HN user

lrpublic

98 karma
Posts3
Comments45
View on HN

Similar software with different usage models can be extremely useful and support mentoring and staff development.

I’ve been using tools like manictime and more recently the open source activitywatch to help junior staff learn how to manage their own activities.

I also use a paper based system similar to the emergent time tracker[3] for the same purpose.

The key difference in approach is these are tools are for the individual to use to record their own activities, either to later record in other tools like JIRA or simply to remember and review their work.

Time tracking and activity logging is really important for some businesses, but having a sensible approach from senior management is critical to avoid them becoming self defeating. When I ask my colleagues to log their time I set and expection that useful accuracy of more than 60% is unachievable.

Whenever a senior manager suggests that developers need to log more time in JIRA I tell them they are focused on the wrong data points and will end up with every developer logging a flat 8 hours a day - probably with an automated script. Maybe useful for billing but nothing else.

https://www.manictime.com/

https://github.com/ActivityWatch/activitywatch

[3] https://davidseah.com/node/the-emergent-task-timer/

- What do you think of breaking changes?

I think it is better to apologise and acknowledge for terms that are offensive rather than erase them.

While removing offensive 70’s TV comedy shows is probably a good thing to avoid perpetuating unhealthy stereotypes, preventing the use of 19th century literature is less helpful because we should not forget history.

True, but it is also true that slavery predates the colonisation of the Americas.

(British cultural reference - What have the Romans ever done for us? Monty Python. - https://m.youtube.com/watch?v=Y7tvauOJMHo )

But the issue at hand here is very important and should not be made lite of.

The first time I saw documentation guidelines was while working for a large US software house in the early 90’s. This was a marketing led initiative, along with very specific instructions about correct use of trademarks the guide was prescriptive about always using female pronouns.

Three decades later we still have significant gender bias in the industry but in my experience things have improved almost beyond recognition.

In that time, attitudes to race, gender and sexuality have advanced significantly in the US and European corporations. I still come across unacceptable attitudes and language, but open sexism, racism and anti semitism is almost non existent. Sadly this is not yet true in some of the emerging market countries I’ve worked in.

The use of language may or may not have contributed to this welcome change, but what was at the time called positive discrimination, a term that in itself is possibly no longer politically correct, did definitely draw attention to an issue that was otherwise not generally discussed at work.

The conversation about pronouns has moved on too.

My somewhat longwinded preamble does have a point, the language we use can make people think about issues they would not otherwise be aware of.

I don’t know if the terms master and servant are generally considered acceptable, my guess is master/slave is predominant because it is meaningful, short and easy to spell and in itself is not racist language.

I think that at least some of the corporate avalanche of support for the current protests is no less cynical and self serving than the political correctness in marketing of the early 90’s, but it will still result in positive change.

A customer is an external stakeholder.

Customers used to have more choice, this made them highly valued stakeholders.

Before the era of permanent rolling mandatory updates and new releases customers (And IT managers) had to be convinced a new version had more value than the software it was replacing.

Windows Vista, DOS 4 And numerous other software failed to get traction because the value of new features was too low vs the pain points.

Now days the focus is on shareholder value not customer needs.

Locking in customers and maximising revenue is far more important than marking software better for the end user or IT teams.

I’m sure I’m one of many people here searching for the ultimate keyboard.

I missed the kick starter for the Keyboardio Atreus.

I’m looking forward to the launch so I can order one retail.

In short it’s a split layout ortholinear similar to the Planck.

Two killer features for me are Bluetooth (and wired) and QMK firmware that allows layers.

https://shop.keyboard.io/

Out of band could be as simple as ngrok, or cloudflare Argo - or as you suggest by a separate connection.

SSH is two factor - key + password and Argo,ngrok,wireguard to a VPS provide DDoS mitigation and attack surface concealment and reduction.

I think I’m missing what your product adds.

With regard to Apple or Google recording the applications users install from the store I think there is indeed an opt in.

That is the comparison I was making with the new Windows package manager.

It's not opt-in, so quite likely a breach of GDPR.

The telemetry in question seems to be logging what is installed, not just how the application is used.

Regardless of consumers willingness to provide feedback it's not a reasonable choice for a large software vendor to collect data from customers computers about competitors products.

From NHS advice on vitamin D referenced in my previous comment

“Some people will not get enough vitamin D from sunlight because they have very little or no sunshine exposure.” .. “ If you have dark skin – for example you have an African, African-Caribbean or south Asian background – you may also not get enough vitamin D from sunlight.”

Updated NHS advice on vitamin D from [1]

“ Coronavirus update Consider taking 10 micrograms of vitamin D a day to keep your bones and muscles healthy.

This is because you may not be getting enough vitamin D from sunlight if you’re indoors most of the day.

There have been some news reports about vitamin D reducing the risk of coronavirus. However, there is no evidence that this is the case.”

[1] https://www.nhs.uk/conditions/vitamins-and-minerals/vitamin-...

- cost, as well evidenced in other comments here. The hyperscalers are orders of magnitude more expensive than dedicated hosting or using collocation providers.

- lock in, all the hyper scalers want to sell you value add services that make it hard or impossible to move away.

- concentration risk, hyper scale providers are a well understood target for malign actors. It’s true they are better protected than most.

- complexity, if you think about how little time the hyperscalers have been operating in comparison with corporate IT they have created huge technical debt in the race to match features.

A couple that I’ve built - they are not commercially available.

I’d consider open sourcing something based on them if there’s sufficient interest.

Perhaps as an integration for one of the major players.

Trusting a central control server is the fundamental mistake here.

It creates a very high value target that is difficult to secure.

I prefer a model where the management commands are signed at a management workstation and those commands are pushed by the server and authenticated at the managed node against a security policy.

I disagree, we don’t have opposing views.

I totally agree with you that the secure by default / sandboxes for application approach is useful for consumers and developers too.

My point is that when this is wrapped up with a closed software distribution platform (Windows Store / App Store) or with a Surveillance Capitalism business model that relies on monetisation of user data there is a problem for the consumer.

The PC accidentally contributed to breaking the control IBM had over the market.

Antitrust investigations into IBM and later Microsoft are also key to the freedom we’ve had. The worry is that we’ve forgotten how bad it was and we’re potentially headed for a cartel like control of our computers.

I thought that was about WordPerfect etc rather than NetWare.

Totally agree that Microsoft did some bad stuff, I just don’t remember there being any malign attempts to disrupt NetWare integration.

NetWare was the main player in PC networking at the time, so arguably it would not have been a good strategy.

It’s absolutely true that the NDS integration was an issue, but my memory is that this was a quality/competency issue on both sides, and not due to a lack of cooperation.

It’s well documented that Microsoft did not behave well in the 90’s https://en.m.wikipedia.org/wiki/Halloween_documents

However in the case of the Windows NT NetWare client I don’t think this happened.

I think one of the variations on Hanlons razor is a more likely explanation.

“You have attributed conditions to villainy that simply result from stupidity”

The really worrying thing is that all the major players seem to have the same strategy at the moment. That is to own and control the platform.

Yes, not unlike Apple and Microsoft but for business users of Google suite, this makes the need to sign up to any Microsoft cloud services less of a necessity.

It seems the direction Google, Apple and Microsoft are all heading in is to own authentication and control access to our computers both at work and home.

Third party authentication technology has been around on Windows in one form or another for decades, but this is interesting because it's cloud based authentication that doesn't rely on corporate infrastructure.

It would be really nice if Google releasing this is a catalyst for an Open Source project doing something similar.

Chromebooks, Windows S (and RT before it), notarization of apps on MacOs could be helpful in an Enterprise environment to prevent malware, this is at the expense of freedom of choice.

I worry that the PC era is ending and we're drifting towards a future market more like consoles and mainframes where you never really own the platform that you paid for.

A Third Solution 6 years ago

Perhaps, but if you think about how systems like this work today, for example scanning ID at the entrance to a nightclub or bar.

One way something like this is likely to be implemented is by validating a ticket or access card/token with a saliva swab. This is just too easy and attractive an opportunity for data collection to be passed up by some operators with business models that monetise the data as a revenue source.

A Third Solution 6 years ago

Quotes from the article:

“It’s easy to fall into dystopian visions of the future — a world shut down by one virus after another”

“It doesn’t have to be that way. ..... Ubiquitous screening is the key.”

The approach is interesting and the possibility of eliminating large scale spread of covid, flu and others is attractive.

However the idea of requiring a saliva swab from every visitor to an office or event has the potential to create an equally terrifying dystopian future where those samples are used to collect and use other data (DNA for example).

How long before screening companies offers to provide free screening and access control systems in return for anonymised data?

This kind of solution needs to have very well thought out privacy rules supported by strong and enforceable legislation to protect the individuals rights.

Facebook and Google have very deep pockets and are taking lots of steps to comply with the letter, but arguably not the full spirit of GDPR.

I think it would be unsafe to assume that there is zero risk of significant GDPR fines on the basis that the regulatory bodies have not picked a battle with google and Facebook.

Smaller organisations that seem to be doing less to respect GDPR are probably an easier starting point for regulators to begin enforcing the law.

For the avoidance of doubt, the main point of my comment was the not insignificant risk (a maximum fine of 20 million euro or 4% of turnover if that is greater) if a data controller does not meet the obligations of the GDPR.

Consent, as you point out, is only one aspect of this.

I don’t think recital 47 allows carte blanche data collection in the name of fraud detection, and at the very least I would think there is an obligation for disclosure of the data collection, a mechanism to access it (DSAR) and the ability to correct inaccuracies.