HN user

rstephenson2

77 karma
Posts0
Comments28
View on HN
No posts found.
Why I code as a CTO 9 months ago

It was hard to tell if he means he doesn’t do meetings at all, though it’s kind of implied. There are lots of high leverage activities around advocating for engineering’s perspectives among the other executives and bringing the business context to engineering, both of which don’t involve directly managing reports.

But I’m also surprised to see so many comments advocating for the CTO disconnecting from the code in favor of doing more people management. As soon as they stop writing code their skills start decaying, their advice and technical direction is reduced to platitudes and thought leadership. It may seem like a CTO who doesn't code will stop making technical decisions and just delegate, but I’d posit that they make decisions regardless, just worse ones.

It seems like this sentiment relates closely to the ideas around dual track career progression, and having technical leadership tied to hiring and managing people. Hiring engineering talent is certainly important to the company, but is quite orthogonal to technical decision making and it seems like a natural place to split the role.

Google has already given Chrome an unfair advantage by leveraging their other services. I suspect the browser market is an unstable system where absent outside intervention Chrome’s 65% market share naturally becomes 100%.

Chrome is such a complicated piece of software that the “forks” are highly dependent on Google and when Google unilaterally makes decisions they have to follow suit. Brendan Eich explains that Brave will continue to support Manifest V2 as long as Google doesn’t remove the underlying code paths: https://twitter.com/BrendanEich/status/1534893414579249152

I think a lot of people don’t appreciate how delicate the balance of web standards is right now. We have it so good (three high-quality implementations of an open spec) and I’m not willing to throw that away just to run Chrome on my iPhone.

If it goes through, your customers can switch, once, to Chrome.

After that, Google leverages its other service monopolies, Chrome goes to 95%+ market share, standards fall by the wayside, and nobody has any choice.

I guess the answer to that is antitrust against Google, but I’d rather do that first than go through the Chrome domination phase.

Boot camps take the “seems to be passionate about coding in their free time” signals and help their students try to fit those signals by encouraging them to build personal projects on GitHub etc. This somewhat dilutes the ability of recruiters to check off “has some GitHub projects” as a heuristic, however useful that was to begin with.

The most plausible theory to me: this is all FCC licensing related, where the owner is operating an FM station that is licensed as an AM station + repeater, but _nobody_ listens to the AM station or cares. Other comments say they haven’t been broadcasting on AM in ~5 years, so it seems likely that it was stolen much earlier and nobody noticed. The Jeff Geerling video kind of supports this, but doesn’t call anyone out since it is speculative. Because if it is true, the station either didn’t notice, or ignored it until the landscapers filed a report, forcing them to address it and pretend like it just happened.

If you were doing it today it’d probably be much easier from the enterprise procurement side. They often give out single-use virtual card numbers per service now.

In the mid naughts ruby/rails was catching on and rubyconf was getting bigger, but the events were on the _weekends_ because most of these were people doing it for fun and not able to expense it to their employer or get time off. There was pushback from prominent people about how ruby was no longer an insurgency and needed to grow up and have employer-paid conferences, which got a nice response from _why the lucky stiff which I can no longer find.

This sounds in line with Google creating go: restrict the language features so you can hire mass quantities of programmers and be reasonably sure they won’t go off the rails. It’s fine for what it’s for but doesn’t seem like that should be the goal of most programming projects?

Especially with AI copilots getting better, it feels like we’re headed for a point where you’re either capable of architecting complex systems, or there isn’t much software for you to write: other industries tend to have rote work for beginners while they gain skills, but in software rote work tends to get automated away. AI can help people learn faster, but given what AI has proven good at, I expect more of the gains will go to expert productivity. (or non-programmer domain experts)

Has anyone verified this (the Mail.app) part themselves, or is the blog post just going off of Apple's press release? The press release:

Link Tracking Protection in Messages, Mail, and Safari Private Browsing "Some websites add extra information to their URLs in order to track users across other websites. Now this information will be removed from the links users share in Messages and Mail, and the links will still work as expected. This information will also be removed from links in Safari Private Browsing."

Note that it says "links _users_ share". That part seems unnecessary if it's _all_ links in emails. I think it points to this feature being more about protecting a user from inadvertently forwarding their email to someone else, while not realizing it has personal identifiers in the links? Preventing others from unsubscribing them, or even auto-logging-in etc.

Though, I personally haven't seen iOS17 remove any query params from emails at all, maybe will have to wait for the next beta to find out.

It seems like the $200/mo plan and below are subsidized by their marketing budget, and the various ToS terms are there to give them discretion over whether those users are worth it or not: either low-cost users who are using too many resources, or users who they think they can charge more.

I investigated Cloudflare and the $200/mo plan seemed to good to be true so I contacted sales who verified that yes, it was too good to be true and my usage of the $200/mo plan would violate their ToS. They initially quoted $5k/mo over the phone, and then came back with a formal quote with a number much higher than that.

My take is that Cloudflare's product is so good that they can get away with any kind of sales practices they want. It's like shooting fish in a barrel: just analyze customers on the $200/mo tier and find the ones that look like they could spend way more. It's not even wrong in concept: sales upselling is SOP, and the low-cost tiers provide a lot of value to people who couldn't otherwise afford what they're offering. But the combination of the two sure leaves a bad taste in my mouth.

AWS doesn't have transparent pricing either, but in a different way. Yes, you can use more and more bandwidth and know exactly what you'll get charged, but once you get to Cloudflare Enterprise levels of bandwidth the AWS sticker prices would be astronomical and everyone negotiates non-transparent lower rates.

What she's alleging seems to be: the MSG conglomerate is using their large footprint to punish law firm employees unrelated to their dispute using venues also unrelated to their dispute. Doing it out of spite sounds possibly legal, if petty. But the other possible intention would be to try to dissuade law firms from taking a case against any MSG property, to try to deny legal representation to the plaintiff. Not a lawyer, but surely there's a law against that?

They might also be banking on this giving Microsoft cover to not take it down.

With the original takedown, Microsoft would be worried that the relative nobodies disappear with Microsoft left holding the bag. If Microsoft instead knows that it’s backed by the EFF who is itching for a Supreme Court fight, they might instead tell the USG “here’s their mailing address, you guys settle it in court”.

Use one big server 4 years ago

It seems like lots of companies start in the cloud due to low commitments, and then later when they have more stability and demand and want to save costs, making bigger cloud commitments (RIs, enterprise agreements etc) are a turnkey way to save money but always leave you on the lower-efficiency cloud track. Has anyone had good experiences selectively offloading workloads from the cloud to bare metal servers nearby?

Is there some nuance as to how this is set up? The company buying back the stock when you leave seems particularly interesting: if the valuation has changed in between when you start and when you leave, the company either buys the stock back at the new, higher price (in which case you make some cash on unvested stock) or the company buys it back at the original price, and from a tax perspective you are selling it to them priced under fair market value and the company owes taxes on that I think? Is there something I’m missing?

I'd be most interested to hear about situations one step up from there, where Hetzner's per-TB-per-month pricing doesn't work out favorably and you want to serve content reasonably quickly anywhere in the world.

It seems like you could build out a CDN on OVH using 1-5Gbps unmetered+guaranteed bandwidth and place servers in the US, Europe, and a few PoPs in Asia for relatively cheap, then use GeoDNS for balancing traffic. But it seems like OVH's pricing offerings have been shifting over the last year to remove the "guaranteed bandwidth" in favor of "unmetered bandwidth" (potentially throttled 50%) on more machine types.

It would still require monitoring and managing bandwidth saturation per host, and it's unclear how much extra hassle OVH adds. But in theory it seems easier than setting up and managing colos in many countries?

$0.035/GB sounds about an order of magnitude too high once you get to a large scale, were these clients doing small amounts of bandwidth?

On the other hand, $0.0021/GB is far on the cheaper end of the spectrum, who is it that offers something that low?

Agreed all around that the pricing is frustratingly opaque.

I wonder how analogous this is to “don’t talk to VC associates” advice. Corp dev is interested in buying a company, any company, at a low price but even once corp dev is sold they’ll have to sell the deal to someone who matters. People confuse “this corp dev person is interested” with “this company is interested”.

If you’re not actively looking to sell, _definitely_ don’t bother taking the meeting unless there’s a champion high up who is personally interested.

Come to think of it, recruiters aren’t all that far off this either…

Can you explain what turned you off about his negotiation, if he wasn't being a jerk? Just the fact that someone would have the audacity to do it, when you didn't feel he had the necessary leverage to pull it off?

Every company you'll ever interview at will negotiate, and most will do so whether or not they have leverage. They usually do this via a recruiter or in-house HR, to try to disassociate any negative vibes that the candidate may feel towards their potential new boss due to hardball tactics in the negotiation process.

Your stance seems designed to deter any candidate from negotiating at all, and you can probably do it because there are enough people out there that are hesitant to negotiate. Which is exactly what this article is trying to fix.

If you work with data security departments at large companies, you get these types of questionnaires all the time already. And every single question has been answered a dozen times before, but each new request's questions have subtle nuances such that it's impossible to build up a FAQ comprehensive enough that a non-technical person could copy-and-paste answers in a legally safe way. You'd think it would be possible, it just isn't.

The part that's not clear about the GDPR is whether you're obligated to manually answer any data-related question a user has, or if you can just post a comprehensive FAQ + data export / account deletion tool, and auto-respond to GDPR requests with links to those.

One interesting part about this is that it's a letter, and the author never explicitly mentions that it was sent in an email. Assuming this letter arrives in the post one day, what do you do? Ask them to email you for verification? Send you one of their 2FA codes? What if your site doesn't have a login? Can they send you a screenshot of their IP address as verification?

I get why the EU didn't want to overly specify the method, but it creates a lot of uncertainty about what processes are allowed/required. And with the pressure of gigantic fines on the line, it seems like GDPR opens up a significant vector for stealing other people's information via GDPR requests.

How about we create client-side plugins for each of the major platforms that people can use to detect the AMP mime-type and automatically mark as spam? Email reputation is a huge concern for senders and if there were enough people using the plugin it would poison the entire thing and may deter senders from using AMP entirely.

Now, for the web AMP I have no idea...

You can do that, and often times debt providers will attach those sorts of provisions: "we'll lend you X and you can keep it as long as you achieve Y or maintain Z". One of the challenges with that is that you can set up domino effects where you miss one goal, and then as a result you don't get the money you need to hit the next and it spirals downwards.

I'm not a lawyer, but don't contracts require consideration for both parties? Usually when employers require an employee to sign something, there is an implicit consideration "and you get to keep your job." But in this case he was already fired. I suppose it may have said "...in exchange for severance, at [employer]'s sole discretion" but it seems a bit fishy to me.

Not quite a device manufacturer, but a technology company: Qwest CEO Joseph Nacchio was convicted of insider trading after allegedly refusing to help the NSA: https://en.wikipedia.org/wiki/Joseph_Nacchio

It may be a coincidence that he happened to both refuse to help the NSA as well as commit a crime, but "insider trading" as an officer of a company is pretty hazy, especially if you have the NSA informing you that they're going to tank your company's stock if you don't comply.

My understanding is that you pay taxes not on the current value, but on the difference between the value of the stock and the price you paid for it. It's essentially treated as income.

Does anyone know of anything a bit larger? There are a lot of great little devices for running WRT for your home, but are there any open distributions for, say, a 50-person startup? At that level, things like maximum connection count and QoS play more of a role. Is it possible to just scale up the hardware and run openWRT, or are there other concerns?