HN user

jpleger

1,844 karma

Security nerd. Father.

Posts0
Comments19
View on HN
No posts found.

The really awesome thing about these being in simple reference designs, is how easy it is to swap out things like that. I really like how they have things laid out, and will be using this as a reference for jr. folks on how to lay out logical blocks in KiCad.

I have often thought how awesome it would be to have a bunch of proven / validated / supported open source blocks for common things like power supplies, sensors, etc. I think that at some point digikey or someone had a modular board that you could mix and match stuff into a reference design, but I can't remember the details.

K, but if these are experts that literally do not exist in the US, why are the salaries not higher than median? It wasn't meant to fill junior level positions.

This program was meant to allow talent that is not available in the US, so that gaps could be filled with experts from overseas.

Things feel like the 2008/2009 time period for hiring, but stock valuations and earnings are still extremely high, which is kinda odd. It feels so strange right now for employment prospects.

I don’t know if anyone else feels it, but the constant under resourcing and do more with less mindset since 2021/2022 have probably made things worse too.

This year, I started actively day trading S&P 500 because of all the volatility. Maybe its biased because I have been staring at charts more diligently than in the past, but IMHO you can almost feel the tension in the charts right now.

2023/2024 would have small swings of like $2-$4, with $5-10 movements on a maybe 1 out of 20 days. Since Trump took office, it has been almost daily $6-$10 moves, with the rare day of only $3-$5.

Its great for day trading, but I don't know how I feel about it in general. I almost feel like this is the oscillation before the car starts to shake itself apart.

CVE Foundation 1 year ago

Hahaha, CVE was created because industry refused to track and report on things in a consistent and transparent manner. When given the option, business will almost always choose the easy path, and things like vulnerability management programs will be set back years if not decades when the external accountability goes away.

In general, lawyers and CTOs would probably love to see CVE go away or be taken over by industry.

Source: been working in security for 20+ years.

Makes me remember some of the days I had in my career. There were a couple really interesting datacenter things I learned by having to deploy tens of thousands of servers in the 2003-2010 timeframe.

Cable management and standardization was extremely important (like you couldn't get by with shitty practices). At one place where we were deploying hundreds of servers per week, we had a menu of what ops people could choose if the server was different than one of the major clusters. We essentially had 2 chassis options, big disk servers which were 2u or 1u pizza boxes. You then could select 9/36/146gb SCSI drives. Everything was dual processor with the same processors and we basically had the bottom of the rack with about 10x 2u boxes and then the rest was filled with 20 or more 1u boxes.

If I remember correctly we had gotten such an awesome deal on the price for power, because we used facility racks in the cage or something, since I think they threw in the first 2x 30 amp (240v) circuits for free when you used their racks. IIRC we had a 10 year deal on that and there was no metering on them, so we just packed each rack as much as we could. We would put 2x 30s on one side and 2x 20s on another side. I have to think that the DC was barely breaking even because of how much heat we put out and power consumption. Maybe they were making up for it in connection / peering fees.

I can't remember the details, will have to check with one of my friends that worked there around that time.

What are you talking about? TCP/IP hasn't changed in the last 20 years... like, at all.

There might be best practices which have changed around NAT, software defined networking and load balancing, but it's all on top of existing protocols.

If you are talking about subnetting practices, it has always been an operational thing... that's not what these books are talking about.

Also, I haven't looked at the Fairphone5, but they are 99% likely going to be using a qualcomm, mediatek or broadcomm modem, which is a black box and are some of the most vulnerable components of modern smartphones.

I worked on a large scale project that was itanium based and let me tell you, the compilers / software toolchains were an absolute dumpster fire. We were planning on being between 500 and 2000 processors in our cluster.

We used HP boxes and I want to say it was around 2002/2003 when this was going on. We were supposed to be a huge public showpiece client for both intel and HP. It… did not go very well. I remember the absolute defeated looks of the HP / Intel people when we pulled the plug and told them the discounts / free hardware still couldn’t justify the engineering efforts we had gone through for the last 18-24 months. This was right as opterons were coming out and that project jumped ship to them.

I think one of the primary reasons that it is such a dumpster fire is there traditionally hasn't been an "open" ecosystem in the hardware world, though now they are being forced towards that direction kicking and screaming.

Every part of the hardware ecosystem has traditionally been done in closed, NDA ridden environments and only over the last 5-10 years has that even started to change.

Designing chips has required NDA-based PDKs. Designing complex PCBs has required closed-source EDA tools. Interacting with any of the IC peripherals often requires binary or non-redistributable firmware.

Hell, even with the modern "open" switch architectures, like Trident3, you can't get software or detailed datasheets from broadcom without an NDA. Same thing with some of the ARM based stuff like with the Raspberry Pi.

Just curious, where aren’t they complying with the ISA? I know they use a couple registers in specific ways, but IIRC, the way they use it was left to the implementer so they aren’t diverging from the architecture.

Are you me?! This basically was my experience working for a very large school district in the early 2000's. My favorite was they asked me to train a school bus driver to be the newest member of the IT staff because "they wanted to learn computers", it also just so happened that this person was the only person their budget could afford (less than 40k/year).

I worked for them as a contractor for a while and one of the big issues they had was they had tons of money to implement new technology (mostly from grants and things like that), but nearly nothing to maintain old tech. They could buy new computers all day long, but if something needed to be repaired/updated/maintained, there was no budget or resources to do it. So there were all sorts of fun issues, like they would buy computers and before they could get deployed their warranty would expire (since they weren't allowed to buy 3 year warranties on the computers) and computers with bad HDDs would get disposed of, even though the fix might be $50 and 10 minutes of time.

Well, its the truth.

You don't have to be a rocket scientist or have a PHD in supply chains to understand there are second/third order consequences by cancelling significant amounts of your forecasted production and then expecting your suppliers to magically pick up where you left off.

Its why you keep production/manufacturing warm rather than do stops (which is what they essentially forced their suppliers to do by cancelling purchases).

This is BCP 101 and I give the auto industry no sympathy since most of this pain was entirely self inflicted. They tried to push all the risk to their suppliers, left them holding the bag and had a shocked Pikachu face when they couldn't ramp back up to prior levels.

This also looks like they are comparing running Windows versions of software to the OSX version of the software on M1.

So there are 2 MAJOR variables, which they combined... performance of OSX vs Windows and performance of M1 vs i7.

IMHO this benchmark doesn't mean anything just based on that alone.

To accurately compare, they need to run the benchmarks on same processors on Windows vs. OSX to establish the OS performance. Once that is done, you can infer performance between the M1 and current gen mobile i7 processors.

To be honest, this is the reactionary responses that you would expect from someone who is extremely behind. The other thing that is really important to keep in mind is how long and how well established x86 has been for desktops. Apps/frameworks/compilers have definitely optimized for this wherever possible and only in the last few years has ARM has been picking up critical mass for desktops/laptops. Sure over there have been tons of phones/tablets but there haven't been many daily drivers.