<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ian_d</title><link>https://news.ycombinator.com/user?id=ian_d</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 07 Apr 2026 01:57:28 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ian_d" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by ian_d in "What being ripped off taught me"]]></title><description><![CDATA[
<p>Evergreen advice from the design side: <a href="https://www.youtube.com/watch?v=jVkLVRt6c1U" rel="nofollow">https://www.youtube.com/watch?v=jVkLVRt6c1U</a> (Mike Monteiro: F*ck You, Pay Me)</p>
]]></description><pubDate>Mon, 06 Apr 2026 14:04:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=47661103</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=47661103</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47661103</guid></item><item><title><![CDATA[New comment by ian_d in "Bucketsquatting is finally dead"]]></title><description><![CDATA[
<p>The _really_ fun bucket squatting attacks are when the cloud providers themselves use deterministic names for "scratch space" buckets. There was a good DC talk about it at DC32 for AWS, although actual squatting was tough because there was a hash they researchers couldn't reverse (but was consistent for a given account?): <a href="https://www.youtube.com/watch?v=m9QVfYVJ7R8" rel="nofollow">https://www.youtube.com/watch?v=m9QVfYVJ7R8</a><p>GCP, however, has does this to itself multiple times because they rely so heavily on project-id, most recently just this February: <a href="https://www.sentinelone.com/vulnerability-database/cve-2026-1727/" rel="nofollow">https://www.sentinelone.com/vulnerability-database/cve-2026-...</a></p>
]]></description><pubDate>Fri, 13 Mar 2026 12:27:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=47363538</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=47363538</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47363538</guid></item><item><title><![CDATA[Zigazoo: GCP Security at "The Largest Social Network for Kids"]]></title><description><![CDATA[
<p>Article URL: <a href="https://amenbreakpoint.com/posts/zigazoo/">https://amenbreakpoint.com/posts/zigazoo/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46944005">https://news.ycombinator.com/item?id=46944005</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 09 Feb 2026 11:15:33 +0000</pubDate><link>https://amenbreakpoint.com/posts/zigazoo/</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=46944005</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46944005</guid></item><item><title><![CDATA[New comment by ian_d in "Flock CEO calls Deflock a “terrorist organization” (2025) [video]"]]></title><description><![CDATA[
<p>Mountain View recently turned off their Flock installs after they discovered Flock had enabled data sharing without notice and other agencies were searching through MV data.<p><a href="https://www.malwarebytes.com/blog/privacy/2026/02/flock-cameras-shared-license-plate-data-without-permission" rel="nofollow">https://www.malwarebytes.com/blog/privacy/2026/02/flock-came...</a>
> A separate “statewide lookup” feature had also been active on 29 of the city’s 30 cameras since the initial installation, running for 17 straight months until Mountain View found and disabled it on January 5. Through that tool, more than 250 agencies that had never signed any data agreement with Mountain View ran an estimated 600,000 searches over a single year, according to local paper the Mountain View Voice, which first uncovered the issue after filing a public records request.<p>A different town (Staunton, VA) also turned of their Flock installs after their CEO sent out an email claming:<p><a href="https://www.aclu.org/news/privacy-technology/flock-ceo-goes-ballistic" rel="nofollow">https://www.aclu.org/news/privacy-technology/flock-ceo-goes-...</a>
> The attacks aren't new. You've been dealing with this for forever, and we've been dealing with this since our founding, from the same activist groups who want to defund the police, weaken public safety, and normalize lawlessness. Now, they're producing YouTube videos with misleading headlines.</p>
]]></description><pubDate>Thu, 05 Feb 2026 20:53:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=46905139</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=46905139</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46905139</guid></item><item><title><![CDATA[New comment by ian_d in "A16Z hires acquitted former Marine Daniel Penny as an investor"]]></title><description><![CDATA[
<p>If you don't remember, Daniel Penny is the ex-Marine that killed a homeless man on the NYC subway then was found not guilty of criminally negligent homicide.</p>
]]></description><pubDate>Mon, 19 Jan 2026 20:46:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=46684265</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=46684265</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46684265</guid></item><item><title><![CDATA[A16Z hires acquitted former Marine Daniel Penny as an investor]]></title><description><![CDATA[
<p>Article URL: <a href="https://techcrunch.com/2025/02/04/a16z-hires-acquitted-former-marine-daniel-penny-as-an-investor/">https://techcrunch.com/2025/02/04/a16z-hires-acquitted-former-marine-daniel-penny-as-an-investor/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46684264">https://news.ycombinator.com/item?id=46684264</a></p>
<p>Points: 5</p>
<p># Comments: 2</p>
]]></description><pubDate>Mon, 19 Jan 2026 20:46:01 +0000</pubDate><link>https://techcrunch.com/2025/02/04/a16z-hires-acquitted-former-marine-daniel-penny-as-an-investor/</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=46684264</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46684264</guid></item><item><title><![CDATA[New comment by ian_d in "Encryption made for police and military radios may be easily cracked"]]></title><description><![CDATA[
<p>There was actually a good DC31 talk called "Snoop On To Them, As They Snoop On To Us" kinda in this vein, but with Bluetooth devices that are part of a lot of cop's gear.<p><a href="https://www.youtube.com/watch?v=cO1JSzAdPM8" rel="nofollow">https://www.youtube.com/watch?v=cO1JSzAdPM8</a></p>
]]></description><pubDate>Fri, 08 Aug 2025 10:36:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=44835471</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=44835471</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44835471</guid></item><item><title><![CDATA[Zigazoo, A Firebase Boogaloo: Security at "The Largest Social Network for Kids "]]></title><description><![CDATA[
<p>Article URL: <a href="https://amenbreakpoint.com/posts/zigazoo/">https://amenbreakpoint.com/posts/zigazoo/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=44634808">https://news.ycombinator.com/item?id=44634808</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 21 Jul 2025 13:23:45 +0000</pubDate><link>https://amenbreakpoint.com/posts/zigazoo/</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=44634808</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44634808</guid></item><item><title><![CDATA[New comment by ian_d in "The young, inexperienced engineers aiding DOGE"]]></title><description><![CDATA[
<p>Elon is also now claiming to have "deleted" 18F (<a href="https://18f.gsa.gov/" rel="nofollow">https://18f.gsa.gov/</a>): <a href="https://x.com/elonmusk/status/1886498750052327520" rel="nofollow">https://x.com/elonmusk/status/1886498750052327520</a></p>
]]></description><pubDate>Mon, 03 Feb 2025 20:07:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=42922281</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=42922281</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42922281</guid></item><item><title><![CDATA[New comment by ian_d in "What happened to Mint?"]]></title><description><![CDATA[
<p>I'd go check the YNAB forums, there's a lot of v4 users who really hate the cloud version. I tried to switch and gave it up for two reasons:<p>- Import from v4 is super broken for credit card accounts and I ended up with weird positive balances that don't add up based on any combination of transactions. Forum advice was "start over".<p>- You cannot tag income as "available for next month", instead all income must be immediately budgeted. Which is different than the old YNAB advice of being a month ahead. Forum advice is to earmark it a special category then fix it when the next month lands (<a href="https://support.youneedabudget.com/t/63pgpp/budget-using-only-one-months-income" rel="nofollow">https://support.youneedabudget.com/t/63pgpp/budget-using-onl...</a>).<p>- No side-by-side month view. You can only view one month at a time.<p>The differences were too much for me and the import was so borked that I immediately gave up and stuck with v4.</p>
]]></description><pubDate>Thu, 23 Jan 2020 18:23:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=22130149</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=22130149</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22130149</guid></item><item><title><![CDATA[New comment by ian_d in "Show HN: SSM/KMS/ENV-aware Go template file fetcher and parser for AWS ECS"]]></title><description><![CDATA[
<p>Since ECS is missing k8s configMap/secrets style integrations for SSM and KMS I wrote this small tool to help get secrets into place without a bunch of ECS-specific custom entrypoint code. Scratches a particular itch I've encountered a number of times working with ECS and thought it might be useful to anyone else running AWS ECS services.</p>
]]></description><pubDate>Fri, 21 Sep 2018 13:48:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=18039639</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=18039639</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=18039639</guid></item><item><title><![CDATA[Show HN: SSM/KMS/ENV-aware Go template file fetcher and parser for AWS ECS]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/ian-d/ecs-template">https://github.com/ian-d/ecs-template</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=18039637">https://news.ycombinator.com/item?id=18039637</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Fri, 21 Sep 2018 13:47:59 +0000</pubDate><link>https://github.com/ian-d/ecs-template</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=18039637</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=18039637</guid></item><item><title><![CDATA[New comment by ian_d in "San Francisco Officials to Tech Workers: Buy Your Lunch"]]></title><description><![CDATA[
<p>I could really see something like France's "tickets restos" / meal voucher system benefitting everyone. Fitting for smaller companies who want to provide a perk w/out an on-site cafeteria, puts some money into the local economy, a little tax relief for employees who are normally buying food for lunch...</p>
]]></description><pubDate>Wed, 01 Aug 2018 18:18:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=17665290</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=17665290</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=17665290</guid></item><item><title><![CDATA[New comment by ian_d in "[dead]"]]></title><description><![CDATA[
<p>The DHS Press Secretary's response is particularly infuriating.<p><a href="https://twitter.com/SpoxDHS/status/1009502457058201600" rel="nofollow">https://twitter.com/SpoxDHS/status/1009502457058201600</a></p>
]]></description><pubDate>Wed, 20 Jun 2018 21:56:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=17360172</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=17360172</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=17360172</guid></item><item><title><![CDATA[New comment by ian_d in "Show HN: Gripsweat, rare vinyl auction and sales with sound clips"]]></title><description><![CDATA[
<p>It's Record Store Day again and I thought I'd share the site that I've been running for a few years now. It collects vinyl auctions and sales daily (with sound clips), and is at >10M items and >500k sound clips.<p>I've killed hours just clicking through sound clips to find 45s and LPs that probably otherwise would have slipped past me. This is especially nice for "deep" genres like:<p>Afrobeat: <a href="https://goo.gl/UG6kZm" rel="nofollow">https://goo.gl/UG6kZm</a><p>Reggae: <a href="https://goo.gl/tHvJyA" rel="nofollow">https://goo.gl/tHvJyA</a><p>Garage: <a href="https://goo.gl/51cJpQ" rel="nofollow">https://goo.gl/51cJpQ</a><p>Northern Soul: <a href="https://goo.gl/Jj88Bd" rel="nofollow">https://goo.gl/Jj88Bd</a><p>etc,etc<p>Or you can just watch RSD2018 get out of hand: <a href="https://goo.gl/VXN8w8" rel="nofollow">https://goo.gl/VXN8w8</a></p>
]]></description><pubDate>Sat, 21 Apr 2018 14:26:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=16891530</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=16891530</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=16891530</guid></item><item><title><![CDATA[Show HN: Gripsweat, rare vinyl auction and sales with sound clips]]></title><description><![CDATA[
<p>Article URL: <a href="https://gripsweat.com">https://gripsweat.com</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=16891528">https://news.ycombinator.com/item?id=16891528</a></p>
<p>Points: 3</p>
<p># Comments: 1</p>
]]></description><pubDate>Sat, 21 Apr 2018 14:26:04 +0000</pubDate><link>https://gripsweat.com</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=16891528</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=16891528</guid></item><item><title><![CDATA[New comment by ian_d in "Show HN: Vinyl record and sleeve grading tool"]]></title><description><![CDATA[
<p>Missing the real-life seller grades:<p><pre><code>  EX- / VG++(+)  
  M+  
  Skip on A2, otherwise MINT  
  SOLID PLAY COPY
</code></pre>
(Kidding, nice tool!) Goldmine does have a bit of a no-man's-land between NM and VG+, though.</p>
]]></description><pubDate>Sat, 21 Apr 2018 13:56:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=16891430</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=16891430</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=16891430</guid></item><item><title><![CDATA[New comment by ian_d in "An Open Source Tool to analyze wasted EBS capacity in your AWS environment"]]></title><description><![CDATA[
<p>Nice tool, thank you for releasing it.<p>Unfortunately, in my experience it's a pretty normal strategy to over provision EBS gp2 volumes to get the IOPS since they scale linearly up to ~10k. I think that's the break-even point where it's actually cheaper to switch over to provisioned IOPS volumes.<p>So we'd have a number of little-utilized (in terms of data actually stored) 3TB drives just to avoid paying for provisioned IOPS.</p>
]]></description><pubDate>Sat, 17 Mar 2018 20:58:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=16609030</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=16609030</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=16609030</guid></item><item><title><![CDATA[New comment by ian_d in "Why George Guidall Is the Undisputed King of Audiobooks"]]></title><description><![CDATA[
<p>I like Carlin's cadence, but I really wish they would run everything through some compression. The volume range between his "speaking" voice and when he's quoting someone is HUGE and sometimes requires mucking around with the volume to keep it listenable.</p>
]]></description><pubDate>Wed, 23 Aug 2017 16:59:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=15083127</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=15083127</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15083127</guid></item><item><title><![CDATA[New comment by ian_d in "How to present a GitHub project for your resume (2016)"]]></title><description><![CDATA[
<p>Yeah, here in the slums of higher-ed dev/IT just having a github repos of <i>any</i> original code makes an applicant novel. We never really discussed an applicant's github code with them, but we absolutely read through and took it as a very positive hiring signal.<p>You don't have to have a huge contribution history or a project with a ton of stars, just having <i>something</i> out there matters to some places.</p>
]]></description><pubDate>Sat, 29 Jul 2017 15:05:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=14881548</link><dc:creator>ian_d</dc:creator><comments>https://news.ycombinator.com/item?id=14881548</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=14881548</guid></item></channel></rss>