HN user

mncolinlee

1,862 karma

I like to hack lots of mobile things.

http://colintheshots.com

[ my public key: https://keybase.io/colintheshots; my proof: https://keybase.io/colintheshots/sigs/4YdtDSG8zFyKbYG1bOtsNBIVYkrl26QpnsVA1pT7zqY ]

Posts32
Comments423
View on HN
colintheshots.com 5y ago

The Bug That Stole Xmas: A Horror Story About Releasing Firefox Focus 8.0.4

mncolinlee
1pts0
blog.mozilla.org 7y ago

Reinventing Firefox for Android

mncolinlee
721pts387
venturebeat.com 7y ago

Mozilla Launches GeckoView-Powered Firefox Preview for Android, Pauses Focus

mncolinlee
2pts0
www.cnet.com 7y ago

Mozilla's new mobile Firefox browser pushes speed, privacy on Android phones

mncolinlee
2pts0
www.engadget.com 7y ago

Firefox revamp for Android promises privacy without losing features

mncolinlee
2pts0
medium.com 8y ago

Bits will pour over #NetNeutrality

mncolinlee
1pts0
muratbuffalo.blogspot.com 8y ago

Paper Summary: The Case for Learned Index Structures

mncolinlee
2pts0
realm.io 10y ago

Realm (YC S11) Java 0.87 – With RxJava Support

mncolinlee
1pts0
www.theverge.com 10y ago

Google's Project Fi adds support for iPads, other data-only devices

mncolinlee
1pts0
vidku.com 10y ago

Show HN: Vidku - Short video sharing with full control and elegant design

mncolinlee
13pts0
www.youtube.com 11y ago

Go with the Flow: A Reactive State of Mind [video]

mncolinlee
3pts0
github.com 11y ago

Stetho: A debug bridge for Android applications

mncolinlee
4pts0
prezi.com 11y ago

AnDevCon RxJava Presentation: Be Reactive with Retrofit

mncolinlee
1pts0
realm.io 11y ago

Realm: a mobile database replacement for SQLite and Core Data

mncolinlee
2pts0
mentormate.com 11y ago

Tap to Live: Apple Pay and the Impending Rebirth of NFC

mncolinlee
1pts0
mentormate.com 11y ago

Confessions of a Developer

mncolinlee
4pts0
yancey.tumblr.com 12y ago

Kickstarter CEO's Life and Leadership Lessons from Dungeons and Dragons

mncolinlee
3pts0
blog.futurice.com 12y ago

Top 7 Tips for RxJava on Android

mncolinlee
1pts0
www.thestreet.com 12y ago

Nissan to Extend Electric Car Leadership With 135-Mile LEAF

mncolinlee
1pts1
medium.com 12y ago

Oculus Thrift: How early investors had VR goggles pulled over their eyes.

mncolinlee
2pts1
medium.com 12y ago

It’s Like An Enron, But For Insurance

mncolinlee
4pts9
news.ycombinator.com 12y ago

Ask HN: My Nursing Reference App is Helping Poor Clinics, Losing Money

mncolinlee
16pts9
medium.com 13y ago

Making Hay of the NSA: My Response to the Data-Mining Argument

mncolinlee
2pts0
medium.com 13y ago

I Knew Snowden. And He’s Not The Story

mncolinlee
245pts99
www.kickstarter.com 13y ago

Liquibench on Kickstarter: Intellij/Eclipse/Resharper for your database

mncolinlee
2pts0
www.colintheshots.com 13y ago

Fear Does Not Lead to Rational Responses

mncolinlee
1pts0
colintheshots.com 14y ago

The LIBORtarian Extortion Rate

mncolinlee
1pts1
colintheshots.com 15y ago

In Defense of the Bitcoin: The Nature of Money

mncolinlee
4pts0
colin-lee.com 15y ago

Going Six in the Ring, Why Paul Graham Isn't Always Right

mncolinlee
4pts0
colin-lee.com 15y ago

Can Entrepreneurship Boost Your IQ?

mncolinlee
1pts0

It's my understanding that despite the high cost to run Meetups, the company itself has never been in a good financial position. They've been bought and sold multiple times.

Former Meetup employee here. A company being bought and sold multiple times is not a sign of being in a poor financial position.

2017: Meetup was first bought by WeWork for $156M.

2020: Meetup was then sold for a fire sale price to AlleyCorp as WeWork was trying to avoid bankruptcy from their unsustainable office rent deals. Watch any of the streaming shows like WeCrashed if you want to know what happened to WeWork.

2024: Meetup was then sold for a very nice multiple of their 2020 price to Bending Spoons after being profitable for several years. However, it had been profitable over those years by keeping it all together with only a small team. Bending Spoons moved operations to Italy, where most developers are cheaper.

SEEKING WORK - Minneapolis - Remote

Expert Android/Kotlin & Kotlin Multiplatform Engineer

Experience: Over 20 years in software development, specializing in Android for 11-12 years.

Notable Projects: Firefox for Android, Meetup, Amazon Relay, Microsoft Flip, etc.

  -   Skills: Android, Kotlin, Kotlin Multiplatform (KMP), Jetpack Compose, Gradle, Java, Compose Multiplatform, some Swift/SwiftUI.
  -   Availability: Recently became available due to employer acquisition.
  -   LinkedIn: https://www.linkedin.com/in/colinmlee/
  -   Website: http://colintheshots.com
  -   Contact: mncolinlee & gmail.com

SEEKING WORK - Minneapolis - Remote

Expert Android/Kotlin & Kotlin Multiplatform Engineer

Experience: Over 20 years in software development, specializing in Android for 11-12 years.

Notable Projects: Firefox for Android, Meetup, Amazon Relay, Microsoft Flip, etc.

  -   Skills: Android, Kotlin, Kotlin Multiplatform (KMP), Jetpack Compose, Gradle, Java, Compose Multiplatform, some Swift/SwiftUI.
  -   Availability: Recently became available due to employer acquisition.
  -   LinkedIn: https://www.linkedin.com/in/colinmlee/
  -   Website: http://colintheshots.com
  -   Contact: mncolinlee & gmail.com

I've been building a game in Compose Multiplatform and have been learning how to integrate new UI features across WASM, Android, iOS, MacOS, Windows. It's great new tech with a lot of promise even though it's still early.

Code quality has been plunging for years while we've become more dependent upon code.

Devin AI working Upwork jobs blew minds, but it succeeded for a reason. Upwork and similar sites are plagued by low quality contractors who do little more than glue together code written by better engineers. It was never a hard formula to copy.

Outsourcing programming work to the lowest cost and quality to third-party libraries is leading to inevitable results.

Obviously, the next leap will be sophisticated supply chain attacks based upon poisoning AI.

SEEKING WORK – Minneapolis – Remote

Remote: Yes, please. I've been remote since around 2017.

Android/Kotlin and Kotlin Multiplatform expert engineer with over twenty years of software experience. I've been building highly successful Android apps as well as Android/iOS apps with shared business logic in Kotlin.

I've been building Android apps for ~11-12 years, including working full-time on major ones like Firefox for Android, Meetup, Amazon Relay, Microsoft Flip, etc.

You can benefit from the fact that my employer has been acquired and our acquirer has informed us they plan to let everyone go.

LinkedIn: https://www.linkedin.com/in/colinmlee/

Website: https://www.colintheshots.com

Mail: mncolinlee at gmail.com

Technologies: Android, Kotlin, Kotlin Multiplatform (KMP), Jetpack Compose, Compose Multiplatform, Gradle, Java, some Swift and SwiftUI, and many others that I use less often.

I've been an organizer both pre- and post-pandemic.

I can say that my pre-pandemic programming Meetup group has been tricky to re-launch. We did decently in virtual Restream sessions during the pandemic, about 15-20 attendees and many more watching the videos. Afterwards, it's much tougher to find free venues. I don't have recent contacts with many speakers. Most sponsors aren't recruiting and aren't looking to spend money on free pizza. Some original members aren't getting emails and notifications because they stopped them during the pandemic.

However, my tech happy hour meetup is more popular than ever. We relaunched it after the pandemic and it's been hopping ever since. By starting over with a new group and new name, we were boosted by a New Group Announcement that put our group in front of lots of new Meetup members. Being one of the active Meetup events in our area, we get higher attendance than pre-pandemic. Also, it's a joy to host these events as I have almost no work putting an event together-- no venue, speaker, or sponsor discussions.

It's a tale of two event formats-- one that used to work well and another that still does.

My take on online events is that people attended during the pandemic partly to be social. However, Zoom creates a problem-- as the number of attendees rises there's a significant burden to speak and to take up space in the conversation. I used Restream to allow conversations in chat and to highlight various comments and discussions. I had great hope when trying gather.town, but it didn't work well because most came to watch the speaker and left without learning how to mingle and socialize in a virtual environment that should have empowered smaller, organic conversations.

They're truly different beasts, but each has clear value. As but one example, I've seen outsourced apps for financial firms where there were literally hundreds of basic security flaws. Would you trust the same review process that allowed those PRs?

I have certainly done this. PullRequest bought the Moonlight developer gig platform. A lot of full-time developers from Moonlight also took on gigs from PullRequest as they've been using the platform to sell their service. I'd guess most reviewers have other jobs or contracts.

Having done more than a few PR reviews and code security reviews for their platform as an Android/Kotlin dev, I've found that the opposite problem is more common. A lot of organizations suffer from insular thinking and their own team often comments LGTM even if there's something glaring.

Writing reviews as an outsider, there's something freeing about knowing that you can review honestly and professionally and not overly worry that a colleague might get offended when you're simply trying to help. It's also not a chore anymore. Since the review is the job itself, it doesn't feel like a distraction. And since you're an outsider, you might know about best practices at your organization that the client hasn't been exposed to.

When I review code, I read the summary explaining what that org likes in a review, but I also make sure to include tools and practices that they might not be aware of. In many cases, I can see they're lacking automated static analysis like ktlint/detekt and point it out. I might notice performance or security flaws that their own team wouldn't consider in a typical PR.

While I actually enjoyed the style of work where reviewing a PR isn't a chore, there are a couple issues I'd like to see improved. Their rates could be improved for the best engineers. Also, the number of jobs isn't always enough for the number of reviewers. Gig work is much nicer if you can actually choose the hours and have more flexibility.

Former Amazon (retail division) mobile engineer here.

A lot of the comments in the OP are true, but possibly a bit overstated.

They definitely expect a lot of engineers to leave after one year with only 5% options. In fact, they'll refuse to give raises if your stock price hikes put your pay "above band," but then they won't make up the missing raise if the stock price tanks.

They do PIP a fixed percentage of the workforce every year, even if they're talented at their jobs-- but it was about 15% when I was there-- and half got to keep their jobs if they ran the gauntlet of hard tasks without a complete mental breakdown.

There's no question Amazon is a difficult employer. But the exact details vary from division to division. It can also be a place where you meet a few very talented engineers and learn a lot. But the good ones rarely stick around. I found that the best managers got quickly hired away for better positions at other companies. I personally had four managers within the span of one year.

They also seemed to have a ridiculous legal policy that drastically limited speaking at conferences, blogging, or personal open source projects. It was far easier to moonlight and get the okay from legal than it was to give a talk at your local Meetup or contribute to Open Source outside of work. I stopped asking for permission or telling anyone.

I also noticed that the corporation seemed to encourage taking on unpaid extra work as a bar raiser or security reviewer, but your division might take no interest in anything you did to help the wider company when performance review time happens. There's a lot of politics and jealousy at play. If your team is working 60, 70+ hours, they won't care that you're producing just as much quality work in 40-50. Managers routinely sacrifice their employees as pawns to gain favor for themselves.

One of the most troubling things wasn't the long hours, busy on-call periods, stack ranking, or PIP policy, but their complete disinterest in firing execs who used abusive behavior. There was one in particular who would scream at our managers and cause some to cry in meetings, but rather than disciplining him and making him change his ways, he was able to transfer to another division where he continued his abuse.

I personally worked in Y2K support at the time on PC hardware. Most motherboards we tested worked, but some needed BIOS updates and one model needed a new BIOS fix which didn't exist. We swapped out the bad motherboards, updated software, and had no problems.

In the UK, there were some medical devices (my memory says dialysis machines) that malfunctioned over the issue.

There is an important lesson about the behavior of the media in this. They whipped out people into a survivalist, doomsday prepper frenzy over an issue that could be solved simply by updating BIOS, software, and/or hardware.

With that said, the effort was very expensive because so much software and hardware needed to be audited at every company.

$100/hr is remarkably low in agency mobile work. When I was doing agency work five years ago, even our Bulgarian developers were billed out at more than that. I was billed out at 3x that back then and it would be more now. It's really challenging to find skilled developers who want to perform agency work and to keep them from leaving for a competing firm.

People are not optimal machines. Instead, they make decisions based upon narratives. An inferior product can win based upon a superior narrative or because it was seen more often and recently than a competitor's product.

Generally, a consumer is only looking for one or two features to match their needs. Producing a very simple product with fewer features to match the needs of a key segment is a great way to start building an audience. If people complain about missing features, it's a good sign that they have some interest in using your product.

There is some great theory around moderation which goes far beyond this piece. David Lakoff's book "Don't Think of an Elephant" is a classic.

Moderation is rarely a choice. There's an old expression, "The only thing in the middle of the road is roadkill." It's not saying that moderates are extinct or undesirable. Rather, left and right political views mostly come from a history of life experiences that drives people either towards empathy for strangers or towards fear of strangers. The combination of these worldviews and the human desire for having a community or clan drives people into parties in opposition to each other.

For most moderates, their experiences instead drive them to prefer either worldview depending upon which issue is being considered. Their experiences are not totally based on seeking safety or showing empathy. They are not middle of the road on most issues, but have a diverse set of opinions. Their opinions are diverse enough to not feel fully accepted into either party and to adjust their own views into alignment, unless their country has a middle party. This seems to be what Graham calls deliberate moderates.

There are also moderates who become moderate because nuance is important to smart policy. Fully left or right ideas both tend to overshoot evidence-based decision-making. I believe this is what Graham refers to as accidental moderates. However, the roadkill metaphor still applies because even accidental moderates still have life experiences that lead them to a worldview as well as the human desire to belong to a group. Even those who apply past policy-based evidence to develop a nuanced view will have a human desire to try to fit themselves somewhere into the partisan political landscape of their environment. It's not easy being the odd one who doesn't fit.

Perhaps one of the most noticeably hackable tests I've participated in is democratic elections. I ran for office a few times and learned a lot about how the system actually works. I believe this is why politics has such a negative connotation. Ultimately, voters want politicians to do what's right and politicians learn they have to gain the genuine love of one group and appease a large enough cross-section of groups without offending an important one.

If there's one thing I learned in politics, the biggest hack is in having a great narrative. Ultimately, brands, companies, and politicians are characters in our consciousness that only achieve meaning through the stories they tell.

Essentially, the story must be believable and ring true to the audience being targeted according to their past experience. For example, evangelicals love a good redemption and hard work story. Each group has their own highest morals. I'd recommend "Don't Think of An Elephant" by George Lakoff, which explains how politicians hack the human mind by crafting an entire language that plays into their hopes and fears.

I'd love to have every test in life be genuine and unhackable. But when tests are clearly so hackable, it doesn't help to not call out how the hack works. Call it responsible cultural exploit disclosure.

Are more granular (or at least visible and understandable) privacy settings coming in future releases, or is this just the UX direction? Why is Mozilla making it so much harder to enable desktop-class protections on mobile devices?

Yes, that release is imminent. Preview will include all of those settings. You can try them right now by downloading Firefox Preview Nightly.

I disagree. Polling in 2016 clearly showed Trump and Clinton were each individually the two least-liked nominees in their parties in modern presidential history. First-past-the-post and bitter primaries were largely responsible for the result-- over a third of voters remained at home on Election Day 2016. In some electoral systems, they even have an option to reject all nominees in these kinds of situations.

It's not even that new. A professor was using a much earlier version of this same tech to steer his boat in the 90's. It was very easy to read left and right signals to control a rudder as a prototype.

There have been commercialized versions of this tech already. The Myo was Kickstarted in 2015 and then acquired by CTRL-Labs. I have one and that generation of the tech was still tricky to use effectively.

https://www.kickstarter.com/projects/312488939/myowaretm-har...

Here's a pretty decent paper on the quite long history of Brain-Machine Interfaces: https://www.physiology.org/doi/full/10.1152/physrev.00027.20...

No one knows a lot when they first start out. However, there's a lot of value in learning new skills by doing. It's the main skill programmers need to succeed in their jobs. No one becomes a great programmer by taking a new college class for each new API.

I have no CS degree, but at the time I was in college, CS programs seemed embarrassingly poor compared to today. I took a few, elective CS courses and did CS research back then and remember numerous graduate students trying to cheat off of the undergraduate English major.

I'll say this. There's advantages starting both ways. By starting from a CS background, you're likely to get a formal education into concepts and terminology that might seem boring otherwise. By starting from a non-CS background, you begin with the most important skill a programmer requires-- the ability and passion to teach yourself new technologies and concepts.

Any developer who begins with a CS background can learn to be self-taught.

Any developer who begins without a CS degree can learn algorithms and advanced concepts.

The first type of attack that should come to mind with SMS-based 2FA is SIM cloning. Identity question answers can be purchased off the dark web from previous leaks. Also, social engineering is notoriously effective against several of the top carriers, who lack effective identity validation. Lives have been ruined.

Firefox 68.0 7 years ago

Extensions can be a good thing for sure. But they need to be done right. Hacking out some hurried implementation of extensions is how malware and security advisories happen. It is elitist to suggest that the desires of the 3% trump building a good browser first.

Also, the Internet and most technology happens to break existing workflows. We shouldn't assume disruption is bad if the result is an improved version.