HNHacker News
TopNewBestAskShowJobs

paws

624 karma · joined March 19, 2010

I build stuff.

Interests: ECMAScript, Rust, security, data, networking, cognitive bias

Microsoft alum.

Email is best way to reach me. Mention HN.

[ my public key: https://keybase.io/paws; my proof: https://keybase.io/paws/sigs/yN1KZs8UWccCKsnw4B6Olcx0KYTLhZOu7ZSWnixzIxs ]

submissionscomments
paws··on Colorado passes agricultural Right to Repair
Do you have links about this?

I was extremely disappointed [1] when I learned about Hochul's last minute nerfing of right to repair and I'd be curious to learn more how the governors office acquired that power. IANAL but thought separation of powers was supposed to be guaranteed by the Constitutions, both US and NY. What happened?

[1] https://twitter.com/onpaws/status/1618787954306211840

paws··on Americans’ IQ scores are lower in some areas, higher in one
Pretty sure I know which company you're talking about b/c I had the same experience. I read somewhere the IQ test may be a mandate from the CEO.

I actually had to take the silly IQ test twice, once on my own and a second time with a webcam proctor who watched me (its as awkward as it sounds).

Anyway the proctor told me I got a perfect score, so I next completed the take home, with all three solutions passing the tests (in an optimal way AFAICT). Got rejected anyway.

The IQ part felt like a big waste of time for me as well as the proctor. So long as they insist on this silly game I agree to not bother applying there.

Every situation is different etc but speaking for myself BNPL seems fundamentally unattractive given how many credit card benefits you'd forego [1]

[1] https://www.cardratings.com/financial-literacy/what-is-buy-n...

paws··on Irs.gov set to require 3rd party auth next filing season
Thank you. Of all those links I found this the best primary source

https://www.gsaig.gov/sites/default/files/ipa-reports/GSA%20...

I don't really understand it, but IMO it will be a real shame if interagency squabbling or whatever this is forces the public to using id.me for login. Fingers crossed things shape up!

paws··on Irs.gov set to require 3rd party auth next filing season
I seem to recall having the opposite experience - vanilla username/password was the only option a few years ago, then later at some point id.me showed up as an option. If id.me ends up being required, that will be pretty gross...
paws··on Irs.gov set to require 3rd party auth next filing season
> login.gov works fine with ssa.gov

Could you please be more specific? How do you know?

The flow I've been using goes like this, starting at the IRS website:

1) irs.gov homepage -> click 'Sign in to Your Account'

2) https://www.irs.gov/payments/your-online-account -> click 'Sign in to your Online Account'

3) https://sa.www4.irs.gov/secureaccess/ui/?TYPE=blahblah (uuid/session url param)

I'd consider using login.gov, but apparently someone didn't finish the job yet even though it's been at least one year since this was announced.

It occurs to me SSO is nice in theory but one might surmise the diffusion of responsibility is problematic.

paws··on Irs.gov set to require 3rd party auth next filing season
Apparently starting next filing season, irs.gov will require the public to use "something else" to login vs the traditional username/password I've been using for a while, presumably managed by the IRS's own servers.

Two questions: 1) id.me seems to have a spotty track record given the $86 million we paid for the two year contract [1]. Setting aside the weirdness of being required to go through a private corporation to see my own government data, I noticed their terms [2] Section 19 lists _mandatory arbitration_. Awful

(Of mild interest, irs.gov doesn't appear to even have a terms page, rather only a Privacy Policy and Accessibility page.)

It's 2023 and the public is online. Why should the public be required to go through a third party to access government services they already paid for?

2) Anyone know what happened to login.gov?

Right now the login page [3] lists only id.me.

Over a year ago it was announced [4] login.gov was supposed to be available [5].

Login.gov appears to be a USDS/18F project [6] and would seem more palatable than id.me. Why did it fail this year?

[1] https://www.nytimes.com/2022/02/21/us/politics/irs-facial-re...

[2] https://www.id.me/terms

[3] https://sa.www4.irs.gov/secureaccess/ui/

[4] https://federalnewsnetwork.com/agency-oversight/2022/02/irs-...

[5] https://www.nextgov.com/it-modernization/2023/03/irs-cio-mov...

[6] https://www.usds.gov/report-to-congress/2017/07/login-dot-go...

paws··on Why did Phreesia share my medical data after I opted out?
At that point, why not just sign e.g. 'void'?
paws··on Why did Phreesia share my medical data after I opted out?
Sounds pretty risky. Have you run that by a lawyer?
paws··on Why did Phreesia share my medical data after I opted out?
> I also cannot complete the check-in process on the tablet without checking

> a box allowing them to contact friends and family in pursuit of collecting money for unpaid bills

Wow, this is pretty shocking. Could you please share more details e.g. company name?

Did you relay your experience with this evil pattern with the doctor? What did they say?

paws··on Disney begins laying off 7k employees
I don't have any inside knowledge, but in case you didn't already know Hollywood is famous for, to put it charitably, 'unusual' accounting practices [1].

Maybe the authorities chase after some of the cases, but as far as I can tell the status quo remains sketchy AF.

[1] https://en.wikipedia.org/wiki/Hollywood_accounting

paws··on Police sue rapper Afroman for using footage of home raid in his music videos
Hadn't seen this argument before but it resonates, thanks. If you have any links to share I'd be curious to read more.
paws··on Police sue rapper Afroman for using footage of home raid in his music videos
> The strong protections that police have should be the norm.

I agree the US generally doesn't have great worker protections and the situation should probably be improved.

On the other hand, when the public seeks redress against police misconduct, they have the unions to thank for serious obstacles they must face. Unions historically have succeeded in hiding disciplinary records from the public, apparently help "bad apples" quickly get re-hired the next town over, inflate salaries and are behind very expensive defined benefit pensions. It seems hard to argue that police unions are furthering the public interest. Combined with qualified immunity, which is nonsensical overreaching judicial activism, and the Supreme Court ruling officers have no duty to protect [0], American policing seems to fail its public terribly.

I've noticed certain YouTube channels seem to easily and consistently get endless examples of obvious police misconduct [1][2][3].

Meanwhile I've previously seen people argue that improving the pay [4] may help, but at least in some states when factoring in overtime and weird contractual rules+bonuses, total pay seems to be already very high.

The problems seem to run very deep.

[0] https://en.wikipedia.org/wiki/DeShaney_v._Winnebago_County

[1] https://www.youtube.com/@AuditTheAudit

[2] https://www.youtube.com/@LongIslandAudit

[3] https://www.youtube.com/@LackLusterMedia

[4]https://news.ycombinator.com/item?id=35235677

paws··on Police sue rapper Afroman for using footage of home raid in his music videos
In all the discussion about qualified immunity, it seems to me police unions don't get discussed enough.

Police unions appear to be a significant reason why police officers are shielded from accountability. They make police disciplinary records private [1], are why officers receive excessive overtime pay [2], sometimes including kickbacks to their municipality/town, issue cringeworthy statements [3], and pour $ millions into elections [4]. The more I learn about them, the more disappointment I have in American policing.

Why does the American public tolerate police unions? Perhaps the better question is, who are the politicians that accept their money?

[1] https://www.nytimes.com/2021/02/16/nyregion/nypd-discipline-...

[2] https://www.timesunion.com/news/article/Police-overtime-spen...

[3] https://www.nycpba.org/miscellaneous/anti-cop-city-council/

[4] https://www.opensecrets.org/news/2022/06/police-unions-spend...

paws··on Supreme Court asked to strike down immunity for police who brutally beat student
I've heard this argument before, and I think there's a kernel of truth there. Thing is, municipalities+towns+states have already poured significant public money into police earnings, thanks in part to police unions who negotiate generous overtime rules, defined benefit pensions, and even off-duty pay for private security [1].

I think most people would agree that higher education tends to bring higher salaries, but strangely this is exactly backwards with US policing. It seems to me becoming a police officer is a rare way to get comparatively high and stable earnings _without_ earning a degree or putting in the work and time investment associated with other decently paying jobs.

Meanwhile, Norway requires police officers to earn a three year bachelor's degree and over the past 12 months the # of police killings is low (I think 1). In the US, it's 1,117 - around 3 a day.[2][3]

How would you add a degree or substantial training requirement when the pay is already so high? The status quo in America is a national embarrassment, IMO.

[1] https://www.propublica.org/article/new-jersey-police-contrac...

[2] https://worldpopulationreview.com/country-rankings/police-ki...

[3] https://www.washingtonpost.com/graphics/investigations/polic...

paws··on An Update on Dianna's Health (Physics Girl) [video]
> Don’t know how land ambulances in particular managed to avoid being covered by the act

https://www.nytimes.com/2020/12/22/upshot/ground-ambulances-...

paws··on Open-source hospital price transparency
Anecdata: I can't say "pharmacy benefits managers" work the same across _all_ systems. When I had health insurance in a western European country, I'd get a prescription, buy at a local pharmacy (paying out of pocket), then submit the claim + paperwork to ins carrier and they'd reimburse me minus a copay, I think 25 EUR or so.

I can't say with certainty there wasn't some kind of "pharmacy benefits manager" behind the scenes, but everything about the transaction felt simple and like a standard claim. Point being, it's not obvious to me that "all systems" require an entity to handle pharmacy benefits in the way you seem to be saying.

paws··on Open-source hospital price transparency
TIL about CPOM, thanks!

Another question I'm curious about, if you don't mind, is why there is no apparent urgency in fixing the painful billing experience for patients. (aka "why don't billing coordinators seem to coordinate with the patient front and center?") Seems like lots of people are fearful of medical billing, and not only because it's expensive.

I realize providers may be out of network, carriers take time to adjust claims, etc. Still, the staggered/surprise billing seems unique to medicine and a 2nd order effect might be people avoiding preventive care to their own detriment.

Say a patient goes to get some procedure done, the medical work is completed in one day. Shortly afterwards they receive bill A. OK, that's fine. But then X months later, they receive bill B with more charges from some provider that they may not even remember.

I thought avoiding that was supposed to be the job of a billing coordinator. Presumably coordinators are constrained by "things" -- what are the factors that make this experience so dreadful for patients and why are they not being changed?

paws··on Open-source hospital price transparency
Thanks for sharing! Billing codes certainly seem like a significant source of complexity. Another area that seems problematic to me is an apparent surfeit of middlemen.

What conclusions might we draw from the fact e.g. a "Pharmacy Benefit Manager" is a job that exists only in the US [0]? Why does it feel like my insurance premiums pay for lots of things that are difficult to attribute to actual improved health outcomes?

Appreciate your insight.

[0] https://www.goerie.com/story/opinion/2021/06/12/op-ed-when-c...

paws··on 2021: A Titan M Odyssey [pdf]
I noticed the paper concludes with "All vulnerabilities we found had been reported to Google and are now fixed."

Meanwhile it was reported recently that Google dropped support [1] for Pixel 3. Anyone know if these fixes were included in the "final" Pixel 3 update? [2]

[1] https://support.google.com/pixelphone/answer/4457705?hl=en#z...

[2] https://www.androidpolice.com/the-pixel-3-deserves-longer-up...

paws··on YouTube is banning anti-vaccine activists and blocking all anti-vaccine content
Anybody know of examples/precedent where an entity covered by Section 230 lost that protection?
paws··on Plaid settled $58M lawsuit over alleged consumer data sharing
I recently received a helpful reply about liability from an HN user who says they're a Plaid employee. Thanks @phoenixy!

https://news.ycombinator.com/item?id=27982516

While I'm still trying to understand the bigger picture implications, maybe you will find this helpful too.

paws··on Tracing Uncovers Half-Truths in Slack’s CI Infrastructure
Thank you, helpful!
paws··on Tracing Uncovers Half-Truths in Slack’s CI Infrastructure
Edit: If there's a better venue to ask please send me elsewhere.

Hi Omar, It seems like you're not at Plaid anymore, but if you don't mind there's something I've been trying to figure out for a while and would appreciate your opinion/thoughts.

It has to do with the way Plaid works. Seems to me when financial institutions have account security liability, such 'security guarantees' tend to be contingent on the account holder _never disclosing credentials_. Given the nature of how Plaid works [1], it would seem Plaid users could be taking considerable risk.

I'm wondering if my understanding is right -- do account holders forfeit protection 'guarantees' their financial institution might offer when they use Plaid? Do financial institutions consider Plaid an 'authorized user' in some special way? Quite possibly I'm missing something and was hoping to understand. Thanks!

[1] https://security.stackexchange.com/questions/198005/is-plaid...

paws··on Next.js 11
> Anyone who relies on Next should want Vercel to be a long-lasting company.

Well said, +1. A feature that gets people excited about a product you use, even when you're not the intended audience, is a good thing.

paws··on The latest DSM update makes btrfs drives unavailable on budget Synology models
Do I understand this right, DSM v7 intends to take away root access in some way? Ugh.

Another negative to add to the list. For me Synology has mostly been a disappointment, I'm sorry to say. Seems their software has been generally in decline for a while. DSMv7 was delayed over a year ago [1], and now they don't expect to ship until summer 2021. v7 doesn't seem to bring anything interesting to the table IMO, and now they want to take away root? Meanwhile the only thing I saw from v6 updates was a request for spying/telemetry [2]. Wanted to like Syno but it's too locked down, too expensive, too annoying.

My position [3] hasn't changed from last year - I don't see myself buying a Syno product again, nor recommending them to most of my technical friends.

[1] https://www.snbforums.com/threads/dsm-7-preview-delayed-unti...

[2] https://imgur.com/a/Yzgw7hq

[3] https://news.ycombinator.com/item?id=23738360

paws··on DigitalOcean S-1
Huh, that's a bit surprising. Can anyone point to examples of what kinds of disclosure obligations are reduced? e.g. liquidation multipliers?
paws··on Free for Developers
> We run our monolith (Spring boot) as a Docker service

Does Cloud Run's free tier 'sleep' containers when they don't get regular traffic? Several years back Heroku nerfed their free tier -- they would proactively place low traffic apps into 'sleep' mode so the next request would have a noticeable several second long delay.

I ask because our SpringBoot monolith takes 30s to startup, and has bursty traffic, so I was of the expectation that Google Cloud would probably 'sleep' low traffic containers like this also. Would be nice if that were not the case.

paws··on Stripe Climate
ICYMI there's a public repo that has more details (and answered several of my questions in one convenient place)

https://github.com/stripe/negative-emissions-source-material...

Nice to see the transparency on this.

paws··on Websites that look like desktop GUIs
Curious what about Hyper Backup do you like the most?
paws··on Websites that look like desktop GUIs
I don't see myself buying a Synology again.

I didn't want to use mine as 'just a NAS' and was hoping the Linux+ssh they ship would allow that, but it hasn't gone as I had in mind. Certain things I wanted require jumping through weird extra hoops, and system decisions I don't particularly agree with are just imposed. The toolchain generally seems quite dated, the kernel is from 2017 (v4.4.59+) and to me their proprietary package format (.spk) seems pointless given we already had apt-get/etc. I saw back in December they deprecated DDSM, also DSM7 was delayed, still not out and that was before Corona so who knows now.

If you wanted the option to spin down your disks, sorry, it's evidently impossible b/c Synology requires you to use their partition layout which dumps their OS partition onto all your data disks. My needs are low write/high read & I would have preferred installing the OS on a dedicated SSD. In fact I paid extra for a '+' Syno with SSD slots, but whoops, too bad the slots can't be used for a bootable OS because there's no BIOS. So something, probably log file appends for services I don't care about are why my data disks spinning 24/7. Maybe that's good for Syno's support costs but it's not great for me.

Why not install Ubuntu you might ask? Sorry, not possible == no BIOS.

I know plenty of people love their Synos -- if it works for you, great. Just one guy's opinion. If you need a NAS for 'just' file serving then you might well be OK.

But if you want to do anything beyond the surface, I suggest looking elsewhere.

← PreviousPage 2 of 5Next →