HN user

jack6e

642 karma
Posts5
Comments67
View on HN

Specific technology choices aside, this was an incredible write-up of their migration process: thorough, organized, readable prose about a technical topic. It is helpful to read how other teams handle these types of processes in real production systems. Perhaps most refreshing is the description of choices made for the various infrastructure pieces, because it is reasonable and real-world. Blog posts so often describe building a system from scratch where all latest-and-greatest software can be used at each layer. However, here is a more realistic mix of, on the one hand, swapping out DBs for an entirely new (and better) one, but on the other hand finding new tools within their existing primary language to extend the API and proxy.

Great read. Well done.

I'd like to point out that my comment mostly referred to the article's original title, which was click-bait referencing GitLab's "secret" to multi-million dollar "success." Spoiler alert: the "secret" was remote work. I took issue with calling their organizational structure of 100% remote work a secret strategy, and with calling their current revenue and valuation a comparative success or that they could be directly attributed to their remote structure.

The updated title is much more informative, accurate, and devoid of click-bait hype.

Skipping over the little annoying facts that fully remote work is not some secret strategy, and that no Fortune 500 company (as an index of success) is 100% remote, let's just do a direct comparison of competitors:

- GitLab is 100% remote and, according the article, was most recently valued at $1 billion, 350 employees, and has an unknown/hidden (or I can't find) number of users.

- Github has a headquarters and also remote work, and was recently acquired for $7.5 billion, with 800 employees and 31 million users.

So...is remote work a secret? Did it lead to a comparative success over a competitor offering similar services but a different organizational strategy? Not really, not even close, no.

More accurately, we should say GitLab has so far managed to make remote work a success for themselves through leadership, organizational culture, and some other actually secret ingredient, which is where the real story lies. Lots of remote companies fail. What has GitLab done right? Sadly, this article only skims the possibilities.

Qualtrics is pretty popular among their initial target audience mentioned in the article: academics. Among academic survey shops this product is the definite go-to.

I imagine, based on my own experience, the average tech worker thinks of surveys as small sets of questions used to easily and quickly collect a few data points. SurveyMonkey is fine for that. But for the types of real surveys that provide the data for serious research, Qualtrics is what you need. I've used it for government surveys, sociological, health/medical, etc., web and in-person, with lots of flow control, randomization, and all the other features needed to produce robust and accurate data.

What? This is entirely untrue, and I feel bad that you had a teacher or reading experience that did not focus on how much inner life, motivation, and emotion are in this poem. I have had the exact opposite experience: people think of Beowulf as a monster-fighting action poem and are disappointed or surprised when they read it and discover most of the content is songs, conversation, historical reminiscences, and not-fighting.

Take as just one brief example these passages from XXXIV lines 52-7 and XXXV lines 5-7 [0]:

So to hoar-headed hero ’tis heavily crushing

To live to see his son as he rideth

Young on the gallows: then measures he chanteth,

A song of sorrow, when his son is hanging

For the raven’s delight, and aged and hoary

He is unable to offer any assistance.

Every morning his offspring’s departure

Is constant recalled

...

So the helm of the Weders

Hrethel grieves for Herebald.

Mindful of Herebald heart-sorrow carried,

Stirred with emotion, nowise was able

To wreak his ruin on the ruthless destroyer

This is a description of an experience almost (but not totally) unknown in modern American/western culture. To dmreedy's point, this captures the duality that on the one hand, these were humans just like us, and fathers who have lost sons violently in war or crime who are weighed down with the burden of that grief and the inability to do anything, to take any vengeance, can probably identify with this ancient father. These words can be a foil that gives voice to their own hearts. On the other hand, we can consider how different Anglo-Saxon society was by looking at the culture of vengeance and reciprocal warfare that resulted in this son's death. Very few of us even experience war, much less can imagine a life in which we expect every spring/summer to be attacked by, or to go out and attack, some neighboring city.

What forces shaped society to develop those systems? How can we prevent returning to that? What was good about life then - what did the people enjoy, and what was evil? These are all questions that are worth asking and trying to answer. But we only get to explore those questions if we approach these texts, as the article's author states, as texts with presence in time and place, creations of real people from a certain time, encoding their particular moment with all its similarities and differences to ours.

Lastly, it does sound better in Old English [1].

[0] https://www.gutenberg.org/files/16328/16328-h/16328-h.htm#XX...

[1] https://www.youtube.com/watch?v=ROghKY1jmuE

(edit for formatting)

Considering that miniature books have been a part of literary and publishing history since at least the 16th century, I doubt this modern rehash will drastically change reading any more than the existing four centuries of iterations.

That said, mini books with this horizontal orientation are a cute and maybe convenient idea for some people. Anything that removes barriers to reading paper books is great.

They state that the cumulative valuation of these 100 companies is $100+ billion, of which $81+ billion comes from the top 5 companies, and $95+ billion comes from the top 10.

Also interesting that the top 2 (Airbnb and Stripe) were in the 2009 cohorts. From the depths of the recession to $50+ billion combined valuation.

The difference is two-fold: actively planting a fake story means that first, the espionage is fake and thus no real intelligence can be gathered, so the only benefit is the hypothetical respect you suggested; second, the story will definitely get out, thus the potential for the negative effect is innately 100%. However, as a real intelligence operation the cost/benefit analysis is inverted, because there is a real, tangible benefit to extracting possibly sensitive commercial and national security information. And while an eventual discovery is always a possibility, it seems care was taken to ensure it would only be a small possibility, and that in any case it would be in the future, hopefully after a large amount of useful data is extracted.

So in the planted story hypothesis, there is certainty of negative outcomes with only the potential for positive outcomes, and those only intangible, while in the this-is-real hypothesis, there is near certainty of some tangible benefit with good probability of significant tangible benefit, with only a potential, distant, deniable risk of negative outcome.

But the effect of that would be to cause massive distrust of Chinese suppliers and cause a shift away from electronics being produced there. IC and cyber experts generally identify the Chinese as using intelligence operations for primarily economic purposes, as compared to Russian/Iranian/North Korean objectives being military or political. A Chinese military intelligence agency using cyber espionage to intentionally disrupt one of the most significant export industries of the Chinese economy does not seem likely, nor does it seem to provide such an out-sized strategic benefit as to be worth the economic cost.

Or at least have testimonies by employees in these company

The original article directly addressed this: "The companies’ denials are countered by six current and former senior national security officials, who—in conversations that began during the Obama administration and continued under the Trump administration—detailed the discovery of the chips and the government’s investigation. One of those officials and two people inside AWS provided extensive information on how the attack played out at Elemental and Amazon; the official and one of the insiders also described Amazon’s cooperation with the government investigation. In addition to the three Apple insiders, four of the six U.S. officials confirmed that Apple was a victim. In all, 17 people confirmed the manipulation of Supermicro’s hardware and other elements of the attacks. The sources were granted anonymity because of the sensitive, and in some cases classified, nature of the information."

It is entirely likely that the companies affected were directed by the IC agencies working on this not to discuss or reveal their knowledge of the hack. Often in intelligence operations it is important and useful to not alert your adversary that you are aware of their intrusions until you are fully ready to take action against them, or have fully removed the danger.

I don't see any reason to take the companies' categorical denials as evidence that this did not happen or that they were not targeted. Those statements are what one would expect in a national security incident and investigation of this magnitude, with such serious implications.

Facebook, Amazon, Netflix, Google. Jim Cramer created the acronym to name these four companies as high-performing tech stocks years ago [0]. But now, as in the above usage, it is more of a catch-all name for the big tech companies. And in its new role as a name for a category of companies, people confuse Amazon/Apple, and also implicitly include other equivalent companies.

[0] https://www.thestreet.com/story/13230576/1/what-are-fang-sto...

This is awesome work, and kudos to Tang, but I am also really impressed with how his advisor, Scott Aaronson, seems to have so selflessly supported his research and given him full credit. Even in Aaronson's quotes within the article he talks about it entirely as Tang's work, and he seems to have considered Tang's best interests in deciding how and when to let him present the work - even that he let Tang present it!

Given a different person, we may have read about "UT-Austin Professor and Quantum Researcher Finds Classical Alternative to Quantum Recommendation Algorithm" (with generic help from students in a footnote somewhere). It's great to see this type of collegial mentorship.

At PyCon in Cleveland this year Amjith Ramanujam did a presentation on "how Netflix does failovers in 7 minutes flat" [0]. Worth a watch/listen for anyone interested in what their response may have looked like. Now I'm curious to read a post-mortem from them and see whether their procedures worked as expected (it sounds like they were down longer than 7 minutes) or where they encountered unexpected issues.

[0] https://www.youtube.com/watch?v=iQI56-up3Yk

This was likely inspired by an event preceding the Nanking Massacre

There is about no likelihood that Tolkien heard about a despicable war crime committed by an Axis power, involving an evil, flagrant disregard for human life, and decided to use that as material for two of his "good" characters. Nothing in Tolkien's works, worldview, or influences aligns with that sort of thought. This is the author who despised German publishers inquiring about his Aryan descent, even though, being of German heritage and a prominent scholar of Anglo-Saxon/Norse/Germanic literature, Tolkien could have perfectly flattered the Nazi mythology [0]. But in your opinion, while hating Hitler and the Nazis for treating Jews as second-class citizens (in 1938, when the persecution was not yet elevated to mass execution), he simultaneously decided, "well, this Japanese massacre of innocent civilians sounds like a fun bit of material, I'll use that"?

More realistically, the influence, as most of his influences, is in Anglo-Saxon and Norse literature, where accounts and songs of battles often make them appear almost like sport, with contests and even gamification. I suppose that is one method of mentally bracing oneself for such a horrifying activity, and for attempting to process the event afterwards. It is part of a common mindset of soldiers at war, one that even the Japanese murderers were engaging, albeit in a perverted misuse. In that view, both Tolkien and the Japanese were drawing from a (very) distantly related source, but much different in purpose, and certainly neither influenced by the other.

[0] https://io9.gizmodo.com/5892697/whats-classier-than-jrr-tolk...

This may be a (passable) evolution of the Latin alphabet, but it is not the English evolution. Missing are runes, and the lost letters eth, thorn, and yogh, which were still in use alongside the Latin alphabet as late as the 16th century.

Probably not many. The most recent SO developer survey said only 20% of respondents thought responsibility for unethical code fell on developers, compared to 80% thinking designers/managers should be responsible.

That's globally. I imagine the sense of responsibility decreases in ethically-gray areas like nation-state warfare against adversaries, and among developers working in strongly hierarchical, military(-esque) environments, for autocratic regimes focused on destroying national/ethnic/religious enemies (as this appears to have been done by).

In another story popular on HN yesterday/today about DNA [0], some of the commenters discussed epigenetics, and the fact that the DNA sequence is simply the "hardware" that encodes what is possible for cells to produce, but there is "software", if you will, above that which determines how sequences of DNA are actually expressed.

In these cases of analyzing really old DNA where only the DNA remains, I wonder how researchers make decisions about selecting what they want to express between varying attributes? I.e., the example used in the article about representing "Cheddar Man" - did they have some basis for selecting the traits to visualize or was it arbitrary?

[0] https://news.ycombinator.com/item?id=16589412

It sounds like you are confusing the multiple attacks described in the article. The most recent attack in August 2017, the primary focus of the article, was indeed intended to manipulate controls and cause an explosion. The January 2017 attack, part of a string of them, is what you are describing. That one was not suspected of intending physical destruction but, "to inflict lasting damage on the petrochemical companies and send a political message."

> "You know what I've noticed? Nobody panics when things go 'according to plan.' Even if the plan is horrifying!" - Joker from the Dark Knight

We mostly expect this type of nomination from Trump. But as most of the anti-Obama comments state, we were fooled into expecting more from him. Obama pretended to be different, which made his sameness all the more stark and disappointing.

And this is why we have fallen so far. Partisan blame is fine for the campaign trail, but as soon as the president takes office he becomes the adult and the responsibility for starting, continuing, or stopping activities falls on him and his administration.

Bush oversaw extra-legal interrogation methods. Obama oversaw a massive increase in extra-legal assassinations by drone. Low-minded citizens can get trapped in the game by getting angry about "the other party" and its actions, or they can recognize that administrations and congressmen in both parties blame the other side for cover while simultaneously building off its precedents to expand their own power.

The meta-game at this point is open to just about any type of psychological trick. We know/suspect Kaspersky helping FSB/GRU, but we also know that CIA/NSA store and use fingerprints from other nation states and can assume Russia does the same. So if something looks Russian but Kaspersky reports on it, does that mean it is NSA trying to false flag Russia? Or is it Kaspersky deflecting Russian suspicions and pointing to the US by bringing it to light...6 years later?

The abilities and willingness of certain nation states to wage cyber warfare and make it appear like someone else are so great at this point, that only solid forensic evidence, and usually not even that, can be indicative.