HN user

josephkern

187 karma
Posts4
Comments97
View on HN

There is so much content on youtube, especially independent music, that it's often I find that I need to purposefully watch things I want to see more of instead of letting autoplay or autorecommend take over.

Purposeful searching and watching habits make youtube much more enjoyable for me.

Of course `Dead Internet Theory` might be true, or at least feel that way, if you let the algorithms drive.

The most interesting question is the one that cannot be answered in the context of this project.

How does decomposing and displaying my life in a database change who I am or who I want to be?

The quantitative display is interesting as well; there are multiple sources where this information could be gathered from by OEMs. It does make me wonder if someone is using Apple Health, Apple Credit Card, an iPhone, and using Apple Music if most of this information isn't already available and potentially displayed in a similar manner.

Apple of course is just used as an example.

Why are we discussing an article from 2017 with no real information besides, USA number 1?

Asymmetry is the key to airpower, if you don't have it you won't have it.

Look-first shoot-first is only one kind of asymmetric advantage.

Eagle Cash 6 years ago

Wait until you guys see the prices for the "AAFES POGS" on ebay ...

Basically while you can use cash, coins are too heavy to justify shipping into country. AAFES instead prints "gift certificates" in the shape of a pog, in 0.05, 0.10, 0.25 denominations.

The resale value on these is hilariously high ... these are federally issued mediums of exchange being currency except in name only. And only useable in deployed locations.

You should consider setting up a well known and repeatable folder structure for your email inbox.

You will need to file everything into a phonetically distinct structure for efficient navigation through your folder hierarchy. Nested directories in this case is not a bad idea.

I have seen this type of structure used very efficiently with a screen reader and Outlook in person.

The question becomes what did MGS:V get correct? Even in an unfinished state I have been judging every game I've played since by comparison.

I think it breaks down into a few categories;

1. Excellent controls. Probably the tightest and least obtrusive controls I've used in a long time.

2. Great characters. While the story itself isn't that great (because it's unfinished), the characters really drive the plot.

3. Amazing ambiance. I really felt that I was in Afghanistan and there were Russians I was trying to avoid. I eavesdrop on their conversations, hearing them yelling orders to each other, and even see them adapting to my tactics between missions.

What makes this game a great single player campaign is ... Weight. Everything has consequences because you care about the characters. Most AAA games don't have characters anyone remembers or cares about.

The C Programming Language, Second Edition; Ritchie and Kernighan; has end of section and end of chapter problems that are pretty good. Especially if you want to learn C.

Not at all really. It's not about the technology, it's about the process. A pentest will (or at least should) determine if you shipped a "secure" product. This company (if it's serious about pentesting all their projects) will assign some kind of risk factor to the website you've built. Information Security is all about identifying risk (at all levels) and mitigating or accepting those risks.

In the case of a an Amazon S3 bucket, I would think the following items should be enumerated in a pentest:

  1. Leaking information via DNS
  2. Secure hosting for DNS records
  3. Secure passwords on your AWS account
  4. Proper permissions set on your bucket
  5. Multiple AWS availability zones
  6. Javascript libraries used are functionally correct
  7. No inclusion of any backdoor features by the developers ;-)
This is more of an audit than a pentest. But sometimes a company will only have peace of mind if they base their measurements off of an established internal process. Even if the tests don't seem to make sense for the technology or implementation they will make sense when it comes to identifying risk metrics across all of their web facing products.

This is a really interesting argument, I had it in my head to disprove your thesis. But the more I thought about it the more I agree with you.

I feel somehow though that the line between functional and non-functional requirements are not as well defined when dealing with user data. There is an expectation (even if unrealistic) that the confidentiality, availability, and integrity of the user data will be preserved. Twitter though can serve as a counterpoint to part of this argument (availability).

Are there examples of a successful MVPs that dealt with user data and failed the confidentiality or integrity requirements?

To replace it you might need Kahn Academy, 2 years in the army, Tinder and some sort of coming of age ceremony with body paint and singing.

Well the army has both body paint and singing ... I digress.

I've started the Georgia Tech online masters in computer science (OMCS), and I must say that I am impressed. Do I think that a non-college entity could do the same work? Possibly.

I started the OMCS program because I had been trying to "learn computer science" on my own, I realized that I didn't have the rigor in my self-study that I needed. This lack of rigor really drove me to search out (and thankfully find) an appropriate program of study that I could pursue on my own time (and fit within a reasonable budget).

Yes! You are a manager first. Your job is to direct the actions of the team, your technical expertise needs to only go far enough so you do not commit your team to a death march.

Even worse if you use your position to cherry-pick projects away from your team because they "sound fun". Talk about a morale buster.