HNHacker News
TopNewBestAskShowJobs

superuser2

8,140 karma · joined July 2, 2010

submissionscomments
superuser2··on Mode Media shuts down, leaves bloggers unpaid
The newspaper was the primary way to get ads into the home. Each city paper had a Google-like position in that city's ad market.

Quality could be higher because ad reach was based in part on subscriber count, not just the attention-grabby-ness of particular headlines.

superuser2··on Room 641A
The entire strip between the trees and the base of the building.
superuser2··on Faking your death
Failure to pay child support is a crime. Depends on the kind of debt.
superuser2··on What If Urban Sprawl Is the Only Realistic Way to Create Affordable Cities?
Thirty minutes of time on a BART car, sure.

Suppose you live in the premium housing really close to the BART, so your walk is only five minutes to the station. Then another five getting through the fare gate and waiting for your train. Then your destination is an easy ten-minute walk from the BART. Great, but that's not a 30-minute trip, it's a 50-minute trip.

superuser2··on New York's Wi-Fi kiosks disabled after complaints of people watching
>For example every homeless is entitled to a shelter

This is an empty mandate unless there is actually money to fund >= 1 shelter bed per homeless person.

superuser2··on What If Urban Sprawl Is the Only Realistic Way to Create Affordable Cities?
> When cities make it difficult to meet and work with others, as they do when they sprawl

This doesn't follow. It's incredibly efficient, in time and effort terms, to get around sprawl. You just drive at 65mph on the wide-open freeways and up the parking lot with plenty of open space in front of every conceivable destination. I've never spent more than 30 minutes making a point-to-point hop where both points are in sprawl. Average case, more like 10. Traffic jams == not sprawl-y enough.

Thirty minutes for any public transit trip in San Francisco or Chicago (at least the parts I can afford) is like a once-a-year pop-the-champagne-corks celebration. Ten, forget it. Not gonna happen ever unless it's the corner store. Getting anywhere useful is usually abut 50 minutes. (I'm pretty sure this is the CTA's SLA. No matter the distance - past a point, roughly 50 minutes. Implies some design effort and a sophisticated balancing of slower and faster lines).

Sure, bus tickets are cheaper than car ownership, but our time is worth something too.

>just agglomerations of many towns without a center

This is precisely what the pro-density anti-car people on HN advocate: dense walkable neighborhoods, with no real solution for medium distance transportation. Tiny markets where local businesses get to price-gouge you because going to a competitor means lighting your afternoon on fire.

superuser2··on Is Running Good or Bad for Your Health?
This isn't quite the article's subject, but...

For a very rough wedge, suppose there were some other activity which didn't have all the positive perceptions around running, which created painful and debilitating injuries requiring medical attention as a matter of course, whose participants could all expect to require specialized medical equipment to go about their lives for a period of weeks to months, several times in their careers in that activity. Imagine there were a whole cottage industry of doctors specialized in patching these people back up and sending them on their way to go get injured again, driving up insurance premiums for the rest of us in the process. Imagine that this activity, and this industry, primarily targeted children and adolescents.

We'd go apeshit. There would be immense moral panic.

A cross country runner at my high school was newly on crutches every other week, sometimes for the third time, and no one batted an eye. Orthopedic surgeons make their careers on relationships with the families of athletic teenagers, and no one bats an eye.

Coming from a background where painful, traumatic injuries are not just something that happens to everyone on a regular basis, statements like "I don't see any harm" are insane.

(Yes, I know it is possible to exercise in ways that mitigate this risk, and I do so. Still, if you really think about it, it's kind of crazy how much we tolerate sports injury).

superuser2··on Why are Adults so busy?
I dedicate my professional life to chipping away at the "drive" required to lead a decent life, and I suspect most software engineers on this forum do too. Our greatest accomplishments as engineers, scientists, etc. are lowering the cost (measured in time and effort) of the things people need. The really deep ones, like food, energy, and medicine, get all the style points. Transportation counts too IMO, but even advertising and finance contribute to productivity (rather than making things cheaper, they make labor worth more).

Economists like to mention that just a few hundred years ago, an average worker's daily wages were only worth ten minutes of artificial light. Now they are worth more than 20,000 hours. This is progress. This is what we do.

Fuck the romanticization of poverty and hardship. That our children do not need to pour as much sweat as us into (literally) keeping the lights on is greatest joy of our success. That drive, grit, pain tolerance, and other survival-mode traits are no longer necessary or adaptive is the best thing that could be happening.

I suspect I will never be able to fully empathize with people who are sad about this. Different mindsets, I guess. Still, I think it's useful for us to be exposed to the opposing perspectives.

superuser2··on Announcing new tools, forums, and features
>Is it possible to set up protected branches, where I can say, only users X and Y are allowed to push to the master branch?

Yes. I recommend (and my employer uses) a Herald rule that admits pushes to master only if the changes are in an approved Diff (unit of code review). This way you get an enforced 2-man rule, but anyone besides the author can approve the change.

This is currently impossible with Gitlab AFAIK, and is the main reason I won't use it.

You can also configure Herald rules to add blocking reviewers to other people's Diffs based on arbitrary criteria (i.e. touches X file and it's a Tuesday). A Diff cannot be considered approved until all blocking reviewers have signed off.

Reviewers can also be groups, so you could say, for example, changes that touch Y file must be reviewed by Security, but any member of Security can sign off.

>Can I do a code review and then finalize it when I'm finished and does the author get notified with a summary like the new GitHub code review feature?

Yes, everything you do on a Diff is batched and happens all at once when you click "Submit" at the bottom. Inline comments, the free-form text box, and the action all come as one email.

> What I really like about the merge/pull request workflow of GitLab is, that multiple developers can work together on one feature branch while a merge request is open and can be used as a discussion platform for the changes - is this possible with Phabricator?

A Diff is really meant to be an individual's small, well-defined contribution. Multiple people submitting code to a one diff can get messy. This would be better modeled as many diffs.

You are allowed to land diffs against branches other than Master, however this gets messy. It is not a first-class use case. My employer does not collaborate on feature branches; instead we land half-finished features into master (and production) disabled by feature flags.

It is NOT a merge/pull-request workflow. It treats Git more like Subversion; Phabricator is a very sophisticated alternative to emailing patches around before SVN committing them (basically the equivalent of landing).

>Also I'm wondering how solid the issue tracking is, and if the project workboards can compete with Trello.

Issue tracking is totally solid, very configurable. Project workboards consist of tasks/issues, which are much more expensive to create than Trello cards: you fill out a pagelong form, pick type, severity, owning team, title, description, etc. vs just free-forming a title. However, you can drag tasks around the workboard just like Trello and it looks pretty similar.

>Can it be used by non-developers without giving them access to the code?

Yes. Permissions (and approval flows, and notification rules) are very configurable. Phabricator is well suited to a large organization with rules, but this suitability doesn't carry too much overheard.

I don't think you could collaborate on issues with customers. Nontechnical people in your company, though, totally - we do that.

superuser2··on Scalable and secure access with SSH
No I'm not.

>If things go south really really bad, we can just get the private key and sign certificates by hand.

Very clearly states that someone has access to the CA cert's private key outside the context of the automated signing service, and can use it to manually sign certs for users if the CA service is down. So the CA service can be bypassed if it goes down,.

superuser2··on Air Force video: F-16 pilot saved by automatic collision avoidance system
Wow, look at that altimeter. 5000 feet in a couple of seconds.
superuser2··on Someone Is Learning How to Take Down the Internet
The amateur radio community can't use encryption and, for the most part, is happy about this restriction.

A zero-privacy internet might be better than nothing, but I'm not 100% sure of that.

superuser2··on Weirdly broken Wi-Fi access points
I don't see why this is a problem. You want to free load on other people's connections but not share your own? (In the US anyway, the free wifi you get for running that secondary SSID just comes from other people's personal connections).

This is why we can't have nice things. I hope they find a way to defeat people doing this, but my guess is it would be prohibitively expensive (war driving entire cities, etc).

superuser2··on Scalable and secure access with SSH
>service dependency

A CA is just some bytes, not a service. And it has been established that there's a backup login path: use (a copy of) the CA outside of the automated certificate signing service to manually sign the needed certificates.

They'd be screwed if they lost the CA's private key, but it is much easer to keep some data around than to keep a service functioning properly.

superuser2··on Weirdly broken Wi-Fi access points
Standard procedure here is to ignore the device's onboard wifi and plug in your own access point. Don't tell them, or they may whine about it being unsupported.

You don't have to use the integrated access point just because it's there.

superuser2··on BMW Plans Board Shakeup, Change in Electric Cars Strategy
>2002 VW Jetta

Early 2000s were the worst years of VW in recent history. Things have vastly improved in Mk5, 6, and 7.

superuser2··on Startup employees don't earn more
> Superfluous income is disposable income

Only if you don't rent a nicer/closer apartment. (OTOH, lower commute times are associated with happiness).

superuser2··on The MI6 Spy Who Perfected the Art of the 'Honey Trap'
Far as I can tell, the intelligence community is a fork in the road on the career path to diplomat. You study languages, public policy, international relations, etc. You get State Department / vague US gov (National Security Language Institute - Youth) scholarships to fly to the middle east and learn languages over your summers. You do internships in college with State and think tanks. It goes from there. (This is probably more for analysts than field agents).

Of course, actual physical badassery is carried out by special operations divisions of the armed forces - you get there by being a really good soldier, sailor, marine, or airman.

The intelligence services do just have regular job boards, college recruiting, etc. too. And then there's private intelligence firms, which have some overlap with journalism (i.e. Stratfor and Reuters both sell intelligence services in addition to their publications).

superuser2··on The careless errors of credit reporting agencies
Each individual inquiry has a tiny effect. The point is that lots of inquiries indicate you are desperate for credit, and people who try to get a lot of credit at once are much more likely to default on it.
superuser2··on The careless errors of credit reporting agencies
>Credit card management has no indication how I'll manage a loan (whether a house or car) due to the nature of spending and utilization

I think the actuary-types who design the scoring models would disagree vehemently with this one. Scoring models are built from regressions on actual default rates.

superuser2··on The careless errors of credit reporting agencies
>web-of-trust like identity system

The most important thing about a government-level identity system is extreme difficulty of obtaining any identity other than the one you were born with. It seems inevitable in a web of trust that fraud rings would emerge to manufacture identities for those looking to escape debts, criminal convictions, etc by some combination of tricking and bribing people to sign authentications.

>You should be able to use any compatible product/software you like to sign orders to your bank with your private key

I'm not sure you should be able to use, say, a poorly written IE extension on your unpatched Windows XP machine. Something federated would be great, where any manufacturer can technically make something compatible, but it has to meet a FIPS standard or something.

Keys could be generated onboard, and then you upload your public key or something.

We're getting way ahead of ourselves - banks are extremely hesitant to use anything better than secret numbers. I'd rather a shitty 2FA implementation than that.

superuser2··on The careless errors of credit reporting agencies
What do you propose?
superuser2··on The careless errors of credit reporting agencies
No, pretty recent. After the regulation change.
superuser2··on The careless errors of credit reporting agencies
The factors are, in decreasing order of weight:

- Credit card utilization (balance as a percentage of available credit at last statement close)

- On-time payments (you just have to pay the minimum required by the date specified for it to count)

- Derogatory marks (collections, bankruptcies, foreclosures and liens)

- Average age of accounts (this favors older people who have been using credit a long time but not opening a lot of accounts recently)

- Total number of accounts (also rewards a mixture of types - car, student, credit card, mortgage, etc)

- Hard inquiries (very slightly dings your score if you're currently looking for credit, punishes you harder if you're desperately applying to everything you can find because this indicates financial emergency and therefore high risk).

https://www.creditkarma.com/article/credit-score-factors

If you use CreditKarma, it'll explain all this and how the values on your credit report fit in to the averages.

superuser2··on The careless errors of credit reporting agencies
Being an authorized user on a parent's credit card does build credit history for the child.

I did not have that, or any cosigned loan.

superuser2··on The careless errors of credit reporting agencies
Shared-secret numbers and physical cards are not enough. We need a cryptographic API that lets citizens sign requests to authenticate themselves, such that the signature they emit is only useful for one relying party at one time (not useful if stolen).

Fifty cryptographic APIs, on the other hand, would be a nightmare. We'd at least need the federal government to force states to implement one conforming to some open standard so that the integrations aren't intractable.

superuser2··on The careless errors of credit reporting agencies
> some entities are incompetent at verifying people's identity

Some entities are incompetent at verifying identity because some people are very loud about making sure a a modern ID verification system doesn't get built, because the ability to commit fraud is a civil right or something.

We need .gov smartcards. Or at least a .gov OAuth provider. Instead we are in the dark ages of shared-secret numbers (SSN, credit card, etc) and scans/faxes of easily photoshopped printed cards.

There is an argument this should be a private responsibility. For interactions on an existing account, this makes some sense - banks should be shipping hardware tokens, for example.

The big issue with identity theft is criminals opening new accounts under other people's identities, and this is a serious problem because the government will enforce that debt against people who didn't actually incur it. IMO it is government's responsibility to demand better proof of authenticity before signing up to enforce it.

superuser2··on The careless errors of credit reporting agencies
>you are trusted by definition

I felt pretty "trusted by definition." Citi gave me a credit card with a $3,000 limit as a college freshmen. A few years later I had an $8,000 limit card and a $10,000 limit card.

I bought my car certified-pre-owned under a program that writes favorable low-cost loans to recent college graduates with no or limited credit history (with an offer letter or paystubs).

You just aren't trusted with housing-sized amounts of money until you demonstrate responsibility with smaller dollar values first.

>basically creating debt and then paying it off

This depends on your definitions a little bit. You don't need to carry a balance and you certainly don't need to pay interest. You just need to create low but nonzero utilization on a credit card, pay it off every month, and not do anything else that might screw up your credit. I suppose you have debt in the interim between making the charge and paying it off, but most people don't consider it to be "credit card debt" if it goes away between statement cycles.

superuser2··on The careless errors of credit reporting agencies
Driver license numbers change when you move, so are not useful for things meant to be long term like credit.
superuser2··on The Falling Man
Because there were fire stairs.

The WTC (like all modern high-rises in the developed world) had a pretty impressive set of firefighting and evacuation infrastructure, procedures, and personnel. This training video goes through it pretty well [0].

- Smoke detectors and pull stations everywhere to ensure any fire is detected and responded to quickly (i.e. before it gets out of hand). There was a fire station across the street.

- A huge console for responding firefighters to see the location of alarm conditions, make building or floor-wide announcements, and even have two-way conversations with intercom stations on particular floors.

- Sprinklers and redundant power for the pumps that run them.

- Fans to push smoke out of the building and supply clean air to evacuation routes.

- Fire stairs, kept closed under positive pressure to keep smoke out, kept unobstructed by regular patrols, encased in material that wouldn't burn through for hours.

- A network of piping and wall-mounted hoses easily fed from the dedicated fire-truck parking.

- Fire drills, designated authorities for the evacuation of each floor, security personnel trained to watch over the fire alarm equipment.

It's not like the WTC wasn't prepared to evacuate in a fire. It's just that nobody anticipated all that infrastructure (pipes, stairwells, etc) getting sheared through by an airplane.

[0] https://www.youtube.com/watch?v=28laYNm5YNw

← PreviousPage 4 of 34Next →