HNHacker News
TopNewBestAskShowJobs

r4vik

1,466 karma · joined March 17, 2011

Hacker and Writer.

Can be found on: github @ https://github.com/r4vi twitter @ https://twitter.com/r4vi

[ my public key: https://keybase.io/r4vi; my proof: https://keybase.io/r4vi/sigs/GEeAG_HvyhAUscpRZo40Z447G8Xllk76gJac3Qf8kwE ]

submissionscomments
r4vik··on Ask HN: Who is hiring? (March 2024)
Novata | Senior Developer Experience Engineer | Full-time | London, UK (Hybrid)

Novata is pioneering the way in ESG (Environmental, Social, and Governance) data management and analytics, empowering private market firms to enhance transparency with stakeholders. Our platform simplifies the collection and analysis of critical ESG metrics.

Are you passionate about developer tools, k8s and Typescript? Come work with me in our platform squad and be responsible for delivering a first class Developer Experience to our colleagues and team members in other squads.

You will focus on coaching engineers to better improve their understanding of the "Ops" side of their skillset, improving tools & processes, documentation, and support channels to make the development journey smoother and more enjoyable.

Apply: https://wrkbl.ink/gj3k2rd

Hybrid in our case means come in when you feel it would be useful, there is no x days per week mandate.

We are also hiring for a bunch of other roles both in London, UK and New York, US: - Data Engineers - Support Engineers - Mid and Senior Full Stack

Full list: https://wrkbl.ink/4MyPLK8

r4vik··on The tech job recession is over
After months of not seeing any outside ir35 contracts I've seen about 3 today
r4vik··on Ask HN: Who is hiring? (July 2023)
Bytedance (Security Engineering) | bytedance.com | Singapore, Sydney, Australia | Onsite | Full Time | Visa sponsorship available

As part of our team, you'll engage in unique and high-impact projects, tackling security challenges on a scale not typically seen in the tech world. You will design and implement new approaches for system security, apply trusted computing, and track cutting-edge security technologies.

We're hiring for: Site Reliability Engineers - Singapore: https://job.toutiao.com/s/i2chcXA

Site Reliability Lead - Sydney, Australia: https://job.toutiao.com/s/i2vTUqD

Site Reliability Engineer - Sydney, Australia: https://job.toutiao.com/s/i2c8kSV

r4vik··on Ask HN: With recent layoffs, how would you advise new grads entering the market?
they've always been lying, the can't find someone with the skills is just a hoop to jump through.
r4vik··on Slack's private GitHub code repositories stolen over holidays
it's totally plausible. and best practice.

If you have a localised blog for multiple regions you will probably have your main blog set up to be indexed and your regional blogs set up to be no-indexed so that Google isn't indexing the same stuff twice.

r4vik··on Ask HN: Do you also have to restart intellij multiple times a day?
I only ever restart it for updates every month or so
r4vik··on Ask HN: Work instead of tech?
trades are brutal for your body and I wouldn't recommend picking one up in your late 30s.
r4vik··on Ask HN: Where to watch skilled developers writing code and explaining ideas?
yes, it is kind of buggy as it's a live streaming platform first and a video on demand library second. Antony does have a youtube channel so you could try that instead.
r4vik··on Ask HN: Who is hiring? (November 2022)
could you post the salary range?
r4vik··on Ask HN: Where to watch skilled developers writing code and explaining ideas?
Anthony Sottile on twitch is a joy to watch https://www.twitch.tv/anthonywritescode if you like Python
r4vik··on Meta cuts Responsible Innovation Team
which team would you rather work on anyway?
r4vik··on Google Pixel 6 still freezes when calling Emergency Services
return it, it's broken - it shouldn't behave like this. Don't live with these bugs
r4vik··on Ask HN: IT Security Checklist for Startups?
From what I can remember when I set this up last all our MDM did was:

- Ensure full disk encryption

- Time limit on how long people can defer OS upgrades

- Report on software installed and versions

- Enforce somewhat complex password

- Enforce password after screen has become locked

- Allow us to remote wipe the machine if lost/stolen

It didn't stop you from installing / uninstalling anything - even itself. Although if your machine stopped phoning home for a certain amount of time we had some alerts set up for the IT support team to follow up.

r4vik··on Ask HN: IT Security Checklist for Startups?
unfortunately yes - I was in charge of this decision as a previous employer and I went with Macs+JAMF even though I'm a die hard Linux user. My work around was to run a fullscreen Linux VM but that does defeat the purpose somewhat.

I'm hoping things are better now - I think Canonical have some sort of MDM for Ubuntu but I couldn't figure out how to pay for it.

r4vik··on Show HN: Wavvy – web-based audio editor (Audacity port)
also it would let you have a common target (wasm) for plugins so it doesn't matter if you're running on ARM/x86
r4vik··on Ask HN: IT Security Checklist for Startups?
It's all about good hygiene early.

- MDM for laptops/phones, don't let people use their own devices. The point of MDM isn't to stop people installing their favourite IDE, the point of it is to make sure the device is patched and running latest OS. If you have a VPN (even AWS Client VPN supports this...) tie MDM together with device attestation so only patched machines can connect to your VPN.

- Unified login, for a start up you can use Google workspace or even GitHub as your identity provider (this gets weird if you have non-devs but you can push it for a bit). Don't have more than one account/password for things, you just log into your google account then use OIDC/SAML to auth against internal apps. If you do this you probably don't need VPN. Use this to auth into AWS too.

- Don't share accounts on SaaS services (e.g domain registrar), this will make rotating stuff when someone leaves a nightmare. If a service doesn't support teams or you don't want to pay for the enterprise version then it's OK for the CTO and 1 other person to have their own login.

- Minimise/avoid static credentials for your infra (e.g. web server talking to postgres) prefer to use AWS Instance roles with short lived dynamic credentials.

- Make sure network isolation is set up correctly, your Mongo db shouldn't be listening on the internet

- Use 2fa but make sure it's WebAuthn/FIDO. Issue everyone with 2x security keys. People wipe / screw up their phones/TOTP authenticator apps far too much.

- Centralised logging, make sure your apps can output logs to opensearch/datadog/whatever. Whenever a user performs an action make sure this gets logged.

- Don't let people manage prod infrastructure without using Infrastructure as code tools (CDK/Pulumi/Terraform), best thing would be not to give people prod access and all changes have to go through CI

- Make sure you know your product is down before your users start calling/emailing. Set up healhchecks.io / pingdom whatever.

r4vik··on US sailors wear out sex workers
seems like they need to implement surge pricing
r4vik··on Converting HDR to SDR with FFmpeg (2018)
This doesn't really fix the color space though so I tried enhanced the prompt

  ffmpeg command to convert hdr video to SDR and fix the colorspace:
and it returned:

  ffmpeg -i input.hdr -pix_fmt yuv420p -filter_complex "colorlevels=entropy_mode=1:levels=srgb:source_range=full:target_range=full:rgb_to_yuv=sigmoidal" -y output.sdr.mp4
I don't really understand this so I asked it to explain:

  how does this fix the colorspace?
It replied:

  The RGB to YUV conversion is done using a "sigmoidal" function, which basically means that it applies a non-linear transformation to the input video. This transformation is designed to "compress" the bright colors in the video, making them more manageable for SDR displays.
  The colorlevels filter is also adjusting the black and white points of the video. This is done to ensure that the video can be displayed correctly on SDR displays, which have a limited color gamut.
  Finally, the target_range and source_range options are used to ensure that the video is encoded in the correct range for SDR displays.
r4vik··on Ask HN: What is your default font for coding and terminal?
Source code pro: https://adobe-fonts.github.io/source-code-pro/
r4vik··on Converting HDR to SDR with FFmpeg (2018)
I don't know if the output is correct but I prompted openai:

  ffmpeg command to convert hdr video to SDR:

  ffmpeg -i video.mp4
and it returned: ffmpeg -i video.mp4 -vf format=pix_fmts=yuv420p -c:v libx264 -crf 18 -preset veryslow -c:a copy output.mp4

  This FFmpeg command will take your HDR video and convert it to an SDR video using the libx264 codec with a CRF value of 18.```
r4vik··on What Does Evergrande Meltdown Mean for China?
This might even be a good thing to force hyper urbanisation, can you imaging if the whole country is quickly forced to abandon rural living?
r4vik··on What Does Evergrande Meltdown Mean for China?
Vietnam and Bangladesh
r4vik··on Ask HN: Who is hiring? (July 2021)
Department for International Trade (UK Civil Service) | Senior Site Reliability Engineer | Full-time | London, UK & Cardiff, UK | ONSITE

At DIT, our Site Reliability Engineers (SRE) ensure that all our services, facing the Internet's erratic nature, are just working and are responsive.

The journey starts from ensuring that the development teams have the right tools to do their day-to-day job, including APM, exception aggregation, log aggregation, autoscaling, performance metrics aggregation, dashboards, software-defined CD/CI pipelines, etc.

You'll evaluate technology and solve cross-service problems. You will develop new services(primarily in Python Django). You'll evangelise product teams about Service Level Indicators, Objectives, Error Budgets and negotiate them. You'll be representing the modern impatient Internet user. You'll evangelise the DevOps culture and break siloes to build better services. You will contribute to the code of supported web applications.

We're looking for several Senior SREs and 1 person Lead SRE to join the team.

Full details: https://jobs.jobvite.com/digitaltradecareers/job/oOQRdfws

About DIT: https://www.gov.uk/dit

r4vik··on Codecov Bash Uploader compromised
copypasta here:

About the Event Codecov takes the security of its systems and data very seriously and we have implemented numerous safeguards to protect you. On Thursday, April 1, 2021, we learned that someone had gained unauthorized access to our Bash Uploader script and modified it without our permission. The actor gained access because of an error in Codecov’s Docker image creation process that allowed the actor to extract the credential required to modify our Bash Uploader script.

Immediately upon becoming aware of the issue, Codecov secured and remediated the affected script and began investigating any potential impact on users. A third-party forensic firm has been engaged to assist us in this analysis. We have reported this matter to law enforcement and are fully cooperating with their investigation.

Our investigation has determined that beginning January 31, 2021, there were periodic, unauthorized alterations of our Bash Uploader script by a third party, which enabled them to potentially export information stored in our users' continuous integration (CI) environments. This information was then sent to a third-party server outside of Codecov’s infrastructure.

The Bash Uploader is also used in these related uploaders: Codecov-actions uploader for Github, the Codecov CircleCl Orb, and the Codecov Bitrise Step (together, the “Bash Uploaders”). Therefore, these related uploaders were also impacted by this event.

The altered version of the Bash Uploader script could potentially affect:

Any credentials, tokens, or keys that our customers were passing through their CI runner that would be accessible when the Bash Uploader script was executed. Any services, datastores, and application code that could be accessed with these credentials, tokens, or keys. The git remote information of repositories using the Bash Uploaders to upload coverage to Codecov in CI. Recommend Actions for Affected Users Because of our commitment to trust and transparency, we have worked diligently to determine the potential impact to our customers and identify customers who may have used the Bash Uploaders during the relevant time periods. For affected users, we have emailed you on April 15th using you email address on file from Github / Gitlab / Bitbucket, and there is a notification banner after you log in to Codecov.

We strongly recommend affected users immediately re-roll all of their credentials, tokens, or keys located in the environment variables in their CI processes that used one of Codecov’s Bash Uploaders.

You can determine the keys and tokens that are surfaced to your CI environment by running the env command in your CI pipeline. If anything returned from that command is considered private or sensitive, we strongly recommend invalidating the credential and generating a new one. Additionally, we would recommend that you audit the use of these tokens in your system.

Additionally, if you use a locally stored version of a Bash Uploader, you should check that version for the following:

curl -sm 0.5 -d “$(git remote -v)

If this appears anywhere in your locally stored Bash Uploader, you should immediately replace the bash files with the most recent version from https://codecov.io/bash.

If you use a self-hosted (on-premises) version of Codecov, it is very unlikely you are impacted. To be impacted, your CI pipeline would need to be fetching the Bash Uploader from https://codecov.io/bash instead of from your self-hosted Codecov installation. You can verify from where you are fetching the Bash Uploader by looking at your CI pipeline configuration.

If you conducted a checksum comparison before using our Bash Uploaders as part of your CI processes, this issue may not impact you.

Actions Taken by Codecov We have taken a number of steps to address this situation including:

rotating all relevant internal credentials, including the key used to facilitate the modification of the Bash Uploader; auditing where and how the key was accessible; setting up monitoring and auditing tools to ensure that this kind of unintended change cannot occur to the Bash Uploader again; and working with the hosting provider of the third-party server to ensure the malicious webserver was properly decommissioned. Codecov maintains a variety of information security policies, procedures, practices, and controls. We continually monitor our network and systems for unusual activity, but Codecov, like any other company, is not immune to this type of event. We are also working to further enhance security so we can stay ahead of this type of activity, including reinforcing our security tools, policies, and procedures.

We will continue to share with you as much information as we are able and encourage you to reach out to us with any questions or concerns you have at security@codecov.io.

We value the trust you place in us and our solutions and pledge to continuously work to earn it. We regret any inconvenience this may cause and are committed to minimizing any potential impact on you, our users and customers.

Sincerely, Jerrod Engelberg CEO, Codecov

r4vik··on The Four Quadrants of Conformism
not the easiest thing to edit in this text area but I've reduced the height
r4vik··on The Four Quadrants of Conformism
50% of the words in this article could have been replaced with an image

  +-----------------------------------+------------------------------------+
  |                                   |                                    |
  |                                   |                                    |
  |           tattletales             |       naughty ones                 |
  |                                   |                                    | aggressive
  |                                   |                                    |
  |                                   |                                    |
  +------------------------------------------------------------------------+
  |                                   |                                    |
  |                                   |                                    |
  |                                   |                                    |  passive
  |                                   |       dreamy ones                  |
  |        sheep                      |                                    |
  |                                   |                                    |
  |                                   |                                    |
  +-----------------------------------+------------------------------------+
       Conventional minded                    Independent minded
r4vik··on Sonic Pi is a code-based music creation and performance tool
you can translate your thoughts into sound without having to have any sort of manual dexterity or years of practice
r4vik··on Visa, Mastercard mull increasing fees for processing transactions: WSJ
it works anywhere I can use a contactless card
r4vik··on Ask HN: Anyone work in Honolulu?
I don't do drugs but I wouldn't take a programming job where I had to do drug tests
r4vik··on Ask HN: Best ultrabook for Linux?
Lenovo Yoga 900
Page 1 of 7Next →