Earlier quoted context omitted.
Just listened to the ZFS on Linux episode. I was sceptical about watching a command-line narrative, but this was incredibly well executed, with episode transcript and mini-reviews of related sites. As the episode started, the speech pattern was so slow I wondered if it was a TTS robot aimed at non-English listeners, but then the voice quickly picked up speed to reach excited-hacker cadence. How long does it take to w…
Thanks for the kind words ;) > How long does it take to write and produce each episode? Rough guide is about ~2-3 hours per minute of video. Research, playing around with ideas, demos, writing, recording video, recording audio, editing, etc. So, ZFS part one was 12 min, that's about 24 hours, and part two is 18 min, so about 36 hours. Those two episodes are about 60+ hours of solid work. ZFS did take a little longer…
16 Things
101–110 of 135 posts
Re: 16 Things
#102Earlier quoted context omitted.
Thanks for the kind words ;) > How long does it take to write and produce each episode? Rough guide is about ~2-3 hours per minute of video. Research, playing around with ideas, demos, writing, recording video, recording audio, editing, etc. So, ZFS part one was 12 min, that's about 24 hours, and part two is 18 min, so about 36 hours. Those two episodes are about 60+ hours of solid work. ZFS did take a little longer…
Hey, what kind of computer do you run with those programs? Apple or PC?
Re: 16 Things
#103Earlier quoted context omitted.
I've worked implementing both, and Bromium is basically as good of a solution to this problem as you're going to get, in the sense that it requires the least modification of user behavior (the user's Windows machine mostly behaves like a normal one). Even Bromium was pretty upfront about the use case for their product though (high-value targets like executives who travel to China). They were very honest about it bein…
> the only 2 sectors of the industry that are continuing to grow being completely unsuited to TPMs (virtualization and mobile) A counterpoint is that mobile platforms often have some form of secure enclave, but sadly not standardized. Even AMD's low cost x86 CPUs are adding an ARM coprocessor, which could in theory be used for functionality similar to TPM, DRM, or AMT. Some of those are more useful than others. On th…
Re: 16 Things
#104In the 'Online Video' section he calls out podcasts as an emerging/trending medium. I'd love to hear more about where people in HN community feel it's moving. Of course there's the obvious Serial momentum, and as a passionate consumer of podcasts I'd love to think through with you guys a little more where we think it'll go. For example a YouTube-like podcast portal seems like a potential option (i.e. moving away from…
Re: 16 Things
#105Enterprise software is definitely an area where there is plenty of opportunity. They're aching for good software; they pay exorbitant amounts for software that just isn't very good. If someone can find a vertical where they can penetrate and provide real business value, they'll do well.
And modern B2C-oriented startup thinking doesn't get it. The sort of Lean/MVP/failfast thinking doesn't work so well when you're building for a half-dozen meetings spaced out over weeks, to match arcane localization requirements for the target customer. The reason startups rarely penetrate is because it's slow, hard, and painful - the sort of thing where big deep-pockets entrenched companies have a huge advantage.
Worse, young startup founders don't have the enterprise experience to grok why everything is so slow and so hard. It's easy to look from the outside and think those silly enterprise people must be stupid and/or malicious to make such an opaque maze of red tape. Hardly! The enterprise is filled with smart, committed, hardworking people who almost inevitably wind up in the same boat, across the many enterprise verticals.
Enterprise is valuable because it's expensive. It's expensive because it's really, really hard. Don't forget that.
On the other hand, if I can make it work as a founder, it's going to work huge.
Re: 16 Things
#106Earlier quoted context omitted.
I've worked implementing both, and Bromium is basically as good of a solution to this problem as you're going to get, in the sense that it requires the least modification of user behavior (the user's Windows machine mostly behaves like a normal one). Even Bromium was pretty upfront about the use case for their product though (high-value targets like executives who travel to China). They were very honest about it bein…
> the only 2 sectors of the industry that are continuing to grow being completely unsuited to TPMs (virtualization and mobile) A counterpoint is that mobile platforms often have some form of secure enclave, but sadly not standardized. Even AMD's low cost x86 CPUs are adding an ARM coprocessor, which could in theory be used for functionality similar to TPM, DRM, or AMT. Some of those are more useful than others. On th…
There was a brief window in time when you had to go out of your way to buy an Intel laptop "without" a TPM (even Macs had them for a time, even if Apple never made use of them). The Trusted Computing Group failed to capitalize on that timeframe by providing both a "reason" and decent solutions to that problem.
There's a lot of reasons why that was, if I've been drinking I'd happily go into many of them.
On the mobile side, I agree, it's a hodgepodge. Apple has their secure enclave (which doesn't quite act like a TPM, even though it theoretically could), and there exist vendors who could theoretically include a TEE in their phones (right now they're almost entirely limited to special "government-specific" use cases).
And I'm ignoring Samsung's solution (which is basically snake oil).
Intel's SGX would be great, provided that the industry suddenly switches to X86 for mobile (which I don't think is going to happen).
The mobile industry is way too fragmented from a hardware perspective for any type of trusted computing platform to achieve even a modicum of install base. That might change in the future, but I wouldn't bet on it.
Re: 16 Things
#107Re: 16 Things
#108The idea of a crowdsourced insurance company is not a good one (to put it mildly). The expected returns of an insurer are highly correlated with the returns of the broader market[3], because a typical large insurance company makes little to no money writing policies and generates most or all of its income from investments[4]. But maybe he's thinking about crowdsourcing the insurance risk itself, not the whole insurance company with its massive portfolio of stocks and bonds (although that's not what he said). In that case, you get an investment that yields X% a year until and unless the underlying insurance contract is triggered, in which case you lose your principal. These securities actually exist[5], but as you might imagine they are not typically purchased by individuals.
I do think the insurance industry can be disrupted. It's harder for a startup to gain traction because economies of scale work differently in insurance than they do in other industries, but a Google or an Amazon could do some real damage if they wanted to invest the resources to do so. There are a lot of interesting problems to solve. But this article totally misses the point.
[1] http://www.progressive.com/auto/snapshot/ [2] https://www.statefarm.com/insurance/home-and-property/homeow... [3] http://pages.stern.nyu.edu/~adamodar/New_Home_Page/datafile/... [4] https://static1.st8fm.com/en_US/content_pages/1/pdf/us/2013-... [5] http://en.wikipedia.org/wiki/Catastrophe_bond
Re: 16 Things
#109In the 'Online Video' section he calls out podcasts as an emerging/trending medium. I'd love to hear more about where people in HN community feel it's moving. Of course there's the obvious Serial momentum, and as a passionate consumer of podcasts I'd love to think through with you guys a little more where we think it'll go. For example a YouTube-like podcast portal seems like a potential option (i.e. moving away from…
Might be a stupid idea as I'm not a big podcast consumer.
Re: 16 Things
#110Earlier quoted context omitted.
Yep. Information security is a nonalgorithmic problem. Much as people might like to disagree or pretend otherwise, it is fundamentally at odds with a service that can scale to meet the needs of clientele in an automated manner. The most successful companies in that space are consultancies that can deliver personalized results to every client on every engagement, and while they are very successful, they will never be…
Something I used to think about during my tenure as a graduate student in computer security: has anyone written the definitive book/study/dissertation on why security incidents happen? As mentioned elsewhere in this thread, it's a very complex problem involving operational, economic, and technical factors, suggesting (as others have mentioned) it's not something that really can be "sold". Watching bugtraq for a while…
Web applications are not the same way. For example, enforcing policy restrictions between users of different permission levels suddenly becomes a custom project depending on what each user can do, what the application does, what functionality is mapped to different permissions, etc...it is not as simple as whitelisting. It is highly contextual.
Unfortunately, web applications are also where most vulnerabilities are found, not the network (at least not anymore).