HN user

ruskyhacker

51 karma

Maker and Breaker of all the things!

Posts1
Comments51
View on HN

Idk how I feel about this. I think this is only an appropriate solution if you are 100% capable and can take complete ownership of patching said dependencies.

I get how there is risk associated with a supply chain attack, but what are you going to do when you don't understand a vulnerability and need to fix it?

Most problems aren't impossible to solve of course, but those who've been working with a codebase for a long time probably have a more intimate knowledge of how it works.

I don't know the answer to your question, but have often thought the same thing. I used to have this saying - at some point you have to take the tinfoil hat off and just "live a little." My thoughts is I'd never make a name for myself if people didn't know who I was. Now at almost 34, I just straight up don't care anymore. I'll never "be someone" and I'm too old in tech to be taken seriously by the movers and shakers.

Not sure where I'm really going with this other than I fully understand opsec, the hacker mindset, cyber security, etc, but I've never really cared to stay private because I wanted to be known. Now that I'm likely as good as I'll ever be, it doesn't really matter lol. If someone finds something I said in poor taste, I'll apologize and hopefully have learned from it and move on.

Definitely try out fancyzones from powertoys if you're on Windows. For Linux I'm not really sure, not much of a Linux desktop environment type, but I'm sure there's something for gnome. Lg makes a software I think it's called screen split, but fancy zones is better in my opinion. I run six 34 inch 2k ultrawides. I use the "edges" for stuff on the back burner - main content goes in the middle. It you have the right monitor some ultrawides can split inputs if you have multiple machines/ sources. That could be useful for dual os or work & personal setups.

You mean open ai put out a model and people stopped using search? Or Google?

What Open ai offers currently can't really compete with search - I understand the data it's being fed gets newer and newer, but it's not really real time like the search engines are. Indexing and presenting data is so different than NLM. Even if it is fed data that's new it's going to have to infer a lot because of a lack of history. It might be able to summarize recent events I guess. Way dumbed down here, but I consider chatgpt like a really smart encyclopedia that can search fast and stay in context across "searches."

If you meant Google, that's sort of what I'm saying - they wouldn't release something that could blow open ai out of the water. But I suspect what open ai offers as a product is something Google could've built long ago, or maybe did and couldn't figure out how to monetize it. They've instead invested in ai to make their products and services better, not as much to offer ai as a service.

What I meant by bard not working out so great was that Google quickly dusted off or slammed together some shenanigans to be relevant, even though what openai is doing doesn't appear to be a part of their master plan.

well my thought is that they 'whipped it up' real quick to attempt to downplay it a bit. Did that backfire? Yeah, I think so. But personally, I think people are missing where the real money is. OpenAI will do great for awhile until every damn product and service is using it, and then it's a race to the bottom. But that's just like my opinion...

I'm probably way too late for this thought to get any traction / discussion - but I have this weird feeling that openai screwed up and showed it's "cool new thing" too early, and publicly.

As much as it pains me to say this, I don't think the real money is in making this a service, or "the product." I think the real money is in using AI internally as a puzzle piece of your backend - ie. the secret sauce behind xyz product.

I'm being very narrow here, but you can only do so much integrating what openai has built into your products - eventually "everything" providing data from the same model brings "everything" to the same level. In contrast if you train and create your own models to make xyz do something specific, nobody knows how it was done, or it surely makes it a lot harder to kang.

I have zero proof, but I suspect Google for instance has models that would literally obliterate what openai has shown capability wise. They're probably not necessarily language models though. Again, nothing to stand on here but I doubt their search and analytics for example are driven by hard coded algorithms these days.

Bard may have been released sort of as a "psh, we've been there done that" when in reality they didn't, because they never planned to make the models they were/are working on "publicly" available to use. It makes me wonder if this is how Google has lead for some long with some areas - now openai sort of screwed it up for everyone by making it a service that can be integrated / adopted by nearly anyone.

The only people I guess that are really going to know are the devs working for these big orgs, and I'm sure that lock and key knowledge.

I sort of explained my thought process above but I suspect they've done it this way for "cdn things"

It's not great, there's certainly a way to secure it, but like many other solutions - stuff it in a storage bucket with a "random" url is "good enough" in the eyes of the platform.

Technically I agree - it's just one of those things that quite a few platforms do... It's similar to the eufy stuff circulated about recently. User uploads XYZ, they expect it to be "private" - platform devs decide private == obfuscated via a super long file name (a bit layman, sorry) in some kind of object storage.

While there's definitely a method of securing the access to the uploaded content to those who should have access, it's often not implemented that way since your uploaded content would be statistically improbable to "guess" and even more improbable to tie it back to you.

I came off a little direct, straight up saying it was not a vulnerability without context. While I still stand by it not being a vuln from a sec perspective, it's definitely not great.

I'm not a career dev, but I have inherited teams and projects before that were a huge mess...

This isn't going to come off nicely, but your assumption that it needs a full rewrite, is in my eyes a bigger problem than the current mess itself.

The "very junior" devs who are "resistant" to change are potentially like that in your view for a reason. Because of the cluster they deal with I suspect the resistance is more they spend most of their time doing it XYZ way because that's the way they know how to get it done without it taking even more time.

What it sounds like to me is that this business could utilize someone at the table who can can understand the past, current, and future business - and can tie those requirements in with the current environment with perhaps "modernizing" mixed in there.

Part of the reason some VPN providers (including myself in the past) lease the hardware is to be extremely scalable. Customer retention low because VPN doesn't work for xyz streaming service? "Check out our new endpoints here in this obscure tiny colo!" Want to spin up endpoints in Russia? Done! Africa? Done!

I have equipment I own in two colos - for other things. It made way more sense when I was selling VPN access to lease everything.

Most importantly, this boast Azure is making falls flat on its face unless they own everything. Even if they "own the servers" they're likely still colocated, being provided network hand-off, etc. ¯\_(ツ)_/¯

Yeah, I've seen a few different implementations of this. The pump one I was able to watch them remove had a clone skimmer attached where your card goes which sent it's data to a bluetooth module hidden inside the service door.

I'm probably not the correct person to answer this question, but I can share my experience at least!

I was incredibly concerned about this with an idea I had. A shared the 'idea' with a mentor of mine, who was 'well off' and not technical. This mentor agreed that before I involve other people I should speak with a lawyer to see how to best protect the idea because like you it seemed to be (and researched to be) an original concept.

He hooked me up with a lawyer and we discussed the options for copyright, patent, etc. Long story short the decision was that there wasn't a clear method of 'protecting' the idea due to it's complexity. I'm not saying you shouldn't consult a lawyer - there are certain things that are easier to trademark, copy, or patent. My idea is/was a biz to consumer saas if that helps any.

I didn't feel any better about sharing with others after that meeting - my mentor had reached out to his contacts who were more aligned with getting startups off the ground to as about what to do in this situation. What was explained to me was that what really matters is how fast you can go from zero -> 'minimum viable' (which could just be detailed ins and outs of all the pieces) -> poc -> 'market'

If there are high startup costs and you can't create a shotty demo or something, then sit down and write as detailed of a 'plan' as you can. Doesn't have to be a business plan, because depending on your expertise you may not care about monetizing it and can utilize people who can bring ideas to the table later on. What you're trying to do is document and plan out how it will work in as much detail as you can. Draw pictures, write process, write pseudo code, mock up layouts digitally if you can, basically whatever you possibly can get into a some kind of organized 'plan.'

While you're doing this it'd be smart to have an audit log that can be validated somehow. Pictures of you working on it where it's clearly visible, certified mail copies of it to yourself, whatever you can do to prove it was you who did this, and this is when it happened.

That's all I've got, I hope it helps. For what it's worth - the idea I'd come up with still doesn't exist for the most part out in the wild, and it has been roughly 4 years. The startup costs for me aren't high, it was the lack of knowledge to get it done myself that caused me to only do the planning bit I described above. My circle of people to tap at the time with the know how wasn't what it is now. (I got more into programming and it widened how many other programmers I know)

Perhaps someday I'll get going on a shotty demo of it to pitch ;)