HN user

sveiss

548 karma

@sveiss on Twitter, GitHub etc. Or, stephen <at> brokenbottle <dot> net.

Posts0
Comments154
View on HN
No posts found.

The parser supports the type hint syntax, and the standard library provides various type hint related objects.

So you can do things like “from typing import Optional” to bring Optional into scope, and then annotate a function with -> Optional[int] to indicate it returns None or an int.

Unlike a system using special comments for type hints, the interpreter will complain if you make a typo in the word Optional or don’t bring it into scope.

But the interpreter doesn’t do anything else; if you actually return a string from that annotated function it won’t complain.

You need an external third party tool like MyPy or Pyre to consume the hint information and produce warnings.

In practice it’s quite usable, so long as you have CI enforcing the type system. You can gradually add types to an existing code base, and IDEs can use the hint information to support code navigation and error highlighting.

Emphasis on the "something like": there are several different drugs in this class (triptans), and it might take a couple of tries to get one that works for you.

Personally, sumatriptan doesn't work reliably, rizatriptan makes me feel super woozy, but eletriptan works well and without noticeable side effects.

Not really.

Immigrant visa issuance is discretionary and unreviewable, as this judgment has just confirmed.

Adjustment of status, which is the process to obtain permanent residency within the US, is also discretionary for family-based applicants. The USCIS policy manual[1] lays out what "discretionary" means; roughly, it's a balancing test where the positive factors need to outweigh the negatives, and in the absence of any factors in either direction, the fact that someone meets the minimum requirements for a benefit counts as a positive.

The person in this case thinks they're suspected of being a member of the MS–13 gang, and was denied the visa on the grounds the consular officer believed he sought to "enter the United States to engage [...] in certain specified offenses or any other unlawful activity"[3] (internal quotes removed).

Those facts wouldn't go away if this individual applied for adjustment within the country. USCIS would almost certainly decide this case warrants an unfavorable exercise of discretion and deny the I-485 application for adjustment.

As for the new policy[2]: there's a procedural bar to adjustment of status for people who entered without inspection. The new policy offers a route for some people to apply for parole-in-place--which has been available to undocumented spouses of military members for well over a decade--which removes the procedural bar to adjustment. The discretionary test above would still apply.

The new parole-in-place policy also has a discretionary test, and applicants must not "constitute a threat to national security or public safety".

So this person is ineligible for an immigrant visa on security grounds; would also be ineligible on procedural grounds if they crossed the Rio Grande; would still be ineligible on security grounds anyway; and doesn't qualify for the new relief to begin with!

The only benefit they would gain by crossing the Rio Grande would be the ability to spend a lot of money on further court appeals that would ultimately be denied; consular non-reviewability only applies abroad. But the new policy doesn't affect that one way or the other: anyone on US soil is protected by the Constitution and has recourse to the courts.

[1] https://www.uscis.gov/policy-manual/volume-7-part-a-chapter-...

[2] https://www.uscis.gov/keepingfamiliestogether

[3] https://www.supremecourt.gov/opinions/23pdf/23-334_e18f.pdf

Less fraud, not zero fraud.

Even if your bank sends the cheque for collection and waits for the payor bank to confirm there’s funds there.

The cheque could have been stolen and forged, or a legitimate cheque could have been altered. There’s even an example up-thread of a bank recycling account numbers. The owner of the bank account it’s drawn against can take weeks or months to notice that the fraud has happened, and when they do the transaction can be unwound leaving your bank liable to return the value of the cheque.

When I used to deposit US cheques regularly in the UK, I’d be offered the choice between “negotiation” (we assume the cheque is good and will pay it this week) and “collection” (we’ll send the cheque back to the US and only pay you when we collect the money weeks later), but in both cases there was language on the form making it clear that they could pull the money back up to years later if something went wrong.

There’s literally no way of implementing cheques—-or most other payment rails—-without someone, somewhere choosing to extend credit and deciding to take on that risk.

SFO’s involvement is that they own or lease the roads and parking lots where the pickups happen, and so have the right to set conditions on their use.

Parking enforcement isn’t automatic at parking lots without barriers either, but that doesn’t mean paying a parking fee to the operator is a “voluntary payment” just because you might not get a ticket if you do skip payment.

As for how they could enforce it, it’s pretty easy to walk around outside the airport and spot the cars with Uber/Lyft decals, or multiple phones, or use ANPR to identify frequent visitors, or just ask passengers as they get into cars. Multiple options for enforcement.

The enforcement might end up targeting the drivers rather than Uber itself, but it would have the same effect.

CLEAR is more than ten times as expensive as PreCheck: $189/year vs $15.60/year. That's likely enough to keep the queues low.

PreCheck (or rather Global Entry at $20/year, which includes PreCheck plus immigration/customs priority) is worth the cost for me. I'm an immigrant, so the US has already done several checks into my background and has many, many copies of my biometrics already, so there's no additional privacy loss.

I could afford CLEAR, but the value just isn't there for me.

PreCheck reduces the intensity of the actual screening: walk-through metal detector instead of millimeter wave scanners, can leave your shoes on, keep liquids/laptops/etc in bags, and at airports with a mix of 2D X-ray and 3D CT scanners for baggage, the PreCheck lanes are more likely to have the older X-ray scanners.

The reduced scrutiny is the justification for the fingerprinting appointment background check. I haven't seen anything similar in Europe, but busy airports are far more likely to have an efficient security setup that can already cope with leaving liquids in bags and the like. Many US airports still have security checkpoints that look like temporary installations, with portable equipment--even when they're brand new redevelopments!

Usually, the queues are shorter for the PreCheck lanes, but this isn't guaranteed.

CLEAR replaces having an an agent compare your face to your ID with having a kiosk compare your biometrics. The real advantage comes from having a CLEAR employee then walk you past the queue to get by the normal ID checking podium.

You need both to get the guaranteed short queue and the less intense screening.

(And then there are the programs to expedite the immigration/customs process too, but at least those include PreCheck, so you don't need all three...)

The disc acts as a licence key. The game itself doesn't get read from the disc after installation--that would be far too slow.

The disc versions of the consoles are popular for people who like to buy games second hand and/or trade in after they've finished playing; it's frequently much, much cheaper than digital purchases, even when the digital versions are on sale. There are disc rental services like GameFly, too.

Of course, the manufacturers would prefer to kill this secondary market, so sooner or later I expect the disc drives to go away completely. That was Xbox's plan around a year ago, per some recent leaks, and if one does it the other certainly will as well.

You can visit home, but you might end up stuck there.

Leaving the US as a non-immigrant always carries a small amount of risk: CBP can always decide to refuse your next admission, even with a visa. After the recent spate of tech layoffs some H1-B holders have been asked to show recent payslips at the border to prove their continued employment, for example.

If you’re super unlucky (with your citizenship, or even just sharing a name with someone on a list) visa renewals can be delayed by months to years for security checks (“administrative processing”).

There are also some green card routes which require a period where you simply can’t leave the US without abandoning your application, after which you’ll be refused entry as a non-immigrant and will need to do the entire multi-year immigrant visa process from your home company. H1-B holders avoid this, fortunately, but TN holders and tourists who get married and decide to stay can get caught out here.

tl;dr: the US immigration system is actively user-hostile.

Someone who has money as the primary criterion for where they work.

The implication being that they're likely to jump ship as soon as anyone else makes them a better offer (and that they'll be at least semi-actively looking for that better offer while working for you), and that the quality of their work output suffers because they're not sufficiently passionate about the problem to be solved.

They're the opposite of "missionaries", in this particular vernacular.

This is common for medium or larger companies.

Instead of paying monthly insurance premiums, the company directly funds the claim payments as they come in. They outsource the work of adjudicating claims, negotiating with providers/facilities, cutting checks, setting approval criteria and first level appeals to another company, called a Third Party Administrator.

Now, who happens to have all the skills and expertise to do the job of a TPA? The big health insurers. These are giant companies with many lines of business. One of those lines is selling insurance to individuals and small businesses, another is selling administrative services to larger ones.

Note that even with a self-insured plan, there’s often insurance involved too: the company will buy a separate “stop-loss” policy that kicks in and starts paying after the employer has paid out a certain amount in total over a year. This protects them from the risk of covering a plan member with a particularly expensive condition.

Yes, they operate the Aviation Safety Reporting System[1] in the US.

It’s intentionally kept separate from the FAA, which has the enforcement role, to encourage reporters to come forward. The second ‘A’ in NASA is ‘Aeronautics’, after all, so it’s a reasonable place to put this function. Reporting to ASRS comes with a certain degree of immunity to enforcement actions, and keeping it separate from the FAA reinforces that.

They have a monthly publication, Callback, which includes anonymised snippets of reports, with each issue presenting lessons learned and usually centred around a specific theme. It’s worth a look if you have an interest in how the US aviation system tries to prioritise safety.

[1] https://asrs.arc.nasa.gov/

Wi Flag (2002) 3 years ago

I was Dotcher on CoD and ingame, but I don’t think we ever spoke. I didn’t post on the forums much at all, and as a teenager on the wrong side of the world the fan gatherings and the like were a tad inaccessible.

I did a bunch of writing, news posting, collecting information for the monthly patch summaries, and then they figured out I could code and I ended up building tools and maintaining various bits of the site. I think I ended up owning the item database code for a while? I remember hearing that one got used at Turbine, because it was superior to what you had internally!

I’m now married to Kelly Heckman (Ophelea), who was site manager on CoD for a while, and my first real job was at a social gaming startup, getting in the door with the help of her network. That set my career on the path it is now, so you can draw a direct line from picking up that game box to where I am now. So yeah, thank you and the rest of the team :).

Wi Flag (2002) 3 years ago

My marriage and a good chunk of my career trajectory can both be traced directly back to having "grown up" playing AC and writing/coding for Crossroads of Dereth. It's a little scary to think how different my life would be if I hadn't picked up that box--possibly the only copy the EB Games in my small English town would get--and gone "huh, looks cool".

I think growing up during those years of transition, right before the Internet became mainstream and ubiquitous, was a huge boon. Sure, the early MMOs were far from the first international social forum enabled by the Internet, but they were right at the technological frontier at the time. There was something special about inhabiting this massive, 3D virtual space alongside people from across the world, and having that experience be just as novel to everyone else as it was to me.

You couldn't replicate that today, and growing up with the world at your fingertips on a pane of glass as a taken-for-granted fact of life must be a very different experience.

Wi Flag (2002) 3 years ago

My favourite part of this story is that Sandra's handle on the fansites at the time was "srand". A highly appropriate coincidence, given the nature of the bug!

If you weren’t aware, the deadline for opting in to COBRA has been significantly extended during the Covid public health emergency declaration. You get an extra year to elect COBRA beyond the normal 60 days, and it’s retroactive to when you first lost coverage due to your job ending.

Depending on how recent “recently” is, and how long you were between jobs for, this might be worth looking in to.

Right, and last November it hit general availability. You don’t need to be running an Insiders build of Windows 10 any more. That was the announcement I linked.

It shipped via the Microsoft Store, so you have to specifically install it, but it works fine on a fully updated non-Insiders Windows 10.

Hah, thank you, that explains a mystery!

I had a motherboard (an ASUS ROG Strix B550-E) that would frequently freeze when I stood up from my chair. I always figured it was something to do with static electricity discharging when I stood up, but no amount of fiddling with grounding helped. An EMI pulse from the gas lift getting picked up somewhere insufficiently shielded would explain it.

Interestingly, I also have a Steelcase Leap chair, as mentioned by someone else in this thread; maybe the gas lift they use is particularly prone to this? Other people also complained about freezes with this motherboard model, so perhaps the combination was particularly bad.

That’s for HTTP/1.1, where WebSockets are really a completely different protocol which “hijacks” the underlying TCP or TCP+TLS stream from HTTP via the Upgrade request.

HTTP/2 has its own concept of streams, so WebSockets can run over a single HTTP/2 stream, and the linked RFC describes extending the CONNECT method to take over a single stream.

Do you have an example of a cable modem that blocks remote setting updates?

Both remote configuration and remote software updates are MUSTs in the DOCSIS spec[1], and my understanding is that the information in the configuration file is technically required for the modem communicate with the headend for anything more than bootstrapping. There’s no way to turn this off and have a functioning modem.

CableLabs enforces adherence to the DOCSIS spec, and there’s a certificate scheme that ensures that only certified devices gain access to the network, so I don’t see how a non-compliant device that allows users to block updates completely could ever be used with most ISPs. (I’m ignoring the possibility of extracting a valid certificate from a compliant device, of course—I’m talking about buying a non-compliant device off the shelf.)

There’s another configuration protocol, TR-069[2] which is more concerned with configuring the Wi-Fi side, and this is usually under user control in user-owned devices. This might be what you’re thinking of?

For ISP-owned DOCISS devices, even if the user switches TR-069 off, it could potentially be silently re-enabled by a remote software update.

[1] https://www.cablelabs.com/wp-content/uploads/2015/08/CM-SP-O... (section 8.2.2 and 8.2.3)

[2] https://en.m.wikipedia.org/wiki/TR-069

Yeah, if it’s just a modem with a separate router that’s fine, but I think you can get an entry level all in one for around $100 now?

I see at least one on Amazon, but it’s hard to tell if it’s refurbished, which most at that price point are.

If you’re with Comcast, then it’s very likely they do have access to the modem, even if you own it.

A cable modem is somewhat “trusted” from the perspective of the network: cable is physically a shared medium, and a malfunctioning or malicious devices can disrupt service for everyone on the same physical cable segment. There’s no way for an ISP to remotely cut off a bad device.

This means cable ISPs demand tight control of the equipment connected to their network, including remote configuration and firmware updates. Comcast enforce this by limiting activation to a list of approved devices, and there’s a certificate-based scheme to try and prevent spoofing an approved device.

Historically, the cable modem also enforced download and upload speed limits as well, giving ISPs another reason to keep modems under tight control, but I don’t know if that’s still the case.

If you distrust Comcast, then you should treat your DOCSIS device as hostile even if you own it, and put it behind a router you do control instead of using a combined modem/router.

Yes. You’re ticked off a list, so that you can’t vote twice, and that helps spot anyone who does attempt to impersonate another voter.

It’s not 100% foolproof, but it turns out voter fraud by impersonation is very rare, so it’s good enough.

When you think in terms of “make sure every vote we count was legitimate”, then “not completely foolproof” becomes a solid argument for voter ID.

Instead, if you take a wider view and think in terms of “getting the best quality estimate of the will of the voting population”, the argument against requiring ID (in the US at least) is that it would distort the results of the election far more than a tiny amount of undetected impersonation fraud does.

This will vary by country. In the US, there are barriers to getting ID for some groups (you need to go in person during business hours, pay and wait an unknown amount of time, and this needs to happen weeks ahead of election days; this is a barrier to someone without transport juggling multiple jobs and childcare, for instance.)

Other countries see the trade off differently, or use different fraud prevention approaches. For example, I know India uses indelible ink stains on fingers to prevent multiple voting, and in the UK, there is no ID requirement (yet) but the ballots are serialised and the secrecy of the ballot can be broken to investigate fraud allegations. Neither of these approaches would be culturally acceptable in the US.

If you do this, be prepared for the company to call your bluff.

Many places have a policy that invoking legal is a one way street, and once you’ve threatened to sue they will give you the contact details for legal and then refuse to speak to you through normal customer service channels for any reason.

You’re now stuck dealing with the people who’s job it is to mitigate risk, and not those who’s job it is to keep customers happy.

It looks like the approach this takes is to use instrumentation to record which files in the container are used at runtime when run under a test harness, and then build a new image omitting any files/packages that weren't used during the instrumented run.

I think there are several serious problems with this approach.

First, I would be very wary about trusting an image modified like this in production: it would be very hard to be certain I've exercised every code path I care about--including rarely hit error paths--when running the instrumented build. Perhaps a localization file with error messages is only loaded when an error condition is hit, and removing that file converts a non-fatal logged error into a fatal file-not-found?

Removing files also makes it very easy for your CVE scanner to report false negatives. For example, running docker scan on bitnami/redis returns a long scary list, including:

   Low severity vulnerability found in coreutils/coreutils
    Description: Race Condition
    Info: https://snyk.io/vuln/SNYK-DEBIAN11-COREUTILS-527269
    Introduced through: coreutils/coreutils@8.32-4+b1
    From: coreutils/coreutils@8.32-4+b1
The docker scan output on rapidfort/redis is empty, so great, we have no vulnerabilities, right?
   Tested rapidfort/redis for known vulnerabilities, no vulnerable paths found.
This particular CVE is present in chown and chgrp, according to Synk's info link. The same version of chown that sync thinks is vulnerable in bitnami/redis is also present in the rapidfort image:
   docker run --entrypoint=/bin/chown rapidfort/redis --version
  chown (GNU coreutils) 8.32

   docker run --entrypoint=/bin/chown bitnami/redis --version
  chown (GNU coreutils) 8.32
In this particular case, it looks like the original "vulnerability" is a false positive, but that doesn't change the wider point -- by trying to clean up an image by removing files, it's really easy to remove whatever signatures a CVE scanner is looking for without actually removing the vulnerable code. Here, it looks like you removed /var/lib/dpkg/info/coreutils*, so Synk doesn't think coreutils is installed, but some of the binaries are still present.

In my mind, false negatives are far scarier than false positives.

Finally, publishing an image modified like this without further cleanup is being a poor community participant.

For example, Redis is distributed under the 3-clause BSD license, requiring the license conditions to be distributed alongside any binary distribution. Your image removes all of the license files, and your Dockerhub page simply says "free to use and has no license limitations". You're quite likely violating Redis' license, and that of other software still present in the image.

You've also left Bitnami's welcome banner in place:

   docker run rapidfort/redis
  redis 12:06:41.40
  redis 12:06:41.43 Welcome to the Bitnami redis container
  redis 12:06:41.44 Subscribe to project updates by watching https://github.com/bitnami/containers
  redis 12:06:41.46 Submit issues and feature requests at https://github.com/bitnami/containers/issues
If a user does encounter an issue with your modified image, you're directing the support burden to Bitnami, who will then have to spend time in triage determining that a modified image was in use and that their code may not actually be at fault.

I think trying to reduce attack surface by removing unnecessary parts of an image is a noble goal, but I don't think a mostly-automated approach is a safe way to do so. I would much prefer to see the output of the instrumented run being used by a human to guide slimming down a Dockerfile manually, which would produce safer images without the risks of automated post-processing.