Yeah I agree, caveat emptor and all that. The blameful framing is bad work product though.
HN user
mcfunley
http://mcfunley.com
https://bsky.app/profile/mcfunley.com
The point is really after working through remediations, there were pretty massive issues remaining that weren’t hard to find and were relatively vastly easier to exploit if the attacker is a Russian teen and not Bruce Lee. And the budget for such things was blown. Priorities, etc
I worked at a company that had hired Mitnick as a security consultant.
His report for a client that turned out to have been rife with SQL injection at the time was largely movie plot physical security stuff. Not wrong exactly, but not the center mass of the threat model they needed either.
He seemed to lack systems thinking, producing a report that focused on calling out specific employees as dumb or incompetent. Counterproductive at best. It seemed like his PR exceeded his utility by a great deal.
That trend continues beyond the grave, maybe.
This was the best conference there ever was and I miss it a lot
By the time this is all said and done we’re going to wind down the DHS in its entirety, bogus lists of political enemies included
Did HN start automatically translating posts from their original German?
To your point, the thing that jumped out at me reading this book is how familiar the German characters are. People have loved to imagine that the Nazi era in Germany was so anomalous it could never happen again. But no, the Germans were just like us.
Category error to think there's a strategy. Trump doesn't even know what a tariff is. People try to project a strategy because it's probably too discomfiting to believe that the greatest superpower the world has ever known elected a complete nimrod king.
Yeah you are right about this, psychological safety is a key ingredient in what “good” looks like. Blameless culture stuff is a bit of another ball of wax, so I didn’t get into it too much.
Glad that one landed, thanks!
Unfortunately no, I've only done it as a private event within a company so far.
In an extended chapter of Mythical Man Month, Fred Brooks described his practice of screening candidates for number-form synesthesia by asking “where is November?”
I have number form so when I was young and originally read this I thought it was pretty neat. But as evidenced in the rest of this thread, it’s an absolutely crazy practice since the majority of great programmers don’t have it. And I assume it’d be illegal these days anyway.
Great to see this course material public. It's a real missed opportunity though to not mention that Galois wrote a lot of it down staying up all night before being shot.
No, it’s orthogonal to the analytics
Author here. The main thing that inspired this happened a few years before I wrote it down. Etsy had gotten a new CEO, and they spent one of their first few weeks in long hours at my desk, iterating on the homepage design in what could only be described as a radically fast iteration loop. We'd ship a tweak, look at statsd for ten minutes, then change something else. This would have been a bad idea for all of the reasons of statistical validity listed, even if we hadn't built statsd to use UDP.
Emphasizing working on the homepage was also analytically dumb in a more meta way, since item/shop/search were really nearly all of traffic and sales back then. Anyway, I felt motivated to get that person to think first and fire the code missiles second.
At the end of the day, I think back on it fondly even though it was ludicrous. Shipping that much stuff to production that quickly and that safely was a real high water mark in my engineering career and I've been chasing the high ever since.
I worked on a feed reader back in 2006. The worst feed discovery kluge I can recall needing to special case was that certainly the most popular blog at the time (Cute Overload) was a frameset around blogger. That was typical though, people’s sites are a mess.
I don't know if it was that deeply irrational, I mean beyond the decision to initiate a war with the United States in the first place.
At the start of the war it wasn't clear that carrier-based air power would be able to effectively suppress ground-based air power. The prevailing theory was that carriers were too fragile to do this. The US Army and elements of the Navy with surface warship backgrounds believed this, too.
That turned out to be super wrong, and the Americans won much faster than expected by cutting off and bypassing Japanese strongholds (Rabaul, Formosa) and keeping their airfields impotent with regular carrier raids.
If those hadn't been the case, the Japanese strategy of seizing "unsinkable aircraft carriers" would appear to make more sense in retrospect. The thinking was that an initial crippling blow to the fleet plus the cost of clawing these back would be too much for the US.
Wrong, and in fact many of the Japanese brass thought it was wrong. But irrational would imply that there wasn't a theory, and there was a theory.
The war was over after the Marianas were taken, if not at Midway. It doesn’t seem right to discount the industrial might like you do when the US produced dozens and dozens of carriers and escort carriers while the Japanese produced four or five more.
But beyond that lots of reasons,
- Intelligence and damage control (mentioned elsewhere)
- The air war of attrition started early, with the Japanese sending flights 600 miles from Rabaul to the Coral Sea. They didn’t rotate their pilots out to recuperate as the Americans did. The average Japanese pilot was a novice compared to his more numerous American adversaries by 44, and flying a very inferior plane compared to the newer F6F’s. And he could expect to fly sorties until he was killed, which by the end of the war was not much longer than one flight.
- Despite starting the war with Pearl Harbor, Japanese doctrine at the top never really moved on beyond Mahan and their plans tended to obsess with engineering a repeat of Tsushima. Yamamoto’s Midway disaster was an attempt to do just this. Compare to the American carrier raid tactics from Doolittle onwards.
- The Japanese were successfully starved of fuel, and for that reason couldn’t even get their big ships out of port before Leyte, which was a doomed banzai charge at sea.
Right, because it wasn't actually the middle layer that was causing the problems
That's generally true about the overall stability, the DB popped constantly.
One reason Emid got grief was because it started barfing every time sprocs, table schemas, views, etc were changed and nobody ever really managed to resolve this. The DBA's would update the text of a sproc without telling anyone and Emid would start throwing exceptions. Certainly a set of fixable problems, but nobody ever really got a good mental model of when it needed to be HUP'd.
"Emid uses psycopg, ergo we have to rewrite the whole thing" was one of the insane justifications tossed around for the rewrite project. Never made any sense.
The business issue motivating removing the middle layer altogether was just that to do anything you needed to change three things in three different programming languages (maybe four if it involved JS or Flash), and this was foolish.
Sid #1 was someone that worked with Rob's dad, IIRC. Not from the investors. He continued to come around for a long while. It was amusing to me watching Chad (CTO hired after the eng founders left) take meetings with the guy.
During the period between Rob's CEO tenures he and Sid #1 built a Google Analytics alternative together, which was in fact written in C. We very narrowly avoided acquiring this company.
Yep same guy, and if the thread makes it unclear I really do consider Jared a genius of the most wonderful sort
OP here—if it’s not obvious from the tweets the timeframe of this story is 2007 through 2008.
It’s amazing how relatable these notes are
(I made the tweets)
If you want to put sql in your templates, I can't help you
Greg would it really surprise you if a tech startup turned out to have done something stupid
I'm as ambivalent about capitalism as the next person. But Etsy is a lousy counterexample to the premise of combining success in business and progressive values. Current and former employees conflating the two is disappointing.
Etsy grew rapidly and organically for a decade, and never figured out how to grow intentionally in an ROI-positive way. As a private company it was not particularly concerned with revenue per employee, and headcount expanded like a gas to fill available revenue. After going public it was way too slow to realize that this wasn't going to fool the public market.
I feel deranged pointing this out, but hiring triple the headcount you need to run your business is not a progressive social value. I don't know what it is.
n.b. I worked for Etsy from 2007-2014. My own values force me to own this.
I find myself having to just imagine the narrative that goes along with most presentation decks you find on the internet. Videos of conference talks take too long to watch. I finally had enough of this situation and worked out how to dump out Keynote presentations along with their embedded presenter notes. This script emits HTML that looks a lot like how @idlewords shares his decks, and it also makes a nicely formatted PDF.
Example output: http://pushtrain.club
(author)
I just grabbed an example at random there. It's not really an excessive example of nesting, but, at the time I didn't grok threading.
I think the data being manipulated is a cloudformation response or something, so, the structure isn't something I'm in control of.
I actually changed it from `(:status (:status ...` in the original, which is even dumber naming, so that it wouldn't look like a typo. Real life programming is thoroughly unglamorous I guess.
This doesn't mention transfer restrictions at all, and that's an altogether different reason that options are complicated. It's a bad idea to assume that you'll be able to sell private company shares, even if the company is popular and you've heard of other people selling. The existence of a market for the shares doesn't guarantee that you'll be allowed to get rid of them, because the company can enforce all manner of restrictions on sales.
The market for stock in a private company tends to be very small. Existing investors and prospective investors in the company can comprise most or all of it. Those folks care more about relationships with the company than getting their hands on a handful of employee shares. What this means practically is that if the company doesn't want you to sell for any reason, the buyers won't cooperate with you either.
If you're planning on selling, you should feel comfortable communicating this to the company. And they should agree to it. And that assent should be very recent and in writing.
You can find startups out there willing to buy derivatives on your exercised shares, which is functionally similar to selling shares. But this is a mixed bag, and you should read those terms carefully.
Read your option agreement. You'll note that among other things, it says that the agreement can be amended by the company at any time to say anything at all. Good luck!
Realistically, when you run a website big enough that the people pushing the code to servers aren't the people who wrote it,
My position would be that you should push your own code even/especially on large websites.