HN user

rograndom

1,490 karma

WordPress core contributor and member of the WordPress Hosting and Performance teams. 25+ years building enterprise PHP/MySQL systems, including TurboHub (Laravel platform managing 1.5M+ WordPress sites across 10,000+ servers) and A2 Optimized (cross-platform performance tools). <br /><br /> Run Soju Web Development in Vermont, working with clients from local organizations to state and federal governments. Write about mindful development practices at developmentenlightment.com and WordPress technical deep-dives at supersoju.com.<br /><br />

Currently seeking PHP/Laravel development and web operations roles. Open to remote work.<br /><br />

LinkedIn: https://www.linkedin.com/in/andrew-jones-6505766/<br /> WordPress: https://profiles.wordpress.org/supersoju/<br /> GitHub: https://github.com/supersoju/<br /><br />

I can be contacted via my profile name [at] gmail

Posts61
Comments137
View on HN
www.theverge.com 6y ago

Plex makes piracy just another streaming service

rograndom
2pts0
a.wholelottanothing.org 7y ago

Converting phone lines to ethernet in newer homes

rograndom
1pts0
m.signalvnoise.com 9y ago

Interviewing job applicants in a coffee shop is barbaric. Stop it

rograndom
2pts0
m.signalvnoise.com 10y ago

Real-time dashboards considered harmful

rograndom
2pts0
getaway.house 10y ago

AirBnb for Tiny Houses in Boston

rograndom
1pts0
ideas.ted.com 10y ago

Why I’m teaching prisoners to code

rograndom
2pts0
insights.ubuntu.com 10y ago

ZFS Licensing and Linux

rograndom
107pts60
insights.ubuntu.com 10y ago

ZFS Is the FS for Containers in Ubuntu 16.04

rograndom
9pts2
ericasadun.com 10y ago

When your client demands Swift

rograndom
2pts0
medium.com 10y ago

The depressed programmer

rograndom
3pts1
www.csoonline.com 10y ago

HIV dating app leaks sensitive information, company threatens infection

rograndom
10pts0
www.vividcortex.com 10y ago

Nobody Loves Graphite Anymore

rograndom
3pts0
medium.com 10y ago

Halloween’s Here: Software Development Horror Stories

rograndom
2pts0
github.com 10y ago

Black Screen – A terminal emulator for the 21st century

rograndom
3pts1
bytecrafter.blogspot.com 10y ago

How JetBrains Lost Years of Customer Loyalty in Just a Few Hours

rograndom
430pts490
www.reddit.com 10y ago

Hi, I'm a web-dev from the year 2005, and I am full of shame

rograndom
11pts1
www.reddit.com 10y ago

How I Built a $17K Monthly Recurring Revenue Business

rograndom
2pts0
github.com 11y ago

Eigenvimrc – Scrape GitHub for vimrc's and rank most popular options

rograndom
1pts0
www.randalolson.com 11y ago

Computing the optimal road trip across the U.S

rograndom
11pts1
dracony.org 11y ago

Stop using PHP-FPM to argue using Nginx vs. Apache

rograndom
1pts0
www.daedtech.com 11y ago

How Developers Stop Learning: Rise of the Expert Beginner

rograndom
7pts0
chrispenner.ca 11y ago

Vim vs. Emacs; is it really a competition?

rograndom
3pts1
tynan.com 11y ago

EV (How to Make All Decisions)

rograndom
2pts0
lifehacker.com 11y ago

How to Automatically Back Up and Purge Your Gmail Every 30 Days

rograndom
7pts1
medium.com 11y ago

A Designer’s Sublime Text Setup

rograndom
1pts0
en.codeceo.com 11y ago

As a Programmer,Why My Salary Is the Lowest

rograndom
7pts0
www.theverge.com 11y ago

Does Twitter have a secret weapon for silencing trolls?

rograndom
2pts1
www.buzzfeed.com 11y ago

The Parody Twitter Illuminati

rograndom
14pts0
www.cafe.com 11y ago

Do Not Disturb – Why Programmers Need Doors

rograndom
2pts0
research.gigaom.com 11y ago

The commoditization of app developer skills

rograndom
1pts0

Location: Vermont, USA

Remote: Yes

Willing to relocate: Maybe

Technologies: PHP, MySQL, JavaScript, React, VueJS, Laravel, WordPress, Linux (LAMP/Nginx)

LinkedIn: https://www.linkedin.com/in/andrew-jones-6505766/

GitHub: https://github.com/supersoju/

WordPress core contributor with 25+ years of enterprise PHP/MySQL development experience. Most recently at A2 Hosting/WHG, where I architected A2 Optimized (cross-platform performance optimization for WordPress, Drupal, Magento, and other CMS platforms) and TurboHub (Laravel-based management dashboard serving 1.5M+ WordPress sites across 4 continents).

Also founded Soju Web Development, building custom WordPress/WooCommerce solutions and SaaS products including centralized WordPress management tools. Strong background in full-stack development, system architecture, and performance optimization at scale.

Open to engineering roles or interesting challenges in WordPress/PHP ecosystems.

Ha! I had one of those in the late 90's. My father had it first and I inherited it when he passed. A couple of months after he bought it, I bought a 1985 LTD, which was basically a 4 door Mustang GT. He asked me if I wanted to race, I said it wouldn't be close. He said "Both cars have the same engine." Yeah, not quite. The Thunderbird had like 120hp, no fuel injection and bogged down to meet emissions, while the LTD had close to 200hp and was several hundred pounds lighter. Another person up the street had the same vintage Thunderbird with the 350ci and had done some work to it. That one went pretty good.

I was working at a web design company a little after windows XP went EoL. One site had a member on thier board who kept raising a stink because the redesigned site didn't work right on their computer. Found out that they were using IE6 or whatever on XP. Our estimate for the fix was $600, which was like an additional 2-3% on top of the original estimate so it was approved. The $600 was used to buy a new laptop for that board member with Windows7 and whatever the latest IE was installed.

Back before flexible web layouts or modals were a thing, we went through a phase of opening a new browser window for some content, and locking the size. Sometimes we'd want to open multiple windows and reference them later on, so we had a naming convention like "_popup_a" and "_popup_b". We had an intern one summer who coded all of his new window calls as "_poopup_X". I have no idea how the client actually found it, but boy did we hear about it.

Most every cPanel based hosting company, including the large ones, will offer a product with LiteSpeed. It's sometimes re-branded, but it's there. The main benefit is that it's a dropin replacement for Apache on cPanel servers and performs much better when it's tuned for that purpose than Apache.

I worked at a place in the late 90s that had a mix of older actual Apple Macs and newer Power Computing towers. One night some water line in the ceiling went and almost all of the machines got showers. Most of the wet Power Computing died but none of the Apple machines did. There was even one that retained probably a quart of water that was dumped out through the disk drive holes the next morning.

My wife has a similar problem with the iMac supplied wireless mouse. She'll go to click-drag something and catch the power switch, which is on the underside of the mouse, on the mousepad turning off the mouse. This has happened maybe four times in the two years we've had it, but everytime it's been "The computer crashed!" and gets power-cycled, losing work. Of course it's still "crashed" when it comes back up because the mouse is turned off. This post makes me feel like I should put a sticky note on there to check the mouse next time.

“I’m not the smartest guy in the world, but I’m certainly not the dumbest. I mean, I’ve read books like "The Unbearable Lightness of Being" and "Love in the Time of Cholera", and I think I’ve understood them. They’re about girls, right? Just kidding. But I have to say my all-time favorite book is Johnny Cash’s autobiography "Cash" by Johnny Cash.” ― Nick Hornby, High Fidelity

I grew up in the strange time where the cars we got as "hand me downs" had 8-track players. At a yard sale we found an 8-track to cassette adapter, and then put one of those cassette to line input adapters to have a discman playing in these 1970s era cars.

Magic was probably the first instance of where I learned that sometimes it's ok to not try to "solve" games or put too much thought into being competitive.

I'm not sure how my friend group found Magic originally, but it was around like 3rd edition or so? We all really liked it and spend way too much money on cards. We would play around the kitchen table in a single game, 5, 6, 7 people all with decks a mile high building huge armies before someone finally gave in to break the peace and attack, usually resulting in everyone else attacking them. Great fun.

I had some access to the internet at work and during a break I started looking up stuff about Magic and found a deck that won a tournament recently. It was a red burn deck, and the tournament was a draft, which I had no idea what that meant, but I had a "winning" decklist and I had most of the cards in there. I traded with my friends for the other stuff I was missing and we set about to play. I think I killed everyone one after another with that "stupid deck" with cards the others just flat out gave to me because they were "bad". I took that deck to a tournament a couple of weeks later and found out what the difference between drafts and constructed decks were, mainly that my deck needed 20 more cards. I still get fourth place and a box of booster packs.

My friends one by one stopped playing not too long after that. I went on to win most local tournaments and play in a handful of pro tour events, but none were ever as much fun as sitting around the kitchen table.

Many, many years ago I was at a company where a manager (M1) wanted full root access to all of the internal servers (mostly file/web servers, router/firewall and the mail server). It's lost to the sands of time as to why, but he was persistent.

There was quite a bit of back and forth between the team that managed the servers, the owners of the company and M1. After a few weeks M1 was finally given access. Within a couple of days he brought a complaint against another manager (M2) that M2 had hijacked M1's personal email and was storing it on one of the internal servers.

Meetings were held into the night to discuss what should be done. M2 was called in, credentials revoked and they were placed on leave while an investigation could take place. Overnight every single server was compromised and no one could get in to anything.

M2 brought in a lawyer, the company brought in a lawyer and all of management and most of the employees were sat down in a room to figure out what to do about this mess.

Turns out M1 had re-used the same "password", which was a single lowercase english word, on EVERYTHING. His personal email, any account on any service maintained by the company and had changed his secure password on the superuser accounts he had just been given to the same one.

There was a literal paper trail of M1 providing this password to the majority of the people in the company. Provided in printed memos asking to have accounts set up, emails asking to have accounts set up, other people having it on the standard sticky note on monitors, M1 saying "and make the password..." in the common workspace for anyone to overhear, etc etc.

Of course, one of the servers had SSH open for remote access... and you can see where this is going.

Expensive forensics team was brought in, servers recovered, and it was determined that M1's account on the SSH server was targeted by automated logins not too long after he was added to the company's website.

M2 is cleared and brought back, M1 had their role decreased and was gone not soon after.

If you're in the US, contact your state attorney general. This is a widespread, known issue that a few are building cases about. They have back channels to facilitate getting the account back.

I've done sub-sub-contract work for a few government and military orgs where standard procedure would be I would be mailed a thumb drive of what should just be images and word docs to add functionality to a small section of an internal website. Every single time there would be things on there, totally unrelated to the project, that I should definitely not have been given.

I am not surprised at all. Maybe 7 years ago I got called in to clean up a website "hack" where the site had a bunch of malicious JS on it. Site was hosted on GoDaddy.

Pulled the site down locally and started the regular process of find/remove, but nothing was showing up. Hosting the site locally, the JS wasn't being put on the page. Checked all the server files for stuff like php.ini, user.ini, etc etc. Nothing was showing up.

Created a plain info.php file on the account. That had the JS injected into it.

Started searching for other sites with the same JS, found a bunch, dozens. Started a search for "neighbor" sites to the one I was investigating, ones that most likely were on the same server. They ALL had the JS injected. Server was owned.

I alerted the client and sent a note into GoDaddy, like you need to check this out. Got a response that it was impossible for the server to be compromised and I should buy their Sitelock service for security. Instead we requested a migration to another server and that cleared up the issue.

I went through the same thing (https://news.ycombinator.com/item?id=34031217), and just finally got the last piece, WhatsApp, unblocked a couple of days ago.

My situation was unique because my Facebook account administered the pages of government agencies and they were very helpful in putting pressure through back channels to get it sorted out. It still took over 30 days after they acknowledged that they dropped the ball to get the account back, and 60 days to get everything back and running.

But I'll pass along this link to my AG as they're collecting stories like this, and there's hundreds we've found so far.

There's $20-30 looper pedals on Amazon and Ali Express that do the job just fine.

Most any USB audio interface will have an "instrument" input/mode that will allow you to plug directly in and will work with Mac/Windows/Linux directly with low latency. Most of the come with some software bundles as well with free amp and pedal models.

I remember seeing one of the first Pentium's, it was either a 60 or 66mhz, but it was STUPIDLY fast. Way faster than any 486 we had at the time. We were just watching someone play Windows 3.11 solitaire on it and laughing when they won because the card "waterfall" animation took what felt like 1 second to complete. It was probably longer, maybe 3-4 seconds, but on our 486's it was probably 10-15 seconds.

We had a place booked on Airbnb near the end of the summer. Had a deposit paid, and the overall price was a bit steep, but needed to stay in the city at that time. Three weeks out we get an email with the "house rules" including disclosing that the owner would actually be staying in the house and would need to go through the main bedroom to enter and exit the property.

We were contemplating what to do with this information as the listing is under "entire place" when a few days later we got an email from Airbnb saying that there was a price adjustment of +$395 for cleaning PER DAY. We had it booked for 5 days so we needed to pay an additional $~2000. That was more than double the original cost. Thankfully we were able to cancel and get our deposit back with just the automated cancellation, but we did get a nasty message from the host that we we reported back to Airbnb.

I was hoping to write up a TellHN about something similar once my situation was resolved, but the same thing happened to me at the end of November.

My Facebook account has MFA and a very strong, unique password. I began to receive emails about my "account recovery code", which I ignored. A day or so later I received an email that MFA was disabled, and then one that my password had been reset. I was able to immediately reset it again from a new device, log in, log out all other sessions and re-enable MFA. Then a few hours later the same thing happened, but by that time it was overnight and I wasn't able to catch it in time. I woke up to the emails outlining that process again along with one saying my account had been suspended.

I went through the recommend process of supplying my ID, which was rejected as "forged" and I was told my account would be terminated, decision is final, no ability to appeal, etc. Luckily (maybe?) my account created Facebook Apps for some state and federal government offices and personnel, and those went away at the same time. Now there's some high level people butting heads with the Meta Pro team on my behalf, and I'm watching the emails as they go back and forth.

It's about 3 weeks later and I still haven't gotten access back yet, but we've collected dozens of other cases of people that have had the same thing happen going back to mid-October.

It appears to be a scam where attackers are able to somehow gain access to Facebook accounts bypassing passwords and other authentication processes and then post about crypto and NFT sales on Facebook marketplace. If the account has a credit card attached, they will buy $100-500 worth of Facebook ads for the same thing.

We're all wondering what happens to the regular people who don't have the business connections to have the ability to reach out to someone that is able to bypass the regular process that is failing in a major way?

Not just getting lucky, but being ready to get lucky. If they didn't have the company or the product already, bumping into the former manager wouldn't be enough. And I think I've just given the type of advice TFA is railing about :)

I grew up in the 80's and the school in my town had a playground like this from when it was first built in the 60's (1960's, obv), but it didn't get much attention. In the mid-80's there was a "new" playground built that was mostly wooden with metal slides, poles, some tire pit thing and monkey bars that were 8' off the ground. Splinters were an every day occurrence, the slide would get hot enough to burn in spring and summer, and in the winter if you had a hole in your mittens, your hand would get stuck to anything metal.

But the thing that really terrifies me thinking back is the "cushion" they put down on the ground. These days it's all shredded foam rubber or wood chips so if you fall, you're not hitting anything sharp. This playground however had GRAVEL. And not just from when it was first installed, they trucked in fresh gravel every six months. Cut hands, torn pants and shirts with streaks of blood were common. God forbid if you got some in your shoe. And of course, kids would throw handfuls of rocks at each other, why not? The teachers on playground duty of course did nothing to discourage any of this. Probably why in a school of less than 200 kids, there were 3 nurses.

That is "rent" price. You pay 1m at move in but you don't own the apartment. The landlord gets the interest on it as your rent. When you move out you get the 1m back.

Got somewhat homesick opening the article and the first photo is a place I've walked right by many times, it's right around the corner from my in-laws. At least one other and maybe three others are within 100 yards of first photo as well.

There was a ramp up of new WordPress and specifically WooCommerce sites starting in late summer of 2020 and spiking huge in December 2020 & January 2021. These are people that were stuck at home due to lockdown or losing their jobs and they started online businesses. The lot of those signed up for 1 or 2 year hosting plans and those came due around Feburary/March of this year. A large amount of those businesses failed, or the owners went back to work, etc etc, and no longer need their sites.