HNHacker News
TopNewBestAskShowJobs

scolson

267 karma · joined October 16, 2013

[ my public key: https://keybase.io/scolson; my proof: https://keybase.io/scolson/sigs/yyI1Z5vFBBh8LcqmA-mZlRrEZB4bNLrW8i9Qmu0HV1I ]
submissionscomments
scolson··on Ask HN: Who is firing?
Obviously, they should consult a lawyer, but I want to clarify this point, because the parent comment can be very misleading.

If you have a specific employment contract, all bets are off and only your lawyer and the courts can really determine what is/is not a permissible dismissal.

Assuming no contract, "cause" needs vary by state, so you can't just trust the parent message. In At-Will states, most of the time, you can be fired for any reason (except protected reasons) at any time including "asking too many questions", "asking the wrong questions", "not asking enough questions", or "he/she looked at me funny and I was in a bad mood." All are perfectly valid reasons for an on-the-spot dismissal in an At-Will state.

Now where it gets trickier is filing for unemployment. This can be harder to navigate than simple At-Will rules. In my state, all of the following will be docked against the employer for unemployment compensation:

* Just felt like firing someone

* Asks too many/not enough questions

* Constant quality issues

* Couldn't actually code and in a developer role

In all of the above, it is expected that the employer either should have figured it out before hiring, or should train/retrain to address the situation.

If an employer fires you for a policy violation, then unemployment will not be charged back to the employer (and likely the employee is not "unemployment eligible"). Usually this involves a longer paper trail with multiple meetings and "official" written notice of a policy violation in your company file before being terminated. Generally, this is a CYA thing for the employer so you cannot claim "you didn't know."

Protip: If there is a bs policy that everyone violates, you can still be fired for-cause for violating it. Chances are if this happens, someone really doesn't like you and they want a good reason to get you out.

But in all cases in an At-Will state, you are still out of a job.

(PS: You notice I do not name my state. Since this is an already tricky situation, assume my state is fictitious, and the rules and experiences are equally made up. Ask your lawyer or the equivalent of your state's (un)employment department/commission/branch for how things apply in your state.)

scolson··on MacOS Sierra Server
As others have said, the general stack is good for small businesses, and they will likely just run it on a mac mini.

The one component that any sized org can really benefit from is the caching server, which stores app store and OS updates on the local network so your 10 or 1000 machines aren't all saturating your internet connection. Even here, running it on a Mac Mini isn't that big of a deal as it is neither mission critical nor underpowered for this one task. And given the size, a mini almost fits anywhere.

scolson··on MacOS Sierra
Hijacking this to point out about as comprehensive a list of software compatibility with Sierra as I have found: https://roaringapps.com/apps?platform=osx&os=sierra

I have used it on past releases (El Cap, Yosemite, etc) and it has always been a great source for tracking the software I care about as a developer.

scolson··on Proxmox VE 4.2 released
The prompt is nagware. The code is opensource. If you want, you can go and modify the file that issues that prompt—lots of other people have. Google for it, and you should find the solution.
scolson··on The Elephant in the Room: Web design work is drying up
Small/Medium Business
scolson··on Swift is Open Source
You can retroactively make a license more open, but you cannot retroactively make it more closed.
scolson··on IntelliJ IDEA 15 Released, Adds Kotlin to the Family of Supported JVM Languages
While you can do most things in IntelliJ, they are often a step or two removed. It is often much nicer to just use the language specific IDE except for times when you need to be going cross-language in a project.
scolson··on Ask HN: How to Find the Best Info on Cancer Treatments?
My daughter had cancer. Fortunately, she is still clear, but I have a pretty good idea what you are going through, both emotionally and with respect to finding qualified information. For what it is worth, I am very sorry your family has to go through this diagnosis and whatever comes next. Cancer sucks.

From everything my wife and I could find, there is no such clearinghouse that is publicly available for what is the "best info," or for readily comparing studies. Because the research on treatments is changing so rapidly, it really does take a scientist (read: your oncologist) to filter through the different papers and compare the stage-based 5y EFS rates, review risks of that treatment, and figure out the pro and con to your relative's situation to determine the best treatment protocol.

This is further complicated by the fact that not all protocols and studies are publicly available. Some groups actively hide information from public view to prevent the "Web MD" effect. The treatment protocol we ended up with for my daughter is widely used and studied in some countries, but was never before used at the hospital we were at. We felt very comfortable with it when we reviewed the literature with our hem/onc, but as the doctor was part of a particular oncology group that shares research and studies, only they could find the critical information. At one point I was looking for more in-depth details, and because of the restrictions by the oncology group, our Dr had to be very careful about what they could and could not show us. I could read some studies in their office on their screen, but could never get a copy of the PDF.

Trust in your medical team. If you aren't getting the information your family needs, ask for more. If you still feel like you aren't getting enough information, then maybe re-evaluate if you have the right medical team.

Now, all of this is written as if you get to have contact with the medical team. If the close relative doesn't want you to have access, please respect their right to pursue the treatment your relative and their doctor have selected as most effective for their highly individualized case. Support them in their quest to get the right information, but don't pry and second guess. I come from a family of medical scientists and medical professionals, and believe me, there can be a very fine line between curiosity and help, and prying.

Good luck to you and your family.

scolson··on SpaceX – Launch Vehicle Failure
I was wondering what happened. This was my first time watching the live stream so I wasn't sure if that was normal or not.

Edit: They just called it, they had an "anomaly."

scolson··on Digital Ocean Private Networking Is Not Private
Most data centers actively want the default private networking to work across the datacenter with everyone. A better term would be non-routing. Rackspace calls theirs "service net". These non-routing networks encourage people to use cheap internal bandwidth (rather than bounce of an expensive leased line just to come back in) and possibly offer a special service just to that data center's customers. There are tons of companies offering sql and nosql databases as a service, and any number of other offerings.

Most cloud providers recommend you configure your firewall rules keeping in mind that other people could be on your internal network connection. This is really a security best-practice anyway.

scolson··on Ask HN: What's left for early startup engineers as the company grows?
Frequently in VC backed companies, founders are removed from the CEO role if they aren't showing the ability to monetize and determine "what's next." Sometimes the founder goes to a glorified secondary tech role like a fellow, and sometimes they leave the company all together.
scolson··on Up to 12M websites may have been compromised via Drupal vulnerability
I read that article last night and was wondering if someone here was going to point out how the 12m figure is made up.

Were there compromised sites? Sure, but I would be surprised if it were more than an order of magnitude less than what the bbc reported. That is still a lot of sites, but not a monumental cluster-fsck that the aftermath is being made out to be.

scolson··on Drupal 7 SQL Injection Vulnerability
Was it a simple fix? Certainly an elegant one. Excluding Drupalcon, I'd imagine it took some amount of time to determine the scope of the problem (was this the only avenue?), best method of resolution (there might have been a few ways to patch this that were more complicated before settling on this one), and then testing to make sure additional problems were not introduced on possible fixes.

This was a pretty critical part of Drupal core, so it would be irresponsible to rush out a patch without proper testing and analysis. Could it have been done quicker? Maybe. But I don't think this is a completely unreasonable period of time.

scolson··on Fundraise, find a cofounder, or both?
Ditto crowdfunding.

You might also consider finding a tech person who can become your CTO if you are not especially strong in technical areas. If you are thinking you might go this route, you might consider doing it before a kickstarter campaign so that you can add some degree of legitimacy (and they can hopefully hype it).

Edit: Why limit your kickstarter to a home version? Different tiers = different markets. Have a plan to not need the croudfunding route, but if you can pull it off, use it to accelerate growth.

scolson··on Ask HN: Do you still use an RSS reader?
Yes, feedly since google reader died. I follow almost 100 different feeds with varying degrees of attention (categorized accordingly)
scolson··on GoTenna – Send and receive messages even when you don’t have service
I wonder how hackable these will be, or what kind of bandwidth you might be able to push. I could see putting one at my home and one at my office to create a poormans wireless bridge.
scolson··on Security at scale at Google [video]
I really wish I was able to get more out of that talk. Sure, it is nice that Google cares about security, but their advice for developers seems to be: 1) Enable TLS 2) Don't ignore chrome/android warnings

Really Google? There isn't anything else more interesting or useful to say? Sure, both of those two points are important, but I would wager a very significant percentage of people in the room (and people watching online) already know both of those points, probably already implement them, and were watching in the hopes that they glean some new useful bit of information.

scolson··on Show HN: Checkr.io – API for background checks
Isn't the point of the test to get exactly what I can expect as a result as a paying customer? Otherwise, what am I really validating?

I will happily email daniel for deleting the personal data. While that works well for a HN comment thread, I still think it shouldn't require interaction on your part.

scolson··on Show HN: Checkr.io – API for background checks
As a follow-up, is your privacy policy industry consistent? For a group disclaiming any warranty over storage of personal information, it seems that much more vital that customers would have a way to manually delete and/or auto-purge the records so that we can minimize risk.
scolson··on Show HN: Checkr.io – API for background checks
Like someone else pointed out, it would be ideal to be able to delete reports (or at a minimum ssn information).

The site looks nice and clean. After running a report on myself, I noticed it said for a minute or so that my ssn was incorrect before it changed to stating it was cleared.

Also, while the national check for me came back clear (as expected), I was curious if that was literally all the report said. I would love to see more detailed reporting underlying the results. Obviously if it doesn't say anything more than "clear" or "no results" or something, then this probably wouldn't be useful.

Pricing-wise, I think it is somewhat fair and were I a bigger company with an HR group, you would be a solid candidate as a vendor.

scolson··on Show HN: Subscription Billing for Developers and Startups
This looks interesting! Was there a video demo somewhere though? I have a vague idea of what you are trying to do, but I'd love to see the interface (our admin and our customer side) before creating an account to see what we think.
scolson··on New Entry Level 21.5-inch iMac
SSD and Fusion are BTO options just like on the rest of the iMac line.

My bigger complaint is that the RAM is non-upgradable even as BTO. I really couldn't imagine if I had to bring my computer back down to 8GB RAM from 16.

scolson··on SaaS Builders: Beware The Free Trial
Of course unlimited free trials are subsidized by paid customers. It is a marketing cost and is baked in to the CAC figure that every SaaS should known and understand.

The trick isn't removing free trials, or changing unlimited to limited. Instead, the trick is to find the sweet spot between costing as little as possible while offering enough functionality that someone can actually figure out if it might be worthwhile for their use without giving them too much that they never pay. It strikes me that the OP was too far to one end of the spectrum--knowing their demographic as they were hoping to, they offered a trial that was bigger than the average podcaster would ever use. Where is the incentive to convert if you can get what you need for free?

While I would never presume to know the OPs business like they do, from a strictly personal standpoint, I find great utility in the unlimited-time aspect if budgeted appropriately.

scolson··on SaaS Builders: Beware The Free Trial
I am a huge fan of the unlimited (duration) free trial. How many of us sign up for something, poke at it, forget for a few weeks, and then go back again more seriously? I'm sure I do it all the time. By the time I remember, I am most of the way through a trial period and haven't actually evaluated wether the product is a good fit for me or not.

Regardless of how long your trial runs, people really need to bake in resource limits. I assume most SaaS companies have offered (or will offer) tiered rate plans based partially on consumption, so if you are starting as a free-only beta, why not bake in some sane resource limits from the start? Some ideas for this might be:

* maximum podcast size/duration (10 min or 3MB free?)

* 4 free uploads, then you pay

* Retention period - free accounts only store data for 30 days from upload

Sure, you are still technically paying for the free folks, but you greatly limit the cost damage while providing reasonable motivation for people to move to a paid tier when they are ready.

scolson··on Stripe Open-Source Retreat
OpenSSH originates from the OpenBSD developers. While the OpenBSD foundation could always use more money, they are no where near as bad off as the OpenSSL team was/is.
← PreviousPage 2 of 2