HN user

uxp

2,264 karma
Posts4
Comments845
View on HN

My mother in law works for a company that allows her to work from home from a personal device running Chrome.

Several times a year I get a phone call at 6:30AM from her asking to quickly drive to her house before her shift starts at 7 to fix her computer, because "something happened" or "I was hacked". Every time, it's been an update which has reset her default apps so email opens in the newish Mail app and not Outlook or Gmail-in-Chrome, or changes the browser to Edge from Chrome. I'm not a systems administrator, so I havent a clue on what the magical incantations of registry paths and values should be which prevent this despite trying.

Obviously if this was a domain managed asset at a company, someone would know how to prevent this. As a "home device", it feels like you're automatically enrolled in the "Global Microsoft domain", and subject to the whims of a product manager making IT decisions.

One really wishes to know: who is the guy with deep pockets that Eshelman upset and what are they beefing over, and how did he get the wholesome quartet of hunters to go along with him.

What are you talking about? Access to public lands has been an ongoing fight for decades with people from the entire political spectrum having opinions about the matter. Whether that be rock climbers trying to access routes, or people who fish trying to access streams, to people like this who are trying to access public hunting land. Assuming that everyone trying to access public lands is some poor pleb is in bad taste. Companies like Patagonia have long supported more liberal access to public lands with millions in donations, as well as organizations like the NRA with their advocacy and financial support.

Validating any contact method that has the potential of sending PII, Health, or financial data should be mandatory by law.

At least once a year I get an automated phone call from a regional hospital letting me know some minor's test results. Calling the hospital's CS department in order to notify them or somehow get my phone number removed from the account is impossible, because I'm not this person nor their legal guardian and HIPAA regulations prevent me from instigating a change on someone else's medical records or accounts.

Yes. Here's a non-crypto instance of using a seed value to deterministically identify the output of a random number generator. This only works in Python 2.x:

    import random
    for i in range(0,50):
        if not i % 15:
            random.seed(1178741599)
        print [i+1, "Fizz", "Buzz", "FizzBuzz"][random.randint(0,3)]
By seeding the PRNG with a known value, one can literally predict the output of a weak number generation utility. In this case, it solves the FizzBuzz puzzle.

https://en.wikipedia.org/wiki/Fizz_buzz

It would be one thing if it was _just_ a little demo utility used to showcase packaging and distribution of a trivial use case, however the creator of this has also created a number of packages which pull in these "demo" packages, like `handlebar-helpers`, which is again just these trivial function packages wrapped in handlebar decorators.

Several of these utility and helper packages are then pulled into other packages and build tools and marketed as legitimate packages, effectively hiding and masking the "just a demo" labels of the root is-even, is-odd, is-number packages. When people like myself complain about the absurdity of NPM supply chain verification, this is what we're arguing against.

Apple Faceshield 6 years ago

For what, though? And I'm 100% being honest here, what is the specific situation you are envisioning that requires a face shield in your home?

In a medical setting, shields are typically used in conjunction with eye goggles and respirators when performing procedures that have a tendency to cause or be around splashing body fluids. Outside of someone sneezing or spitting on you directly, I can't think of an analogous situation that I come into on even a rare circumstance that a face shield would protect me from.

Apple Faceshield 6 years ago

It's not about the money. PPE like face shields are specifically used during procedures that involve significant bodily fluid, like intubation, which is the process of pulling or pushing a tube down a patient's esophagus. Going to to the grocery store does not require a shield.

Secondly disposable medical equipment, when used properly within a healthcare environment, is extremely wasteful. For most consumable items used in a hospital, they are covered in packaging with specific serial numbers and lot numbers that allow reconciliation if it's found that the goods are not sterile or have deficiencies. There is also a provenance or chain-of-command aspect that allows attestation of safety throughout the entire supply chain. While we might be talking about how to sterilize n95 masks, reuse face shields, and asking for donations of PPE from the public right now during a pandemic, the fact remains that in normal circumstances there is massive liabilities that hospitals and clinics would be subjected to if they started sourcing protective equipment from the public that could have been tampered with, may be slightly used and broken, or otherwise could cause harm to the patient and they'd be unable to identify the source of those resources. Everybody stocking a "handful" of PPE isn't a scalable solution to maintain a national supply.

This is one reason why we pay federal taxes.

ceejayoz, I generally respect most everything you write on this site, but I'm amazed how dismissive you are of this.

Can you point me to a study stating that the flu vaccine is 100% safe and effective? Not mostly effective, or mostly safe, but 100% honest-to-god safe for 100% of the population to get?

edit: really? calling my GP an anti vaccine crank? fuck you.

Nope. Like I just stated in my edit, I'm not advocating that anyone forgo the flu shot, but that the flu shot is not 100% effective or 100% side effect free.

It's not bias. It's a fact. My GP is the one that has specifically told me to avoid the shot because I have a history of complications with it.

If you're capable, I'd love for you to diagnose me with some other mental disorder or logical fallacy, but please look at my medical history before you start dismissing my experiences as idiotic.

I've received the flu shot three times in my life. I've been hospitalized for influenza three times in my life.

Please tell me more about how I've deceived myself.

Just as the MMR vaccine is less about you contracting measles and more about your spreading measles to more vulnerable populations that are unable to get the vaccine, the flu shot is identical in that regard. Sure, it helps you not get sick and/or to lessen the effects, but there is the fact that some portion of the population is unable to get the shot for various health reasons.

Edit: Instead of downvoting please tell me how my experiences are wrong. I'm very much aware of evidence and studies stating that its "impossible" to get the actual flu from the flu shot, yet I am walking proof of contrary evidence. I'm also aware of how batshit emotional people can get with regards to vaccines, and I want to be clear I am absolutely NOT advocating that anyone forgo getting a flu shot every year. When everyone else gets the shot, I'm safer. When I get the shot, my body reacts violently and I will contract the virus.

I'm a .NET developer and I can't tell you how many times I've searched for documentation and come across something that's targeting UWP which is different than WPF and entirely not the same as WinForms and it takes way too much energy trying to identify why exactly the documentation isn't what you want. I thought Microsoft was more or less sunsetting WinForms until they also announced WinForms for .NET Core a couple months ago. https://docs.microsoft.com/en-us/dotnet/core/porting/winform...

I literally have no idea what Microsoft is doing anymore. Sometimes it feels like Linux was 10 years ago when I would accidentally install Konquerer on Gnome and all of a sudden I had two desktop systems installed and my root drive had doubled it's consumed harddrive space. It basically worked, but it was a terrible experience.

Based upon this article were the retail costs of a cheap flickering LED bulb is approaching the single dollar mark, the cost increase to use a proper AC/DC converter could be orders of magnitude more expensive (at a rough minimum).

Honestly it's starting to feel like a most cost effective long term solution is to build homes with a master AD/DC converter (or several depending on sq/ft) and simply wire 12v outlets and light fixtures. The energy savings of swapping all incandescents or compact florescence bulbs with cheap LEDs with cheaper power converters is starting to scare me knowing just how shoddy and fire prone some of these power converters can be.

whitelist the few that are actually real

I'm speculating that the balance is in the reverse favor. Last night I was looking at some file on GitHub which was redirecting to what looked like an S3 bucket subdomain named with a pattern like "github-production-f7e281a2", which I simply presumed to be cache-busting via subdomain instead of appending the hash to the filename. If my assumptions were correct, every time GitHub deploys a new build, you would have to whitelist that subdomain.

PBMs are rent seeking middlemen. Their desire to seek the lowest drug price is arguably what contributes to things like quality standards at pharmaceutical manufactures slowly loosening and contaminants getting into the supply line.

Honestly, we should have an independent 3rd party with zero financial investment in either approving or rejecting a quality check of a batch sample. Something Federal, so manufacturers cant "shop states", that administers and regulates drugs and their distribution. Not sure what I would call it. I tend to go with cartoonish things, so Merlin after the bumbling wizard sounds fun, but the bureaucrat in me thinks the acronym "F.D.A." would suffice.

In PG&E's world in context of this comment thread. Dividends are any payout amount that was not captured in the regulatory framework. Salary is a captured expense. Bonuses are paid from a pool when a surplus is created, or rather a profit is made, or more bluntly when dividends are earned.

Legally, you're correct. PG&E has been operating counter to those rules for a while.

http://investor.pgecorp.com/news-events/press-releases/press...

https://www.kqed.org/news/11737336/judge-pge-paid-out-stock-...

PG&E can’t pay out more in dividends by shortchanging operations and maintenance.

They have before.

https://www.sfgate.com/bayarea/article/PG-E-diverted-safety-...

edit: obviously this is a lot more nuanced than simply eliminating the O&M line item and diverting that income into dividends. In this instance, they had higher than expected income resulting in a positive cash value which was due to MANY factors, but they simply decided to add it into the dividends rather than into O&M, which they knew was running lean.

edit 2: You're working on the assumption that they are operating at a 100% accurate estimation schedule. You know that this is an impossible task, and so I think we are arguing that the delta between the actual operating costs and the estimated operating costs, when it has been a positive value resulting in unexpected monetary value, has typically been diverted in this case to dividends rather than to maintenance. Even if that value has been 2 to 5% per year, it's still millions of dollars. The fact that it was diverted to compensation rather than maintenance indicates a tendency of the PG&E entity to value it's corporate officers over the public (eg, spending money on maintenance is investing in the public safety, whereas spending money on dividends is the officers cashing out and taking a personal win). This is I think the biggest breakdown of how public utilities operate in this economy. They are largely private companies with a mandated monopoly, so despite being a private or publicly traded company, they _should_ act like a publicly owned or municipally operated company. We (the people) have given them an extremely liberal license to operate, and they should return that favor in kind. When they don't, they've broken the social contract.

At least in the US, we would also need extensive regulations and caps on the cost of products. As a commonly cited example, when Pell Grants (Federal student subsidies) were increased to adjust for inflation and costs of living somewhat recently, average costs of tuition went up by about the same amount across nearly all colleges.

This is a classic move in our economy: 1) product or service slowly becomes more expensive relative to income, 2) a subsidy that was supposed to go to the bottom tier to help even the playing field but is now used by more and more people due to 1 adjusts it's payout to return to it's planned effectiveness, then 3) product or service operator notices that consumers have more available money and adjusts their cost upwards.

Similar effects have been observed in more nuanced ways, like the costs of fresh fruits and vegetables being higher than boxed and processed foods, so low income food subsidy programs bump their monetary payouts to encourage purchasing of fresh foods, and some boxed or processed foods have a statistically unusual bump in retail prices in the area. This is the kind of bullshit that really starts to make me think that the USA needs a secondary monetary system (not bitcoin/blockchain, and not Dollar based) to be used for redemption of welfare and entitlement benefits which would make it impossible to track between something like an increase in food stamp benefits and monetary compensation for the use of those benefits. I'm cool with Kraft thinking that Velveeta cheese "product" needs to be more expensive in our magical capatalistic society, I'm just not cool with them thinking that only because the lowest income shoppers suddenly have 5 more cents in their account every month.

I think it was Tim Minchin's Storm that brought the quip "You know what they call Alternative Medicine that works? _MEDICINE!_". This is an entirely true statement, but also seems to miss the R&D period. And I'm not specifically saying its a modern R&D period.

It was well known for centuries that willow and aspen tree bark had anti-inflammation properties, so R&D could simply be to test if chewing on branches or bark was what helped with inflammation, or does it need to be from a fresh tree or can a dead tree also provide benefit. Once it's been determine that it's the bark, then can one grind it up and drink it in tea? For centuries, drinking a tea made from some plant material was the cutting edge of drug delivery mechanisms. Then for modern times, what substance within that plant can be isolated that provides the specific function we've observed. Can it be synthesized? Can it be pressed into a pill, or placed in a capsule? Now it's what you and I may observe as modern medicine, but there is a fact that chewing on the bark, the so-called "alternative medicine" is just unrefined medicine, where the level of refinement is determined by your society's manufacturing and science communities. Some day, some culture will probably look back and think that it was uncivilized that we had to go find someone who we needed to convince to dispense physical chemicals that we had to consume in order to feel better, just as we might look at someone chewing on a stick to relieve a headache as wacky. That's what "Asprin" is for.

That said, I'm entirely in the camp that thinks that modern alternative medicine is a sham. Cannabis' biggest problem is obviously political, but it probably also has the biggest potential for being a candidate for research to isolate and properly identify the interactions with the human body today. It clearly has some effect on the body (and mind), but as far as I'm concerned it's flower is still a caveman era drug while CBD oils are essentially Victorian drugs. We might see some kind of modern medicine originate from it, but I'm skeptical for now.

Loot Box Lottery 7 years ago

A coworker and I went to lunch randomly a number of months back and I discovered that he and his wife are avid WoW players on the server that I played on nearly 10 years ago. This sparked me to impulsively purchase 30 days of game time on my character, which was surprisingly still available on my Battle.NET account. I happily dinked around for a bit, leveled up my character from 70 to 90, and discovered the VAST amount of collectables that are present these days, which was quite shocking.

When I stopped playing WoW, players could collect pets by redeeming tokens/codes from blizzcon or other real world fan or collector activities, but today there is an entire mini-game surrounding battle-pets which can be collected in-game and also purchased via earned gold or simply cash. Additionally, Raid or PvP gear sets can be supplemented with purchased "cosmetics" and "heirlooms" which again can be purchased through earned gold or through the store with cash. It seems like every side-game activity has some kind of purchase available to "speed up" the time it takes to "earn" the appropriate currency required to redeem the reward. I've been out of the gaming loop for far too long to really see how bad it's become, but it was absolutely shocking to see it.

I've seen the same architecture implemented in MSSQL and MySQL. It's pretty easy to paint yourself into a corner where your one database is doing all sorts of stupid things because you never sat down and identified the problem space in the larger context and moved to a wider configuration instead of simply using a table with short-lived rows as a queue. It's the same arguments about nails and hammers.

The media is generally regarded the same when publishing both medical history information and classified materials. If they obtain the information during their regular course of business and report on that obtained material, then they are protected as reporting on a story that is beneficial to the public. If they coerce others or help to obtain protected information, whether classified materials or PHI/PII, then they can be held liable for the release against the existing laws regulating disclosure.

The We Company S-1 7 years ago

including some that the CEO owns and they lease from him

Did you see the part of the filing where, in case of death or incapacitation in the next ten years where the CEO is unable to fulfill his duties, a group of two board members _and_ his wife will select the next CEO, and if those named board members are also not available anymore then his wife will solely pick the two board members who will pick the next CEO with her, and if _she_ is unavailable then the estate of the CEO and his wife will pick the next CEO?

Page 198

I've never seen a company like this transfer to successive control via the private estate of the CEO in case of a vacancy. There's a lot of WTFs in here.

It really depends on how the SSN is used, but using a false SSN is considered fraud.

If the party requesting it is using it for billing and collections, and you fail to pay a bill and they send it to collections, and subsequently report the collection to a credit agency, then it is a clear case of fraud. If you randomly happen to pick a valid SSN, then you are committing identity theft in addition to fraud.

If they are just using it as a Unique ID, they may not ever know that it's fake. None-the-less it is still fraud.