HN user

JakeTheAndroid

634 karma
Posts1
Comments231
View on HN

I don't agree it's a myth. Is it an extreme risk? Yes, of course. Do people view the risks to be way too low? Yes. But I worked at Cloudflare pre-IPO, got shares at 1.73, and at one point CF was at 200 a share. That was more or less what I was "promised" from the equity.

Stripe is one example of a successful startup not going public, but there are tons of startups that are going public. And there are many startups that wish they could go public, but they simply don't have the finances or business to do so.

I don't think VCs changed much from when Google went public until COVID. We were seeing massive overvaluations of tech companies for years. Once through 2020, VCs got scared and now the landscape is a bit different. But the AI craze has started to get VCs back out of their shells taking bets on risky projects.

So, yeah, idk what I agree with this assessment. At least it's not been my experience in tech over the last 8+ years.

PCI is the most checklist framework around. SOC 2 can be a checklist audit, depending on how much effort your internal compliance team puts into it. I've never had SOC 2 be really a checklist in the way PCI is. SOC 2 requires you to design and write your own controls and scope in or out different aspects of the business. SOC 2 does include monitoring and stuff like that.

The difference really is point in time vs period over time audits. PCI is a point in time audit, SOC 2 is a period over time audit. So for SOC 2 you do need monitoring controls, and then they test that control over the entire period (often 6-12 months). So you are monitoring the control effectiveness over a longer period of time with SOC 2. And even PCI has some period over time controls you need to demonstrate.

From the outside all compliance will seem like checkboxes to most people once controls are established. Because really the goal for most of the business is to make sure the control they interact with doesn't break, and the compliance team will likely give a list of things that the business can't afford to have broken. Which does seem like a checklist similar to PCI. But really, only PCI is straight up a checklist, as you don't really get to decide your controls.

I am not sure where you're getting your information on requirements for PCI service providers. There isn't anything inside of PCI DSS that requires some sort of SOC report to be generated and distributed to customers. And Cloudflare does make their PCI AoC available to customers.

They clearly defined the scope of impact, and demonstrated that none of this impacts systems in scope for PCI. There was no breach to change management inside of BitBucket, and none of the edge servers processing cardholder data were impacted. They will have plenty of artifacts to demonstrate that by bringing in an external firm. So I am really not clear why you're bringing up PCI at all here. They made it clear no cardholder data was impacted so your perspective on the required "on-site" audits is moot.

Cloudflare operates two entirely different scopes for PCI; The first being as a Merchant where you the customer pays for the services. This is a very small scope of systems. The second is as a Service Provider that processes cards over the network. The network works such that it is not feasible to exfiltrate card data from the network. There are many reasons as to why this is, but they demonstrate year over year that this is not something that is reasonably possible. You can review their PCI AoC and get the details (albeit limited) to understand this better. Or you could get their SOC 2 Type 2 Report which will cover many aspects of the edge networks control environment with much better testing details. After reading that you can then come back to the blog and see that clearly no PCI scoped systems were impacted in a way that would require any on-prem audit to occur.

And they are not a card network. They are a PCI Service Provider because cards transit over their network. They are not at risk of being unable to process payments or transactions for their Merchant scope even if there are issues with their Service Provider scope. Because, again, these are two separate PCI audits that are done, testing two different sets of systems and controls.

And, as an aside, Cloudflare effectively always has on-prem PCI audits occur. Because the PCI QSA's need to physically visit Cloudflare datacenters to demonstrate not only the software side of compliance, but the datacenters deployed globally.

Imagine a world where tiny runways that only service EVs are integrated into the city and you can hop between them as easily as catching a bus.

I mean, that sounds like a massive shift in infrastructure and city planning. I am not sure how efficient and affordable this would need to be to achieve that level of integration into daily society. Currently nothing, in the US at least, is setup to function this way. Whereas rail and roads are already deployed.

And again, this ignores any of the issues brought on by scale. If this is the way we want people traveling at a 10x or 100x rate, the airspace is going to be busier and likely will need some sort of coordination, whether ATC or some other mechanism.

A lot of words to say that you are fine with curtailed speech, and that Elon's Twitter/X is not doing anything unique in regards to speech. Which is fine, the product needs to be for someone I guess. But don't pretend that Twitter is a safe haven for speech when it's not. It's just another social media site where moderation is done at the whim of those in control of the platform.

That's a pretty ridiculous notion to pit illegal content such as death threats and real libel with free speech.

I am not the one that chooses to call myself a "free speech absolutist" and I am not the one that is claiming that Twitter is a place for free speech. If we're only looking at what is considered free speech in the US then Twitter had completely free speech before Elon took over. My usage of illegal content was in response to the claim that there were no laws around censorship in the US. Clearly there is, and you agree; Illegal content does need to be censored. I am fine with that, but is a "free speech absolutist"? If so, they aren't an absolutist.

I wasn't making a claim on whether or not that was reasonable content to take action on.

CIS IS a slur.

No, it's not. It might be able to be used as a slur but that is true for most adjectives. You feeling like it is a slur says a lot more about you than it does about people who use that word. And this is just another example of where someones personal perspective is influencing the moderation on Twitter/X. You agree with Elon that its a slur, which is fine I guess. Elon says thats going to get banned, and that's not a free speech issue for some reason. But when people bring up the usage of the N-word or anti-Semitic language, Elon is oddly quiet. Again, I guess that is fine, it's his platform, but clearly slurs aren't wholesale banned, so then how is that free speech? Oh, right, it's not. It's the exact same as Facebook or Reddit or any other website. As if Elon isn't doing anything unique but selling you on the idea that he is.

There are no censorship laws in America.

Yes and no. There are libel and slander laws, and there is definitely content that has to be moderated, such as illegal content. Which, if we're being strict on the idea of free speech absolutism, then complying with the laws is still censorship. Which is sort of the issue with the entire idea of "free speech absolutism" in general.

Please show me some examples of new Twitter increasing political censorship of people he disagrees with.

The fact that the word CIS gender is considered hate speech on the platform[0]. That's a decidedly moral perspective and one that comes with an entire political movement.

The flight trackers thing (from what I understand) ended up being a security risk

You understood wrong. There is no risk, period. The flight trackers aggregated public data which literally anyone can go look at. And they didn't validate whether the plane being tracked had anyone on it, and they didn't follow the people on-board around telling you their destinations once they landed. There was no real risk, full stop. Musk and other people with private jets have many ways to remove themselves from those trackers and simply chose not to do it.

Turkey thing is not a choice of his.

Weird, now it's not a choice when he decides to censor stuff, but it is a choice when he decides to not moderate people using other slurs AT individuals. Is Musk located in Türkiye? No. Is the Corp offices for the company located there? No. Do they have employees there? No. Türkiye has no power over Musk, yet he still bent the knee because he wanted his platform to stay up in a country so that he could continue to benefit from the user base. Just like Zuck does with FB and Dorsey did with Twitter before that. Musk could have said eff you to Türkiye because he truly believes in free speech, but he didn't because he doesn't.

[0] https://twitter.com/elonmusk/status/1671370284102819841?s=20

It's almost like there is a bottom line and laws and stuff that require sites to moderate content. Elon will either follow suit or he'll pay out a ton of money and go broke taking Twitter/X down with him. Twitter is really no different than Facebook or any other social media site, the censorship still occurs and by and large along the same lines. The primary difference is that Elon is fine with the extreme right voices not the extreme left. But there is still a boot on the throat.

Flight trackers are not allowed on Twitter. Why? That's clearly free speech, and it's not political in nature at all. Elon just doesn't like it.

Censored in Türkiye because like every other platform he will crumble to government pressures.

He's doing the same shit that he tried to call out in the "Twitter Files", the ONLY difference is which views he supportive of compared to say Zuck.

And overall it's fine with me. A platform built around free speech absolutism is doomed to fail. No one wants to be associated with the most extreme voices, unfettered and in some cases even promoted. It's just more embarrassing when Elon says he wants to establish true free speech values, then his platform doesn't represent those values, and he tries to lie to your face telling you it is.

Yeah, it's so free the word CIS is considered hate speech. It's so free you can't see tweets without logging in. It's so free Elon gave insider information to hand selected journalists to build a misleading narrative. Maximum freedom for sure.

We all know why certain people seem to like Musk, they just won't admit it because they know the reasons make them look bad.

Also, there are still scams, still fake accounts, still tons of bots, etc lol.

Thanks for the update on that. I went back and checked and you're correct ESPN+ is there for Live TV. I just also happen to pay for Hulu Live, so it gets a bit buried. But it is in fact there.

I then went and checked Disney+ and you're also correct. Some of the Hulu content is now on that app. But yeah, its almost like completely random content was moved over, so it seems like its just easier to go to Hulu for now. But it's been clear for a while that Hulu is dying slowly.

For a while it seemed like Hulu was the path to killing Netflix but that floundered out years ago. And now everyone has their own service, so it seems very unlikely its worth trying to rebuild off Hulu at all. We'll see how Disney deals with the more adult/dark content on their platform but that seems like a better problem to solve than having 3 different platforms for streaming stuff. I do wonder if they will care at all about live streaming though; it costs a lot of money and idk how good the margins are.

Well this is already sort of the case. But instead of Netflix it's Hulu. Hulu was the sort of agnostic platform that included live TV and needed to be able to VOD all the shows available on live TV networks. Now, you bundle Hulu + ESPN + Disney. Until every company wanted their own streaming service, Hulu was where you could find broad network content. And they even have commercials, so it worked great by classical TV metrics.

The issue is, Hulu created content is meh. Hulu's UI is meh. And Hulu doesn't aggregate ESPN+ and Disney+ in a single pane. And now everyone wants to own their own cut of the streaming service pie. So there was a push for this type of service that saw the incumbents rallying together against Netflix. For whatever reason that wasn't good enough for them, so the idea that now they will just partner with Netflix seems unlikely.

Your entire line of comments seems to miss the entire conversation.

In Germany, they do find it economically viable and important for line level employees to have direct representation on the company board. Talking about the CEO or other management classes being on the board is missing the conversation. Suggesting that because US companies don't believe in the economic value is missing the conversation. Suggesting that people are saying that this type of board composition is illegal is also missing the conversation. No one said it's illegal, but it's equally not a legal requirement either like it is in other places.

The conversation is that this composition doesn't exist, by and large, in the US, and people think it should. People seem to believe that it does have value to the business.

So yes, it does seem like you're creating semantic arguments because your points miss the conversation semantically.

When I was a kid I went to work with my dad sometimes. He owned his own painting/handyman company. One of these work trips had a lot of work but very little an 11 year old could really do. I spent most of my day doing nothing, and it felt like the longest day of work in the world. I was tired, bored, and felt like I had actually worked all day. My dad said "sometimes having no work feels like more work doesn't it?" and honestly, yeah. Sometimes that really is the case.

A few years ago I had a tech job where they straight up didn't have work for me to do. For the first month it was amazing. But after a few months a day of doing nothing was completely draining. And my dads words rang in my head again, and I was like damn that as true now as it was when I was 11.

Doing nothing is shockingly hard mentally. We need to be engaged in stuff day to day, and without that engagement it seems like we spend a lot of energy trying to find something to do.

And I am again forced to ask this silly question, but what are you referencing in regards to Section 230? There is no such delineation that is made as part of Section 230[0] and there is no legal definition for being a platform. Thusly there is no conundrum here.

This is a talking point that got beat dead in 2020 and I am shocked that it still has any life on HackerNews. It's not only moral positioning, it's a fundamental misunderstanding of what makes someone a publisher and what is actually covered as part of Section 230.

[0] https://www.eff.org/deeplinks/2020/12/publisher-or-platform-...

So because a Twitter is single purpose its bad? If the twitter account followed two peoples private jets would that be enough? Or does it need to be a whole sale repost of the entire flight tracking feed? Can the person parse ANY flight data from this type of a Twitter account? Where do you draw your arbitrary line here?

This entire premise is so very weak to me. Elon is famous and a public figure and it's his own choice that people have as much interest in him as they do. He does everything he can to be in the public eye. There are tons of plane tracking accounts or applications. There is even one that tracks AF1 which carries one of the most powerful and important people in the world.

And this isn't a location tracker. This account doesn't follow Elon around and Tweet where he's headed once he lands, how long he might be staying, where he went for lunch, etc. And Elon can use completely legal methods to reduce how much of this information is publicly available.

Just because you can publish information like this doesn't mean it's ethical

And just because some actions MIGHT have negative outcomes doesn't mean they are unethical.

Elon has all the tools to avoid being tracked by a random flight tracking service. If he doesn't use those tools then he doesn't care that much about his privacy. He posts images of him sleeping in the Twitter HQ, which has a publicly listed address. We aren't talking about some powerless individual who is having big companies abuse their privacy.

I mean I agree, there is probably fat to cut. But the premise was that if you were an exec and saw that video you'd then consider tightening up the amenities. And if you're basing that decision on a TikTok video that seems a bit short sighted to me.

If you're tightening up the available amenities that should be based on totally different data that has nothing to do with a social media post.

I am not missing those options at all. It's just that the video is not the issue nor the way time can be spent at the company. If your metrics for evaluating performance is wrong that should be addressed before becoming adversarial to your employees based on a flawed perception.

And if there isn't enough work to justify a FTE, then again your metrics are bad. The forecast was not accurate enough. And the only way to know if that's true or not is to fix the formula, do the math again, and figure out the truth.

In both scenarios the employee isn't necessarily the problem, or even a problem at all.

And if we take a step back and evaluate the source material, it's a TikTok video. It's meant to be content. Do we even know if the employee is really only working 20% of the time? We aren't getting a 16 hour live stream here, it's short form content. The truth of the matter is heavily obscured.

It just seems like a bad idea to me to base you're business decisions around a TikTok video, especially when it's one that is adversarial to your employees. Instead, spend the time to understand the reality. Like we might find that the employee is actually working 90% of their workday. And then suddenly you're making decisions that never need to be made in the first place.

I've worked long enough to know that the mean time for work completion (assuming C is not the predominant factor) is more than 20% of your work week.

Depends heavily on function. Plenty of roles are somewhat peaks and valleys of backlogged work. There might be times where some employees really can get their work done using 20% of their day, but then at a different stage they would need to use way more than 20%.

Wait, so you have an employee that can get all their work done using 20% of their working hours and then spend the rest of their day ensuring they don't burn out and you want to become adversarial to that employee?

Because clearly they are getting stuff done if they can post that video and not get fired. Otherwise, you have a low performer slacking off which is its own, completely separate issue from the video itself.

It's like that quote from The Office where Michael says Jim is a lazy worker because it takes Jim 20 minutes to complete a project that would take Michael hours to complete. Seems like you're saying you want your least efficient employees and can't be bothered to understand the working habits of your most efficient employees.

Or maybe, just maybe, using time as a sole metric isn't the best way to evaluate employee effectiveness or efficiency.

What are you using arrive at this opinion? What creativity existed in a measurable way before 2020 and what does that metric look like now? Who is less creative in this environment and in what ways are they less creative? What amount of creativity is necessary for a business to operate successfully or solve meaningful problems?

Not all problems require new or genuinely creative solutions either. And it seems really difficult to try and measure the creative output by individual contributors at any given company. You have no way of gleaning the micro decisions or solutions that people come up with for their internal issues. So this doesn't seem like one could "easily argue" this point at all, in fact it seems quite difficult.

Are you suggesting that product offerings are less creative as a whole? And if so, again what metric are you using to arrive at this conclusion? And are there really no trends of this same metric before 2020?

This is insane. We don't live in a meritocracy. The idea that someone only gets to that level of wealth and business ownership because they make good decisions or understand the laws or requirements isn't something you can demonstrate with any consistency. Deciding to simply trust that he is correct because of his status is a dangerous game to play.

I think they have a few larger issues than contracts they are working to overcome. Pretty sure they are mostly concerned with getting their employees out safely. Further, those contract disputes are going to come mostly from Russia, and with the current state of Russia's isolation, I am curious if there is even a channel for an impacted Russian customer to raise a grievance. How would Namecheap even pay them out for damages?

They have a pretty clear carveout in their TOS where they get to decide a breach of Acceptable Use, and one of the AUP that says "Engages in or instigates actions that cause harm to Namecheap or other customers." which one could make an argument that providing means to an invading military force as an action that harms Namecheap. So please show something material that outlines they cannot discontinue service without massive legal implications. Not to say that TOS' are indisputable in court, but it's hard to imagine that a court in the West would consider this a material breach considering the situation. This seems much more like a concern troll than a legitimate issue.

And to frame it as virtue signaling after outlining when they are impacted directly seems really odd. Normally people are compelled to do something, even something dumb, when they face a large crisis. I don't think we usually consider that virtue signaling, and it seems like an unnecessary thing to bring into the conversation.

Yeah, they will still sell it but it wont sell to people living in CA which is one of the larger US markets. that's a non-trivial market to close your doors to for something like FSD. The margins on FSD have to be some of the best on the whole car.

The EU regulations and standards are likely just as annoying for them, but they don't sell the same volume across the EU yet, and the regulations are a bit more consistent across the whole region. So getting a Tesla in one EU country will work the same in another. Which is just easier for a consumer.

I am not saying this would end Tesla, but I can't imagine a world where they want it to come to that. I think they would look at either properly complying or some other workaround before just drawing a fence around FSD in CA.

California is one of, if not the largest EV market in the US right now. Consumers by and large don't care where a company has their HQ, but they will be upset if they don't have access to features. And this impacts people that aren't in CA that have FSD but road trip to/through CA. I can't imagine this is an ideal situation for Tesla to be in, and they'd prefer to avoid this as much as possible. There isn't a really good solution here for them.

I don't see how they can jurisdiction shop in any similar way to a credit card company in this instance, these are markedly different scenarios and services provided.

To be honest, I'd happily let my car mess up the flow of traffic trying to block the box. The only reason this exists is because everyone decides to enter the box to make the light.

When working in SF without self driving I would regularly not let myself block the box and I'd miss multiple lights. Police need to actually ticket people that do this. I've seen cops sitting at the intersection waiting to ticket people for bypassing traffic by using the carpool freeway entrance while doing fuckall about the blocked intersection causing people to want to choose the HOV option.

I understand that it's a part of driving that a self driving car would need to know how to navigate. But we really should just fix this problem through proper traffic enforcement instead of trying to make self driving cars participate in this completely shitty and unnecessary practice.

I mean, I guess it's just a matter of perspective. If you think having an entrenched class system is good, then I guess nothing is "wrong" with it.

Sure, early on in the system it's possible for it to be fairly competitive. You have a mix of responsible and irresponsible families passing down wealth, and the ones that do it best will retain their wealth the longest. But over time it becomes a very different game. Take a look through history; the stories it tells don't look good for the bulk of the working class.

It's one thing to be able to leave your wealth to your children, it's another thing to have a completely protected trust that is exempt taxes. The longer this runs, the less money forced back into the economy and through compounding interest it becomes impossible for a new set of "nobility" to reasonable ever achieve the same status.

It is a zero sum game, as there is effectively a limited amount of wealth. And the more it becomes centralized around a noble class the less everyone else has.

You can leave money to your children today, it's not like that's not possible. So I am not sure what you're on about. The loophole being discussed here is doing it free from taxes. Like Elon Musk won't need to shelter his kids kids kids from taxes on his billions. If you make enough money that can be true for you too. But yeah, you might need to teach your kids proper financial skills so that they don't blow through what you leave them so it reaches your grandchildren.

You can already setup a trust today for your kids. You can leave your kids shares in a brokerage account and that has some pretty solid tax advantages. There are a ton of ways to leave behind your wealth that doesn't require completely untaxed assets.

Example: if there were 1000 spacefaring civilizations in the Milky Way, what are the odds that all 1000 of them (assuming they were within out light cone) would remain quiet or hidden? Couple that with mass and energy ultimately being limited then there is a strong incentive and advantage in becoming as large as possible. So even if 99% of civilizations remain quiet, the 1% will still make themselves visible.

I am not sold on this math necessarily. When you ask "what are the odds?" what is that based on? How do we derive these odds at all? We know nothing about how these civilizations would evolve or what their values would be. So how can we assume that out of 1000 that 1% would be visible based on the odds? This sort of assumes that the Drake Equation is accurate, when the last few parts of that equation are complete guesses.

Additionally, on the notion of hidden civilizations in particular, it's essentially impossible to remain hidden to a K2 or K3 civilization so there's really no point.

And maybe this is the difference. Maybe all 1000 are visible to K2 or K3's because it doesn't matter. But equally all 1000 aren't visible to K1's. We are so far away from K2 that I see no reason to speculate on the likelihood of this since we have literally no basis for this other than some fun thought experiments. And all of this is based on how we view ourselves and apply those same traits to beings we have never met and possibly can't even imagine.

This is simply so far out of our grasp to intelligently speculate on, I tend to just avoid doing it.

Bezos isn't Amazon. What he chooses to use his wealth on be called into question without conflating it with Amazon the company.

And yeah they are one of the largest employers in the world. You have yet to define what specific action Amazon should have taken to produce radical change. Maybe it would have just been a flat out increase in salaries, but with the lens of education, it seems like this is a positive move.

This is a rather myopic view of society. If you believe that the status quo is unquestionable (that businesses should only prioritize their self-interest), then of course you can't believe in any radical change to it.

No, THIS is a myopic view of society. Entities are always going to work towards the social reward system established, and Amazon/Bezos are acting exactly as you'd expect for our reward system. If the issue is a broader society problem then by definition it cannot be exclusively Amazon/Bezos fault.

And this brings us back to what SHOULD they be doing in this scenario? I am not saying don't question the status quo. But how does questioning the status quo change anything about this scenario? We can question the status quo while also accepting that people live inside the status quo, and thats not inherently bad. I fail to see how it's inherently bad that Amazon is paying for employee education. What SPECIFICALLY does it block in terms of radical change? How do these two things become mutually exclusive in this scenario, not some hypothetical scenario?

But what part does Amazon have to play in radical change here? Is the radical change that Amazon should help push for free college federally? Like what specifically is the radical change being blocked by a private company paying for its employees college? We could sit here and create hypotheticals but unless there is something directly actionable, what more can we expect?

This might be a bandaid but this issue existed before Amazon, it's not created by Amazon. And many other companies have done this before Amazon. If the issue is the cost of education, there are so many factors causing that how can we expect a single private company to lead that change?

So what is the actual proposed solution that Amazon is making less viable through this change, and how could Amazon have enabled that radical change better? And once we derive what that action could have been, we have to evaluate the value it has to Amazon because at the end of the day they are operating a business not a social justice non-profit.

Please clarify how Amazon is shitting on your lawn every morning. What specifically does Amazon do to target you to your detriment. Are you upset by their carbon footprint? Do you work for Amazon?

I just don't see the logical progression here. Amazon can still be an asshole and also be doing something positive. Elon Musk is widely known for being an asshole yet most people would say that SpaceX and Tesla are net positives. So it's clear that life isn't so black and white where an entity can only assume one role at a time (Good/Evil). Instead, we all partake in good and evil activities in the micro.

And if the bottom line drives a business then what does it matter if PR drives this decision so long as its a positive move? Why do people have this obsession with purely altruistic acts that don't exist?