Live data from Hacker News

16 Things

a16z.com

101–110 of 135 posts

Re: 16 Things

#101

Earlier quoted context omitted.

Just listened to the ZFS on Linux episode. I was sceptical about watching a command-line narrative, but this was incredibly well executed, with episode transcript and mini-reviews of related sites. As the episode started, the speech pattern was so slow I wondered if it was a TTS robot aimed at non-English listeners, but then the voice quickly picked up speed to reach excited-hacker cadence. How long does it take to w…

Thanks for the kind words ;) > How long does it take to write and produce each episode? Rough guide is about ~2-3 hours per minute of video. Research, playing around with ideas, demos, writing, recording video, recording audio, editing, etc. So, ZFS part one was 12 min, that's about 24 hours, and part two is 18 min, so about 36 hours. Those two episodes are about 60+ hours of solid work. ZFS did take a little longer…

Hey, what kind of computer do you run with those programs? Apple or PC?

Re: 16 Things

#102
post #101

Earlier quoted context omitted.

Thanks for the kind words ;) > How long does it take to write and produce each episode? Rough guide is about ~2-3 hours per minute of video. Research, playing around with ideas, demos, writing, recording video, recording audio, editing, etc. So, ZFS part one was 12 min, that's about 24 hours, and part two is 18 min, so about 36 hours. Those two episodes are about 60+ hours of solid work. ZFS did take a little longer…

Hey, what kind of computer do you run with those programs? Apple or PC?

[deleted]

Re: 16 Things

#103

Earlier quoted context omitted.

I've worked implementing both, and Bromium is basically as good of a solution to this problem as you're going to get, in the sense that it requires the least modification of user behavior (the user's Windows machine mostly behaves like a normal one). Even Bromium was pretty upfront about the use case for their product though (high-value targets like executives who travel to China). They were very honest about it bein…

> the only 2 sectors of the industry that are continuing to grow being completely unsuited to TPMs (virtualization and mobile) A counterpoint is that mobile platforms often have some form of secure enclave, but sadly not standardized. Even AMD's low cost x86 CPUs are adding an ARM coprocessor, which could in theory be used for functionality similar to TPM, DRM, or AMT. Some of those are more useful than others. On th…

Secure enclaves are very useful tools for OS design, but that's not the kind of security we're talking about here. Enterprises can't easily exploit processor protected VMs and address spaces to, say, prevent PII from leaking. By and large, companies aren't losing data to VMWare jailbreaks; they're losing it to much, much more prosaic attacks.

Re: 16 Things

#104

In the 'Online Video' section he calls out podcasts as an emerging/trending medium. I'd love to hear more about where people in HN community feel it's moving. Of course there's the obvious Serial momentum, and as a passionate consumer of podcasts I'd love to think through with you guys a little more where we think it'll go. For example a YouTube-like podcast portal seems like a potential option (i.e. moving away from…

I'm not in the podcasting biz, but I do listen to a lot of them, both from established radio players like NPR, and from people who got started by "casting pod." Radio is terrible, because you can't decide when to listen to what you want. However, radio producers have vast experience making audio content that people like. My guess is that people who know how to make radio will move over to podcasting and make money via "native advertising," the same way they make money via "advertising" today.

Re: 16 Things

#105

Enterprise software is definitely an area where there is plenty of opportunity. They're aching for good software; they pay exorbitant amounts for software that just isn't very good. If someone can find a vertical where they can penetrate and provide real business value, they'll do well.

There's a lot of opportunity in enterprise, but it's really hard. I spent 20 years in enterprise myself before founding my own startup in that space. The sales cycle just kills you. I can have a product that would save enterprises hundreds of thousands a year, but it takes weeks, months, years to make a sale!

And modern B2C-oriented startup thinking doesn't get it. The sort of Lean/MVP/failfast thinking doesn't work so well when you're building for a half-dozen meetings spaced out over weeks, to match arcane localization requirements for the target customer. The reason startups rarely penetrate is because it's slow, hard, and painful - the sort of thing where big deep-pockets entrenched companies have a huge advantage.

Worse, young startup founders don't have the enterprise experience to grok why everything is so slow and so hard. It's easy to look from the outside and think those silly enterprise people must be stupid and/or malicious to make such an opaque maze of red tape. Hardly! The enterprise is filled with smart, committed, hardworking people who almost inevitably wind up in the same boat, across the many enterprise verticals.

Enterprise is valuable because it's expensive. It's expensive because it's really, really hard. Don't forget that.

On the other hand, if I can make it work as a founder, it's going to work huge.

Re: 16 Things

#106

Earlier quoted context omitted.

I've worked implementing both, and Bromium is basically as good of a solution to this problem as you're going to get, in the sense that it requires the least modification of user behavior (the user's Windows machine mostly behaves like a normal one). Even Bromium was pretty upfront about the use case for their product though (high-value targets like executives who travel to China). They were very honest about it bein…

> the only 2 sectors of the industry that are continuing to grow being completely unsuited to TPMs (virtualization and mobile) A counterpoint is that mobile platforms often have some form of secure enclave, but sadly not standardized. Even AMD's low cost x86 CPUs are adding an ARM coprocessor, which could in theory be used for functionality similar to TPM, DRM, or AMT. Some of those are more useful than others. On th…

I take issue with "often", as the vast majority of mobile phones don't have anything (even if there exist specific models which could have them).

There was a brief window in time when you had to go out of your way to buy an Intel laptop "without" a TPM (even Macs had them for a time, even if Apple never made use of them). The Trusted Computing Group failed to capitalize on that timeframe by providing both a "reason" and decent solutions to that problem.

There's a lot of reasons why that was, if I've been drinking I'd happily go into many of them.

On the mobile side, I agree, it's a hodgepodge. Apple has their secure enclave (which doesn't quite act like a TPM, even though it theoretically could), and there exist vendors who could theoretically include a TEE in their phones (right now they're almost entirely limited to special "government-specific" use cases).

And I'm ignoring Samsung's solution (which is basically snake oil).

Intel's SGX would be great, provided that the industry suddenly switches to X86 for mobile (which I don't think is going to happen).

The mobile industry is way too fragmented from a hardware perspective for any type of trusted computing platform to achieve even a modicum of install base. That might change in the future, but I wouldn't bet on it.

Re: 16 Things

#108
It's probably not the section that most of you will be focusing on, but the "Insurance" section seems to be written by someone who doesn't know the industry. Insurers are absolutely already starting to monitor driving habits[1] and offering discounts for home monitoring devices[2]. Large property/casualty insurance companies are sophisticated competitors that don't hesitate to invest in promising new technologies or techniques many years before they pay dividends. The industry is anything but "stodgy".

The idea of a crowdsourced insurance company is not a good one (to put it mildly). The expected returns of an insurer are highly correlated with the returns of the broader market[3], because a typical large insurance company makes little to no money writing policies and generates most or all of its income from investments[4]. But maybe he's thinking about crowdsourcing the insurance risk itself, not the whole insurance company with its massive portfolio of stocks and bonds (although that's not what he said). In that case, you get an investment that yields X% a year until and unless the underlying insurance contract is triggered, in which case you lose your principal. These securities actually exist[5], but as you might imagine they are not typically purchased by individuals.

I do think the insurance industry can be disrupted. It's harder for a startup to gain traction because economies of scale work differently in insurance than they do in other industries, but a Google or an Amazon could do some real damage if they wanted to invest the resources to do so. There are a lot of interesting problems to solve. But this article totally misses the point.

[1] http://www.progressive.com/auto/snapshot/ [2] https://www.statefarm.com/insurance/home-and-property/homeow... [3] http://pages.stern.nyu.edu/~adamodar/New_Home_Page/datafile/... [4] https://static1.st8fm.com/en_US/content_pages/1/pdf/us/2013-... [5] http://en.wikipedia.org/wiki/Catastrophe_bond

Re: 16 Things

#109

In the 'Online Video' section he calls out podcasts as an emerging/trending medium. I'd love to hear more about where people in HN community feel it's moving. Of course there's the obvious Serial momentum, and as a passionate consumer of podcasts I'd love to think through with you guys a little more where we think it'll go. For example a YouTube-like podcast portal seems like a potential option (i.e. moving away from…

To follow on to your YouTube analogy, does anyone know of a place where someone can make a playlist of podcast (or radio) excerpts? To me a one hour commitment to a podcast seems daunting, especially if it hasn't been well recommended. Is there a place where I can find 3-5 minute "best of" clips for given episodes, maybe arranging those together to form a playlist about a topic? Like "Today we have Bob Smith on the SoandSo show talking about Big Data, John Doe talking about something on the BlahBlah show, followed by..." and I could easily listen to the whole show if the excerpt sounded interesting.

Might be a stupid idea as I'm not a big podcast consumer.

Re: 16 Things

#110
post #51

Earlier quoted context omitted.

Yep. Information security is a nonalgorithmic problem. Much as people might like to disagree or pretend otherwise, it is fundamentally at odds with a service that can scale to meet the needs of clientele in an automated manner. The most successful companies in that space are consultancies that can deliver personalized results to every client on every engagement, and while they are very successful, they will never be…

Something I used to think about during my tenure as a graduate student in computer security: has anyone written the definitive book/study/dissertation on why security incidents happen? As mentioned elsewhere in this thread, it's a very complex problem involving operational, economic, and technical factors, suggesting (as others have mentioned) it's not something that really can be "sold". Watching bugtraq for a while…

For your example, this happens to be relatively simple. The design is boolean - "Let the corporate network be accessible to the outside world? Y/N" and this is almost universal to implement because network access works the same way almost everywhere. What you're doing is essentially whitelisting access - you can simplify that to an algorithmic problem and solution space.

Web applications are not the same way. For example, enforcing policy restrictions between users of different permission levels suddenly becomes a custom project depending on what each user can do, what the application does, what functionality is mapped to different permissions, etc...it is not as simple as whitelisting. It is highly contextual.

Unfortunately, web applications are also where most vulnerabilities are found, not the network (at least not anymore).

Post reply on HN