HNHacker News
TopNewBestAskShowJobs

throwawayjava

2,805 karma · joined May 1, 2017

submissionscomments
throwawayjava··on A Survey of Deep Learning for Scientific Discovery
A good review article is worth its weight in gold for both the researchers who write it and the research community.

Remember that research communities are extremely transient because of the professor : phd student : practitioner ratio and the low odds that a graduated phd student a) stays in research and then b) stays in the same research area for their whole career. Therefore, most members of a given research community have approximately 1-3 years of experience in the broader academic field and approximately no experience in the area covered by the review. Therefore, a good review can simultaneously:

1. prevent a lot of wheel re-invention, and

2. push the research field in a certain direction (either accidentally or purposefully).

Also, good review articles typically include some amount of synthesis. I.e., the creation of a conceptual framework and language for understanding and talking about a bunch of vaguely related stuff. This article tries to do that e.g. in Section 2.1 but the topic of the review is so incredibly broad that the categories are not super useful.

throwawayjava··on The New York Times Releases Its Dataset of U.S. Confirmed Coronavirus Cases
problem is somewhat ill-posed, but see

https://raw.githubusercontent.com/bgruber/zip2fips/master/zi...

throwawayjava··on The New York Times Releases Its Dataset of U.S. Confirmed Coronavirus Cases
Not all self promotion is good self promotion. I've nuked candidates because their online portfolios demonstrate bad technical judgement, questionable professional ethics, a fundamental misunderstanding of core ideas, etc.

Put more simply: a portfolio is a demonstration of your work. Anything you put out in public with your name on it is part of your portfolio. Obviously, don't put bad work in your public portfolio.

There's a reason you see very few serious data scientists publishing hot takes on their medium blogs -- it's a serious threat to your professional integrity and brand if you get it wrong. The only people I know & respect who are writing publicly about this topic have SME collaborators. (Of course, we're all playing with the data and talking about it in private with friends/coworkers over coffee.)

Self promotion specifically by spreading your amateur take on a health crisis seems a bit... immoral? Or at least the sort of thing that makes me question the candidate's judgement.

If you want to write publicly and in a formal way on this topic, get a subject matter expert to serve as a co-author. Anything less is more risky than it's worth, even from a purely selfish perspective.

throwawayjava··on The New York Times Releases Its Dataset of U.S. Confirmed Coronavirus Cases
Oh, I think it's completely fine to play with the data and talk about it with friends.

But SEOd medium posts have different reach potential than a facebook comment/phone call with friends/family. That's kind of the whole point of them.

throwawayjava··on The New York Times Releases Its Dataset of U.S. Confirmed Coronavirus Cases
"Oh boy, I can hear the sophomore software engineering studio students firing up their word processors from here" works just as well.

I don't think the critique was of self-learning or bootcamps. It was a critique of a certain sort of cringe-worthy self-promotion.

And not just cringe-worthy. Spreading information based upon a cursory analysis of some CSV files without any training or experience in epidemiology, public health, public communications, etc. seems... irresponsible.

Also, off-topic, but most of my peers at university taught themselves how to program years before starting college -- typically in middle/early high school. And I mean actually taught themselves, from books and zine tutorials, not 'attended a formal course of instruction that was offered by a venture-backed firm instead of a formal course of instruction at a traditional university'. I guess times have changed, but the characterization of university students in CS as 'not self-taught programmers' is definitely the opposite of my experience. You came into the CS degree knowing how to program and learned how to do CS. And the characterization of "anything not university" as "self-taught" -- even formal courses of instruction that cost five figures -- is even more strange.

throwawayjava··on 3.28M file for U.S. jobless benefits
This comment is a tad ironic. My monthly expenses are $N, and I keep at most $N + 1,000 in my checking account. Often much less e.g during the first half of the month. I keep my checking account balance as low as possible precisely because I know "the difference between checkings and [high-yield] savings". Keeping more than a small buffer extra in your checking account seems pretty financially illiterate to me.

Also, keeping anything more than absolutely necessary in a checking account is ridiculously dangerous if you're using ATMs outside gas stations....

throwawayjava··on 3.28M file for U.S. jobless benefits
I've encountered exactly two people in my life who were perfectly healthy, both mentally and physically, but just sat around all day doing nothing for years on end.

Both were landlords.

throwawayjava··on 3.28M file for U.S. jobless benefits
Are you aware of a quantitative model relating economic losses to loss of life / quality-of-life? I see this claim repeated over and over, but after hours of searching I can't find any quantitative models. If such a class of models did exist, we could weigh it against various SIR models and make an actual assessment. Without that economic model, the decision calculus you're suggesting we make isn't really possible.

Also: even that conversation seems like a huge false choice. Why not just give up on market capitalism for a few quarters and make sure everyone is fed/clothed/sheltered? It's not like houses disappear overnight if rent/mortgages aren't paid. And it's not like we've never suspended capitalism in the past -- the federal government put in price controls, effectively nationalized industries/supply chains, etc. during WWWII. And then we returned to capitalism afterward.

> But nah, the "market" apparently entirely consists of assholes on Wall Street playing Capitalism II and lobbying governments for payouts. No way it has any real impact!

TBF, those are the folks getting most of the economic relief so far. And not just from recent Congressional action. Somehow when it comes to ensuring liquidity in certain financial markets, the federal government can move mountains in minutes. But when it comes to people having a safe place to sleep and food to eat we're the mercy of the invisible hand.

Why can't e.g. HUD, unilaterally and without congressional action, create "liquidity in the housing market" by making enormous zero-interest loans to everyday folk whenever they feel like that's necessary?

People who trade in equities and bonds have enormously powerful economic backstops, which people who merely pay rents and mortgages and buy food do not have.

throwawayjava··on Quarantine will normalize WFH and recession will denormalize full-time jobs
Based on issue polling, we know that a majority of people who are opposed to the individual mandate also strongly support a ban on pre-existing conditions clauses. And also those same people oppose any form of universal healthcare.

But abstaining from health insurance right up until the point where you need it is the same as having other people pay for your healthcare. A ban on pre-existing conditions without an individual mandate is a form of welfare. So in actual practice many people who are nominally opposed to universally subsidized HC are in fact not opposed to universal subsidization of healthcare... as long as there's some nominal involvement with the insurance industry prior to use.

The broader point: many people don't realize that just because you're paying into something doesn't necessarily mean it isn't welfare. In a democratic society with a lot of individualism and distrust of government, sometimes this "hack" is the best way to deliver a welfare state. See also: social security.

throwawayjava··on How I survived being a $220k/year intern
> If not, but the environment is okey, I keep going.

If you're a strong developer and willing to live in certain areas -- at least for a couple years before you're trusted enough to go remote -- you can make $200K/yr. It's mostly just a matter of telling yourself you are worth that much, applying to companies that pay that much, and not being afraid to be on the job market every few years.

throwawayjava··on Melbourne professor quits after government pressure about reporting data breach
Consumer data brokers are a legal (non-criminal) business and they would definitely reidentify then well information if it weren't illegal.
throwawayjava··on How I survived being a $220k/year intern
> passes up 50K

If the author had another job lined up already, the severance package wasn't worth much of anything -- it only paid out until he had a new position. So, probably closer to passing up $0 than to passing up $50K.

Still a bit of an annoying personality. If you know you won't get any $ from the severance package, just send a "thanks but no thanks" message to the person off-boarding you. Don't harass some poor corporate lawyer 2 years of out law school with inane demands for preferential terms on the severance contract for an individual contributor.

throwawayjava··on Melbourne professor quits after government pressure about reporting data breach
There are some mathematical definitions [1], but the fundamental problem is that with enough cross-referencing between databases it's hard to say anything for sure [2]. You never know what data other people might publish in the future.

I'm not aware of any legal definitions, but given the thorniness of reidentification I would assume they're insufficient.

[1] https://en.wikipedia.org/wiki/K-anonymity

[2] https://www.wired.com/2007/12/why-anonymous-data-sometimes-i...

throwawayjava··on Don’t try to sanitize input – escape output
Sorry, this still seems like a terribly hacky way to think about code.

Again, if you write a template engine or a SQL engine, the code the library's developer writes to determine how holes are safely filled is literally sanitizing input! You never get away from sanitizing inputs, you just do it further from the source and closer to the sink.

> So sanitization of input is a good idea

Right. "Don’t try to sanitize input" is bad advice. Also, the whole point of escaping outputs is that you don't trust inputs. Escaping outputs is done to sanitize inputs.

If by "sanitize input" you mean "add some backslashes to $_GET values like it's 1995", well, I guess, point taken. But then, the actually good advice should be "step back learn how to think more systematically about your code", not "escape outputs instead of inputs!"

throwawayjava··on Don’t try to sanitize input – escape output
> (hack cough cough hack)... there is no fundamental solution presenting yet.

Because people think those hacks are fundamental solutions (see: this blog title).

But really, the fundamental solution is finally at long last treating programming as a form of engineering.

> I know the expected answer will be: it's an abstraction of a more complex problem of understanding data and how it is used... Why do the frameworks not eliminate them by construction?

Because in any non-trivial system there are always edge cases, and attackers will find the edge cases. This is why XSS persists even as template engines have taken over. "filter output" is not a panacea. Nothing can replace carefully thinking about the entire range of possible inputs and their related outputs.

But instead of educating programmers to think carefully about how to specify and design robust systems, the software industry repeats gang-of-four-style mantras like "escape output". Even while admitting those solutions don't work universally and offering "get security review" as some sort of universal fix.

throwawayjava··on Don’t try to sanitize input – escape output
> "Sanitize inputs" means modifying the input before you even know where it's going.

Okay.

That's not how I've ever used that term or seen it used. Prepared statements are a form of input sanitation. HTML purifiers are a form of input sanitation. Maybe this lingo is specific to PHP-land?

In any case, "You need to know the semantics of the sink in order to know what to do with an untrusted source" seems like an obvious truism not worth writing about.

throwawayjava··on Don’t try to sanitize input – escape output
Output filtering is input sanitization. wtf is is that you think you are filtering? Inputs!

> the developer who builds sanitization has to guess at all the possible output domains.

No they don't. They need to carefully understand/document all the places input might be used and ensure no command injections are possible. In some cases (e.g., web apps, where everything is string) that works relatively well...

Until, of course, you're the one writing the input sanitization logic in the HTML purifier / prepared statements generator. And those code bases do have occasional CVEs. So, random PHP dev can put faith in a library but the system itself never gets away from having to sanitize input!

Output filtering has the complimentary problem -- you need to understand every possible input. That's not always trivial like it is in PHP-based websites. Think about e.g. an embedded system santiziing potentially adverarial time series data (what does this mean / how do you detect it? Harder, right?). Or a compiler. The blog post author even points this out: "...In these cases you’re best off using a proper SQL parser (like this one) to ensure it’s a well-formed SELECT query – but doing this correctly is not trivial, so be sure to get security review."

Ultimately, "Filter outputs not inputs" is incomplete advice that kinda sorta works well for the most part in web apps. The correct advice is, again, "carefully specify the semantics of your sources and sinks".

throwawayjava··on Don’t try to sanitize input – escape output
...so the blog post boils down to "sanitize all inputs that don't get piped to /dev/null; also, there are some good libraries that will do that for you (...by escaping outputs... but oh btw those only work sometimes of course, and in other cases, be careful?).

In other words, for the love of god please do sanitize your inputs.

throwawayjava··on Don’t try to sanitize input – escape output
This feels like a distinction without a difference.

Escaping outputs is just one way of sanitizing inputs. Sometimes it works. Sometimes it doesn't. The author of this post even realizes that their prognostication is not general and then offers the advice to "be sure to get security review"...

At the end of the day, you need to make sure that any untrusted source is treated in a safe way by every sink and does not otherwise interfere with system specs (e.g., mangling user output). Whether that happens at line 5 (where the input is read) or line 155 (where the command is generated) doesn't really matter. Or to be more precise, is determined by whatever design patterns the framework developer chose.

What matters at the end of the day is that command injection isn't possible and the system's specs (including UI/UX specs) are respected.

Crucially, both input and output constraints are informed by the nature of both the source and the sink. Hence the existence of libraries like DomPurify and HTMLPurifier, which consider one very particular type of sink. Sometimes you will write code in domains where others haven't written excellent libraries but where sanitization (of either input or output) is needed. E.g., embedded systems.

I'd replace the author's advice with "carefully specify the semantics of your sources and sinks", which is ultimately what the author's actual advice (basically, "use trusted libraries and, when not, be sure to get security review") boils down to.

throwawayjava··on Holes in Bayesian Statistics
The linked paper is a very nice overview. Of course there problems are known and there are people trying to fix all of the issues (mostly in the relative obscurity of non-overhyped corners of academia), but the concise example-guided description of these problems is great.

Somehow I think the most fundamentally damning critique, and causality shares this problem, is also the most vague. That applied scientists/experimentalists look at the "automation" that these approaches are supposed to enable and say "that's either doing the trivial part of the job or giving you BS answers".

throwawayjava··on Half of Americans Don’t Vote. What Are They Thinking?
> Your problem is you can't define meritocratic in a way that everyone will agree with

Of course you can't. One man's merit is another man's vice. The very notion of a meritocracy is literally a sarcastic joke [1].

But the problem is even worse than that. EVEN IF if you could define a universally agreeable "meritocratic" system, you would still have the problem that people with power would abuse the system to lock out others.

Suppose 100% "meritocratic" people were selected at random. They then immediately change the rules. Now 99.99% of people disagree with the legal definition of "meritocratic". But tough shit, cause this ain't a democracy, and the other 00.01% of people have all the power.

[1] https://en.wikipedia.org/wiki/Meritocracy#Etymology

throwawayjava··on Boeing Starliner's flight's flaws show “fundamental problem,” NASA says
> Software is hard

Traditional engineering companies don't respect software. You can tell by the fact that they pay well below market rates.

throwawayjava··on Design: the key to writing and advising a one-draft thesis (2002) [pdf]
The author of this piece is a computer scientist (as opposed to a humanities professor), and in that domain their advice is quite reasonably universal.

It's almost unimaginable to write a (PhD) thesis in computer science without an extremely detailed outline. The thesis is not some thing you come up with whole-cloth, and it is certainly not a substantial dump of novel work.

The CS PhD thesis is typically a function of between three and 10+ previously published & peer reviewed papers. The exact function used to combine these previous publications into a thesis can range from `concat` (the "big stapler" thesis) to a substantial rewriting.

The level of rewriting depends on many factors, e.g., the advisor's style, the norms in the department/country, the quality of previous published papers, and of course pedestrian things such as the student's promised start date for their first post-graduation position and/or the amount remaining grant money.

But in any case, there's going to be a rather small design space in terms of the overall high level outline. The choice of chapters -- and even the internal organization of those chapters -- will mostly match previously published work.

In some sense, CS theses are closer to an anthology than a book. There's a bit of design work you can do around the edges to make things into a coherent whole, but you're not going to be making substantial modifications to the meat of the thing.

throwawayjava··on Does Visual Studio Rot the Mind? (2005)
> I can totally imagine that for a beginner developer it can make the difference... I believe in writing every character of my code and testing it thoroughly, I wrote many bug free codebases with it, that's my experience.

I'm entirely split between vigorous agreement and shaking my head.

At some point I just lost interest in committing various interfaces to working memory. The more trivial the more virulent my disinterest. Web stuff, especially front end? Unless it's crucial UX for something Very Important, it's just not worth the effort. Bring on the program synthesizers, even if they're limited to tab completing. I would literally rather memorize gibberish. If I wanted to memorize things I don't actually need to, I would've gone to med school.

At the same time, for code that actually matters and requires deep thought, I type every character and think about each one a lot.

Hopefully at some point program synthesis will be good enough that we don't have to make this choice. In the meantime, pretty much everyone doing something other than code-for-the-sake-of-code is writing some software where understanding every character really matters and some software that just needs to do the dumb thing right more than half the time to be worth it.

> It automatically formats your code, so the codebase doesn't resemble the one in your head anymore.

Same thing. One the one hand, your coworkers are not your psychologists. On the other hand, who is going to explain the code if you can't? And again, the resolution is: does this code being correct really matter?

throwawayjava··on [dead]
Requirements to become a professor of Mathematics at Cedarville University include:

• Commitment to biblical integration of faith and science in and out of the classroom

• Qualified applicant must be a born-again Christian

• Qualified applicant must agree with and be willing to abide by Cedarville University's Doctrinal Statement, Community Covenant, and General Work Place Standards.

Here's the job posting: https://www.cedarville.edu/Job-Openings.aspx

throwawayjava··on Is Catalina a Good Upgrade Yet?
Yes, that's true. But if I'm opening up the terminal because the UI is glitchy I'll just use Ubuntu...
throwawayjava··on Nearly half of Americans didn’t go outside for recreation in 2018
It's not true.

They define a discrete list of "outdoor activities" that are relevant to their members -- mostly equipment provides for niche sports/activities with expensive equipment needs (climbing, skiing, cycling, camping/backpacking, fishing, hunting, scuba diving, etc.).

In particular, someone who walks in their local park every day or plays pickup soccer/basketball at the local outdoor sports field would answer that they didn't participate in any of the listed activities.

throwawayjava··on Nearly half of Americans didn’t go outside for recreation in 2018
That headline is wrong. Nearly half of Americans didn't participate in a list of 42 outdoor recreation activities that this particular trade group profits from, which is quite different from "didn't go outside for recreation".

"Outdoor recreation" was defined as: adventure racing, backpacking, bicycling (BMX), bicycling (mountain/non-paved surface), bicycling (road/paved surface), birdwatching, boardsailing/windsurfing, car or backyard camping, RV camping, canoeing, climbing (sport/indoor/boulder), climbing (traditional/ice/mountaineering), fly fishing, freshwater fishing, saltwater fishing, hiking, hunting (rifle), hunting (shotgun), hunting (handgun), hunting (bow), kayak fishing, kayaking (recreational), kayaking (sea/touring), kayaking (white water), rafting, running/ jogging, sailing, scuba diving, skateboarding, skiing (alpine/downhill), skiing (cross-country), skiing (freestyle), snorkeling, snowboarding, snowshoeing, stand up paddling, surfing, telemarking (downhill), trail running, triathlon (non-traditional/ off road), triathlon (traditional/road), wakeboarding and wildlife viewing.

That's a pretty decent list, but it excludes what are probably by far the two most common forms of recreation that occur outdoors: walking in local parks and playing team sports outside (organized or pickup). But for some reason does include _indoor_ climbing!? Probably because this is a trade group comprised of companies that make an enormous amount of money from gym climbing but make exactly $0.00 when kids spend all summer playing in the community park ;-)

Direct link to report: https://outdoorindustry.org/resource/2019-outdoor-participat...

throwawayjava··on Being a Noob
Pew did a comprehensive study of urban, suburban, and rural communities (link below). Their empirically-backed findings are pretty divergent from these common stereotypes.

https://www.pewsocialtrends.org/2018/05/22/what-unites-and-d...

There's even an entire portion of the report that basically boils down to "everyone thinks others do not understand their community's problems but is pretty confident they understand other community's problems".

https://www.pewsocialtrends.org/2018/05/22/how-people-in-urb...

throwawayjava··on David Rosenhan’s fraudulent Thud experiment set back psychiatry for decades
> It is in essence a type of culture war hiding behind a so-called diagnostic manual

Right, OP was complaining that DSM changed because of politics, and my point was... "yeah, no shit, politics is inseparable from what the DSM is trying to do".

OP can't point to "real science" justifying either the original definition or the changed definition, because both are inherently outside the domain of science.

← PreviousPage 2 of 34Next →