HNHacker News
TopNewBestAskShowJobs

steelframe

5,213 karma · joined June 18, 2013

submissionscomments
steelframe··on Tell HN: John Friel my father, internet pioneer and creator of QModem, has died
Another software engineer chiming with QModem being one of his childhood core memories. Sorry for your loss.
steelframe··on VW breach exposes location of 800k electric vehicles
I'll never trust some rando working at a valet to treat my GRC right. I've seen too many dashcam horror videos of even people working at dealerships failing at manual and safe rev temps.
steelframe··on VW breach exposes location of 800k electric vehicles
I've owned two LEAFs. Fantastic vehicle. I only got rid of it when I realized all the cars around me were only getting bigger and heavier, and I felt I needed to get an SUV to defend myself against that.
steelframe··on VW breach exposes location of 800k electric vehicles
I pulled the DCM fuse on my GR Corolla. I can confirm that it disabled the microphone. One of these days I might get around to pulling the car apart and popping in a resistor in place of the antenna.
steelframe··on The paper passport's days are numbered
I fully agree one should own their own keys. I suppose in the case of my phone I feel I can't let perfect be the enemy of good.
steelframe··on The paper passport's days are numbered
Since I run GrapheneOS on a Google-less Pixel phone, I can't install airline apps. So what I typically do is use my web browser to check in for my flight and get a PDF of my boarding pass, then I take a screenshot of the QR code.

The last time I did that the TSA scanner was able to read the QR code just fine, but the tablet app that the flight attendant was using at the gate couldn't read it for some reason. After about 10 seconds of fidgeting with the tablet they asked me what my name and seat number was. I told them, and after checking the list they let me through onto the plane. It looked like they tapped around in the app to override the QR code scan or something.

Fast-forward 20 minutes, and we don't push back from the gate when it's time to depart. After another 5 minutes of delay they got on the PA system and said something about the passenger count being off and that the airline's headquarters wouldn't authorize departure until they figured that out. At one point about half an hour into this a flight attendant walked over to my seat and leaned over to adjust the air flow thingy, which I thought was a super weird and random thing to do. In all it took nearly an hour of everyone sitting on the plane at the gate before they figured it out and authorized departure.

I actually have no idea where the breakdown was, because this happened at the gate when I flew earlier and it wasn't at all a problem. I presume the flight attendant scanning QR codes at the gate didn't hit the right buttons on their tablet that time. If we're going to rely on peoples' completely random personal devices to track authorization to travel, our systems need to be a lot better than this. Exceptions to whatever they think should be the "typical" flow should be straightforward and streamlined.

In the meantime since they've gotten rid of kiosks in my local airport I guess I'll be going to the front desk every time and ask for printed boarding passes.

steelframe··on The paper passport's days are numbered
> What happens when the network goes down?

When I was traveling in London in 2018 I was barely able to pay for the groceries I needed in order to eat that night because I was checking out just as the global VISA outage started happening.

https://www.theguardian.com/world/live/2018/jun/01/visa-outa...

The machine took a long time to process my payment, but after a couple of attempts it managed to go through. As I left the store I noticed a long line forming for the self-checkout registers, and nobody else was able to get their payments to go through. There was apparently no option to fall back to cash at that store.

Whenever I travel now one of the bits of research I do now is to make sure I have a plan for getting basic necessities like food and shelter should an electronic payment system outage like that happen again.

steelframe··on The paper passport's days are numbered
> we still have checks and credit cards despite most young people just tapping their phone around

Unfortunately we're losing cash. There is one of those modern "chic" mixed-business-and-apartments developments not far from my house. Shortly after they completed construction my 12-year-old daughter visited the ice cream store there with her friends, but she couldn't pay for her ice cream when she got to the register because they didn't accept cash. They ended up just giving her the ice cream.

Most of the restaurants there have a "no cash" policy posted in their windows and at the till. No skin off my back. They're overpriced for what they are anyway, so I'm happy to give my business to other local restaurants not in the fancy mixed-use development.

steelframe··on The paper passport's days are numbered
I have a card passport that I can use when crossing the Canadian-US border by land. In fact just my driver's license is technically all I need.

The problem was when I caught COVID while on a trip to Vancouver. I was getting very sick and needed to get back home ASAP, but since I took the train I couldn't drive. All the car rental companies in the area were completely booked out. I thought, "Great, I guess I'll just go to the airport and catch a flight," except since I had crossed by land on the way in I didn't have the document I needed to fly out.

Fortunately I was able to find a bus early the next morning, but it was looking pretty sketchy for a few hours until I could figure out how to get back home. After that experience I'll never travel out of the country again without my actual passport.

steelframe··on The paper passport's days are numbered
Yup. You can always keep it powered off and in a Faraday sleeve until it's time to use it at the border. It should be possible to distribute a device that's smaller and lighter than a passport, and I'd be all for it, so long as it's at least as reliable and/or if there's a fallback process when it isn't.
steelframe··on The paper passport's days are numbered
I've simply been buying Pixel phones and using the GrapheneOS web installation tool. It holds your hand through unlocking the bootloader and flashing the new image on, and it always works without a hitch. Super-easy and reliable. I suppose you still don't "own" the radio firmware, but at least you can have a perfectly functional Google-free Android phone that way.

I suppose the real trouble comes from needing to install software from the Google Play store in order to travel. If you feel you need to do that you can create a new Google account just for that installation of the Google Play from the phone itself and then never give it any of your personal information such as a payment method. GrapheneOS claims to do a pretty good job of sandboxing Google Play components.

Regardless I agree with others here who think it should always be possible to travel without any electronics on your person.

steelframe··on Sherlock: Hunt down social media accounts by username across 400 social networks
The only personal information they're going to get from me will be what's in my libel lawsuit.
steelframe··on Sherlock: Hunt down social media accounts by username across 400 social networks
I recently Googled myself, and in the first page of results I ran across some shit AI website that scrapes random web content about people and attempts to summarize it. It got my current occupation completely and comically wrong -- as in, it has nothing at all to do with tech.

If you're trying to figure out anything about me from social media or other such random web pages, I don't care to have anything to do with you, and I don't care what you're led to believe about me. I suppose this is born of privilege, but the only contacts I care to make are directly via people I already have a relationship with.

steelframe··on Tell HN: I just updated my wife's Chrome, and uBlock is no longer supported
> If only Mozilla (the parent organization) wasn’t horrible.

Well, they're not getting any of my money, and they're not selling my eyeballs to any advertisers. For a while I used a filesystem written by a convicted murderer. I'm not sure at what point I'm supposed to avoid software because of who wrote it.

steelframe··on The era of open voice assistants
> Yeah, OP is comparing this to Google/Amazon/Apple/etc devices

Thanks; it seems I actually needed to spell that out in my post.

steelframe··on The era of open voice assistants
If it's possible for the hardware to facilitate a use case, the employees working on the product will try to push the limits as far as they possibly can in order to manufacture interesting and challenging problems that will get them higher performance ratings and promotions. They will rationalize away privacy violations by appealing to their "good intentions" and their amazing ability to protect information from nefarious actors. In their minds they are working for "the good guys" who will surely "do the right thing."

At various times in the past, the teams involved in such projects have at least prototyped extremely invasive features with those in-home devices. For example, one engineer I've visited with from a well-known in-home device manufacturer worked on classifiers that could distinguish between two people having sex and one person attacking another in audio captured passively by the microphones.

As the corporate culture and leadership shifts over time I have marginal confidence that these prototypes will perpetually remain undeveloped or on-device only. Apple, for instance, has decided to send a significant amount of personal data to their "Private Cloud" and is taking the tactic of opening "enough" if its infrastructure for third-party audit to make an argument that the data they collect will only be used in a way that the user is aware and approves of. Maybe Apple can get something like that to a good enough state, at least for a time. However, they're inevitably normalizing the practice. I wonder how many competitors will be as equally disciplined in their implementations.

So my takeaway is this: If there exists a pathway between a microphone and the Internet that you are not in 100% control over, it's not at all unreasonable to expect that anything and everything that microphone picks up at any time will be captured and stored by someone else. What happens with that audio will -- in general -- be kept out of your knowledge and control so long as there is insufficient regulatory oversight.

steelframe··on Updates to H-1B
> where the hiring company has even looked for US applicants

I've worked at a company where >90% of the technical interviews I conducted were H1-B hires. It makes perfect sense for a tech company to bias the applicant deck in this way for a few reasons. They're willing to accept a lower comp package. Once they're onboard, they will generally keep their head down, do whatever they're asked to do, and accept whatever working conditions they get without complaining. That said, I've known several brilliant H1-B workers. However I've noticed that they rarely stick their neck out and challenge the status quo, which can lead to bad ideas receiving unquestioning and persistent efforts to implement in spite of the writing being on the wall about that project's inevitable demise.

I've worked at companies that hire primarily non-H1-B workers, and I can tell you that the amount of complaining about working conditions in particular at those companies was a couple of orders of magnitude more raucous. The end result of a complacent workforce was a soulless office with ubiquitous infrared sensors, no available meeting spaces, a microkitchen stocked with a pittance of moldy food, and with floating workstations where the equipment was chronically broken or missing.

steelframe··on Egoless Engineering
> Stop making reactive decisions. If something bad happened on a total, extremely unlikely lark, don't act like it's going to happen again next week.

This is a central theme in Bruce Schneier's 2003 book Beyond Fear, which I continue to recommend 20 years after I first read it.

steelframe··on Intel announces retirement of Pat Gelsinger
I think Apple Silicon has shown us that x86 doesn't have the monopoly potential it once had.
steelframe··on Intel announces retirement of Pat Gelsinger
> any C-level exec will hold on to the position for dear life until they are forced out

I don't know. Frank Slootman's retirement from Snowflake earlier this year was certainly not celebrated by any significant stakeholders. I'd imagine at some point someone like Frank realizes that they are worth more than Tim Cook, they consider that they're in their mid-60s, and they decide the remaining time they have on earth might be better spent in other ways.

Every person in the workforce, no matter how ambitious or how senior, is forced into the calculus of money and power vs. good years remaining. I expect the rational ones will select the balance point for themselves.

steelframe··on What does this button do? – My new car has a mysterious and undocumented switch
My 2024 Toyota GR Corolla has a fuse that, when pulled, disables the Data Communications Module (DCM). It also disables the in-car microphone. At first I was mildly annoyed at not being able to make phone calls over a Bluetooth connection between my phone and the car's computer because of that, but the more I thought about it, I realized I was actually okay with the car's microphone also being disabled.

I often put my phone into Airplane Mode when I'm not actively using it, and I prefer to avoid the distraction of a phone call while I'm driving because I'm a terrible multitasker. If it's too easy for me to receive an incoming phone call when I'm driving then I'm too likely to do it when I really shouldn't.

In general I want as little data collection and reporting capability built into my car as is reasonably possible. I wish more auto manufacturers would make it as easy as Toyota did with the GRC -- and a few other of models, as I've heard -- to disable telemetry.

steelframe··on Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230
Speaking as someone who owns 3 Framework laptops, I was not disappointed to find Framework mentioned no fewer than 13 times in this comment thread. Assuming all goes according to plan with the moderation on this comment, now Framework is mentioned at least 16 times!
steelframe··on Is Chrome the New IE? (2023)
When I parked a rental car in downtown SLC last week I had to find a way to pay to park. There was a kiosk with a functional screen, but the touchscreen part of it was broken, so I couldn't interact with it. I plopped my stuff down and sat on a concrete bench in the cold and dark to try to figure things out on my phone.

The QR code sent me to a website to install an app. Google Play store said the app was designed for an older version of Android and couldn't be installed on my device. I eventually found a "pay online" link hidden down the page a bit, then spent several minutes filling in my credit card number and what not. Then when I got to the part where I was to select the expiration month and year, the drop-down menus simply didn't work. I had no way to continue in my default browser, Firefox.

It had been 7 or 8 minutes, the cold was starting to numb my fingers, and I was no closer to actually paying for my parking space. I debated just canceling my appointment and driving away rather than risk a parking ticket, but I decided to give it just one more try in the Vanadium browser. Lo and behold, the drop-down menus worked, and after over 10 minutes of messing with a broken kiosk, a broken app, and a broken website, I was able to proceed to the point where I punched in my parking space number. Which, of course, wasn't marked.

At that point I looked up and down the side of the street and noticed a post with numbers for two spots behind me. I noted which number was bigger to infer whether my space would be one higher than the higher or one lower than the lower and punched that in. After my appointment I came out to find the car parked behind me had a parking ticket, while my car didn't. So I guess I managed to punch the right sequence of buttons on my phone to avoid a parking fine.

However the fact remains that I couldn't legally park my car in Salt Lake City unless I was in possession of a functioning smartphone and was running a Chrome-based browser on it.

Not sure if this is more a story of Chrome being the only browser that's tested and/or compatible with critical services I need to use to function in a major U.S. city or if it's a story about municipalities like Salt Lake City making things as difficult as possible for people so as to collect more revenue from fines.

steelframe··on I quit Google to work for myself (2018)
Forgive me if I seem presumptuous in my advice here. You've done things in your career that I can only dream of doing. What I can say is that I've somehow managed to survive a quarter-century in a string of Big Tech companies without dropping out (yet).

It sounds like you may have been looking at the currents and picking the one that seemed best one to swim in. I found there's often -- but not always -- another option: build a dam. In other words, change it up. Alter the landscape. Seek to change the business in a way that nobody's been willing/able to do before. Looking back at my career I found I was happiest and most successful when I was able to tell my boss what I was doing vs. waiting for my boss to tell me to do something interesting/impactful/etc.

When that option doesn't seem to be presenting itself, it's probably time to move on. But I've found it's often worth giving it a try first.

A couple of times I needed to earn the right to create my own destiny by pushing through some grunge work, but once I established a degree of trust with my management chain, that was capital I could "cash in on" by proposing something big, new, and interesting. It never ceases to amaze me to see how boldness often gets rewarded. I just saw a co-worker of mine draw blood from a stone (funding-wise) by proposing something ambitious and controversial last week. Suddenly they're a TL of a new team this week. They've built a reputation for "just getting it done," so management has confidence in their ability to execute and drive results.

Whenever I'm starting to feel stuck in a rut, that's when I open a blank document and start hammering out a design for something new. I'm not even thinking about promotion when I do that. But somehow, somewhere down the road, either a promotion or a bigger opportunity with another company has always come of it.

steelframe··on RCE Vulnerability in QBittorrent
This is exactly what I do with any software that talks to the Internet. However I'd still really, really like for an advanced adversary to not have arbitrary RCE on my machine, whether it's in a container or not. Any zero days in my kernel that said adversary may have in their back pocket are then exposed for exploitation.
steelframe··on Record numbers of wealthy Americans are making plans to leave US after election
> They best vote first

The votes of all of the 1% are worth about one-hundredth as much as the votes of all the rest of us. They won't be missed. Except perhaps in one or two counties in a swing state.

The lack of their money sloshing into the political system, on the other hand, will very much have an impact.

steelframe··on ChatGPT Search
> Search is pretty much dead to me.

I've heard reports that requesting verbatim results via the tbs=li:1 parameter has helped some people postpone entirely giving up on Google.

Personally I've already been on Kagi for a while and am not planning on ever needing to go back.

steelframe··on Steam games will need to disclose kernel-level anti-cheat on store pages
> root kit that’d exfiltrate your credentials

Yes. I truly believe some janky random anti-cheat kernel module could very well capture telemetry about my keystrokes to a log and then send that log off to a server.

At the very least I don't trust that it's secure enough to be in the kernel of a machine for which I require any degree of trust in its integrity.

steelframe··on Steam games will need to disclose kernel-level anti-cheat on store pages
I built a separate Arch Linux box just for Steam gaming. I will never log into any of my sensitive accounts -- email, banking, etc. -- on that machine. It's a Framework laptop so I can physically keep the camera and microphone disconnected. I basically treat it like a public terminal.
steelframe··on Math is still catching up to the genius of Ramanujan
My education prepared me to make millions of dollars by the time I was in my mid-forties. I learned that if I take every task seriously and strive to do the absolute best I can on that task, no exceptions, regardless of how I personally felt about a subject or an assignment, I would end up being an employee that saw to it that anything I did, I did to the absolute best of my ability.

Not every task ended up being worth doing, but some sure did. And regardless, more important than any one individual tasks, I earned a reputation with management. This in turn resulted in a steady stream of bonuses, stock grants, and promotions. I suppose I was doubly-fortunate to have focused my efforts in the tech industry from the early 90's onward. You have to be really unlucky for nose-to-the-grindstone efforts in FAANG companies to not work out pretty well for you from 2003-ish until today.

With continued good health I can look forward to another 20 or 30 years of life, where I get to do whatever I want with my time because I earned so much money being content to conform to whatever my employers required of me. Nobody will remember my name, but that's okay with me, because I won't either.

← PreviousPage 3 of 30Next →