HN user

snowwolf

1,282 karma
Posts9
Comments251
View on HN

It took a long time to realize that the most compelling devices have good, well maintained software.

I continue to hold the view that Tesla's success is because they are really a software company, not a car company.

My wish list:

* HTTP/2 (3?) (on the roadmap) * a refresh of the dyno line-up - at least pass on some of the cost savings of removing/supporting free tier by reducing dyno pricing or preferably bumping specs * auto-scale for all dyno tiers * rebuild security team with reputable lead * edge / multi region active-active DX * edge ssl termination * iterate on chat ops (underrated feature) * more metrics * more alerting (e.g. crashed apps) * better user/access team management (default app roles) * enhanced secrets management in env (2 layers of env view/roles - config vs secrets) * DDOS protection * Treat CI env vars as secrets!

If you used your previous password on any other sites, we highly recommend you also change your password on those sites.

This is the most concerning part of that email, as it implies more than an "out of an abundance of caution", but rather that they suspect their password DB has been compromised.

Thinking about it, it does sound the most likely as they were probably the same DB the customer oAuth tokens were stored in that were used to access Github repositories. But if they already knew the data was stored together why wait till now to reset passwords?

Support engineers use a number of customer support tools to get their job done including Okta’s instances of Jira, Slack, Splunk, RingCentral, and support tickets through Salesforce.

I like how it just glosses over access to all the other tools which often contain a treasure trove of data. Just Slack can give an attacker worst case credentials pasted into channels and best case loads of information for more targeted social engineering attacks. LAPSUS$ even stated they had access to over 8K channels.

Exactly my point. However the European Commission has released "Approved" SCC's in June 2021. Does this case now invalidate those because "the DSB has rejected these measures as absolutely useless when it comes to US surveillance" in which case it is in conflict with the European Commissions guidance.

My ideal goes further than that. All I want is a reasonable data plan with non extortionate roaming rates from my existing provider (phone service is not important to me these days due to FaceTime/WhatsApp/etc). Some providers were starting to offer decent roaming to a large selection of countries that came out of your existing allowance with no additional charge but they seem to have started rolling back on that now as margins are getting squeezed. There is no reason for roaming charges for 1 week to be higher than the cost of a 1 month pre-paid local sim.

I don't know the rollout process but perhaps it involves taking servers offline, putting more load on the still live unpatched servers, increasing the probability of the race condition occurring?

A lot of their problems seem to come down to the fact that they aren't experienced in vaccines so have made multiple missteps along the way because of that on the procedural side of things.

Their choice as partner for the Oxford vaccine was purely political. Merck were originally the preferred choice (and they have a lot of vaccine experience) and a deal was almost done, but the UK vetoed it because all production would be in the US and they wouldn't offer the guarantees the UK had gotten from Oxford as part of their funding of the Vaccine development.

https://www.theguardian.com/society/2021/jan/29/we-had-to-go...

The origin of the UKs priority access to the AZ vaccine was due to their early funding of the Oxford vaccine on condition of 1st priority. This was before AZ even got involved. In fact the UK govt had such deep involvement that they were able to veto a deal between Oxford and Merck to manufacture and distribute the vaccine over fears that it would allow Trump to block their priority access through export controls (as Merck would manufacture in the US) so the UK make Oxford partner with AZ. AZ inherited that pre-existing deal between Oxford and the UK govt.

The killer feature for me which lead me to me switching away was Fitbit Pay. They just don't have the take up by banks that the competition (Apple and Samsung) have. Maybe that would have changed, but if they integrate Google Pay instead, I may switch back.

I don't want my TV to run any platform/OS that would be the main source of content. Mainly because when I buy a TV it generally lasts for 10 years or so. My current Sony TV (around 10 years old) came with some "apps", none of which now work. Which I'm fine with. But what happens when that's the main OS for the TV? I'd much rather buy a new chromecast or firetv every few years to get the latest experience.

Moving your SSH port isn't really about security. It's about reducing noise in your logs from annoying port scanners constantly hitting common ports. Although that does then have the benefit of making your logs more useful for detecting actual attacks. And it probably reduces some CPU cycles too as an added bonus.

Dyndns to solve the static IP issue, and if not all ports are blocked setup WireGuard on an open port and connect via that. To be honest I prefer to not expose a lot of these home server type projects directly on the web as a lot aren’t that secure. You’re better of going via WireGuard.

The only place you get stuck and need an intermediary vps is if you are behind CGNAT. I came across this recently that helps set all that up. https://github.com/erikespinoza/v4raider

Personally I think it is better to think of Tesla as a software company that makes hardware for their software to run on, rather than an automotive company. In that respect they are probably better compared to Apple than Toyota. A lot of their key USPs are a result of the software they create rather than the hardware.

Maybe the relevant supervising authority didn't find it important to notify those 9 million customers.

Which is a problem right? Now it emerges what has been breached. Including credit card data. Surely the prudent thing would have been to warn all their customers immediately to allow them to be on the lookout for malicious use of their data (phishing, etc.) and not wait until they have concluded their investigation.

EasyJet said it first became aware of the attack in January.

vs

The GDPR introduces a duty on all organisations to report certain types of personal data breach to the relevant supervisory authority. You must do this within 72 hours of becoming aware of the breach, where feasible.

So either EasyJet was delayed in their reporting of the breach, or the ICO didn't feel it was urgent to notify 9 million people that their data had been compromised. But it is now 4 months later?