HNHacker News
TopNewBestAskShowJobs

rdslw

2,269 karma · joined October 5, 2010

submissionscomments
rdslw··on I almost sold Baremetrics for $5M
I can't even visit OP as my pi.hole blocks it :)

Let me guess: another spam^H^Hads analytics^H^H^Hspy business there under the pretext of 'better user satisfaction'.

rdslw··on Top Paying Tech Companies by SWE Level
Disagree.

This is top 5. Look at the difference betwen position 1 and 5 (30% (sic!) for entry level). Ask yourself how many companies are in the SV area?

Then think where MEDIAN of those numbers is.

Looking at top 5 is like looking at best performing stocks in last year (from 5000 of ohers), and thinking "YEAH, thats what I should expect from my future investment portfolio".

rdslw··on Top Paying Tech Companies by SWE Level
what struct me actually is this: > Typically 2-5+ years of experience. (...) Possibly lead a small team or project. Ability to mentor engineers (...)

WHAT?

I don't know a profession with high knowledge requirements where after 2 years you can and are expected as a job req to manage a team.

This speaks to me two things: a. a lot of staff is young and unexperienced b. rotation in segment <5 is big

rdslw··on Better password protections in Chrome
I don't agree with 1.

This "But Google's Password Checkup doesn't just use public sources" is infering that Google's db is bigger and better. You don't know and this is example of magic lotion marketing.

"Our magic lotion for hair grow is muuuuch better, as it have secret formula".

Actually I suspect that Troy's db as for now is better/bigger.

rdslw··on FortiGuard XOR Encryption in Multiple Fortinet Products
This speaks about Fortinet: "2018-06 - 2019-11: Multiple conference calls, discussing technical details, agreeing on disclosure time"

Translation: half a year to communicate:

- you send it unecrypted

- yes we do.

rdslw··on Gitlab's Director of Risk and Global Compliance Resigns
Candice Ciresi (aforementioned director) commented: "As I believe GitLab is engaging in discriminatory and retaliatory behavior, I have tendered my resignation."

E-mail notification (her resignation): https://i.imgur.com/AE8UtvD.png

First time it was edited: https://i.imgur.com/7N7mTC2.png

Current version: https://i.imgur.com/YjWmpGk.png

rdslw··on OpenSSH's Support for U2F/Fido Security
Does such approach as desribed by you mean that token needs to store P1/K1 for every site?

AFAIK It does not.

And if it does not, your explanation contains bigger errors about enrollment/process.

@akrel described it much better.

rdslw··on SSH Handshake Explained
This is quite poor article, which you can grasp after reading it. Few examples:

* quote: "generates ___something___ referred to as the exchange hash H" - in article which tries to sound technical and in fact in some parts goes into much details, this ___something___ is really funny :)

* copy pasta description of forward secrecy, wrongly explaining why it is forwardly secure

* wrong chain of events with lack of important diagram, while adding boilerplate :(

p.s. amount of upvotes shows these days a lot of us click up before reading _whole_ article.

rdslw··on Dropbox no longer follows symlinks to items outside of your Dropbox account
> But in 2019 it is basically an inferior and antiquated tool for syncing your own files.

IPO dates of most (once) cool tech startups signal time to search for replacement and time of approach change by them.

rdslw··on The We Company S-1
Your actions are reason, why this (yours incl) sections are useless from investor perspective.

Take for example a risk from We Work company S1: > the sustainability of our rapid growth and our ability to manage our growth effectively;

translation: getting older may cause you die.

in other words: dont put your cat to microwave, and beware as your tea might be hot in your cup.

rdslw··on Google kicks out popular open source app(s) with fake excuses
We need your help. Google is doing evil :(

Google is sending in June messages about limiting access (read NO access) to some apps using oauth accessing gmail. Of course under privacy pretext, and of course they won't do this is apps 'comply' and udnergo verification process.

Currently it hit (among others) very popular sms backup + (https://github.com/jberkel/sms-backup-plus) app which allows to backup and restore calls metadata and sms (with content) to gmail.

Develeoper of the app complied and submited app for verification process, but of course it was denied by Google. Whole verification process announced from them is another corporate mambo-jumbo = read lie.

Google guys, please help from inside. Why your company is doing this?

p.s. it does not applies only to gsuite, but to all gmail.

rdslw··on Scene report from the Chernobyl Zone
Knowing many Belarusians, they recommend reading book by Aleksievich which is a written down summary of 500 individual discussions with first hand eye witnesses/victims of the event.

Highly recommended.

https://en.m.wikipedia.org/wiki/Voices_from_Chernobyl

rdslw··on Gitlab's Journey from Azure to GCP
I did not write anything about author having/not having technical skills. You're reading it between lines, and in my opinion it shows (again: for me) kind of insecurity. I suspect that emphasis of 'being competitive for the positions we were hired' also shows it. But it's my opinion.

What I wrote (and what I stand for) is that it is good to know that this article was written by 'content marketer' - meaning person with a SPECIFIC agenda for writing that article (by definition of 'content marketing' itself).

Thats always good to know. If anybody praises something I always prefer to know if there is something (e.g. salary?) which may created/influenced/PAID such opinion. We (hackernews) derided it on many ocassions. To give different example: I personally ask all bankers if they have commission on me (for specific recommended product), or not. And I consider it healthy to know and ask.

To make it clear, I think that there is a good content marketing, and that there is a a bad content marketing. The bad for example can be seen easily with searching google for "blog 10 best sleeeping bags" and similar.

rdslw··on Gitlab's Journey from Azure to GCP
Putting aside valid thing that article was written by person with role at gitlab 'Content Marketer', one thing struck me:

"This Pingdom graph shows the number of errors we saw per day, first in Azure and then in GCP. The average for the pre-migration period was 8.2 errors per day, while post-migration it’s down to just one error a day."

This was measured independently by pingdom, not by gitlab.

Hello azure?

rdslw··on Microsoft, currently the most valuable company, is having a Nadellaissance
As an investor I bought few years ago MSFT stock. I did it as I saw two things:

1. azure

2. o365

1. because I knew what happened (and was happening) with AWS

2. because microsoft moved to subscription model

Those two things, connected with third "secret" incredient: BIGGEST user base (corporate) which WILL use those two offerings = success.

Satya is/may be great. I bought stock around 2014/2015 because of the above and nothing more.

If you have a big userbase you can monetize it really really well.

rdslw··on Chrome “clear cookies on exit” feature does not work
Unfortunately, this is not true.

This is still NOT (fully+) fixed in current (73) Chrome/Chromium.

+) in most real usage scenarios your cookies will persist, contrary to your/users belief.

The even bigger problem, is google employees for a few years (sic!) delaying fix for this. AFAIK press article documenting it is in the works, but you can just jump into chrome bugs discussions and draw your own conclusion if this was prompt and appropriate reaction.

So the problem is:

1. it is not yet fully fixed

2. it is MULTIPLE years in this state

3. google knew about it and was interested in keeping it as it is.

rdslw··on Chrome “clear cookies on exit” feature does not work
This happens for a few years (much older than URL in question).

This happens also in Chromium.

There is (proably?) a logic when cookies will be deleted, but it is under so strange conditions, that 99% of users who choose this options, DO NOT HAVE cookies deleted on chrome/quit/restart AT ALL.

:-o

rdslw··on Serverless Docker Beta
Count me in as a over-engineering and selling-things-engineers-do-not-need hater.

The very list of benefits on ZEIT, mentions 4 things: first two of them are clear over-engineering bloat (plus premature optimization), and second two were actually created only because of serverless. They were (and nothing more was mentioned in section benefits ;) :

* Clusters or federations of clusters * Build nodes or build farms * Container registries and authentication * Container image storage, garbage collection and distributed caching

I don't know why everybody can't see fakeness of argument'you need clusters, farms and hundreds of servers'. You don't. Actually you do only (contrary to your statement), if you're FANG.

Why? Because look at real world HUGE examples. E.G. stackoverflow (and no, your company/startup/whatever, will not reach their level of traffic) can do everything on literally dozen of servers, while they admitted that in some scenarios 1 web server was enough. Source: https://nickcraver.com/blog/2016/02/17/stack-overflow-the-ar...

Our 10x..100x smaller companies would perfectly do on 2..4. There is no need for whole over-engineering.

The ultra funny thing is ZEIT selling 'deployment self-heal' as old known (windows anybody) and ridiculed recipe: it will work after restart. Right. It's better to shut off car engine, go out, go in, and start again. This is XXI engineering :)

rdslw··on Sapper – Progressive web apps powered by Svelte
Can it be used in any of web ides available these days? stackblitz etc.
rdslw··on Show HN: Cost of a 51% Attack on Popular Cryptocurrencies
Could you please add another column stating income from mining fees, you should have if having specific hashing power. Important: calculate mining fees FROM hashing speed, not from money.

It would be a kind of an alternative benefit comparison.

rdslw··on Best practices for user account, authorization and password management
This is very good primer on the topic, including unicode normalization, punycode and others, with ultra short python examples and links to more info.

https://www.b-list.org/weblog/2018/feb/11/usernames/

rdslw··on Convenient End-To-End Encryption for E-Mail
IM won't replace e-mail due to two important things you seem to be neglecting (for a long time :) ). They are:

* human psychology and ways of working

* lack of features on IM (and this problem is bigger than implementing crypto in e-mail).

_

Let me describe them more, starting with humans:

* we love to separate things in our minds, like work/home linkedin/facebook profiles that will never merge, no matter how much money fb will pour into fbworks or others.

* we assign e-mail, an aspect of 'longer asynchronous communication'. We desire this 'asynchronous' aspect, allowing replying us with a delay. We demand that a separate (sic!) tool with such characteristic (and publicly agreed typical use) exists

* we need communication tool for longer (like this or yours post) exchanges, where MULTIPLE people can participate. We need to able to put into one message 10..20 minutes of work. And no, we will not be publishing and exchaning academic papers (read attachments/separate documents) for such discussion to happen.

* it can't be tied to instant/short comm tool.

_______

Features:

* we need (must) to have a searchable archive of this communication tool, instantly available, surviving device changes (telegram and signal are out), and multiple years to store

* this tool must be connected to publicly available namescheme of internet: domain names - no IM are, they create they own space. This is ultra crucial: I must be able to send and receive information to a participant who I know only a domain. Like for examples yours: youagain@latacora.com

* I need to be able to talk with multiple people, knowing who they are (domains), and @Immuppet1980 or @894984320123 is not, while tptacek@latacora.com is

* we need to to have multiple addresses all being accessed with relatively small number of clients (read 2). Welcome to the IM hell, when if you're 40 and have friends from around world you need to ahve: signal, telegram, fb, whatsap, sms, ghangout, alo, and I'm not even started with asian tools! This sucks.

_

So no, while I share your despise to current crypto-email state, the proper way is to try to secure e-mail, not to get rid of it. Incrementally, getting rid, one by one all bad things of it. There is no bing bang approach.

rdslw··on Germany vs. Elsevier: universities win temporary free journal access
This.

Elsevier is not stupid. January without access means:

* most scientis realise it's not necessary

* the smaller rest of them, learn how to use scihub

* elsevier is 10% less on revenue (contrary to giving it 'free access' now and retrocharging later) for every month

* people start publicize in different places, diminishing elsevier value, and proving that you can print elsewhere (sic!)

In result elsevier strong grip ends in a bing bang. Would scientific world hold them for just 3..5 months, and they're out of the business. Simple.

rdslw··on Intel Issues Updates to Protect Systems from Security Exploits
Dear Intel, dont worry, this will be court tested.

And btw, did you notice that huge amount of people disagrees already with you, simply putting your stock 8% down in two days?

rdslw··on Blackbird: Bitcoin arbitrage
I'm sad at the quality level of comments on this discussion. Lot of people are commenting clearly without reading EVEN the readme.md of the linked post.

This tool advantage relies on the fact that NO bitcoin needs to be moved, so all posts about long time of btc transfers make (almost) no sense.

On the other side only ONE (so far) person mentioned (importantly) that it works only on bitfinex, and even him didnt clearly wrote that this work ONLY if bitfinex has higher price than other exchange (reducing arbitrage opportunities by half), because you can short btc only on bitfinex.

Where is HN from 5 years ago? :(

rdslw··on Microsoft Adds an OpenSSH Client to Windows 10
Thanks for the link.

It says "ON THE BACKLOG" since October 01, 2014. You have a pretty long backlog, if you didnt implement the second top voted request in three years, out of backlog ;-)

rdslw··on Litecoin and Ethereum buys and sells are temporarily disabled
Let me guess, do you live in USA by a chance?

My first hand experience (2017) is that US banking oferring (from a european guy perspective) is a eyes opening experience.

* There is no instant bank wires (free ones) between major banks. Or at least the same days ones, working reliably through most of banks.

* You get paper checks from your bank :)))))

* Small business (sold a car, got a return from landlord) give you money on checks, also accept only paper checks if you need to pay them on the spot (in the office).

* your bank charges you a monthly fee, to protect you from overdraft (wtf is this on debit account??), he shall block from happening at the begining - we call it "protection racket" in Italy.

* boa/citi and others have websites with design from 2005, not to mention mobile apps..

* you can't send money from bank account to a different bank to your unsophisticated friend (plumber, maid, or mr sandwich) just knowing his phone.

* when you withdraw money from coinbase to your connected US bank account, you pay 1,5% of face value. WHAT? PERCENTAGE FEE? This is USA banking thing, as the very same coinbase, charges fixed 0.15 EUR fee per no matter how big wire if you're european.

* major us banks got two factor just two years ago in terms of security.

* tap to pay (we call it paypass) is also almost 10 years after europe.

* first chip card in citi was offered to me in 2015 or 2016? Still magnetic (easily copied) card is used in majority of points in the USA

etc..

Some of them are chaning in the last two years, but mostly for sophisticated customers, small banks, and people not being able to use those features between different banks. It will still take a lot of time to catch up with a Kenya from Africa...

rdslw··on New Remote-First Formula and Updated Salary Calculator
I think it does not stand.

in US 6 weeks of paid vacation is still rare in professionals. 3 is common. So you're using 3-6 while in europe there is guaranteed 6. This is apples and oranges.

Besides: this is in addition to the sick time. Sick time is paid and you don't use vacation time for that in europe. How is that in US? Can you get additional 4 weeks paid sick time? Can you get 8?

Then in addition you have this perks in US as long as you work as professional in top companies. While the real difference in terms of health care is after this work. Last I check, average age at FANG is below 30 yrs in USA! Wow! So imagine you're 45, you dont work at google/etc: then at low impact events or maybe even medium events if you dont have family healthcare is comparable (your savings cover it). But at high cost/high impact situations or medium ones if you have full family, you're not covered (add to this highest in the western world cost of healthcare in US). While it's state funded in europe also at the high cost level (read cancer therapies and all the things like). This is big difference for last 40 years of live.

And then you have mentioned maternity: that alone (and most of people have families in any place of world) from family perspective is a huge difference financially AND child development.

p.s. and there is cost of living. in US alone you can easily have it in SanFran at 1.77x of US average - you can imagine how it scale to the other parts of world? Sauce: https://www.wolframalpha.com/input/?i=cost+of+living+index+S...

rdslw··on Show HN: Echo Podcasts – Goodreads for podcasts
Sure you can sue as you'd like, but in this case: * Apple never lost over trademark in court with Apple Corps and did not had to pay. * When Apple Corps tried to finally sue breach of trademark agreement (the one for 80k), they ultimately lost in front of court: https://en.wikipedia.org/wiki/Apple_Corps_v_Apple_Computer#c...
rdslw··on Show HN: Echo Podcasts – Goodreads for podcasts
There is a world beside US. Bigger actually.

In fact amazon can't have (generic 'echo' word trademark) and does not have it in any sane part of world. All sane states do not allow generic trademark on common word.

My speechless was (and still is) about how much brainwashed must we be to consider it fine, normal and to actually defend such practice. Yuck.

← PreviousPage 4 of 10Next →