HN user

specialk

200 karma

Engineer at HubSpot in Dublin working on leadin.hubspot.com

Graduate Trinity College Dublin. Ex-chairperson Dublin University Computer Science Society

Twitter: @__kbaker__

Posts7
Comments33
View on HN

This isn't purely a resource allocation problem. There are real people finding themselves homeless or in bad living conditions because of the explosion in rents in Dublin. Families shouldn't have to live in hotel rooms. We need to remember that the change and disruption that companies like AirBnB bring are not always good for society as a whole.

There is a supply and demand tension in Dublin over accommodation. Building more apartments, i.e. increasing supply, will help alleviate this tension. That doesn't mean we can't also tackle the problem from the other direction by reducing demand. AirBnB is demand.

It's hard to tell how much any government would want to pull on a lever that might reduce demand. Those tourists bring valuable outside revenue into the city. We need them too. There's lots to balance here. Let's not optimise just revenue.

Concentration indicators:

Wearing headphones

Working away from normal desk

Interruptions still happen, of course. When one does, we suggest letting the person know upfront that you’re concentrating on something, and asking them if it’s urgent. And if you’re the person doing the interrupting, try not to get offended when you get asked if your needs are urgent.

OMG yes big fan of this. Setting expectations up front for this kind of behaviour is great. Without a 'culture' for allowing people to stay focused without an immediate interruption, I have always found it hard to explain to people interrupting me why they could have used an asynchronous communication tool, like Slack/HipChat/email, for non-urgent questions.

There is a subtle irony in your comment. I think it is interesting to tease out because much of the arguments on diversity come from one's own perspective.

So, if you'll indulge me, your argument is essentially 'us vs them' is a bad thing. About right? If so, I agree. We're not going to solve an exclusionary tech culture by excluding people or creating two sides to a debating war.

But what strikes me is that your comment didn't even reference Nicole Sanchez by name once. Your comment was "she" and "her" time and time again. Did you even notice yourself do it? I somehow doubt it was intentional. But I'm an optimist.

There is a great clourflare article [1] that has talked about this before when they first suggested LV certs.

The seemingly good news is that globally, SHA-2 is supported by at least 98.31% of browsers. Cutting 1.69% off the encrypted Internet may not seem like a lot, but it represents over 37 million people.

There is also an interesting discussion in Security Now #538 [2] there is also a transcript of the show [3]. Skip to page 2 of 39 just where Leo says "Yeah". Android 2.2 and Windows XP SP 2 are on the list of things that don't support SHA-2. These devices exist particularly in the developing world. It sends the wrong message, to the developing world in particular, if we don't support HTTPS for them. It encourages websites in areas where it isn't 1.69% of their users but maybe 5% of their users to just not enforce TLS. TLS with a SHA-1 signed LV cert is better than no security at all.

Facebook's also has a cool server add-on to dynamically serve LV certs to those who need them is very promising. If it is in-production at Facebook it is bound to be good.

[1] https://blog.cloudflare.com/sha-1-deprecation-no-browser-lef...

[2] https://www.grc.com/securitynow.htm

[3] https://www.grc.com/sn/sn-538.pdf

My team added something four weeks ago that might be an idea to try - we're still trailing it ourselves. It started accidentally and became a tradition on our team though so your mileage may vary.

If the pull request is small, fixes a bug or is a blocking you, then you can spend you quick-code-review-chip for the week and ask the team to look at it at their first available opportunity. (Sometimes reviewed within 15 minutes, usually an hour tops)

It allows team members to ask the rest of the team to unblock them quickly. Limiting it to one a week prevents abuse of their team mates' time and encourages all team members to plan their work out ahead as to reduce blocking.

We also wrote a quick HipChat bot that keeps track of who's spent their quick-review-chip too.

I completely agree that how can you get blocked waiting for a code review? Some concurrency is wonderful for avoiding being blocked.

In work I currently have 3 pull requests open all touching different sections of the product. The 3 PRs are all at different stages of the review process. For example, I'll be closing one first thing tomorrow and deploying it out (don't like deploying in the evenings - its bad luck). Another I just opened as I left work today, so I doubt anyone's reviewed it yet.

I'm sure Quora has a big enough codebase and not enough developers (like most companies) that they always have a list of things a mile long that they would like to do or should do, be that new features or just refactoring.

2-3 days isn't long for a review and iteration cycle in itself. I have one PR that is currently open for 5 working days at this stage. We decided that it didn't quite fit the bill on the first draft . It is blocking progress on two other tasks in our backlog but we also have 14 things on our backlog of goals for this week. The team is working around it while we finish it off or create issues for things we think have fallen outside the scope of the initial job.

One thing we've noticed alot on my team is that we try and make our pull requests for review as small as possible. We all have a rough guide of about max 500 lines. Sometimes we do go over but its a rough guideline. Smaller PRs are just easier to review for everyone involved. Reviewers don't have walls of code to break through or need to keep tons of context in their head.

Post-commit reviews (or post-merge into master or whatever you process is) is an interesting idea. I'd be curious to see what my team think of the idea tomorrow for a small sub set of our codebase.

If you don't have that much time to write tests I'd recommend integration tests. Then at least you have some tests. Treat integration tests as smoke tests. If there is smoke then you can start looking for the fire. Integration tests are always better then no tests at all. At least they tell you there is a fire even if it is vague in telling you where it is.

Might as well keep all the bug reports in the same thread.

I noticed one more thing on the job posting text: the word-breaking is a little off. Here's a image with one example: http://i.imgur.com/Zuv1Zjc.png CSS's word-wrap: break-word is probably not want you want to be using for that container.

One other thing I noticed but that isn't a simple fix is postings like this one from HubSpot[1] list two locations Cambridge MA and Dublin Ireland but the ad only shows up in Dublin. I thought I'd point it out if you're looking for some more work :D

This is awesome.

[1] https://news.ycombinator.com/item?id=9813335

Have you seen the Acceptable Advertising manifesto [1]? Sites like reddit and stack exchange have signed up. Essentially AdblockPlus one of the big two adblocking plugins has this manifesto where ads are not garbage, animated, annoying etc. won't be blocked.

My guess is that so many users installed adblockers because of obnoxious ads on a few websites they visit without realising that it removes the non-annoying 'acceptable ads' that support the sites they love. Hopefully something like the acceptable ads manifesto will help stem the tide of quite frankly shitty ads .

[1] https://acceptableads.org/

Even calling yourselves the Onion for Startup News is hilarious. The whole 'we're like uber but for ... ' has become meaningless. The pieces on your tumblr so far have been pretty funny.

This industry needs more social commentary along the lines of Silicon Valley on HBO and sites like this. Silicon Valley nails our industry almost every week. It's brutal, but it's reasonably accurate satire.

Does the US not have regulations about UAVs automatically firing of weaponry? Don't all current UAVs have human operators. The so-called "man in the loop". I'm having trouble finding evidence one way or the other but does the man in the loop have to pull the trigger or can he override a pre-programmed fire order. Allowing robots to automatically fire ordnance seems something congress would legislate against -- or at least I hope so.

I'm a little concerned with a swarm of drones controlled by one human. Humans have limited attention span -- they just can't watch 30 video feeds. Could this pre-programmed approach with limited human control lead to greater civilian causalities?

This is a very intriguing move for Intercom. They've gone from offering products that are designed to solely work inside your SaaS product to customer acquisition. A very interesting shift from a company perspective. I'm sure there must be many competitors in the customer nurturing / lead acquisition business who are eyeing up this product release very closely.

I'm curious if it will catch on or if users stigma against livechat will hurt. Have to ask yourself when was the last time you used livechat? I'm having trouble remembering the last time I did.

"Amazon cut off service to Wikileaks, claiming that whistleblowing violates its terms of service. It had no need to go to court to prove this, because if you rent a server from Amazon, you have no rights."

I find it highly amusing that RMS doesn't seem to agree with Amazon's restrictive ToS agreement but his GNU software license is one of the most restrictive licenses out there. If I include a GNU licensed library I accidentally lose all my rights too. Funny that.

"A study found that people who read novels on the Amazon Swindle remember less of the events."

Replace 'Swindle' with 'Kindle' then with any ebook reader ever. I doubt there is anything about the Kindle in particular, over other ereaders, that causes people to remember less. This is attacking Amazon with everything and hoping some of it sticks.

I'm trying not to defend Amazon but RMS's arguments are painfully bad at times.

Slack was hacked 11 years ago

Hey thanks for the long response. I totally get the premise of peppering I think my problem is with this sentiment "A properly implemented, simple pepper can only help password security and can't hurt it".

From all the advice I've read security and crypto they don't work like that. The assumption is the other way around. A properly implemented, simple pepper can only hurt password security until proven otherwise by rigours testing and analysis.

Time and time again we read stories of a tiny implementation detail that created a sly and subtle vulnerability that simehow leaks information about original plain text by interrogating the cipher text.

bcyrpt with a large work factor and a per user salt is a PROVEN method to prevent attackers learning the plain text. Until I see evidence from a trusted cryptanalyst I'm not going to roll my own by adding in pepper they didn't plan on being there.

EDIT: sorry let me make my point a little clearer. In the event that the hacker can access the filesystem or memory -- whereever you store your pepper -- could the hacker use the pepper and an implementation detail in the peppering technique to learn information about the plaintext or the salt? This question is what needs to be answered by qualified cryptanalysts before developers start using peppers wide-spread in my opinion.

Slack was hacked 11 years ago

Is there any significant evidence that peppering passwords helps? I've seen arguments for and against peppering out on the big bad internet. Everyone has opinions but there are few people's opinions about crypto that I actually trust.

The best article I've seen against this technique is by ircmaxell [0]. Nicely summed up in this sentence "It is far better to use standard, proven algorithms then to create your own to incorporate a pepper."

Anyone have source material (academic paper, Bruce "The Crypto God" Schneier blog post) that shreds some light on peppering passwords?

I'd be much more interested in how many iterations of bcryprt Slack were using. That has a much bigger bearing on events for me. Anyone at Slack know/want to answer that question?

[0] http://blog.ircmaxell.com/2012/04/properly-salting-passwords...

Five Years’ Time 11 years ago

I'm also an apiary.io user. I must agree there is something lacking in the hosted API docs space. What I find most lacking from apiary.io is features. They have such a limited way of expecting APIs to behave that it can be hard to represent some things inside the API docs system they have.

I wonder is it is possible to create an apiary.io to readme.io auto-migration tool. Even if it does require me copying the markdown behind the apiary.io docs manually into some tool that spits docs into readme.io. That would honestly save me many hours, probably many hours for many folk too.

I've requested access to the open source pricing plan, after I hopefully get approved it is probably something I'll look into in more detail. I'm in need of a new (probably) needless automation side-project.

Edit: wow I completely missed the free trail. If you're an open source project they'll upgrade you to the Dev Hub pricing plan. Ugh feeling so stupid for missing that the first time around and not getting started 10 minutes ago.

Yeah I agree the hyperbolic sentences are over the top. The only way for anyone to reliably get 100% uptime is to use two or three cloud providers or their own dedicated boxes somewhere. Even AWS don't provide 100% uptime guarantees. Though I think the author's underlying point that good design should lead to fewer/smaller planned outages. However, his statements are over the top in the extreme.

Two whole days of zero service. In this one moment I have lost all expectations of good service from Verizon's cloud.

It doesn't look like customers were given much warning either. This story was originally published on the 6th of Jan. Could you imagine trying to find alternate hosting setup by the weekend if you have any kind of availability expectations? It seems like madness to me. Even if you did move yourself to another host to cover this 48 hours of downtime how likely are you to move the majority of your business over to AWS, Google Cloud, Azure etc.

The lack of notice on this seems to be a bigger issue to me than the fact that Verizon is taking their whole cloud out of service for 48 straight hours.

There are responses in here that say they are in a healthy environment where they "feel great, valued, treated equally, competent and successful". What's the magic ingredient to a healthy working environment for everyone? Or is it just an environment where implicit/explicit bias towards minority groups in tech just doesn't exist? How do you make someone who is a minority on the team feel like a valued and vital member of the team?

I'm a little concerned with the lack of any absolute numbers in the data visualisations in this article. The 'more/less' and 'higher/lower' bars could be very misleading on some of these stats. I can understand that adding numbers can make these visualisations a little more intimidating but is it too much to expect the high/low ranges to have an absolute number on them?

For example in the disposal income visualisation what kind of magnitude of a difference is there. Is the average 2 thousand euro a year lower or 10 thousand euro a year?

What concerns me is that some of these stats can be massaged with the right visuals into producing a difference between East and West that isn't as big a difference as the graph makes it out to be.

Can the OP tell us anything about building their Twitter framework in Swift. Any gotchas or problems they came across building it? Is Swift ready for the primetime. Should I start switching all my apps to Swift ASAP? Otherwise I'm just starting at code in a language I can hardly read.

Personally from my college experience I know that I have used my laptop in lectures for both good and evil. I have legitimately used it to google work, ideas and to open tabs on papers/etc. to read later. I also used to write code in all my programming lectures because programming lectures were dull otherwise, might as well make use of the time. However, there are many times I have opened up reddit or HN during lectures and 'checked-out' as the article suggested.

Sometimes I have paid for not listening to the lecture but the majority of the time it doesn't matter. The idea that I learned my college curriculum in lectures would be a joke. As a computer science student I learnt my trade in the labs and tutorials and interactive courses rarely from listening to a lecturer explain X, Y or Z.

The better the lecturer or the harder the module the more laptops that were closed in my lectures. My compiler design course for example, infamous for being the most difficult module no one dared open the laptop as there was too much knowledge to consume.

Lecturers can easily do a self-assessment survey of how engaged their class is and how interestingly they are presenting their material but how many heads are hidden behind laptop screens.

For the one lecturer who did ban laptops I have to say I went to absolutely none of his lectures unless I had coursework to submit. I found it a bit presumptuous that he could demand I close my laptop, I was not distracting him or disturbing the class.

You don't learn in lectures where lecturers read their slides to you laptop open or not. If the lecturers are going to waste my time with pointless reading of slides then I might as well do something useful on my laptop like my coursework or just read hacker news.

I think this article is blatantly missing the point. Adding two-factor auth is the best way to stop shared compromised credentials (we all know people who don't use a random password everywhere) being reused on every common login form on the internet. Companies like Facebook are not going to issue everyone with authenticated tokens or smart cards. SMS though being a simple hurdle for a determined hacker it is effective at stopping en masse attacks on compromised credentials.

Using SMS as two factor auth for a bank does seem stupid to me as I expect hackers to be more determined to crack my bank account than my Facebook account. Banks have the resources and the long account setup times to allow them to use proper auth tokens.

Is there a better solution that SMS for low risk sites like Facebook or Twitter or my blog etc? Something with the same easy of use portability etc. Is the Google Auth token app any better?

EDIT: login not logic in first paragraph

I think I spent three years in college getting examined on UML diagrams of all sorts. There is so much detail you can put into a UML diagram that means so much, like arrow heads mean class A implements interfface B. I have never seen anyone in work life ever use that much detail. I have done 100s of sketches of class diagrams and sequence diagrams but never have I made one that would fit the rigid rules of UML diagrams.How can there be so many rules for drawing lines between boxes?

I once did create fully compliant UML diagrams for a requirements document. The next day half the team emailed me back asking what all the box types, arrow heads and broken lines meant. Honestly, simple sketches with annotations have served me so much better than following the rigid rules of UML.

Thanks so much for the response. Can you tell us more about the algorithmic changes, or is the HN source code public?

I find the idea that commenters with higher karma having more powerful down-votes slightly disconcerting. My fear is that if people down-vote comments that are well meaning and relevant but they disagree content we will only ever see one train of thought rise to the top of comment threads.

This could start a vicious cycle where voting cabals of power-users form. For example if Idea X becomes popular among some members of HN they will be able to always steer the discussion to talk about Idea X or down-vote a competing valid Idea Y into oblivion. Comment readers could be converted to Idea X, as it is always appearing at the top of relevant comment threads. So now the voting cabal as even more members. Growing the dislike of Idea Y. The cycle then repeats. The discussion is then steered over time by the thoughts of a select few power-users.

Maybe this is just the natural order of things and I'm subconsciously afraid of change. Thoughts?

Is a twenty-something founder going to hire people twice their age in the early days of their company? Unlikely.Twenty-something founders hire people they know, who are usually their own age. Friends from college, or the other twenty-somethings from their last company.

As a early-twenty-something I only know a relatively small number of engineers 30+, and have only worked with a handful. Compare that to the dozens of engineers my own old that I know, and have worked on projects together. If I founded a company tomorrow I know which 4 friends from college I would want on my team, they're all other twenty-somethings.

The only engineers over 25 I have worked with (excluding open source projects) were my bosses at previous companies. I simply wouldn't know who to hire. Anyway, would any self-respecting engineer take a job at a company found by one of their interns or recent graduates from a few years back? I highly doubt it.

In my hypothetical would I really hire someone who was twice my age? Probably not. To be honest I'd be afraid of their experience. I'd feel maybe their my training wheels. They have a lot more experience than me, will their experience take over my company's vision. Part of the mentality as a twenty-something founder is proving yourself, be that to your colleagues, your peers, your parents, or whoever said you just wouldn't make it.

I find it hard to find other twenty-somethings hiring many people twice their age in the early days. Maybe without even realising it a culture similar to that of college creeps in. Every new hire creates culture, and from my hypothetical I don't have a very diverse team to start with if I start with college friends and other twenty-somethings.

Somewhere in the early days no one seems to be spotting the 'culture' problem start-ups are creating. Was this problem unintentionally created? Or was this problem created sub-consciously created intentionally? Would I as a twenty-something founder sub-conciously create a company where my Dad or my even my cool Uncle wouldn't want to work at? Probably.