HN user

txcwpalpha

4,424 karma
Posts2
Comments691
View on HN

The article covers this:

Sadly, having a microSD Express card slot on the Raspberry Pi 5 does not make a lot of sense at this point due to the cost of MicroSD Express card. An M.2 NVMe SSD is cheaper... For those reasons, [we] will not manufacture the HAT, but the design is released under a permissive MIT license, so anybody could manufacture it if needed. Maybe a microSD Express slot will make sense in a future Raspberry Pi 6, as prices come down.

Why is it anyone's "problem"? Nobody said they're being forced to do it this way - just that they are. And I guarantee that there are thousands of other companies out there that have an API-fanout model as well, and might be interested in how Amazon does it.

I don't get the hostility around this article. Nobody is forcing you to read it or to do it this way. If your system is architected in a different way where you can run your whole system on a single instance, then good for you! But Amazon presumably doesn't have that luxury, and others may not either.

The unibody design, while still bad, actually seems to be a bit of a red herring in this case. The article describes that the actual cause for disassembling the entire vehicle was that they had to replace the tailgate, and had to repaint the body to match the new tailgate. Painting the body basically required disassembling the entire truck (which is also ridiculous).

For the painting though, even in "simpler" cars, vehicle painting is ridiculously overpriced and complex, IMO. I've been quoted nearly $2000 to fix a dent the size of a nickel on my basic 10 year old car because the body shop said they'd have to repaint the entire door, then repaint all of the panels adjacent to the door to blend it in. In other words, fixing a dent the size of a nickel somehow requires repainting an area thousands of times larger. It's ridiculous. There must be a better way.

I don't follow. No special support channel was opened up here. The u/AWSSupport user just linked them to the standard "get account support" link that everyone else uses.

I'd also note that a special support channel isn't really needed here. This situation (lost access to account due to owner no longer being available in some way) is a common situation that AWS Support is pretty good at handling through the standard channels.

I don't see how this is a failure at all. Amazon Pay and Stripe are not competitors. Amazon Pay is a customer-facing service that makes it easier for customers to enter their credit card information and use it across multiple websites. Stripe is the backend service that processes those payments for on financial networks.

This announcement is about these services coexisting, not about them competing.

They aren't giving up on Amazon Pay. There's misunderstanding in this thread about what this announcement is.

Amazon Pay and other payments products from Amazon are customer-facing products that make it easier for customers to make payments. Stripe is the backend software that makes it easier for Amazon to process those payments. They coexist, they don't replace each other.

The original statement from Lufthansa mentioned that Airtags fall under the category of "Dangerous Goods". "Dangerous Goods" is a term used by the ICAO to refer to batteries or items with batteries (also refers to dangerous chemicals or radioactive material, but if you look at ICAO guidance about Dangerous Goods, the bulk of the guidance is about batteries).

Hundreds of tags transmitting is bad for the same reason that phone's have to be shut off during flights.

Phones don't have to be shut off during flights. That hasn't been a thing for years.

Any given commercial flight has hundreds of phones, wireless headphones, tablets, smartwatches, etc all transmitting radio signals at significantly higher power than Airtags.

Various airline regulatory bodies have rules that prohibit both devices that transmit wireless signals being carried in the cargo hold, as well as devices that have batteries being carried in the cargo hold. AirTags, while probably not the intended targets of such rules, technically fit both of these categories.

The airline is effectively just saying "we follow the rules we are supposed to follow". In practice, I doubt they care at all, and you're not going to see anyone trying to sniff out AirTags to prevent them from being in luggage... but you're also not going to see the official spokesperson of an airline make an announcement saying "yea go ahead and just ignore the rules, it's fine".

Correlation does not imply causation. A company achieving "record profits" does not necessarily have to be because there was no drop in productivity.

It's entirely possible that a company can have a drop in productivity and record profits at the same time.

Anecdotally, my company had record profits during the period of WFH, and I personally think my productivity stayed the same or improved. However, as a company we also shipped significantly less new features/products than we did in years past (and my opinion as to why is because we had significant organizational delays caused by miscommunication about timelines and priorities (stuff that in theory might have been improved if we were not WFH)). If we had not had a drop in the amount we shipped, it's possible our record profits would have been even higher record profits.

Personal productivity isn't the same as organizational productivity. This is one of the key things at the heart of the WFH discussion. It's entirely possible that you personally wrote more lines of code, but the team still fell behind in products shipped. This could be due to many different factors. One easily identifiable one is that while good employees might be more productive WFH, poor performers are even more poor when WFH, and it becomes much more difficult to actively manage/coach/mentor poor performers when they are remote.

There's many more metrics too, like attrition, or poor onboarding experience for new hires, or inability to coordinate across teams (sure you're producing more personal output, but is it the right output?)

Organizations are more than individuals working in isolation. They're coordinated masses of people that have to work together, and what is best for one person's personal productivity may not be best for the organization's overall productivity.

The public sector builds the infrastructure, often following decades of investment and work.

It does? I don't think I follow. In your list of components, every single one of those is, at least in the US, largely or almost entirely handled by private companies.

The big semiconductor companies are private. I actually don't think there are any notable public entities that make their own chips. Hardware companies (I'm assuming you're talking about things like motherboards, routers, switches, etc) are private. Fiber optics/communications/networks are laid almost entirely by private telecom companies (and there's actually a big push to take this away from private companies and make ISPs be government entities). The article that you're commenting on is all about a private entity investing money into laying fiber and improving the protocols that communicate over it.

I have rarely seen a start up on improving optical fiber or electronic chips.

There are a lot of SMBs working on chip design. I'm less familiar with fiber, but a quick google shows at least a couple, all private.

This gets overlooked a lot in the outrage porn of "Texas bad".

Every single adjacent grid to Texas was also suffering from rolling or consistent blackouts during last year's February winter storm. Oklahoma had blackouts, Arkansas had blackouts, Missouri had blackouts, Louisiana had blackouts.

https://kansasreflector.com/2021/07/26/fuel-shortages-drove-...

The blackouts were not as bad as Texas and had they been on the same grid, it may have been able to spread (and lessen) the pain a little bit, but the point stands that Texas' neighbors did not have much electricity to spare.

This month is a little different because other states do have spare electricity AFAIK, but the links Texas has to those grids have relatively low capacity to share it.

It would not need to cede any authority. The Texas grid already has interconnects with the East, West, and Mexico grids at four different interconnections, and imports/exports electricity through them continuously, while still having its own regulatory authority. The person you are replying to is suggesting to increase the capacity of these interconnects.

There was/is a plan to create a large hub for sharing up to 30 GW of electricity between the East, West, and Texas grids, but unfortunately it was scaled back significantly: https://en.wikipedia.org/wiki/Tres_Amigas_SuperStation

"it's not even hot yet" what?

May 2022 is on track to be the hottest May on record in Texas. It's already hitting over 100 degrees in most of Texas. It does not typically get this hot until July. Most of the country is facing a huge heat wave this last week, and while some of the country got a reprieve this weekend, Texas did not.

For comparison, this time last year the temperature was in the 70s/low 80s. The average high for May in Austin is 86. The temperature this week in Austin is forecast to be over 100.

It's ridiculous that the Texas grid can't handle this, but to say "it's not even hot yet" is disingenuous. It's fucking hot.

https://news.yahoo.com/texas-shatters-heat-record-temps-1805...

https://weather.com/forecast/regional/news/2022-05-06-heat-w...

https://www.kvue.com/article/weather/may-2022-track-to-be-wa...

FIDO weakens security by limiting authentication to just something you have (a device/USB token) and something you are (biometrics) while throwing out the requirement for something you know (a password).

Not necessarily. The specific implementation being talked about in the article is to use your phone as your FIDO device, and your phone has to be unlocked. So the "something you have" is your phone, and to unlock it, you can either use "something you are" (biometrics via face ID or fingerprint), or you can have a PIN/password on your phone to make it "something you know".

I wouldn't be surprised (and I would hope) that the FIDO app or feature on phones would also come with the ability to restrict it via PIN/password even if your phone unlocks via biometric.

I think AWS App Runner (+ Aurora Serverless) could be even better. From what I can tell, App Runner is supposed to be the successor to Elastic Beanstalk and AWS's PaaS offering. App Runner seems a little immature right now (it launched last year and was missing some key features on launch), but it is actively being developed.

I've always been hugely disappointed that AWS doesn't have a better PaaS offering, given Heroku's languishing, and I was hugely disappointed when App Runner launched and was missing some key features... but there is at least a little hope that it's improving.

You've inverted the dependency of the relationship. People don't buy Nabisco because it's at Target; they go to Target because it has Nabisco products, hopefully for cheaper than other stores.

This is true for smaller stores (eg the mom-and-pop corner store or even large stores), but once retailers get to the super-large sizes, eg Target/Walmart, the relationship flips. People go to Target first and buy Nabisco because its at Target. If Nabisco wasn't there, they buy something else, but they don't stop shopping at Target.

Thus, stores absolutely pay for every item of inventory that appears on their shelves except for some new products that might have special consignment arrangements.

Suppliers do not pay for better shelf placement. Stores determine that based on sell through and margin; the products that generate the best overall revenue get the best placement on the shelves.

This is 100% incorrect. As I mentioned in my previous comment, some stores may operate like this, but not all. I can tell you from personal expertise in this space, but also just from a simple Google search about how retailers operate (do a search for the terms: slotting allowance, shelf-space rental, pay-to-stay, pay-to-display). See below for some links to get you started. Big retailers do not own all of the products on its shelves, and they certainly do make arrangements where manufacturers can pay extra fees to get preferential endcap placement, shelf placement, and shelf space. I have even seen agreements where a manufacturer will literally own (rather than rent) a specific shelf in an important store and can do whatever they want with it, as long as they pay recurrent fees (it reminds me of someone owning a condo in a building and paying HOA fees).

Big retailers may of course choose to not sell a certain shelf placement to a specific product because they want to reserve it for another purpose (like another competing product), but as a general rule of the thumb, if you're willing to pay enough, you can have whatever shelf spot you want.

Big retailers will also charge fees to manufacturers for the transportation and storage of the product for when the product is being stored in the retailer's warehouses or being moved by the retailer's trucks (sound familiar to what Amazon does?). The reason they can do this is because the retailer doesn't own the product, the manufacturer still does. The retailer profits by facilitating the sale of the product.

In some situations, big retailers may indeed purchase a block of products, but in every scenario I have personal experience with, the agreement was always one in which the manufacturer was obligated to buy back any product which did not successfully sell in the store, which ultimately has the same effect as just renting shelf space.

Further reading:

https://www.npr.org/transcripts/718711109

https://www.vox.com/2016/11/22/13707022/grocery-store-slotti...

https://www.cbsnews.com/news/how-grocers-wring-extra-cash-ou...

https://www.businessinsider.com/r-wal-mart-to-impose-charges...

https://cspinet.org/resource/rigged

https://smallbusiness.chron.com/rent-space-grocery-store-ven...

No they don't. Stores buy their stock. They can choose to stock other brands or to make their own products, but they invariably have to purchase what they sell.

This is incorrect. I wish people would stop repeating this in this thread. Some stores purchase their stock. But the really big players do not operate like that.

When you go into Target and go to the cracker aisle, Target has not actually purchased all of the cookies and crackers that you see on the shelf. Target effectively rents out shelf space to Nabisco, who then comes in and puts their items on the shelf (or will pay Target to take the product and put it on the shelf for them). The pricing agreement can get quite complicated and depends on the amount of shelf space, location in the store, and can also depend on number of items eventually sold... but the takeaway is that Target does not just outright buy boxes of Oreos and then try to resell them. If the Oreos don't sell (say perhaps because the customers opted to buy the Target brand sandwich cookies instead), Target isn't out any money, because they still got their shelf rental fees from Nabisco.

Going even further, Target also engages in the same type of activity Amazon does with their analytics (including sales volume, margins, customer profiles etc) and use that information to decide who gets to rent how much shelf space and where. Target et al spend incredible amounts of money optimizing this stuff, which isn't far off from what Amazon does.

People have this old rusty view of brick & mortar stores, but the reality is that they've been masters of this stuff far longer than Amazon has even been around. Amazon championed bringing these practices to the online space and became the most obvious juggernaut, but that doesn't mean these other companies are angels.

I don't think they are outliers. I know quite a few people who have attempted the "covid digital nomad" lifestyle (and I myself have some experience as a nomad pre-covid), and although they haven't reported something as entertainingly cringey as posting up on a McDonald's sidewalk for conference calls, they're not too far off.

The logistical problems (working wifi, etc) are expected and avoidable to anyone with half a brain, but the bigger problem is the social divide. The story about the guy in Costa Rica seems to be the most accurate. There is a good amount of disdain for this type of lifestyle, especially during the pandemic. Among my "nomad" friends, the only ones that haven't come limping back home were the ones who successfully walled themselves off from external judgement and formed a "bubble" where they only associate with other nomads. Fun if that's what you want to do, but probably not what most people expect when they embark on this escapade.

I can't tell either. On one hand, this article seems like a response to the hundreds of other articles, instagram posts, blogs, etc we've seen over the past several months that endlessly romanticize these actions. The vast majority of people that I know that have done this, have done so with an attitude moreso that COVID is an opportunity for vacation than anything else. They bought vans and celebrated with gaudy influencer-esque Instagram posts, and then were dismayed when not everyone celebrated with them.

Though the problems like "someone was judgemental about wifi at a campground" are mundane, it can be quite a jarring wake-up-call to encounter if your attitude up to that point was that everyone will think you are some kind of fabulous unicorn for being a nomad. So from that perspective, I am slightly tempted to be sympathetic. And if this article discourages even one person from going on these ridiculous "we bought a van!! aren't we so cool? follow us on instagram!" escapades, I'll be happy.

But on the other hand, while the rest of us were struggling with real problems like being laid off, ill friends and families, and the soul crushing weight of responsibly not traveling, these assholes were out frolicking and potentially making things worse. And now this article makes it seem like they want our sympathy that there wasn't a pot of gold at the end of their rainbow? Come off it.

Unless it's free of DRM and easily copied, backed up, moved, etc,

Even in most of these cases you don't legally own it, either. Even when you buy a DVD, you are just buying a license to use that DVD to consume the content on it. You don't own the content, and it's a violation of that license to copy a movie off of a DVD and onto your hard drive, for example, even if it doesn't have DRM. It's just that the legal content owner typically doesn't come after that type of violation.

When consumers buy a DVD or Blu-ray disc, they are not purchasing the motion picture itself, rather they are purchasing access to the motion picture which affords only the right to access the work according to the format’s particular specifications (i.e., through the use of a DVD player), or the Blu-ray Disc format specifications (i.e., through the use of a Blu-ray format player).

https://www.techdirt.com/articles/20150422/23110430764/dvd-m...

That said, I don't blame Twilio for not catching this

I do.

Twilio is a multi-billion dollar company and there is no excuse for them not having proper security processes to catch stuff like this early. Even if we take the "S3 is hard" arguments at face value, this wasn't a 0-day or some complicated unpredictable exploit. This was an extremely basic misconfiguration on a mission-critical part of their architecture that would have been caught by even the simplest out-of-the-box penetration test or audit. For a company like Twilio to not be doing basic, fundamental stuff like that is a big deal and they certainly should be blamed for it.

Certainly not, and in their layers of defense against this stuff, they should have had processes to train people, audit bucket policies, conduct penetration tests etc, and there's no excuse for them not having caught it before.

But with that said, one of those layers of defense is also using tools that are easy to keep secure so that the vulnerability doesn't appear in the first place. While Twilio isn't "a lone developer", I wouldn't be surprised if the person who did create that bucket on behalf of Twilio was just a lone developer fumbling around in the console. And again, that's no excuse, but it still is an area for improvement.

The problem with S3 is the exact same problem with everything else in AWS. In their quest to be compatible and attractive to every single possible niche use case of the world's largest companies, they completely forgot the lone developer who just wants to upload a couple files.

You'll even see this in their sales pitches. AWS will spend so much time talking about the most advanced use cases and how they are possible, but if you ask them a simple question about how to run a single bucket that doesn't also involve using all of their ML tools and global accelerator and cloudfront, they'll be blindsided. It's almost as if they consider the common use cases to be "too simple/obvious" and therefor they never bothered to create any documentation or put any thought into it.

GCS also supports disabling bucket ACLs permanently at bucket creation time, and that is the option they recommend[1].

S3 does too. There's an entire page during the creation wizard that is dedicated to blocking any and all public access, even causing the bucket to ignore ACLs or other settings that would otherwise expose the bucket publicly. All public access is disabled by default, and enabling it actually requires the user to actively uncheck 5 different checkboxes, each of which explains that unchecking it will open the bucket up to public access, and then even requires an additional attestation, in a large orange warning box, that says you acknowledge that the options you chose will result in the bucket being public.

I'll be the first person to tell you that AWS is overcomplicated and hard to use, but this isn't that. IAM and bucket policies are a pain to work with, but if you screw up with those, the worse you will do is expose your bucket internally. But exposing a bucket publicly to the internet is an entirely different act, and there's not really any excuse for it other than just not reading the directions.

However, neither this option in S3 nor the option you linked in GCS would have served Twilio's use case. They wanted their bucket to be publicly accessible, just not publicly writable. That's an entirely different access management issue.

On Trouser Pockets 6 years ago

Interesting! The Kuhl pants I own don't have any rivets in them at all (in fact there's no metal or anything non-fabric except for the crotch zipper and button) so I have not experienced that. Will have to keep that in mind if I look at any of the other styles from them, though.

On Trouser Pockets 6 years ago

Kuhl pants are some of my favorite pants I own, second only to my Prana pants which also have similar pockets.

I recently discovered that "hiking pants" are superior in almost every way to normal pants. They're usually more comfortable, deal with both high and low temperatures well, and nowadays have aesthetic styles that you can even wear in semi-formal work situations or to a nice dinner.