HNHacker News
TopNewBestAskShowJobs

twunde

1,577 karma · joined October 7, 2011

My email is my username at gmail.com
submissionscomments
twunde··on Ask HN: Why do people use password managers?
What you're describing is more secure and I do know several people that do this, sometimes with syncing via Dropbox. But it's a battle against convenience and user experience and requires a fair amount of technical expertise to set up and use. While I _could_ teach my family to use a local password manager like keepass, it would be an uphill battle, whereas using 1Password, etc is _easy_ for them and means I reduce the number of tech support phone calls I get from my family (for context the most recent call was about fixing earthlink web email roughly a month ago).
twunde··on Ask HN: How can my mom downshift as a SQL developer?
On a different note, you're probably understanding the value of a good sql programmer, especially outside of pure tech companies. I've seen one provide more value than a team of programmers, and unlike many codebases it's rare that you need to do a complete rewrite 5-10 years later.
twunde··on Almost half of Californians speak a non-English language at home
It's unexpected, until you dig down into the reasons why immigrants might not learn a new language.

1. There may be a community of your type of immigrants so you might not need English and within the community there are trusted people who can translate, so you don't actually NEED to learn the language yourself. This is why immersion language programs work well since you're forced to learn a language. Otherwise it's much harder, even if you're motivated.

2. When they moved they likely were not given the tools to help them learn. And even if they were given some of these tools, were the immigrants able to balance work with these classes. California does this well, they have a lot of free ESL classes, which are well taught and agencies/non-profits push immigrants to attend them.

3. Learning a new language is HARD, especially when you're older. Especially if it's not similar to your existing language (learning Spanish, French, German is relatively easy for English speakers since there are many words that sound the same. Learning Russian or Mandarin or Arabic is much harder since the language aren't part of the same family).

Integrating large groups into an existing community requires a lot of intentional work, no matter if that's immigrants integrating into a country or a company meeting with another. If that intentional work isn't done, you end up with silos.

twunde··on Ask HN: Manhattan Project for Climate?
The issue is that we've relied on hydrocarbons for so long that switching off means significant change at basically every level of the stack. Let's take the transition to EV vehicles as an example. To do this you need to build charging infrastructure along common and uncommon routes. Do all houses need home chargers now? What about people who use street parking only? To make the switch worthwhile you need the utilities to switch the power base to renewables. Oh and with the switch, we're now more than 2xing the amount of electricity we need to generate. So now we need to upgrade our transmission lines to carry a lot more energy. And the grid in general needs to be smarter since renewables aren't consistent in energy output. EVs need less maintenance but it's more specialized so now we need to retrain all the mechanics. Oh and how do we do this with affordable prices?

We have to make a lot of changes across virtually the entire economy including equipment/factories etc that have lifespans in 30, 50,100 years. There are major questions about how fast we can accelerate the timelines as we basically reinvent ourselves

twunde··on MOVEit global security incident
There are financial consequences for healthcare data leaking (actual monetary fines) and some consequences for payment data leaking (primarily in the form of higher rates) but there's no significant penalties for leaking SSNs. So every adult feels like they get their data leaked on an annual basis and only get free credit monitoring. I think adding penalties for SSNs leaking would help.

Admittedly there are some macro effects that are causing security to be taken more seriously by companies in general. The proliferation of compliance programs especially SOC2 had made basic security the default for a large portion of b2b tech companies. Cyber insurance requirements are increasing. Newer state regulations and SEC regulations have pushed other companies to increase resources dedicated to security.

That said this is an uphill battle after a decade or so of companies having no security with passwords or SSNs in plaintext and everyone having access permissions.

twunde··on A new F# compiler feature: graph-based type-checking
This is the type of feature that makes me want to use F#. Really great work, I would love to see similar work replicated in other languages (python's type checking libs especially). As an outsider it feels like the Bazel/Buck/Pants approach applied to type checking
twunde··on Ruff v0.1.0
Ruff isn't quite at feature priority with the tools it's replacing (although it's close). The main benefits to using ruff is that it's great enough to run regularly locally without being noticable, even on large codebases and it provides tool chain consolidation (although the latter can be achieved with other tools like pants). The speed difference is more noticable in monorepos. If you instead have many smaller repos it probably makes sense to just implement the original tools
twunde··on Ask HN: If GraphQL Is So Great, Why Doesn't Everyone Use It Already?
Graphql offers benefits for a few types of architecture (typically microservices or when you are supporting multiple clients such as Android/iOS clients). If you don't have these, then Graphql primarily adds complexity
twunde··on Harness launches Gitness, an open-source GitHub competitor
Harness actually came from the opposite direction where they started out with CD, bought a CI comment (drone.io if memory serves) and are now introducing git hosting. So it's likely CI/CD is better than the git hosting
twunde··on Ask HN: Is EdTech a Good Bet for Venture Capital?
There is opportunity in edtech, but it's much harder to find viable business models that have VC-worthy returns than in most other verticals. Most edtech companies are either B2C or are selling to school districts or universities. Selling to school districts has unique changes due to school boards and often grant-based funding models. This makes getting initial traction and scaling up more difficult. If you look at successful companies in the space like teachers pay teachers, or clever you'll see that many have relatively small amounts of funding and have been around for more than a decade in order to get acquired.
twunde··on Replanting logged forests with diverse seedlings accelerates restoration
You may also hear this practice called selective cutting/lumbering. Essentially they leave trees in ones or twos scattered through to reseed the area around it.
twunde··on Chromebooks will get 10 years of automatic updates
As (The Verge's article[https://www.theverge.com/2023/9/14/23873319/google-chromeboo...]) about this points out

``` The company currently guarantees eight years of automatic updates to Chromebooks. That period, however, begins at the time when the company certifies a Chromebook, not when it’s actually in the owner’s hands. Because of the time it takes schools and businesses to purchase, receive, set up, and deploy new fleets of computers, they commonly end up getting four to five years of use out of them in practice. ```

so this is really about ensuring that the laptops actually get 5 years of use before needing to be replaced.

twunde··on Ask HN: Are there good Cloudflare alternatives? e.g., edge cache, firewall
You may want to double-check your plan to ensure you're not on Business or Pro. If you are indeed on the Enterprise plan, information about your account manager and contact plans should have been in the onboarding PowerPoint they serve as part of the setup. If you don't have that, I'd follow the instructions in https://developers.cloudflare.com/support/troubleshooting/ge... I'd also consider opening a ticket asking about your account manager.
twunde··on Cybersecurity in a Growing Company
What you're looking for is commonly known as MDM (mobile Device management) software. It lets you manage laptop and phone configurations such as requiring a lock screen. If you're a windows shop you'll want active directory at up. While you can do this yourself, most smaller companies will look for a MSP (managed service provider) to do the setup and ongoing management including laptop setup. There are a lot of them out there so it's worth shopping around to find one with both good pricing and more importantly one that's responsive to your needs. Investors and other startups in your area might have suggestions on good ones
twunde··on Ask HN: Mosquito Killing / Preventing Innovations
There are a few options. As mentioned by heresjohnny you should have insect screens on your windows. There are other deterrents like citronella candles or the rather new bug repellant devices: https://www.nytimes.com/wirecutter/reviews/mosquito-control-... There are also bug zapper devices although I don't know whether they're effective against mosquitoes
twunde··on The OpenTF Manifesto
While the Nomad stack is a direct competitor to k8s, Consul and Vault are both heavily used alongside k8s. In fact, Consul had features that were only for k8s the last time I checked
twunde··on Ask HN: How do I get employee opportunities as a long term contractor?
This is mainly a matter of formatting your resume so that it looks like you've had one job but many projects. If you compared your resume to someone that works at a consulting company like Thoughtworks your resume should look similar
twunde··on Ask HN: I have 10 yrs of Exp. Failed 4 takehome projects. What am I doing wrong?
I would email the recruiter back asking for feedback on the project. The worst they can say is no, and at best you get some insight into their reasoning.

Code review: For a senior dev, I would expect tests even if I didn't ask for them explicitly. I'm also surprised to see that the functions are in a generic utils instead of better named files.

The reality: 1. other people are spending more time on these takehomes. 2. Being more senior means that there are higher expectations. 3. The takehomes are typically a qualitative assessment

twunde··on Everything that uses configuration files should report where they're located
This brings to mind php's phpinfo. While often left publicly available, it provided (provides?) information on all loaded configurations.
twunde··on Ask HN: Why are most Startups asking for US Remote instead of just Remote?
To clarify, the reason that remote jobs list random states is because those are the states that the company has already done the payroll/HR paperwork for. They can add others, but its a fair amount of work by legal, finance and HR. If you're only hiring 1 person from that state, its a lot of hassle for relatively minimal benefit. This is part of the reason why PEO companies like Justworks are extremely beneficial for remote companies since they're already pre-registered in every US state. Also if you're founding a company where you want remote workers you should skip directly to a PEO since otherwise its a time-suck of issues.
twunde··on Ask HN: Are You Using OpenTelemetry?
Yes, implemented it at my current company and my previous company. It's definitely worth spending the time to learn opentelemetry since its rapidly becoming the standard interface for observability signals, particularly tracing.

Roadblocks: - Some backend providers still don't support opentelemetry format. Notably the number that do support it have increased dramatically over the past year. For those who don't natively support opentelemetry, you'll likely want to use the opentelemetry collector to translate to the format of choice - There's a fair amount of difference in maturity level depending on the language you're using. For example, python's opentelemetry ecosystem is very mature whereas rust's ecosystem was lagging behind. - Tracing is probably the strongest aspect. While metrics and logs are supported, they're definitely lag behind in terms of the TLC they're given

Tidbits of note: - Opentelemetry collector has rapidly become the go-to agent of choice. It has leapfrogged vector.dev in terms of features, and I'm seeing some enterprises choose to use it as their customer-facing agent (ie GCP's agents are clearly opentelemetry + plus some extras) - As more companies support opentelemetry as a format, there's less of a need for opentelemtry's format translation feature.

twunde··on Put an io_uring on it – Exploiting the Linux Kernel (2022)
Previous discussion on hnnews when this was originally submitted as a Graph Security piece: https://news.ycombinator.com/item?id=30605356

This is now mirrored since Grapl shut down (RIP)

twunde··on Learnings from kCTF VRP's 42 Linux kernel exploits submissions
For anyone who wants an easily digestible read on io_uring exploits I love my former colleague's post: https://chompie.rip/Blog+Posts/Put+an+io_uring+on+it+-+Explo...
twunde··on New York State Senate passes prohibitions on non-competes
Most companies do not pay for the period of time that a non-compete is in effect. What you're describing is somewhat different. Typically that's known as garden leave, and essentially you're treated as a current employee for the period of time, but you're not allowed to work. Which means that you'll likely have the 6 months of free pay. I'd definitely review your contract and the terms.
twunde··on Health industry responds to data privacy crackdown
For systems you control, yes even if what you've described takes a fair amount of work to get to. The main issue is that for software that wasn't built healthcare first, the strict privacy wasn't a requirement. Retrofitting your software and workflows can be a hell of a lot of work. Add in that you now need to verify that all the vendors you use are also compliant with the terms of your BAA.

For most non healthcare first SAAS providers you either do a major rebuild or you end up with a healthcare specific cluster which is missing some of your tools (although it's worth pointing out that many more vendors particularly in the observability space are now HIPAA compliant.)

twunde··on Ask HN: Cyber Security folks – what are your biggest pain points?
It's not normally MDM that slows down the laptops, its usually the security agents/proxies that are installed via MDM that slow down the computer. Antimalware agents for macs in particular tend to be very problematic with Jamf Protect being one of the few exceptions. And if you're using an enterprise proxy like Zscaler, you might as well switch to thin clients instead.
twunde··on GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
It took 8 days to proactively reach out. It may very well have been identified earlier and then taken some time to be passed off to Google's vulnerability reward program and get any approvals necessary
twunde··on 12 years since Saab’s bankruptcy: Secret NEVS electric cars revealed
You can find quite a few for cheaper, especially in the Northeast. My current Saab is nearing its end of life, and I'm _so_ tempted to get another one, even if it doesn't really match my lifestyle anymore
twunde··on 12 years since Saab’s bankruptcy: Secret NEVS electric cars revealed
You can still get parts, although if you're going through your mechanic they can be expensive, especially if the mechanic isn't a SAAB specialist. I do think its worth looking to see if you can find a SAAB specialist. When I was based in NYC, Swedish Underground was by far the best SAAB mechanic I ever used (it was booked usually 1-2 weeks in advance with just Saabs) and everything that was fixed, stayed fixed.
twunde··on Three Companies Impersonated Millions to Influence Internet Policy
Techdirt has a good writeup of this press release https://www.techdirt.com/2023/05/12/ny-ag-doles-out-wrist-sl...
← PreviousPage 2 of 26Next →