HNHacker News
TopNewBestAskShowJobs

semenko

1,034 karma · joined April 1, 2011

nick.semenkovich.com / semenko@alum.mit.edu / @semenko

Physician Scientist (MD/PhD) & Infosec Enthusiast

Via MIT EECS / WashU Med / Mass General Brigham

https://meet.hn/city/43.0386475,-87.9090751/Milwaukee

submissionscomments
semenko··on Incident with Actions – Resolved
GitHub's COO shared this under-reported X post last month [1] on their exponential growth. I'd love to see more proactive messaging on their growth rate / vision for agentic interactions.

> … platform activity is surging. There were 1 billion commits in 2025. Now, it's 275 million per week, on pace for 14 billion this year if growth remains linear (spoiler: it won't.)

> GitHub Actions has grown from 500M minutes/week in 2023 to 1B minutes/week in 2025, and now 2.1B minutes so far this week.

[1] https://x.com/kdaigle/status/2040164759836778878

semenko··on Google Workspace CLI
I have "Advanced Protection" turned on, so I just can't use this at all, because my newly created Google Cloud GCP app isn't trusted (even though I own it and I'm requesting read-only scopes). What a mess.

  Access blocked: [app name] is not approved by Advanced Protection. Error 400: policy_enforced
semenko··on NIST was 5 μs off UTC after last week's power cut
I found the most interesting part of the NIST outage post [1] is NIST's special Time Over Fiber (TOF) program [2] that "provides high-precision time transfer by other service arrangements; some direct fiber-optic links were affected and users will be contacted separately."

I've never heard of this! Very cool service, presumably for … quant / HFT / finance firms (maybe for compliance with FINRA Rule 4590 [3])? Telecom providers synchronizing 5G clocks for time-division duplexing [4]? Google/hyperscalers as input to Spanner or other global databases?

Seriously fascinating to me -- who would be a commercial consumer of NIST TOF?

[1] https://groups.google.com/a/list.nist.gov/g/internet-time-se...

[2] https://www.nist.gov/pml/time-and-frequency-division/time-se...

[3] https://www.finra.org/rules-guidance/rulebooks/finra-rules/4...

[4] https://www.ericsson.com/en/blog/2019/8/what-you-need-to-kno...

semenko··on The Karma connection in Chrome Web Store
I was optimistically hoping some of the MV3 changes would result in Chrome webstore policy enforcement being standardized, but that hasn't happened.

Sensor Tower (https://sensortower.com/) makes a lot of popular extensions, like StayFocusd https://www.stayfocusd.com/. They seem to resell ad data (in violation of [1]?) and ship likely obfuscated code [2] (in violation of [3]?), but there's no enforcement or even clear reporting mechanism.

[1] https://developer.chrome.com/docs/webstore/program-policies/...

[2] https://robwu.nl/crxviewer/?crx=https%3A%2F%2Fclients2.googl...

[3] https://developer.chrome.com/docs/webstore/program-policies/...

semenko··on A new way Ebola replicates
This is incorrect. The abstract clearly describes both cell line and in vivo experiments after modeling.
semenko··on Lung cancer pill cuts risk of death by half
Agreed! This specifically is for adjuvant osimertinib for EGFR+ Stage IB–IIIA completely resected NSCLC.

The headline here is really strong -- and the actual abstract is much more sober: "5-year OS rate was 88% with osimertinib vs 78% with placebo" [Full abstract is here: https://meetings.asco.org/abstracts-presentations/219805 ]

P.S. Hi Chris! (I think I picked up a summer student from you last week!)

semenko··on Outcomes after surgery performed by associate clinicians vs doctors (2021)
This title has little to do with the article (and keeps changing).

This piece compares non-surgeon MDs with non-MDs (medical assistants) performing minor surgeries in resource-limited settings.

Its a bit of an odd comparison, as the non-MDs have specifically trained in a 3-year program to perform minor surgeries (CapaCare).

semenko··on Will I Ever See the $36MM Oberlin College Owes Me?
>they wouldn't be able to afford it.

Oberlin has an endowment valued at approximately $1 billion — this is ~3% of that. (Understanding all those funds may not be liquid, they certainly have some assets.)

semenko··on NumWorks: An open-source graphing calculator (with Python and Rust support)
I just stumbled upon NumWorks and was excited to see some competition for TI's calculator monopoly [1].

It looks like NumWorks is open source (including the hardware) [2] and supports Python and Rust! [3]

[1] https://gen.medium.com/big-calculator-how-texas-instruments-...

[2] https://www.numworks.com/resources/engineering/

[3] https://github.com/numworks/epsilon-sample-app-rust

semenko··on 9,000-pound electric Hummer shows we can’t ignore efficiency of EVs
Carbon costs per-vehicle can be calculated based on your local grid power source, duration of ownership, and more: https://www.carboncounter.com/ -- be sure to click the "Customize" tab

If your annual driving distance is low (<5,000 miles) and your grid is relatively dirty (e.g. the midwest [SRMW] grid), a range of EVs have more CO2 emissions/mile than conventional internal combustion vehicles.

(This is a project from the MIT Tranick lab / http://trancik.mit.edu/)

semenko··on Workarounds to computer access in healthcare organizations (2015) [pdf]
Physician scientist here: this study is a bit dated. Many of these issues have been "solved" (depending on your threat model) within the last ~7 years. Most healthcare systems have adopted Imprivata [1] for SSO, where physicians tap a badge and are connected to (usually) a VDI session of Epic.

What this study misses is the real driver of EMRs: billing. EMRs exist to facilitate billing documentation to charge for patient care. Yes, they have other benefits (like viewing lab results), but if you ever see true critical care (at the bedside, in an ER, or in an ICU) little depends on the EMR (or even labs for that matter).

A few comments here talk about patient notes: in most clinical environments, inpatient notes are useless, and a tedium required to bill. They're filled with copy-pasted jargon to meet insurance company requirements. True patient care happens in less than ~1 paragraph of text called a handoff. [2]

[1] https://www.imprivata.com/

[2] https://bmjopenquality.bmj.com/content/bmjqir/7/3/e000188/F2...

semenko··on Bad government policy is fueling the infant formula shortage
The lack of a stockpile is due to limited shelf stability and long-term bacterial growth.

It's unfortunate Reason doesn't expand on the other side of this issue: the formula industry lobbied the FDA to reduce bacterial testing frequency (and inspections overall), with an emphasis on Cronobacter risks, arguing that the FDA "overestimat[ed] the expected annual incidence of Cronobacter infection". [1]

[1] https://theintercept.com/2022/05/13/baby-formula-shortage-ab...

semenko··on The Unreasonable Math of Type 1 Diabetes
Hey Graham -- great post! The Medtronic / Guardian sensor combo is generally disliked by patients, though (in the US) the Medtronic 770G is FDA approved for ages 2+.

Most prefer the t:slim X2 with "Control-IQ" (their hybrid closed-loop: https://www.tandemdiabetes.com/products/t-slim-x2-insulin-pu...), which is FDA approved for ages 6+, and works great.

The bleeding edge is the Beta Bionics (https://www.betabionics.com/) bi-hormonal system (insulin + glucagon), currently in clinical trials for ages 6+.

semenko··on Google Drive may restrict files identified as violating ToS
I don't quite grasp the panic about this: my impression is Google currently restricts ToS violations from sharing (your own access is retained).

The only change here is end-users will be explicitly notified (and can theoretically contest the decision).

semenko··on After months of delay, the House passes infrastructure bill
Apparently this is real — fascinating! ( The relevant text of the bill is here: https://www.congress.gov/bill/117th-congress/house-bill/3684... )

This builds on an NHTSA-funded pilot program called Driver Alcohol Detection System for Safety (DADDS; https://www.dadss.org/).

DADDS advanced two technologies for passive impaired driving detection: non-contact breath sensors (exhaled EtOH near the driver), and touch sensors (embedded into the steering wheel).

The bill adds this as a requirement on top of existing distracted driving prevention systems, which have been expanding but don't always get much press (e.g. Subaru's driver-facing cameras).

semenko··on First confirmed hatchings of two California condor chicks from unfertilized eggs
The mechanisms of parthonenogensis aren't fully characterized, but at a high level, it occurs in a secondary oocyte during meiosis II -- the oocyte only starts out with a Z or W chromosome.

It's perhaps best shown in this figure: https://rep.bioscientifica.com/view/journals/rep/155/6/image...

(Via this paper: https://pubmed.ncbi.nlm.nih.gov/29559496/)

semenko··on Decades after polio, Martha is among the last to still rely on an iron lung
Physician scientist here -- this is a unique and somewhat odd case where Martha prefers to use the iron lung over modern alternatives.

She would likely do fine with a modern non-invasive positive pressure ventilation (NIPPV) approach.

There are many patients with other illnesses (COPD, ALS, etc.) that depend on nocturnal ventilation -- most commonly nocturnal BiPAP (two pressure levels that support respiratory muscles).

semenko··on Pandemic Ventilator Project
Physician here; this isn't true for the ventilation of COVID patients, or ICU patients in general.

There's a difference between simple ventilator [1], and an anesthesia machine [2] that adds gas mixing, scavenging, etc.

ICU patients are anesthetized using IV sedation (a common regimen in the US is fentanyl/propofol), not inhalational anesthetics. Most vents only have simple inline filters to reduce contamination.

[1] A classic vent in the US is the Puritan Bennett 840. Here's its manual showing filters: https://www.medtronic.com/content/dam/covidien/library/us/en...

[2] https://en.wikipedia.org/wiki/Anaesthetic_machine

semenko··on Total cholesterol and all-cause mortality – a study among 13M adults
Probably because most data disagree with this comment. There's a ~20% relative risk reduction in vascular events & mortality per ~40 mg/dL decrease in LDL.

The CTT is probably the best summary of these data: https://www.cttcollaboration.org/

semenko··on Run Chrome apps in Electron
Yes, in fact: https://chrome.googleblog.com/2016/05/the-google-play-store-...
semenko··on Google Begins Rolling Out Google Play Music Family Plan
Back when Apps for Work was "Google Apps for Your Domain", non-business/vanity use was part of the marketing.

I use (paid) Google Apps for personal & family stuff - and this seems like a pretty arbitrary restriction on Play Music.

semenko··on Google Begins Rolling Out Google Play Music Family Plan
Yet another service not available to Google Apps users. :/

"You can only set up a family group with a personal Google Account, not a Google for Work or Google for Education account"

semenko··on Android libstagefright still exploitable
Whoops, yep -- definitely wasn't that clear. As pointed out below, the policy is linked to: https://android.googlesource.com/platform/external/sepolicy/...
semenko··on Android libstagefright still exploitable
The isolation seems mostly defined by this SELinux policy: https://github.com/android/platform_system_core/blob/lollipo...

   service media /system/bin/mediaserver
       class main
       user media
       group audio camera inet net_bt net_bt_admin net_bw_acct drmrpc mediadrm
       ioprio rt 4
You'd need another exploit to elevate from SELinux (and I think send MSSes for a self-propagating worm). Though given Android's abysmal patching, most Android kernels are also terribly outdated...
semenko··on How to Find the Wi-Fi Password of Your Current Network
No, it shouldn't. WPA2's 4-way handshake allows client/supplicant & access point to prove they both know the PMK without directly disclosing it: https://en.wikipedia.org/wiki/IEEE_802.11i-2004#The_Four-Way...
semenko··on Redirecting Stdio is Hard
Oh hey, any chance you could explain this bit of the /usr/bin/google-chrome script I've always wondered about? (Sadly, the bug is RVG.)

   # Sanitize std{in,out,err} because they'll be shared with untrusted child
   # processes (http://crbug.com/376567).
   exec < /dev/null
   exec > >(exec cat)
   exec 2> >(exec cat >&2)
Somehow child processes can abuse stdin/stderr/stdout in ... creative ways?
semenko··on Wait, Google Sent Me
Agreed -- see this never-ending Chrome bug: https://code.google.com/p/chromium/issues/detail?id=177351
semenko··on Wait, Google Sent Me
Yeah, if you really want to do this, you can use chrome.permissions with "optional_permissions" set in your manifest requesting all urls -- then call permissions.request() on invocation to add a specific host.

See: https://developer.chrome.com/extensions/permissions

semenko··on Wait, Google Sent Me
That granularity exists -- it's called activeTab: https://developer.chrome.com/extensions/activeTab

(Though it might not be possible to modify the referer with activeTab alone :/)

semenko··on Netflix HTTPS performance experiments for large scale content distribution
The first thing that came to mind was @agl's discussion of TLS's overhead with Gmail: https://www.imperialviolet.org/2010/06/25/overclocking-ssl.h...

It's a bit hard for me to reconcile "<1% of the CPU load" (Google) with "up to 50% capacity hit" (Netflix).

Page 1 of 4Next →