Viewing profile — Msurrow
Msurrow
HN member- Joined
- Mon, Sep 19, 2016, 4:17 PM UTC
- HN karma
- 659
- Public activity
- 155 items
- HN profile
- View on Hacker News ↗
About Msurrow
No profile information was provided.
Recent public activity
-
comment
Comment #49032415
Honest question: For let’s say a senior developer having to go through all of these steps for the model to implement a feature: > Product Design > System Architecture > Program Des…
-
comment
Comment #48708220
> month ago there was a wave of posts and tweets about engineers walking around cafes and parks with their MacBooks propped half-open, as fully closing the lid forces sleep that st…
-
comment
Comment #47181985
> They would NEVER admit any failure in their society, no matter the hard evidence in front of their eyes. That must be the swedes. Danes complain constantly, about everything. Edi…
-
comment
Comment #47173525
I think he meant that at that time all users were programmers. Yes, _all_ .
-
comment
Comment #47114038
I agree that yes most just want PnP and basically don’t care about security. But it seemed on the posts above that there was an engineering complexity, and a robot vaccum needs loc…
-
comment
Comment #47112992
I have not knowledge of this kind of software dev/hw production, so can you please explain why the units cant just be born with a default pass and then have the setup process (whic…
-
comment
Comment #47100462
Yeah was thinking the same thing. I wonder if the author didnt known that passpory chip == fingerprint. And FP is a much worse modality to have registered because, as opposed to Fa…
-
comment
Comment #47071863
That that is exactly why [more] regulation is necessary! Regulation is not done with the purpose of preventing companies from profits. It is done because companies cannot be expect…
-
comment
Comment #46932155
No, they are not. Doesn’t matter how many LoC; it only take 1 LoC to introduce a vulnerability. Wireguard is a protocol. So what implementation is “very intentional about its choic…
-
comment
Comment #46912323
You are still implying that wireguard are somehow different from ssh in its suceptibilty to vulnerabilities existing or being introduced into its codebase. And it simply is not. Ed…
-
comment
Comment #46911275
I’m calling it consultant speak because your response to an argument is to bring up something else, instead of actually responding. The same with this last reply; you can keep thro…
-
comment
Comment #46899674
Sure, no one said it wasnt layered. But saying ssh is a risk “on principle” due to possible vulnerabilities, and then implying that if wireguard is used then that risk isnt there i…
-
comment
Comment #46896866
But doesn’t your argument that the principal risk [with ssh] is vulnerabilities also apply to the alternatives you say is best practice? Firewalling off ssh (but not http(s)) has t…
-
comment
Comment #46579976
You cant.
-
comment
Comment #46414664
Depends on environment variable P=NP
-
comment
Comment #46373921
> *If you don't want your LG TV quietly snooping on what you watch and using it to serve you ads, here's how to turn Live Plus off. If LG makes money from snooping on you, what mak…
-
comment
Comment #46360401
Yes, it does. First of all: occam's razor. Political theatrics seems simpler than the US defence/intelligence forces sudenly realizing that drones can be launched from ships. Esp. …
-
comment
Comment #46359117
The construction on some of these windmill farms started years ago. Before that permits & legal has been in the works for a long time. This surely included security clearances. The…
-
comment
Comment #46314437
Man, I got my rope out for this..
-
comment
Comment #46216618
If the employer says so and I do so anyway then that’s a employment issue. I still have to follow company rules. But the point is that the company needs to delete the collected dat…
-
comment
Comment #46216380
Yes. GDPR covers all handling of PII that a company does. And its sort of default deny, meaning that a company is not allowed to handle (process and/or store) your data UNLESS it h…
-
comment
Comment #45891667
If that’s the case why give the OSS project any time to fix at all before public disclosure? They should just publish immediately, no? Warn other users asap.
-
comment
Comment #45891613
My takeaway from the article was not that the report was a problem, but a change in approach from Google that they’d disclose publicly after X days, regardless of if the project ha…
-
comment
Comment #45891546
In addition to your point, it seems obvious that disclosure policy for FOSS should be “when patch available” and not static X days. The security issue should certainly be disclosed…
-
comment
Comment #45832598
The OP/article is very clear and very direct on what the problems are. The response is so typical american conflict-shy “let’s talk so we can slowly dimish your critique, and also …