Hacker Newsnew | past | comments | ask | show | jobs | submit | more orthogonal_cube's commentslogin

$240/yr in software subscriptions but likely far more than that by selling the extra metadata they can extract from the service


its likely not the metadata, since they already have access and sell that, but then they can sell ads on maps like Google does.


I don't understand why people are so deluded about the value of metadata about them. It's not that valuable, you're not that important.


Are Ubiquiti products commonplace for companies that contract with the US government outside of the DoD/DoW?

Since DoD/DoW generally requires STIG compliance, and none authored are for any specific Ubiquiti product, we can cross that off the list. Sure they can get exceptions or use a more generalized STIG but stakeholders generally have pre-defined limitations on what they will and will not allow on networks they sponsor.


The Defense Industrial Base is 10s of thousands of companies. May are small businesses. Many need to obtain CMMC Level 2, which has requirements for FIPS certified encryption. Our systems do not directly connect to Government systems and those STIGs may not apply directly. So, could I use Ubiquiti in some places? Maybe, not to store controlled information in this case. I could probably store previously fips encrypted files there. Would I want to use Ubiquiti cloud services? No.


It was fun exploring this to make a native-shell-only peer-to-peer file transfer utility at work for some automation scripts. At least, it was until trying to replicate it in Powershell was somehow triggering Crowdstrike and the corporate Cybersecurity team thought I was writing malware.


This is not uncommon when becoming disillusioned with something that has been hyped up and forced upon you for an extended period.

The fatigue of the product (and sting of false promises) causes the negatives to overshadow anything positive to say.


I find this study interesting but wonder if the wording is specifically done to cause some sensationalism.

> However, there is a twist: for positions on distributed teams, the firm consistently hired more experienced workers, even after reopening. This divergence suggests that the firm’s hiring decisions were influenced by the complications of remote work rather than other macroeconomic trends.

They don’t consider (almost intentionally) that remote positions don’t have the same restrictions as in-person positions. Anyone meeting desired qualifications can be considered for a remote position. Only people willing to relocate to, or already live near, a target office and meet the qualifications can be considered for an in-person job. Remote positions therefore are likely to be more competitive and difficult for inexperienced candidates because the pool of candidates is far larger. The hiring manager is incentivized to pick the person they believe will contribute the most for the amount they’re willing to pay.

The findings about mentorship in-person may be true but it is strange to put that as the deciding reason. There are no details provided over how “quality” is quantified nor decided. Selecting a sample size of one firm to analyze in detail without looking at others to confirm this feels very flawed.


I miss working at a place which allowed this.

Some employers get tangled up in just the legal review process.

Once I asked permission to submit a patch to a project and it had quite an interesting email trail. It came down to a single question: if the patch was written during hours billed to a customer for the purpose of fixing a bug in a deliverable product, and the library being patched had to be recompiled and delivered with the source code, and the contract states that all work and intellectual property associated to the product would be transferred to the customer, do we have authority to release the patch in the public domain?

Legal didn’t want to answer it.


The customer would probably prefer that you released it - that would mean next time they need a change the previous is up streamed.

Note that the resulting patch is almost assuredly not public domain and you should never use that term.


I frequently reference this exact meme to people whenever someone complains about complicated or difficult-to-write code. Now that’s you’ve made this project I suppose we have zero room to complain anymore!


Dang, haven’t read much on Julia as of late. I remember using it for a CS 300-level course around 2016 when learning about tokenizing and parsing as part of language fundamentals. Julia has undoubtedly made some significant performance improvements since then. Would love to see a follow-up that explores what, if anything, from this still holds true and what improvements can be made.


To answer the first question, a number of veteran independent researchers probably wouldn’t have touched such a system. Plenty of companies will send their lawyers after you if you tell them that you’ve discovered a vulnerability of some sort and wish to responsibly disclose. Even if you do things in good faith, the company has zero reason to assume the best from you and can hold a sword over your head by citing poorly-written laws that lean in their favor regarding computer fraud and abuse.

DoD does appear to offer a “Defense Industrial Base - Vulnerability Disclosure Program” for all public-facing DoD/DoW systems.[1] However, this might not include contractor-controlled assets or services. I cannot view the HackerOne page that it redirects to (login is required) to view more details.

[1]: https://www.dc3.mil/Missions/Vulnerability-Disclosure/DIB-Vu...


The line between security research and espionage seems really thin.


Would spies disclose their findings?


Honestly I’m surprised this wasn’t already a feature in macOS. Thank you for coding it and publishing as open-source!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: