HNHacker News
TopNewBestAskShowJobs

skolor

768 karma · joined January 23, 2009

submissionscomments
skolor··on Run for Office: Find all elected offices you are eligible to run for
This (local political action) is something I've found interesting for a while, but never enough to actually get involved. Seeing this made me look up some data for the area around me, since I was curious and the OP didn't have enough data for my area.

Apparently the town council elections are coming up soon, with several slots available. If I'm reading through this data correctly, it would take about 2% of the town's residents to vote for a council member to knock out the incumbents, based on last year's election. Someone somewhat active in the community can probably arrange that.

skolor··on Run for Office: Find all elected offices you are eligible to run for
Apparently they're looking for volunteers (http://getinvolved.runforoffice.org/volunteer). I'm not involved with the project (although seriously considering volunteering), and it looks like they mostly just have scraped state/federal senate/congress/governor information and plugged it in, but aim to add more.
skolor··on Show HN: Learn how to build electronics with monthly kits
I have no idea about the quality, but I saw this kit getting posted on Twitter this afternoon: http://www.boldport.club/. It looks a little simpler, but may scratch the itch you're looking for.
skolor··on Why I Strive to be a 0.1x Engineer
The important part of the parent comment was "just like everyone else". For people who are employees, not stakeholders, recognition for success is important and the parent clearly felt they were not being recognized relative to their peers for what they were doing.
skolor··on Microsoft's Software is Malware
Note what the actual source for that says:

> Microsoft Corp., the world's largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process.

The implication being made in the gnu page is that Microsoft delays fixing bugs so that the NSA can exploit them. The source article says something slightly different though, that they inform "various" agencies prior to the patches going live. I suspect the linux kernel devs do too, or Firefox, or any number of open source projects. I'd be more surprised if none of the people on the security lists for those groups don't have a list of agencies (both US and otherwise) they send bugs to .

skolor··on Nine Charged in Insider Trading Case Tied to Hackers
I would imagine it's at least somewhat rare. The indicators for espionage and insider trading are quite similar: most spies are caught because of sudden affluence. Making a ton of money off insider trading is going to set off a lot of red flags and likely trigger an investigation.
skolor··on The most popular APIs and tech at college hackathons
Its my understanding that Azure is slightly better for students. Their Dreamspark offering, at least when I looked at it, was better if you got started in the first couple years of school.
skolor··on In Silicon Valley, many want sharing salary info to be less taboo
If it's shared in a corporate environment or anonymously, it shouldn't. I generally expect most of the people I work with the be in a +/- 10% band for my "peers", and +10-50% for my immediate management level, which my understanding is pretty accurate from the numbers I've seen.
skolor··on In Silicon Valley, many want sharing salary info to be less taboo
I haven't read that book, but isn't increased negotiating power for CEOs a more likely explanation than social embarrassment? If I've been chosen as the lead candidate for a CEO, it's a lot easier to justify a large salary if I can point at our competitors and say that I should be paid competitively to their CEOs.
skolor··on The old suburban office park is the new American ghost town
We've seen the reverse of this now. Everything I've seen has shown that newer generations are moving more into the cities, back to closer to their employers.
skolor··on Purism – Privacy-Respecting Laptops
I'm pretty put off that I spent 5 minutes digging around on their site and couldn't find one of those claims. All I saw was "Everyone is trying to steal your private datas, but for a large markup we can make you secure."
skolor··on Income of an uber driver
Presumably you would have less wear and tear on the car by driving it less. This entirely accepts the initial purchase of the car as a sunk cost, so the number of hours doesn't really factor in, the rest of the costs are all hourly, unlikely the car purchase which is a one time cost.
skolor··on FBI investigating vandalism of fiberoptic cables at Livermore
Why wouldn't they just drop their equipment and leave? Cutting cables causes a noticeable outage and requires people to physically visit the point of modification, which ruins the covert potential for such equipment.
skolor··on FBI investigating vandalism of fiberoptic cables at Livermore
No public information about a crime doesn't mean no clues.
skolor··on My Parents Were Home-Schooling Anarchists (2011)
I don't have any good introspection into what this number means, but according to this (http://www.nationsreportcard.gov/reading_math_2013/#/state-p...) 18% of 8th graders were found to be "Below basic" reading.
skolor··on My Parents Were Home-Schooling Anarchists (2011)
There's quite a bit of research to support this[1]. Basically, regardless of any other factors, increased parental involvement consistently shows better performance.

[1] https://www.nea.org/tools/17360.htm

skolor··on Seen that job listing for a while, its no coincidence
I've been making some grumblings, and would really like data to back things up. Would anyone who was recently hired (past year or so) mind sharing information about the process?

I'm mostly interested in the length of time from first contact->first day on the job, whether you think that is a reasonable amount of time, and the rough size of the company (or the name, but I understand people not wanting to share that)

skolor··on Seen that job listing for a while, its no coincidence
I work for a pretty large company, and the more involvement I have with the hiring process the more painful it is to see. We just move so incredibly slowly, with frequent false starts, and we've lost a number of good candidates because of it. I'm fairly concerned we're going to lose someone I referred because of it, but there's only so much prodding I can do and that doesn't serve to fix the problem.
skolor··on The Netflix Website Gets a Major Upgrade
Its actually the opposite that annoys me: if I was watching a TV series, the last time I was logged in I watched episodes, and there are still remaining episodes, stop asking me to rate the series. Its a minor but consistent annoyance that I'll be 3 episodes into a series and it wants me to rate the entire series.
skolor··on Improve your touch typing
At least in vim, you can remap just about anything that you want to.

The reason the feature doesn't get included as often is because of exactly this. Even someone who could make use of the feature, and is annoyed by the current keybindings, doesn't take advantage of re-binding. The reason it is available on video games, on the other hand, is because its necessary for controller support, which a large enough portion of the video game community uses for it to have high demand.

skolor··on United Airlines bug bounty program
Compared to other bug bounties it isn't bad at all. Airline miles are generally valued at around a penny a mile, so $500 for XSS, $2500 for an auth bypass, $10000 for code exec isn't all that bad.
skolor··on How the DEA took a young man’s life savings without charging him with a crime
After looking through their data a little, I'm curious: who is paying all these bribes[1]?

7% of people who interacted with the police report paying a bribe to them? 11% for education I could believe, but 15% to the judiciary, 17% to "land services"?

Maybe I just need to step my bribe game up, but that seems significantly higher than I would have expected.

[1] http://www.transparency.org/gcb2013/country/?country=united_...

skolor··on Resource-Rich PhD-Level Self-Education
I've always liked this - http://matt.might.net/articles/phd-school-in-pictures/ - as a description of what exactly a PhD is.
skolor··on Your cyberpunk games are dangerous
That's not really the choices available. The options aren't NSA reports bugs/uses them for intelligence collection, its NSA uses bugs for intelligence collection or they don't find bugs at all.

Its possible that the right answer is we should have a US agency finding bugs and getting them patched, but it certainly shouldn't be any of the intelligence agencies. That feels a little too like putting the military in charge of the police force.

skolor··on Ripple fined for acting as a money services business without registration
Don't forget that "they chose freedom" for a population of 2.5 million people[1]. That's less than Chicago or Nevada, today. The original thirteen colonies had a population density slightly lower than Wyoming.

The whole idea that the Founding Fathers had some perfect vision has always struck me as absurd. Even ignoring technological advances, the country now has more than 100x the population crammed into 9x the space. They made decisions for a country that is vastly different from what we have today.

[1] http://www.nam.ac.uk/exhibitions/online-exhibitions/war-amer...

skolor··on Obama signs executive order allowing government to seize hackers assets
Its my understanding that this just adds another reason the Secretary of the Treasury can add someone to the SND list[1]. The ability to this already exists for other reasons, such as "terrorism" and drug trafficking. The executive order just added "Cyber" to that list.

[1]: http://www.treasury.gov/resource-center/sanctions/SDN-List/P...

skolor··on NSA's Backdoor Key from Lotus Notes
That gives you the worst of both worlds, though. You get the major developmental downside of a backdoor - making sure no one in the development pipeline finds and removes it - while still having to do the non-trivial work of actually exploiting the bug. Admittedly I don't have real experience with the 0-day black market, but the internet tells me I can just show up with $200k and buy a Chrome/Windows/iOS 0-day, if I know the right people. I find it hard to believe its actually cheaper or even easier to backdoor software than it is to just buy the exploits.
skolor··on NSA's Backdoor Key from Lotus Notes
So, serious question:

Why would they backdoor Windows, when apparently they could just buy an exploit for $X00k[1]? Its seems buying an exploit serves all those same factors, at a similar price range, while making it much harder to point a finger at the NSA when it eventually gets discovered.

Its probably a safe assumption that if someone is found using a backdoor in Windows, its probably the US Government that put it there. If its an exploit, its a hell of a lot harder to point that finger at anyone in particular.

[1]: http://www.rand.org/pubs/research_reports/RR610.html

skolor··on Gemalto's findings of its investigations into the alleged hacking of SIM cards
From the article, it sounds like they just looked at old incident reports and said "yup, these two are 'sophisticated,' they could be the NSA/GCHQ."

Its a little disturbing that the "sophisticated" attacks they detected don't really sound all that sophisticated. Is spoofing an email and sending a PDF/Office exploit really considered sophisticated? While its a step above the most basic script-kiddie type stuff, that isn't unreasonable for even normal pentesting to do, and I wouldn't consider it an indicator of a nation-state attacker at all. Even if the attack was using 0-day in the attachment viewer, its not unheard of for malware kits to employ similar techniques.

It definitely says something that those attacks were at least partially successful against systems Gemalto thinks could have resulted in the theft of sensitive crypto keys.

skolor··on How the NSA’s Firmware Hacking Works and Why It’s So Unsettling
I think the generous interpretation is that the US Security companies simply don't get as much collected data in the areas being targeted by the US intel agencies. I don't have any real data to back it up, but I would assume Kaspersky has a much higher install rate in Russia than, say, Symantec. I wouldn't be surprised if the same is true for much of the middle east, too.

Its especially interesting that the mere assumption that the US security companies are covering for the intel agencies is going to make it look more like they are. If Kaspersky is on 90% of the computers targeted by the NSA/CIA, they're going to be much more likely to get the data necessary for this kind of analysis, which reinforces the thought that the US companies might be covering it up.

Page 1 of 10Next →