HNHacker News
TopNewBestAskShowJobs

riyakhanna1983

223 karma · joined December 5, 2017

Hacker/entrepreneur (HN ID at gmail)
submissionscomments
riyakhanna1983··on Ask HN: Are you comfortable uploading sensitive data to ChatGPT or Gemini?
If someone were to build a paid, privacy-preserving wrapper of ChatGPT, it may not see as much traction because ChatGPT is free.
riyakhanna1983··on Ask HN: Teach Programming to Kids?
That makes sense. I’m mostly curious to know if parents are actively encouraging their kids to develop programming skills.
riyakhanna1983··on Ask HN: Parents who control their kids' education, when do you introduce LLMs?
I’m curious to know your opinions on teaching coding to kids. Is it a good idea given claims around AI taking over programming jobs in the near future? How many parents here would like their children to learn coding?
riyakhanna1983··on Ask HN: Kernel Containers (security like VMs, perf like LXC)
The hypervisor needs hardware virtualization extensions. So if you are running in a public cloud, then yes you would need nested virtualization.
riyakhanna1983··on Selling open-source software
Many have attempted to offer services that allow developers to "sell their FOSS projects". Unfortunately, no successful model has emerged so far.
riyakhanna1983··on Ask HN: Python Serverless Functions?
[MORE: cannot edit] We're looking to cut down our Cloud costs, so over provisioning to make up for cold starts is not an option for us. Curious to know how others are in the same situation and how they are handling this?
riyakhanna1983··on Ask HN: Python Serverless Functions?
We have not, but suspect that cold starts would be worse for GAE apps.
riyakhanna1983··on Ask HN: We found a cracked version of our software on the web, now what?
Plug: in the past, I helped a few companies and OSS devs track usage of their code in mobile apps https://codescout.app/ and provide leads. Happy to chat if this is relevant.
riyakhanna1983··on Dozens of malicious PyPI packages discovered targeting developers
Malicious packages are yanked as and when they are found or reported by the community.
riyakhanna1983··on PyConUS talk on detecting malicious Python packages
Tool: https://github.com/ossillate-inc/packj
riyakhanna1983··on I'm Peter Roberts, immigration attorney who does work for YC and startups. AMA
Thanks, Peter! Would you know the processing time for IEP application? Could it be expedited?
riyakhanna1983··on Show HN: Launch VM workloads securely and instantaneously, without VMs
Thanks! gVisor intercepts app syscalls and serve them in user space (inside separate VMs, one for each container), which reduces runtime performance significantly. Both Firecracker and gVisor use VMs to sandbox container code.

Kwarantine, on the other hand, directly runs container code on the hardware (no VMs). It uses MMU/page tables to provide a different kernel to each container.

riyakhanna1983··on Firecracker: Start a VM in less than a second
We will post more publicly soon.
riyakhanna1983··on Firecracker: Start a VM in less than a second
You can read about its IO performance against QEMU in their NSDI paper (table 8,9): https://www.usenix.org/system/files/nsdi20-paper-agache.pdf

Even though the startup times are fast, the IO performance is poor compared to native. This is primarily because of IO emulation. We've been working on a new hypervisor that can directly run isolated containers (no VMs). Email me if you are interested in learning more.

riyakhanna1983··on Select a muscle and it provides the exercises to workout the selected muscle
Thanks for making this website! It will be very useful to a number of us.
riyakhanna1983··on Ask HN: What are you working on?
Been working on a new hypervisor that can directly run isolated containers (not VMs) to enable secure micro-services without virtualization overhead. Email me if interested in testing or contributing.
riyakhanna1983··on Ask HN: Show me your half baked project
Been working on a new hypervisor that can directly run isolated containers (not VMs) to enable secure micro-services without virtualization overhead. Email me if interested in testing or contributing.
riyakhanna1983··on Evolving Container Security with Linux User Namespaces
> "There's also benefits of being able o run a special kernel per workload."

I wonder if we will see kernel namespaces that would let you run specialized kernel for each container just like a VM.

riyakhanna1983··on VPN by Google One
I'm confused. If the product targets tech savvy customers, does Google not already know its reputation among the group?
riyakhanna1983··on BPF, XDP, Packet Filters and UDP
But does FC not incur high I/O overhead at runtime?
riyakhanna1983··on BPF, XDP, Packet Filters and UDP
Why not just run Docker containers natively?
riyakhanna1983··on Syllabus for Eric's PhD Students
Just like mine :)
riyakhanna1983··on Int. students may need to leave US if classes are 100% Remote
Could the waiting be attributed to your country of citizenship? I know there's a long wait for citizens of a few countries because there are per-country limits on green cards.
riyakhanna1983··on Deno 1.0
Doesn't this mean more opportunities to inject malicious code?
riyakhanna1983··on Ask HN: How to build a minified Linux kernel for my Docker?
I'm looking to improve the security posture by stripping the kernel off unwanted stuff (ebpf, zillion different file systems, drivers) that introduce CVEs into the kernel.
riyakhanna1983··on Ask HN: How to build a minified Linux kernel for my Docker?
Sorry, I should have made it clearer. Yes, I'm talking about the Linux kernel on the host that's running Docker containers. If I use the default Ubuntu kernel, it contains a bunch of unnecessary functionality. Is there a tool that I can use to configure the host kernel to only contain the absolutely necessary functionality required by the Docker container image?
riyakhanna1983··on What’s the one thing in the world you want to build?
Build tech that replaces phone numbers with something that cannot be spoofed.
riyakhanna1983··on Companies consider abandoning open office layouts to prevent disease spread
A friend of mine has furnished his garage, and is renting it out as a private working space in his neighborhood.
riyakhanna1983··on PWA Store
Out of curiosity, what advantage would that provide?
riyakhanna1983··on Supply-chain attack hits RubyGems repository with malicious packages
Not only that, you could end up shipping malicious code to your customer.
Page 1 of 3Next →