@bentomn@hachyderm.io
@bentomn@hachyderm.io avatar

bentomn

@bentomn@hachyderm.io

app, web backend lately. #GameDev has-been. enjoyed #PostgreSQL. #infosec voyeur.

he/him in Oakland, California
Cover photo shows a fountain pattern in firework powder by Cai Guo-Qiang from the movie Sky Ladder (2016)

This profile is from a federated server and may be incomplete. Browse more on the original instance.

bentomn, to random
@bentomn@hachyderm.io avatar

Too many LED streetlights lighting up the water vapor in Oakland. Caught a few planes and satellites. It would take a dark and dry location. Might try the top of the ridge later.

bentomn,
@bentomn@hachyderm.io avatar

Maybe, possibly. Better get up to the ridge for a better look.

bentomn,
@bentomn@hachyderm.io avatar

Found dark sky along the ridge top.

Around midnight in Oakland, California. #aurora

bentomn, to random
@bentomn@hachyderm.io avatar

Rain two years in a row, and the grass grows quickly. Probably looking at a few more cuts before the hot and dry season arrives to blast furnace what remains.

bentomn,
@bentomn@hachyderm.io avatar

@mikeyp Yeah, I do it twice and that tends to work. This year will be three or four. The fire inspector likes to visit 4th of July weekend, which can be a surprise. It seems like I’m always racing up a ladder to clear the roof before going out of town. Now, they post the fire inspection date to the city permit website sometime in June. It helps to know the deadline for their photo shoot.

bentomn, (edited ) to random
@bentomn@hachyderm.io avatar

“Western automakers are cooked.”

A trip to the Beijing Auto Show reveals just how advanced China's EVs are. So what are the so-called "foreign" automakers doing about it?

I Went To China And Drove A Dozen Electric Cars.

https://insideevs.com/features/719015/china-is-ahead-of-west/

bentomn,
@bentomn@hachyderm.io avatar

“No, actually we don’t get any GM PHEV models in the United States," I told him. "Only a few GM Ultium-based EVs and they’re not doing all that well."

I was embarrassed. Here I was in China, trying to empathize with Western brands, thinking they were being pushed out of China due to politics and things that were no fault of their own.”

bentomn,
@bentomn@hachyderm.io avatar

“In reality, it felt like it was the late 1980s again, when American manufacturers felt like they could sell whatever underdeveloped models its accounting department had cooked up to the public, and we’d just have to deal with it. Now that I’ve seen a glimpse of what’s going on in China, the Western manufacturers, particularly the American ones, don’t seem like they’re trying at all. “

bentomn,
@bentomn@hachyderm.io avatar

“If the U.S. and Europe get what they want—a crackdown on Chinese imports—it doesn’t feel like it would result in better cars. It feels like it would keep buyers of those markets locked to cars that aren’t executed as well. It’s nakedly protectionist because deep down, all of the Western auto executives and some hawkish China pundits understand that Chinese EV and PHEV models are more compelling than what European, other Asian, and American brands have come up with.”

bentomn, to random
@bentomn@hachyderm.io avatar

Novavax found a partner to support their shot, which some notice may offer a varied immune response vs mRNA.

Sanofi strikes deal with Novavax, boosting the vaccine maker https://www.statnews.com/2024/05/10/sanofi-vaccines-novavax-covid-flu/

bentomn, to random
@bentomn@hachyderm.io avatar

Researchers pooling data from medical records, activity trackers as outreach.

“Solve Together will [..] connect researchers with individuals interested in participating in clinical research studies.

Any U.S. adult can join Solve Together, whether they have ME/CFS, Long Covid, other post-viral fatigue-related illnesses, or none of these conditions (serving as “Control” participants). Joining is free, voluntary, and participants can opt out anytime.”

Via @curelongcovid

https://solvecfs.org/research/solve-together/

bentomn, (edited ) to random
@bentomn@hachyderm.io avatar

Steve Albini. Fond memories of the many times #Shellac was in town. When there was time in the tour schedule, they would invite everyone back for pancakes on Sunday, and a morning show. It’s nice to see the letters, kranky takes, and tales of Bob Weston saving the day by salvaging a power supply to continue recording as scheduled. Guy was punk, and like many aging punks, needs more rest than they know. Fuck heart attacks. #SteveAlbini

bentomn,
@bentomn@hachyderm.io avatar

“At times, this could make it difficult to write about Shellac, as Pothast discovered when she almost persuaded bassist Bob Weston to play her some of To All Trains down the Zoom call, ahead of its imminent release. In the end, Weston couldn't be persuaded. "It just sounds like another Shellac record, he offered. "It's the same three guys in the same studio."”

https://shellac.bandcamp.com/album/to-all-trains

The Wire - Shellac Feature
https://www.thewire.co.uk/issues/484

via
https://thequietus.com/articles/34131-steve-albini-obituary

#Shellac #SteveAlbini

bentomn,
@bentomn@hachyderm.io avatar

@docpop Absolutely. Albini had this tendency to tell stories, and be extemporaneous during shows. One of the pieces for pitchfork mentioned he trained as a journalist before finding this outlet as a chronicler of live sound. It was also nice to catch a glimpse of Electric Audio, his recording studio, in some of the videos that are making the rounds. In those he talks about all the things he and his team came up with to record drums, that contributed to so many recordings over the years.

bentomn, to random
@bentomn@hachyderm.io avatar

“The US government’s dependence on Microsoft poses a serious threat to US national security,” says US senator Ron Wyden. “The government is effectively stuck with the company’s products, despite multiple serious breaches of US government systems by foreign hackers caused by the company’s negligence.”

The US Government Has a Microsoft Problem | WIRED

https://www.wired.com/story/the-us-government-has-a-microsoft-problem/

bentomn, (edited ) to random
@bentomn@hachyderm.io avatar

Reading about the process Postgres uses for core development was a big turn off.

(They do patches over email, then Tom Lane commits the change, obscuring change authors in the web views. Or at least that’s what I thought based on what I could find to read at the time.)

bentomn, (edited )
@bentomn@hachyderm.io avatar

Reading this blog, it seems my concerns from the outside looking in were somewhat valid.

Here a developer of thirty years, with fifteen years of experience on the project, relates how difficult it is to carry a feature all the way through, and land with reliable tests.

http://rhaas.blogspot.com/2024/05/hacking-on-postgresql-is-really-hard.html

bentomn,
@bentomn@hachyderm.io avatar

Read this again, and it says unless you’re able to give six months a year, you can’t realistically participate.

Few will find that time outside a corporate or academic sponsorship.

Can a different code review platform, or forum software, reduce time obligations for contributors?

Watching python core, I see a similar sunk cost to their mailing list. Also a big turn off.

For key committers/reviewers, the mailing list just works.

This is why process change is hard.

ben, to random
@ben@werd.social avatar

The lessons we're learning from XZ Utils aren't just applicable to open source projects. They're a warning to every team that builds software. https://werd.io/2024/backdoors-are-an-everyone-problem

bentomn,
@bentomn@hachyderm.io avatar

@acdha @ben It’s worth talking about because it showcases that dependencies need regular review. What code can you remove this quarter? Can you drop a complex dependency that no longer has an owner? In the case of systemd loading xz as a shared object with elevated privileges, and xz being the vector to obtain remote code execution, it gives security teams and responders a nice case study for where to focus audit efforts.👀

bentomn,
@bentomn@hachyderm.io avatar

@acdha @ben the m4 stuff and the tar packages retrieved from the servers being different than what’s on github demonstrates you can’t prevent some motivated groups. if it’s your system, you could just not load that dependency, maybe. perhaps the stability of a smaller auditable code is better than that lightly maintained github package accepting PRs. dependencies are added early and often stick. if your org doesn’t greenfield, adopting a posture for legacy remediation can help.

bentomn,
@bentomn@hachyderm.io avatar

@acdha @ben that’s certainly the hope, yes, I believe we agree on much of this. Socializing and celebrating by lines removed is easy to implement and understand. Other areas are rationalizing browser like code, build artifact caches, pdf pipelines, legacy code build tools, jobs hanging off ci/cd, terraform. Some will get lower privs, sandboxing because the audit and remediation can’t be completed in acceptable time. The end goal of this work is increased ownership of the critical paths.

bentomn, to random
@bentomn@hachyderm.io avatar

The invisible seafaring industry that keeps the internet afloat https://www.theverge.com/c/24070570/internet-cables-undersea-deep-repair-ships

gregly, to mentalhealth
@gregly@retro.pizza avatar

Okay. My Mastodon feed is, on the whole, way nicer than my old Twitter feed, but the ratio of horrifying/depressing news to interesting/happy news is still way too high.

I’m looking for suggestions for generally happy/upbeat stuff and people to follow, to try and balance things out a bit. Because I want to stay informed of the lousy stuff happening in the world, but I don’t want to be utterly deluged by it.

#mentalhealth

bentomn, (edited )
@bentomn@hachyderm.io avatar

@gregly following a few hashtags can improve the mix of good, thematic posts.

mikeyp, to random
@mikeyp@hachyderm.io avatar

Had my first Cybertruck sighting in my neighborhood. Except it was a little kid driving the Kids Cybertruck with his Dad strolling behind him.

$1,500(!)
https://shop.tesla.com/product/cybertruck-for-kids

bentomn,
@bentomn@hachyderm.io avatar

@mikeyp parent in marketing, perhaps.

hbuchel, to random
@hbuchel@hachyderm.io avatar

Kind of hate that I see people calling any tech that seems like "magic" on the surface, AI, now.

bentomn,
@bentomn@hachyderm.io avatar

@hbuchel “statistics” didn’t test well in focus groups.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • everett
  • osvaldo12
  • magazineikmin
  • thenastyranch
  • rosin
  • tester
  • Youngstown
  • Durango
  • slotface
  • ngwrru68w68
  • kavyap
  • DreamBathrooms
  • megavids
  • InstantRegret
  • ethstaker
  • GTA5RPClips
  • tacticalgear
  • normalnudes
  • Leos
  • modclub
  • khanakhh
  • cubers
  • cisconetworking
  • anitta
  • provamag3
  • lostlight
  • All magazines