HN user

fivre

1,172 karma
Posts3
Comments250
View on HN
US Tech Force 7 months ago

https://news.ycombinator.com/item?id=46277687 mentioned Recoding America as "what you're up against", omitting the important "people had learned what they were up against and were well into the process of building collaborative effort between civil servants

the book _is_ good, but it's rather disheartening that all the people discussed (and many more that couldn't fit into the book) on the federal side were summarily fired to clear space for sycophants and toadies round one (the DOGE broccoli hair kids siphoning off sensitive data and doing some casual corruption) are putting out this as sycophants and toadies round two: _lasting_ corruption in partnership with the least scrupulous bits of private industry

the people in the book are https://18f.org/ and spent the last decade building useful relationships, familiarity with public sector quirks, and standard software toolkit items for government tech. they got tossed for the crime of working with the Biden admin and wanting to work towards building tech entirely for public good under the auspices of the law.

whatever branding and whatnot this comes wrapped in i don't trust this admin nor whatever bits of the private sector are looking to work with it in the slightest to not stand up something that works in the public interest. we're gonna get new and exciting forms of graft and revolving door exploitation of sensitive data

chatgpt grant me an AI demon that can transform any manager saying this into a pixie trapped in a cage, attached to each of their ICs' heads for duration of the project, or something

zuck is the founder of the company and has been at the helm since its inception

consider where that management debt may have come from, and whether accepting the current crunch will somehow alleviate it, or signal that crunch will solve all problems and should be used, likely more aggressively, in the future

being politely hostile isn't not being hostile, it's just being hostile while maintaining decorum. there aren't meaningful consequences for a CEO breaking decorum in negotiations with those under them; maintaining it is just a nicety

while prior context is absent, at least in this email zuck isn't offering assistance or asking what he could do assist, it's just a politely-worded "get it done, fucker"

i find a servant leadership approach far more effective, and better able to acknowledge that said team problems were quite likely caused by previous "stop complaining and get it done" leadership whose only skill is cracking the whip

are there technical details on exactly what x.com did?

cloudflare offers a lot of self-service tools, which can and do allow customers that cloudflare doesn't want to service to use it until someone finds out (my favorite example is that, briefly, the foreign ministry of Iran briefly managed to register and activate properties on the service)

registering while only directing brazilian clients to cloudflare would be difficult using the standard method (setting your domain's nameservers to the cloudflare servers), but cloudflare's CNAME setup option only requires a TXT record. it's possible x.com did that by just paying for a business plan and never interacting with cloudflare staff

doing so for the _root_ record is a bit dicier, but as x.com operates its own nameservers they're probably able to handle the not-quite compliant fuckery necessary to CNAME the root: https://developers.cloudflare.com/dns/zone-setups/partial-se...

in 2010, i did a study abroad semester in moscow and was confused by all the armed security in grocery stores, standing around, doing nothing. i only later connected the dots from the recent breakdown of social order in the 1990s (https://www.youtube.com/watch?v=FSrQe9J8Cv8 is a contemporary far-past artistic take on it, the chorus is roughly "in the nineties, they killed people, and ran around naked and mad")

rather strange trip to see the same arrive in the us

OIDC seems like it can reasonably help in a fair number of these cases, maybe? it's iffy because (a) the major providers, are, well, Google and their ilk, (b) SSO solutions trend toward reducing user confusion at the cost of choice--im still out on whether the common "enter your email/account identifier so we can select which IDP we use" login flow is something of an anti-pattern or not

i generally like having the option for "sign in with github" as opposed to the all-encompassing "sign in with google" (ignoring that github is a microsoft account but not quite at this point)

smaller-scope IDPs for a particular field ("ey, you work on code stuff? you probably have either a github or gitlab account to log into our code-adjacent service" or "ey, you use stackoverflow? you can use that same login on superuser") is maybe a decent middle ground, where shared authentication is more explicit than third-party cookies were

Use it for art, entertainment, experiments, explorations. Use it to mine the depths of the human soul and reflect back at us what we are. Don't use it for law, health care, directions, or anything humans depend on.

you could, but the companies building these things very much want to sell it to other companies that do "things humans depend on", because that's a much larger market than just the entertainment industry.

do the people managing the chatbot know that though?

this shit gets sold as a way to replace employees with, essentially, just the middle manager that was over them, who is now responsible for managing the chatbot instead of managing people

while managers are often actually not great at people management, it's at least a somewhat intuitive skill for many. interacting with and directing other humans is something that many people are able to gain experience with outside of work, since it's a necessary life skill unless you're a hermit. furthermore, as a hedge against managerial ineptitude, humans are adaptable creatures that can recognize their manager's shortcomings and determine when and how to work around them to actually get the job done

understanding the intricacies training a machine learning system is a highly specialized and technical skill that nobody is going to pick up base knowledge for in the regular course of life. the skill floor for the average person tasked with it will be much lower than that of people management, and they will probably fuck up, a lot

the onus is ostensibly on AI system vendors to make their systems idiot-proof, but how many vendors actually do so past the point of "looks good enough to close the sale in a demo"? designing such a system is _incredibly_ hard, and the unfortunate reality is that if you try, you'll lose sales to snake oil salesmen who are content to push hokum trash with a fancy coat of paint.

these systems can work as a force multiplier in the hands of the capable, but work as an incompetence magnifier in the hands of the incapable, and there are plenty of dunning-krugerites lusting to magnify their incompetence

2001: what is this nonsense plot? why in the hell would anyone fill the world with mass-produced nonsense information? what purpose would it serve!?

2015: what is this nonsense plot? how would you even create a virus that destroys a language? it's inconceivable! it makes no sense! why!?

someone please find whomever it is feeding Hideo Kojima advance knowledge of exactly what the next poison trend in the information industry will be

Untranslatable 2 years ago

i particularly like that hacking the URL query parameters is apparently the only option for navigating the country and language categories, but those query parameters are at the end of the URL, usually past the edge of the URL bar field

they're past the end because the first parameter is a giant "authenticity token" base64 blob. you'd think this is maybe important, but removing it doesn't appear to affect the request at all

they were pretty consistent about picking good artists though, which was great for scenes i dont follow myself

no one person can sift through every scene and genre to find the good shit, and there's plenty of bad shit. i can do that for like, one scene

bandcamp articles generally delivered me more quality finds with more variety than automated "you may also like..." curation systems a la spotify or last.fm.

it's not like the latter are truly democratizing anything either--once getting big on spotify (or nowadays, tiktok) became important commercially, you got a whole ecosystem of influencers behind the scenes offering promotion in those systems. getting boosted via a faceless "chill sunday morning coffee music" playlist is still curation

yes, i use irssi to hold persistent sessions for all the twitch chats im in. doesn't require anything special beyond an oauth token sent as the server password

the original "protocol not commercialized" sentiment in the OP is a bit odd. nobody commercialized HTTP per se (okay, you could make an argument for SaaS CDN proxies, but i don't think that was the spirit of the original argument), they commercialized things you could deliver using it. the channel-based real time chat model is what mattered, not the intricate details of how the underlying bits are delivered

functionally, Discord and Slack have commercialized that model, with clear and obvious effects for people that were using IRC. every community i was part of via IRC has migrated to those services, and i haven't encountered a new community on IRC in forever, but have encountered plenty of new Discord communities

that has nothing to do with staffing. Korea has a uniquely hostile ISP market where service providers want to charge foreign services ridiculous amounts (versus peering agreements in most markets) for access to Korean consumer networks

so are what are you actually opposed to? the general concept of drugs? you can't really get rid of those: pharmacologically active substances exist as a natural consequence of how biological receptor and message-based systems work. unless you propose dispensing with organic bodies altogether and uploading our consciousnesses to the cloud. until such time nature can and will produce molecules that fit into the same receptors that dopamine, serotonin, GABA, glutamate, etc. do

are you opposed to "non-productive activity"? fuck it, let's ban the entire concept of recreation. free solo climbing isn't particularly productive and is a risky activity; anyone caught doing so should be promptly and harshly scolded, and then sent to the salt mines forever to produce economic value

are you opposed to violence and human suffering? yeah, me too, but drug abuse is by far not the only thing that can result in negative societal consequences. antisocial behavior (which, to be clear, is not _all_ drug use, but is some, same as how not all driving is reckless driving) is an unfortunate aspect of the human condition

"things that I don't engage with personally are inherently bad and should be purged from society" is a bigoted and egotistic argument. you probably do things i find unpleasant and i probably do things you find unpleasant. as a society, we find ways to understand why others do things and to minimize their negative impacts--we allow drinking, but not the markedly more dangerous drunk driving. "simply eliminate everything that may have a negative impact that i, personally, the saintliest person in the world, do not partake in" is a non-starter.

JSON patches aren't the most intuitive and kustomize needs some helper tooling to generate them for you (given JSON objects A and B, generate a patch that transforms A into B), but overall the kustomize model makes more sense, and the team behind it seems to be more actively improving developer QoL stuff than Helm is

templates are only good if your templates can remain simple and do not need to expose most of the output fields. my experience developing a chart for wide distribution has been very much that your templates will not remain simple (and will turn into an incomprehensible mess, since you'll need them to handle tasks templates are fundamentally poorly suited for) and that there is always someone, somewhere, that needs some particular resource field exposed in values.yaml. the

As a result, the number of possibilities for configuration is often unreasonably large and complicated, mimicking the actual resources they want to create, but without any schema validation!

bit from the op is incredibly true. values.yaml grows, over time, to have every field in the objects it generates, just organized differently, without validation, and with extra complicated relationships with other settings

kustomize allowing you to provide a base set of resources that users can apply their own patches to avoids that config surface bloat problem entirely

it will be necessary to deliver software without bugs that could have reasonably been avoided in time

ive had this sentiment thrown at me too often by peak move fast and break things types. it's too often a cudgel to dispense with all QA in favor of more new feature development. shipping shit that has the same pattern of flaws youve encountered in the past when youve been shown ways to catch them early but couldnt be bothered isnt accepting that you cant catch everything, it's creating a negative externality.

you usually can make it someone else's problem and abscond with the profits despite, but that doesn't mean you should

i definitely read them. bandcamp had a very skilled editorial team that would reliably surface both new and interesting scenes and archival labels that wouldn't have found much reach otherwise, and ive definitely bought albums and found stuff i wouldn't have heard otherwise based on their recommendations

not everything, but their work definitely brought me to music i wouldn't have found otherwise

i find the OP rather amusing--one of the earlier incidents during my time at Cloudflare (circa 2015) was dealing with prolific domain fronting, where IIRC some third-party proxy tool had set something up to the effect of "send SNI query for unblocked site on CF network, send HTTP Host for blocked site" automatically. this was ultimately blocked less because it was strictly undesirable and more because it resulted in some sort of cache poisoning problem. the unintended use started serving those proxy hack results to regular, non-domain fronting requests for whatever reason, which is obviously bad--you want the CDN to serve normal requests correctly, so you squash abnormal requests that work on their own, but cause cascading problems for other not abnormal requests.

many years down the road this is now an actual (with the problem cases handled) feature!

CRs that simply instantiate an instance aren't all that useful IMO. they're much more useful if you have something like Prometheus' case where they want to attach configuration to various Kubernetes resources and can't easily fit it in annotations.

i don't know that i would actually recommend Helm for much though, since dealing with templates beyond a basic "sub string into field" use case is pain and misery. once you start dealing with named helper templates that operate at different scopes and all but the simplest control flow, the lack of tooling makes debugging templates a nightmare. the operator ecosystem has its own problems (i still can't tell what the extra Red Hat stuff beyond kubebuilder is really helping with and can't stand updating it), but having an actual programming language and all the accompanying type checking and testing tools available is a major benefit.

if you don't need something complex, kustomize feels much less breakage-prone than Helm, though its patches aren't as intuitive to write.

technical skill matters, and using that technique skillfully for realist interpretations is one of the easier bridges for neophytes to understand the technique

abstract interpretation within the confines of a particular medium is harder to appreciate if you haven't seen manifestations you can readily understand

That's already the case. ISPs have the freedom to charge prices that vary by region and available service tiers.

Most consumers aren't going to care that a portion of the price is Comcast structuring prices so that it can cover mandated costs of doing business. I've never encountered a company listing, say, that it's charging additional pennies so that it can meet its Social Security tax obligations, for example. That level of granularity simply isn't that interesting for consumer-level prices.

If Comcast thinks these fees are unreasonable and wants to lobby voters and politicians to work against them, it is free to do so via other means.

idk if you've used a chromeos device, but they have an infuriating update schedule where it seems like there are updates daily, and they _always_ require a full system reboot. they apparently can't be consolidated either, so half the time i'll reboot to apply one and immediately get a notification of another

this presumably allows them to ease that a bit and apply some updates with the system still running, with maybe a quicker browser-only restart

Amazon isn't necessarily competing better (though they often are--even if im okay getting a slower delivery, not-Amazon vendor sites will do shit like require signature confirmation without the purchaser requesting it, which makes the package all but undeliverable to certain apartments), but they win on the guarantee that buying a product through Amazon isn't going to sign me up for an endless stream of marketing email.

Granted, Amazon has much less need for that endless stream of marketing email because they're already the de facto first choice shop. It's a lose-lose game if you're a conscious consumer and both want to support a non-Amazon monoculture for internet retail but also don't want to have to yet another drip feed of marketing email.

Ideally there'd be competition among email service providers to recognize the modern landscape of CAN-SPAM compliant but entirely unsolicited and unwanted email and provide user tools that aggressively bin non-transactional email and penalize senders that send 10 "transactional" emails for a single interaction ("here's your confirmation! here's a shipping update! here's another shipping update! are you satisfied with your purchase? leave a review!) as shadow marketing.

Either they're knowingly doing this for brand reinforcement reasons or are honestly clueless and don't recognize that a single email that links to a continuously-updated order status page is preferable. I figure mostly the former, but either way there are limited mechanisms to encourage vendors to make judicious use of email.

you're here, and your old blog is about tech stuff, so there's a decent chance you follow a lot of tech people. there are plenty of _those_ on mastodon, because tech people will suffer through bad UX if the product has certain qualities that that community values (federation being the big one in this case)

that doesn't hold for other groups. people that don't want to think about internet application protocols (most people) throw up their hands and leave at the first notion of needing to choose an instance or needing a JS bookmarklet to follow someone not on your instance

plenty of those people are experts in their field and write interesting content i wouldn't otherwise encounter, but they aren't migrating to mastodon because of that, and there's a decent chance they won't migrate anywhere and will return to sharing their work in niche walled garden academic journals and conferences

sure, mastodon maybe keeps out the garbage firstnamelastname9023285023 accounts that do nothing but send low-content replies and retweet inane celebrity(s' social media managers') posts, but it's keeping them out because only a very specific population will bother to get in, which is a bad filter

Firefox may not be _as_ fast as Chrome, but it's a fairly negligible difference nowadays. rendering speed hasn't been a limiting factor for a while, and i feel like network latency and poor application optimization has been more the culprit there. you can only squeeze so much blood from the optimizing inefficient JS stone, and no amount of rendering engine optimization will ever fix shitty backend API response times

Firefox fails because there is no actual industry pressure to build a better browser. you simply can't sell a browser alone anymore: the free offerings have been good enough since the early 2000s.

Safari only needs to be good enough for iOS users to not abandon the platform entirely, and the ecosystem wants to push you into native apps anyway (Apple wants their IAP cut).

Chredge is, well, _there_, but basically just a minimum batteries included that maybe funnels some set of users into other Microsoft offerings, but it isn't the core product.

Chrome is, well, Chrome.

Firefox is comfortably supported by Google funding as an antitrust action shield. there's no real pressure for them to try and beat Chrome in market share because they're explicitly paid to be minority market share, and aren't really going to lose that share because they already have all of the "intentionally don't want to use Chrome" market. Mozilla faffs about making also-ran internet services (idk, whatever the heck that VPN offering was, etc.) because they fundamentally can't lose their main revenue stream so long as Google wants to avoid antitrust action, and have no real pressure to offer a competitive product.

neither has anyone else!

the inevitable "you could have used something simpler than Kubernetes!" comments that appear every time it's mentioned neglect to note that you're more likely to find a Kubernetes example for whatever you're doing readily available in the wild.