HN user

dmattia

338 karma
Posts2
Comments67
View on HN

They are sometimes required. Say you are on a mailing list for some company you gave your email to at some checkout counter one time, and you want to unsubscribe. You probably don't have an actual account with a login with that retailer, they just have your email address.

In this case, what alternative is there than having a magic link in the footer of that email that says "unsubscribe" that includes a token unique to that email address that acts as proof of owning an email account when you then click that link and ask to unsubscribe?

In California under CCPA, it actually goes beyond just frontend regulation and cookie banners, and into the realm of backend tracking management: https://oag.ca.gov/news/press-releases/attorney-general-bont...

The California Attorney General ruled that if a user presents a GPC signal, the company should update all of their backend systems to opt out of tracking in the same way as if the user clicked a "Do Not Sell My Personal Information" button.

Will it let me feel the breeze at the top of Half Dome?

Or have me chase a squirrel around after it stole my snacks?

Or have me feel the pride of accomplishing a long hike that I trained for?

Or let me talk with interesting people along the route and hear about their travels?

Or help me find an incredible pizza restaurant with concepts that aren't in my local suburban area?

Or give me the health benefits of hiking outdoors?

I'm not sure how a headset could ever obviate the desire for travel

It's almost certainly for the companies to pay less money, but with a more generous reading, I think it could be argued that that doesn't necessarily have to come out of employee salaries. That data could be used to:

- Set reasonable ranges to find the right candidates they are looking for faster and minimize hiring friction

- Standardize payment levels in a way that reduces legal liability in certain states like Colorado/California. Or the most generous reading of "reduces legal liability" would be "promoting fairness".

- Reduce the time spent by HR/other teams of negotiating or setting salaries, as they can simply target some target like "we want to pay more than 60% of companies like us"

- For budgeting/forecasting with new hires, this allows companies to have more confidence in their estimates as they plan hiring.

- Some companies now offer calculators even before you're hired with what your salary/compensation might look like, such as https://posthog.com/handbook/people/compensation

But yes, overall I do believe that most companies also expect a general reduction in salaries when they use these tools.

This seems to be only partially true when I read into it. The EU said that Microsoft would need to move their security tools into user-space (or at least to use the same APIs as are available in user-space). If they did that (like Apple has done), they could kick everyone out of kernel-space if they wanted.

They shouldn't. Microsoft should have APIs that enable security vendors to work in userspace.

The EU didn't say that Microsoft couldn't kick vendors out of the kernel, just that they couldn't do so without having the APIs available that would let security vendors operate outside the kernel.

Mac and Linux have such APIs, so CrowdStrike operates in user-mode on those platforms, so those platforms do not give security vendors the ability to crash the operating system.

This is fascinating, thank you for the info! If I am understanding, it would have then been difficult/impossible for CrowdStrike to create a user-mode only sensor without these equivalent APIs.

So I guess I'm not sure I see validity in the claims of those blaming the EU here. It seems as though the EU would have allowed Microsoft to kick users out of kernel-space if they had APIs that allowed making security products in user-space. Like Linux/Mac already appear to have.

I suppose I was expecting something more authoritative here. They confirm that there was an attempted read-out-of-bounds, as CrowdStrike said, but that's not really new information at this point. I suppose we'll need to wait for more detailed analysis from CrowdStrike at some point.

This post explains why security software has historically run in kernel-mode, and really seems to be pushing new technology that Microsoft has that would push security vendors into user-mode (with APIs that attempt to assist with many of the reasons why they have historically used kernel-mode).

Crowdstrike already runs in user-mode on both Mac and Linux (from what I can tell), and it seems like running in user-mode on Windows would significantly lessen the risk of catastrophic failures like a blue-screen-of-death. I know the bulk of the failures here belong to CrowdStrike, but I can't help but think about the fact that Apple kicked security vendors out of kernel-mode a ways back, and that if Windows had done similarly, an issue like this probably wouldn't have been possible. By even offering kernel-mode options to external vendors, I believe Microsoft is creating risk for themselves.

Workbrew 2 years ago

I used to like using homebrew on personal machines. But then as the person in charge of the dev environments at my company, I tried using homebrew packages for our devs but it just went horribly because homebrew don't have old versions.

- Different folks ran `brew install <foo>` at a different time? They may see different behavior

- I ran `brew install <foo>` after a coworker did? I may not be able to replicate whatever issues they are facing

- Someone new ran `brew install <foo>` on their new laptop? They may have an entirely separate major version of that library with breaking changes.

- Do I know if folks are using vulnerable, old packages? Nope!

- Does production use some database with version X, but homebrew only supports a client for version Y? Eh whatever, just have folks locally use version Y. What could possibly go wrong with using a different version locally vs in production.

I kept our own homebrew tap for a while and pinned versions. That was fine. But then I had to maintain that tap, and there wasn't any easy way I found for checking if the versions we kept in that tap had any vulnerabilities on any registry I could find.

Then I found Github Codespaces / devcontainers, switched everyone to use Linux inside Docker, used linux package managers to install pinned versions of everything we needed (using the same exact packages as we bundle into production), and scan my containers using a container vulnerability scanner nightly.

Instantly, 10+ hours of work per week for me vanished and I can now at least reproduce problems and fix them for everyone when they come up.

Beautifully shown, thank you for making this. As a full-time RVer that spends a lot of time in national parks, this is quite useful.

Fun things I noticed:

- All the mountain parks are summer focused, which stinks a bit as I want to see them all but have limited time

- Great Smokey Mountains and Shenandoah have nice fall weather/leaves, and it's cool to see a bump in fall for them

- People go to Great Sand Dunes most in summer, which is when the sand is so hot it's painful to touch. There's great opportunity to camp there during the less busy seasons

- Likewise, it seems like too many people go to Zion when it's crazy hot. It's wonderful for a lot of the year, I just wouldn't go in Summer

- I'm shocked at how busy Isle Royale is compared to other parks, never would have guessed that

Disclaimer: I used to work on Google Search Ads quality models

Google obviously tracks everything you do for ads, recommendations, AI, you name it. They don’t even hide it, it’s a core part of their business model.

This wasn't the experience I saw. Google is intentional about which data from which products go into their ads models (which are separate from their other user modeling), and you can see things like which data of yours is used in ads personalization on https://myadcenter.google.com/personalizationoff or in the "Why this ad" option on ads.

and it’s very much not necessary or even a sound business idea for them to do something else

I agree that Apple plays into privacy with their advertising and product positioning. I think assuming all future products will be privacy-respecting because of this is over-trusting. There is _a lot_ of money in advertising / personal data

Say I have a pico cluster with a few service nodes and a few upstream clients register themselves, and then I deploy a new version of the service nodes where all existing service nodes are taken down and replaced.

Can the client still talk to the service nodes? Is this over the same tunnel, or does the agent need to create a new tunnel? What happens to requests that are sent from a proxy-client to the service nodes during this transition?

Or at a much higher level: Can I deploy new service nodes without downtime?

Yeah for sure! So you sort of need a phone paired with it, but only as in you need a family member (or someone on your phone plan) to have an iPhone, but the watch owner themselves doesn't actually need any other phone that the watch.

It's called "Family Setup": https://support.apple.com/en-us/109036, and it lets me use the watch in what is sometimes called "Standalone mode" or "Companion mode" in different apps.

If you go down this route, know that many apps in the app store will not be downloadable, as they don't support "Companion mode", but I can still get everything I personally needed just fine.

As far as the SIM goes, I think I'm using an electronic sim card? I'm not positive

I had a dumbphone for two years, it was fine.

For the past two years though, I've been using just an Apple Watch, which I was able to connect my old phone number to. It has maps, texting, calling (works best via bluetooth), weather, heart rate monitoring, alarms, email, sports scores, and some music apps. When attached to my wife's phone plan, it costs me $5 per month for all service.

I think the unfortunate reality of dumbphones is that of the folks searching for dumbphones, we all have fairly specific ideas on which features we want and which ones we don't, but there are only like 5 reasonable options available, and most don't hit the mark for many of us. If you want good maps, that rules out many. If you want a camera, that would rule out the watch like I use. If you want reasonable texting ergonomics that isn't speech-to-text, that rules out pretty much all of them

My understanding is that your docker image must have the lambda runtime interface client installed on the image in order to work.

It's not a huge step usually to add the RIC, but it's a bit more tied in to AWS than CloudRun is, which can run arbitrary docker images, if I understand.

I'm using Pulumi in production pretty heavily for a bunch of different app types (ECS, EKS, CloudFront, CloudFlare, Vault, Datadog monitors, Lambdas of all types, EC2s with ASGs, etc.), it's reasonably mature enough.

As mentioned in the other comment, the most commonly used providers for terraform are "bridged" to pulumi, so the maturity is nearly identical to Terraform. I don't really use Pulumi's pre-built modules (crossroads), but I don't find I've ever missed them.

I really like both Pulumi and Terraform (which I also used in production for hundreds of modules for a few years), which it seems like isn't always a popular opinion on HN, but I have and you absolutely can run either tool in production just fine.

My slight preference is for Pulumi because I get slightly more willing assistance from devs on our team to reach in and change something in infra-land if they need to while working on app code.

We do still use some Pulumi and some Terraform, and they play really nicely together: https://transcend.io/blog/use-terraform-pulumi-together-migr...

In general, one of the goals of microservices should be that if one of the five services goes down, the other four should be able to operate in some capacity still.

In practice, this can make the math quite a bit messier, but I don't think it necessarily has been worse overall from my perspective.

So instead of having your system be up or down 99% of the time in a monolith, you'll have it fully up 95% of the time (using your numbers), but of that 5% of downtime, 20% of the time one of your products will be running slowly, or 10% of the time some new feature you launched won't work for specific customers in some specific region, etc.

At my company it makes things like SLA/SLO guarantees for "our services" pretty complicated in that it's hard to define what uptime truly means, but overall I think the five microservice approach, when done well, should have less than 1% of complete downtime, at the cost of more partial downtime

Deno in 2023 2 years ago

Some serverless use cases work like you say, but Docker-based options such as AWS ECS, Docker-based Lambda functions, or Kubernetes would all commonly make use of compiled options

Would upgrading to 11.21 and then using blue/green have been easier? I'm asking as someone with RDS postgres-aurora running 11.9 right now, so I'm genuinely curious on your thoughts

I used Cider while at Google, and setup Google Codespaces at the startup I'm working at now.

Some notes:

- Codespaces uses the devcontainer spec, so folks can use our setup offline if they want

- I get far fewer questions about how to do XYZ, and when I do get questions, I can almost always reproduce them, which is a breath of fresh air

- We do pay a fair chunk to use high CPU/memory machines, this is worth it for us. I have a very lightweight laptop that I use

- Some of our developers like having multiple separate codespaces at a time as a way to separate out different projects. I just use branches, but some folks like the codespace workflow.

- I can run vulnerability scans over our dev environment which is nice

- When I onboard devs, I can get them to the point of running our full application suite in a 15 minute meeting

- I don't have to deal with m1 vs not-m1 issues that were popping up all the time before we made the switch

- Having a linux base is nice, as that's what we use in production. We deal with some annoying dependencies and not having to install them on Mac anymore is nice

- It's seamless changing between my laptop and desktop that I work from. All the code is instantly on the other when I switch, even if I haven't pushed up to git

- Chrome + Notion + Slack + our task tracker app + etc. take up a lot of memory now adays. Even with 32gb machines, folks often would run out of memory trying to run our app. On a codespace, all of the memory is dedicated to just the app.

- With prebuilds, when a developer opens a codespace, we already have all of our python, node, go, etc. dependencies preinstalled (also things like awscli, terraform, pre-commit, VsCode extensions, docker). They just run `aws sso login` and then `start --serve` and things work.

- I live in an RV, and sometimes don't have great internet, but my Codespace is on a remote machine that does always have fast internet. Even being an internet-based service, this works great for me.

The biggest cons:

- Some of our devs were really passionate that they preferred other IDEs than VsCode. Some other IDEs do now have support, but they aren't as supported as VsCode yet

- Codespaces have downtime occasionally (as did Cider at Google). Most folks just use a local copy/devcontainer of the app or do other things when this happens, but some folks choose to always use devcontainers/local copies because this annoys them so much. At Google, we just posted memes when this happened and went home.

- Codespaces become inactive after a controllable amount of time has passed. Some folks don't like the 40 seconds to reactivate a codespace after being inactive for more than 30 minutes, so they either write scripts to keep their codespaces alive or just don't use codespaces at all.

Overall:

- most of our newer employees exclusively use codespaces.

- A few of our older employees who developed locally for years have chosen to continue developing locally, and will just hop into a codespace to run a quick terraform command or something if their local version gives errors.

- The number of questions we deal with regarding issues on a single users' machine have gone down dramatically, and tbh most of the questions come from folks who use the local still

- We do pay a pretty penny for this, but it's a small fraction of our overall cloud spend or costs per employee

Duo Outage 3 years ago

I love that the status page is being updated regularly.

But I have no idea what the difference is between DUO1, DUO2, etc. through DUO73. I feel like they should have a better way to clarify which users are affected.