Access to the available font list might be useful for identifying devices likely issued by a particular organization. Unusual fonts that are part of an org's branding usually are installed as part of a standard device image. This allows employees to produce brand-compliant presentations, etc. I was an intern at GE in the mid-90's and we had a custom font with just one character defined - the "meatball" corporate logo.
HN user
ShabbyDoo
Is Iran's domestic internet still fully operational (sans access to/from the outside world)? If so, I wouldn't think the cut-off would help much security-wise because a single Starlink terminal would allow the US/Israel domestic access.
How often is the UI spec modified in practice compared to the frequency of UI changes? I wonder if this scheme actually reduces app update frequencies much. I can imagine that UI improvements often would require spec changes. Imagine adding colors to the map POI's, etc.
I've read several articles about this SuperNova trojan, including a couple that included decompilations, but none included what ought to be two key details:
1. Was this GIF-fetching endpoint likely exposed publicly by most customers' SolarWinds deployments?
2. Public or not, was there any auth in front of this endpoint when deployed?
My presumption is that some (most?) customers deployed the SolarWinds admin console publicly (with its own auth in front) and that this particular GIF-fetcher endpoint, being deemed trivial, was not protected by the console's auth scheme. Thus, those who knew about the trojan just had to scan the known IP ranges of SolarWinds customers until they found the exposed admin console, and then remote code execution was easy from there.
If this endpoint was protected by the same auth scheme as the admin console, then this trojan becomes more of a privilege escalation attack. Its existence would increase the value of obtaining the creds of a SolrWinds user, but (presuming SSO integration) those creds would get the attackers lots of other access given the sorts of IT people who use SolarWinds.
If the endpoint was not fronted by any auth scheme but the admin console was not exposed externally, then the benefit would be that attackers who gained access to a SolarWinds customer's employee-facing network (what's the name for the network segments accessible to anyone who plugs in a laptop in a cubicle?) could "ride" this trojan to gain access to a more privileged part of the network.
I'm not an infosec guy. Do these arguments make sense?
So, the user graph will be bifurcated, with US users isolated from those in the rest of the world? If so, I don't see how the US-only TikTok remains popular for much longer.
I'm surprised a manufacturer of such engineering machines hasn't differentiated itself by offering a SLA on driver (and general software) availability for future operating system versions. It would be reasonable to require users to pay a subscription fee for extended support. I'd think the resale value of machines with drivers still available would be much higher than for those without and that this eventually would allow the manufacturer to charge a premium price for the machine at initial sale.
I own a Fujitsu Scansnap s1500. It's out of support, and the existing drivers are incompatible with Catalina. I now must pay a 3rd party $100 for drivers or fiddle around with a Linux scanner server or similar. Never again will I pay $400 for a Fujitsu scanner, that's for sure.
I just watched a Youtube video of the STS-1 landing. He definitely was a happy guy, but it was nearly after landing until he finally exited the shuttle.
I presume the audio sources would have been bugs placed in nearby structures, etc.?
Yes. The author didn't note his testing methodology. JMH (Java Microbenchmark Harness) is the gold standard for executing Java benchmarking tests:
http://openjdk.java.net/projects/code-tools/jmh/
It takes care of details like JVM warm-ups. ensuring sufficient invocations for JIT compilation to have occurred, etc.
I've always been opposed to folks who grumble about suburbs and urban sprawl. I thought that new developments and neighbourhoods meant a growing population and a bigger tax base. I've always lived in the suburbs and love it. I still think there's lots of great things about living in the suburbs, and there will always be demand for it.
I like how the author says that sprawl isn't the problem, the problem is that new developments are large scale, single-purpose, and with no room for improvement or addition.
The graph/map showing how downtown and poorer areas bring in more tax is what did it though. Even just thinking about ploughing in the winter makes it pretty clear that winding suburbian roadscapes are costing the city a lot more than we pay them. That's without mentioning schools, fire halls, garbage collection, etc.
I guess one of the more difficult issues is convincing North Americans that they don't need a private single-family house, large yard, 2+ cars, etc.
For Google, ART seems bigger than just Android. Consider the degree to which their infrastructure depends on the Oracle JVM and the associated strategic risk. As one datapoint, recall the Oracle vs. Google Java lawsuit. How much additional ART development effort is required for correct execution of non-AWT (Abstract Windowing Toolkit) Java applications (essentially, headless server processes)? I know the Java/JVM ecosystem well, but I have not done any Android development. Surely, Google wants control over the destiny of its core software stack.
The article doesn't mention one seemingly huge benefit of JIT compilation: profile-guided optimization:
http://www.slideshare.net/ZeroTurnaround/vladimir-ivanovjvmj...
Perhaps the baby has been thrown out with the bathwater?
Little is mentioned about how ART compares to the JVM. For example, does ART perform escape analysis? Not all object allocations are equally bad. The Sun JVM can figure out which objects may be allocated on TLABs (Thread Local Allocation Buffers) - an optimization which reduces the burden placed on the garbage collector because TLAB-resident objects may be deallocated as the stack is popped. [Please fact-check me as I'm merely a long-time Java developer vs. an expert on JVM internals]
I learned that panhandlers, at least in Chicago, interpret polite negative responses as opportunity and will continue to bother me. So, I have taken to saying flatly, "Not happening." It's not so rude or demeaning that I inadvertently pick a fight, but it's blunt enough to let them know that they're just wasting their time with me.
To add to the collection of work-arounds posted here, most hotels seem to have reasonably modern/common printers. Often, they are connected to the untrustworthy hotel PC by a USB cable. It seems faster to unplug the printer from the hotel PC and install drivers on one's own laptop than it is to figure out how to gain access to the hotel's crappy computer. Hotel printers connected to hotel computers via ethernet/WiFi also likely have working USB ports, so one simply could bring his own cable with a "B" plug. I'm sure there are ways a malicious person could install rogue printer firmware, etc., the likelihood of such threats existing in the wild is 1/1000th that of the sum total likelihood of evil existing on hotel PCs.
I suppose the relevance of my entire comment hinges on the presumption that anyone reading HN only uses hotel PCs for printing stuff. Valid?
I was thinking about the sorts of fraud categories AirBnB likely experiences. Most fraudsters want cash or cash equivalents, and the use of lodging on a particular night is nearly as illiquid as stolen fine art. So, those seeking stuff to resell will choose to defraud one of the zillion online marketers who ship stuff to doorsteps. A buyer who actually used the space he reserved could initiate a chargeback later claiming that the service promised via AirBnB wasn't provided -- couldn't access apartment, wasn't as described, etc. However, space providers likely will cooperate with AirBnB and provide evidence in their defense. Better to attempt a chargeback elsewhere if one is short on money. It seems that using AirBnB as a platform for crimes between buyer and space provider is possible, and there certainly has been at least one heavily publicized case, but we would hear a lot more about these events if they were happening much.
So, what's left? Collusion between buyer and space provider -- in all likelihood, they are one in the same, or identities have been stolen. For example, I list my condo on AirBnB for $100/night. Someone books it for the weekend, and then doesn't show up. AirBnB owes me $200 -- after all, I gave up other options to profit from its use. An honest buyer pays up. But, maybe the buyer is dishonest -- he used a stolen credit card, etc. In this case, AirBnB eats the loss and pays me as the space provider. Now, wouldn't it be convenient if I was also the buyer? Cash from stolen credit cards, funneled through AirBnB (much akin to the way online poker sites were used to transfer stolen money via bad heads-up play). This would work until AirBnB noticed that my listing seems to have a suspicious propensity to attract fraudulent buyers. Then, they'll shut me down. So, I'll pop-up elsewhere. After all, no need to actually have a space because no one I accept will ever show up!
I bet the usage patterns of the party/parties involved in this fraud are drastically different than those of legitimate market participants. Someone with a fraudulent listing could out himself by rejecting a bunch of legitimate AirBnB buyers, and this behavior would stand-out as it's the opposite of the behavior expected of an honest seller. So, he must protect against this risk by making his listing unappealing (high price, bad photos/description, unpopular location, etc.). The behavior of users browsing AirBnB when viewing this property could identify its relative undesirability (few clicks, etc.), and price outliers could be identified by comparing similar offerings by date/location/type. The click stream of the "buyer" likely is most revealing. Someone selecting an unappealing property without doing much comparison shopping likely isn't a legit buyer.
What other stuff might predict fraud? Vague descriptions might indicate a fraudulent listing. Most space providers love to tell buyers what's special about their offering. Could some scoring of a listing's prose prove a strong predictor? I've never listed with AirBnB. What do they do to verify listings? As a buyer, they verified my identity. Could this serve multiple purposes? Certainly, I'd feel better listing my guest room if I know that AirBnB will know the identity of the guy who rented the room and then stabbed me at 3AM. But, in addition, does identifying market participants in strong ways help keep fraudsters from repeating their crimes by setting up multiple accounts? Obviously, newer market participants are more risky than established ones, especially those who have interacted with known legit, long-time users. The social graph comes to the rescue here. Even astroturfing ought to show up as a small, disconnected graph unless legit users' identities are stolen.
Of course, this comment is all just conjecture. Obviously, AirBnB can't tell the public about specific fraud methods or how they identify suspicious activity. However, I like the concreteness of considering actual fraud scenarios, so I decided to put forth some ideas for discussion.
Most of the comments here presume that it's unacceptable for a drone ship to break down in the middle of the ocean and be without crew to repair it. What if these ships were designed so that nothing too awful would happen if they floated around in the middle of the ocean for awhile awaiting another ship with a human crew to perform repairs. Or, maybe another drone ship or two to tow a broken one back to land?
My understanding of container shipping is that customers make SLA choices much akin to us Americans choosing between UPS Ground/2nd Day Air/Next Day, etc. UPS uses these varied SLAs to smooth out its use of fleet capacity and for price discrimination. Shippers operate transshipment ports as part of distribution networks much like the hub & spoke designs of the major airlines. These ports have a bunch of shipping containers sitting around awaiting capacity.
Consider the needs of companies that must transport low-value, high weight/bulk cargo. These companies likely already choose the "UPS Ground" equivalent for container shipping. Due to low product value, inventory costs are low (in transit goods are inventory), so it's probably less expensive to have buffers of goods in the supply chain than it is to pay for tight shipping SLAs. Why should these companies care if the variance they experience in shipping duration is due to capacity constraints of manned-ships or that it took an extra two weeks to fix the ship upon which their cargo was in transit?
I've always seen local governments as the root cause of "last mile" providers' ability to turn their customers into the product. Why haven't elected officials made more stringent demands upon the companies given monopoly (or at best duopoly) rights to convey bits to and from my home?
I have a condo in Chicago and was delighted to learn that a company was offering our building last mile connectivity via microwave along with SLAs for not only bandwidth but latency as well (to which point I don't recall)! Sadly, the condo board didn't seem so enthralled. Unlike the suburbs, city folk have more options apparently.
What's notable is that no one has yet posted here saying, "Go stunk for me. Perf and reliability were both awful. I went back to blahblah and threw away all my Go code." It's usually easy to find detractors of any technology.
So, even though you hated your previous job, you obviously did well at it -- at least well enough to save-up a nice nest egg. Let's presume that you will progress over time from crappy programmer to a solid one. Anyone like you will get at least that far and likely much farther. The question at hand is simply what you should do to facilitate this progression. Have you considered solving some small but pesky problem which you know is common in your industry? A calculator for compliance with Governmental Rule XYZ? A converter between two 90's era (or worse) file formats still in use within your previous industry? I have no clue what you did before, and I probably wouldn't know what projects to suggest even if I did. My point is only that you can make-up for being a mediocre programmer with deep knowledge of a specific industry. If Patrick can make $30K+ selling bingo card software to teachers, you ought to be able to do similarly in the niche you know well. To avoid having to be a good salesman, maybe you put up a website with the file converter thingy and then sell premium advertising space to vendors in that niche.
I have the same number of feet but one more knee than this guy. From what I understand about above-the-knee prosthetics, walking up stairs with a "normal" gait is an impressive feat. Clearly, the technology is near-miraculous.
With all this said, I'd much rather see advances in bionic attachment techniques. If I could have a metal rod extending from the distal end of my tibia through skin, being without a foot would be much less annoying, and my physical abilities would improve significantly. I could just clamp on a prosthetic in the form of a carbon fiber spring -- the same sort I have now. Presuming the rod required little maintenance, I would require far fewer trips to the prosthetist for construction of new sockets as the shape of my residual limb (the politically correct term for "stump") changes over time. No risk of skin issues preventing me from using my prosthetic leg. No risk of catching my prosthetic foot on something while walking and pulling it off my body. Current socket-based attachment techniques create what effectively is an extra joint with very limited range of motion. Oddly, this is useful for subtle manipulation of a gas pedal (I'm missing my right foot), but it is mechanically inefficient, reduces my perception of stability, and keeps me from feeling like the prosthetic foot is "mine". Because of this extra joint, heavy shoes feel really heavy. Lots of effort has gone into making prosthetic feet light -- a much less valuable attribute if direct body attachment was possible. Reducing the value of making prosthetics lightweight would allow for all sorts of innovation.
My understanding of the current state of affairs is that, while it's quite easy to stick a metal rod into the distal end of a bone, it's quite difficult to allow it to protrude through skin without risking infection. My general take when reading yet another article about some amazing $100K prosthetic device is similar to my thoughts when hearing fuel cell folks talking up the technology in the early 2000's -- They all showed up at tech events talking about how fuel cells were going to change the world, how their own novel technology was going to make them more efficient, lighter, whatever. My question to them was always, "When am I going to be able to replace my laptop battery with a fuel cell so I can take a cross-country flight without worrying about my battery running low?" They always gave some vague answer and then went on talking about the improvements they were making to a technology which was not at all available to me. It's 2013, and I haven't yet owned a fuel cell. However, I'm writing this on a Mac with much better battery life than was available a decade ago even though the fundamental technology used in its battery is unchanged.
I fly twice a week and have found that the actual rule enforced by flight attendants seems to be, "Don't force me to see it."
I had looked at Spark a couple of weeks ago. I'm looking for a lightweight service-y sort of framework which just happens to have a good HTTP service available out-of-the-box. My application does back-end processing and coordinates a bunch of data feeds, thick-client HTTP requests, background processing, etc. all together. Spark was too web-centric (not a bad thing, just not what I need). OSGi was an attempt to be what I want, but its requirement of classpath isolation (a good idea conceptually) is onerous in practice. Right now, I'm using a homespun amalgam of Grizzly, Guice, and java.util.concurrent (for thread pooling), and other stuff. I really didn't want to build my own container. I'm intrigued by Apache Karaf, but OSGi is a huge pill to swallow (If you haven't debugged OSGi classloading issues, you'd be in for a treat).
In a nutshell, I want a service lifecycle container which allows me to write small, lightweight, modular services which depend on each other. The container should provide for cross-cutting concerns like monitoring, management, configuration, logging, auditability (I have concrete definitions for these things -- they're not just abstract biz-speak to me). HTTP should be an out-of-the-box, optional module. A service which exposes another service via a RESTful interface and depends upon the HTTP service should be another. For my application, services which listen to multicast data streams are just as important interfaces to the world as JSON-over-HTTP-via-REST. I want to write the HelloWorld method body and be able to do stuff like: expose it via a RESTful interface, invoke it every N seconds, inject an interface exposing the HelloWorld contract into other services, etc. When I want to know how my HelloWorld service is performing, there's a pre-built web interface which provides New Relic-esque views. I'd like to capture audit trails of the transactional flows through my services from an origination point (HTTP call, scheduled job, etc.) so I can translate failures, poor performance, usage rates, etc. into meaningful information (I wrote a poor man's version of this myself, and it's been quite useful).
Does anything like this exist? I sure can't find it. Modern JBoss (now Wildfly) might actually be closer to my requirements than I think. Perhaps I should look at the work they're doing on Version 8.
What percentage of the issued student loans were taken out by those attending for-profit institutions?
The article suggests that more than a few seconds of privileged access to an important economic indicator would have little value due to the speed of algorithmic market participants. I disagree. Imagine that you knew this morning's unemployment number a second before everyone else. Could you have become a bazillionaire? No. Your potential windfall would be limited by how much of a position you could take on without moving the prices of instruments past the point of where they likely would end-up after the general availability of this economic indicator. Order books are fairly light right before a number is released because most participants presume themselves to be the victim of a better-informed trader if the option they "wrote" by putting an order on the book is exercised. So, you as a well-informed trader would have limited opportunity to take on position without paying at least as much as the likely value of that position after everyone knows what you knew a second beforehand. Conversely, imagine that you knew a day or two ahead of time what this morning's unemployment number would be. You could slowly build up a huge position and make orders of magnitude more.
Right. It's technically not front-running. However, I've heard many traders use the term when talking about how to take advantage of other market participants' likely future orders. As an example for those not immersed in this sort of jargon, imagine that you are driving by an oil refinery and see a huge explosion. You grab your smart phone and go long on gasoline because you presume that short-term refining capacity will be greatly reduced and prices likely will spike. While you had no specific knowledge of other market participants actual orders, you moved quickly to take advantage of their likely future behaviors. Even given this common usage, the author of an article aimed at the general public should not have used language suggestive of a crime when describing behavior akin to my above example.
Even ignoring the threat, the sarcasm and tone of blame are unacceptable. What company would want a reputation for being mean to those choosing not to be customers (even if somehow deserved)? There was no value to Groupon in the email sent to the SF restaurant. Of course, I'm sure the sales guy felt better about himself though.
"Air-Conditioned Vest Keeps Factory Workers Cool"
So, according to the link, some guy in China invented one. My dad worked for years in Akron rubber factories, often in front of a steam-powered press of some sort. Temperature was controlled through large exhaust fans -- a practice largely adequate when the outdoor temperature was cool but barely tolerable in August. I recall Summer days when he would instruct my mom before he left home that the window air conditioner in my parents' bedroom should be cranked up to full power in anticipation of his arrival home from work. [We didn't have central air at the time] After eight hours in a 100+ degree Fahrenheit work environment, he wanted little more than to lie down in a cold room.
I was thinking just a couple of weeks ago about this and how a refrigerated suit would have made him much more comfortable (and likely a more efficient worker). Even if an employer does not care about the happiness of its employees, it does care about productivity and the wage required to attract and retain workers. Why are refrigerated suits not more common? I recall reading about ice pack vests worn by people in sports team mascot suits. However, I don't see the guys working on the side of the road wearing anything similar.
Could an inexpensive, reliable suit be "powered" primarily by dry ice? I presume the energy density of a block of dry ice to be at least a order of magnitude greater than a modern battery pack. I'm imagining some sort of small water pump which would cool off the water by allowing it to flow around the dry ice and then circulate it around a person's body. It doesn't seem unreasonable for a road crew to carry along a cooler of dry ice for suit refills.
"We could build roads that lasted 50+ years if we simply added 10% crushed up superball into the asphalt mix."
I have presumed that Musk's choice of how to present the HyperLoop to the world was motivated by the goal of drumming up popular support for the project in California. In effect, he likely wants the citizens to tell their government, "Go out and buy Elon's product." Governments are accustomed to citizens saying, "X is a problem and something must be done." vs. "We want Problem X solved via Means Y." So, one incentive which kicks in is risk aversion. No elected official wants the failure of something new to be pinned upon him. Also, better ways of doing things often are worse for politicians. How much bribery, favoritism, etc. is encompassed in the process of fixing the same road over and over again every few years? Politicians might dislike the reduction in power and control which would come along with a road which would last 50 years.
Imagine if companies with innovative technologies marketed them directly to citizens. "We sell a road system which will last for 50 years. Tell your local government you want Surface XYZ." Such marketing would be akin to the marketing of prescription drugs to consumers as a indirect way of influencing physician prescribing habits.
Could changes in artificial lighting affect food consumption? Lab mice, pets, and people all have been exposed to similar changes in lighting types over time. Color temperature effects? The 60hz strobing effect of fluorescent bulbs? Have better lighting technologies resulted in brighter environments? Have security concerns. etc. lead to light exposure for more hours of the day?
Could better control of feral cat/dog populations in urban areas explain the observed increases in rat weights? What if fatter rats are easier and/or more desirable prey? Why should a cat waste effort chasing after a fast, skinny rat when a fat one providing more calories is less likely to outrun it?
I'm a Clevelander, and I bought workbenches for my basement here:
The warehouse is huge. It's (somewhat ironically) in an old auto plant in a Cleveland near-ring suburb. They (as of a few years ago) list items both on their own website and on eBay/others. I recall being told that their business model is to make an offer to a company closing a plant for all equipment -- simple liquidation.
When I was there, some guys from Florida were looking at some sort of precision measuring device. They owned a small machining operation and said that this particular device would cost $125K new. HGR was selling it for less than $5K.
I was quite pleased with my $30 workbenches. One had been modified with large, lockable casters. On the way out, another customer noted that the castors alone would cost $100 new for a set. One could question the time efficiency of my purchase, but I wasn't working at the time so my opportunity costs were low.