HN user

switch33

61 karma
Posts5
Comments174
View on HN

Water retention is something but food that isn't as good or yeild that results in not as good food is a even worse problem too though, the specifics about gypsum should be more researched. I suggested transition metals because it's different and it may be safer but even the alternatives associated with fisher are just as scary for food growth too.

https://www.thermofisher.com/blog/mining/can-you-name-all-17...

Some of the elements that fisher might use like gypsum, not sure if any of it is safe either though. Soil needs more research, is what most people think but growing things is getting harder not sure if the opensoil project can cover enough of the problems yet.

A more safer alternative might be using transition metals and post transition metals in plant soil. Though using transition minerals usually results in having to be treated with something that can cover coding soil too.

Large repos make sense or don't make sense based on companies that work with large data or not based on predicate calculus and derivatives usually dealing with repos as well as stories and have more problems with ssds too.

There is lots of problems associated with ssds as well as large monorepos. There are more complicated than people realize but if you did google code jam it teaches them somewhat but needs to be explained too. There problem is stories sort of intersect with programming too. Clockwork with ssds needs to be reworked for google code jams. The problem is elixir sort of works with stories and programming. Predicate calculus and proof theories sort of are the only way programming will really make sense in a world full of ssds. Leveldb could be a more interesting problem for google code jams if it has some newer features too. Conflict resolution is tower of hanoi and that has problems with consensus algorithms and concat too.SSDs need to do derivatives for pieceing and parting software too and that is more interesting too.

The problem is clone is more of a start phase after vfork but before fork regardless for github. So it's kind of a bit strange that we call vfork first but that is about templates too.

As for templates they need to be in different languages and in different formats for video games consoles, and so many other formats they port systems and games that sort of work digitally to certain things but not playable to certain things too.

The other problem is that clone is part of syscall interfaces and part of apis and part of a lot of other things too.

Software is usually verified by some form of hashing scheme like md5, sha-1, or sha-2.

Windows used to run on md5 till it was proven it was horribly broken. A collision could be generated for the typical md5 having two programs have the same md5 disabling the security guarantees it usually provided. Part of stuxnet was believed to be able to overcome the installed package checking mechanisms.

SHA-1 has taken over for verification for a lot of sources including many linux packages. As for it's security it is debatable to a certain extent. There are efforts to port things to sha-2 but it hasn't been officially done yet I think.

Malware persistence is a focus on the malware persisting on the computer or network after infection. It is a very big field considering most organizations use apps from many different software vendors.

When you install an app it can be in source form but it also may contain many different binary(compiled sources). This is problematic. A good example is Hadoop (famous for computing big data problems) contains lots of pre-compiled .jars(java sources compiled).

Static analysis and verification became the go-to standards for a lot of study on verifying binary integrity. But every format and packaged store is different and has different levels of security. There are also more advanced methods or protecting like capabilties(monitoring based on what the apps have access to). A very good minimal for this are some of the libraries released by google including shipshape: https://github.com/google/shipshape

Many companies can no longer get away with just installing a firewall or relying on security products because security is now an "inside problem." Where the software they download from their cloud service(openstack for example) comes from many different vendors. Another example is docker(also many different vendors used to package apps together but provide isolation from the system).

SHA-1 has not been known to be broken, however there are some strange attacks that show that it might be possible it is overcome-able through other means. A prime questionable of how it is overcome example is ssh ebury (http://www.welivesecurity.com/2014/02/21/an-in-depth-analysi... ). SSH ebury seems to be unique in that it during regular execution of the program despite there being no noticeable changes to the user alas from running specific shell commands that are not normally run by regular users it looks not infected/safe.

As for companies installing older versions of software with known remote code execution vulnerabilities or other types of vulnerabilities that are very severe, I do not know of many services or open source software that checks against this! There are however many continuous integration services. Continuous integration services if not done from your company though has problems on verification as well.

A good monitoring practice would be to use homebrew(usually available for most operating systems) to monitor and track what is installed on a regular basis and have some form of whitelist.

Network Traffic analysis for companies is major headache as well. Traffic can be compromised in many different ways. Wikipedia covert channels is a good explanation of some of the complexity involved. There are many tricks for data ex-filtration that make it basically undetectable by normal means (they require some level of active-monitoring). Almost all anti-virus now include network Man-in-the-middle traffic monitoring to do their work.

Anti-virus companies generally have two methods of classifying software as good-ware vs. bad-ware. One is whitelisting and the other is blacklisting. Whitelisting is a selective list of good software. Blacklisting is a selective list of bad-ware. Both methods are generally debatable for which is better. Despite the fact that your anti-virus itself could be compromised usually having an anti-virus provides some level of security.

People despite all this realize that running a company without using pre-made opensource code is rather ridiculous as so much runs on the app stores or third party software sources(outside your company's control).

Security in many cases can be thought of as a castle with multiple walls or layers of defense, but your firewall as being your main wall of defense is a bad decision, because a wall is just what makes your castle stand up to some attacks, it doesn't actively patrol your inner walls for insider threats. Companies need active monitoring systems for access control logs espeically since many common interactions can seem malicious but are just part of people's daily jobs now.

A lot of security is moving to "anomaly detection" where anomalies are jolts of irregularities in the normal business day. Some things that are bad can be parts of normal activity, but done over a longer basis or with extended activity may be hazardous to businesses (a good example is Denial of service attakcs). While anomaly detection is a good trend with smart systems it also suffers from the same "packaging and extending attack surface" like everything else.

This is a short overview of how security works in general, though if you have any questions feel free to ask.

The expression don't quit your day job seems to suffice here. Don't quit your day job until your idea has a platform to rest on. You could always work for few years then pursue what you originally planned, just you will have more startup capital which is a plus.

On a side note, if your idea is a tech based startup idea you can save a whole lot of time/work/effort and money if you read up a bit on microservices, docker, coreos, devops, and selling Software as a Service(SaaS).

"Malware is by definition self contained and can simply be removed. We move the file to another directory, so it cannot be executed."

Wouldn't this require un-obfuscating the exploit page because the malware can be basically innoculous looking like an image file? I ask because I am just curious how the tool manages to do this so automated.

Also, props on starting this company. I have been thinking about starting some kind of cybersecurity startup or newer tech startup for a while but haven't produced much yet.

1) Books are mostly gimmicky just as news are for trading, but I think you should assume %'s should be dependent on how much you are willing to lose.

2)good

3)good

4)Somewhat make it up as you go, but basically you need to make sure some metrics work. Some people are more hype oriented for trading on hype like they will buy stocks that are being talked about more like when the CEO is on the tv talking etc. But every investor should check metrics to see if they make sense. A company has to have some really good prospects for it to be sporting a large future earnings number. Understanding and researching a bit about the company and other companies in that market segment which you can usually garner at the morningstar site.

5. Then invest in top 1 or 2 companies that are in a specific sector on a down day on the market. Make trades that you know will have some returns but will not risk you too much. Tech and biotech are very much growing, but the have risks associated with them. Buy brand names that you know are good. Look at monthly activity and price floors. There are price floors where some stocks will stay at a single price like facebook stood at 75 for a lot of this year or like good stood at 430 for a while before shooting up to 540 on some good news/earnings reports or qualcom which stalled at 70 because of it's china deal being stuck in process.

6.If you buy mutual funds use vanguard. All other ones cannot compete with their low expense ratios. For starting out buying stocks n etfs use fidelity or schwab (i'd recommend either of the two for starting out as an investor, because mutual funds can also fail as well it is good to know how to do regular investing).

7. You should consider the easier route by looking at past few months and past year. There doesn't need to be a particular event for a stock to be a good time to buy. You can also buy a stock based on it's just a time where it got beat up on some random news but is still a good stock. Another thing you should know is growth numbers are fidgety animals. Growth numbers don't make sense for many tech businesses or other types of fast growing businesses. One reason is if you have say 10 enterprise customers paying like a million dollars per year and then you get another 10 customers you suddenly are growing at 50% rate.

8. Diversification is a good start, but since you are starting out i'd choose at most 5-6 stocks, then as you grow change your holdings number for how much you want to risk. You can definitely put more into etfs or mutual funds when you have more money to play with. Mutual funds often have a required minimum to put in.

9. When you are starting out it may be helpful to cut your losses when you are losing a good 30%+ on a stock, unless you think that it will make a real turnaround. This is because generally a good break from the price target can be disasterous and you can always reinvest whatever you have left into something else.

Investopedia is great. You should also look at www.finviz.com . They outline good metrics for stocks in green and bad ones in red so you can learn a bit more to look at. There are other things you can realize from finviz like insiders buying the stock or not. If insiders are buying a stock they think it will go up. If insiders sell the stock they may (or may not) think the stock will fall.

While greater risk can mean greater returns, for most investors a better strategy usually avoids some of the heftier risk in the first place.

People often "fall in love" with certain stocks but that is usually not too good of a thing. When too many people hold a stock that stock can fall from too high expectations.

Apple for instance everyone loves it because they make earnings all the time and beat them. The company has great returns, but it is very bid up. The stocks future earnings as a result are very highly projected, which makes the goal of reaching them harder every quarter. (same goes for some other companies like Tesla)

I would not be telling people to start making money off of shorts as their first few trades. Shorts are much more riskier than holding good amounts of selective monitored companies.

Most people should hold about 5-6 stocks that they can keep track of, but those 5-6 stocks should be well thought out bought on good opportunity timing with good metrics.

Calls and shorts are just for quick bucks. They can make you a lot of money with the right timing, or you could lose it all. It's important to read up and know what your doing before you decide to play with options.

I could have made a lot of money off of amazon when it went from 300 to like 360 or so in a day from the last quarter's earnings based on a call if I made it, but some bad news could have equally made the stock not reach as high as it did.

Instead what I did do was buy and sell the stock like 3 times or so before the earnings report making money each time, because amazon was hitting relatively noticeable support levels at around 300. I was also under the impression that they might make the earnings report but it may be on bad management or something which can result in stocks being devalued.

Amazon is a stock that has good potential revenue in many developing sectors, but it has not made net income greater than it's growing debt in 20 years that it has been on the market. It is a growing anomaly in the world of modern day trading but is an amazingly futuristic company.

Hedging is also something you only really do if you are heavily invested. Like buying a put on the S&P 500 if you have a large portfolio(large as in good % of your money) but you are worried about a stock market crash.

While valuation metrics are one aspect of trading and I do think that most beginners do overlook the basics of them that should be covered before almost any investing.

For real returns it may not always be best to play it by all the metrics. It is important to note that the market itself fluctuates a lot on sentiment and sometimes a good valued holding can turn sour fast even with good metrics but bad timing.

Some companies will over invest in dividends which in turn means they are not investing in growth as much as they could be for instance.

Some companies will try to grow revenues but by focusing too much on the quick buck of short term and will not be as good for longer term with steep competition.

It is also important to note that the market reports of portfolio manager purchases like berkshire hathways tend to report just the stock name and not the amount they hold of that stock. As well as the fact that you do not see how long that portfolio manager generally holds the stock without constantly crawling that site daily. The portfolios holdings are only updated at the end of the day. So you can see recent purchases but you cannot see when they sell them until the day after.

I have been investing for roughly the last 6 months or so out of college. I would have made a good amount of money if I made a few more riskier trades, but I have been mostly playing it safe. So far I've made around 7k or so give or take with some of it being bigger trades than others.

I've made more in some etfs, but haven't cashed them out yet. I have mostly been actively monitoring them with many of them being relatively good single stock investments. I am currently waiting for the market to go down to finally start making mutual fund and maybe some etf purchases at the moment.

So I think I will help you get started a bit.

First a few quick questions you should ask yourself and reply as a comment here if you have time (My responses are in brackets just for some dialogue on it.):

1.How much do you think you should invest in a single stock as a %. What about a % for an etf? or % a mutual fund? (You should remember cash is king for being a personal investor, as you are not a mutual fund who has to meet certain wins you should play things somewhat safe for starting out)

2.How much time do you have to spend watching the market? (It is important to watch the market at least a few minutes a day whether it be by phone or by tv or just looking up at least what the market is at and some of your holdings)

3.What news items(twitter, finviz, morningstar etc) do you think are important for trading? (personally I like finviz, morningstar, and seeking alpha. Although it is important to note that most investing advice is just opinions and not all fact checked in every case. Twitter is a horrible idea for sentiment analysis because anyone can say anything out of context in only 140 characters, but seeking alpha is a decent amount of sentiment with some structured information about the well-being of the investor's mindset with some backed information in most cases.)

4.What market data should determine your trading? (What metrics do you think you should pay attention to? What level of risk seems worthwhile?)

5.Do you prefer an active concentrated approach to investing or a more diversified approach? (even warren buffet makes most of his money on 5-6 stocks but owns tons for diversification, but you are more likely to buy indexes or etfs for diversification as an individual)

6.Should you buy/sell on your own or are you better off using etfs and mutual funds some of which are index funds? (Most people do a bit of both but buying mutual funds or etfs are longer investments than daytrading stocks. You can save yourself a bit of trouble by using bogleheads passive investing portfolio to pick mutual funds: http://www.bogleheads.org/wiki/Lazy_portfolios )

7.What are some criteria or timing events you can think of that would be a good time to buy a stock? (This is important because it shows risk timing.)

8. Should you concentrate in one sector of stocks? (This can work if you really know a lot about that sector, but it is rare. I have been fairly successful with trading mostly tech and some biotech lately but tech is still very risky)

9. How long should you hold a stock for? Do you ride it to what % of loss? When do you know when to cutt loses and move money elsewhere or take winnings and cash out? (This greatly depends on the stock of course, but I think the answer is basically you should in most cases be ok with looking at trends of the stock's day range. If it breaks below it's normal day trading range it may be very bad news and you should consider selling it. If your stock goes up think about it as will it do better next quarter by beating earnings. And what about the general market as well?)

As for actual trading brokers in my opinion there are 3 good ones: fidelity(has the most safety/trust for your money), vanguard(has the best mutual funds with cheapable/do-able expenses with great returns), and schwab(very beginner invester friendly, and I plan to join them when I will pick up trading more).

An in-house project would take a long time to develop most likely.

If you want to develop a large service providing project like an e-commerce site then you should read up on microservices if you haven't read up on them. Microservices basically split a lot of project logic into smaller components and workers usually that basically each are tasked with very specific things.

Netflix is a perfect example of microservices, where data is tracked throughout the whole application, there is a good caching layer, and everything is logged/meant to be restarted if it fails etc.

Building distributed services using finagle(from twitter), and hystrix(from netflix) as the start of the backend can be helpful as a start for relatively any project.

Ingesting large amounts of APIs can be done with a distributed architecture using several seperate akka clusters. This ends up being a bit more complex but there are good resources for this out there, some of which were developed for the company "fab" which has docs online like these: https://secure.trifork.com/dl/goto-berlin-2013/GOTO%20Night%... .

Even if you are developing something in-house odds are if you don't want to break the budget then you should find good parts that are already are working very well out there.

If you want more specifics, ask a more specific question though.

I am also wondering of some companies have made money off these things.

I know of some examples off the top of my head, but I don't know too much specifics on how the idea came from or what exactly the sell/how they make money. I think a lot of the money comes from investors until they really start selling a product, and selling a product of just information is somewhat hard I think.

For example:

Mattermark-> tracks startups and provides info for VC firms and regular joes

Dataminr, StockTwits-> Monitor twitter for viral events or breaking news

Elixir is usually the best bet for high throughput with low memory requirements.

But I think you should read some presentations about microservices before you decide to code a giant new architecture. There are other solutions already developed. A guide on the mindset of microservices that is useful is well written in these two articles: http://www.pwc.com/us/en/technology-forecast/2014/cloud-comp... and http://www.tigerteam.dk/2014/micro-services-its-not-only-the...

Xing used elixir/erlang built an rabbit mq, riak, and redis based service that seemed like a good build for scaling a large system with minimal memory and latency. You can watch that video here: https://www.youtube.com/watch?v=38yKu5HR-tM

For scaling microservices you generally want to use http and queueing services for distributing the messages. There are many options in this retrospect. Redis and RabbitMQ are some of the better ones. Something newly being developed but could be of interest is syncfree: https://github.com/SyncFree . The reason syncfree is a good fit for a distirbuted service is it will not get bulky from updates based on timed services. For the rabbitmq version of riak: https://github.com/jbrisbin/riak-exchange

An alternatives to riak is hibaridb, but may take a bit more work to get functional with other stuff: https://github.com/hibari/

With http APIs you can just curl into your APIs. Or load balance and proxy them with HAProxy, Nginx, Varnish etc. Amazon has route53 for managing it by dns. There is also zonify: https://github.com/airbnb/zonify

Microservices are also usually built on some form of actor framework. Akka is what Gilt used. You can watch a video on Gilt's microservices: http://tech.gilt.com/post/65070094551/gilts-kevin-scaldeferr... .

Serialization is just as important in microservices for scaling up small microservices to handle larger loads. For example, when Gilt wanted to scale they used Jackson json serialization. Jackson (www.github.com/fastxml/) is fairly scalable because it is as fast as protocolbuff and has support for hierarchies. They also used the sbt runtime packaging for automatically re-creating and re-compiling their components. They built components using ClusterMate (https://github.com/cowtowncoder/ClusterMate) I think.

You might be interested in a startup that hook's github gists for microservices at hook.io .

As for updates they often use pubsub architectures. I think Gilt used one as well. You can infer a lot of what they did from their released github code at www.github.com/gilt/ .

Other resources to read about microservices: https://news.ycombinator.com/item?id=7994540

Disclaimer: I do a lot of reading, not a lot of building. Though sometimes a lot of reading means reading research papers, and whitepapers from companies to get an idea of what works or not.

[dead] 12 years ago

"That could work completely offline and sync transaction data periodically with the central server."

From what I've gathered you want the app to sync data when possible but still work as it should when offline? There are several solutions in the space of this.

A simple solution would be to split or abstract the logic with handling the data versus the functionality of the mobile app itself. In which case you should not be tied down to specific backends.

Anything that works for mongodb or other databases you can usually find something that converts said backend to something working for postgres or whatever for server side.

As for mobile your data backend should be something lightweight and it may be beneficial to use something that is agnostic to mobile like html5. Key players for web data usually are Indexedb and somewhat basket.js : https://addyosmani.github.io/basket.js/ . As the web is usually the way of using what mobile apps are using for storage gathered from a look at angular.js in retrospect.

Some of the other stuff you mentioned:

A more accurate terminology for what you may be looking for in the future for communicating with several distributed systems would be a CRDT key-value(for example; https://github.com/dominictarr/crdt ) if you want it to be purely distributed over many devices completely and provide the same updates to many devices. There is still a lot of on-going research in the area with Riak and Redis having somewhat successful uses in the box at the moment. A newer idea is something called SyncFree: https://github.com/SyncFree

As for resolving git transaction conflicting updates there is a solution that is being developed talked about here: http://the-paper-trail.org/blog/subverting-sinfonia/

A more json version for updates would be something along the lines of: https://github.com/Operational-Transformation

"I was able to learn the tools easily because an expert in one of the tools, and worked on it for 3 years. In the mean time, I lost all my programming skills. I now don't have any programming skills what so ever."

If you are expecting to pick up a new language you cannot expect to code at the same speed as the programming language you have been working on for quite a while with. But that is not necessarily a bad thing.

C/C++ have huge changes in the language updates as well so it is not too suprising if you think you have unlearned some of them. In retrospect maybe you just learned some of the algorithms rather than just learning the languages themselves when doing the languages. To re-learn them i'd look at more used libraries for C++ like libmusl and be aware that real programming is not all about just algorithms.

Instead of picking a new programming language to learn maybe you should learn a bit more about the "ecosystems" of languages. While almost all programming languages are good at almost everything, there are a few special "sweetspots" of coding in specific languages.

Some example questions you should pay attention to: Why are some programming languages used more than others for specific situations? What is the difference between a scripting language and a normal functional programming language?

Some of those questions have somewhat obvious answers. Many of the languages now are specialized in a few things. Erlang is great for passing data around. Rust is good for recoverability with a server. Go is good for concurrency patterns (but fails on some degree where concurrency patterns are not just steady/simple). Ocaml is good for security based programming because it is a static language(one instruction/way of executing for most of the language) it is also used entirely by at least one company that operates in the space of trading. Python is good for computing with numbers because it automatically can handle large numbers and can be easily convereted to C/C++.

I'd suggest learning the ecosystem of what drives what in a specific category. For instance do you want to get into machine learning? reverse engineering? devops (automated deployment)? Picking some skillset that is out there already that is highly valued and then learning about programming languages by viewing what companies are doing is a good way to learn. You see business decisions that are made based on programming language, time, money constraints, and it's not all just about what they just had at the time for the bigger tech companies because if it sucked they re-coded it.

If you have any specific questions you can ask away below.

Crypto insecurity is just one of many concerns and it is missing somewhat of the point. There will always be debate over it.

There is a chilling effect that big tech companies in the US have been working on side channels for nearly any protocol that is ever developed. There needs to be research into side channel resistant crypto as well.

But what about the bigger growing trend in computing that is causing more troubles (dependency growing system wrappers)?:

Has anyone else noticed the trend for wrappers over increasingly larger and larger parts of operating systems? For example systemd (https://en.wikipedia.org/wiki/Systemd) while good for providing automation provides even more system administration power by controlling package managers.

Docker contains configuration information for the full app that is being deployed contained within that container as well. It will take quite some time to make docker more secure, and using it may contain some level of attacks.

And hypervisors as well are larger and larger in size as well. There is becoming an increasing standard for the amount of code in frameworks, platforms, operating systems and more for interoperability.

While these are good things that need to happen as fixes need to be quicker, they are also bad things in that they provide newer larger attack surfaces. Cloud computing is also becoming more and more rewarding for heavyset computation and sharing of resources. The ambiguity in choice of it all means that there will inevitably be a plethora of choices in the cloud.

The dependencies in frameworks and how we develop software has continously grown over the years as well to the point that people are using things like versioneye: https://www.versioneye.com/ to sort changes in it all.

While diversity is good and the cloud ecosystem is becoming more profitable. Why is there almost no security company focused on making the "cloud" tamper resistant? (i.e. monitoring docker containers and looking for misconfigurations etc even on github) There definitely should be a working effort in that retrospect.

It is also equally problematic that cloud software will be ambiguous in design. Cloud software that is built to be fast may use a custom in-house Just-In-Time code engine for faster database or code execution which may be harder to really address security wise.

In retrospect there are many security companies that are working towards securing the appstores, why should they not be working towards securing/integrating with cloud providers?

There should also be more opensource security anti-viruses besides just clamav. For people to be secure there should be a newer trend into opensourcing specific security modules and working towards a functioning operational level of configuration/management security as well as malware detection.

I didn't know that app analytics was such a big business. Is this because you recently acquired distimo and you are cutting the slack?

Sounds interesting, how much do you think you would be willing to sell it for? I am not sure I am really interested in buying it really. How does it compare to some of the competitors: http://www.flurry.com/ or http://www.localytics.com/ or http://www.mixpanel.com/ or http://www.upsight.com/?

"It's hard to sell it, but I think it will allow me to focus on other areas a bit better."

What do you plan to work on next?

All of IT 12 years ago

Too long didn't read summary: Ask open questions, provide people with code, talk to them how they would find answers or improve it. And spend a little bit of your time learning some IT if you expect to hire anyone decent.

The problem is that there are many limiting factors in questioning surveys and what you are testing them on. And determining a person's aptitude for technology is a very subjective process. Do you test their resourcefulness by asking them what sites they visit and learn from? Do you test their actual programming ability by having them do a live coding that could be too specific case? Do you ask them about terminology which just shows they may know some buzzwords?

Google for a while gave up on asking algorithm questions supposedly for a certain subset of jobs they had.

I think as IT is getting more specialized and there is a difference between people knowing certain things it is important to have some form of domain knowledge which can be in the form of terminology quizzed, but at what level is up for debate. But maybe a more open question format would be better.

I think always presenting the interviewer with the code and having them look it over then provide input is maybe a better fit. It is like math, everyone wants to just use a calculator but in school you use your head at first for a while, but eventually everyone in a work environment uses a calculator anyway.

The computer questions should be the same, they should have access to a computer. They should then be quized on how to reason out this x code and how can I change it to be more like y. They need to be problem-solving questions, that use some critical thinking but also involves some reasonableness to them. Some may ask terminology, but it shouldn't be the main focus.

It also does not help that employers don't know what to ask for their tech jobs as well in many cases. If someone wants to hire a web developer they may just copy and paste and re-write the job requirements of a random posting they find online. This is what I imagine happens 90% of the time. The reason why job posts are such crap is because when someone posts a new requirement they probably all just update their templates that they had before-hand. It's technological ignorance at best!

What is getting worse is also specialization in different sectors of computing is just confusing companies more-- Devops, machine learning, security programming, etc etc. And as computer literacy is improving in population yet code is getting automated more and more there is becoming an increasingly difficult question of what is necessary to learn for aspiring programmers who will be joining the workforce.

A few good devop team can easily be more productive then 3 times the size of it in developers if the developers know nothing about devops.

A few good machine learners can solve real problems with data mining that may save a big company millions that a group of programmer interns wouldn't know how to do.

A few good pentesters can find holes you completely missed and need to patch providing your company from losing tons of credit cards through an open point of sales or losing important company data.

One funny way to see experience in IT security is to simply ask are we getting more safe, or less safe security wise. The answer less safe shows that they have been working in the IT security field, however if you ask researchers at universities they may not know about the level of problems in the security industry being so prevalent but they may still be good fits for specific research.

It is hard to manage which are necessary, and it is also hard to address skill level. There are many groups of interns now who could easily possess such skills that may be of way more use than people know as well.

Many companies rather hire a student out of college than a phd student because they may have some interest in some of these things and because he may have some sample projects or notice in communities even though he may not have specialized skills.

One of the most major faults though is that we have tons of jobs that are not using any technology at all and involve 0 programming, while others that are entirely programming. The future of programming should adapt to things where there are jobs that have people do both. Project managers and devops people should be developers as well, not just people who manage but coders. But this is only applicable to certain technology focused companies, which is becoming harder to reason not to be technology focused.

For the reasons above I've actually been learning on my own lots of diferent technologies way before trying to get a job in IT. However, IT is still too rapidly changing to learn "everything", but people can benefit from learning how big companies like yahoo, reddit, facebook, netflix, linkedin etc deploy their infrastructure to handle large amounts of data. They can also learn security and machine learning as well as other more special skills which can get them a job or even better start a startup. With the ease of setting up a Software as a Service, it is becoming more approachable to start a startup then to get locked in the horrid cage of mismanaged companies as well.