HN user

imroot

2,063 karma

Linux Geek. DevOps Nerd. RHCA. CISSP. Recovering attorney.

https://www.ianwilson.org/

Me@ the above domain...

The views and opinions expressed herein are my own and not necessarily those of my employer, Hacker News, or any other site that may display this content.

Posts1
Comments387
View on HN

I've always said that in the back of my mind, the most successful grocery store would be the 'walls' of the store -- bakery, deli, produce, meats, floral, cheeses, dairy and having a little selection of store brands in the middle where consumers can pick up (and vendors can pay a premium for endcap space, because they're the only non-branded products out there), with the rest of the SKU's behind the walls of the grocery store in a fulfillment only model.

Kroger should have pulled a Wal-Mart and turned to their shrink-heavy stores in urban centers to online fulfillment only -- basically only their delivery drivers can retrieve items for an order, and everything's shopped by an associate (Look south of the MicroCenter in Dallas if you want to see what one looks like: it still has the Murphy USA in the parking lot and is basically an unbranded walmart building with 'driver' and 'associate' entrances -- and then deployed the robotics there: less retail space, more online/fulfillment capacity (have humans grab produce and custom sliced/packed items, robots pick the dry goods), and while you lose some cashier jobs, you'll probably have net improvement in terms of time waiting to be picked.

I ran a large cloud environment for two different US based retailers.

Grocer A: They built their cloud strategy with Azure in mind. Microsoft partnered up with them early on at the C-Level and grocer was given a metric fuck-ton of free services to help build and identify the proper cloud strategy for all of their 2500-ish stores.

Luxury Goods Retailer B: Moved from a Data Center to AWS, since that's where our corporate IT partner recommended we go to. C-level leadership tried to get some fake products removed from Amazon.com, Amazon.com said no, we were given the green light to spend "...whatever needed to be spent" to get us off of AWS and over to Google Cloud as quickly as possible.

It's been my experience that the Google Cloud sales reps will always usually reach out after money raising announcements and other acquisition events just to let you know that they're there and please spend money with them. It was never "Don't fund your competitor," it was always, "we're google, our tech works, they're not going to sunset google cloud, our support sucks, use our partner."

What overhead?

Just about every web server these days supports ACME -- some natively, some via scripts, and you can set up your own internal CA using something like step-ca that speaks ACME if you don't want your certs going out to the transparency log.

The last few companies I've worked at had no http behind the scenes -- everything, including service-to-service communications was handled via https. It's a hard requirement for just about everything financial, healthcare, and sensitive these days.

Percepta was a company that was doing a lot of CV/ML in this space looking for shoplifting traits. They had a few paying customers before they were completely acquired by ADT Business. A lot of shoplifters use the PLU for bananas when tag swapping higher-ticket items at the self checkout, so, more than likely, they wanted to check that you were actually purchasing bananas.

I've eliminated Chrome from my personal systems when uBO stopped working. Blocking v2 manifests also broke a few extensions that were being developed for my day job: they've spent the last few weeks working on Firefox extensions and are almost at the point where they're getting ready to wipe Chrome from our corporate machines.

In the 90's my grandma had her knee replaced. She was bed-bound for 2 weeks before they'd start physical therapy to get her knees back in order. (Ironically enough, her first knee was recalled...so she had a total of three knee surgeries Left, Right, then Left again) over a span of 11 years.

In 2018, my mom had her left knee and right knee done at the same time...and they had her up walking the halls of the floor the next day and was back at home less than 72 hours after her surgery, and she's walking just fine these days without any assistance.

As someone who manages a bug bounty program, this kind of pisses me off.

For some of our bugs given on h1, we openly say, "Hey, we need to see a POC in order to get this to be triaged." We do not provide test accounts for H1 users, so, if they exploit someone's instance, we'll not only take the amount that the customer paid off of their renewal price, we'll also pay the bounty hunter.

My manager was just following orders to protect his job: he has kids and a wife at home and I don’t blame him, but, he’s one of the few bosses that I don’t keep in communication with.

I hope your daughter is doing better and is adapting to a normal life post-transplant.

If you knew who it was, and understood the culture there, it’d be totally on brand for them.

Large, global retailer with their tech center in the Midwest. Most of the long term goals were presented from Italy, most of my coworkers were there because they had been there for 10-20 years and were zombies waiting on their package so that the company could move their jobs to Dallas.

Ironically enough, when I relocated to Dallas, one of their recruiters reached out. I think it was one of the few times that I’ve ever been unprofessional and was laughing as I hung up the phone to a recruiter.

About six years ago, my seven year old son passed away: he had liver cancer at a really young age, had a full liver transplant at six months, and lost all hearing as a side effect of the anti-rejection medications. It was a sudden turn -- he was participating in his school's holiday program on a Friday (spending the rest of the afternoon with me at work on his iPad because neither mom or the babysitter could pick him up) and had passed on a Wednesday.

My job at the time gave me three days off before calling to ask me if I could come back to work, with my boss and HR on the line telling me that they also 'gave me the weekend' (since I was on-call when it happened). When I said that I needed more time away in order to deal with it, they fired me, then begged me to come back as a contractor a few months later.

I was so upset over the things that happened that I turned them down -- it wasn't what I wanted to do and it wasn't how I wanted to be treated: I'm much more selective about where I'm working at these days.

Get an itinerant frequency -- $300, requires no coordination, and you can encrypt your comms.

One of the (ham) radio clubs that I'm a member of does this as a benefit for the group, and it's something that's nice to have: I can give my wife a radio and not worry about what she may or may not say if we have to take two separate cars when we road trip.

I've been meaning to do the process myself, but, I haven't had the time (and honestly, I'd want someone else to do the paperwork for me so I'm more likely to pay someone else to do it) recently, but, this might be the thing that prompts me to go and do it.

73 de K4IMW/WQZQ315

  Location: Dallas Texas/Miami Florida (Winter), Chicago Illinois (Summer)
  Remote: Yes
  Willing to relocate: Only to mild climates with mild winters.  
  Technologies:  Terraform/Consul/Nomad/Vault/Ansible/Chef/Puppet/k8s/helm (DevOps), Information Security (CISSP, CKA, CKS, AWS Certified Security - Specialty)
  Résumé/CV: ianwilson.org
  Email: hi at the above domain
Have 25+ years of technology experience including 10+ years of FedRamp (Mixture of DevOps and Security), 8 years of Healthcare Information DevOps/Security, and 8 years of Endpoint/Cloud/Application security. Former technology consultant for a big 4, led large, geographically diverse technical teams and delivered global solutions for travel, QSR, and retail industries.

Reach out; if I'm not a good fit, I know plenty of folks who are looking who I could refer you to.

I had a similar experience with US Bank. Business account, over $50k lost; they said that they can 'terminate their relationship with me at any time for any or no reason whatsoever,' and didn't have to return the money.

The Fraud and Trust VP seemed shocked when I mentioned to her that it wasn't a big deal for me, and that I had my personal accounts with a credit union.

It's been 4+ years. I've written the money off.

You'd think that, but, as someone who did a phyiscal pentest on a prison recently, that's 1000% not the case.

You can set up your access controllers for anti-passback, but, most folks don't, because companies don't want to pay the costs associated for an 'in' reader and and 'out' reader and implement that level of security.

Don't forget, the telecom operators usually send large amounts of money in kickbacks to the prison in exchange for the 'privilege' to run these systems.

While Prisoners have no expectations of privacy, most do not know that all of their calls are listened to, transcribed, and shared with prison officials. There is some speech-to-text sentiment analysis that will prioritize a call that has certain phrases spoken.

It's just...a mess.

When I was a public defender, I had prosecutors and jail staff hint to me about things that were said during the calls. A few years later, they had to drop the charges in a few cases because it was discovered and reported that the calls between attorneys and clients were being monitored and recorded.

I'm no longer under this specific NDA, so, I can talk a bit about this.

It was well known in the wireless industry that ATT collected and kept the most data on all of the carriers: 7 years for text metadata, "7 years" for call history (I put that in quotations because it was rumored that ATT kept them indefinitely, but, there were technical limitations for restoring data that far back), and 7 years for the contents of the text messages themselves. Verizon was up there as well, but, I don't remember specifics.

The carrier that I worked with kept only 3 days content of the actual messages, 28 days for the text message metadata, and 28 days for the call records for their enforcement database, but, they could get calling records and sms envelope information for billing back 7 years, and at the time, we had to implement sharding at the database layer that maintained the warrant database due to the amount of traffic that we were receiving from the calling systems and the amount of queries/data that we were sending out, in near realtime, to law enforcement users who paid $10,000/month for access to that data.

AT&T wasn't storing this data out of the kindness of their heart, it was a (probably small) revenue stream for them.

I've been hired through HN twice.

Once at Singly, in 2010-ish. Was a contractor for about 4 months, they brought me on full time, and I spent about a year there, left to go to one of the big 4 consulting companies, spent 7 years there.

The second was at Greenhouse (the ATS) in 2021 -- was there until Jan of this year.

He's def a good source, but, he said that "cybersecurity" is the new buzzword of the year, replacing "AI" and "Digital Retailing"[0].

When you talk security to most dealerships, it's about protecting the assets that are on their floor plan -- the vehicles -- not necessarily anything else. Most places have tried to take steps that prevent their sales folks from walking out with their customer book, but, that's the extent of most of their information security needs.

--

0: https://x.com/GuyDealership/status/1803421101713715290

I have a ton of MFJ in my shack, and some MFJ hooked up to the radios I'm using on a daily basis; MFJ's loss will be felt in the amateur and public safety industries.

Edit to add:

Whenever I've had issues with one of their products, they literally walked me through disassembling and testing their products on the phone together -- and the staff there working the phones was knowledgeable, kind, and the type of folks you'd hear in the background at their tables/booths at hamvention and other radio-focused events. This isn't just a loss for everyone who uses MFJ, this is going to be felt amongst retailers as well as folks who are in that community. Their products were built well, tested to work, and rock solid: truly generational gear.

The number one source of both professional services revenue and production incidents at one of my previous companies were from users who would completely remove or invalidate anywhere between 600 and 60,000 records from our system EVEN AFTER typing:

reject sixty two thousand four hundred and six records

into a modal with paste disabled and a red background.

You can't fix stupid, even if they're paying customers.

I rent at a WeWork style building, and have been at this coworking space since 2018.

My rent has consistently been around $700/month. This year, they got a new sales person, a new community manager, and finally started fixing things like the broken coffee machine (which was only broken because the previous community manager didn't want to clean it/stock it), removing expired products from the vending machine, and finally changing out the water filters on the drinking fountains...and the tried to raise my rent to $1400/month, with "No room for negotiation."

Interestingly enough, the minute I started moving things out of my office, we could negotiate a smaller amount of money for rent, but, I'd rather take that $700 and just get an extra bedroom in my apartment: things can be closer and I can do more.

When I moved in to this building, there was a waiting list of people to get in -- now, it's close to 85% vacant...with more and more folks leaving every day.