HNHacker News
TopNewBestAskShowJobs

thoraway1010

1,042 karma · joined March 7, 2020

submissionscomments
thoraway1010··on G Suite Doesn't Let You Contact Support Until Logged In. Locked Out = Stuck
You miss the point entirely.

Currently because the volume of bogus support requests is so enourmously high, and the fraud attempts also very high - the cost to properly do something like handle account lockout requests properly (on the scale of billions of users) would be EXTREMELY high.

Google is actually pretty clear for consumer accounts, if you lock yourself out your content is lost and they suggest setting up a new account.

Cell phone companies do handle this, you can do things like sim swaps etc with a real person - but you are usually paying $50 - $100 per MONTH with them. And even there plenty of folks have complained of having 2FA codes stolen as a result of this convenience.

If they could charge $50 or $100 to provide paid support (a situation that is actually very COMMON at the enterprise level) for at least some people this will be worth doing. Then the business case is there to staff / resource etc the fix.

Currently, with youtube / gmail etc, the revenue per user is so low it will NEVER make economic sense to have humans dealing with an account.

But keep on banning paid support and you'll keep on getting no support.

thoraway1010··on I want to have an AWS region where everything breaks with high frequency
A great idea! I'd love to run stuff in this zone. Rotate through a bunch of errors, unavailability, latency spikes, power outages etc every day, make it a 12 hour torture test cycle.
thoraway1010··on Stripe Hires AWS' Mike Clayville as Chief Revenue Officer
I wonder if Apple and Google and Facebook and Microsoft and Stripe had just done something "anti competitive" and entered the payment space squarely themselves if rates would come down. They seem more consumer experience directed than other players.

The security they can deploy (apple pay seems pretty good now as long as card onboarding isn't broken) seems like they could drive down to basically low interchange?

thoraway1010··on Stripe Hires AWS' Mike Clayville as Chief Revenue Officer
The other thing is trust. They have (yet) to screw customers on pricing that I've seen. Has amazon ever raised prices on an existing service? I'm not saying the prices are any good, but they don't seem to go up.

So you can spin up in a few seconds, scale, stop and even invest in the platform without worrying too much. Also - they don't seem to discontinue services that quickly, again, doesn't feel like you will be screwed.

I just had a call TODAY with a vendor, the price could be as low as $30/unit or $120/unit - that's a near 4x delta from sure to hell no for our use case. Sales guy needs to go talk to their manager to see if they can get us the lower pricing. And who knows if next year (it's annual) we'll again get their "manager" to sign off on the lower pricing.

Something about enterprise sales folks thinking is very short term. No price transparency - maybe we can qualify and squeeze them for more per unit. Or maybe get them in low and squeeze them on renewal once they've invested. The overhead of dealing with them is so high too. Show me actual product screens (not talking heads and bullet points). By the time you get to the demo you have wasted a week of your life.

So big thumbs up to AWS here. You can see baseline pricing up to huge traffic. You can see savings plans discounts up to large amounts etc.

thoraway1010··on Stripe Hires AWS' Mike Clayville as Chief Revenue Officer
My requests - pass interchange onto the customer - and allow merchant to do so explicitly at whatever rate they want (not cash discount or anything). Ie, merchant might cover first 1% of interchange, pass rest on (so "premium" card holders with high interchange and high rewards pay the big price). We do have to get to chip+pin so the fraud issues diminish.
thoraway1010··on Stripe Hires AWS' Mike Clayville as Chief Revenue Officer
It's not just enterprise - many small / mid size places are much much happier (myself included) with an invoice attached.

AWS gets this right (even though invoice is high level). You get something that can be quickly forwarded down / up and around and end up in the AP system / accounting system etc in good shape (ie, vs a 6 page PDF of an email chain). They just care that third party invoice is there in good shape with approval by whoever owns the expense line its hitting.

thoraway1010··on Google’s search monopoly complicates a mental health crisis
No insurance hassles - I did medical billing for a bit. The insurance co's basically just run around doctors because they KNOW folks give up. You could absolutely force the $40 extra payment if dr + patient etc proved it out / appealed it - but often not worth it. Also govt billing into central county system for the poor - ugh - the bureaucracy / overhead was a nightmare (always having to recertify to financial need / paperwork this and that - 50% of time was on stuff I'd consider no value add).

For a while I had individual insurance (prior to obamacare). Because it had pretty high deductibles, I would just do a private pay / cash doctor for primary care etc.

Some big wins:

NO discussion about whether something was covered or not! You want to get service, just call.

No crazy surprise bills - yes - I once tried to go to urgent care for something at the main hospital, but NO ONE would tell me what I would be charged as a cash pay client. Yes, it can be expensive to do cash pay, but with a doctor billing by the time you can basically predict / know your cost.

Service - you are paying by the hour. I never felt pressured out the door (no surprise). The service is good to great.

Convenience - I got someone close who used his downstairs as his office. Have a problem, go in and get checked out. Because you don't need the huge billing infrastructure I think you can get away with smaller office sizes. To pay for a full time biller you need a few doctors, who then need a receptionist etc etc.

thoraway1010··on U.S. prosecutors seek 27 months imprisonment for former Uber self-driving head
Most startups IP is not worth $200M no matter what they think.

This guy was a grade A jerk too - if he doesn't do time then white collar crime is going to be even more unfairly under-enforced.

thoraway1010··on You don’t need SMS-2FA
I've got the dual yubico key thing going. It seems to work fine. I don't need to pick overly complex passwords if I don't want to.

Google does this well. Yubico Security Key + they seem to monitor my logins / rate limits etc.

I deal as do many folks with relatively to extremely sensitive info (yes, also have stuff on auto-delete).

Complex passwords require a password manager - if those get updated and rooted then my yubico seems to save me again.

In fact, with yubico I have a few passwords I memorized that aren't TOO crazy long - with a 2FA hardware key you may be able to SIMPLIFY passwords and still have good security.

And the yubico is EASY! Clip it to your keychain and go.

thoraway1010··on When a customer refunds your paid app, Apple refunds its 30% cut [edited]
Retail is crazy miserable for the person actually MAKING the product.

Getting INTO stores is hard. The store can dump product back onto you - so they have no risk. The price on shelf has NOTHING to do with what you get, if you are small you are already going through some intermediaries. Ie, person making product, packing, shipping to distributor (some make you pay cost to get it to them), then distribution costs then retailer markups then return handling yadda yadda. THEN retailers will ask you to run promos and give them discounts or they will drop you.

3%? EVERYONE would pay that. In retail I'd say person making product gets maybe 20%? 80% is taken by others?

thoraway1010··on When a customer refunds your paid app, Apple refunds its 30% cut [edited]
That's awesome! However, it WILL result in stripe attracting a LOT of the crappy billers (ie, folks who mislead / make customer unhappy etc). If your business is < 1% refunds, no worry if fees stay. A fair number of business have just 1 or 2 refunds PER YEAR.

Other business obviously have MUCH higher refund rates (sneaky autobill businesses etc). For these loosing 5% on the refunds matters if they have a lot of refunds, so they'll be very tempted by no costs if you autobill and get caught. They'll just autorenew everyone, autosign up and then be VERY good about refunds to avoid chargebacks. Even if just 30% of customers don't catch a few months you end up with real money.

Of course, CUSTOMERS may hate these players, but stripe I guess is focused on what works for the businesses generating lots of refunds.

thoraway1010··on Small mail server best current practices
I think we are just going towards centralized trust proxies.

Ie, if you are paying for google apps, have credit card on file, meet their rate limiting rules for outbound with SPF / Dkim etc then you are probably OK. Some random IP doing direct mail? Much less likely to be OK.

Given govt has done such a bad job in this space, these big corps are essentially picking up the slack / trust that you'd normally say govt was responsible for. Gives them a metric ton of power, and they don't tax so have no money to provide any corresponding service.

thoraway1010··on Facebook has blocked Dreamwidth
I'm explaining why sites that HOST but do not necessarily send content are blocked.

I've got no problem with their operation, but YOU are going down a VERY dangerous and slippery slope by saying I can't block domains that clearly host trash because they might host something else.

On my network I can block child porn, malware sites, scam sites and even entertainment sites like youtube. If you are running a service that mixes the content together, then you may be blocked by folks (like me) who don't have time to chase down every (free) subdomain you allow scammers to create.

That is my right. Period. Full stop. That is not censorship.

Folks here get censorship confused. The govt does virtually nothing to stop these scam sites - so they are certainly not being censored. I'm fine if govt does nothing, as long as communities of people can block these places.

And yes, if you run a site on the internet and don't make it slightly difficult for scammers to use your site to host crap, then other folks in the neighborhood will move the heck away from you.

thoraway1010··on Facebook has blocked Dreamwidth
Malware and childporn reduction efforts also often go after the hosts of that content. I'm not sure why calling the folks hosting this stuff what it is incorrect. Sure, childporn folks don't actually necessarily "send" child porn, they just respond to requests from viewers. But they host it.

These scam sites are like that - do you really think you can make $30,000 a week working 30 minutes a day from your home computer if you just send these idiot $25?

thoraway1010··on Google reportedly peeks into Android data to gain edge over third-party apps
For everyone one of the apple / google huge privacy breach headlines / comments some quick thoughts.

Google and Apple can at least plausibly infrastructure an anonymized data collection service and control access to it reasonably.

- You probably should worry more about the per user per connection logs your "loggless" VPN provider keeps in crappy open to the world datastores.

- The data sniffing and tracking your own ISP is doing.

- The uninstallable malware / bloatware etc that comes on huge number of phones built by third parties (ie, not google or apple).

Whenever I sign up for a "free" service (like google analytics or its equivalent for android) I am under almost no illusion that google isn't also using that data to help track users access the web target them, figure out what ads to show on my site (if I let them) etc etc.

And yes, we will find out that facebook tracks the URLs of sites people share on their platform and "snoopes" on that to figure out popularity trends. And twitter will watch tweet metrics related to their competitors. I wonder if we will get some headlines over those issues.

Finally, some folks come up with weird threat models - google is out to get me and now they can. Heads up, google could get you before this as well if they cared to. Can you imagine a govt having google's power. That would be a near dictatorship!

thoraway1010··on Small mail server best current practices
The volume of spam is mind boggling. When we first implemented DMARC / DKIM etc our legit emails were 3% or so of all outbound mail per the reporting we got back! We have a somewhat trusted domain.

Some mail delivery systems start to notice that your domain name is being used as part of a lot of spam / bogus emails, so you can have perfect IP history / no spam and STILL start triggering some random filters (no big players but smaller protection product filters).

So the game must be absolutely never ending for everyone and the inbox a valuable target - especially now that unsolicited phone calls really do seem to get ignored these days - I feel like spammers killed the golden goose on phone calls and the telcos let them.

I will say DKIM / DMARC is working well, except google (which we now use for outbound) gives us transient SPF errors even though we are 100% using their IPs. Not sure why that is (ie, SPF failure on an IP that should clear)

thoraway1010··on Amazon met with startups about investing, then launched competing products
We just had someone claiming to work for amazon who said it was "routine" to "trawl" through CUSTOMER production data.

How are they trawling through all our buckets and databases without codepaths for access?

Again, they aren't talking about amazon data (ie, billing, support inquiries etc). They are talking about customer production data.

thoraway1010··on Intel's 7nm is Broken, Company Announces Delay Until 2022, 2023
Agreed - but that has also not been smooth. I'd be curious to know the 10nm volumes at TSMC vs intel. The world has really changed.
thoraway1010··on Amazon met with startups about investing, then launched competing products
This frankly doesn't match my experience and I have to say I find it unlikely.

Before going into our AWS production S3 buckets, looking at our databases for customer lists AWS seems to be pretty careful to get an OK.

Now we are being told that production customer data was normal to trawl? How in the HELL are they passing all their certs with all production data so wide open. I do customer managed keys - I mean, this is a HUGE backdoor.

Either Amazon is lying about AWS security (and has fooled a bunch of others) or routinely trawling AWS customer production workloads for data is a false statement.

thoraway1010··on Swiss police automated crime predictions but has little to show for it
Repeat rates are VERY high in burglary. And a person who hasn't burgled is relative unlikely to commit a home burglary even if the opportunity presents. Some neighborhoods without repeaters here all leave their doors unlocked. I grew up in an area like this, never had a house key until I moved away, we would go on months long vacations without locking up the house. Literally EVERY neighbor could have walked in anytime (house was totally dark). It never happened.

Car thefts as well, I lived in a tough neighborhood, same guys checking cars all the time. If these guys were around just roll down windows and leave car unlocked. Still had my car stolen which was annoying.

thoraway1010··on Swiss police automated crime predictions but has little to show for it
But it misses the larger context which is that Swiss are proactive in trying to reduce crime through many approaches. They use many automated tools, hotspot mapping etc. The article even mentions they use something like 20 tools.

As a result of this larger effort, they have kept crime low and solve lots of serious crime.

The US has really moved to what I might call the critique approach in this area. No one is willing to propose actual solutions, but everyone likes to complain and critique. This creates somewhat of a do nothing or can't do effect in govt especially and I think also reduces attractiveness of professions like policing or working in govt (you can't ever actually do or even try things without folks eagerly slamming you).

Pretty pathetic - and doesn't bode well for our covid testing / tracing response either.

thoraway1010··on Swiss police automated crime predictions but has little to show for it
Ha.

The swiss had something like 50 murders TOTAL of which only 3 were unsolved. That's something like 0.5 per 100,000?

The USA is probably an ORDER OF MAGNITUDE higher?

The solve rates for crimes in the USA is horrendous - something like 35% in places like Baltimore.

Before we talk about how little the swiss have to show for their approach, perhaps we should allow them a touch of credit for creating a system that has reduced homicides AND led to the identification and conviction of those who commit them?

And maybe do something about the 15,000+ people killed per year in the US?

thoraway1010··on Why You Need a Community: Opportunity Exposure and the Internet Echo Chamber
This exactly, and I'd add another thing - online only communities can become dominated by the folks with the absolute strongest feelings / opinions. Most offensive or most offended, most absolute in their thinking. It tends to drive the folks I'm interested in hearing from out. In a social group they'd quickly just not be invited to stuff, or might value other aspects of a relationship and so dial back a bit. Online - not so much.

There's also very little consequence for blowing things up into bigger / click-bait style headlining.

If community is bouncing ideas around, thoughts, etc, then that is much harder online.

I've found getting off social media helps HUGELY in naturally helping get other communities going.

thoraway1010··on AMD Announces Ryzen Threadripper Pro: Workstation Parts for OEMs Only
AMD has had a GREAT story with their socket - the length it has been supported is incredible. I hope they keep that up and don't confuse ryzen parts with nonsocket compatible parts.
thoraway1010··on Target’s gig workers will strike to protest switch to algorithmic pay model
I drove for uber BRIEFLY (horrible company for other reasons).

This whole it costs 60 cents per mile to drive a car in the US is total garbage. Seriously, these are rich folks driving new mercedes I think. Folks driving for shipt are not driving late model mercedes.

1) A car get's old sitting in your driveway, if you have an unused asset and put it to use your variable depreciation is actually lower.

2) You should be able to get a car cost (excluding gas) per mile down to 10-25 cents.

3) Fuel is $2.2/gallon. Assuming 30mpg (no prius etc) that is 220 cents / 30 miles = 7 cents per mile.

4) You get a tax break as a result as well.

5) You need to reduce business net costs by costs you'd incur just in general for car ownership (ie, you might still need plates, registration etc).

For folks doing 50,000 miles per year, 60 cents per mile less 7 cents per mile for gas is 53 cents a mile to own the car. On a new car with a 3 year life that is $80k for a new car every 3 years? Let's say $20K repairs and overhead still is a $60K car.

thoraway1010··on Target’s gig workers will strike to protest switch to algorithmic pay model
It's says target gig workers will strike - no qualification or limitation whatsoever.

When fords union employees went on strike, they virtually all were on strike as well.

Is the headline really 99.5% of target gig workers do not go on strike? 0.5% go on strike? That's a BIG difference then everyone walking. They should at least do a follow-up with how many people quit or struck (50,000 or whatever).

thoraway1010··on Linux founder tells Intel to stop inventing magic instructions and fix problems
How many processors really will be shipping with dual avx-512. I thought his complaint was in part around the fragmentation here.

Cloudflare had complaints as well. Even if you just have a fraction of your code running 512, you take a big hit.

Cloudflare talks about a 0.3% 512 workload (ie, a cryto library for SSL) blowing up their throughput.

"It is equivalent to giving up on two cores, for nothing."

https://blog.cloudflare.com/on-the-dangers-of-intels-frequen...

Do you / Intel GUARANTEE no frequency scaling to handle 512?

Intel quotes these specs on throughput and seem to do it using full frequency for FP. But if you have 512 in your mix (ie, 1-2% 512) do you really get that speed. Cloudflare talks about frequency dropping to 1.4Ghz

thoraway1010··on Linux founder tells Intel to stop inventing magic instructions and fix problems
Doesn't avx-512 crush the clock. Then they still spec using the non avx-512 clock speeds for floating point somehow. I always felt there was game playing here.
thoraway1010··on Target’s gig workers will strike to protest switch to algorithmic pay model
Wow - this is big news IF TRUE.

Shipt has something like 100k shoppers, the fact that they are going on strike is HUGE - it's so hard to organize a group of 100,000.

One thing that I think is better about shipt vs uber etc. YOU get to pick which orders to take I think. Rush hour traffic across down for a $10 order? Forget it.

Here's an account from a shipt shopper:

"After 4 orders (remember, this is about 4 to five hours of work), I have made a total of $110.55. If you do the math, that’s averaging out to be $27.63 per order. Now, you also have to take into consideration gas and wear and tear on your car, but I think I may have driven a total of 50 miles between these four orders. And if you don’t want to deliver to a place far away, you don’t have to. You get to pick which orders you want to accept."

Has Shipt announced any fallback planes when their 100K shoppers walk? Will be interesting to see how they handle this - it may be the largest strike by any workgroup in a long time!

My only worry is sometimes the headlines turn out to be basically total lies. Hopefully that is not the case here. ie, they write a headline saying shipt shoppers are striking, but it turns out to be actually 0.5% of shipt shoppers.

thoraway1010··on What I Learnt From Reviewing 22 CVs
22 CV's.

Anyone doing hiring would love if their life only involved 22 cv's. I'd interview half of them :)

If you hire regularly at least in some fields, the total flood of cv's is a bit crazy (obviously something is scraping and auto or one click submitting them).

Page 1 of 8Next →