that either I didn't have enough evidence to prove myself entirely or that I was just flat out wrong. Writing is a form of thinking in my opinion. And if we don't write, we do lose that side of thinking too. I do appreciate though that Paul doesn't go further into predicting the consequences as Plato's warning does here. But I'll be willing to bet that Paul is right that there will be some negative consequences for sure.

← PreviousPage 3 of 23Next →