HN user

larkinrichards

715 karma

you can find me at http://pete-richards.com/

Sometimes I perform experiments to measure the intelligence of internet commenters.

Posts25
Comments87
View on HN
pmc.ncbi.nlm.nih.gov 7mo ago

A Statistical Error in Estimation of Recommended Dietary Allowance for Vitamin D

larkinrichards
6pts1
nvd.nist.gov 11mo ago

CVE-2025-8901: OOB write in Chrome

larkinrichards
3pts0
www.wsj.com 2y ago

The World Excel Championships

larkinrichards
2pts0
forum.gitlab.com 4y ago

Gitlab CVE-2021-22205: RCE by unauthenticated curl -F

larkinrichards
1pts0
support.google.com 4y ago

Security Update for Google Drive

larkinrichards
3pts0
onlinedomain.com 6y ago

ICANN and Verisign agree to .com price increase

larkinrichards
1pts0
opensource.googleblog.com 7y ago

Bringing the best of open source to Google Cloud customers

larkinrichards
6pts2
github.com 8y ago

Simple formulation of the fine structure constant

larkinrichards
2pts0
edwardtufte.github.io 10y ago

Tufte CSS

larkinrichards
169pts26
www.southwest.com 10y ago

Technology-related Delays

larkinrichards
1pts0
google-opensource.blogspot.com 11y ago

How to format Python code without really trying

larkinrichards
4pts0
medium.com 11y ago

Why the Company’s Success Should Be Your Focus

larkinrichards
1pts0
blog.stubhub.com 11y ago

Staging or production stubhub?

larkinrichards
1pts0
www.slate.com 12y ago

How Long Could You Endure the World's Quietest Place?

larkinrichards
2pts1
pete-richards.com 12y ago

Configuring a Static Asset Pipeline with Django and Heroku

larkinrichards
1pts0
google-opensource.blogspot.com 12y ago

Introducing Farmhash

larkinrichards
1pts0
admitted.ly 12y ago

Admittedly is down (matching game for downtime)

larkinrichards
1pts0
techcrunch.com 12y ago

Chute (YC W12) Rights

larkinrichards
4pts0
developers.facebook.com 12y ago

Facebook Apps Disabled

larkinrichards
5pts1
jcs.biologists.org 13y ago

The importance of stupidity in scientific research (2008)

larkinrichards
2pts0
reillybrennan.com 13y ago

Rebuilding the pitch deck for the Pocket

larkinrichards
22pts9
www.nothingbutnext.com 13y ago

Yes, and Listen to Your Gut

larkinrichards
1pts0
www.nothingbutnext.com 13y ago

Nothing but Next

larkinrichards
1pts0
refer.ly 13y ago

Configuring A Static Asset Pipeline With Django And Heroku

larkinrichards
24pts6
refer.ly 13y ago

DIY Sous-vide

larkinrichards
4pts0

How do you define "minor accident" -- perhaps it was a "minor" accident because no one was injured and no other party was involved?

Last time I bought a car, I found the one I wanted with the note that it had been in a minor accident. I paid for the carfax, and learned that it had some damage and repairs, and had somehow traveled across the country in the process. Limited details, except, the accident had occurred in Florida. $10 later I had the police report. It was a 4wd car and suffered 2 broken axles & broken drive train. not minor in any way.

Article says "photos of the damage made it look more than minor"

Sounds like buyer was scammed.

The term "salvage" was a complete shock, but a deeper dive into the CARFAX vehicle history report, which he didn't pull until after the sale, uncovered a "minor accident."

Photos of the damage made it look more than minor, and a Tesla technician told him the repair work as shoddy.

Find SF parking cops 10 months ago

offline now. It's a reasonable to expect that this information should not be available in real time to protect parking officers. It's already published daily, as mentioned in other comments.

Find SF parking cops 10 months ago

there is -- https://data.sfgov.org/City-Infrastructure/Map-of-Street-Swe...

"undergoing maintenance" but spot check of data looks correct to me.

Street cleaning tickets are given efficiently and enforcement is conducted to minimize the time that people can't park. 2-4 parking officers drive in front of the street cleaning vehicles and ticket everyone parked. if you're watching at the time you'll see almost every car on the street pull out in front of the officers, circle the block and park right back in the same -- but now clean -- spot. those that don't get tickets.

Exploit chain--

1. zendesk allows you to add users to a support issue and view the complete issue history by sending a response email to a guessable support email from a person associated with an issue and cc'ing the person to add.

2. Zen desk depends on a spam check for inbound email validity. This check does not appear to catch instances where sender email is spoofed. Zendesk claims this is bdue to DKIM/SPF/DMARC config but I have trouble imagining that 50% of Fortune 500 would get this wrong. There are many automated checks available.

3) Apple issues an Apple ID account to anyone who can receive a verification email Sent to the mailing address (support@company.com)

4) Slack allows you to sign in to a workspace using any Apple ID associated with the workspace domain (e.g. support@company.com)

This researcher reported #2 to hackerone and was declined. Researcher later discovered full exploit with 3 and 4. Did not update hackerone, contacted affected companies directly.

it would have been prudent to update hackerone on the additional finding, but it feels like an easy oversight for a 15 year old after getting rejected on the first round.

Zendesk should take the higher ground and recognize the mistake and correct it. Not get all "ethical mumbo jumbo."

Based on the Oct 12 change log, "changed flight 4 to "starship super heavy" -- this reads that they can perform multiple flights with the same mission profile. So they can do a few quick test catches and avoid relicensing?

unlikely. They'd already created the prototype decks. They had the fabrication know-how in house. Sure they have in house VFX experience, but rigging the scene and trying to match lighting to reality and ultimately disappointing customers? It's a no brainer to use the real deal when you can.

Many would hire an agency to create an ad for you but that would 10x the cost, not to mention dealing with the opinions of an outsourced creative director...

Insufficient sample size to support this article.

Cruise can only operate in a small region between 10pm and 5:30 am when bus service is limited and there will be few interactions to report.

Waymo rides are still significantly limited. No clear data on service rates or range.

All other programs have a safety driver in the car who is able to quickly react and prevent reports of an incident.

My best friends are those I play catan with regularly. There is no other game so enjoyable, which can inspire such anger towards friends for their transgressions, yet allow such easy forgiveness. Rest in peace, Klaus.

How can I protect myself? For full details scroll down to the end of the article. Summary: Whenever you open a link from Instagram (or Facebook or Messenger), make sure to click the dots in the corner to open the page in Safari instead.

“How do I protect myself?” should be point number one.

Does apple require that developers allow users to open these links in safari—- w/o tracking? Or do developers feel this is the only moral way they can agree to this user-hostile behavior?

I joke with my friend: “I can build it myself for more!” And true, some projects cost more than buying it from a store… but the experience is worth it, and usually the end product is better than what you can get from a store.

during a delivery once, i caught a curb, flipped upside down on a bicycle, landed laptop down, bent the frame of my 2014 macbook pro, and the screen survived undamaged. still using the same laptop today, no issue. anecdotal evidence… is anecdotal.

GitHub Copilot 5 years ago

If your house doesn’t have fire proofing (Sheetrock / lathe & plaster) then you know what’s inside the walls.

I spend many hours of each day ~programming~ wrangling text files and I use macos + zsh + textmate2 for my daily drivers. I see shell as an important proficiency because it helps maintain a lower-level understanding of how the "magical" GUI "works," which often helps in debugging obtuse errors, and I'm sad to encounter more engineers who are completely unfamiliar with it.

When it comes to examples like that posted by the OP, I like the combination of piping/pasting to mate and multi-caret editing for most scenarios where others would reach for awk/xargs.

Here's me following the same example scenario but with multi-caret editing (slowed down slightly):

https://user-images.githubusercontent.com/226503/101993951-6...

Step by step:

  1. git status -s | mate
  2. select " D" with arrow keys + shift
  3. command-E macos default for "use selection to find"
  4. option-command-F to find all (multi-caret editing starts)
  5. type "git checkout" to replace " D"
  6. command-left to move cursor to start of line, then shift-command-right to select to end of line.
  7. copy
  8. select all + delete (clear document)
  9. paste, 
  10. press return to insert newlines
  11. select all + copy
  12. switch back to terminal
  13. paste
To me, this is many small steps, but each step is more mechanical and flows naturally, and the general flexibility of multi-caret editing means it is applicable more often in my daily work.