HN user

twunde

1,577 karma

My email is my username at gmail.com

Posts38
Comments757
View on HN
www.vaines.org 3mo ago

The comforting lie of sha pinning

twunde
4pts0
pirg.org 1y ago

State Noncompete Tracker

twunde
4pts0
techcrunch.com 2y ago

Exabeam Merging with Log Rhythm

twunde
1pts0
www.theverge.com 2y ago

AWS CEO Stepping Down

twunde
44pts13
kubernetes.io 2y ago

Server Side Apply Is Great and You Should Be Using It

twunde
1pts0
www.theverge.com 3y ago

Red hook's mesh network today

twunde
5pts0
pirg.org 3y ago

Chromebook Churn

twunde
4pts0
github.blog 3y ago

Quieter Dependabot

twunde
1pts0
www.theverge.com 3y ago

How to Replace the Sky [Comic]

twunde
1pts0
www.theverge.com 3y ago

Conference line radio among the Hmong diaspora (2019)

twunde
49pts5
defector.com 3y ago

Meta Will Continue Burning Billions of Dollars Until Something Happens

twunde
8pts6
theinternetsaysitstrue.com 3y ago

13 Months: The Kodak Calendar Experiment

twunde
90pts67
comsec.ethz.ch 4y ago

RetBleed

twunde
15pts2
blog.sentry.io 5y ago

Sentry API Auth Bypass

twunde
1pts0
www.theverge.com 6y ago

Conference line radio among the Hmong diaspora (2019)

twunde
3pts0
access.redhat.com 8y ago

Lazy FPU vulnerability disclosed

twunde
1pts0
www.christian-schneider.net 8y ago

Cross-Site Websocket Hijacking (2013)

twunde
1pts1
www.cs.uni.edu 8y ago

Introduction to the Mumps Language (2017) [pdf]

twunde
67pts42
news.ycombinator.com 8y ago

Ask HN: Older developer hiring platform?

twunde
13pts12
skyfallattack.com 8y ago

Skyfall Attack

twunde
10pts1
events.static.linuxfound.org 8y ago

Google's Migration from 10 year-old RedHat 7.1 to Ubuntu(2013) [pdf]

twunde
3pts3
mobile.nytimes.com 8y ago

IBM has more employees in India than in the US

twunde
4pts1
mobile.nytimes.com 8y ago

A student loan collector must halt collections

twunde
59pts62
www.mcsweeneys.net 8y ago

McSweeney's response to the Google Memo

twunde
44pts7
news.ycombinator.com 9y ago

Bitbucket is down

twunde
8pts4
news.ycombinator.com 10y ago

How do you keep a good work/life balance

twunde
3pts4
www.nytimes.com 10y ago

Electricity Transmission Line projects stalled

twunde
1pts0
assets.thoughtworks.com 10y ago

Thoughtworks November Technology Radar is out [pdf]

twunde
6pts0
news.ycombinator.com 10y ago

Bitbucket experiencing problems

twunde
2pts0
news.ycombinator.com 11y ago

Best resources to learn C#

twunde
2pts2

I can't comment about the minimum number of stores, but I do think its the correct idea. I live in a town of ~12000. We have 6.5 bookstores (including the good local thrift store as .5). Stores/restaurants do turn over fairly regularly, so its still tough, but it certainly seems viable. We get a good number of tourists, which helps but I do think you need a mix of restaurants, and a mix of different types of stores. Even as you go to nearby towns with big box stores, they all have downtowns that are doing ok with locally run businesses. Notably the downtowns all are small business focused with few if any box stores

Within the US, energy prices for are typically split into supply and distribution rates with taxes and fees added to each of these. There are typically a large number of these fees that are passed through to the consumer, but just are bundled together to reduce confusion. An example fee is one for keeping power plants idle as extra capacity for when it's needed. Electricity has a nationwide market with different prices for spot prices vs long term although if you are big enough you can also get a direct contract to hedge your energy supply prices.

The complaint here is that PJM is spending money on upgrading the long range wires and passing that fee in a way that's not calculated for usage but instead it's likely divided evenly amongst member states. If you're upgrading wires in PA why should Maryland pay for that? These would taking in new/higher fees being passed to consumers.

The long range transmission lines are different than short term transmission lines. The long range ones appear someone to hit electricity from a power plant in California for a business in Baltimore.

This is essentially what some 3rd party vendors do, which is why supply chain malware is typically found in hours now and not weeks.

The reason why npmjs, pypy and other public registries don't do this is because it would likely 10x+ the cost of their infrastructure while not bringing in much new revenue. It's also potentially orthogonal to paint customers needs since it could likely lead to downtime or at least block new releases going out

Other airports do have ads for tech companies (Seattle comes to mind) but the concentration is significantly lower.

Billboards are primarily focused on brand awareness since you can't update them frequently and you don't have amazing targeting/attribution data. They're also hyper-geographic specific. For tech companies that means that billboards are most useful when targeting either a specific conference or when targeting people that can make sales decisions.

Sf's billboard space is heavily used by the tech industry because A) you've got a high concentration of consumers for your tech product (developers, marketers, operations, product managers, etc) B) you've got a high concentration of decision-makers in terms of director/VP/execs/consultants going through that airport who may end up making a final decision on your sales. C) you've got a concentration of investors in terms of VC, private equity, angel investors. This helps bring in interest for that next round/acquisition. For your existing investors this means that they've got something to brag about. D) hometown pride. Companies tend to put billboards near where executives travel through since it's a reminder of the work that the marketer is doing. It also helps with hiring and media reputation.

If you compare SF to NYC or Boston, those other cities have a much smaller amount of their workforce in tech (22% compared to 11%). This is especially true if you think about the number of people transferring at these airports. The concentration of customers just isn't there, which is why NYC ads tend to be more consumer driven.

For people to care of would have to be like healthcare. The Change Healthcare breach cost 2B+ and led to a huge loss in market share. Or like AMCA, which went bankrupt after the breach (Labcorp's billing company). If you're a health tech company you can no longer insure your way out of the problem over you reach a certain size.

The reality is that we need data breaches to be painful but maybe not company ending events unless it really is sensitive data. As patio11 likes to say the right level of fraud is not zero. There's a middle ground where we can increase company liability or reduce the damage caused by a beach.

The ROI of Exercise 11 months ago

If you're in the northeast US it's very common to have free or have to pay a nominal fee for public tennis courts (this may depend on the quality of your town's Park and rec department)

In NYC, it's 15/hr or 100/season. In the town I grew up in it's 20/yr for residents and 40/yr for non residents. I'm my current town it's free. And I suspect that there are waivers/discounts for folks that can't pay that amount.

This is much more viable than it was in the past with the advent and adoption of nvm, pyenv etc but the limiting factor becomes system dependencies. The typical example from yesteryear was upgrading openssl but inevitably you'll find that some dependency auto updates a system dependency silently or requires a newer version that requires upgrading the OS.

Something popular in my area, especially in the somatics community, are grief ceremonies ala https://www.earthdance.net/event/grieving-ourselves-whole-ex... although there are several variations. If that feels too new age-y or its not offered near where you live, it may be worth looking for grief groups/bereavement support, either through your preferred religious institution or through the local medical community (they're often supported by your local hospital)

VC funding is often required for companies that require a lot of runway prior to selling. The example that comes to mind are database companies like Mongo, dgraph, scylla etc. These require a fair amount of upfront work to create the product before their usable. A different example are industries that require a fair amount of compliance like healthcare, banking etc

https://arstechnica.com/information-technology/2024/04/germa... discusses some places that are moving to Linux and some places where migrations have been reverted. But from personal experience the main issues are in order:

- Is all your software supported on Linux? Are you sure? Do all the features work or are any missing/broken? Have you tested this or are you relying on Sales or docs that are likely wrong? What happens if one piece of software drops Linux support?

- Does using Linux block any future planned projects or make future projects much more complex?

- You now need to spend time with every new hire training folks on the new OS, as well as retraining existing staff.

- Are you going to piss off a lot of staff because you've made their life harder?

- For compliance/security requirements, do you have everything necessary to easily explain to auditors that these computers have the equivalent security (antivirus, monitoring, mdm all with metrics, dashboards and logs)?

Essentially this boils down to a lot of work, which impacts the future flexibility and the morale of the company in order to save a relatively small amount of money. Often times your spending more money on supporting Linux than you're actually saving.

ChromeOS is a modified version of this argument. ChromeOS comes with a strong security and compliance story, and has easy built in management. There's been some adoption in call centers but primarily it's used in schools by students because the school has been given a grant so gets them for free. Even with all that, very free businesses are adopting ChromeOS because a) some workflow they use isn't supported and b) Windows is not significantly more expensive.

Daily stand-ups, the main benefit of which is that managers (EMs/PMs) get daily updates on status. Sprints themselves which promise that a certain amount of work will always get done, without any free time being wasted.

A lot of the ceremonies in general are mostly helpful to the EM/PM. How many things that you're doing are actually improving how you get work done? Especially when you consider how much time is spent on these ceremonies (sprint planning 1 hr, sprint retro 1 hour, daily standup 15-30 minutes. Plus whatever prep is needed and the interruption time.) For many companies this is a 20% or more overhead that's mainly busywork because you still need the additional meetings to understand what you're working on.

Playbooks that I've found value in: - Generic application version SLI comparison. The automated version of this is automated rollbacks (Harness supports this out of the box, but you can certainly find other competitors or build your own) - Database performance debugging - Disaster recovery (bad db delete/update, hardware failure, region failure)

In general, playbooks are useful for either common occurences that happen frequently (ie every week we need to run a script to fix something in the app) or things that happen rarely but when they do happen need a plan (ie disaster recovery)

One issue I've found with cultures that emphasize no jerks is that the pendulum can swing too far that way to the point where its difficult or impossible to provide critical feedback. Not to say that you need to be a jerk to have difficult conversations, they can and should be done with empathy.

The market over the last 2ish years is significantly worse then it's been over the past 10 years with the exception of Covid due to the rise of interest rates and change in tax incentives. This has hit large companies pretty hard, so there is a double whammy of fewer jobs from the biggest sources and more competition with other engineers. Anecdotally it does seem to be warming up, but it is uneven with significantly longer timelines to get a new position.

So what can you do? 1. Update your LinkedIn with descriptions of all your jobs so it looks similar to your resume. This should include technologies you've worked with. This is basically doing some SEO work so you get inbound recruiter emails (understanding that the quality of those inbounds will vary dramatically). 2. Apply to jobs directly and actually write cover letters (take a look at Who's Hiring, etc).

In terms of new skills or certifications, it's usually easier to add something adjacent to what you already do instead of learning something completely new. If you're a backend engineer, maybe you learn about data pipelines, or cloud infrastructure. If you're a front-end engineer maybe learn to write some backend code using nodejs. Put a side project on your resume, and ideally online.

Parts have been. Sourcegraph is basically the code search post built by ex-Googlers originally. Bazel is the open source build tool. Sadly, most of these things require major work to set up yourself and manage, but there's an alternate present where Google built a true competitor to GitHub and integrated their tooling directly into it.

Its pretty common to see "easy" algorithm problems or potentially build a small simple app as a way to test that you can actually code. I'd say 75% of companies I've interviewed at have at least one algorithm interview with hands-on coding. This seems to be even more true at big tech companies because you're likely debugging software written in multiple languages.

There are some places that are much better about this than others. I remember in Europe several of the restaurants had _books_ containing all the potential ingredients and cross-allergens for each dish. I distinctly remember Wagamama's in London pulling one out and double-checking it due to my spouse's eggplant allergy. Sadly it removed most of the menu that we were excited to eat, but it was damn impressive.

You can't control whether there are layoffs, but you can control how to handle one. Update your resume and LinkedIn, so that if/when you need to look for a new job you're already ready. Also do go out and socialize. If you need to justify it, think of it as networking. There's a good chance that the people you meet, may be able to help you find a new job or intro you to someone.

One place to search is the local Parks and Rec website (for your town/city and potentially nearby ones). your town and/or library may also have their own separate events pages, which can be useful as well. Depending on your interests, it may also make sense to search for climbing gyms, dance classes, art classes and try them out. You can also find some things on Facebook and Instagram, but I find it hard to start out.

Beaver Drop 3 years ago

For anyone who enjoyed this I'd highly recommend reading Eager: The Surprising, Secret Life of Beavers and Why They Matter. My favorite tidbit is that there were beaver ancestors the size of small bears, so yes there were rodents of unusual size in real life

Based on the description they are doing a multi stage build, but using the prod container as a base and then building the dev container atop that. But yes you could easily go the other way with dev building an artifact and adding it to a secure locked down container. This is less typical with dynamic languages that don't typically create a single binary, but still comes up. The downsides are that your prod container is now significantly different and for dynamic languages the fast feedback loop now has a slowish build step

I'm general, it's an anti pattern since it's makes everything much more complicated. The typical reason to have it is so that there are dev tools in the dev container (autoformatter, linter etc) or support for hot reloading and then the prod container is locked down. The other pattern you'll sometimes see is that the prod container will include an agent or a certificate bundle, although it's more common to use sidecars for this.

It becomes problematic because it then becomes easy for engineers to have a completely different container for dev then is used for prod. I recently found an issue where a dev container was using a completely different base and had a different version of node installed compared to the prod container

This is honestly very common, especially for first time managers. I've seen this happen at least 5+ times. Keep in mind that switching back to an IC time doesn't preclude you from being a manager in the future, and I'm fact many people switch from manager to IC back to manager ala https://www.google.com/amp/s/charity.wtf/2017/05/11/the-engi...

In terms of advice, talk to your manager about the fact that you're struggling.

I've used pants at a small company <10 engineers and worked at a company migrating to Bazel with 200+ engineers. Bazel used to take a dedicated engineer 3-6+ months to bootstrap the full setup (creating the build files, seeing up the Bazel server, updating CI to use Bazel correctly including caching) especially since the docs weren't great from what I remember. I suspect that the time could be cut down by now especially if someone experienced with it does the implementation. Given the amount of time necessary for the setup, it typically makes sense for companies with monorepos with 50+ engineers although existing expertise would change the equation.