HN user

15thandwhatever

170 karma
Posts6
Comments60
View on HN

Large companies do this.

Small companies/small groups of developers have no idea how to implement and manage this, but think that it should be easy.

I've recently been approached by a group of developers to enable SSL on their internal sites. When I mentioned that this would take some time, the response was "why can't you just use LetsEncrypt?"

I replied that LE only works on external facing sites, not internal sites. The next response was "fine, why don't we make it all external facing?"

I'm still trying to explain that their CI server (Jenkins, with its history of remotely exploitable vulnerabilities), and their internal OAuth2 server should not be public facing.

Ugh, I didn't stop to consider the special education component (and its cost). That's my bad.

This reminds me of a similar theory in regards to affluent towns with low taxes that have minimal social programs, that "export" their elderly to nearby cities with higher taxes but have programs such as Paratransit and Meals-on-Wheels.

It tends to be a negative correlation.

In the Northeast US, you'll generally see the best performing districts have a lower amount spent per child than the underperforming districts.

The underperforming districts will have higher property taxes (as a result of the higher education cost). This generally leads to parents seeking to move to a different school district for financial and educational reasons.

In education, at least, more money does not equate to better students, but instead, more mismanagement.

Arecibo! I remember them from my time around Park Slope. My personal go-to was Evelyn Car Service from Prospect Heights.

That said, even Manhattan has had phones for black cars. I've routinely called Dial 7, Carmel, and Skyline on different occasions on demand (primarily when it's raining, when it's really hard to get a yellow cab), and had no issues. I still do so when Uber surge pricing is ridiculous for my tastes.

In the LES where yellow cabs can be scarce, you had Allen Car Service and Delancey Car Service (who I'd call for airport runs).

The reliability of these car services was pretty good. They'd call you if they were delayed or were otherwise late. (Drastically different from San Francisco, where the taxis were pretty much a terrible crapshoot experience)

When Uber started to take off in NYC, some of the feedback I heard was "I get to look like a bigwig", when in reality, anyone can get a black car, and if you think it makes you look more important... it doesn't.

My point is, there's a lot of talk of "Uber was revolutionary" and "before Uber there was nothing!", when the sad truth is these folks never bothered to look?

I mean, anyone who's lived in NYC for some time can tell you the numbers for Carmel or Dial 7 in a heartbeat, and some may even be able to recite the jingles from their ads.

Uber was just yet another dispatch car service, but with an app.

The other thing that's discounted here is how people treat their products they've purchased.

I'm not saying that's the sole cause, but it surely doesn't help when filters aren't cleaned, things aren't replaced at their regular intervals, and other standard maintenance isn't done.

I'm comfortable with buying a used car given the maintenance paperwork and/or maintenance-related receipts are provided. But that's about it.

I'll probably never buy any used household appliance related to hygiene or food consumption -- washing machines, dishwashers, or even a microwave.

Depends on the part of the US.

The Northeast Corridor[1], where the DC-NYC route that was previously mentioned is part of, is owned primarily by Amtrak -- so they get priority on the rails and can run as often (and as fast) as they please. However, they share the rails with other passenger rail lines so both entities cooperate on scheduling and maintenance.

Not to mention that there are sections that are designated as high speed sections, consist of 4 tracks (1 local and 1 express track in each direction), and is electrified. Plus, there are regional transportation agencies (and Amtrak) that operate locomotives capable of 150mph+.

Yes, I know this speed pales in comparison to Europe, but as far as I'm aware, it's still faster than any other rail system in the US.

That's why when Northeast US people rave about Amtrak service (between Boston and DC), and everyone else doesn't, both sides think the other side is crazy due to a myopic view.

What suffers in the Northeast is delivery of freight, so almost all of it needs to go by truck, which contributes to traffic congestion, and drives even more people to mass transit for long distances (which makes it easier to make a convincing case for expanding passenger rail operations). Or to relocate to more densely-populated cities that have rail access.

One interesting by-product of this, is diesel engines are banned in New York City rail tunnels, so the only way to get freight from New Jersey into New York city, is via a 140-mile detour known as the the Selkirk Hurdle[2].

In other parts of the US, the rails are owned by freight companies (BNSF, CSX, etc), so their customers' cargo gets priority, and Amtrak suffers because they don't automatically win the "battle" like they do in the Northeast.

Additionally, in these areas, due to the lack of electrification, Amtrak has to rely on an aging fleet of diesel locomotives[3] that break down often, and when they do, everything gets backed up. Couple this with the fact that the only section of Amtrak's network that's profitable is the Northeast Corridor and there's less incentive to throw good money after bad, and also leads to politicians calling for the defunding or even eradication of Amtrak.

1: https://en.wikipedia.org/wiki/Northeast_Corridor 2: https://en.wikipedia.org/wiki/Selkirk_hurdle 3: https://en.wikipedia.org/wiki/List_of_Amtrak_rolling_stock#L...

I don't get why we hold TSA to a higher standard than what they are: security guards.

Security guards don't go trumpeting how many bank robberies they've thwarted, because they simply don't know.

However, they will tell you about all the contraband they've confiscated simply because that's measurable.

Correct. Regulatory arbitrage is about finding and taking advantage of loopholes, and shifting business activities to other business units (or even locations) where while those actions are technically legal, they're very, very borderline.

Then you generally couple regulatory arbitrage with money spent on lawyers and lobbying to monitor the existing loopholes, in order to make sure they don't disappear.

What Uber/Lyft are doing is more equivalent to poker: a combination of betting (a large enough war chest to pay lawyers and fines) and bluffing (using marketing campaigns to garner public interest and shame/scare the establishment).

When the stakes get too high (e.g. ride sharing laws in Austin, TX), they fold.

To nitpick on something...

You say:

I agree it should be optional to just live in an uninsured and unsellable shed if you want. The buyer or insurance company can make the inspection, should they want to.

But then go on to say:

Should a publicly funded fire department put out the recurring fires in your house due to your homebuilt fireplace and diy electric wiring?

You can't have your cake and eat it too: allow reckless behavior, disregard neighbors' lives and property, and have a reasonable life and property loss prevention policy?

The purpose of your publicly funded fire department is to extinguish fires before they spread to nearby properties and cause even more loss.

The efficiency at which your city/town/village/county/etc's fire department performs this, is something everyone's insurance company pays very, very close attention to when building the elements and costs of policies that'll serve your neighborhood.

Your choices (albeit simplifying it a bit), are:

a) staff up on building inspectors and fire inspectors and spend on office space

-or-

b) staff up on fire fighters and spend on real estate acquiring parcels of land, building firehouses upon said parcels, acquiring more fire-fighting apparatus, and contribute additional funds to the state's firefighting training academy and your fire fighter's pensions and life insurance policies

To me, this (inspections vs. emergency response) is the very definition of proactive vs. reactive.

The FedEx we know, isn't actually FedEx. Nor is FedEx Home.

FedEx is really the airline (all the time) or long-haul, inter-city transport (most of the time).

The guys who come to your doors to do a delivery are generally not FedEx employees, instead they work for a local franchisee who scored the winning bid to serve that particular route (similar to candy/soda vending machine "contract routes").

FedEx Home is another flavor of this.

As is FedEx Custom Critical.

In general, residential delivery is one of the more expensive operations a carrier can undertake (at least in the US). So almost everyone who does large volume is scrambling to find cheaper ways to deliver their goods to you, such as:

- FedEx SmartPost (FedEx on the long haul, USPS on last mile)

- UPS SurePost (UPS on the long haul, USPS on last mile)

- LaserShip (Pick up from local Amazon warehouse, deliver to last mile)

- USPS Contract Delivery Service ($carrier on long haul, independent contractor for last mile)

- USPS in general (FedEx, UPS, or contract carrier on long haul, USPS employee for last mile)

The People's Code 10 years ago

I agree, but with a little twist: the problem is not that the latter party doesn't know how and the former party has the answers, maybe it's that the former party doesn't know how either.

In this particular instance, the actual problem is notification. OP said he fixed the bug in his original code, and one of his downstreams should fix the bug too.

Fair enough.

But then things took a turn towards "you should do the work", "civic duty", and what not. To which OP replied he's not going to fix it in a code base he's not compensated for.

The actual problem in this scenario here isn't OP's willingness to donate his time, it's that the right person at the downstream needs to be notified (and in turn acknowledge the problem). And in the world of open source, this is a common issue which is impacted by multiple notification avenues, developer continuity, and general infosec policy.

But instead of any one of us creating an issue saying "Hey dudes, this was fixed in the upstream -- here's a copy-and-paste pointing to the fixed and respective vulnerable code", it's a pile-on with holier-than-thou mantras regarding why OP should do the free work of reading the source code, testing a fix, and creating a patch.

I disagree on a wholesale "ban". There are some excellent Bloomberg pieces that dive into details correctly (particularly items by Matt Levine and Megan McArdle over at Bloomberg view).

But these shiny, infographic-like Bloomberg Businessweek features tend to be light and fluffy. Ugh.

US insurance carriers generally ask you to certify that you did not have insurance through another carrier/policy simultaneously (upon submission of a claim), as policies tend to have 100% coverage kick in on things like annual and lifetime maximum numbers.

Double-dipping on insurance policies messes with their actuarial table calculations.

I also remember a string of commercials from IBM about how they help out police with predictive algorithms, historical analysis, etc.

Here's one I was able to dig up: https://www.youtube.com/watch?v=5n2UjBO22EI

Why is it quiet when IBM does it, but horrific when Palantir/Big Bad Thiel does it?

It's either: a) no one cares about what IBM does anymore, because they're seen as "old school", or b) no one was paying attention before and only now caught wind of it?

It's easy to aim at the low hanging fruit of specifying explicit version numbers when installing packages via Puppet, Chef, Ansible or Salt.

This should be common sense because if you build servers/containers at different points in time, it's possible to have 4-5 different versions of libxyz in use depending on when that instance was spun up.

However, if you're writing code in Ruby, Python, Node, Go, or even Java, you're using a version manager for the base interpreter (e.g. rvm, rbenv, conda, etc) because the distribution-packaged version is typically a year behind, or not present at all.

Then you're using the language's package manager (Rubygems, PIP, npm, go get, mvn) to install packages.

Then a lot of these framework maintainers are bundling the necessary libraries with their package for consistent builds (e.g. nokogiri on Ruby, libv8 on Ruby, etc).

You're also making the assumption that the CoolFramework use things like autoconf/automake (which generally has the reputation nowadays of being "bloated") for enabling consistent compilation across OS variants.

It's hard to maintain explicit versions in separate locations when a typical web application nowadays has at least 100 dependencies, and the typical web site has several components (the web app, a queue, a scheduler, maybe some separate workers).

This all sounds great in theory, but I feel it is very hard to maintain in practice with a fast moving ecosystem, which almost all of the above languages are.

This is the complete opposite of what is happening.

What you're describing is straight up hacking, and if there was as clear of a breach of the law like that, we wouldn't be having civil discussions about whether HFT is good or not.

Besides, almost nothing routes to Wall Street anymore. Especially not for stocks.

NASDAQ's trading platform is in Carteret, NJ. NYSE's trading platform is in Mahwah, NJ. Most HFT firms, if they're not already colocated in Carteret or Mahwah, are located in Secaucus, NJ.

At first, I think this would be just as complicated to enforce as US municipality taxes.

There are several taxes to be levied within a given state, with the rates changing based on county/city borders (see New York), regional cooperatives that span multiple towns but not the entire county (see Illinois), multiple taxing districts within a town (see Connecticut).

That doesn't even get into the fact of taxes that are levied just for your industry (see the extra taxes on your car rental bill for picking up at the airport, or Arizona's former shared rental facility recovery fee for recouping the cost of building a new rental car facility).

This was Amazon's argument against collecting state sales tax.

But taking on the opposite view for a second, and siding with you...

While it's complicated, all the incumbents in the hotel, rental car, and taxi industry that we're trying to displace for "not being agile enough", have spent the necessary man-hours to build the necessary components into their system to identify a taxable situation and properly deduct and remit taxes. They've hired own in-house staff and relied on external accounting firms to do their due diligence of regulatory matters (even to the extent of arguing against particular new taxes or tax increases).

Hertz, Hilton, and Greyhound all operate within these "heavily taxed" confines (in terms of effort, not absolute dollars), and communities/states have gotten used to their compliance, which in turn funds the various operating coffers of a municipality/region/state.

So yeah, why not expect the same from Airbnb?