HN user

Kocrachon

164 karma
Posts0
Comments46
View on HN
No posts found.

I understand NDAs are a thing, but I still don't think I'm too comfortable with the idea of letting a bunch of third-party people look at a bunch of my internal information. And I understand this is targeting startups a lot more than large established companies. But to me that's even more concerning because as a startup you're really trying to move fast and hoping someone doesn't beat you to the punch, and you're handing a bunch of people you don't know how much of your secret internal information, and hope that they don't go talking to other people about it.

Can someone explain to me why python uses try/except so often? I see that promoted as a solution instead of;

if 'bar' in input['foo'].keys(): val = input['foo']['bar']

Generally, exceptions cause code to run slower and I feel like in any other language is considered bad practices.

I never understood why Python promotes EAFP vs LBYL. Both performance and accuracy wise, checking before doing is safer and faster performance.

I find the attitude here from many people interesting. When I look at a bunch of rust communities, like the rust reddit or the rust discord, they are all cheering about this. But there seems to be so much hatred for AWS here that people would rather just use this as another chance to take swipes at AWS.

Ignoring the fact AWS contributes code/development to the project, they are also helping fund/finance parts of it and basically offer a bunch of free hosting to the Rust team.

https://imgur.com/w6udBdU

Eh, I think it varies. All of the FAANG are such a huge gap of eachother.

About 6 years ago, Netflix and Google offered me far and away the most. Facebook Was Closer to them but still lower. Apple and Amazon were on par with the lower end of the spectrum.

I recently moved to Austin and started interviewing again, so far, AWS offered better wages than Apple and Oracle, especially for the area (was comparable to Seattle wage even), and Netflix and Google basically demanded I move (Netflix to Cali, Google to NYC). And Facebook I don't know because I refuse to work there.

So I think mileage may vary. AWS seems to pay a "Flat Rate" across the board, so if you live somewhere other than NYC, Seattle, or SF, your pay will likely be better than the adjusted wages other companies factor in for smaller cities.

Although I ended up taking an offer for Salesforce because they blew everyone else away pay wise.

And? Thats not because "AWS" was like "OMG so smart", AWS is already well aware of this issue but lays the blame on "Shared Responsibility" and are likely annoyed that Salesforce, a partner of AWS< released this without communication.

Honestly, my guess is there was a lapse in Salesforce somewhere, where either legal or PR didn't check this because this likely goes against Salesforce and AWS NDA for their partnership. I worked as an AWS partner before, there are requirements that go into place before you can release stuff like this to the public. Plus, having worked with Salesforce as well, I assume they have a PR policy to not use the word "hacking" in tool names or description, especially in regards to partners. My company has similar rules for OSS stuff.

This was more of a bad PR / Legal issue. AWS is well aware that people misconfigure permissions...

And again... better tools and more popular tools already existed... This is not new

https://rhinosecuritylabs.com/aws/pacu-open-source-aws-explo...

Not to sound like a jerk but why do you think this would be some "OMG" response from AWS? This is not some sort of "hacking", this is a tool that is being used to detect whether you misconfigured API access to be overly permissive. The tools job is to find them and them "abuse" them. Its not like AWS is not aware of user misconfigurations. The issue is AWS does not provide tools to detect these very well. Tools like CloudAware also exist because of things AWS don't provide. Not like AWS isn't aware of the ability to make such tools, considering these are just crawling and attempting to use a series of already existing AWS calls.

The tool is great as a free tool and very helpful, but its also not like AWS doesn't already have the people smart enough to make something just as good, if not better. It just obviously not AWS's priority. They can just leave the blame on the user for not properly managing IAM permissions.

Open EMR 6 years ago

Not sure how I feel about my medical information being handled by PHP...

How is this any different from PlayStation, Nintendo, and Xbox services? Not only do they get a cut of all of that revenue from those services and DLC, but the companies have to even pay for the right to make software for these devices. so are we going to start attacking Nintendo now? At some point I think a manufacturer should be allowed to manage this kind of stuff.

Paypal has its own issues. Such as disputes, its easier to dispute with my bank than to dispute with Paypal.

My Twitch account was accessed and the person made a whole bunch of purchases on my account. Twitch customer service basically doesn't exist, so I went to paypal. Paypals system throttled me when I tried to report each action.

With my bank, I can call a number, say "These are all fake" they instantly cancel and refund my money, and I can file chargeback / fraud paper work.

Paypal has a long ways to go customer service and customer experience wise still.

Yeah this article is only covering a specific attack vector, to claim that public Wifi is nearly risk free because of HTTPS is a very dangerous statement to make. The risk of public wifi was far from just having your traffic spied on.

What's the big deal if it's ring, or me with a bunch of chinese-made POE cameras and blue iris as a local server? shouldn't people have the right to set up surveillance on their own house for protection and deterrence?

saying people are paranoid for having cameras is ridiculous, people also have security systems. It's a deterrent and doesn't necessarily mean high crime. if you live in Major City like I have my whole life, it's just a fact of life that you're going to want stuff like this.

I doubt anyone will see my comment since I am a few hours late. BUT, I want to say, despite what bloomberg AND apple say, here is why I think Bloomberg failed on this report, and didn't do enough to PROVE their claims were accurate.

They made the flat out claim that AWS sold its Chinese infrastructure because of the hack. But this is flat out not true, anyone who actually knows anything about the Chinese goverment knows that AWS, same as Microsoft, cannot operate out of China. They are required to have a PARTNER to operate in China. I worked for Microsoft during the deployment to China, and we too had to have a partner. We were essentially "leasing" our technology for them to run it.

http://www.miit.gov.cn/n1146295/n1146557/n1146619/c4860613/c...

"According to the China Telecommunication Regulation, providers of cloud services—infrastructure as a service (IaaS) and platform as a service (PaaS)—must have value-added telecom permits. Only locally registered companies with less than 50 percent foreign investment qualify for these permits. To comply with this regulation, the Azure service in China is operated by 21Vianet, based on the technologies licensed from Microsoft.

Microsoft Azure operated by 21Vianet (Azure China 21Vianet) is a physically separated instance of cloud services located in mainland China, independently operated and transacted by Shanghai Blue Cloud Technology Co., Ltd. ("21Vianet"), a wholly owned subsidiary of Beijing 21Vianet Broadband Data Center Co., Ltd. "

So this to me proves that Bloomberg didn't fact check this story enough, and there are holes in it. Does this mean that China DIDN'T try anything? No, but this leaves me to question Bloombergs sources and not fact checking their reports, as there is obvious misinformation in it.

EDIT: I googled AWS China, and this is the FIRST link. https://www.amazonaws.cn/en/about-aws/china/

And at the bottom it covers all the same legality stuff. So again, its like they didn't even bother to research AWS China for 10 seconds.

I've worked for a few small businesses that used suse as an alternative to RHEL. I've never worked for a large company that has. I also know a few individuals who use it for personal projects. But that's about it.

As someone who has sold on Amazon, its not as simple as you make it sound.

Amazon takes my product, which I identify, and puts it in a bin at whatever warehouse. Another seller, sends in the same product, but theirs is counterfeit. Without opening the package, how is Amazon to know which one of us is selling the counterfeit and which one is real?

Now, my inventory is mixed in with amazon's and this counterfeiter, that product gets shipped out with my name because the customer chose my price of the list of sellers, but Amazon takes whichever one is closer, not the one I sent them. This is done to help ensure cheapest/fastest possible shipping. I take the blame even though someone else sent bad product.

This is a shitty situation all around, but how does Amazon fight back? They do eventually go back after the counterfeiters, but its a slow and complicated process because its super simple to set up as a seller on Amazon.

But, this is also not a new issue. Ebay still has this issue and I would say its far more mature than Amazon at the "3rd party seller" crap and Ebay cant fix it either. Its a shitty hard situation to deal with.

In the US, they are all individual "contractors". They call them Flex Drivers. They are similar to Uber drivers. Individually hired but are technically contractors. So Amazon does background checks on them but technically they are not Amazon employees, they are "self employed". Which is why many of them drive things like Uhaul vans for deliveries. They try to cram as many orders as they can into a van, and rush them through, to get the biggest possible payout.

Maybe its just harder to parse through then. Whenever I go through the prime videos, I have a hard time finding good content to watch outside of Amazon created series. Where as with netflix, lots of good new, exclusive stand up content and newer videos such as disney classics.

Amazon outside of its own created content seems to lack.