HN user

int0x2e

609 karma
Posts0
Comments146
View on HN
No posts found.

The Iranian regime would absolutely use nukes as soon as they have two or more weapons ready. Just as they have launched countless attacks against civilian areas in many of their neighbor states in the past 2 weeks, including several nations that have prohibited any use of US military installations or their in their country or their airspace as part of this campaign.

If Iran's regime had nukes, I guarantee you'll see UAE, Saudi Arabia, Qatar and several others go all in on their own nuclear programs immediately. They'd be fools not to.

Israel's nukes are troubling, but the weird "nuclear ambiguity" doctrine has already stood for so long and managed to avoid nuclear flare-ups so far. I'd still like them to not have nukes, but they won't be launching any nuclear first strikes for sure - since we've seen them not do that even while fighting many major wars and suffering losses without taking that step...

There are not even 7,000 Mossad agents, period. 7,000 is the highest estimate publicly available for the TOTAL number of employees in the Mossad, and 95% of them are not agents - just like most US intel are not field agents. Real numbers for agents are far, far lower without a doubt.

Also - Israel got burned so bad with the idiotic Pollard affair, there is zero chance Israel would put so much of their assets in the US when they have a 7 front war. They are many things, but they are not idiots, and they clearly care far more about their immediate security interests than what the US thinks.

These theories make absolutely no sense, my dear fried.

UniFi 5G 8 months ago

I used to think the same way, and I loved UBNT. Sadly, after 2 different more advanced configs I had caused wild stability issues - affecting APs, a USG and the controller itself to the point of making them less reliable than a random TP-Link router, plus an ERL randomly dying on me without warning and never booting again - I decided to pull UBNT from anything and anywhere.

I now exclusively use open-source projects with a strong history and community - or used high-end enterprise gear that I pick up when it reaches EOL so it's dirt cheap. Stability has been so much better, even with the most advanced configs I ever created.

Storage will never work. Quote me on this. Nuclear or a mix of nuclear and renewables will be the only way to seriously get away from fossil fuels. Also, even if storage works some day, hoping we manage to discover how, scale and implement it across human civilization in time is a crazy bet to make. Even if we seriously go all in on nuclear and renewables tomorrow - it might already be too late, so betting on some miracle tech to be found, scaled and implemented in time is not only unwise, it would require several miracles to have any hope.

This is more of an argument for how pure economic thinking and the current constraints/processes have poor correlation to actual impact and desired outcomes. It's similar to how Enron would make the most money when California had rolling blackouts - by operating right at the edge of the network crashing, they would make the most money because reserves were low, so they intentionally shut power stations down and caused small grid crashes.

If you really believe in renewables, if anything, we need to go all in on nuclear for the base load, but no one seems to be headed in that direction other than China and India, because the don't have the same market failures we do.

It's much worse - if the data isn't just a ton of tiny files, and you're able to spin up a bunch of workers for parallelism, you can get up to 120 Gbps per storage account (without going to the extreme of requiring a special quota increase).

That means in a little bit over 5 minutes, the data could have been downloaded by someone. Even most well run security teams won't be able to respond quickly enough for that type of event.

At a former team, we went from spending quite a bit of time on code style comments and disagreements to spending no time at all on it, with the simple act of making the code linter a breaking step in our CI build, and deciding no review will start until the build is green.

We had to adjust our linter settings here and there - but it was still super efficient for everyone's time compared to what we had before...

I can't recommend this more.

The difference between theory and practice, is that in theory there is no difference, but in practice - there is.

So far, every "provably secure design" I've seen ended up being insecure in practice due to the things people abstract away.

I'm not saying it's impossible, but I have not seen it done perfectly thus far.

We've seen more success by having many many iterations and widespread usage of common designs and patterns. These are not perfectly secure by any means, but they are secure enough against common threats to make it functionally equivalent until we figure it out.

For enterprises, it's hard to have a ton of different tools. I worked at a very large software company, and our security tech stack was so big and convoluted, that just maintaining a compliant CI/CD pipeline was a 5 person job, because there are ~20 different tools to integrate and debug, and each of those changes every year or two, so you're constantly re-learning, re-integrating, debugging,etc. Having a single (or just a couple) vendor(s) sounds like a dream!

Those aren't cheap, but rolling your own usually isn't any cheaper. Even huge enterprises usually buy instead of build because it's cheaper in both the short and long run.

Think about most managed cloud services - you could deploy your own SQL servers on EC2, configure replication, fail-over, backups, security patching, log collection, observability, etc. - but you'll end up paying a lot for engineers to build, maintain and monitor that solution compared to just spinning up one of the ready made offerings by AWS. It might be cheaper to do if you have a ton of RDS, but it really has to be a huge huge volume, and even then, AWS will probably find a way to discount your bills to make it still better...

I work at one vendor currently and have worked at a few prior. The difference is astounding - my previous gigs, including one of the biggest vendors ever was exactly as you said. My current gig is exactly the opposite - strong focus on real security insights and value, none of the box-ticking bs, and a great roadmap. It is rare, but when everyone at the org, and especially the product side really know how attacks play out - you can make a real impact on the world.

You're right that a generator must be taken care of, but a truck with an inverter is very different from a generator if you plan to power something significant. The truck+inverter will probably keep your fridge and lights running, but can't power your whole house unless you get an oversized aftermarket alternator, which will cost more than the generator probably will (aftermarket car parts aren't cheap).

Does Google really have Android though? Android is open source with a flexible enough license that if Google ever tried to tighten their grip too much, they'd lose the dev community quickly. They own the Play store and Google services, but you can create an AOSP device (a non Play/Google services device) with no issues, and some chinese/low-end players already do that exactly to avoid some of the licensing costs and requirements.

They may have had a very good handle on Android talent in the start, but now every facet of Android engineering has a non negligible community outside of Google.

I'm not saying it's like Google has nothing, but their position in the Android universe is one or two bad moves away from slipping from their grip at any moment. It's not a hard link like Apple's.

My smart home is also my home security solution, so I wanted it to work through a (short) power failure.

Getting a UPS for my Home Assistant node was the easy part. Like you, I was worried about the many nodes scattered throughout the house that needed power.

The solution I've come to for now is using a USB plug for mains power, that goes through a DIY USB battery bank charging board (that I got off AliExpress) that's plugged into an 18650 cell. Most of these boards can either charge or provide a 5v out, but some are happy to do both at the same time, and can act as a mini-UPS.

I totally agree.

It's also great to see how with a little technical know-how, you can avoid paying 100s of dollars for some IoT tech that is reliant on more people buying overpriced hardware for it to work in the future, and instead - go for DIY or cheap hardware (e.g.: SonOff) which gets a huge audience due to their low prices, which guarantees someone like me will spend the time to get it properly supported soon enough...

All of a sudden, the premium product becomes the inferior product, because it will have a smaller market share, and therefore, fewer hackers :-)

These chips are intricate enough to potentially contain backdoors. While it is something I never thought about with respect to Espressif, it does seem plausible that they could be a target.

As the old saying goes, "the S in IoT stands for security" - I choose to trust Google/Amazon and their peers to have an Internet-connected device, but everything else (95% the IoT devices I have) gets sectioned off to a dedicated VLAN & WLAN with no Internet access (and no access to the rest of my network).

This keeps me safe, and keeps the devices safe from each other (micro-segmentation in the access level). No need to trust what has minimal interfaces, and then I don't worry as much if I don't roll software updates every week...

FWIW, there's a study that looked at patent filings and paper publications for inventors in small vs. large companies.

It seems that as a whole, when people choose the Big-X route, they tend to make fewer inventions and publish fewer papers and their inventions and papers get cited less.

So, in theory, by going to work in Big-Tech, you're choosing greater comfort and prestige, while reducing your overall impact on the world, while the startup route holds much more expected impact, but a much higher likelihood of reduced financial comfort.

There's a part of me that thinks that nations that encourage hoarding talent would be less successful than those that encourage innovation, and therefore, I wonder if we need some sort of innovation grant (i.e.: for every successful patent application/company registration/etc. that is NOT fraudulent, the submitter gets 24 months of financial support at the median income level, so they can chase that dream)

I call this "resume engineering". Some years ago, I decided to pass on a very impressive position at one of the then-hottest tech unicorns. I kinda liked the people, thought the tech was cool, but didn't see any way for the company to succeed.

As I thought, that company died, firing 100s of folks before the end.

It's been a few years, but a former colleague who took that job, managed to land an impressive title at my previous employer, above my level at the time... I have since left that company (unrelated), moved to a startup, and couldn't be happier.

My opinion is that titles don't matter. At all.

Compensation does matter, but you have to also value your happiness and factor that as well.

Isn't this a prefect recipe for a super-bubble? When you help people with the down payment this much, wouldn't basically everyone try to apply to enjoy appreciating property values, driving demand and prices ever higher, and even worse - with relatively little commitment to follow through if the economy gets choppy? With the down payment, at least you have some skin in the game, but with this program, for the first 5-10 years you would probably see your mortgage mostly as a rent alternative...

It's a little more complicated - in AAD, the app developer has a single app registration, which is the app side of AAD. The app can ask for certain permissions, specify trusted sign-in URLs, manage client secrets, etc.

Then, on each AAD tenant that wants to use this app, an admin for that tenant would create their instance of the app, called an enterprise application or service principal. That second object can choose whether any user in that tenant can sign in to the app or not, and can assign AAD roles to users/groups.

It is very common for apps to have a single tenant, and therefor the app registration and enterprise application are both in the same tenant, but if the app registration would allow it, any tenant can create their instance, and assign users from their tenant any role they desire.

This means that it is possible to have an app managed really well within your tenant, yet make the mistake of allowing sign-ins from other tenants, and thereby outsiders could still have full access...

The really cheap stuff actually doesn't even have a power supply! There's a breed of LEDs that takes straight AC and rectifies it using the LEDs themselves. By using a large number of tiny LEDs in series (typically in COB form), you can easily reach close to 110v or even 220v, and then you add a small current limiting controller in series that's dirt cheap compared to magnetics... These are super cheap, and appear bright, but they flicker at 120hz, which can be annoying when there's motion or if you're sensitive to it.

I'd say it's a very bad choice for a bedroom or living room light, but I have nothing against it for the outdoor lights, signage and a bunch of other applications where cost is king.

If you're willing to share your design, I'm sure there are other folks like myself who think this is a cool idea. I've wanted to do PoE (or passive PoE) for lights for a while now...

I have worked on a project where we integrated with AAD for auth. One of our developers did things that looked fine - used the common Asp.NET middleware for AAd, configured it, used the latest version, set authorization policies on sensitive routes, etc. Then I did my own code review, and saw that they had passed "verify: false" in the options. When asked why, they said "I just copied this from StackOverflow and it worked...". This guy is not dumb BTW. It's just that security is easy to get wrong, especially if you don't know where the dragons are. We later had a full suite of positive and negative automatic tests, and had an independent pen test verify that things were done properly - but most small teams will never get those resources...

There's little doubt in my mind we're not yet close to making self-aware models or anything of that nature, but I think it's hard to deny we're getting closer at an incredible pace. The most telling metric to me is not what they can or can't do, but rather, how similar their errors and patterns are to children. My 4 year old seems to share more with GPT's hallucinations than I'd initially guess, and as time goes by I see more and more of these small similarities. These models aren't there yet, but they will get to the point where they would at least fool the best of us, at which point you must ask yourself if our wetware has any special merit over their hardware...