Well, yes and no. Yes, when a single-source strategy is adopted, the spec is written for that supplier, but that does not mean that all cases where the spec is written with a specific supplier in mind are single-source bids. Sometimes it's an end-user trying to manipulate a bid so that only one supplier can answer. That's the distinction I'm trying to make.
Single-sourcing is a procurement strategy, not an outcome of RFP manipulation. When a purchase is put forth, the end-user[1] writes the specifications, and procurement staff[2] determines the procurement strategy. If the end-user can convince procurement staff that only a single provider can meet their needs, then they move forward with a single-source procurement.
When a specification is written specifically for a single vendor, it's not called single-source; although the end-user probably advocated for single-source during negotiations with the procurement department. Not surprisingly, this is a constant source of friction for procurement departments. End-users almost always want to buy their preferred solution, and especially in IT. There are often good reasons, but I digress.
In some contexts, the single-source procurement strategy is simply not available; usually due to procurement law. This is when you most commonly see manipulation of specification. However, competing vendors can challenge the procurement in court through a procedure usually called a "bid protest". That's not exactly what's happening here, but it's similar.
1: The person who will ultimately use/implement the purchased goods/services.
2: Usually a separate department responsible for ensuring that goods/services are "responsibly" procured.
> The problem is, in the current system, it's impossible to figure out who's doing it.
No, the problem is who is responsible for paying the fines. If the terminating carrier were responsible for paying robocall fines, this problem would be solved overnight.
But for some reason, the American people can't stomach this solution because we have a obsession with perfection in justice. The counter argument is, "The carrier isn't the one who is making the robocalls!" My POV is, that doesn't matter.
Unless carriers are obliged to participate in creating a network that supports compliance, law enforcement will always hit a brick wall when attempting to enforce existing laws. Carriers have been given _years_ to solve this problem, and in 2019 we're pitched STIR/SHAKEN... Seriously?
Make the problem more expensive than complacency and it will get solved.
> The authentication info is bigger than the call data required to set up a call.
That's not a counter-argument, it's a cop out. SSL negotiation uses more bandwidth than a vanilla HTTP GET request too, but sometimes a secure channel is more important than preserving bandwidth.
> Telcos with TDM or CDMA transmission have serious backwards compatibility problems.
More cop outs. In order to resolve problems, you have to make changes. You can't show up to the solutions meeting and proclaim that a problem can't be solved because "the old system doesn't work that way." Sometimes you must abandon the legacy systems to solve new problems.
In the US, voice time is rarely metered for domestic calls. Even discount providers offer unlimited domestic calling. The only case where you see metered calls is for pre-paid SIMs, which aren't very popular here, because you can get unlimited talk & text for $25/month.
This is hard to explain to anyone who hasn't done business with the Federal government, but your visions of national security letters are very much on one end of a broad spectrum. At the other end of the spectrum is the mundane.
The mundane includes things like contracting with the Federal government or even certain government contractors. Our company just contracted with PAE, and PAE contractors must agree to much of the same Federal Acquisition Regulations as someone doing business directly with the Federal government. One of the vendor forms was 37 pages long, and it contains sections explicitly requiring certifications that your company will comply with sanctions. The form binds the signer to personal culpability for failure.
So if you're a company contracting in this process you're tasked with preventing delivery of your product to Iran, and the Federal government gets to set the bar, not you. If you fail to meet the bar, you end up in Michael Flynn's shoes, only far less public. How long of a bet is it to expect a Federal bureaucrat will interpret compliance the same way you do? Are you willing to risk inquiry if your opinions differ?
I don't like what's happening here. I don't like it at all, but I know just enough about dealing with the Federal government that I can smell the odor from here.
Heh. Seems everyone has decided to shoot the messenger.
You may disagree with the policy, but ryaymercer isn't wrong. Living in startup land where everything is light, you move fast, and things get broken, it's very easy to overlook that there is this 500 lb gorilla in the corner just waiting to smash you into pulp for doing the wrong thing.
My guess is that something internally at Slack has triggered this. It seems likely that they're in the midst of contracting with a Federal agency, or something of the sort. When you do business with the Federal government, all manner of hell is unleashed on you in the form of paperwork and due diligence. "Negotiation" boils down to litigation, and litigation is god damned expensive.
I am not saying what's happening is right. I'm simply pointing out that this is the culmination of decades of policy and momentum within our government. Wagging our collective fingers at Slack isn't going to change a thing. What can Slack do? Let's say they pass on whatever opportunity is driving this ridiculous witch hunt. So then what? Some Federal agency doesn't get to use their messaging platform? Who cares? Nothing changes.
It all starts with asking the right questions, and ryanmercer's post likely contains the answers to a number of questions that few people are asking: what's motivating this change, who is responsible for the policy, and how can our community affect change to prevent it in the future?
I haven't commented in over 3 years, but you're the first person I've seen mention Vero Beach on HN in the 8 years I've participated. As a Vero native, your comment resonates.
> Even with Time Machine backups, you still spend many hours setting configs after a restore.
But how many hours do you spend establishing, testing, and maintaining a backup plan that mitigates the risk of spending a few hours getting back to working status after a restore?
In my experience, TimeMachine is wonderfully effective at restoring system state (including things like shell customizations, dotfiles, etc). The marginal return on investment in more comprehensive backup setup just doesn't pay dividends. Of course, there's the issue of offsite backups, which typically aren't as comprehensive as TimeMachine.
The point I'm making is that technical folks often have a hard time making value judgements as it relates to technology. Having a backup of your data is 100% necessary. No argument there. Having a backup of your system state? That's not as high a priority, because you're mitigating a future time investment with a current time investment. You have to weigh the two against each other: time spent today versus potentially time spent in the future.
In the README, this description is given of the process:
"When the list of repositories has been compiled, it proceeds to gather all the filenames in each repository and runs them through a series of observers that will flag the files, if they match any patterns of known sensitive files. This step might take a while if the organization is big or if the members have a lot of public repositories."
Digging in to the source code under `/lib/gitrob/observers/`, you'll find `sensitive_files.rb` [1]. It looks like this class loads patterns from `patterns.json` [2]. This file contains patterns that match common sensitive files like private key files, common configuration files, command history files, and config files. It has the ability to match by path, filename, or extension.
No tool can look at a file and say for sure if it contains sensitive information, but this list looks like a good start for flagging common mistakes. I'm sure the author would appreciate pull requests to patterns.json as well.
The phrase "sector defining" is commonly used to say that a car defines the target parameters of the sector at the time it is present. Not necessarily that that it was the first in the segment.
The debate over whether mid-engine is superior to rear-engine is not an open and shut case. Although proponents of either camp would have you believe otherwise. The advantages of mid-engine are en vogue, so I won't repeat them here, but here are some advantages to a rear-engine car that are often dismissed:
Under acceleration, a rear-engine car has an almost absurd traction advantage over any other engine packaging configuration. For example, under acceleration, the 911 has a 74% rear bias, where the Cayman has a 67% bias.
Under braking, a rear-engine car has better weight distribution as well. Again, the 911 has a front rear distribution of 58/42 versus 64/36 for the Cayman.
I'm not nearly well versed enough in vehicle handling dynamics to hammer out a full-blown debate, but I have read very compelling arguments from both sides of the debate. I transisioned from the "mid-engine is the only compelling packaging format" camp to the "maybe the rear-engine format isn't completely insane" camp.
Good thing you checked Wikipedia :) I was just about to point out that VW Beetle motors had a smallish oil cooler in (or near) the fan shroud at the front of the engine.
That's true, but there are hard limits to the heat conversion efficiency of an otto-cycle internal combustion engine [1].
Given two engines, both optimally designed to approach those limits, air-cooling is not as practical or as efficient as water-cooling. This means that for a given displacement, you'll hit the boundaries of air-cooling before you will water-cooling. If you want to continue to increase your power for a given displacement, you have to find a way to dissipate the wasted heat energy. That leads you to water-cooling.
It's not that water cooling is that much more efficient, but that it scales more easily. With air-cooling, you have limited space around the cylinders for cooling fins. The head is particularly problematic because of the valve gear. With water-cooling, you can increase the dimensions of the radiator in three dimensions to improve heat dissipation capabilities.
> Was it necessary to make the point as he did when he did? I don't think so.
Feynman was deliberate in his means of communication. Was it necessary? That's a tough one to answer.
As crazy as it sounds, causing your listener to be frustrated can be a very effective rhetorical device. Feynman's goal was to get the asker to think carefully about the question he had asked. Consider that, in a way, he was relaying his own sense of frustration to the asker.
Sometimes, in order to have someone truly understand you, it is necessary for them to shift their emotional state to one more similar to yours. The beauty of Feynman's explanation is that he hits the listener hard, then walks them back to a place of understanding. I thought it was a brilliant bit of teaching.
Was it necessary? I think that a short period of discomfort is a small exchange for a deeper understanding of not just how the physics of magnets work, but an understanding of how to properly ask questions, and just how deep the physics rabbit hole goes.
Congrats on the 1.0 release guys! We've been using Tabula since the days before the app packaging. It's been really cool to observe development progress, and especially to see you guys tackle the problem of distributing as an application.
The first time I visited the site, I really had no idea what I was doing. I'm going to write up my experience here for the benefit of the author.
I'll admit that I did not read the blurb on the landing page carefully. While that's a little embarrassing to admit, it's also typical user behavior. Users don't read; they scan. I did what a typical user would do: I scanned the copy and looked for the clicky-bit, and then I clicked it.
From there, I'm presented with a page dominated by two images. I tried to figure out what the hell I'm supposed to do.
Hrm... I see two obvious clicky-bits on this page: Agency and Porn buttons. The image over the Agency button looks pretty agency, and the image over the Porn button looks pretty porny.
What the hell am I supposed to discern here? Maybe I'm supposed to figure out which one is an actual image used by an agency or in a porn film.
I click my first answer.
Aaaaah geeze.
Fortunately, I'm on my free time and my wife has a sense of humor. She asks me to please close the door while baitin'.
"Fuck this, this isn't any fun," I think. And I close the window.
I drop a comment warning other HN users that they're going to be porn-audio-bombed by the site and move on.
A couple of days later, I notice that I've collected a few karma points and check my profile page to see what sage advice was deemed useful by the HN crowd. Heh, it was just my warning label and a swipe I took at Rob Reinhart that boosted my score.
I revisit the agencyorporn.com link, this time prepared for what awaits me.
Headphones? Check.
Smart kid who always reads directions attitude? Check.
Click!
Reading...
"Guess which of these tantalizing names belong..."
Names!? Wait, there's text on the pages?
I click the Start button for the second time in my life and I see what is clearly a camera and a dildo. Mkay, where's the "name"? I start at what I think is the top (the border of the two contrasting colors). Nope.
I really take a step back and start at the actual top. Holy shit, there it is. It's been staring me in the face the whole time! The text at the very top of the page is what I'm supposed to evaluate.
I try a few and quickly get bored with the concept (sorry). The audio also seems like it's leveled to be pretty loud. I'm kind of put off by the whole experience and I exit.
That's my experience as a user. As a product guy, my feedback would be this:
Users don't read.
If I'm supposed to focus on something, please make it the center of focus.
Users don't read!
Use visual hierarchy to communicate importance.
On the landing page, what is the most important element? Users are drawn to imagery before text, so the most important element on the screen is the image of the woman to the right. Secondarily, my eye was drawn to the Agency or Porn logo, then the start button. The instructions are the fourth most important thing on the page, visually. It's not clear that they are instructions. IMO, they should be labeled as such. The fact that they started with what appears to be a rhetorical question caused me to evaluate the text as a "blurb" (marketing copy), so I ignored it. My mind jumped directly to, "I'm already sold, give me the game!"
In the game interface, the visual hierarchy is out of whack as well. The item I'm supposed to evaluate is outside the visual grouping of all the game control elements. It looks like a page title, not a game element. Visually, the most important parts of the page are the two giant images. These images communicate (reinforce, really) the function of the buttons for "Agency" or "Porn". They are supporting elements, not primary elements. The "name" I'm supposed to evaluate should be the most important item on the screen.