Viewing profile — ericalexander0
ericalexander0
HN member- Joined
- Wed, Feb 06, 2019, 10:23 PM UTC
- HN karma
- 214
- Public activity
- 175 items
- HN profile
- View on Hacker News ↗
About ericalexander0
No profile information was provided.
Recent public activity
-
comment
Comment #44932355
Security people will argue forever “defense in depth” this, “real world doesn’t match the study” that. Yawn. Here’s the hard truth: cybersecurity today is basically fashion. It’s n…
-
comment
Comment #44542588
> Could a rogue agent theoretically run a destructive command? Sure. Have I seen it happen in weeks of usage? Never. I've been in cybersecurity over a decade, and this still blows …
-
comment
Comment #44355037
At the last job we deployed to thousands of nodes across AWS, Azure, and Aliyun. There was no unique needs across those environments, from a deploy perspective. There where some mi…
-
comment
Comment #44339372
If you want alignment, set clear rules that everyone understands. At SpaceX, their spending policy was simple: If it helps us get to Mars faster, spend it. If not, don’t. That simp…
-
comment
Comment #44337675
Most people and by extension, most businesses don’t think from first principles. They copy what others do because it’s easier. It reduces cognitive load. But that kind of thinking …
-
comment
Comment #43047729
I haven't seen anything useful in the agent space. I definitely haven't seen anything I would trust in a business process. At the same time, I'm constantly amazed at how accessible…
-
comment
Comment #43030994
Security is about real risk reduction, not chasing whatever’s trendy - but that's what most security teams do and then complain about the results. Most business functions are metri…
-
comment
Comment #42991844
I look at this through the following perspectives: As a security engineer, this is pretty obvious - blindly handing over login credentials to AI agents? What could possibly go wron…
-
comment
Comment #42898600
I see two possibilities here. Either Musk is a foreign agent attempting to cripple the US government or he's a student of Blitzscaling and Jim Collins' The Map. Incentives can help…
-
comment
Comment #42865201
I doubt they're no performers, they're likely selective performers. Issues like this can often be explained by Public Goods Game theory. If there's no economic incentive, then some…
-
comment
Comment #42831936
The key is modularity with good interface design, then you have AI generate each component and play more of a QA role to validate each component is functional.
-
comment
Comment #42823427
I code but my day job is closer to CISO. I've been working with react for years and one of the biggest pain points is the near immediate security debt you take on through the compl…
-
comment
Comment #42823354
Cooling is a single DC factor with costs derived from electrical costs. In most DC build outs you're looking for favorable network peering (ie pipe size, latency, or both) and low …
-
comment
Comment #42301886
As a manager I'm always trying to figure out if my direct reports are vice or virtue motivated. With vice being money and title. Virtue being what you get to work and with who. In …
-
comment
Comment #41419249
I've built security programs at 3 companies. This is how I would solve these problems. 1. SSO everywhere. Okta if budget is no concern and Keycloak if it is. 2. Password manager fo…
-
comment
Comment #40554663
Having worked in adtech for 6 years I learned through many-many conversations with friends and family that 1) they don't care to understand how it all works and 2) they don't belie…
-
comment
Comment #40454302
The book Trillion Dollar Coach ( written by Eric Schmidt and other ex-Google leadership) has a first hand account of how they went from a philosophy of few managers to more. Surpri…
-
comment
Comment #40223693
Check out Beyond The Goal and Beyond The Phoenix Project for a deeper dive in this area. I work in cyber security and use many of the concepts often. The root cause of many poor ou…
-
comment
Comment #39412036
So many questions. Why not reveal what sites/code this was tested on, so others can try to repeat? What was the false positive rate? Why didn't they compare results with commodity …
-
comment
Comment #39135425
This. I've established security programs at 3 companies over 10+ years. I've rarely encountered an engineer who didn't care. I've encountered many with competing priorities. What g…
-
comment
Comment #39049487
My mind immediately goes to Bezos & "Resist Proxies". From a guy who has built security programs at 3 companies. https://www.aboutamazon.com/news/company-news/2016-letter-to...
-
comment
Comment #38935508
Sometimes these events provoke regulators to take a closer look at the company. https://www.ftc.gov/news-events/news/press-releases/2023/11/...
-
comment
Comment #38903474
Predictable based on a large body of knowledge. From Orson Scott Card's How Software Companies Die to David Packards HP Way. There's also Deming, Goldratt, and Jim Collins. https:/…
-
comment
Comment #38816350
This problem is not exclusive to Meta. It's the product of "big ball of mud" design. It relates to Dunbar's Number and the limitation of mental models.
-
comment
Comment #37747701
https://docs.gitlab.com/ee/user/analytics/dora_metrics.html