HN user

talon88

164 karma

I write a lot, both in and out of work.

[ my public key: https://keybase.io/seansli; my proof: https://keybase.io/seansli/sigs/FwfhOc9AavfCb9DI2onOAMdsOOZRH4yJ_pwue3wihVA ]

Posts2
Comments23
View on HN

"Perhaps financial renumeration, while fair, isn't entirely necessary"

Is it that in your world, eating and paying the rent isn't necessary either?

'Many' creative people sounds like some programmers, which is somewhat small subset of all creatives. I'd be surprised if the majority of creative people — artists, writers, actors, and more — would happily go about saying that financial renumeration doesn't matter to them.

Destin, for example, puts a lot of effort into his videos and his work. Financial renumeration not being necessarily inevitably means Destin does something else for the majority of his time and does Smarter Ever Day less (if at all). This is almost certainly the same for every other artist out there. Sure — maybe all art isn't necessary. Maybe some of it is crap. But saying that being paid to be creative isn't necessarily means that you get very little art, if at all.

This is not common in the gaming industry, nor is it professional, nor would it likely be legal in the United States. Given that they're in Germany, though, I'm less sure of the laws there, so I can't speak to that.

Honestly, though, even if it were common, I would still not want to work on a team like that, and not just for idealistic reasons (if you allow things like that to happen you're just letting the industry continue to be racist, sexist, etc): that behaving from a team you'd be working with would reflect poorly on your career and your future, as the explicit racism would likely also exist implicitly in performance reviews, compensation, and future recommendations.

In your first line, you say to drop Dropbox due to lack of client side encryption, and in your second line you mention that you can just roll your own while still using Dropbox...?

I have had just about nothing but pleasant experiences with the cops. I was an EMT for three years, and the cops that I worked with on a daily basis were the ones that got me — and others, including druggies that ODed, domestic violence victims, and suicide-attempts home at night.

Of course, the natural extension is to say 'well, who has pleasant experiences with cops besides other cops and EMTs and firefighters'?

Even after I moved out here to SF and into Bayview, I still had good experiences with them, meeting them on walks home and pulling up next to them on my motorcycle.

Yes, there are bad cops, and we see articles like this, but that doesn't mean that all cops are bad, and saying 'all of them are fucking pigs' undermines the entire system, and only makes things worse. The bad cops should be ejected from the system, the good cops should be commended. The system itself isn't broken, and treating it like it is just makes it worse.

Coin 13 years ago

Try reading the FAQ before your vomit more words onto the screen.

Oh my God, a new Ted Chiang story.

I have to say, having read everything he's written, I'm curious what a full novel would look like, though I'd be happily content if he just came out with a short story/novellete/novella a year forever. He just puts so much thought into his world-building it's incredible.

It just feels so juvenile — first he doesn't comply, then he says he'll comply, then he refuses to comply, then he's ordered to show cause and represents himself (!), then he prints out the encryption key in 4-point font in a clearly noncompliant gesture.

Yes, there are privacy issues at stake, but there's a much more mature and reasonable to way to conduct oneself than it seems like he has.

I find the drip-feed of information a really interesting choice, though I'm curious of its efficacy versus the wikileaks style dump.

It keeps the news alive for a longer period of time, sure, but it also means fewer eyes are looking over it and connecting the dots between various different pieces of the revealed information.

Wouldn't it be better if everything was revealed at once, and the various investigative reporters out there all got to go through it independently and write up a cohesive summation of the results, instead of this two-three page exposé per day?

I'm not sure it's really 'journalism', per se, as it is flowery language complaining about something with vague metaphors.

Not speaking for the security team, how likely would it be that this was an attack using reused passwords from another website?

How likely, specifically, is it that someone got into one or multiple employee accounts, found the admin console password lying around (or in an onboarding email that wasn't deleted, or in chat logs), and then accessed the internal admin site? The list of what was taken looks like it's straight from what a Support Rep would need to deal with password resets, OTPs, etc.

Breach is generally detected in one of two ways - information is sold and that leads to scrutiny when users write in, and/or you have auditing mechanisms (ip geolocation, for example) which points out behavior that does not seem to be correct.

Once you see this, you run through a full audit of all of your accesses, searching for things that don't fit a pattern. Logins of your admins — did they login at some time that they don't usually? Was there a login from a Russian/Chinese/Unusual IP? Did someone go into something they usually shouldn't? It's not an exact science, which is why it's really hard to do — you may never be sure what exactly was compromised.

Finally, how likely it is that other sites are breached: highly likely. The problem is that when you have leaked email/passwords, there's a large number of people that reuse passwords, and those people can be working at Blizzard, banks, or other companies. Unless they have proactive intrusion detection scanning in place, you don't know until after they've come in, looked at what they wanted to, and left.