HN user

jtheory

2,034 karma

@ founda.com

email: hackernews@[MY USERNAME].com location: Le Chalard (rural central France), or Amsterdam, or Kuala Lumpur.

Posts13
Comments1,216
View on HN
Passport Photos 2 years ago

I especially appreciate this on the assumption that it will be pulled in as input for AI training.

Nah.

Java applets involved running an actual JVM on every client computer, which meant basically doubling the risk surface of the browser... plus you had a completely different UI (that couldn't match the browser UI) sitting inside a web page.

I confess I wrote a bunch of Java applets back in the day; but I can't say I'm surprised they died, and I don't think they'll be back.

100% yes.

It's also about the entire internet & its users, not just threat models on specific sites.

We can't ask the general public to consider threat models and evaluate what sites should need HTTPS or just HTTP. General, non-technical intuition is basically useless for this eval; it's not a good path.

It's much smarter to just make HTTPS the default, make it easy & free for any site to provide it, and then let browsers show big warnings for any site that's not secured.

(Browsers are moving this way already)

I did not get the sense that this is a balanced perspective.

The author does have a point that not sterilizing your pet will likely lead to criticism, even though it's a more nuanced situation.

But still — the solution to all of the sourcing problems is "do your research, and get an individual, not a breed".

If there's an actual shortage of adoptable dogs in your area, talk to the shelters about it, and also consider _not getting a pet quite yet_, rather then taking random advice from the internet and telling people to breed their pets.

Personally I'm in France: much less neutering here, but also there's a serious feral cat problem in my village, and also too many puppies. And toxoplasmosis infection rates are massive... it seems like a much more obvious choice to sterilize free-roaming pets, but still many don't.

Both using LetsEncrypt.

A few maybe-useful thoughts:

* setting up LE & an auto-renewing cert isn't too hard, and it feels smarter than paying for a cert the old way, but if you're super-busy with everything else, it may not be worth it, yet.

* setting up LE in a rush is bad. You'll make some minor error, you won't double-check in 3 months that yes, the renewal happened, and you will find out that your site has been hacked from your customers or potential customers (except that no, it hasn't been hacked)

* whether you buy a 2 year cert ("now I have 2 years to set up LE") or do set up LE, sign up for SSL cert monitoring. You can have something like DownNotifier.com ping you directly in Slack when expiration is coming up.

Patients Know Best, REMOTE-only (no physical office). Full-time, with occasional exceptions. Core working hours: within a few hours of GMT -- current IRL span: Costa Rica to Bangalore, sometimes a bit further: I'm currently working from Kuala Lumpur for a month while visiting in-laws.

I post on HN sometimes about work-life balance (more than half of our dev team have small kids), building something that improves life/health, and our culture (collaboration and good communication over competition).

Superb communication skills required -- we all need to be highly articulate, clear, and at ease talking through complicated concepts with each other. Sometimes remote work tools are (nearly) flawless, but with some bad luck you might be explaining something complicated over a choppy connection with a punishing 3-second delay and a marching band in the background.

Skills talking with strangers: useful, but not an everyday requirement.

If you're interested in PKB's growth, funding, profitability, contracts, etc., ask -- our CEO is also active on HN. Or Google us. I'm in the CTO role.

We're hiring on & off in different dev roles, and I'm a bit ashamed to admit that our response rate to CVs is unimpressive; but if you're interested and not in a rush, it's a good idea to get a CV and intro letter into our inbox, and we scan through them periodically. Note that of the positions currently listed, at the moment we're probably looking more for mid-level full-stack engineers than any of the others; our stack is principally Java (8)/JEE-based. We use Docker in production and dev environments, Prometheus for stats.

Bonus points (all positions) for experience in the medical world (as an intelligent patient counts!), as well as some history building things from scratch.

More details (and to submit an application): https://www.patientsknowbest.com/careers.html

This is the reason.

It's abstractly difficult to inform a person that their close family member has died, potentially from violent causes, possibly very suddenly.

But come down this hallway, now, to tell this woman that her child is dead; this is what it will be like. You'll need to change your clothes first; you'll need to practice first; and this is what it will do to her, and what it will do to you.

I (obviously) found this very powerful, and while there's some compromise involved in adding in these carefully-selected specifics, it's worth it.

Hi Emil, apologies, we're due for another dive into applications. We do try to reply to everyone, but at present we're small enough (and busy enough) that we run through applications in cycles... so there can be a significant delay.

I'll try to review yours tomorrow to at least get you an initial response.

For anyone else applying - if you have a time constraint (like "I think we'd really work well together, but I need to have a job lined up in the next 2 weeks") then you can contact me directly at cto@ (company domain).

Patients Know Best, REMOTE-only. Full-time, with occasional exceptions. Core working hours: within a few hours of GMT (current IRL span: Costa Rica to Bangalore).

See my other posts for more depth on work-life balance (& hiring working parents = many of us), building something that improves life/health, our culture (collaboration and good communication, not competition).

Superb communication skills required -- we all need to be highly articulate, clear, and at ease talking through complicated concepts with each other (skills talking with strangers: useful, but not an everyday requirement). Sometimes remote work tools are (nearly) flawless, but with some bad luck you might be explaining something complicated over a choppy connection with a punishing 3-second delay and a marching band in the background.

If you're interested in PKB's growth, funding, profitability, contracts, etc., ask -- our CEO is also active on HN. Or Google us. I'm in the CTO role.

We're hiring on & off -- currently we're on hold for full-stack devs; but our lead frontend engineer is going to be motorcycling up the South American coastline in a few months, so we need to hire someone with a front-end focus. We need: solid JavaScript skills and you know, the normal front-end skillset; a little behind the times because we need to support IE8+.

Bonus points for JSP experience (the backend is pretty solidly Java-based at present), HighCharts. We're in PoC stage for front ends that build on our REST API (to escape the Java-based stuff entirely).

Bonus points (all positions) for experience in the medical world (as an intelligent patient counts!), as well as some history building things from scratch.

More details (and to submit an application): https://www.patientsknowbest.com/careers.html

I started writing Java with no IDE; and mostly just used * imports; that worked pretty well (and I don't remember it being a headache at all). In IDE land (since, uh, I guess the first I used was called Roaster) automatic imports meant I could always use specific imports, which is a tiny bit better in my mind, but not worth ever doing it manually.

Un-Facebooked 10 years ago

I have no trouble believing this of Facebook; that said, I find it frustrating that he could very easily be seriously misrepresenting what triggered this block, and still be "honest" about this report. More direct quotes from his posting history would help a lot.

Note that Facebook isn't saying they blocked him for that most recent post; more likely that something in that comment triggered a human review of his history, and that review concluded that he should be blocked.

Now he's asking us to evaluate that review (ok, good) and consider the repercussions of Facebook's overagressive filtering on free speech (sure) but this is very hard with only a 2-line summary of what he posts about in his account, and no direct quotes.

I do think this is a likely a completely legit complaint; but it's still very open to the risk that his style of posting was much more noxious than he represents.

(Alt: maybe if he posts too much detail, then the conversation veers into discussing those details rather than the free speech issue, which is more important than his single case).

This is how my wife & I moved to France, in 2006; we each got a "Titre de sejour", a 1-year, renewable, long-stay visitor visa.

It's not a regular tourist visa (and in fact if you're in France as a regular visitor/tourist you'll have to leave to apply for a titre de sejour). We needed to prove that we had housing arranged, means to support ourselves (savings plus income coming from outside of France... telework for companies in the US, in my case), and expat medical insurance.

Then we could stay for a year. We renewed this for 5 years and then were automatically upgraded to residence permits (with the right to work in France, actually).

--

Edit: somewhere along the way I was checking if some other European countries had similar options -- I remember it wasn't an option in most (it's not allowed in the UK. I think Germany wasn't okay either... forget where else I checked).

Ireland had some options around retiring in Ireland that seemed like they might apply for teleworkers, but I haven't checked into it properly yet.

It's worth emphasizing... the paper trail must show you're doing everything you can to warn the company that this project is currently on track to fail, and (as much as you can illuminate it) what the costs to the company will be.

Back up your reasoning as clearly and simply as you can.

From the perspective of your employers: because they're paying your salary (and others as well, including half your boss' salary dedicated to this), for a failed end result -- firing you as the scapegoat doesn't leave them with nothing, it leaves them with far less than nothing; all of that time and salary lost, plus the costs of replacing you (whether because they've fired you, or because they've burned you out entirely). Plus costs to reputation, which harms client relationships and hiring both.

Being able to say "I told you so" later doesn't really help anyone; but if you can suggest a better path (drastically reducing scope, extending or segmenting the delivery timeline, or even canceling the project), then you should be able to get someone to listen.

If your boss really grasps where things are going (and that this isn't just "the usual developer griping"), then he'll get credit as well for saving the situation, and you both benefit.

Blue. No, Yellow 10 years ago

I do think "they" will prevail, certainly more easily than than xe or thon or other invented options. So I actually use it, though there's still a part of my brain that flashes a red light each time, and I have to consciously ignore that.

I do think using "she" as the hypothetical example for roles people think of as male is still useful; it hopefully makes people question their knee-jerk response a bit.

Blue. No, Yellow 10 years ago

It's just an alternative to using "he" (or "they", which still feels a bit awkward) to describe a hypothetical person. Either flip a coin to choose their gender, or always use "she" to counter-balance (a little) all the times writers default to "he".

Scala Native 10 years ago

A few different people are trying to politely show you a way you're undercutting yourself.

Is this something only for people who want to start writing, and need to start building the habit to put in time every day? Or can it also be useful for people who already write?

The main issue that pops out to me is that people who write have projects (sometimes several, sometimes massive ones), and "writing" daily sometimes means much more editing/cutting than writing fresh text (I'm married to a novelist; her first book lost about five hundred pages between the first "completed" draft and the final result). Or -- writing may mean composing new text, but it's placed somewhere in a much larger work.

Last thought! Be very careful about having ability to export from the start, and be very sure you don't run out of time / hosting fees / whatever and let it die with anyone's work trapped in it.

Yes, but if they're already downloaded the last decade of your email history... well, I'm not sure how much it helps that you're blocking them from further access. What if they start emailing "helpful" links, invitations, whatever to everyone in your contact list? What if they are rather less strict about how they secure their (your) data, and they're employees spend lunch breaks poking around for public figures who might have interesting histories?

These sharing mistakes are hugely easy to make, and sometimes have unpleasant consequences even with no malice intended on the app company's side.

Someone in our company tried out do.com several months ago, and granted it access to our company directory in Google along the way. We didn't end up using the service; but unfortunately after a while of inactivity they started sending "invitation" emails to not just users on our own domain, but also Google Groups we have set up... some of which include customers of ours who were not at all amused to see that (it appeared) we had exposed their addresses to some random 3rd party without permission.

Apologies all around, of course, but these days it's simply hard to be paranoid enough about this sort of thing. Gmail & Google Apps have tons of useful apps you can add with a few clicks; but what are you actually risking, using them?

Note to self: if I renounce my US citizenship, do NOT check the box saying "I'm doing this for tax reasons".

Seriously, this is apparently real law, but according to a "citation needed" bit in wikipedia, has never been enforced.

The 1996 law included a provision to bar entry to any individual "who officially renounces United States citizenship and who is determined by the Attorney General to have renounced United States citizenship for the purpose of avoiding taxation by the United States."[47] There is no known case of this provision, known as the Reed Amendment, having ever been enforced.[citation needed]

What's your reasoning here, actually?

There are still fairly few expats who go to the trouble to renounce their citizenship... so "good riddance" to them?

It's perhaps worth pointing out that these are people who've already left, some of them decades earlier, who hung onto their US citizenship possibly because it's been easier than the alternatives (I can tell you getting citizenship in, e.g., France, is non-trivial, particularly if you're not married to a citizen, but even so if you are).

But now, for this little slice of expats, keeping US citizenship has become the more onerous option, and so they have a pragmatic reason to drop their old citizenship in a country they no longer inhabit, anyway. What's to get worked up about, really?

How many common "first instruments" are there for kids? Maybe 5? There's a pretty good chance you'll get it right without doing any research whatsoever.

It's not quite as bad as asking "what species was your first pet?" but not much better.

This is the real problem with security questions; the answer space is often so very small, and can be narrowed down even further with a little research.

Questions like "what was the first name of (your maternal grandmother, your first best friend, etc.)" are very common -- well, there are stats on most popular first names of given generations in different places. If you know what country the person is in, you can make a good guess at these.

they're proposing using UTC everywhere which is what lots of people already do.

"A lot of people"? I use UTC for a lot of things, because I'm writing code.

But when I travel, I certainly don't use UTC everywhere; my phone shows me the time for "Roaming" and "Home", and that's incredibly useful for me to guess at e.g., what time to break for lunch, when we're nearing close of business hours, when I ought to get to bed so that I get a good night's sleep, etc..

I suppose the really crucial "standard" we're talking about is the associations we have with different times, and timezones are the (official) attempt to keep that meaning consistent around the world.

I doubt it'll work -- partly just because to make this shift:

-- everyone who operates mostly locally would have to relearn those time meanings (all except the English... Hmm; why are they the only ones who don't have to suffer? Perhaps the new "fixed" time should be based on the most populous time zone)

-- everyone who switches time zones regularly will have to learn a new set of time meanings for every zone they travel to.

To be sure, the second set of people have it hardest (until the phone apps catch up and provide that info automatically). But the first group of people -- the vast majority -- will make sure this doesn't happen easily.

Eh, they really don't work well for cleaning the ear canal, though.

I have ear canals that I thought needed to be cleaned regularly, until I stopped using Q-tips. Now they only seem to need to be cleaned once every 4 years or so (if I notice sound getting a bit muffled), with a syringe and sink full of warm water. I had thought the Q-tips were cleaning them, but were definitely causing more problems than they solved. (Ditto for ear drops, which didn't seem to help much. Just taking the time with a syringe & warm water is better).

My pediatrician uses little metal tools to clean out the kids' ears if needed. Better than a blunt, soft thing that can't easily get wax out rather than push it in, though of course you'd better hold still.

Rate limiting per-IP assumes an attack from a single IP, or a very small range of them (so, only defends against a trivial DoS, not DDos... which are sadly easy to set up these days).

Per-IP per-account as well doesn't work if the attacker has a large list of usernames. Even brute-force "dictionary" attacks can dodge simple limiters by submitting one password with 2 million diff usernames, then a second password with 2 million usernames, etc..

I'm not saying these are bad (though if someone can trivially stop your real users from signing in by hitting the limit on their accounts, that's just a DoS in another shape). But we're agreed already... these are non-simple problems, really.

One thing I wonder about, as password hashes get both processor and memory-hard -- are we presenting a trivial DoS attack on our servers, by basically letting any IP submit a request for a server to dedicate this (non-trivial) level of RAM and processor to a given task (hashing a random string to verify that this login is not correct)?

I suppose the answer is yes, but it's worth it. It's possible to fix this sort of hole (partially, at least) by capping the number of hashes processed concurrently. But most simple implementations will just assume "we're not likely to have more than X users every signing in concurrently, so we can set the work factors based on that plus some headrooom".