HN user

laurencei

1,745 karma

Always working on a few things here and there :)

Posts33
Comments256
View on HN
www.smh.com.au 3y ago

‘Immense harm’: Medibank confirms hackers have stolen customer data

laurencei
5pts3
www.unrealengine.com 4y ago

Unreal Engine 5 is now available

laurencei
328pts158
www.smh.com.au 7y ago

Samsung phone users get a shock: They can't delete Facebook

laurencei
36pts13
laracasts.com 9y ago

Learn Vue 2: Step by Step (free series)

laurencei
2pts0
news.ycombinator.com 10y ago

Ask HN: Has anyone here successfully applied to Stripe Atlas?

laurencei
10pts7
stripe.com 10y ago

Stripe BYOT (Bring Your Own Team)

laurencei
40pts16
www.itworld.com 10y ago

Newly found TrueCrypt flaw allows full system compromise

laurencei
19pts1
www.gchq.gov.uk 10y ago

A Christmas card with a cryptographic twist for charity

laurencei
3pts0
www.dailymail.co.uk 10y ago

Does Apple deliberately slow its old models before a new release?

laurencei
5pts0
www.news.com.au 10y ago

CIA Blames NSA Whistleblower Edward Snowden for Paris Attacks

laurencei
3pts0
mypropertytracker.com 11y ago

Show HN: My Property Tracker, with automated data entry

laurencei
39pts32
www.brisbanetimes.com.au 11y ago

Ebola Scare: Woman in Cairns (Australia) Hospital

laurencei
2pts0
eyewitness.io 11y ago

Show HN: Eyewitness.io – Monitoring for cron, queues and websites

laurencei
10pts2
www.smh.com.au 12y ago

Uber drivers issued $2500 fines

laurencei
2pts1
www.smh.com.au 12y ago

EBay initially believed user data was safe after cyber attack

laurencei
2pts0
www.smh.com.au 12y ago

Ride-sharing apps (i.e. Uber) ruled out in one state in Australia

laurencei
2pts0
news.ycombinator.com 13y ago

Show HN: Record your CSS usage on your website - remove unwanted CSS

laurencei
1pts0
news.ycombinator.com 13y ago

Show HN: Record your CSS usage on your website - remove unwanted CSS

laurencei
5pts1
www.tummy.com 13y ago

4.2.2.2: The Story Behind a DNS Legend

laurencei
2pts0
bugzilla.mozilla.org 13y ago

Firefox takes screenshots of your HTTPS data - Mozilla says thats ok

laurencei
14pts9
www.smh.com.au 13y ago

Telstra to clamp down on peer-to-peer

laurencei
4pts0
www.smh.com.au 13y ago

Rocket fail: Russia-launched satellite plunges into Pacific

laurencei
2pts0
www.smh.com.au 13y ago

Web start-up Path to pay $800k to settle privacy charges

laurencei
2pts1
www.smh.com.au 13y ago

Why you shouldn't work less

laurencei
1pts0
news.ycombinator.com 13y ago

Ask HN: Official source stating hash DB password requirement?

laurencei
5pts2
news.ycombinator.com 13y ago

Ask HN: Why is this "Ask HN: " not in the Ask HN section?

laurencei
2pts2
news.ycombinator.com 13y ago

Ask HN: Found someone building my SaaS idea, does that mean idea is validated?

laurencei
4pts11
math.stackexchange.com 13y ago

Real life-and-death issue that requires a mathematical solution

laurencei
9pts5
www.smh.com.au 13y ago

Android apps leaking personal, banking details

laurencei
1pts0
news.ycombinator.com 13y ago

Ask HN: Wide 'out of focus' landing page images?

laurencei
1pts3

I did something with my Bosch washing machine (not like the OP). My washing machine is at the other end of the house from my home office. Sometimes I would put a load of washing on, and despite setting an alarm, might forget (perhaps I am in an important meeting etc).

So I decided to solve it.

Using the Bosch API - I can tell both when a cycle is complete, and if the door is open. Currently I use their default version, but there is a local hosted option I'll be switching too now the proof of concept works.

So using Home Assistant I have a simple script that detects when a washing machine cycle is complete AND the door has NOT been opened. This implies my washing machine has wet clothes still in it.

So Home Assistant will alert my phone (and my wife only if she is home based upon presence detection) once every 15mins that there are wet clothes waiting in the washing machine.

Very simple - works perfectly.

Excluding the part of how the access was gained (i.e. fault of end user etc) - I would have thought Stripe would have far better security measures in place for obvious signs of fraud?

If someone changes the bank account of a business for funds to be sent to - why not have a short (?48 hours) delay in allowing funds to be sent there. Especially if the business has been running a while (not sure in this specific case) with no bank account changes - then its not unreasonable for a built in delay for new accounts to be used.

Coupled with some basic stuff of "new bank account, new express accounts, spike in charges, sudden request(s) for withdraws" seems like something that a smart team in Stripe with their development experience could easily implement as an automated security trigger, and hold the funds pending additional security checks?

"They might not have "known", but come on, you're selling radiation-hardened chips to NASA. "

But do people ever actually "invoice NASA" for components. It was probably one of 100 different sub contractors building the actual circuits to NASA specifications, i.e. it was lower in the chain rather than NASA itself.

(Doesnt excuse the non-disclosure to those subcontractors)

I'm not a machine learning person - so I'm confused about this.

As someone who doesnt understand ML - I have always assumed the whole point of ML is to try different things in the game, almost randomly, and over (long) periods of time the AI gets better and better at the game.

If having a single unexpected event causes such a large swing in outcome, and the AI cant "explain" what is different to cause the swing, then what exactly is the ML doing for it to fail on such a seemingly simple change? Doesnt that defeat the whole purpose of this?

I'm obviously missing something obvious - because I would assume the real goal of ML is that it can teach itself the game, even if that involves unexpected situations, as a human does?

What I find strange about this is you dont need it to be "deepfake".

Just an inside job.

If a large company allows a single employee to transfer millions to a new bank account/vendor that has no history, on "their belief" the instruction came from an approved person (i.e. their boss, CFO etc) - that company has major governance issues that are not related to deepfake.

Imagine the more simple scenario - an employee transfers millions, knowingly fraudulantly, to some people they are working with. They then simply supply some "deep fake" pictures and a story how it was an accident - and boom; you walk away with millions.

Checks and balances exist for many reasons - deepfake doesnt overcome those by itself. This company is just missing basic steps that would have protected itself here.

edit: in fact- its even more obviously some inside job; put the deepfake aside for a moment. How was the meeting even booked? Their PR person said "none of our internal systems were compromised". So this meeting magically appeared in someone's calendar? Using their internal video system (Skype or Teams or whatever). And the criminals knew to target this person, with enough knowledge of random office people to deep fake them? Come on...

I don't want music recommendations from something that can't appreciate or understand music. Human recommendations will always be better.

I find Spotify's "discover weekly" list to be generally pretty good. Sure, there are some songs I dont like, but there are often 3-4 great songs each week that get added to my regularly playlist.

Its all good an well to say that human recommendations are better, but I'm not paying someone $50 per week to spend 3-4 hours finding me new and good songs. I get something that is maybe 80% as good included, and the reality is that is good enough.

I feel like one of the reason AI is doing well is it doesnt need to be better, it just needs to be "good enough" at a fraction of the price..

We laugh as IT experts.

But think about it from the end user perspective. Literally the most simple instruction; near fault proof. On an airplane that is thousands of feet from remote IT support (plus "costs").

The instruction to staff; problem with "the Internet"? - press the "Interest Reset" button.

Far better than "router restart", "renew DHCP leases" or "reboot IT"

Explicit, non ambiguous and without technobabble.

Brilliant.

When attempting to login to your Microsoft account, instead of typing your password you can do an optional "one time password" generation thing from Microsoft. So instead of typing your password +2FA - they email you a 6 digit "one time password" that you can use instead.

You cant disable this.

So all Microsoft accounts could have a daily 1 in 1 million chance of been overtaken.

Odds are low - but if you then spam this across thousands of attempts per day - they would statisically "get lucky" from time to time...

Yeah - and what is crazy is when you think about it - Microsoft generates a 6 digit code.

So it is a "one in a million" to randomly guess what the code is on any given login.

But it is "one in a million" for each Microsoft account you know about - and if they have millions of email addresses, and automate it each day (I also get attempts 1-2 times per day).

Yes - the odds are small - but there is a greater than 0% chance someone can randomly get into your Microsoft account - and there is no way to stop it - even with 2FA etc - this bypasses all of that!!!

Crazy...

Doesnt that just mean you need to validate the source of the video? If LTT says to stay way from a product on the LTT main youtube channel - that would seem valid?

If the video was a re-post or hosted elsewhere - then you would start to reconsider it?

I love my LG TVs.

The problem is, for anyone who wants a smart TV, every brand is just as bad. Samsung, Sony etc.

I know some people say "get a dumb TV" and use chromecast etc - but I just want an all in one integration etc.

I suppose the risk is people could 'game' the system.

Person A finds the issue, reports it.

Then Person A secretly tells Person B about it (with no apparent connection), and Person B reports the same issues a few weeks later, but with apparent different code/description to look ever so slightly different.

At the risk of been downvoted: you cant. It is impossible.

Even if you had $30 billion, and your goal was to guarantee the distribution of only $1 to everyone, it still wouldnt occur with all the excess.

When you factor in corruption, fraud, inadequate infrastructure, and vague defining of the parameters.

Just think of the edge cases to understand why this couldnt be achieved:

1. A subset of the population will ACTIVELY reject your attempt to give them $1, as they will consider it spam, anti-god, conspiracy or one of hundreds of other reasons (look at recent world events to see that there is always a % of the pop on the other side)

2. A subset of the population will ACTIVELY attempt to fraud you for extra money. Claim multiple times, or claim on behalf of other people (their dead grandmother)

3. A subset of the population will ACTIVELY use corruption for extra money. Consider state actors such as North Korera, or third world countries with poor controls

I could go on - but those 3 reasons alone are enough edge cases to start with.

They have a sub-title in their article "Redefining the game engine – this is more than ads"

Then they go on to say "Advertising has long been and we believe will continue to be the economic engine for mobile games, driving players into their games and driving revenue at scale"

Then finally "It also reinforces our strong conviction in the long-term strength and growth of the in-game advertising business"

Seems like they are just doubling down on the ads in games mainstream...

Its funny though - because their mobile web interface is SOOOO bad, I'm using the "Apollo" app, which means I dont see any Reddit ads, and its a much better experience.

If they didnt have such a crappy web experience, I would probably just use the native web page and see some ads.

So its actually driving people away to alternatives that reduces their revenue. Crazy...

"I have noticed that as I build better landing pages for my MVPs I get judged more harshly"

Can I ask - why do you think you are building a "better" landing page? If you are getting judged more harshly, doesnt that mean your pages are not actually "better"? Maybe as you are building more pages, your subjective opinion of your own designs has changed....

I've seen it a few times on MVPs launched here. Some new YC company and their flashy homepage, but when I browse the homepage I have no idea what the company actually does. The pages are clean, but the actual idea is vague...

The problem is everyone has been burnt by this before. The moment you build a 3rd party solution, then they pull the API away from you 1-x years from now, your dead in the water. Thats not to say people wont give it a go, but I wonder how viable you can build an eco system onto of someone else's API?