100% agree with this, seems weird to call an engineer “smart” for triggering an API that allows any input but can’t handle it. I also kind of doubt it was an engineer testing vs some much more subtle issue as billing is in line for everything.
If this was 10 years ago, this was also the era when any real customer could write any ARN (resource identifier) they wanted including commas due to no expected standardization across services. This could have been trivially triggered by a customer.
Just a matter of time if no one is escaping commas in billing files.
Not earlier commenter but their username is a reference to “ableton live” which is music production software. Not “able to live” which is just a one letter difference
It’s less that they’re flailing and more that it’s become some sort of lord of the flies culture with senior leaders directly competing with each other to try to take their bite of the pie.
The way AWS is structured with strongly owned independent businesses just doesn’t work, as GenAI needs a cohesive strategy which needs
1. An overall strategy
2. A culture that fosters collaboration not competition
Or at least an org charts to make them not compete with each other. (Example: Q developer vs Kiro)
I bet if you looked at the org charts you would see these teams don’t connect as they should.
As a heavy EC2 user who hasn't used ECS, the behavior makes perfect sense as ECS is running on EC2 but unless I sat and thought about it my first instinct would be that AWS would make it "secure by default" on a container level since containers often have different permission requirements and so the container would be the security boundary.
That said, I'm guessing it would have been obvious to anyone once they start setting up IAM permissions and therefore not much of a pitfall.
So it's a good reminder, but I agree with you, maybe the article doesn't need to be so long to get to the same point.
It's a reasonable take from the author, but the argument that you shouldn't use a tool you don't understand cuts both ways. Avoiding powerful tools can be just as much of a trap as using them blindly.
Like any tool, there's a right and wrong time to use an LLM. The best approach is to use it to go faster at things you already understand and use it as an aid to learn things you don't but don't blindly trust it. You still need to review the code carefully because you're ultimately responsible for it, your name is forever on it. You can't blame an LLM when your code took down production, you shipped it.
It’s a double-edged sword: you can get things done faster, but it's easy to become over-reliant, lazy, and overestimate your skills. That's how you get left behind.
The old advice has never been more relevant: "stay hungry."
I think most folks would disagree that the other commenter is on the "extreme" end of the privacy spectrum. It's very context specific. Some ISPs are state specific or even town specific.
I agree with my sibling comments, your evasiveness isn't helping us make up our own opinions on this matter.
While I'm pro right to be forgotten, and do believe HN should allow an account delete.
But HN's ethos is to inspire discussion and readability of it. Lack of a delete seems to be by design so that conversations are always readable.
You can see the spirit of that in their guidelines[0] such as "Comments should get more thoughtful and substantive, not less, as a topic gets more divisive".
You can further see that in the design in how they handle deletes [1], where once "archived" things are permanent
I am not a lawyer, but GDPR compliance looks like it doesn't quite apply due to not necessarily being targeted at European citizens https://gdpr.eu/companies-outside-of-europe/
This is one of the great parts of America, personal liberties. But simultaneously one of the downsides of the individual > whole scheme, sometimes sacrifices hurt the individual but are good for the whole.
Quite the conundrum, once you go down the whole > individual route, where do you stop?
I understand your sentiment and I’m sure you’re well meaning. But Asian Americans are one of the most diverse groups, it’s a huge part of the world and part of the problem is people assuming all Asian Americans are the same personality
Part of the problem is Asians don’t vote as a block, so who will protect them? If for a group of people, votes are split, who will look out for their needs?
For book suggestions I would suggest the old classic: “How to Win Friends and Influence People”
Talks about active listening, and remembering things about others.
As for generally not being as narcissistic, I think you’re already on the right track. 90% of being aware of other people, is being aware that you’re sucking up the airtime. Conversations are dances, both parties need to be engaged
Facebook is big enough to acquire almost any company they want
> Can this mean that they are going to?
Put aside whether or not it makes sense to acquire dropbox.
To me this looks like they will not since it could look like a conflict of interest to stockholders and therefore a breach of fiduciary duty. Drew would stand to make a ton of money at the cost to FB shareholders in a dropbox buyout and it's not necessarily to the shareholder's benefit
If facebook wanted to buy dropbox, the safer play would be to buy dropbox, then add Drew to the board of directors
Great article, covering something we should probably keep in mind.
Higher education is often a needless gatekeeper for keeping those with generational wealth wealthy
Often a subtext that I feel is missing here is that in the end people aren't that different on average, and our parent's wealth matter more
Today, zip code is a pretty accurate predictor of success, there's so much embedded in a zip code such as wealth, industry, and safety that affects kid's outcomes.[0]
If this was 10 years ago, this was also the era when any real customer could write any ARN (resource identifier) they wanted including commas due to no expected standardization across services. This could have been trivially triggered by a customer.
Just a matter of time if no one is escaping commas in billing files.