HNHacker News
TopNewBestAskShowJobs

temp667

206 karma · joined August 10, 2020

submissionscomments
temp667··on AWS Lambda Edge changes duration billing granularity from 50ms down to 1ms
Yeah - here's some coverage.

https://geoawesomeness.com/developers-up-in-arms-over-google...

That plus shutdowns of things - google is not most stable

temp667··on AWS Lambda Edge changes duration billing granularity from 50ms down to 1ms
Google has raised prices on all sorts of things - I think AWS is one with rep for not raising prices.

Maps API's I think went up pretty big time on google side.

temp667··on My Son, the Organ Donor
Post mortem the arguments are even easier then.

More organ donors would be a good thing, give folks $100 one time gift card for signing up - you'd have a ton of folks do that and the cost is tiny.

Maybe $2,500 to help with funeral expenses if you scoop all their organs out and sell them for $2.6M (that's probably average billed charges for a heart / kidney transplant).

Reality - the folks with the money (transplant surgeons, athletic directors in colleges) and their supporters here will NEVER share with the folks running around on courts and fields (college athletes) or providing the organs or whatever. You actually see this pattern over and over, usually with a fair bit of suffering on the side (folks not able to get transplants, injured college athletes etc).

temp667··on My Son, the Organ Donor
The issue is that you are supporting a bunch of for profit businesses making an absolute killing, while not even throwing table scraps to the key players, the donors.

If someone is going to harvest my Organs and get paid $800K+ per year (California Transplant Surgeon's probably average $750K and some are making $2-3M/year) it's really hard to swallow your and their morally superior tone.

temp667··on My Son, the Organ Donor
It's very interesting - sort of like college athletics. Everyone makes good to insane money - except the people taking the big health risks and/or putting in the hours.

A lot of moral outrage at the idea here though usually from folks getting rich off the industry.

There have been proposals to do something like $10 - $20K for a liver. The way to get around the outrage mob is usually to point out the health risks, impacts on life a quality of life etc.

In short, if you were in a car crash and lost a liver, you'd be getting a big pay day for those things.

Normal split is 1/3 or so to hospital, and 2/3 kept by donor network admins I think for the fees they charge for Organ acquisition. Donor Network West in CA does $90M a year or so I think? I'm not sure what annual fees are nationally, I'd expect in the 100's of millions range (this does not include all the costs to actual do the transplant).

That said, any discussion on this type of topic tends to attract of one liner type attacks from the outrage folks - so not usually worth having.

But folks are thinking about how to dramatically increase donor rates because it is so impactful. Other options have been to pay $100 - 500/year you list as a donor etc which would save incredible numbers of lives at what is relatively low cost. I heard one funny idea which was to do this for folks who get M class licenses (motorcycles). The idea was to both scare them about the risks of riding a motorcycles and of course they really are more likely to be a donor per mile riden (I'm a rider, and the stats are actually terrible in contrast to other things people worry about)

temp667··on Zoom zero-day discovery
the Pwn2Own exploits have generally not already been out there. There have been a long history of these, including some incredible chrome exploits! So the disclosure process tends to work out OK.
temp667··on Academic “ghost-writing”: the cheating scandal no one will discuss (2020)
Yes, keep on eye on HN posts, especially mobile browsers often have a very jumpy experience - common issues are various permissions pop-ups for things like cookies, and weird reflow issues as you scroll etc. Would it be helpful if I provided specific examples of crap laden or janky websites?

This is such a common issue HN site guidelines actually have a rule for this:

"Please don't complain about website formatting, back-button breakage, and similar annoyances. They're too common to be interesting. ..."

I've become more and more convinced the AMP haters just have total blinders on to the crap that websites spew - or are browsing with ad blockers or javascript blockers or something.

temp667··on Academic “ghost-writing”: the cheating scandal no one will discuss (2020)
does anyone know how AMP seems to avoid this (despite the hate here). On AMP sites I rarely get the post paint jumping around insanity.

My own metric - non AMP site + clickbait headline = jank and constant jumps as dynamic stuff happens (be it ads changing or show off or attention grabbers or analytics maybe).

temp667··on We found and fixed a rare race condition in our session handling
Huh? I want my bank to be VERY clear on when I transferred money for my home closing (and keep that record). They need to keep records and the browser used, IP used, authentication flow etc. Why does this have to be thrown away?
temp667··on Red Flags I Saw While Doing 60 Technical Interviews in 30 Days
Perfect - you'd be someone we wanted to hire!

But seriously, if you are in a business that has been around a while (20-30 year range) and likes folks to stay a long time - you just are not as interested in hiring the type of folks who want to set off bidding wars, drag out offers, counteroffers, job hop etc.

If the candidate is great, can always just say, would love to talk through an offer that would work for you. If they are reasonable - bingo - everyone is happy. Again though, these offers end up with a short expiration so I can get to next person if you don't want position after all that.

But I also pull down posting pretty promptly, do a quick 5 minute phone screen with lots of folks right away (same or next day after application) etc. so they can move on too.

temp667··on My bank sent me 64 copies of the same debit card
No bank should be sending cards to an address not on file - that is a major fraud risk 101 issue right there.
temp667··on Red Flags I Saw While Doing 60 Technical Interviews in 30 Days
72 hours is not a quick timeline. I've routinely set shorter (48 - 36)... Just say no if you don't like offer so company can move on.
temp667··on Red Flags I Saw While Doing 60 Technical Interviews in 30 Days
>I turned down the [exploding] offer because the experience got me thinking about the company’s work culture. Were the methods employed by the company to get me to accept the offer indicative of their work culture?

What I line - I would never hire this person. There are people who see big deals when much more obvious reasons exist, they just can't see beyond themselves.

In this case, orgs I work with our small, we almost always have a #2 and #3 candidate ready to go. It's rude to drag this out more than it needs to be for everyone, and it tells you how interested someone is if they want to sit on an offer. 2 days, let us know. If you are not interested, fine.

Note, I've normally already talked through comp packages and ranges early and asked them if this is in the range or what they are looking for. If they have been straight at this stage I normally get offers signed within hours. That's a good sign for everyone.

temp667··on Excel Never Dies
If something is driving you nuts, ask on a forum, because excel is EXTREMELY flexible and used in some pretty high volume environments and the original developers really paid attention to user input (for a long while that stopped).

In many cases you are just not fully up to speed with the features in windows / excel.

temp667··on Dr. Seuss books deemed offensive will be delisted from eBay
In my case - the downside to misgendering someone is extremely high. If my work day was to skip work and go hiking, or go into work and misgender someone, the latter has much higher downside consequences in some areas.

The other issue, I've had preferred pronouns change. I'm not sure if that has settled down, but there was a lot of new language / wording constantly churning. There was a him that was a her, but then I found out they preferred they instead of her - so I'd been mis-pronouning them even though I wasn't misgendering them.

Given the amount of risk involved in getting this stuff wrong, it really is safer just to use names.

If you use names, you need to use them for everyone. This can get complicated for some folks because names like Ted, Bob, Sue, Joe etc may be more familiar from a pronunciation standpoint for a white person for example, but then that person avoids pronouncing Khamala or Nkosazana because they are uneasy with how to pronounce the name. That becomes obvious pretty quickly.

Managers also have had some awkward situations correcting minority employees use of terms if the manager is of a different background, ie, someone saying latino community (who is themselves latino), and manager has to correct them that it is latinx not latino.

temp667··on Thanks HN: Lessons learned after Google nearly killed my site
First - most of these places are running pretty advanced virus / malware scanners. So when you go to download a file from drive etc, a scan is done (at least for files that are not enormous).

This is actually a big issue sometimes for folks who use google drive, because malware will infect their files, they will then be synced to google, then blocked from downloading them ever again!

That leads to support requests list this:

https://support.google.com/a/thread/60528209?hl=en

Even if you pay the ransomeware fee, google WILL NOT let you access your own files again. So years worth of files - GONE.

They do use different origins for these services. Google DOES actively ban users (everything, youtube, drive and email) from their service even users using google services (vs a third party upload service). Ie, if you are going to run a phishing scam, host the image on this service, not google, or your drive account + a lot of other stuff is at risk. I've even seen google follow links to other accounts your google account is an admin on, so can have business impacts and more.

I don't know where the idea comes from that google is very hands off on this stuff, they run a major spam fighting op that blocks lots of even potentially legit email, they do tons of scans through chrome, they do advanced stuff for opt-in domains on their paid platforms (even more intrusive but let's them pick stuff up behind password locked pages etc).

This last one can really confuse site owners, when NON PUBLIC content results in site bans.

temp667··on Dr. Seuss books deemed offensive will be delisted from eBay
It is, I do this routinely because I'm constantly meeting people and don't have desired pronounces in front of me.
temp667··on Dr. Seuss books deemed offensive will be delisted from eBay
Folx? How do you pronounce the x? I'm in a pretty progressive setup and haven't heard that yet.
temp667··on AdGuard publishes a list of 6K+ trackers abusing the CNAME cloaking technique
You just have unique names for images - isn't that already used for email pixels?

ie, se09d.png

Also used sometimes for standard cache invalidation efforts so common for both nontracking purposes too.

Worst case sites will just install a middleware layer to proxy all their requests and traffic back to ad tech machine I'd imagine or install some middleware on their stack.

temp667··on The CNAME of the Game: Large-scale Analysis of DNS-based Tracking Evasion
One asked for by folks on HN who said third party cookies should be blocked - well, the ad tech companies are making them first party.

I'm surprised they even setup another domain, you could do path rewriting at load balancer level to route the /extras path to the ad tech software / provider.

temp667··on The CNAME of the Game: Large-scale Analysis of DNS-based Tracking Evasion
Yeah, from where I sit Chrome is the absolute first target, regardless of how many nails are being nailed into its coffin.

There is some thought that if Apple opens up iOS a bit Chrome could make more headway there as well.

Numbers I've heard are Chrome - 60%, Firefox < 5%.

temp667··on If you miss an Apple Card payment, Apple disables all your Apple accounts
Exactly correct.

"If you or someone else enters your password, security questions, or other account information incorrectly too many times, your Apple ID automatically locks to protect your security and you can't sign in to any Apple services."

There is then an immediate unlock option with a trusted device or recovery key etc. There are other recovery methods if you don't have 2FA. If you don't have 2FA you are in security question land, which is more heavily rate limited even beyond this for recovery.

temp667··on If you miss an Apple Card payment, Apple disables all your Apple accounts
"This is not a bug, this is by design."

Please provide some clearer support for this statement of supposed fact.

We've got so many MUCH MORE likely scenarios.

These are the common ones that disable or lock account:

* Repeatedly entering an incorrect Apple ID and password. * Not using your Apple account for an extended amount of time * Billing issues such as unpaid iTunes or App Store orders * Security reasons * Charge disputes on your credit card

I've yet to hear of a missed payment on an apple card resulting in this (and I have an apple card and have missed payments).

temp667··on Spy pixels in emails have become endemic
Sure, tracking pixels worked this way, you give the image a unique hashed filename.

But these "spy pixels" that can see the street you are on. I've not been following this space, but google proxies the request, how does the spy pixels active spyware payload deploy even? And if they are using the ip address that is just a google IP (or a cloudflare IP if I'm going through WARP).

temp667··on DigitalOcean S-1
But is that what is happening? They said it was a work related project. That's exactly what we do.

Why would a place like google even use an interviewees code without careful copyright assignment and work for hire protections (ie, you need to pay someone in USA generally to own their code).

I've found some potential hires are randomly paranoid - and if they start giving you lots of hypothetical disaster / ripoff scenarios early, not worth the hire?

temp667··on DigitalOcean S-1
I loved pair! Never followed what happened to them!
temp667··on DigitalOcean S-1
We give new hires a homework project that is directly work related. We don't consider it unethical. It's really a fantastic way to sort out who can deliver. We used to have it be part of the onsite interview - they could sit for a few hours and do it.

I like these because they are not games. If you want something done, you'd ask an employee to do it. So just ask someone to do something you need done.

In our case at least by the time it was something that was part of an interview, it had already been implemented on the business side. Our projects were usually 2 hours tops?

The idea that this is unethical is wild.

We also do paid internships and have folks actually work on stuff that way -> do a good job, pretty good line up for a full time position.

temp667··on Spy pixels in emails have become endemic
Interesting - we used to have tracking pixels and now we have upgraded to active code spy pixels?

Tracking pixels go way back, they were used primarily for deliverability and engagement analysis.

The article says that now the sender can see what street you are on. I thought google proxied these so you got a google IP - how do they defeat google's proxy? Also you would think that most email providers would filter out spyware - I have not picked up any of these spy pixels through google so far.

temp667··on USPS Selects Oshkosh Defense for Next Generation Delivery Vehicle Fleet
Did they copy the workhorse design? Or is the link wrong? So weird.
temp667··on The U.S. Air Force just admitted the F-35 stealth fighter has failed
In some places the cost to do a govt deal can be many multiplates easily (and totally justified) normal cost.

The hammer is not actually $1,200. The paperwork can easily be.

Do you have McBride Principles stuff done and documented? Have you trained your staff on McBride principles if they might purchase supplies, documented it and maintained proper documentation (this is about something in Northern Ireland which has very little to do with buying snacks for a kids program). Repeat x100. Where I am the ethnicity / race / national origin stuff is huge, and the different agencies don't have a common set of labels. So you are stuck asking everyone very personal questions even they don't understand. I mean, for ethnicity you are one thing, for race there is another set of labels, so you have to ask them the same race question 4 times under each random set of labels that are being used, for national origin another set etc.

The actual quality of your hammer? Never tested. The details on the paperwork - lots of folks looking and nitpicking. Some of this just starts as a resolution at some level, that gets added on and added on over and over. So some politician will say McBride principles are great. 2 years later a contract analyst or internal auditor asks, how are we documenting / demonstrating compliance with this requirement. They then push their vendors to train staff involved in purchasing on the principles. Then they want documentation of that training. Each one in isolation is a small waste, but at scale it's a monumental waste.

What's even funnier, stuff stays forever. There are requirements in contracts to hand out old IRS forms (W-5) for Advance EITC - that program is long gone, but you still have to hand out the forms - and tell staff that if they fill them out and submit them nothing will happen. Sure builds staff faith in govt efficiency.

You can't even argue this stuff, I used to try and it's a brick wall.

I can't stand it, but if you can push paper and have some political pull it's a gravy train, because cost / quality is so low on the basis of selection list. This tends to attract the wrong type of company (ie, scammers get a lot further than they should, and companies delivering good product don't).

← PreviousPage 3 of 8Next →