HN user

d4mi3n

2,563 karma

Security engineer in Detroit, MI.

Ask me about technical security. I occasionally have good ideas and often find better ones through people I speak with.

damien@absurd.engineering

https://www.linkedin.com/in/dlwilson

Posts19
Comments630
View on HN
unitedwizardsofthecoast.com 29d ago

United Wizards of the Coast recognized by NLRB

d4mi3n
113pts67
unitedwizardsofthecoast.com 2mo ago

United Wizards of the Coast

d4mi3n
234pts218
arstechnica.com 9mo ago

Customers imperiled after nation-state ransacks F5's network

d4mi3n
3pts1
www.youtube.com 1y ago

Turning Disposable Vapes into a Fast Charge Power Bank [video]

d4mi3n
2pts0
factorio.com 2y ago

Factorio: New New Rails

d4mi3n
2pts0
www.youtube.com 2y ago

Can rock dams reverse climate change? [video]

d4mi3n
16pts5
www.youtube.com 3y ago

Ritom Pumped-Storage Plant Project – Tunneling Under Extreme Conditions

d4mi3n
3pts1
www.reuters.com 3y ago

U.S. SEC votes to advance stock market overhaul proposals

d4mi3n
2pts0
www.bloomberg.com 4y ago

NSA Says ‘No Backdoor’ for Spies in New US Encryption Scheme

d4mi3n
2pts4
www.wsj.com 4y ago

Businesses Seek to Soften SEC Cyber Rules

d4mi3n
1pts1
www.wsj.com 4y ago

Neurodiverse Candidates Find Niche in Remote Cybersecurity Jobs

d4mi3n
2pts1
every-layout.dev 4y ago

Relearn CSS Layout

d4mi3n
9pts2
www.reuters.com 4y ago

U.S. to work with Big Tech, finance sector on new cybersecurity guidelines

d4mi3n
48pts54
grist.org 5y ago

Oregon’s air quality is so hazardous that no one knows what it means for health

d4mi3n
18pts25
www.wsj.com 9y ago

The Rise and Fall of a K Street Renegade

d4mi3n
2pts3
news.ycombinator.com 11y ago

Ask HN: How do you build software for government agencies?

d4mi3n
5pts9
www.youtube.com 13y ago

Is Sad Music Actually Sad?

d4mi3n
2pts0
www.youtube.com 13y ago

Is A DOS Attack A Weapon?

d4mi3n
1pts0
tenderlovemaking.com 13y ago

Tenderlove on Rails security exploits

d4mi3n
20pts3

I knew the publishing and game industry weren’t known for good treatment of their labor, but WOTC had a fair reputation in that regard. This has apparently degraded prior to my joining the company and has continued to do so. A big motivator for organizing for many was the steady erosion of pay, benefits, and the lauded perks despite a workload that has and continues to grow tremendously.

Worked in tech for a long time before I got to WOTC. Went through a lot of layoffs and short term executive decisions that invariably leave anyone without preferred stock out to dry. Wish I had a union then. Glad to have one now.

Edit: Words are my own. I am not a rep of WOTC or Hasbro.

This is actually a pretty interesting observation as GMail, when it first came out, was just as clunky as all the other webmail clients. At the time, everyone was used to Yahoo!, MSN, etc. and Google was the odd one out with their webmail client.

This changed when they were the first folks out there to get a dynamic interface in the browser (some of you may fondly or not so fondly remember the days of DHTML, XMLHTTPRequest, and the like). Fast forward 10 or 15 years and now GMail is the standard by which everything else is measured.

I'm sure there are some things that are objectively better, but a surprising amount of preference comes from familiarity.

Probably a diversification play and a play to see out bigger contracts. If you've worked in the FEDRamp space, you may be aware that Wiz (last a checked, a year or so ago) is one of the few and possibly ownly player certified to operate in FedRAMP Medium/High deployments operating with the technology it does (eBPF instrumentation).

Well, in the case of a company trying to market to you, it literally _is_ their business. It makes them money.

The problem is that we have markets where we: - Incentivize organizations to pursue profits at the expense of everything else, which includes social good and civic rights - Rarely hold bad actors accountable (and almost never in a timely manner)

Which means, given enough time, we're always going to trend to whatever makes the most money. Targeted advertising makes money, and will continue to do so unless or until we collectively decide to make it a greater risk to profits than it is today.

I think this is interesting in that I feel, grammatically and structurally, LLMs often generate _higher quality_ text than most humans do. What tends to be lower quality is the meaning of said texts.

Say what you want about marketing-isms of your typical LLM, they have been trained and often succeed at making legible, easy to scan blobs of text. I suspect if more LLM spam was curated/touched up, most people would be unable to distinguish it from human discourse. There are already folks commenting on this article discussing other patterns they use to detect or flag bots using LLMs.

I'm still salty that I can't use em-dashes anymore for fear of my writing being flagged as AI generated. Been using them for years—it's just `alt+shift+-` on a Mac keyboard and I find them more legible in many fonts compared to the simple dash on the typical numpad.

It's so sad to me that good typographical conventions have been co-opted by the zeitgeist of LLMs.

I suspect this is partly due to the quality of documentation for Elixir, Erlang, and BEAM. The OTP documentation has been around for a long time and has been excellently written. Erlang/Elixer doc gen outputs function signatures, arity, and both Elixir and Erlang handle concepts like function overloading in very explicit, well-defined ways.

I've seen but haven't used CEL. Anybody with experience with competing tech have any strong opinions? I've used OPA, know CEL used by GCP and Kyverno, but otherwise haven't seen anything compelling enough to move away from the OPA ecosystem.

This guide has aged surprisingly well, but I’d add to this: the above response is about as good as you can get—it is firm, non-combative, and moves the conversation forward.

Don’t antagonize your recruiter. You want them to advocate _for you_ when a prospective employer is drafting an offer. Work with them to give them the ammo they need to make that happen.

I was laid off at my last 3 positions and can really relate to this. If it’s any consolation: how a company handles this is a good indication of the maturity of their management and recruiting function. I also strongly disagree with any assertion that would state “short stints = unreliable employee”. Nobody can make that assertion without confirmation of what caused those stints and the tech market from 2020 - today has been notoriously volatile.

There are plenty of great orgs out there that will soak with you before making assumptions, but as a rule most startups have fairly inexperienced management unless they are founded by a team that’s been through the rodeo a few times.

Company as Code 6 months ago

I always thought of this as authority, accountability, and responsibility of a thing. Ideally one group or person has all three. In practice you’ll have many entities with some combination of the three.

What you describe sounds a lot like Diátaxis[1], which is a strategy for writing and organizing technical documentation. It categorizes docs into one of four categories: tutorials, explanations, how-tos, and references.

Category is derived from a fairly simple heuristic: whether the content informs action or cognition, and whether the content serves the reader’s application or acquisition of a skill[2]. I’m a fan and it’s simple enough that most anyone can learn it in an afternoon.

1. https://diataxis.fr/

2. https://diataxis.fr/compass/

Unless my understanding of how IPv6 is flawed, I don’t think your assertion is true in practice. One of the big benefits to IPv6 is that addresses are plentiful and fairly disposable. Getting a /48 block and configuring a router to assign from the block is pretty straightforward.

I’m aka unsure if IPv4 really gets you the privacy advantages you think it does. Your IP address is a data point, but the contents of your TCP/HTTP traffic, your browser JS runtime, and your ISP are typically the more reliable ways to identify you individually.

Other response address how you could go about this, but I'd just like to note that you touch on the core problem of security as a domain: At the end of the day, it's a problem of figuring out who to trust, how much to trust them, and when those assessments need to change.

To use your example: Any cybersecurity firm or practitioner worth their salt should be *very* explicit about the scope of their assessment.

- That scope should exhaustively detail what was and wasn't tested.

- There should be proof of the work product, and an intelligible summary of why, how, and when an assessment was done.

- They should give you what you need to have confidence in *your understanding of* you security posture as well as evidence that you *have* a security posture you can prove with facts and data.

Anybody who tells you not to worry and take their word for something should be viewed with extreme skepticism. It is a completely unacceptable frame of mind when you're legally and ethically responsible for things you're stewarding for other people.

Make Google multiple millions by improving ad delivery and conversion within Gmail. Probably by also helping Google land big corporate or public contracts, but last I checked most of the money was made via ads in the free tier of GMail.

If you're using the container to manage stuff on the host, it'll likely need to be a process running as root. I think the most common form of this is Docker-in-Docker style setups where a container is orchestrating other containers directly through the Docker socket.

While this is true, the general security stance on this is: Docker is not a security boundary. You should not treat it like one. It will only give you _process level_ isolation. If you want something with better security guarantees, you can use a full VM (KVM/QEMU), something like gVisor[1] to limit the attack surface of a containerized process, or something like Firecracker[2] which is designed for multi-tenancy.

The core of the problem here is that process isolation doesn't save you from whole classes of attack vectors or misconfigurations that open you up to nasty surprises. Docker is great, just don't think of it as a sandbox to run untrusted code.

1. https://gvisor.dev/

2. https://firecracker-microvm.github.io/

Here here. I also have ADHD though I couldn’t use stimulant medications due to bad reactions to it, but I’ve had success with non-stimulant medications (Straterra aka atomoxetine [1]).

A big thing I struggled with prior to medical treatment that I don’t often hear discussed about ADHd was rejection sensitivity.

For those unfamiliar: imagine a time someone said something that hurt your feelings or caused a strong emotional reaction.

Now imagine that as a routine emotional response to day to day interactions. Feeling intensely sad, irritated, insulted, etc. to extents completely o it of proportion to whatever was said or even implied.

It’s brutal. It contributes to a lot of depression and social anxiety for folks with ADHD. It doesn’t matter if you’re aware of the response being disproportionate—you get to go on that emotional roller coaster whenever somebody says they don’t care for your favorite food, accidentally cut you off in a conversation, or the day just turns out differently than you were expecting.

Medical treatment makes a huge difference—in my particular case the difference between feeling like I had the emotional regulation of a toddler and not needing to constantly question every emotion I felt prior to responding to things I was reacting to.

Stimulant medications didn’t work for me, but they do this for most people with ADHD (more effectively, too!) and like alterom it saddens me whenever FUD like this crops up.

If I were to put on my security hat, things like this give me shivers. It's one thing if you control the script and specified the dependencies. For any other use-case, you're trusting the script author to not install python dependencies that could be hiding all manner of defects or malicious intent.

This isn't a knock against UV, but more a criticism of dynamic dependency resolution. I'd feel much better about this if UV had a way to whitelist specific dependencies/dependency versions.

I’d counter that with the Equifax breach that raised thei stock prices when it became clear they weren’t being fined into oblivion. Suing is also generally only a realistic option if you have money for a lawyer.