Hacker Newsnew | past | comments | ask | show | jobs | submit | more whitepoplar's commentslogin

Personal wish list:

- Right-side USB-C

- Slightly brighter display

- Slightly wider hinge angle

- Option for nano-texture display, just like the MBP

- WiFi 7


Apparently the M4 Air has a slightly wider hinge angle than the M3 Air


Huh. Definitely wider than the M2.


TIL! Any link to this?


Dedicated HDMI port


Can anyone with security expertise clarify what Wiz actually does? Is it a legitimate company or is it fuzzy consultingware?


It’s a security-as-a-service platform that monitors whatever clouds or systems you plug into it for security vulnerabilities, but is built specifically for public cloud service providers and their workloads. I quite liked the product, as it would notify my team of erroneous configurations, outdated AMIs, exposed ports, vulnerable workloads, and whatever custom policies we setup (e.g., SSH open between VPCs in AWS, rather than via a Jumpbox).

I loved the product when I used it (huge improvement over Nessus), and am immensely disappointed Google owns it as it means I’ll have to find something else going forward. This is the sort of acquisition a regulator should block, because Wiz really is best-in-class at what they do for every cloud they support, and customers benefit more from it being agnostic.


Wiz uses various API's via read access in your accounts/orgs/subscriptions to assess risk of configuration.

They also snapshot your disks, cloning them to Wiz accounts to provide secrets scanning / vuln scanning / etc against your infra.

These resulting risks / findings are scored and provided in their SAAS Wiz console via dashboards / APIs / integrations with remediation guidance.


> They also snapshot your disks, cloning them to Wiz accounts

I can see how that could be worth $32B.


It is a very legitimate tool. It identifies misconfigurations and vulnerabilities in cloud deployments. Anything from a container with a known-vulnerable package in the manifest to a workload with improper firewall rules.


Isn't this what tool like MEND or Black Duck (formerly Synopses)?


I understand those (I haven’t used them) to primarily be about software composition analysis. Wiz does that, but they are mainly known for Cloud Security Posture Management (the “you have an exposed S3 bucket”, “you have a workload with no inbound firewall”, “etc.”) and integrating things like SCA to increase alert fidelity (do you care as much that a workload has an inbound ACL allowing MongoDB connections from the Internet if the workload isn’t running MongoDB?)


Wiz is closer to the CNAPP field instead of the software composition analysis tools you mention, Snyk would fit here for SCA.

Sysdig, Palo Alto's Prisma Cloud, or a few others compete with Wiz's CNAPP offering. Wiz also strays into some SCA and SCA-alike tooling for containers, code or XDR with their CDR/XDR products log ingest and agents available for response/quarantine.


Basically give it read access to your cloud account, and it will scan all of the resources to identify potential miss-configurations. Identifying CVE in software is one thing, but it's identifying incorrectly configured resources that would otherwise be secure can dramatically reduce the risk surface.

A lot of cloud providers already have little hints like "hey - did you mean to create this account in God mode?" or "It is recommended not to create this god mode json key file" - Wiz is taking this to the next level of detail


Would also be interested in this. I don't know anyone who uses Wiz. Google says they had 350 million in revenue last year, aiming for 1 billion this year. So 100x revenue TTM. Crazy stuff.


That's because A) big companies that use it don't really like bragging about their security tooling, lest it be used to better profile their infrastructure by attackers, and B) it's basically enterprise-only and insanely expensive.

Source: worked for a large enterprise company that used it, and I loved it. Phenomenal tool, will be a shame to see it die (or at least its non-GCP aspects wither and die) under Alphabet's ownership.


FYI we don't really value companies on a TTM basis so 32.0x Revenue would be the right multiple to quote


They were the one's to first report on DeepSeek's recent data leak, and they've found a few others.

One exploit I remember Wiz finding was "ChaosDB". A flaw in Microsoft's Cosmos DB allowed anyone to use the default-enabled Jupyter Notebook to basically dump and modify anyone's databases, without authentication. Full admin access.


My last company used it to complement other cloud security scanning products. It’s probably a bit of an understatement to call it a scanning tool. It was easy to integrate with our other systems so we could assign vulns to different teams.


Can you recommend a good rule of thumb for autovacuum settings given a large workload like yours?


Here's mine:

- autovacuum_max_workers to my number of tables (Only do so if you have enough IO capacity and CPU...).

- autovacuum_naptime 10s

- autovacuum_vacuum_cost_delay 1ms

- autovacuum_vacuum_cost_limit 2000

You probably should read https://www.postgresql.org/docs/current/routine-vacuuming.ht... it's pretty well written and easy to parse!


Do you ever need to VACUUM FULL?


It’s too slow at that scale, pg_squeeze works wonders though.

I only “need” that because one of my table requires batch deletion, and I want to reclaim the space. I need to refactor that part. Otherwise nothing like that would be required.


Yes, I was asking because you have mention deletes. Thanks for the answer, cool stuff!


Do you know of a good resource which describes these simple best practices?



Thanks!


uBlock Origin Lite is still available, thankfully.



But for how long? I'm sure Google is hard at work on Manifest V4.


What is lost by going to this version?



If it’s anything like Safari’s declarative blocklists:

Ad blocking on Youtube.

Youtube-blocking Safari extensions “solve” Youtube blocking by using non-declarative APIs that need full access to Youtube. Apple seems ok with that so far, but the APIs are not as goods, so their success rate is limited.

Whether Google will allow new extensions that block Youtube remains to be seen.


> Ad blocking on Youtube.

uBlock Origin Lite blocks all ads on YouTube for me.


Google push out updates at regular intervals that detect the adblocker

why didn't you notice before? ublock origin has a special quick fixes list which updates very frequently, without Google's involvement

but with manifest v3: Google are now in charge and have to approve all "definition" updates

which they will only do once they've got a new detection method ready

and this is the entire point of manifest v3


>but with manifest v3: Google are now in charge and have to approve all "definition" updates

No, they don't. MV3 extensions are allowed to fetch remote data which definition updates would be.


Just saying, I've been using Lite for months. It's been fine.


they'd have to be really, really stupid to start doing it before their main countermeasure has been removed


> uBlock Origin Lite blocks all ads on YouTube for me.

Someone else is saying uBlock Origin Lite leaves a "skippable blank" where the ad used to be, while I know for a fact uBlock Origin completely and transparently skipped over the ad.

Could you confirm?


It completely blocks it.

But you have to change the toggle from basic filtering mode to complete filtering mode.

I think some people just haven't realized that.


Could you please tell me what "Youtube-blocking Safari extensions" are you referring? Are they MacOS only or can be installed on IPad? Thanks!


I can recommend Wipr 2 - excellent blocker from a great developer. I've now switched to Safari for all my YouTube watching. Universal purchase works on macOS, ipadOS and iOS.


I just downloaded it.

It works way better for Youtube than the one I had, and after some more testing I don't need the additional annoyance blockers I had. I might just go back to Safari!

Thanks for the recommendation.


Sure! AdBlock Pro blocks video ads for me, but it shows non-video ads that you gotta skip.

On iPad I just use Brave and haven't seen an ad yet.


custom filters / block lists


Realistically, how often is this functionality used en' mass? I remember using it once or twice throughout my lifetime of using this extension.


An ad blocker is useless to me if I can’t block whatever I want with it.


It's useless if it blocks 99.9% of what you need, but not the custom 0.1% you want on top?


As long as I have an alternative I would never choose the ad blocker that doesn’t let me block the elements I want.

For most websites I don’t care but there are many websites that I visit very often and removing annoying or useless elements and padding is practically mandatory at this point - I wouldn’t want to go back to not being able to do it.

So, answering your question, yes, “useless” was hyperbole.


I use different extensions for blocking individual elements on pages, like sticky headers or other custom divs. They're still working fine, e.g.:

https://chromewebstore.google.com/detail/click-to-remove-ele...


also you'd think that the pushers of this agenda would get real-time updates to things like block lists metadata. God knows they do it themselves several times a day...


dignity


How does Timescale compare to other extensions like Citus and Hydra/DuckDB?


I'm not an expert on either of those, but this is my take anyway: Citus is distributed and afaik just eventually consistent, for a lot of folks that's simply not an option as their application relies on ACID compliance.

As far as I understand Hyda + DuckDB it is a higher level add-on onto postgres than timescale is. This is on the one hand nice since you can just put it into an existing database without any migration effort whatsoever. But this also means they likely don't really interact with systems like the storage engine. For example Timescales deeper integration allows us to actually store the data differently on disk which allows for saving space via compression.


for one thing, depending on your licensing contraints:

- Citus is AGPLv3 https://github.com/citusdata/citus/blob/v13.0.1/LICENSE

- Hydra is Apache 2 https://github.com/hydradatabase/columnar/blob/v1.1.2/LICENS...

- Timescale is mostly Apache 2 https://github.com/timescale/timescaledb/blob/2.18.2/LICENSE


It has wireless charging, just not MagSafe.


Yeah but the MagSafe charger I've spent $150 on doesn't work without the magnetic part.


It works fine, you just have to manually align it, like any other Qi charger.

I half suspect you're trolling based on this and your other comments under this post, but in case you're not, the Magsafe charger specs state they are Qi compatible.

https://www.apple.com/shop/product/MX6X3LL/A/magsafe-charger...

  > The MagSafe Charger is compatible with Qi2 and Qi charging, so it can be used to 
  > wirelessly charge your iPhone 8 or later, as well as AirPods models with a wireless
  > charging case, as you would with any Qi2 or Qi-certified charger. 
PS: What MagSafe charger cost you $150? The regular Apple charger costs $39.


Not OP but I have the Anker 3-in-1 Cube and it was $150 when I bought it a year or two ago. It charges a phone, watch, and airpods at the same time, and sparks joy for me.

https://www.anker.com/products/y1811


I got a Belkin one 5 years ago for about the same price. Charges my phone and watch! Awesome. Then the next year I got a 13 Pro Max, and the charging coils didn't line up. Phone won't charge. I swore to never buy $150 chargers ever again.

I paid $25 for something from China. It took a month to arrive, but it works great.


I assume it's some elaborate mounting thing if you spent that much on it, but actually a magsafe charger will act as a standard Qi charger as well.


Yep. Switched from iPhone to Android but still use my magsafe charger on my bed stand for the new phone.


I wonder if one of those MagSafe cases that basically "passthrough" the MagSafe magnets in the phone would work.


Just as well as any of the other ones for Android phones. Heck, you can even buy adhesive magnet rings to stick directly to any case or phone back, as long as you align them properly.


Absolutely. Plenty of even cheap cases have the magsafe ring to align the charger and then would work with the magsafe puck just fine.


Is MagSafe worth it? I think I've misaligned my iPhone 12 mini once on my Qi charger total over the past five years or so.


Well I have an ancient wireless charger (power unknown) that doubles as a stand that I got for free as swag from some conference. I just keep my magsafe supporting phone on it when I'm not using it and done.

Look ma, no magnets!


does the target market for a cheap iphone spend $150 on a charger?


Literally just replaced the flimsy clip-on vent mount charger in my car with a ProClip custom fit mount and a Qi2 charger that ran me ~$115 all-in. I wanted longevity with this solution.

(See also: https://www.proclipusa.com/pages/product-finder)

I was pretty close to picking up the new SE4 to replace my iPhone 14 Pro and I'm balking at the lack of MagSafe on top of the $599 pricetag.


Then sell it and buy a $10 Qi charger.


Fidelity's "Zero" funds are great, but only for specific scenarios IMO. They can't be held outside Fidelity accounts, so what happens if you get caught up in some KYC nonsense and Fidelity closes your account? Are you forced to liquidate and incur capital gains? There are also some embedded tax efficiencies inherent to ETFs, like 351 exchanges, which aren't popular now, but may become popular in the future. TBH, this mainly applies to taxable accounts. For nontaxable accounts, Zero funds don't have much downside.


> They can't be held outside Fidelity accounts, so what happens if you get caught up in some KYC nonsense and Fidelity closes your account?

This literally happened to me. I'm banned from Fidelity for some unknown (AML presumably) reason but have no other issues with any brokerage, bank, or exchange.

Fortunately I just held a bunch of ETFs, so it was straightforward. But it does happen.


The zero fund I am familiar with (FZILX) has a once-a-year dividend schedule which I'm sure nets them a lot of money, vs paying out more frequently. If you want to unload, you can only do it once a year without throwing away your earned dividend.


That's not how dividends work.


You have to hold the fund on the ex-dividend date...

Pays out once in Dec. If you buy in Feb and sell in Oct, you're not getting your dividend although you earned most of it... If you had VTI, you'd get 3 of them.


Dividends are built into the NAV price. It just becomes taxable income when it is paid out.


Ah right


I'd also thought your idea sounded like it made sense, sort of like how a trader can attempt dividend stripping, but looks like the user baking cleared that up.


They raise a good point, which I've never considered before. This could be considered a form of dividend arbitrage based on the difference in scheduling between the component dividends vs the fund dividends, based on the knowledge that a non-zero amount of fund holders will exit the fund before the once a year dividend date, but not before the fund earned dividends based on the fund components.


Nevermind, it looks like baking cleared up my misconception in another reply.


I do, yes. But while traveling, I've found it very useful to have rich media links, apps that don't break, etc.


You just have to shovel a lot of shit and eventually something will stick.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: