HNHacker News
TopNewBestAskShowJobs

sadfnjksdf

61 karma · joined March 10, 2014

submissionscomments
sadfnjksdf··on What if we never run out of oil? (2013)
All known resources are finite.
sadfnjksdf··on Heartbleed disclosure timeline: who knew what and when
As soon as anyone knows, they are going to use that info however they see fit. Probably getting their own house in order before spreading the news, to not put themselves at risk.

However, even though spouting a conspiracy theory is a faux pas here, I can't help but wonder if the "he who smelt it, dealt it" rule applies here. Lets say your country were to setup a network interconnecting major research institutions, etc. After its use takes off and it is obvious that everyone is going to be communicating over this new medium in a short amount of time, you see the value in keeping tabs on people. You decide that it is in your best interest to put backdoors into encryption algorithms in enterprise communication software. So you see there are these guys that have become the place that everyone is starting to go to find what they are looking for. This is a good place to be. You eventually get your hands on this also. It's a waste of time and energy to constantly be decrypting everyone's messages, so what the hell- let's put a backdoor in that also. Everything is going well. Wait... ok, we should have thought of that. Another country now knows about this vulnerability and it hasn't been publicized, which means they will start using it to spy on contractors that work for us. We'd better leak this information so everyone fixes their hole. Let's tell Google. We're already on good terms with them.

sadfnjksdf··on Capitalism isn't working and here are the reasons why
> removing development restrictions in booming cities, unleashing an epic (or Chinese-level) building boom

Which would be interesting because it is debatable whether we have the resources for that.

On one hand, we have people like Tim Worstall of Forbes claiming that we will never run out of metals that would be used in a building boom, because innovation reduces and replaces use of existing metals, e.g. modern day pennies use steel and a copper coating:

http://www.forbes.com/sites/timworstall/2011/10/15/when-are-...

Although, I think Tim takes a lot of liberty with his assessments, like his recent wild speculation that humanity could never populate another star system because it would take too many people to preserve our culture: http://www.forbes.com/sites/timworstall/2014/04/07/perhaps-c...

On the other hand, in http://en.wikipedia.org/wiki/Iron_ore#Available_iron_ore_res... it states that Lester Brown of the Worldwatch Institute has suggested iron ore could run out within 64 years based on an extremely conservative extrapolation of 2% growth per year, and so if there were a boom, innovation to replace use of iron ore as a structural component would be required.

sadfnjksdf··on Capitalism isn't working and here are the reasons why
I always like reading historical analysis, but have a few questions:

> We did a bad job of distributing the wealth generated by that.

I'm not sure what you mean here. Do you mean that those that profited did not reinvest in stocks that may have helped companies grow and provide jobs? Or, that the government did not tax enough to pay its own staff and overhead and then redistribute via programs that do not necessarily target the areas that really need it? Or that they should have given that money to churches and other charities to distribute?

The reason I ask is that there are few pure redistribution models. The closest are some churches and charities, but they typically still have some overhead deducted. The next best can be stock investment, as, depending on the companies, that money is in large part repaid in the form of raises or new jobs. The least efficient is ofter government, because accountability is limited to the % wasted in the process of providing services, unlike capitalism where competition provides accountability; if you do poorly, you don't survive, unless a government bails you out.

> What happened to agricultural commodities in the 1920s is happening to nearly all human labor now. And that's pretty terrifying.

Could you expand on that and provide some references?

sadfnjksdf··on IRS misses XP deadline, pays Microsoft millions for patches
I wonder what retail companies are doing about all of their POS (point-of-sale) computers running XP.
sadfnjksdf··on Passwords are obsolete
Ok, valid point- to clarify, when I said 2-factor SMS, I was assuming a 30-second TOTP like Google's.

If you don't use TOTP, someone can login to your account just by knowing the password which they can use from almost anywhere. If you were to only use TOTP, they'd need your phone. To me them stealing your phone is tougher than stealing or guessing your password.

sadfnjksdf··on Passwords are obsolete
Woah, hold on.

> sort of like two-factor authentication without the two-factor?

If you don't have 2-factor, which most sites don't, then it is 1-factor. This is replacing that 1-factor with another 1-factor.

> So how do I login to my email account for example if I need to login first to my email and get the temporary password? It's a chicken and egg problem.

You are taking him too literally. While he did say it could replace passwords, he obviously didn't mean email auth. Email auth would probably still require a password. Since many have their email password saved, they may not usually have to enter that anyway, most of the time.

> Somewhat flawed idea in theory, even more horrible in practice. I hope this doesn't become a real thing. I will refuse to use any site that implements this flawed passwordless solution.

You've not presented any valid argument against it. Why is it flawed? If it is horrible in practice then why do many companies use SMS as secondary auth (for the "2" in 2-factor)?

sadfnjksdf··on Ask HN: Idea Sunday
While we're at it * :

Funding Monday - where everyone pitches to VC's in the same HN thread.

Trial Tuesday - where everyone provides a link to their demo in the same HN thread.

Writing Wednesday - where everyone writes an informative hacker-related topic on their blog and shares a link to it in the same HN thread.

Throwback Thursday - where people all share something informative about past experiences or past apps/etc. in the same HN thread.

Free Work Friday - where people request work to be done by volunteers to develop their product with a possible chance at employment at some future date all in the same HN thread.

* - with slight sarcasm

sadfnjksdf··on Ask HN: CTO wants me to leave
> the company is dead.

No, it's not. It means the relationship between the cofounders is severely damaged. The company may be fine.

Everyone is making the assumption here that what the CTO is doing is wrong. It may have been the right thing to do for the company. It is just the wrong thing for the OP.

I think the OP should lawyer up, try to get fairly compensated for his contributions, and end the relationship.

Business is unemotional. Those that invest their life into a business are emotional. Be true to yourself and it is ok to love what you do and enjoy who you work with and what you work on, but when it comes down to it, it is a job. Founders are no more special than any others. As soon as you start making significant progress from idea to product, ensure that you have clear written contracts setup.

There should really be a site for those beginning their company that provides sample contracts and talk about about the pros and cons of each approach for ensuring that when relationships end, things are handled in manner civil and with prior understanding of how things work. It could only be a good thing, because the incentive will be there to work more effectively in order to contribute in a way that will end in value immediately and/or later, regardless of the outcome. There are a lot of people that specialize in helping people in this regard, but I can't think of a site that is specifically for the purpose I'm speaking of.

sadfnjksdf··on How *NOT* To Do A Password Field
On a related topic, a troubling new trend (to me) is the reliance on passwords being automatically generated/kept by a tool. You are putting your trust in something else for something only you (or a select group) should be trusted with. If everyone were to start doing this or a vulnerability was found in it and exposed, then attackers would exclusively target the tool or the password store, making many at risk.

It is a trade off, because you have the ability to use significantly more complex passwords that are harder to brute force or guess using personal information. Just don't forget that you are providing new attack vectors in the process. If they access your password store and you didn't know about it, how at risk would you be if they were to unlock all of your passwords?

Do you really understand how the password store and password generator work?

sadfnjksdf··on How *NOT* To Do A Password Field
> Don't let a user submit a password which doesn't meet your requirements. Use JavaScript to disable the button and highlight the text of your password policy.

If you are going that route, please change last line to:

"Use JavaScript to disable the button and highlight the text of your password policy (in addition to server-side validation)."

However, consider using a "poor password", "good password", "great password" approach that changes as you type and don't have a short max length in your validation, this way you can promote entering sufficient complex passwords of longer length. The best of these I've seen is a "progress bar"-looking thing under the password fields that also uses color changes (just don't use green as bad and red as good, and be aware of color-blindness/blindness) and text under it to describe how good or bad the password is.

Here is one of Microsoft's recommendations. It looks a lot like the cartoon in the post: http://technet.microsoft.com/en-us/library/cc786468%28v=ws.1...

That helps but is far from good enough. Read: http://en.wikipedia.org/wiki/Password_strength

Focus a bit on entropy to go with that colored-progress bar I talked about:

"It is usual in the computer industry to specify password strength in terms of information entropy, measured in bits, a concept from information theory. Instead of the number of guesses needed to find the password with certainty, the base-2 logarithm of that number is given, which is the number of "entropy bits" in a password. A password with, say, 42 bits of strength calculated in this way would be as strong as a string of 42 bits chosen randomly, say by a fair coin toss. Put another way, a password with 42 bits of strength would require 242 attempts to exhaust all possibilities during a brute force search. Thus, adding one bit of entropy to a password doubles the number of guesses required, which makes an attacker's task twice as difficult. On average, an attacker will have to try half of the possible passwords before finding the correct one."

Following on that with: http://en.wikipedia.org/wiki/Entropy_%28information_theory%2...

That states the limitations thereof, so entropy alone is not good enough:

"Limitations of entropy as a measure of unpredictability

In cryptanalysis, entropy is often roughly used as a measure of the unpredictability of a cryptographic key. For example, a 128-bit key that is randomly generated has 128 bits of entropy. It takes (on average) 2^{128-1} guesses to break by brute force. If the key's first digit is 0, and the others random, then the entropy is 127 bits, and it takes (on average) 2^{127-1} guesses.

However, entropy fails to capture the number of guesses required if the possible keys are not of equal probability.[17][18] If the key is half the time "password" and half the time a true random 128-bit key, then the entropy is approximately 65 bits. Yet half the time the key may be guessed on the first try, if your first guess is "password", and on average, it takes around 2^{126} guesses (not 2^{65-1}) to break this password.

Similarly, consider a 1000000-digit binary one-time pad. If the pad has 1000000 bits of entropy, it is perfect. If the pad has 999999 bits of entropy, evenly distributed (each individual bit of the pad having 0.999999 bits of entropy) it may still be considered very good. But if the pad has 999999 bits of entropy, where the first digit is fixed and the remaining 999999 digits are perfectly random, then the first digit of the ciphertext will not be encrypted at all."

But, even checking for common passwords (search and you can find numerous articles on that), etc. is not good enough. You must also tell people not to use easily guessable personal information in their passwords. Your birthdate, then "$" then your son's name then "$" then his birthdate may have "ok" entropy, but it would be easily hackable for anyone with elementary knowledge about the person.

That starts to get into the fallacy of security questions to reset your password, though. Security questions are terrible, and I cannot believe that financial institutions use them. If you hack the email account and know enough personal info, you bypass the password. That's bad.

But, everything is hackable, eventually. There are no hard rules that cannot be broken. Even our understanding of physics, etc. is incomplete. Anything is possible.

sadfnjksdf··on U.S. Daily Temperature Anomalies 1964-2013
Can't wait to see 2014. Right up there with... hmm, maybe not.
sadfnjksdf··on Amazon to acquire Comixology
I've not had a problem with the comics we've gotten from Amazon. If anything, the reader on the Kindle Fire HDX takes a little getting used to because you need to click to zoom to read a good bit of it. I've tried reading them on my laptop but can't get into it; I can't read books on a horizontal screen. Things will be much better with electronic paper, so it will be like a comic book again. Sure, I could buy an actual comic book, but what fun is that?
sadfnjksdf··on Firefox OS 2.0 starts emerging from its cocoon
Not anytime soon. Until it has a large share of the market, it won't be worth the time for developers to really come aboard, and the only way to get there is to have a large enough sized team driven to be better than iOS and Android, which they don't have yet, and probably won't, sadly. The mobile web trend has started to die back down, too, according to recent stats; writing apps in JavaScript for FFOS would make sense if it were just a matter of reusing the same served content.

But, I'd like to see FFOS do well. David against Goliath(s) sort of thing.

sadfnjksdf··on Hackers Lurking in Vents and Soda Machines
Misleading title- I didn't see much mention of a soda machine. :)
sadfnjksdf··on The Micro
I'm really excited about a low cost, quality 3D printer but:

1. How much is another spool once the kickstarter is over?

2. "In addition, when making the specification for the seamless frame of The Micro, we demanded only the best quality surface finish."

I don't understand. If the point is to be at a reasonable price point, why make a point of saying you are picky about design? I would understand print quality, but exterior design I could give a rat's ass about- a low quality printer would go into the closet or on the craft table, not proudly displayed for all.

sadfnjksdf··on Fog Creek's Intern Hiring Process
I never thought of Fog Creek that way before. In fact, I've always gotten the impression they were down-to-earth. But, that one shot of a spreadsheet in this post listing Brown, Rutgers, Princeton, Yale, etc. changed my mind.

The other turnoff in this was the weeding out of candidates based on resumes. We hired an excellent employee out of a batch of horrid resumes- what a great hire, though.

sadfnjksdf··on 2048 in 3D
I made more points by just going counterclockwise through the arrow keys over and over: 5368
sadfnjksdf··on Poll: How long have you been programming?
Me also! Had a hiatus on programming for this most part in university though, otherwise would be in same bracket.
sadfnjksdf··on Poll: How long have you been programming?
omg I now have empirical evidence that I'm old. The top of the curve is 10-15 years and I'm beyond that now. OLD!
sadfnjksdf··on Copying stdin to stdout in Java
grep is even shorter:

    grep $
That reads lines from stdin and echoes to stdout.
sadfnjksdf··on Mistakes we've made
I disagree with one "but" in this post. Rebranding is not optional/too expensive. It's THAT important. Don't not do it, and never give up on a necessary TODO. Good luck! You guys are doing great.
sadfnjksdf··on A decentralized anonymous marketplace
Fully decentralized means everyone has their own autonomous device to act as server and client of the transactions and has a usable decentralized (probably mesh) network. P2P over the standard net is NOT fully decentralized.
sadfnjksdf··on Why I like Java
> I was a professional Java programmer for three years

3 years is about the amount of time it took me to get a false sense of security in my understanding of a language, imo. After 3 years i thought I knew Java. After 3 years I thought I knew Ruby. I was wrong.

BTW- if I were to receive a question on my application asking how to read stdin and write stdout, that would be a bad sign.

> So yes, I enjoyed programming in Java, and being relieved of the responsibility for producing a quality product.

Many quality products I use have been written in Java.

> It was pleasant to not have to worry about whether I was doing a good job, or whether I might be writing something hard to understand or to maintain.

Though, I understand the intended meaning of "Java is too verbose", You can write code in Java that is easier to maintain. Java is not an excuse for poorly written code.

> The code was ridiculously verbose, of course, but that was not my fault. It was all out of my hands.

You get paid to write maintainable code that does what is intended. It was never "out of your hands".

I no longer like Java as much, but I don't think Java ever was a reason to sit back and let bad code happen.

sadfnjksdf··on The Corruption of Agile
Doing things in a list which allows reorder, choosing which items in that list will get done per time period, and communicating that in short time periods. That is a methodology of management which embraces change, not micromanagement. Scrum doesn't micromanage, managers do. If you are being micromanaged, quantify the overhead of meetings and planning vs. the amount of time being derailed or working on things that wouldn't have been prioritized. You may get more done without management, but is what you are getting done what needs to be done? That is what Scrum is about.

I think XP's original stories and tasks on note cards in planning meetings were a better way to shorten tasks than Scrum leaving that open though- time estimation can be a problem in Scrum without proper planning.

sadfnjksdf··on The Corruption of Agile
Ok. First off, there is no "Agile". There was XP. There was Scrum. There was Kanban. etc. No Agile. Agile originally meant "more dynamic than Waterfall" and had a connotation of being able to handle change. If you've never worked on a large Waterfall project, which many of you haven't, you just don't understand how bad it was.

And unlike others have said in this thread it has not been around for 10 years. It has been around for almost 20.

Why "Agile is what it is" is because no one could stomach the proper way to do these individual methodologies, so they just dropped process altogher and called it Agile. Then on the other side you've had loons for several years now selling certifications.

Don't diss on Agile. There is no Agile. There are remarkable methodologies called XP, Scrum, Kanban, Lean, etc. and great people and histories behind them. Read and learn about them.

sadfnjksdf··on DHH Ping Pong
http://www.miniclip.com/games/table-tennis/en/ ?
sadfnjksdf··on HTML is almost 100% responsive out of the box

  print "a = #{a} b = #{b}, c = #{c}, d = #{d}\n"

                 V
  print "a = #{a}, b = #{b}, c = #{c}, d = #{d}\n"
sadfnjksdf··on GameCube Emulation and Pixel Processing Problems
> no way in hell we'll be able to emulate those old, custom graphics cards with full accuracy and full speed using only general purpose CPUs

I see your logic there. Claim there is no way in hell it will happen and it will significantly increase the probability that it will happen.

sadfnjksdf··on Replacing `import` with `accio`: A Dive into Bootstrapping and Python's Grammar
And avra kadabra to you also.
Page 1 of 2Next →