HNHacker News
TopNewBestAskShowJobs

sqbic

22 karma · joined January 23, 2025

submissionscomments
sqbic··on Data Became Code: We Ran Code Inside Fortune 500s
They are seen as being the top-notch best of the best companies around, equipped with unlimited resources and endless cash to keep their stuff protected, detecting/blocking such issues in advance and preventing these kinds of things from happening in the first place.

Of course the "Fortune 500" usually also means that they are so big that they are divided into multiple completely separated departments/units, each with their own tools, practices and processes.

These issues have exploded especially since the dawn of DevOps. Devs have been developing with tight "agile" deadlines, the Ops part has been barely done as the admins were told they were no longer needed and they pivoted to "Cloud Architects" or such, and doing Ops is not "delivering" anything, so you don't get rewarded for fixing reliability issues unless they are visible to end users.

Just when organizations started to realize this doesn't fly in the long run and started to take back control with stuff like Platform Engineering, the Devs got equipped with tools that have even bigger blast radiuses and started running around with huge LLM-scissors and AI-agents with unlimited permissions, vibing stuff into production even faster, cheered and supported by the hyped up upper management sipping more KooLLM-AId.

Now that the water level is starting to rapidly drop, we get to see which organizations have been swimming naked.

sqbic··on Helsinki Hacker News Meetup
Nice one! As a seasoned industry veteran, I've been wanting to have something like this, and while there are many evening tech meetups going on around here, your schedule is much more suitable for the otherwise busy life! *starts karma mining to qualify*

Filled the form and included my email with the HN user ID just in case you'd be willing to deliver the meeting details that way when they've been decided.

The phone number is not associated with WhatsApp (never had it, and won't), but it works with Signal in case it would be more viable option for meetup info comms than email. Who knows, perhaps even a shadow group already exists there, or has potential to get established?

Thank you for arranging such gatherings, hoping to meet up soon!

sqbic··on Denmark: EVs Make Up 97% of New Private Car Sales in July
No wonder, the country is so small that any modern EV can drive it around completely with single charge. They also have abundance of especially wind energy, and the government recently dropped the electricity tax to EU minimum in order to make electricity very affordable for the Danish folks.
sqbic··on I love my Bluetooth keyboard
I tasted heaven for a moment with Planet Computer's QWERTY phones. Now that those are gone, I despise text communications with the phones that don't have a real keyboard and just want to avoid it overall.
sqbic··on Fixing a 20-year-old bug in Enlightenment E16
I love Enlightenment still, even the new ones. The most important component of it to me is Terminology. What a gorgeous and functional Terminal emulator.
sqbic··on SSH certificates: the better SSH experience
I've had very good experiences with SSH Communication Security company's (the guys who invented SSH) PrivX product to manage secure remote access, including SSH certificates and also cert based Windows authentication. It supports other kinds of remote targets too, via webui or with native clients. Great product.
sqbic··on macOS Tahoe 26.4 Beta 1 Adds Charging Limits to MacBook – Appleosophy
(Sorry for replying to this comment, apparently can't reply to the original post or the comment above.)

I've been using a software called AlDente by AppHouseKitchen on my MacBooks.

It still has some nice additional features over the new macOS Charing Limit feature, especially if using the licensed version (one time tiny purchase).

If just wanting to spare the battery of your older non-Tahoe Macs, even the free version works fine.

https://github.com/AppHouseKitchen/AlDente-Battery_Care_and_...

sqbic··on FFAB – Free GUI for FFmpeg
It's been impossible to not notice how often ffmpeg has been the answer to my various occasional multimedia conversion/processing tasks over decades. Still, seeing the GUI and reading the list of example possibilities made me wonder how much more it can still do, landing me at the wikipedia page. What an incredible bundle of software.
sqbic··on Stop Breaking TLS
While eps, edr, etc. solutions have their role in security and some of the products can be used for "TLS inspection" within the localhost already, doing the inspection in separate network appliance brings benefits such as (but not limited to) not needing to care if the client operating system is supported by the eps product or if the eps is functioning correctly, offloading the "heavy lifting" and policy enforcement to the appliances and ensuring that only actual real egress connections to specific services are inspected.
sqbic··on Stop Breaking TLS
What changed my mind to be in favor of TLS inspection at work environments was seeing what kind of highly confidential stuff employees might be copy-pasting to random websites, LLM assistants, cloud-based "desktop applications" and such against the approved use policies of each of these tools without giving it a second thought.

TLS inspection products can intercept the paste transaction before the data leaves the company network, hitting the user with a "No you didn't! Shame on you!"-banner and notify the admins how a user just tried to paste hundreds of customers' personal information and credit card details into some snooping website, or into otherwise allowed LLM chat which still is not allowed to be used with confidential information.

There can even be automations to lock the user/device out immediately if something like this is going on, be it the user or some undetected malware in the user's device attempting the intercepted action. Being able to do these kinds of very specifically targeted interceptions can prevent potentially huge disasters from happening while still allowing users more freedom in taking advantage of the huge variety of productivity tools available these days. No need to choose between completely blocking all previously unseen tools or living in fear of disastrous leaks when there are fine-grained possibilities to control what kind of information can be fed to the tools and from where.

There are plenty of organizations out there where it is completely justified to enforce such limitations and monitoring in company devices. Policies can forbid personal use entirely where it is deemed necessary and legal to do so. Of course the policies and the associated enforced monitoring needs to be clearly communicated and there needs to be carefully curated configurations to control where and how TLS is or isn't intercepted so employee privacy laws and regulations aren't breached either.