The author is right that USB-C docks can be used to hide malicious devices - but the same is true of any USB device. You could hide a Pi Zero in a mouse, keyboard, memory stick, or anything else that you can open up and access the USB headers. Scary - but also requires a higher level of physical access than other vectors such as phishing.
HN user
seanherron
Head of Information Security at Samsara. Previously Director of Engineering at Slack and White House Presidential Innovation Fellow.
Contact me at sean@seanherron.com
Sure - but I'd rather not tunnel everything through a VPN, especially given the fact that I already have relatively high latency.
I've been using Starlink as my primary internet provider for the past year. I'm just outside of Eugene, OR and prior to Starlink my only internet options were Viasat or dial-up.
I definitely notice the variability of Starlink. My download speed ranges from ~40mbps to ~200mbps, and my upload speed ranges from ~5mbps to ~50mbps. This doesn't really seem to be connected to time of day or what I would expect to be typical use patterns. My internet is never unusable for Zoom, streaming video, or other average use cases.
A lot of people complain about decreased speeds, my personal experience hasn't really shown this to be true. What I have noticed:
* Over the past year, I've seen a huge improvement in latency and packet loss. I used to have latency in excess of 130ms, and I would typically see a few dropouts lasting ~30 seconds per hour. My latency now is rarely more than 60ms, and I never have dropouts.
* Being behind an IPv4 CGNAT is annoying. I get a lot more captchas and fraud prevention techniques being applied in my browsing.
* Geolocation is way off. I wish SpaceX did a little bit more effort to dedicate IP geodata to specific cells in their network - everything defaults to their Seattle POP for me.
* The adoption of Starlink out here is astonishing. Virtually every house near me has gotten it in the past 2-3 months. It's a huge game-changer for people. It's pretty amazing what the Starlink team has built out in a relatively short amount of time.
Often BDR calls don’t even focus on if the product is a good fit - it’s “how much budget do you have?” “Are you the decision maker?” “When are you looking to make a purchase?”. That’s, frankly, a waste of time for me. It’s one thing to have an initial call to show off core functionality and see if there’s a good fit - but if the focus is just trying to determine how much money I have, then it’s going to leave me fairly annoyed that I spent time on the call.
This is more of a post-sales item. A pivotal part of a renewal is going to be how successful implementation is - and that success is largely dependent not just on the sponsor of the project but on the team that supports them. Those folks are often the ones who don’t get the trinkets. Something like a nice jacket or even a pair of socks can go a long way to building positive sentiment there.
Seems to be a fair amount of recent interest in 10gbE home networking. I bought a Brocade ICX6450 based on this thread with 24 Poe+ ports and 4 SFP+ ports for about $100 on eBay with free shipping - it works amazingly well and powers my entire home network.
Bit of a learning curve, but I found the CLI interface to be similar enough to Junos, which I learned while managing EX switches.
I didn't expect to learn much from this article - but it actually really resonated with me. I often am responsible for purchasing decisions and found much of the advice to sales reps really insightful.
(1) The number one thing that bothers me is when I reach out to a company to explore their product and I get scheduled with a BDR who's sole job is to "qualify" me as a lead. I know BDRs are in a tough spot - but if you have someone reaching out and interested in your product, take advantage of that and get them straight to the person who can demo and answer questions. I'm shocked at how many companies make me want to prove myself as a customer before spending time on demoing.
(2) Ask before recording meetings, and if someone doesn't want to be recorded make sure you actually have the ability to turn that recording off. I've been on calls where the person who set up the Zoom/Gong wasn't on the call, and so no one had the ability to stop recording.
(3) The details of what is shared on calls is often completely lost. Every time a new person gets on the call, they ask the exact same questions that have already been answered. Make the customer feel as though you're interested in their business, have discussed their pain points, and have a plan ready to help them.
(4) Discounting discussions are always a pain. It's a game that no one likes to play.
(5) Offer to send some swag to the implementing team at your customer - not just your champion. It's a nice gesture and goes a surprisingly long way towards building positive sentiment.
Yeah, optics or DAC cables are definitely preferable. I wouldn’t run more than one or two 10G-BaseT units in most switches - but when you have a modem or device that only supports it, it’s a much cheaper way to get connected than buying a dedicated switch.
For about $50 US, you can get a 10Gbase-T SFP+ module that gives you a copper port at 10gig within a SFP+ form factor. That, coupled with a cheap Mikrotik switch, is plenty to get started.
Second hand Brocade ICX switches are also plentiful and not too power hungry (but they can be loud).
I wish used equipment was that cheap now! We are constantly looking and old balers in our area are still going for $7k+. For something relatively recent and in good working order, much higher. Also, don’t forget building a dry place to stack and store all of it!
I own a farm, this summer we produced and sold about 1500 bales of hay. Had no idea hay exchange existed, the vast majority of our sales were via craigslist and Facebook marketplace, with most being small-scale (50 bales or fewer). The rest came from word of mouth and our local 4-H group.
Producing hay at this scale is extremely difficult. The start-up costs are in the hundreds of thousands of dollars, and you're typically barely breaking even. This year is unusual in that supply was way down, so prices were a lot higher than normal. The only reason we can do it is that we have a relationship with someone who cuts & bales a number of small fields for a per-ton fee.
I could see a tool like this being useful for large-scale operations that are doing the big round bales yet don't have an established relationship with a buyer. For an operation like ours, where we are producing small ~60lb traditional square bales, I don't think we're going to find anyone local enough who wants to buy at the quantity and size we have. For instance, only two entries in the entire state of Oregon.
That said, I'll post on here next season, I'd be really interested to see if anyone reaches out.
Those all happened at least 20 years ago - I was looking at things that have happened in recent history.
In what modern situation would a whole plane parachute actually help save lives? The vast majority of the (extremely rare) commercial aircraft disasters occur during takeoff or landing, when a parachute would provide little utility due to the distance the aircraft is from the ground. Other notable recent disasters had either instantaneous destruction of the aircraft (Metrojet 9268, Malaysian 17) or were caused by pilot error or murder/suicide (Germanwings 9525, Colgan 2407).
Perhaps the only incident I can think of where a parachute may have helped was US Airways 1549, where a bird strike caused loss of power to both engines. In that case, however, sufficient safety controls existed to enable landing on the Hudson river, and the aircraft functioned as designed (engines broke off when hitting water, the aircraft floated long enough to ensure safe evacuation of all passengers, life rafts deployed, etc). I would argue a parachute would probably have resulted in loss of life as a giant A320 parachute falling uncontrolled on to New York City would probably kill people crashing in to a building.
Rather than focus on superfluous, impractical safety measures, commercial aircraft designers have instead spent time on things that actually save lives, such as Traffic Avoidance and Ground Proximity warning systems.
Note that parachutes do exist for smaller planes, where the risks and benefits are substantially different. A good example is the Cirrus SR-22. It seems that most cases of deploying the parachute on the Cirrus is due to pilots running out of fuel, a failure which is extremely improbable in commercial aviation.
Wasn't this invented by Disney in the 50s? http://en.wikipedia.org/wiki/Circle-Vision_360%C2%B0
We looked at doing things like logging git commit frequency to try and provide realistic estimates to users of their time that they could then confirm or alter. Realistically, with the diversity of talent we have here (both technical and non-technical) and the time it would take to do well, it didn't really seem too practical.
It would be awesome if WakaTime and others provided some way of interfacing with an API, so that individuals could track time in a way that made sense for them while reporting in a relatively consistent standard to a central system used for accounting and billing.
>> Given that there is no download link or price
Like everything 18F produces, Tock is a work of the US Government and is in the public domain. There's a link to the GitHub repository in the blog post (https://github.com/18f/tock). We don't intend to launch Tock as a service, rather, it's something we made for internal use that is open for others if they find value in it.
Very interesting to look at the original content of https://github.com/greatfire/ and https://github.com/cn-nytimes. One appears to be a collection of resources for proxying around the Great Firewall [1] and the other has a number of clones of the New York Times translated in Mandarin [2][3].
[1] http://webcache.googleusercontent.com/search?q=cache:X_4LmyL...
[2] https://github.com/cn-nytimes/mirrors [3]: https://dtl1al4e74u07.cloudfront.net/
(18Fer here)
That's one of the things we're very much focused on fixing. While we can't go in and change every federal government website out there, we can work to ensure that the security of the platforms we are working on is tight as possible. 18F is working with a number of agencies (see https://18f.gsa.gov/dashboard/ for the full list), and our hope is that we can be a force multiplier in security best practices throughout government.
Furthermore, we take responsible disclosure very seriously, and welcome any feedback through our email (18f@gsa.gov). We should probably take this up a notch and have a dedicated security inbox that goes directly to our core security team.
Have you seen the Presidential Innovation Fellows (http://www.whitehouse.gov/innovationfellows) program? We're a group (about 60 alumns so far) focused on doing CfA-esq projects within the Federal government. Jen Pahlka just finished up spending a year with the program helping scale it up and do even more awesome things. Ping me if you're interested.
Sent you an email - a few folks over there should be able to help you out!
It's awesome to see this posted - I was (one of) the original creators of code.nasa.gov when we first launched it in early 2012. I've since moved on from NASA, but the agency has kept on posting things to the site as well as on GitHub (https://github.com/nasa). So glad to see the torch continue to burn.
There's a big effort within the federal government to do more around engaging citizens in using (and contributing to) free/open source software, as well as starting to develop more user-centered products and services. If you're interested in that sort of thing, check out 18F (https://18f.gsa.gov and https://github.com/18F). We'd love to hear from you.
Structured Product Labels (http://www.fda.gov/forindustry/datastandards/structuredprodu...) that will get the same cleaning and harmonizing that the drug adverse events data received.
We set it to 120req/minute and 60,000req/day to ensure that load on the system isn't too high at launch. Over the next few weeks, we'll be adjusting the limits based on the traffic patterns we see.
As noted in the documentation, if you need more than 60,000 per day, give us a ring at open@fda.hhs.gov.
Huge shout out to api.data.gov as well - all of our key authentication and analytics are powered by their open source API Umbrella platform.
I'm a federal employee serving as a Presidential Innovation Fellow (http://whitehouse.gov/innovationfellows) working on open data initiatives at the FDA. We worked with a contractor to build the platform and were happy to find they were incredibly excited about the prospect of open source.
We're going to focus on product recall and product labeling data next - expect to see some more releases throughout the summer.
Completely agree. We built openFDA from the beginning with the mindset that everything we produce will be open source. Our hope is that users of openFDA can help us make the API more efficient, return better data (we do a lot of cleanup), and independently verify our methodology.
Beyond improving our own site, it would be absolutely fantastic if someone took openFDA and spun up their own copy. That could be another government agency using it to serve up different data, an external group mirroring openFDA in case of government shutdown or other issue, or a company that uses our code to build something innovative.
I know that sentiment is shared among a lot of agencies right now. In particular, 18F (https://18f.gsa.gov) is a new digital services delivery unit that is looking to do this at a huge scale across the federal government.
Great to see this on HN! I'm one of the openFDA core team members and would love to help people who are interested in using the public drug adverse event API. It's good to note that we've also released all of the source code behind the platform (https://github.com/fda) and are actively interested in having members of the community help us make improvements.
Please do ping me if you have any questions about the API or want to learn more! sean.herron@fda.hhs.gov
Also, here's a direct link to the API documentation: https://open.fda.gov/drug/event
There also is a nice web GUI that NASA JPL published on top of the XML feed: http://eyes.nasa.gov/dsn/dsn.html
From the pictures, it looks like the ship is registered in the US (though that could change once it is finished).
If you're doing it on another day, the inventory (and thus price) probably changed. The price of a seat on a plane is dependent on how many other seats have been sold.