Hacker Newsnew | past | comments | ask | show | jobs | submit | arcfour's commentslogin

As a security engineer I have no idea why these sandboxes would even be connected to the internet at all for tasks that aren't intended to use the internet. A package proxy? Why not run our own internal cache? Then we aren't at (as great a) risk of someone poisoning it with a malicious package during model training, for example...

We’re hiring. :)

(And we’re fixing many of these things, but worth noting this happened at a third party vendor, not in our lab)


Could you add any detail on why Google uses (used?) Irregular? I wouldve thought that type of service would be a core competency that Google needs internally.

Even if you had it internally (which we do), there is so much surface area and it’s such a novel space that you’d want as much testing on it as possible. There aren’t many vendors, and irregular is one.

AFAICT one fundamental issue is that they don't seem to have hired actually security engineers or experts to do any actual security.

They are hiring philosophers and therapists to psychoanalyze the things. It’s just absurd to assume that they aren’t hiring top notch security engineers.

They made mistakes, obviously, but people are so conspiratorial these days that they just assume unlikely things off the jump.


No, I think they didn't hire proper security engineers because they just don't understand what that means. Incompetence, not malice.

Can we try to play nice now and recognize that other people have diverging, but valid, interests from your own? For example, securing things?

Passkeys are not about securing things.

The entire value proposition, and the reason big sites are pushing them, is they take the user out of the loop of authentication. You are no longer authenticating the user, you're authenticating the users device.

For websites you don't have to worry about cookie theft and dealing with the support load of users needing their accounts reset or dealing with fraud. You can also do some level of attestation to hardware which makes automated account creation more difficult.

For the user it offers no additional benefits. You still have something secret that gets presented to a website to login. Password managers solved this problem. But now for some reason you can't log in when you buy a new laptop.


It is playing nice to criticize things. It's not just "different priorities", passkeys have intentional trade offs which cause them to be "more secure" but in ways that users do not want because it negatively affects them. The intentional trade off made in the name of "more security" makes them wildly inconvenient and risks causing massive lockout. Like removing all the staircases from people's homes and replacing them with climbing walls all in the name of "security". You can't just diffuse that by say "well we want banks to be more secure, we have different priorities."

I am already seeing my "normie" friends getting locked out of accounts due to not understanding passkeys. If they don't have their phone, or it's dead, or it breaks, or is stolen, they just can't access their account anymore. They have no idea how they work or what they're trading off, nor do they understand that they should have prepared for this scenario ahead of time somehow. Upon telling them "yeah you have to use your phone now that you have a passkey" they all universally say "wtf, that's stupid, I never want to have that happen again, I will never use a passkey again."

Passkeys should never have been built for general audiences, they are a huge mistake, I hope they cease to be relevant and die due to everyday folks realizing they're inconvenient and the "more secure" gains ain't worth it for the usability nightmares.


"I am already seeing my "normie" friends getting locked out of accounts due to not understanding passkeys."

In a weird way this is good news for us. If people are losing passkeys, getting locked out, and incurring non-trivial support costs as a result to the relevant companies, then there's no way those companies will crank down even harder by requiring hardware keys.

As an option, I don't mind it existing for situations like a work environment. Work environments are so much easier because there is a clear line to get my credentials reset, from scratch if necessary, even if I lose everything. The problem is that the consumer authentication case is even harder because it lacks that clear line without also creating a backdoor.

So I insist on centralizing my passkeys into a password manager. I have no passkeys outside of my password manager and will continue to reject them. If it's important enough to slap authentication on, it's important enough for me to not lose it because I couldn't choose where to stick it, which is in a basket that I protect very, very carefully.

Honestly I just don't see how something like Amazon could ever turn on the "require hardware key" feature without blowing their own foot off, or really any consumer-facing service. Everyone loses keys. To a first approximation nobody is going to buy three keys and correctly manage setting up all of them to work with every service. Even if we magically stipulate that all sites support it and they all have some integrated unified approach so that there's no software-side friction at all to register all three at once everywhere, you just get too many people who stuck all three keys on one keychain, people whose houses burned down, people who so successfully stored both backups "securely" that they have no memory of where they are anymore or how to get them back, an endless parade of lost keys. The consumer as a whole is not capable of managing hardware keys.

Given how often my household loses its second car keys for extended periods of time I am not exempting myself from this. My work key lives a much simpler life... it just sits in one place, doing work things. My family would hardly last a month if everyone had to carry around physical keys to log in to things.


Why should I recognize that as valid interest, when it's straight out hostile to me? I know why they are doing that. It doesn't oblige me to accommodate their selfish interests.

I'll have to remember this one the next time I hear the phone/poverty argument made in bad faith.

> some of the bots won't respect robots.txt

The link you posted literally only lists the scanner related to security/safe browsing. Why would it? What kind of bot would that be if an attacker could just put up a robots.txt that causes it to ignore the site?! And many do...for obvious reasons.

It's misleading because this implies you're getting heavy scraper traffic from Google bots that don't respect robots.txt for reasons of greed rather than because it's necessary so they can proactively avoid surfacing malicious websites.


I was thinking about this line a lot. Because yes, "not all bots" and "not in all cases".

But what gives them the right to do whatever with the sites if they claim it's for security purposes? They are not law enforcement. Moreover, other bots are missing from the docs which they clearly state on the same page. How many other bots of theirs are ignoring robots.txt?

I think we should hold Google to a higher standard than some random blogger (me).


...Because law enforcement does not have the interest, reach, or time to investigate every single cybercrime, and if they do it won't be timely - it will be after the fact, punishing the criminals, and not preventing harm.

Google is in a unique situation to protect their users, and they also want to avoid serving search results that are malicious (yes, I know about their ads problem) - so they are proactive about scanning for sites that are malicious so they can avoid sending users to them.


See, here's where I disagree. Plenty of people are in an unique position to help the law enforcement. And yet it's usually criminal to do so.

Also, I don't want Google to be the police of the internet, especially when they felt the need to drop the "don't be evil" guideline.


I feel like we have advanced technology to the point that we can't be that far off from the truth, or at least we would look more charitably back on our views now since they're grounded in observations made with the best tools we have available to us as opposed to e.g. the flat earth where you can actually see and experience the curvature of the earth without needing any specialized tooling at all.

> experience the curvature of the earth

I'm not an historian but the curvature of the world was probably explained away by some other phenomenon because, after all, the world is flat (for those experience curvature in times of flat Earth).

So to "experience" the curvature of the Earth, you first have to know the Earth is round. Much as our "bug free" software is only buggy once we find a bug, before that, the bug was a feature ;)

Similar the stars were explained away as holes in a black sphere surrounding the Earth: the light points in a night skies didn't lead to a universal acceptance of the Universe. It was telescopes that made us realize that those "holes in the sphere" were actually galaxies.

So my understanding would be, that it was Magellan circumnavigating the Earth that made folks actually "experience" the curvature of the Earth.

This might be being pedantic but I am trying to point out that "experiences" are related to understanding and perspective. Experiences are different in different contexts: hence my experiences are different to all those around me.

My interpretation of "experiences" differ according to understanding. An apple falling on my head might well have more to do with evilness of various gods than gravity before the invention of gravity. But even gravity is just another interpretation/explanation/myth to explain the "experience" falling apple.


It's just a typical enterprise PC configuration. Probably because nobody writes efficient software these days.

45 security apps cut the ram and CPU performance in half out of the gate, then you have Win11 with its web gui and users who complain about any slowness so i7 or r7 is about the norm most places / bulk big 3 oems make for business.

and rowhammer etc mitigations microcode updates

personally I have an i7 in the lab that turned into a crawl on Youtube because they started sending VP9 video by default, but i7 doesn't have hardware decode for it. Got a plugin to force h264 (h264ify) and it's back to normal.

Then you have situations where a software update adds a CPU instruction dependency and straight up doesn't work anymore.

Had to install and force-retain an old version of Spotify client on a bench lab PC because the new versions require AVX-1/2. It's a streaming audio player...


> because the new versions require AVX-1/2

Well, an 128kbit MP3 requires at least a 486DX2-66 but you also need to run the OS. /s


So the governments that install them aren't somehow complicit?

Two things can be true at once.


[dead]


Beware of cities 'ditching Flock' only to immediately replace them with Axon, which is the same thing.

[dead]


If there's anything Flock does that Axon doesn't, it's only because Axon doesn't have people smart enough to do it yet. Once the funding shifts from Flock to Axon, they'll hire the people who can make it happen, especially if enough money shifts that they can pilfer the exact same engineers.

The police want the capability. Flock just happens to temporarily have the better technology.


Axon Fusus AI is very much similar to what Flock offers. Why are you talking about body cameras to make it seem like I am comparing Flock with simple body cameras?

Does Axon retain the data it is collecting? If so, even if they have no plans to use it like Flock does, those plans can change, sometimes even without the company's blessing. They sound like the lesser evil right now, but the core issue that goes well beyond Flock, Axon, and similar companies is that if data is collected and retained, someone will find leverage to use it for their own purposes.

[dead]


Axon Fusus AI is very much the same thing to me, yes.

What’s worse is flock is actively suing those local governments hoping to override democratic process.

We don't have it in the US, I remember being annoyed that there were no more cheap cellular modules for microcontrollers for a while.

> unclear how speed didn't increase

How can you comment as if you are knowledgeable enough about aviation to speak on this with authority, but you aren't aware that turbofan engines don't have instant throttle response and need time (up to 8 seconds) to spool up? I think a little more restraint is warranted in something like this if you don't know something that basic.

You can actually do the math to work backwards and approximate how much thrust the engines were producing during that time, which was about 15,000 lbf (vs ~120,000 lbf max thrust for a 767-300er) which reduced how quickly they were decelerating by... Maybe a few % or so. But they didn't start accelerating yet. They would have in another second or two, however.

I'll agree that they should have gone around far earlier; getting non-spurious GPWS callouts on final because you're trying to dive and find the glideslope is... Crazy, and configuring landing flaps over the numbers is also crazy, and so is landing 10-20kts faster than the highest possible Vref value for the type, and everything else. But that's fairly obvious...


> How can you comment as if you are knowledgeable enough about aviation to speak on this with authority, but you aren't aware that ...

This is par for the course for HN; smart people applying first-principle thinking on unfamiliar domains for about a minute, which confirms the biases of other outsiders who vote the plausible, but not-quite-right comments to the top.


HN is particularly notorious for armchair aviation experts. I am an aerospace engineer having worked in airworthiness & certification as well as maintenance/repair/overhaul on multiple different aircraft types both fixed and rotary. I mention this only to establish my bona fides as someone who knows their shit:

The comments here during the 737 MAX MCAS thing were fucking wild. So many randoms spitting out confidently incorrect nonsense.


> The comments here during the 737 MAX MCAS thing were fucking wild. So many randoms spitting out confidently incorrect nonsense.

Maybe that helps explain some of the fraction of HN that loves LLMs: they found their soulmates.


The most ridiculous one was a poster who claimed that MCAS would run the trim at double the rate of the trim switches.

The trim motors only have 2 speeds - on and off.


I've worked on several engine families engine certification, I can't read threads about aviation on HN because my brain hurts too much from people who know nothing posting like they are experts nonstop.

It actually causes me stress because a) I need to prevent myself from posting corrections and b) from knowing that these people are everywhere and are posting fud about trains or something


That’s all forums in a nut shell. Any time you read about something you’re not personally familiar with it’s “look at all these people who know what they’re talking about… “, as soon as it’s something you are personally familiar with it’s “wtf are these people on about?!”

“Gell-Mann Amnesia“ - usually applied to media when experts scoff at stories they know to be sometimes woefully inaccurate but still accept all the other pages as gospel.

Coined by Michael Crichton (the famous author).


HN is notorious for armchair <insert-topic> experts for <insert-topic> you actually know, outside of software, computing/computing-adjacent electronic hardware and startups. “Fucking wild” “confidently incorrect nonsense” is likely the norm on most fringe topics, judging by the few I know about.

This is par for the course for HN; smart people failing to interpret a comment in a charitable light, preferring instead to author a condescending reply in an apparent effort to score imaginary points at the expense of intellectually stimulating conversation.

Turbofans being slow to spool up is jets 101.

So presumably OP never took jets 101. Neither have I. So what? The condescension remains unjustified and contrary to fruitful interaction. (See also the "lucky 10000" xkcd.)

Does any combustion engine, like the one in your car, have instant throttle response? When you hit the kickdown switch in your car there is still a delay before you start really accelerating. Now imagine a much bigger engine - it's not very difficult to guess one of those would take even longer without being familiar with the inner workings of turbine engines.

> OP never took jets 101. Neither have I. So what?

So you,me and OP will likely miss a lot of nuance when discussing jets - after all, reality has a lot of detail. Stating the existence of blindspots is not condescension, having blindspots does not make one inferior.


>This is par for the course for HN; smart people applying first-principle thinking on unfamiliar domains for about a minute, which confirms the biases of other outsiders who vote the plausible, but not-quite-right comments to the top.

You get what you incentivize. The point of the number in the top right is to incentivize. This kind of contribution is what this place is built for.


This sounds about right to me, so I upvoted.

Lots of armchair experts incorrecting each other

HN = A bunch of weirdly aggressive nerds who fail to explore nuance living in the same prison cell.

Not having handles where they should be at 1000 callout should have been an instant toga party.

That they passed their minimums and still weren't set up correctly is shocking, yes. How can you commit to landing instead of going around when you're not configured for landing?

The more egregious thing to me though is ignoring the GPWS callouts on approach because they were chasing the glideslope. If you can't maintain a stable approach, you need to go around, it's the first thing you learn.

You expect this behaviour from a first-timer in the sim, not a commercial cargo pilot.


> You expect this behaviour from a first-timer in the sim, not a commercial cargo pilot.

I'm curious - are commercial pilots reprimanded for doing a go-round after messing up the approach?


No, they're reprimanded for continuing.

https://skybrary.aero/tutorials/stabilised-approach


No. They might have to say why they went around but they can't be punished for it (that's a great way to open yourself up to liability even stripping away all of the human elements). And I can't imagine any reason that an airline would truly care since they don't want their planes crashing so they don't want to discourage pilots from going around if they need to do so. The delay incurred is usually fairly small anyways, maybe 20-30 minutes.

However I will say that the majority of unstable approaches (97%!!) do continue to landing: https://flightsafety.org/wp-content/uploads/2017/03/Go-aroun...

...but I think that most of these unstable approaches are likely marginally unstable and only in one dimension. This landing was so far outside the realm of normal it's actually mind boggling that it actually happened. Pilots are trained to immediately go around without questioning it if many of the things that happened on this flight occur (such as not being in landing configuration well before touching down!)


We're not jurors or NTSB investigators - this is just a public messageboard on a tech-focused platform. It's totally fine to speculate and wonder here ... and to be corrected respectfully.

Was anything I said disrespectful? It is not intended to be, but it may read as somewhat stern; that's more because speculating without having the fundamentals down is not what I expect from HN. The knowledge in question isn't arcane or a secret.

> How can you comment as if you are knowledgeable enough about aviation to speak on this with authority, but you aren't aware that turbofan engines don't have instant throttle response and need time (up to 8 seconds) to spool up? I think a little more restraint is warranted in something like this if you don't know something that basic.

I'm a pilot, and I don't fly turbofans/jets. Not claiming any "authority", but qualified to comment... It's not "something that basic" unless you fly in that category, there's a lot more to aviation experience than knowing a fact about an engine you don't use. (But hey, congrats to you that you know it!)

> I think a little more restraint is warranted in something like this..

More restraint than saying "unclear <i.e. to me> why ...", an exact statement about what I didn't know, which harms no one and led to several informative explanations by people who know (most of them in good spirit)?

This is what good conversation is about.

...

Anyway, the point I was making holds and is this:

Orthogonal to whether they could/should have gone around at that point, and given that they stayed on the ground after all, it may turn out that that 4 seconds of indecision (instead of pure deceleration) may have directly contributed to the fatalities at the end of the crash.


There are numerous services that will let you host static pages for free or nearly free. There are also numerous services that sit in front of your website that can block bots and reduce load on your origin server, many of which are also free, or very low cost relative to the service they provide.

The situation you are in is far less dire sounding when you consider that you have these options available to you.


Except that I don't have these options per employer policies.

So your employer is having a problem, and prevents you from using any of the available options to solve it? And you have asked them about all of them/told them about the problem? They don't like saving money?

Well, sounds like it's not your problem then.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: