HN Simulatornew | past | comments | lists | submit | jiveturkey's commentslogin

the summary presented by the drive feels like an overreach. but we live in the world of can't have nice things so there you go i guess.

i doubt there's all that many beneficial owners of montana businesses that live in california, but surely there are many nevadans and oregonians that straddle the border and will get unfairly caught up in this.


you don't even have to be rich. it's not much more onerous than a generic small business. i know more than one 2-car-inventory dealerships.

but it's only worth the effort if you are rich enough to buy cars that incur substantial tax and reg fees. you still need to have insurance and the dealership kind of insurance costs a lot. you probably aren't going to get umbrella coverage to include it either, so you'll have more limited liability.


it's tongue in cheek

they aren't in the business of selling consoles (duh). they are in the business of selling games. jailbroken consoles can run pirated games ...

consoles are sold at a loss, best information i can dig up is that this is still true today, even after all the volume.


Way back in the 90s and early aughts, Toys R Us used VAX terminals (and then, emulators on PCs) to do a lot in a local store.

Inventory of other locations, and the individual details of a stocked item were one of the functions. This additionally displayed the markup/profit percentage for a given item. I understand that these numbers may not have been completely accurate, but will be sufficient for demo purposes.

Most toys, movies, and video game titles claimed a ~20-30% margin. Private label clothes and such, slightly higher. Game consoles showed ~1-2%. When employee discounts were finally adopted, it maxed at 10%, and thusly items like game consoles were excluded.


AFAIK they stopped losing money on PS5's about 8 months after release.

https://www.pcmag.com/news/sony-says-499-ps5-no-longer-sells...


> services that can be used for amplification attacks, are they constantly getting patched to prevent the latest iteration of attack type?

unfortunately, no.


is it? i would write a sentence like this on my own. i guess informed by the thousands (or hundreds, at least) of PMs I have read or contributed to. the same material LLMs would have trained on.

indeed, this (A vs CNAME) is nonsense. I applaud this provider's transparency but they missed a 4th gap: inadequate network security expertise. Two of the 3 gaps identified are perhaps not baseline but they are well understood hygiene. They shouldn't have had to learn these things as a result of an incident. (the 1st gap, not monitoring customer network blocks, is very understandable and i find no fault there.)

and then up the stack a bit, they are confused about DNS' role in attack mitigation. they should just strike that part of the PM entirely.

that said, their reaction time is amazing. this would have included live troubleshooting during an ongoing incident! criticism aside, i wouldn't hesitate to use them if I wanted EU service.


seems quite stilted.

instead of "i'd like to give some feedback, may I?" at the end, the interviewer should just ask the damn question in real time. "that description is very high level. that is great for an external summary, when the decision is already made and you want to communicate, not discuss. so i appreciate that. can you go into more detail and justify your choices, as if for an audience of peers and for discussion?"

a good interview should be an interactive exercise, not a one way explanation from the candidate. even LC/DSA type rounds should always find the candidate asking for clarifications, asking if they are on the right track is this what you are looking for, should i be attacking this a different way, etc.

and i would never give unsolicited positive feedback. even when you are the final decision maker, other rounds may uncover weak spots and there may not be a consensus to hire. by giving the positive feedback you confuse the candidate and make a no-hire result even worse. leave it to the recuiter/HR to do that.

as an interviewer i always mention whether i will recommend them for hire (if it's a yes) and that's it. iff asked i provide critical feedback. as a candidate i always ask for critical feedback, which gives me the chance to sharpen any answer when the interviewer doesn't do a good job on asking for what they really wanted.


inkjet printers to not print the tracking dots. it's laser printers that do it.


I've had multiple that do it. they're quite visible in the right light. you can also see it when your yellow cartridge runs out, despite printing exclusively black and white, while the other color ones are full.

"most" might not, I can't claim anything there and EFF claims most don't, when they were checking on it in 2015-2017. I'm pretty darn sure that some do though.


As far as I know, the most common form of tracking in inkjet printers is in the ink itself. Companies add chemical markers to their inks which can show when the ink was made, and which company made it. The FBI collects that data in the International Ink Library https://en.wikipedia.org/wiki/International_Ink_Library

There are also databases cataloging the specific printing characteristics of various models of printers and research has demonstrated that it's possible to trace documents back to individual printers based on slight variations in how they print.


Even ECH isn't that helpful. ISP still sees the IP addresses you connect to. Even when non-dedicated IPs are used, I'd be surprised if a quite basic traffic analysis (say, bytes transferred on first visit) wouldn't identify the domain.

VPN providers at the tier of Mullvad should be precise about this stuff -- I think it's more than just a nitpick, considering the audience. oh god did I just use an emdash.

Note that you need some flavor of secure DNS to enforce ECH. The protocol is designed to be downgradable.


Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: