I do this. But I hit a wall with shopify. They only allow 5 email addresses to be bound to an account and only one account to one phone number. So now I cannot get tracking information from about a dozen online stores that at some point or another switched to shopify after I already made a custom email for them
HN user
fishpen0
[ my public key: https://keybase.io/fishpen0; my proof: https://keybase.io/fishpen0/sigs/sQrSU7NmrkQAzyGJlHoLU91s8CX8k0wo5i2clv1LdTg ]
In a real company? A private codebase at a minimum should still be getting regular security patching and dependency updates. Always eventually one of those updates requires some level of refactor. If I see a project with no commits, I run away.
In practice this just stops victims from coming forward and deepens the cycle
But then your "lockfile" equivalent is just... a list of commit SHAs scattered across import statements in your source? Managing that across a real dependency tree becomes a nightmare.
The irony is that this is actually the current best practice to defend against supply chain attacks in the github actions layer. Pin all actions versions to a hash. There's an entire secondary set of dev tools for converting GHA version numbers to hashes
It doesn't matter. We pulled axios out of our codebase, but it still ends up in there as a child or peer from 40 other dependencies. Many from major vendors like datadog, slack, twilio, nx (in the gcs-cache extension), etc...
I think it stunted out. Outside of only the densest areas, maker spaces never really formed. The stuff remains accessible as a hobby only to the wealthy who can afford all these tools and machines in the majority of the country. I'm a nearly 40 minute drive to the closest maker space and I'm in one of the 10 densest populated cities in the country. The last city I lived in, the maker space was too popular and raised their fees so high that it is also impossibly inaccessible to most people.
This pricing model will continue to incentivize them internally to not fix the hundreds of clearly documented issues that causes CI to be incredibly slow. Everything from their self-inflicted bottlenecking of file transfers to the safe_sleep bug that randomly makes a runner run forever until it times out. All of it now makes them more money
This pricing model continues to incentivize them not fixing the hundreds of clearly documented issues that causes CI to be incredibly slow. Everything from their self-inflicted bottlenecking of file transfers to the safe_sleep bug that randomly makes a runner run forever until it times out.
We are a ~20 person team who use private runners and this will increase our annual costs by ~12k/yr. This is a huge relative cost increase for us. If anything this hurts small teams that focused on expansive automated testing more than giant orgs.
gitlab
Not really comparable at any compliance or security oriented business. You can't just zip the thing up and sftp it over to the server. All the zany supply chain security stuff needs to happen in CI and not be done by a human or we fail our dozens of audits
Yeah this is mostly the "build twitter in a day" projects that conveniently ignore the reason these companies have 10,000+ developers is the 99.9% of the software that is not the frontend that actually makes the company things happen at the company. The much bigger customers of many of these companies being the advertisers and the artists/creators who have their own interfaces and analytics and billing and payment tooling. The business rules engines and feature flags with tens of thousands of rules that allow any of these companies to operate in subtly different ways for customers in different states, countries, and regions with different laws for accessibility, fair use, and using and storing data. The auth and security layers that often have multiple interfaces for employees, customer classes, partners supporting native-auth, oidc, totp, developer tokens, etc... Apps for a dozen or more different app ecosystems on hundreds of device types from the obvious web and phone-based ios/android to the less obvious carplay, watch, roku, firestick, etc...
Right, but if you just search for "house listings" you find zillow and redfin and other stuff. Becoming the new word for "listings" will tie specific brands to our use of language in very interesting ways. What happens if I register my app to a common word. In this example, can I take "listings" and astroturf my app to the top? Is this a new DNS "buying all the domains" race?
It's actually hilarious to think of a scene where all the people on the bridge are shouting over each other trying to get the ship to do anything at all.
Maybe this is how we all get our own offices again and the open floor plan dies.
But not in paragraphs. Their written language in those forums is short form sentences that are a mix of emojis and almost randomly inserted words that are more akin to honorifics sprinkled in to convey tone "no cap" "frfr"
Bench seats are almost certainly not coming back in modern low cost vehicles due to side impact safety regulations. They aren't _illegal_ but its extremely difficult to meet those standards with a bench configuration and ironically probably why a budget pickup is less likely to have them. Cutting those corners by not having a bench at all is an easy way to save money in the design.
The hauling and towing is another one. Unfortunately batteries are much heavier than a combustion engine and take away from the total capacity of the vehicle. It's curb weight is 500lbs more than the 1998 Ford Ranger. Same thing, budget vehicle means budget suspension, so its weight lowers the capacity instead of increasing the cost of the suspension.
There is more to it than copyright when you start going down the path of photorealism. As much as it is a picture of Indiana jones, it is also a picture of Harrison Ford. As fun as it is to make hilarious videos of presidents sucking ceo toes, there has to be a line.
There is a lack of consent here that runs even deeper than what copyright was traditionally made to protect. It goes further than parody. We can't flip our standards back and forth depending on who the image is made to reproduce
This has the potential to multiply the issues with Fenway and other older fields dramatically.
If every player ends up with a bat custom tailored to their swing this will get very interesting.
Ready for games at Fenway to be 90% HRs
The most secure company is, of course, the company that doesn't exist. Bankrupting your org is certainly the most effective way to keep it secure.
Yes, their role is defense, but not insofar as to remove the profitability of the organization. In several orgs now I've seen the legal team blow contracts and the security team break the product and the IT team break development in the name of performing their role "correctly".
Brainless box checking is not part of defense, you must be willing to critically think about how to fit your role to your product or organization's profit motive.
Coming from San Diego and moving to Boston has been a hilarious ride. In San Diego pockets of people in every neighborhood own literal battery powered golf carts and use them to drive to grocery stores and such. These things are perfect for the streets of Boston, small, easily maneuvered into small spaces. Instead they are illegal in MA with only very specific exceptions for park services and other municipal works departments.
Every time I ask about it people jump all over “they aren’t safe on the highway”. Okay cool. If you own a golf cart in SD, it’s illegal to drive it on the highway. Problem solved right? I mean we have mopeds, motorcycles, literal bicycles sharing all these streets too. Certainly golf carts and kei trucks can have a special license plate for non highway vehicles?
The difference is often that “Member of technical staff” and “Staff” are two different things. Lots of companies have “member of staff” ~= swe 1 and 2 but then simultaneously also have staff above senior.
New laws and regulations make companies more liable for being hacked
Companies buy cyber insurance to reduce their risk if they are found liable
Cyber insurance companies force tech staff to install garbage software in order to check compliance boxes.
Garbage software breaks
Turns out everyone used the exact same brand of garbage software to check the same garbage box
People in hospitals die
When you reduce everything to a checkbox and eliminate critical thinking to apply the need to the exact situation you end up with 90% of companies running zscaler and crowdstrike
"This is just how you solve this, everyone does it this way in our industry"
Unless of course you are a small fish who just needs sso for compliance and for some reason you get to pay like you are a $5B conglomerate despite still very much preferring to just pay an advertised price and not spend a month of people's time in negotiations
HN is full of tech workers yes, faang workers no. HN is full of way more people in tech roles at non-tech and old-tech companies who don't shower them equity that only goes up than you might be aware of. I work in the meetup space and know many dozens of tech workers in Boston that are feeling the rent squeeze and will never own property here
You can always sell your RSU immediately to get cash.
This is not true at all. My current company is privately held and has RSUs. Over the last two years there has been a single buyback and it was at a fixed closed market price and we were limited to selling 10% of our vested RSUs. Lots of startups flipped to RSUs with no plan to go public or be bought out in the last few years.
Additionally, even if your company is stable RSUs are frought with issues like what happened two orgs ago where a blackout period started and our stock went into a 30% free fall during the blackout and never recovered. We ended up getting a tender offer, the company sold to private equity and unvested shares were clawed back
Gambling vs Guarantee. I've lost options or unvested RSU 3 times to companies suddenly rolling over, getting acquired, or doing layoffs. Of the two times I've hit it and actually had them pay out, one payed out at only 1/3 of the original valuation of the equity and one only paid out for two quarters before we were acquired.
Take the pay increase vs the equity every time. Plus by changing 5 times, I diversified my equity on more companies and ensured something hit at least a little.
The dystopian future where diseases like psoriasis get you fingered for every crime within a mile radius of your home or office
There are a handful of key litmus tests that are part of the background check. If you are/were a felon, If you lie at all during the check, If you are in extreme debt, If they find public record of you being anti-american, If you fail a drug test.
These all come up during the screening interviews of your peers, family, and coworkers. I have done about a half dozen or so of these for former peers, friends, and colleagues who have moved on to do public sector or join private military companies that needed clearance.