Arguably
That's doing a lot of lifting.
I think you could make a 50/50 decision at the CEO level for most decisions, and merely by making a decision faster the org would have better profit outcomes.
HN user
https://nds.lol
Arguably
That's doing a lot of lifting.
I think you could make a 50/50 decision at the CEO level for most decisions, and merely by making a decision faster the org would have better profit outcomes.
Meanwhile, you still can't do fast-forward merges in GitHub :clown: https://github.com/orgs/community/discussions/4618
And it doesn't even rebase and merge correctly with fast-forward if there it's a clean set of commits! https://github.com/orgs/community/discussions/5524
It's everything you mention in the second paragraph, and additionally just the ability to turn them off.
Imagine everyone had their routers disabled simultaneously. I don't know if the cell networks could function with the surge in standard traffic that would happen, and then you've effectively plunged all or part of the country into a communication blackout.
I think "turn it off permanently by bricking it" is almost as bad as "leverage for DDoS".
I worked on Bot Mitigation at Amazon, and we once saw a ton of traffic that was heavily distributed amongst consumer devices world-wide, but surprisingly in the US too. We suspected compromised routers that were using the home page as a health check. There was a lot of investigation I did, and the short realization after talking with the network engineers is that the amount of traffic, and distribution of sources, would be impossible to stop. There merely isn't enough bandwidth in the world to stop so many residential device if it hits a specific target. To be clear, this was coming from less than half of active Amazon customers, not everyone in the US.
Anyway, it wasn't routers, but it was a consumer device, and it wasn't nefarious, it was incompetence (in code), as usual.
Small organization (< 20 people): $10/mo
If you went to 100k/year and still a solo dev, that's just 0.12% of your ARR. The percentages here are meaningless; $10/month should be doable for anyone that wants to run a business, even someone solo.
This probably refers to the fact that Windows XP still has support contracts. Microsoft commonly calls their software EOL and then supports it for 5+ years. I don't think that's a bad thing, but they tend to use it more as a marketing term than a true hard line where security fixes stop going out.
Thanks for the detailed explanation! I think it would be great to drop this (or something like this) in the project README.
Hmmm I've recently been evaluating https://www.kysely.dev after finding that Prisma can't support foreign data warehousing (FDW) with Postgres.
I don't really know enough about Kysely yet to make an informed opinion between those two. If you know more than me, can you give me your take??
Edit: Hmmm perhaps based on the primary author's other repos (https://github.com/mythz) it looks like they're a fan of C#. Perhaps it's the LINQ-like syntax that separates them the most.
Have you looked at FolioHD? It's geared towards photographers and artistic types that want a really nice portfolio website.
Paying an amount that is just-above-market-rate for a domain and not needing to understand how to configure DNS for someone non-technical seems like an absolutely worth-while reseller case.
Good news, I haven't been on reddit for years.
The bots are real, regardless of what either of our opinions are. https://www.youtube.com/watch?v=GZ5XN_mJE8Y
It's odd when certain topics - vaccines being one of them - come in with a flurry of comments when it isn't even highly upvoted. Especially when you have some drivel as the top comment saying Gates flew on the "lolita express" and some link to Prince Phillip. Ooookay? What about the article?
Hear hear. Everyone arguing against this seems to want the permanent, forever solution. There isn't one. This isn't software - it's reducing harm over time as best we can, and it's a fight that will take approximately the rest of human time.
The argument that we created a bioweapon is like... and? We also have nerve agents and gas and nukes. It's like everyone posting here exists in some other reality where they never talked to another human in a grocery store. We all get along as best we can.
Strong agree. I'll tell you the other reason not cited: it slows down organizations. Doing things right to avoid the (seemingly) small chance at being massively wrong is the inverse of the bet that doing many different things quickly has a small chance at a massive payout.
Let's say I'm an executive and I think there's a 1% chance of a breach that costs me 100x and a 1% chance of a 100x payout on every project.
I have 2 projects that each make $X. Let's say $X is $1000. 1 project will go from $X to $X/100 based on breach, so it's now worth $10. 1 project will go from $X to $X*100. It's now worth $100,000.
I went from making $2000 to $99,990.
This goes back to the argument about fines. They aren't NEARLY severe enough. If I'm an executive at a big company, I may enforce greater security on the "cash cow" projects (e.g. ad revenue and GSuite at Google [but not the Pixel or GCloud], AWS and Retail at Amazon [but not Alexa, Kindle, etc]) but the rest? I need to get ANOTHER cash cow. If my service that's only netting me $1M/year goes to $0, and I needed a service that would make $1B, I literally do not care.
If adding in-depth security to the $1M/year project makes delivery 2x slower, I've now spent 2x on something that probably wasn't even worth it. This is a game of stats; businesses and features as cattle not pets. I'd rather have 2 projects and another dice roll than 1 project that's just "meh".
That's not how I operate, but if you're playing this game as an executive, that's the most logical outcome.
Now I want to read an article about the economics of selling game hacks. I just assumed they weren't really worth the investment to build since the number of people that want to cheat seems low.
After typing that I realize this is like coming to understand just how many people are on steroids to get a physique they want. It's like nah no one takes steroids except EVERY HUGE PERSON you've ever seen, barring the extremely rare genetic outliers.
Fascinating.
I meant the intangible, personal gratification that comes with pwning noobs as a reward but fair enough :)
Question for people that build hacks: given how robust this open-source anti-cheat is, does building the cheat give more reward than playing the game? It seems like it would take a ton of hours to be effective..
No, because Azure as an organization consistently lowers the security bar. It's like auditing a dam with a massive leak.
https://www.wiz.io/blog/chaosdb-how-we-hacked-thousands-of-a...
https://www.npr.org/2023/07/12/1187208383/china-hack-us-gove...
https://www.tenable.com/security/research/tra-2023-25
https://www.theverge.com/2023/8/3/23819237/microsoft-azure-b...
https://www.spiceworks.com/it-security/vulnerability-managem...
I had a similar take until about a week ago. A friend showed me his workflow with Copilot and whatever Jetbrains AI assistant is.
Use it as a tool: what if instead of opening up a new tab, searching for the API docs for the library you're trying to find a function in, find the function, re-read the parameter arguments for the 400th time, and then use it, you could just highlight a snippet and say "Paginate the results from S3 using boto3" and the code would just populate?
You have to have the clarity of thought to know what you're doing, but the time it takes to write every line for basic stuff you've done 1000x before can be greatly compressed if it's inlined with your IDE.
I think this is the move for most LLM tools: integrate it with existing tooling. An LLM for Excel for corporate bookkeepers, CPAs, etc will be great. A Word/PDF summarizer that's tuned for attorneys will also be fantastic. Highlight a paragraph, ask for relevant case law, etc.
I thought ~2 years ago the results were... not great. Now I'm pretty happy with it.
SecureFrame (helps with compliance regimes like SOC2) recently added the ability to generate Terraform templates to automatically generate infrastructure that will fix specific platform risks for AWS, Azure, GCP, etc.
It definitely needs someone at the helm since it does hallucinate, but I have found it to cut down my time on mundane tasks or otherwise niche/annoying problems. When was the last time you visited 4+ StackOverflow posts to find your answer? Copilot, so far, has always hit a pretty close answer very quickly.
lol, the internal docs on this at Amazon were something very close to "we invented this before Avro and we think that's probably a better choice if you need binary serialization."
My 2 cents: don't use it.
Is WarpStream considering hiring Aphyr to do a Jepsen test?
Tell me you're in your 4th year at a BigCo without telling me you're in your 4th year at a BigCo.
The goals of the organization are mostly a facade. The people running the organization, and their actions, are what the goals of the organization actually are.
How many times do you check HN each day instead of doing work?
Why even think about software as a building at all? Just think about it as software. I don't understand the urge to draw parallels to other fields.
Check out the post by Schiit Audio's CEO (I think CEO?): https://www.head-fi.org/threads/schiit-happened-the-story-of...
It looks like the audio sector was hit particularly hard by the war in Ukraine.
I'm really looking forward to the client implementation. I worked on a Rust NTP server where I used to work. It was truly faster than ntpd or chrony, which is a meaningful benefit when you're talking about something that sends out data about clocks and time.
Unfortunately the server is relatively easy to build. The client, however, is where a LOT of the intelligence and difficulty lies.
Is there a large format print version of this available? I'd love this as a big poster.
Management is about extracting value, which is what most of those on replies on StackExchange are doing.
Leadership is about training new leaders.
Bob is a kick-ass employee. Why not make him into a leader and have him figure out ways to make the other employees just as productive? He has to learn to multiply his effort. He doesn't need to be a manager to do that; he just needs to be made into a stronger leader and be given progressively larger scope.
I got my units backwards :sweat: My bad!
Yeah. Try running with PYTORCH_ENABLE_MPS_FALLBACK=1 <script> --full-precision
Depends what fork you're running... Some seem to be using CPU-based generation, others use the MPS device backend correctly which is MUCH faster. I have another comment floating around about lstein's fork, but it takes some massaging to get it to run happily. https://github.com/lstein/stable-diffusion/
1.3 sec/iter on my M1 Mac, so ~39 seconds.
Try the lstein fork: https://github.com/lstein/stable-diffusion/tree/fix-cuda-res...
You'll still need to play with modifying some of the code to get it to run, but `dream.py` works for me. Funny enough, I got only img2img effectively working with the lstein branch; it broke txt2img for me.