HNHacker News
TopNewBestAskShowJobs

patrickmn

548 karma · joined January 3, 2015

https://patrickmn.com/ | @pmylund

Co-founder and CTO of Clovyr, a company that makes it easy to build and use decentralized applications

submissionscomments
patrickmn··on Why functional programming matters
Not joking at all. Functional languages have a reputation for being hard to learn mainly because they aren't what most people learn initially (and switching paradigms is never easy, no matter which direction you're going.)

Disclaimer: The above is an opinion. Double-blind trials have not been performed!

patrickmn··on Why functional programming matters
Why compose classes, abstract base classes, etc. when you can compose simple functions!

It's true that abstractions in functional languages can seem foreign and hard to understand, but generally they have some purpose, being grounded in mathematical practice. OO abstractions and patterns OTOH, taught essentially in "elementary school" which possibly makes them seem easier to understand, do a very poor job of solving more problems than they create.

Learning a functional language is often a transformative experience that lasts throughout a career, whether you even use functional languages or not. It might make you do something as simple as partitioning which functions have side effects and which don't, even if the type system doesn't enforce it. Or use a form of quick/fuzz testing, even if it's not the standard test suite. Or make parts of the data immutable for scalability, auditability, etc. Or...

There really are few things as satisfying as developing a large codebase in a functional language. A lot of the frustrating maintenance work just goes away. But even if you don't, functional principles can yield similar benefits in imperative languages.

patrickmn··on Apple has biomedical engineers developing sensors to monitor blood sugar
Yes, this is very important: Diet can be a complement to medical treatment, not a replacement. Don't make Steve Jobs' mistake!
patrickmn··on Apple has biomedical engineers developing sensors to monitor blood sugar
In paleolithic times, the average human diet included a lot of fatty meats. When the fatty game went extinct, and protein-heavy diets failed (protein isn't a fuel source except through gluconeogenesis,) carbohydrate-heavy diets became more common. It's not clear that a carbohydrate-heavy diet is the ideal human diet, just one we're compatible with. The human body can make almost anything work, for a time.

At the same time, tribes in Papua New Guinea who eat almost exclusively carbohydrates have been shown to be virtually free of heart disease.

Zooko and Amber Wilcox-O'Hearn maintain a fascinating blog on the science of ketogenic (very low carb) diets that I can highly recommend: http://www.ketotic.org/

patrickmn··on Apple has biomedical engineers developing sensors to monitor blood sugar
Diets have been (anecdotally at least) shown to be effective in the treatment of autoimmune diseases like Type 1 diabetes, multiple sclerosis, Chron's disease, and many others. A popular book on the subject is The Wahl's Protocol: https://www.amazon.com/Wahls-Protocol-Autoimmune-Conditions-...

Now, that's mostly anecdotal. There are very few studies on diet in general. As far as type 2 diabetes is concerned, though, low-carb diets have empirically been shown to reduce the need for insulin injections, slow progression of disease, and prevent the disease in the first place.

patrickmn··on Apple has biomedical engineers developing sensors to monitor blood sugar
A low-carb diet? (Tongue-in-cheek, but not really.)
patrickmn··on Web Development in Go
NaCl's secretbox for encrypting the session cookie - nice
patrickmn··on Americans Are Skeptical That Hard Work Will Pay Off
Fair point. I can qualify that by saying it's much more pronounced here than where I'm from, Northern Europe.
patrickmn··on Nginx reaches 33.3% web server market share while Apache falls below 50%
Nginx is the web server equivalent of programming languages with fibers (in a good way.)

Is there anything that competes/a "next Nginx"?

patrickmn··on Americans Are Skeptical That Hard Work Will Pay Off
There's gotta be some kind of Schroedinger's cat type joke here. If you're not in your seat, you don't exist.
patrickmn··on Americans Are Skeptical That Hard Work Will Pay Off
One of the things that bothers me the most about the United States is the ubiquity of "ass-in-seats" thinking. Somehow, the appearance of sacrifice (commuting two hours a day and being there at 9) means much more than the results you deliver in many companies.

It should be "smart work," not "hard work." Hard implies it's all just the transfer of energy--what seems to excite MBAs--when all that should matter is delivering results. Isn't that what capitalism is supposed to be?

patrickmn··on How to force manufacturers to take IoT security seriously?
That, branded with a stamp that goes on the box that merchants will pressure vendors to obtain because the non-stamp ones cause a lot of complaints, could be very positive.
patrickmn··on How to force manufacturers to take IoT security seriously?
By all means, if the Internet connection serves a purpose, great. But a sleep monitoring gadget probably doesn't need an Internet connection just to show your sleep score. For all the flak Fitbit has gotten, at least it gets this right (syncs over Bluetooth.)
patrickmn··on How to force manufacturers to take IoT security seriously?
Linux (as in distributions, homegrown or not) has "ok" security. But unless vendors go through a lot of steps to both lock it and what runs on it down, and make sure issues are addressed in a timely manner, it's not.

The key will likely be something like Android, that's based on the Linux kernel, but locks the vendors into some notion of a safe environment, and applies updates in a timely manner (the Linux kernel still has frequent critical security fixes.)

(Having vendors be able to articulate what the devices should be able to connect to or do, and having the OS/runtime enforce that would be a huge step forward.)

But Android itself is also insecure primarily due to fragmentation and end-of-lifeing, hence the feeling of hopelessness.

patrickmn··on How to force manufacturers to take IoT security seriously?
IoT seems hopeless because

- There are so many different kinds of devices and different hardware

- Vendors want to maximize profits like everyone else, which entails making new devices all the time, and ending support on the last model fairly quickly (typically within two years,) but consumers regularly keep their devices for more than two years.

- Hardware vendors historically were not software vendors. For many IoT makers, this is their first real foray into software. The mistakes being made are amateurish, at a level that we saw on PCs in the mid-90s.

- Although there are some IoT standards, they're mostly concerned with communications, not the operating system. It feels like we're still 5+ years off from something as basic as automatic updates being a given (even just notifying users that an update is available and allowing them to easily install it is a challenge currently.)

Two things that are really bothersome:

- A huge number of IoT devices don't need the 'I'. They are perfectly capable of serving their purpose without an Internet connection (e.g. over Bluetooth,) but a huge attack surface is added to make you able to configure the device via a central website, or simply to monetize usage data.

- It is futile to trust each vendor to have the security expertise to lock down every device. An "IoT operating system" would be highly desirable, but there is nothing anywhere near real world implementation, and given the heterogeneous of hardware components it doesn't seem likely something non-Linux-based will come along.

Brickerbot is hostile and aggressive and shouldn't be necessary, but maybe it is. That's beside the point, though: Nobody has to be given permission to brick insecure IoT devices. Vendors don't feel it where it hurts (the bottom line,) and consumers increasingly just don't care (studies show people have grown accustomed to security incidents -- "it happens to everyone and everything; replace it and move on, there's nothing you can do")

Hacks made Microsoft shape up in the 90s and early 2000s, but Windows has only become actually secure since after Vista. Maybe just don't buy IoT devices for another 5-10 years, or at least put them on a separate vlan.

There are a bunch of groups trying to spread the word, but it doesn't seem many vendors are listening (or if they are, they don't have the capability to really secure their devices.) We've had some success with Securing Smart Cities working with local and state governments, and trying to address some of these issues before hilariously insecure IoT hardware becomes ubiquitous in cities/related to critical infrastructure: http://securingsmartcities.org/

It's hard to see how it's not going to get much, much worse before it gets better.

patrickmn··on Elevating Mechanisms of the Ancient Greeks
For a second I was excited to discover the secrets to the ancient Greek philosophers' enlightenment, but hey, cranes are cool too!
patrickmn··on Are liberals on the wrong side of history
Recommend Robert Reich's "Inequality for All" on this subject: http://www.imdb.com/title/tt2215151/
patrickmn··on Hackers set off Dallas’ 156 emergency sirens over a dozen times
Video with sound: https://twitter.com/deadlyblonde/status/850576467234869248
patrickmn··on How Goldman Sachs Made More Than $1B with Credit Scores
It's pretty terrifying how much information CreditKarma (TU- and Equifax-backed,) Mint and such have, and what that turns into when it's shared and combined.
patrickmn··on Show HN: Octaspire Dern – Programming language
> Every variable and function definition in Dern must be documented by a documentation string. Dern also makes sure that every formal function parameter is documented in the documentation of function definition.

Interesting. Should this be available as a compiler warning in other languages?

patrickmn··on A quick look at the Ikea Trådfri lighting platform
If you're doing things that should be done over an encrypted channel, but forego TLS (or a suitable alternative like Noise Framework or WireGuard) because it adds attack surface, you are adding more risk than you are removing. A better solution would be to separate the parts of the stack that are sensitive from the parts that do things that you don't trust/are not in your control. This could be openbsd/POSIX style separation between your sensitive and the TLS-terminating process, or ideally placing them on completely separate machines. (Just make sure you trust your internal network if you aren't going to encrypt traffic on the inside...)
patrickmn··on Visual explanation of the last Google Codejam 2017 question
And, of course, being good at coding competitions doesn't mean that you're necessarily a good software engineer. The Jeff Deans are rare. "Hoping for the best" is pretty accurate.
patrickmn··on Unreasonable Ineffectiveness of Machine Learning in Computer Systems Research
Trucks driving autonomously on the interstate and being picked up by a human operator near city limits doesn't seem that far away. The trick will be to balance competition and the need to be first to market with the risk of accidents, because every negative PR hit for self-driving cars sets back the entire field politically.
patrickmn··on GCC 7 Release Series – Changes, New Features, and Fixes
Clang really pushed this area forward. Good to see.
patrickmn··on Ponzu – An open-source HTTP server framework and CMS in Go
> Automatic & Free SSL/TLS

A couple of years ago, I wouldn't have believed we would be seeing essentially zeroconf TLS/PKI in software anytime soon. Letsencrypt, the "encrypt everything" movement, and people like Steve, Ponzu's author, have improved internet security tremendously at a time when it is critically needed.

patrickmn··on Textbook manifesto (2016)
It just needs to be spun as a free market thing (the professors are entrepeneurs and competition brings down prices) :) And then cross your fingers nobody gets sued into oblivion.
patrickmn··on A quick look at the Ikea Trådfri lighting platform
I only have my own experience on this subject, so I'm definitely projecting.

I didn't mean that hacking is as culturally significant as the Dala horse or Semla. Just that, for example, nearly every kid in our town came to the LAN parties, even the "jocks." And everyone needed to troubleshoot networking issues, figure out how to get the games to run (cough without a serial key cough,) and so on. The biggest jock in town was cool because he played a MUD without ASCII colors, making him "hardcore." (Not to mention that the largest LAN party in the world, Dreamhack, which continues to this day, is in Sweden.)

Does that mean that all those kids became hackers? Of course not. But clearly being exposed to system internals coupled with a driving curiosity is how a lot of hackers got started, and so it's no surprise to me that IKEA has capable infosec talent.

patrickmn··on A quick look at the Ikea Trådfri lighting platform
Yeah, don't get me wrong. Not implementing TLS because you're worried about attack surface is a bad idea. But if all you're doing is verifying a gpg signature on some firmware, a TLS stack is probably overkill.
patrickmn··on A quick look at the Ikea Trådfri lighting platform
I grew up in Denmark and Sweden but I'm not sure I can give you a single reason. It's more that kids are more likely to be exposed to computer internals than in most other countries. PC gaming and LAN parties much more commonplace, an unfriendly climate most of the year encourages indoor activities, there isn't much going on (the downsides of peaceful countries...) and so on.

A lot of the early Internet's game cracking scene originated in Sweden, too.

patrickmn··on A quick look at the Ikea Trådfri lighting platform
Undoubtedly true, assuming you use something well-scrutinized like signify or gnupg for that signature verification.
← PreviousPage 2 of 4Next →