HN user

Prunkton

114 karma
Posts2
Comments65
View on HN

From the Age Verification Blueprint:

AVI [Age Verification App Instances] SHOULD support the generation of Zero-Knowledge Proofs

Maybe I'm not seeing the full picture but as long there is a 'should', the whole thing is worthless. Keep in mind, national states need no implement their own solutions and AFAIK during the pilot phase ZKP was just skipped. Could be for other reasons (was not finished yet) but in the end a 'should' is a 'should' and no 'must'.

Source: https://ageverification.dev/av-doc-technical-specification/d...

I'm working and gaming on Garuda for over 3 years and not planing to switch any time soon.

It runs super smooth, with the build in 'wayback machine' and 'curated' Arch distro (7.0 zen kernel just dropped a week ago) pretty much bullet proof for beginners or as a daily distro if you want to get stuff done w/o caring much about it - just loving it. On the other hand side you have cutting edge gaming tech like wine/proton staging versions per default, so I'm playing Blizzard games with NTSYNC (the tech from the article) for several months now :) Forgot about most of the flashy default UI though :D

I'm hopeful the article is right about its prediction, although I'm under the impression the attacker/defender dynamic is asymmetric and the defender on the loosing end. I hope someone can proof me wrong though...

Making the assumption that the same amount of money needed to attack a critical vulnerability is also required to find and fix it.

Lets say we have a project with 100 modules, and it costs us $100 000 to check these modules for vulnerabilities. What is stopping an attacker from spending the same amount of money to scan, lets say 10 modules but this time with 10x the number of tokens per module than the defender had when hardening the software?

very little, about 25 TB written on the always-on one. The offline one just does diffs, so probably <12 TB. Both are kind of data dumps, which is outside their designed use case. That's why I included data integrity checks in my backup script before the actual rsync backup runs. But again no issues so far

Since it’s kind of related, here’s my anecdote/data point on the bit rot topic: I did a 'btrfs scrub' (checksum) on my two 8 TB Samsung 870 QVO drives. One of them has been always on (10k hours), while the other hasn’t been powered on a single time in 9 months and once in 16 months.

No issues were found on either of them.

Fintech dystopia 12 months ago

so much japing, so little substance and to make a point LETS JUST SWITCH TO CAPS and round it off with a reddit comment - this is capitalism baby!

Also, what is this headline even about? Why the bashing on fintech? I worked for 4 fintechs and communicated with many more, not a single one was blockchain related.

Why is this even on hn?

If you want to read proper criticism of blockchain, read Molly White's essays instead

https://blog.mollywhite.net/blockchain/

Since the headline is about gaming distros: I'm on a quiet similar OS for like 2 years now, Garuda. Also tuned for performance/gaming, arch based, btrfs etc. Biggest differences will probably be the zen kernel, pre installed gaming utils like lutris, fan control etc. and a probably less performant but highly customized default style.

Its a curated version of Arch, releases drop in with a ~2w delay. It's brutally stable. As I said, I'm running the first installation for almost 2y now, doing my updates (everything comes with GUI support) daily to weekly and I faced one single hick up so far. I resolved it on the most user friendly way, picked the last snapshot during the boot (it automatically created before the update) and it acted like nothing ever happened. BTRFS with Timeshift works like magic for these rare edge cases.

I wonder how it compares to CachyOS, will definitely test it in a few weeks on my laptop

Location: Germany

Remote: Yes

Willing to relocate: No

Technologies: Java, Angular, vue.js, node.js, TypeScript, PostgreSQL Azure/AWS, DevOps, Linux (with an interest in: Solidity, Golang and Rust)

CV: https://docdro.id/NXEQW87

E-mail: (check CV or DM me)

Former SE Manager/CTO with a 10y foundation as a full-stack developer, particularly in the financial sector. Equally comfortable leading international/remote teams or diving into hands-on coding, I thrive in roles that demand both technical expertise and strategic oversight.

Location: Germany

Remote: Yes

Willing to relocate: No

Technologies: Java, Angular, vue.js, node.js, TypeScript, PostgreSQL Azure/AWS, DevOps, Linux (with an interest in: Solidity, Golang and Rust)

CV: https://docdro.id/NXEQW87

E-mail: (check CV or DM me)

Former SE Manager/CTO with a 10y foundation as a full-stack developer, particularly in the financial sector. Equally comfortable leading international/remote teams or diving into hands-on coding, I thrive in roles that demand both technical expertise and strategic oversight.

I dealt with a EU//German regulator in the past about this very topic in a finance context.

This behavior is peak willful ignorance. Its sold as risk planing by EU entities but after all its just liability planing.

What I mean by that is, for convenience reasons everyone goes along with US Clouds knowing it is technically absolutely possible to access the data but as long the contracts are clean and state they are following EU law its fine. Just in case you can make the point the contract was broken the paper is of relevance.

Since we've already evaluated - let's exaggerate - that "most Top 40 songs are slop", maybe lyrics are a big factor in creating identity? I mean, it's true for books, right? I could easily imagine an AI-generated Top 40 song that people would still describe as having a unique identity.

I'm not super into the topic, but let me give you two niche examples that are definitely not Top 40 material, yet are considered to have a strong identity within their communities.

I guess one of the reasons the game Yasuke Simulator has like 10x more sales (don't pin me down on that) on Steam than the actual game Assassin's Creed: Shadows is its very catchy soundtrack, with lyrics that are funny and strongly aligned with the content. [0]

Another example, not focused on lyrics and from a completely different niche genre, is this jazzy death metal song that was particularly well received, not only because of the intentionally hallucinatory video. One could even argue that the hallucination is perceived as a feature, not a bug. So why shouldn't the same be true for audio? [1]

[0] https://www.youtube.com/watch?v=Hkh38jhILec

[1] https://www.youtube.com/watch?v=OzXafFUekl0

Location: Germany

Remote: Yes

Willing to relocate: No

Technologies: Java (Spring), Angular/TypeScript, SQL, Azure/AWS, Docker, Linux (with an interest in: Solidity, Golang and Rust)

CV: https://docdro.id/NXEQW87

E-mail: (check CV or DM me)

Former CTO/SWE Manager with a 10y foundation as a full-stack developer, particularly in the regulated financial sector. Equally comfortable leading teams or diving into hands-on coding, I thrive in roles that demand both technical expertise and strategic oversight.

both stablecoins (and many others) are implemented as tokens on other chains, mainly Ethereum but also TRON, BNB and others. So you would need to 51% attack these chains to attack assets on these chains. Leaving aside, 51% attacks will not work for Proof of Stake based chains like Ethereum, it is more like 66% if not more.

A more feasible 'attack' would probably be to just make the private companies black list addresses like they did last week with the bybit hack.

Location: Germany

Remote: Yes

Willing to relocate: No

Technologies: Java, Angular/TypeScript, SQL, Scala, Python, Azure/AWS, Docker, Linux (with an interest in: Solidity, Golang and Rust)

CV: https://docdro.id/NXEQW87

E-mail: (check CV or DM me)

Former SE Manager/CTO with a 10y foundation as a full-stack developer, particularly in the financial sector. Equally comfortable leading teams or diving into hands-on coding, I thrive in roles that demand both technical expertise and strategic oversight.

Location: Germany

Remote: Yes

Willing to relocate: No

Technologies: Java, Angular/TypeScript, SQL, Scala, Python, Azure, Docker, Linux (with an interest in: Solidity, Golang and Rust)

CV: https://docdro.id/NXEQW87

E-mail: (check CV or DM me)

Software Engineering Manager with a 10y foundation as a full-stack developer, particularly in the financial sector. Equally comfortable leading teams or diving into hands-on coding, I thrive in roles that demand both technical expertise and strategic oversight.

good write up, let me share my experience coming from the other side.

"3. Lack of Vision from Leadership" comes in different flavors.

One scenario is exactly as described: leadership genuinely lacks vision, which inevitably leads to layoffs. Another, is when management is already aware of impending layoffs but cannot talk about it yet. While this may seem nefarious, it often has legal implications that restrict transparency. I've been in the difficult position to continue to manage teams while the companys closure was already known to management. Not allowed to inform people is one thing but trying to emotionally prepare them for whats coming is a different, so the drop may not be as high.

Forcefully reducing server costs by 50% and cutting of contractors is hardly considered a vision. 'A lack of vision' could be the actual message. By the time I knew what is going on and costs got reduced I encouraged the best kind of development within the team: CV-driven-development with vague sprint goals!

You want to make use of the new fancy LLM APIs and play around with it? Sure! Introducing a new tech stack? I can not think of a better idea!

While its far from an ideal scenario, its often better than wasting energy on dead features. My idea was to giving people the opportunity to work on something they find personally meaningful and is driven by self motivation. I hope it helped, at least after speaking to every one personally after the bomb dropped, no one was really surprised.

used new models and measurements to assess GPP from the land at 157 petagrams of carbon per year, up from an estimate of 120 petagrams established 40 years ago and currently used in most estimates of Earth’s carbon cycle

One petagram equals 1 billion metric tons, which is roughly the amount of CO2 emitted each year from 238 million gas-powered passenger vehicles.

this sounds pretty significant. Any particular reason why it hasn't been updated for the last 40y?

Since you may not have seen it in your previous career: be aware of politics in companies (that size). Especially when you are interacting with other departments, PMs and positions generally above yours.

I'm not saying its the most important thing or specific to the first days. But getting the dynamics early on will benefit you, your project and the people involved.

Also more specific to day one: have fun and be excited :) good luck!

Location: Germany

Remote: Yes

Willing to relocate: No

Technologies: Java, Angular/TypeScript, SQL, Scala, Python, Azure, Docker, Linux (with an interest in: Solidity, Golang and Rust)

CV: https://docdro.id/NXEQW87

E-mail: (check CV or DM me)

Software Engineering Manager with a 10y foundation as a full-stack developer, particularly in the financial sector. Equally comfortable leading teams or diving into hands-on coding, I thrive in roles that demand both technical expertise and strategic oversight.