The author is right that USB-C docks can be used to hide malicious devices - but the same is true of any USB device. You could hide a Pi Zero in a mouse, keyboard, memory stick, or anything else that you can open up and access the USB headers. Scary - but also requires a higher level of physical access than other vectors such as phishing.
This is just the tip of the iceberg. Turns out our operating systems are actually just sandboxed applications in the hardware manufacturer's proprietary hellscape. Not only are they not real operating systems anymore, they are no longer even in real control of pretty much anything.
ARM doesn't have a concept of anything like the management engine, but remember it's just an ISA and actual SoC implementations like from Qualcomm, Samsung, Apple, Amazon, etc. are free to add their own logic and side controllers.
That's different. It's a feature where Apple deliberately keeps some components running after shutdown, in a very low-power way, and provides an option to turn that off. Those components (the Bluetooth chip, for example) are all strictly separated from each other by IOMMUs.
Intel Management Engine is very different. It's basically another CPU within your real CPU, running its own software with no visibility to the main OS, and it has (AFAIK) full access to other components. If it's compromised, or has a factory backdoor, you're 0wned.
The closest thing to Intel IME that the iPhone has, is the baseband, which can run its own code. But if I'm reading marcan correctly (https://news.ycombinator.com/item?id=30393283), modern iPhones/Android phones all use IOMMUs to isolate that (with the exception of a few so-called "free/libre" phones). The IOMMUs can be easily inspected from the OS to make sure they're correct, so it's just not a concern, unlike IME.
The baseband doesn't have control over the application (main) processor the way IME does, however, and Apple is rightfully distrustful of Qualcomm's security and the two are fairly stringently separated. What a baseband (or WiFi controller) rootkit can do, however, is intercept all your network traffic, and inject exploits for software bugs in the main OS.
I would expect apples quality control processes to pick this up. They’re so closely involved in the chip design process that it’s hard to imagine Apple’s engineers are debugging wouldn’t notice something was amass.
Not to mention the technical challenge of quickly understanding and editing Apple’s designs from the limited information that is shared with the foundry.
The device could be dormant until it gets a signal, meaning Apple won't find it unless they cut up the die. And they could attach it to anything that looks like a bus, then figure out how to exploit it later.
I love how people forget what this is for. that's "love" in sarcasm quotes, if it isn't clear.
this is for me when I want to enable virtualization on a user's laptop remotely, without sending a human to their desk or to their house to enter the bios password and to enable virtualization or do whatever else I need done in there.
this is how I ship a laptop from the manufacturer directly to an end user, at their home, and they unbox it, turn it on, log in, and the computer becomes a corporate-managed device. I don't have to fly someone out so they can set up the computer, or ship the computer to the office for configuration before it gets shipped again to the end user.
this is not a nefarious thing, nor is it a target for hackers, because there are far easier ways to trick someone into doing something which lets the hacker onto their system.
well if you aren't in an enterprise it is unused and inactive
if you don't want to spend $0.10 on the feature in the chip, spend 100 billion times more than that to start a CPU fabrication company and license x86_64 so you can make your own CPU.
we can't have everything a la carte. it doesn't make sense.
Framing it as a $0.10 cost issue is disingenuous. It's not that I want to save $0.10, it's that I want hardware that specifically does not have that functionality. And I'm willing to spend more to get it; though not $10billion more.
And it's not that they'd have to re-tool their fabs to make it either; they're already set up to make non-ME systems for certain government buyers. Please let civilians buy those systems.
I think hackers will decide on this, not you. And at least acknowledge that IME/PSP seriously expands the attack surface of the hardware at a very low level, enabling new classes of exploits against which the OS has no defense.
So this is made for noble purposes so it must be no risk?
So is the internet. And a few other things. I do not feel your arguments particularly strong.
E.g. wouldn't this purpose a target for specially prepared external managmenet dongles (similar like those hinted in the article but of course made professionally and with the noblest of noble system admin motives) that could be plugged in where and when corporate management is necessary to set up, then remove, send to the next computer if necessary? And not built into EVERY computer, from granny to the schoolboy so YOU could do something? This concept soulds like the key under the doormat kind of security. And you rely corporate systems on this.
yep all the hacks which have broken it sure have me proven wrong. gosh.
the thing isn't even capable of the devastating things you all fear. it's a minimal CPU (a slow 486 on Intel chips) with a miniscule web server which is off unless configured to be on and it can't read your disk or read RAM. all it can do is talk to hardware. it's how you configure the bios without rebooting at the console.
yeah I was saying that these are not always enabled on consumer devices and are protected by firewalls in most consumer and corporate situations by default.
you are smart enough to have firewalls in place, right? or are you so knowledgeable about security that you turn those off?
I see you linking to attempts and maybe some real vulns but even if they were exploited in the wild without local USB access, which I don't see in those links, firewalls would have prevented them.
physical access appears to be a requirement for those now-patched vulnerabilities, so while I was mistaken about a bit of this, my overall point stands. wow I guess you sure proved your side!
if you don't like this kind of thing in your CPUs, please feel free to start a CPU company and make your own stuff.
Good for you I guess but I sure as hell don't want no "corporate management" malware anywhere near my stuff let alone inside the chips where they can't be disabled. Please keep this crap fully isolated in your "corporate devices" so that we don't have to deal with it.
It's true that we haven't got a remote exploit yet, or at least, it's not publicly known. And I agree that it can be useful, convenient even, for everyone involved. It does however give up a good amount of control, the end user's control over their own machine.
>this is not a nefarious thing
Hell is paved with good intentions. The intent is irrelevant. Every substance that we banned so far in agriculture were developed, and used with the intent of improving the crops. Yet, they turned out to be a net negative. We don't know the end game of the ME/PSP yet, but I'm not keen to participate, I'd gladly buy a CPU without it, and let other people find out.
Or they could pre-make a bunch of docks and swap them out at a cowering space or target office building. Easy enough to gain physical access to most offices. You could get a job with the cleaning crew
Even a simple charging cable can contain e.g. a HID chip while still working as a charging cable. I saw an unattended cable on a table at work once, I'm sure someone who needs one would've used it without second thought. But our employer is also sending fake phishing emails to make people aware, I wouldn't be surprised if they also plant devices like that.
...and if they don't I should propose it, sounds like a fun project. Leave a random cable or USB stick that just shows a warning that it could have been malicious. Or something that just opens up https://nyan.cat and sets the volume to max :D.
I've been using Starlink as my primary internet provider for the past year. I'm just outside of Eugene, OR and prior to Starlink my only internet options were Viasat or dial-up.
I definitely notice the variability of Starlink. My download speed ranges from ~40mbps to ~200mbps, and my upload speed ranges from ~5mbps to ~50mbps. This doesn't really seem to be connected to time of day or what I would expect to be typical use patterns. My internet is never unusable for Zoom, streaming video, or other average use cases.
A lot of people complain about decreased speeds, my personal experience hasn't really shown this to be true. What I have noticed:
* Over the past year, I've seen a huge improvement in latency and packet loss. I used to have latency in excess of 130ms, and I would typically see a few dropouts lasting ~30 seconds per hour. My latency now is rarely more than 60ms, and I never have dropouts.
* Being behind an IPv4 CGNAT is annoying. I get a lot more captchas and fraud prevention techniques being applied in my browsing.
* Geolocation is way off. I wish SpaceX did a little bit more effort to dedicate IP geodata to specific cells in their network - everything defaults to their Seattle POP for me.
* The adoption of Starlink out here is astonishing. Virtually every house near me has gotten it in the past 2-3 months. It's a huge game-changer for people. It's pretty amazing what the Starlink team has built out in a relatively short amount of time.
Willamette Valley here — it's been nothing less than a game changer.
I checked the speed tests for the first week but until the brief outage yesterday I haven't thought about it. The internet just works, and we're able to stream, download, work, videoconference.
Viasat is like the Stone Age in comparison. Low data caps, very long latency, nearly twice as much money.
People don't realize that even in areas not that far from population centers connectivity can be virtually nonexistent.
Datapoint of one here, but I recently visited a friend in Willamette Valley, and their area had fiber. Is that not an option for most people in your hood?
I'm on a farm, so while there's fiber in many of the towns, if you go ten minutes drive outside of them it's not really an option. Maybe they'll get there eventually.
It's amazing how many companies assume geolocation is perfect, for consequential decisions. I wasn't allowed to book a COVID vaccine by Walgreens because they said I was booking from a different state (I wasn't).
>This allows local devices to use the Starlink lat/long that dishy uses for satellite targeting.
How does this solve the geolocation issue? The parent poster mentioned IP based geolocation, which isn't affected by the starlink terminal providing some sort of local debug api to get the current lon/lat.
> This doesn't really seem to be connected to time of day or what I would expect to be typical use patterns.
I'd expect somewhat typical time of day use patterns on Starlink as a whole [1], but you're probably seeing variable congestion/capacity because the satellites are in motion and you'll have varience in which satellites are in view and how many other users are using the same satellite as you, as well as how many users are connected through the same ground station as you. I'd bet there are some really interesting network graphs.
[1] although I wouldn't be willing to guess if it looks like office, residential
> This doesn't really seem to be connected to time of day or what I would expect to be typical use patterns.
This has been my experience too which I've assumed they are capping speeds. Often I work late so am up in the am's so would have little competition for bandwidth and if I do a speed test it's lower (~60Mb down) than when I first got it and would regularly be 100Mb+ sometimes over 200.
Also recently we've been getting more network dropouts.
All that said, it's been a game changer for me as I was living with 3.5Mb down before starlink and a significant overall improvement.
Is it worth it in your opinion? I had it preordered for almost a year but cancelled it when they raised their prices and never took delivery. I've read the 2nd generation dish is faster with a bit more stability, but I'm not entire sure.
Not OP, but my parents use it in northern california because they live in a spot that the standard ISPs have decided isn't worth running connectivity to - gigabit cable is available if they lived 3 miles closer to town. No utilities other than electricity.
They had HughesNet before, barely ever got more than 1 Mbps. Latency was ~1000ms on average. They paid for the 100 Mbps service for awhile but HughesNet oversubscribes their satellites to a disgusting degree and they rarely saw more than that 1 Mbps.
Even when the bandwidth was ~10 Mb, the latency levels caused basically all of the streaming services to not function.
When they first got it, it was ~100 Mbps on average. Now it's around 50 Mbps. Latency is still holding around 40ms. Still at least an order of magnitude better on all fronts compared to their competition. I was able to play some competitive shooters with decent success ... although CoD had a tendency to occasionally boot me when satellite switches happened. Seems to trip the anticheat, but I can't really blame Starlink for that.
I have two connections - one "standard rural WISP" sort of thing, 25/3 on paper, what it delivers varies wildly. And then Starlink. My network is set up so I can easily switch systems between the two.
Starlink is far worse about "Random sites decide that I'm evil." Even things like Lowes have, at times, utterly refused to work, throwing nonsensical server error messages of the "Go away and quit scraping our content!" variety that go away when I use the same system, on the same page, just literally routed out the other ISP.
The benefits of CGNAT are that you're hiding in a lot of other traffic, but the downsides are exactly the same. And Starlink is far worse than cell data in terms of it.
Seems to be a fair amount of recent interest in 10gbE home networking. I bought a Brocade ICX6450 based on this thread with 24 Poe+ ports and 4 SFP+ ports for about $100 on eBay with free shipping - it works amazingly well and powers my entire home network.
Bit of a learning curve, but I found the CLI interface to be similar enough to Junos, which I learned while managing EX switches.
I bought an ICX6450 too; the learning curve is indeed pretty steep and getting the 10Gb ports enabled.. well I got the licenses sorted but the ports still don't work and remain dark no matter what I try.
I'm thinking of switching to something less advanced, there just isn't a ton of great information I could find to get things sorted with the ICX.
I'm competent enough to setup pfSense, but this Brocade switch has become a pain in the neck! Recently after a power outage, the switch doesn't even work right anymore and I'm not sure where to begin troubleshooting it.
Curious what others are using for 10Gb at home? I'm all ears and will be grateful if you have recommendations.
One thing that has caught me out with the 10Gb ports that need licensed:
If you enable them with license and don’t provision them, they won’t run at 10Gb. Further, you have to commit the changes or else they won’t stick on power cycle.
Sounds stupid but this had me going in circles for a while: apply license, provision the ports, commit the changes, check connection, cycle power and check again.
> Curious what others are using for 10Gb at home? I'm all ears and will be grateful if you have recommendations.
Lots of options. What’s your budget, both for purchase and power draw? How many ports do you need? 10GBASE-T or is SFP+ okay? How much noise can you tolerate (i.e. is this in a basement closet or right next to your desk)?
I didn't expect to learn much from this article - but it actually really resonated with me. I often am responsible for purchasing decisions and found much of the advice to sales reps really insightful.
(1) The number one thing that bothers me is when I reach out to a company to explore their product and I get scheduled with a BDR who's sole job is to "qualify" me as a lead. I know BDRs are in a tough spot - but if you have someone reaching out and interested in your product, take advantage of that and get them straight to the person who can demo and answer questions. I'm shocked at how many companies make me want to prove myself as a customer before spending time on demoing.
(2) Ask before recording meetings, and if someone doesn't want to be recorded make sure you actually have the ability to turn that recording off. I've been on calls where the person who set up the Zoom/Gong wasn't on the call, and so no one had the ability to stop recording.
(3) The details of what is shared on calls is often completely lost. Every time a new person gets on the call, they ask the exact same questions that have already been answered. Make the customer feel as though you're interested in their business, have discussed their pain points, and have a plan ready to help them.
(4) Discounting discussions are always a pain. It's a game that no one likes to play.
(5) Offer to send some swag to the implementing team at your customer - not just your champion. It's a nice gesture and goes a surprisingly long way towards building positive sentiment.
A while back I wanted to become a customer of a company I had formerly worked at. I reached out via an executive-level friend and former co-worker who made a warm intro to sales. And STILL they first scheduled a call with a brand new to the job BDR who knew less about the product than I did. Not that person's fault, and I felt bad for them, but it was a complete waste of everyone's time.
Sadly that's how incentives works in modern sales orgs – BDRs get paid on the number of calls they convert to the next stage and you were a guaranteed conversion since you already knew and wanted to buy the product.
So that’s a problem with how the incentives are set up I’d say. Not the BDR’s or their manager’s fault, rather a high level incentive problem which should be fixed.
What’s HN’s opinion on sales commissions anyway? I always thought that research showed that any job that requires creative thinking doesn’t make people work harder if they are compensated based on bonuses / commissions.
Have any large organizations ever experimented with getting rid of the whole commission based compensation for sales? If so, how did it work out?
I think at least from sales orgs, bonuses are very easy to justify. Sales orgs are very data-driven – typically their CRMs measure everything from the time it took to close a deal to how much each rep brought in a quarter. If just paying a regular salary worked to motivate reps enough, you'd find lots of companies doing that, but they're pretty rare.
As someone that's done sales, it is very important to qualify even incoming leads. I can't count how many times I wasted my time because the person who thought they wanted the product actually wasn't a good fit. After I implemented a lead qualification pipeline, that number dropped dramatically and the leads that did qualify were, predictably, much more likely to buy.
Yeah but qualify them by showing them the fucking software.
It's gotten so bad out there that I've gotten to the point where I just refuse to do qualifying calls. When I can smell one brewing I just email and say I'd like my first call to be one where I can see someone using the software via screen share, or be given the opportunity to log in or have a test account myself. I don't care if I'm talking to a high school intern feel free to screen your big swinging dick's sales guy's schedule but then get your intern show me the fucking thing, the features, the screens, what it does, the basics of how it works.
If I start a call and it's happening I just ask if they're able to show me the software. If they say no, we'll schedule a future call for that I say great press the button in that CRM that qualifies me for that call and I'll log off now.
If they don't want my business good for them, they can run things how they like, but my time is valuable too and I'm the customer so if you can't show me the product fuck off.
After doing dev work for nearly two decades, I've been in presales for the last six years. I've definitely had a one or two intro calls with tech-savvy people who bullied their way past the BDR. These were smart people with good ideas, who had no idea what procurement at the enterprise company they just started working for even begins to look like, and it was 60-90 minutes none of us will ever get back, for a project that's never going to happen anyway.
I worked at a company where we jumped at every opportunity that we got, it's real nice to be somewhere now where there's a little more of a vetting process.
As some one running growth for a low code/no code platform for internal tools - we would want a qualification call to help the demo team with info that can then allow
demo team to prep a demo which can make the call really relevant. Given how crowded our space is most of the times customer would have seen atleast 2-3 tools before and learning what they liked or didn’t like is very important.
If you insist on scheduling two calls with me where it’s a guarantee one of the two is completely fucking useless and irrelevant for me then you’ve maxed out your potential mean highest average relevance of a sales call to 50%. That’s your best case.
Maybe just work on a couple common use cases and get your team able to pivot and share the more relevant examples on a demo in the first call and aim a little higher.
Your software’s various applications are probably not each the special precious unique snowflakes you think they are. Just a guess.
Often BDR calls don’t even focus on if the product is a good fit - it’s “how much budget do you have?” “Are you the decision maker?” “When are you looking to make a purchase?”. That’s, frankly, a waste of time for me. It’s one thing to have an initial call to show off core functionality and see if there’s a good fit - but if the focus is just trying to determine how much money I have, then it’s going to leave me fairly annoyed that I spent time on the call.
These calls exist because companies have learnt from wasting their time talking to people who can't afford it, aren't the decision maker and aren't interested in purchasing any time soon.
The conversion rate of the sales profession is really low, and it can easily get an order of magnitude worse without qualification.
Which is ironic because often times companies refuse to give budget numbers unless I sit through a damn demo first....
At this point I strongly disfavor companies that do not publish their retail prices. everyone from Microsoft to SpaceX can do it, there is ZERO excuse for companies not doing it today
I'm a bit like you, I prefer published list prices. It really helps me if I know my budget is somewhere near your list price.
But I'm also in a business where we don't. And the reason we don't is because hardware is involved, and so prices can vary by 2 to 3 orders of magnitude.
In other words it takes time to gather up your requirements, which include hardware, software and crucially install and support services. From this we can generate a quote.
I'm not involved in the sales side, but I expect there's at least some demo as part of this process because it's helpful when reading the quote if the user has some idea of what they are buying. I don't think it's a terribly long demo though.
That all said, it is helpful to both parties if budget is mentioned early. With software-only projects I will often give the caller some idea of budget very early just to make sure we're playing in the same ballpark. That saves a lot of time.
> But I'm also in a business where we don't. And the reason we don't is because hardware is involved, and so prices can vary by 2 to 3 orders of magnitude.
> In other words it takes time to gather up your requirements, which include hardware, software and crucially install and support services. From this we can generate a quote.
IOW, if the customer were afforded just a little bit of price discovery the business would tank.
Lots of companies have interactive websites where I can input all my requirements and it outputs exactly how much I'm going to pay, with no human in the loop involved.
That is still not a reason to hide price. At a minimum publish the range, but in the modern age these is very little reason a matrix or wizard could not be created to get that price.
A F150 is almost infinitely configurable, yet I can walk through the website and configure my dream truck I will never actually buy because it is the price of a home and I don't want to live in it....
Further still most of the time when I see companies hiding behind 'install and support' my Spidey sense star tingling
'install and support' starts to feel like buying a car where at the last step they start tacking on all these extra fees and 'services' and try to bleed you dry.
3 different times I've used a product, either via freeware or sales lead and when I went to go buy the spent so long getting back to us on a price we had written around it on the engineering team. One small team had not sold a copy before and so they took 3 weeks to settle on a price (but they had a sales staff), in which time I had learned enough 3d math to just re-write the system.
A lower ranked salersperson does the qualifying. The more trained ones do the selling. They are optimizing their resources and for a big purchase, the buyer is expecting a more involved process than one-click checkout.
Yeah I get it it’s just annoying. Train some entry level people to show some basic software features instead of training them to waste people’s time asking questions.
That's a quick way to lose sales. It's like asking a backend dev to make a pretty frontend website to impress a visually oriented client. Roles are stratified for a reason.
Wanted to reply to this as somebody's who bounced between pre-sales and engineering roles in the past.
For #1, what is most likely happening is that they are trying to maximize the use of the pre-sales engineer's time. I can't tell you how many demos I gave as a sales engineer, but I can tell you that the opportunities that progressed past that demo are much less than 50%. After a while, sales engineers can even grow resentful of their BDR or AE for what they view as wasting their time. You could probably maximize your chances of getting a pre-sales engineer on the call to demo it by clearly stating your pain up front and emphasizing you have a rapidly approaching deadline to narrow your options down to a final 2 or 3.
I completely agree with you on the rest of your points. It can be hard to find sales reps that do the fundamentals well.
> opportunities that progressed past that demo are much less than 50%
Any sense of what industry norms are? 50% sounds astonishingly high to me. For most products I would have expected a pre-sales demo to be a pretty early step. 50% basically means everyone you talk to is committed to buy something and is only looking at 2 vendors.
It varies drastically by the business but I would say that it’s more on the magnitude of 10% or less (for enterprise sales, IME).
If you’re getting a 50% conversion on your demos then either your sales org has _really_ dialed in the target persona (qualifying everyone else out early) or your market is very wide.
I would suggest that there's a subtle difference between "progressed past the demo" and "converted". 50% progression past the demo is reasonable. 50% conversion would be amazing.
Yes, this is what I meant. I would say that for over half the demos I gave, that was my last time talking to that prospect. For the rest, some of them would go a few more meetings and fizzle out, and some would convert to actual sales.
I hate companies that do this bullshit, as it’s fundamentally disrespectful of customers.
We regularly have to deal with this crap to prospect vendors for tech solutions. Some companies do multiple rounds of qualifications with people punching their KPI cards wasting my time. If you’re recording the calls, listen to the recording and stop wasting my time.
If we don’t need the vendor, we ghost you. If we really need the vendor, we have a process to flag it so that someone gets ahold of a C- or founder level contact in the company. That’s gotten at least 3 sales directors fired, and with the high level sponsor, we usually grind out a significant concession to close the deal.
No offence but you clearly have never worked for “the vendor side”!
Do you know how many thousands of time wasters you get a month? People comparing you to the competition, trying to get a master class from you so they can pose as a consultant for your technology, learning from you so they can apply for a job… the list goes on and on.
Give them all swag…?! Hahahaha there would be people lining up to waste your time and get free swag.
Thank god for the BDRs making sure you’re not some underling with no budget, authority, need or time pressure. Yep that’s BANT for you!
Discounting discussions should be simple: you buy more? You pay less. You commit for longer? You pay less. Simple.
It’s painful when the prospect start calling you expensive, saying the competition is cheaper, that there could be a “partnership” because they are the hottest newest crypto-quantum-ai to revolutionise web3.
This is very common in the US, almost to the point of being standard. It is incredibly annoying and it gets in the way of doing business. This is particularly true in the hardware front.
Interested in a connector?
No problem.
What's you estimated annual utilization rate? How many product lines is this going into? What's your current usage? What will be your MOQ? How often do you expect to reorder? Etc.
The difference with Chinese suppliers could not be greater. I can't remember the last time a Chinese supplier interrogated me this way on first contact. They are often eager to do business with anyone and have no problem selling sending you samples or selling you a small quantity for testing.
Not sure what that's about. I truly detest dealing with companies that size you up like that.
> Offer to send some swag to the implementing team at your customer - not just your champion.
This seems weird to me. I guess if it works to send some trinkets to people you do it… but if it makes a difference to them I’d be kinda judgmental about that fact ( not really related to the sales process).
Personally I don’t want more trinket crap in my life but maybe other folks feel differently.
The devs integrating with your solution are going to hate it at a certain point. This may or may not be your fault (underlying technical limitations you've papered over will look like your fault from the outside at a certain point).
Devs hate basically everyone else's code.
A t-shirt (or jacket, or water bottle, or whatever) is a surprisingly cost-effective way to turn "I hate this" into "Sure it has some quirks, but have you seen the other options?"
The gentle way of expressing this is well known: if you are not embarrassed by code you wrote a year ago, you have not improved at all.
As far as I am aware, coders and artists are the only two groups of people who routinely describe their own creations as "shit", "crap", "garbage" or "disgusting". How could one even begin to appreciate someone else's work when the primary feeling we have of our own is self-loathing?
(If you haven't looked at a piece of code, gone "what kind of idiot...?" and discovered via git-blame that it was you, you have not been in this profession long enough.)
Yea, maybe not a shirt, but hell, send them some nice coffee or some snacks or something. My current job is probably at least 50% implementing stuff my company bought, and for one of them, they had an on-site meeting about the implementation/proof of value stuff and they offered to buy everyone coffee/tea/whatever at a coffee shop by our office before the meeting and that definitely helped me be a bit less grumpy about the work.
Any sort of "congrats on launching/implementing our stuff" gift is at least an acknowledgment of the work put in to help the sales team land their contract, and that helps keep the relationship on a good footing.
A few companies I have worked for have had a strict no gifts policy. Many of our customers had similar policies, to the point that we couldn't even pay for a customer's coffees if we have a meeting at a cafe.
These policies are aimed at preventing even the whiff of bribes or favoritism wrt purchasing or awarding of contracts.
Mostly this was in the Oil and Gas industry. We had a few mining clients that were less strict wrt gifts/swag. I now work in the banking industry where there are strict regulations against bribery, facilitation payments and many types of gifts.
So I find it a bit weird to hear that sellers provide "swag".
This is more of a post-sales item. A pivotal part of a renewal is going to be how successful implementation is - and that success is largely dependent not just on the sponsor of the project but on the team that supports them. Those folks are often the ones who don’t get the trinkets. Something like a nice jacket or even a pair of socks can go a long way to building positive sentiment there.
Swag is the scourge of the earth. It’s almost always cheap junk made overseas and goes directly into landfill. It’s the kind of stuff I would never spend my own money on, so by definition I don’t need it. I literally walk away whenever I see it, avoid at all costs.
(1) The sales and SE time is very expensive in both direct and opportunity cost. If you were on the sell side you would appreciate this. Leads, even incoming, absolutely need to be qualified.
I'm with you on the rest, maybe not all the way on (3) though.
That sounds nice, but it simply is not possible for very technical products (many kinds of databases, low-level infra, dev tools, etc). You won’t be able to find BDRs that can talk to devs the way another dev would.
Shameless self promototion at comtura.ai we are working on 3.
With Comtura we plug into call transcriptions and recommend conversational suggestions to push the customer's voice into Salesforce.
We have come across so many companies spending hundreds of thousands on Salesforce data entry with very poor quality data captured. This also results in sales management potentially spending 8h a week just watching Gong recordings to understand their pipeline.
I am Chris, one of the cofounders of Comtura if you are interested to learn more about we do email me at chriss[at]comtura.ai
For about $50 US, you can get a 10Gbase-T SFP+ module that gives you a copper port at 10gig within a SFP+ form factor. That, coupled with a cheap Mikrotik switch, is plenty to get started.
Second hand Brocade ICX switches are also plentiful and not too power hungry (but they can be loud).
Just a heads up to anyone who does intend to go buy a bunch of those modules.
They run absurdly hot, and they eat a lot of power.
If you don't have very good ventilation then you may find these modules running at well north of 80C. I ended up having to mount a 120MM PC fan and attach some mini-headsinks to them to keep them under 50C. Just sitting on a desk they were too hot to touch.
You may find that the power budget for your small 8-12 port SFP+ Switch isn't enough to run more than a few of these at once. I have an 8 Port Mikrotik SFP+ switch that can only run about 4 of them. The Quad-Port SFP+ NIC I bought from fs.com (Intel XL710-BM1) can only do two.
Expect to also run into issues if you use old, poor quality or mistreated cables. If you bend them too far (trying to get around a sharp corner) - they will work fine at 1Gbit, but just not work at all at 10Gb.
You may find it's a whole lot cheaper (and more reliable) to just get some optical cable and transceivers if you want to go more than a few meters.
For distances less than a few meters DAC cables are often reasonable value.
From personal experience, I'm now leaving the 10G-BaseT transceivers for runs where I can't run optical (like existing in-wall wiring).
Yeah, optics or DAC cables are definitely preferable. I wouldn’t run more than one or two 10G-BaseT units in most switches - but when you have a modem or device that only supports it, it’s a much cheaper way to get connected than buying a dedicated switch.
Woah, the brocade switches might be a very good option. I don't mind it being loud, since my server rack is in a well insulated part of my basement and have had no noise issues even with a couple 2U servers. Thanks for the suggestion!
Depending on how many ports you need, you may get away with an ICX 7150-12. It has 14 fixed Gb copper ports and 2 10 Gb SFP ports. It's fanless and has 12 GbE PoE ports.
I own a farm, this summer we produced and sold about 1500 bales of hay. Had no idea hay exchange existed, the vast majority of our sales were via craigslist and Facebook marketplace, with most being small-scale (50 bales or fewer). The rest came from word of mouth and our local 4-H group.
Producing hay at this scale is extremely difficult. The start-up costs are in the hundreds of thousands of dollars, and you're typically barely breaking even. This year is unusual in that supply was way down, so prices were a lot higher than normal. The only reason we can do it is that we have a relationship with someone who cuts & bales a number of small fields for a per-ton fee.
I could see a tool like this being useful for large-scale operations that are doing the big round bales yet don't have an established relationship with a buyer. For an operation like ours, where we are producing small ~60lb traditional square bales, I don't think we're going to find anyone local enough who wants to buy at the quantity and size we have. For instance, only two entries in the entire state of Oregon.
That said, I'll post on here next season, I'd be really interested to see if anyone reaches out.
I've been cutting my own hay (10 acres) for 17 years now. My equipment investment was as bare-bones cheap as possible ($5k for a 1960's tractor, $2500 for a 1960's baler, $1k for a couple of wagons, $2k for a wheel rake, probably $10k in maintenance over the years). The one thing I can say with confidence is that making hay is the single most stressful thing I do all year. Finding clear weather, and then watching the weather hour to hour after it is cut, and before baling day is agonizing.
I wish used equipment was that cheap now! We are constantly looking and old balers in our area are still going for $7k+. For something relatively recent and in good working order, much higher. Also, don’t forget building a dry place to stack and store all of it!
I guess that's good for me. My last cutting ever was last Saturday. We are moving and all the equipment will be sold in the spring (or sold with the property.) Located in N. Illinois.
Would be interested in learning more about the property you’re selling … the wife & I have been looking around Northern Illinois (she’s from Rockford) for a small farm. My email is in my bio.
> Also, don’t forget building a dry place to stack and store all of it!
Would Romanian haystacks help? Or is it impossible to do it on a large scale without a large amount of manual labor? Can you just drape a tarp over each hay bale?
If hay is stored outdoors in a typical temperate climate without a tarp, it's just a waste of everyone's time. Sure, cattle or goats can eat it, and it will make a turd, but the nutrients are gone within a few months.
Here in California, the water supply is obviously a concern as well. The grower I regularly deal with was very concerned at the start of the year, and I doubt last week’s atmospheric river storm did much to calm him down. After all, this is harvest season right now, not replanting season.
All hay is irrigation intensive, but my understanding has long been that premium quality alfalfa hay is especially so. The fields around here used to be flood-irrigated, but as the cost of water has risen over the past 10-15 years, I have seen that practice curtailed drastically. You lose too much water to evaporation. That implies heavy investment in more precise irrigation systems.
I know nothing about farming but there's a global manufacturing shortage right now that is making new parts and new machines scarce, which puts a lot of pressure on the used parts market. I'm guessing there's not much special here and that it's just participating in the global trend.
If you're looking for a non-conventional way to sell your hay bales, think about seasonal decoration.
There are plenty of city slickers who will pay more than farmers for hay bales to put on their front porches in September and October. My wife spent a week searching a six-county area trying to find one for her annual hay bale + cornstalk + indian corn + pumpkin + scarecrow display.
I've occasionally seen mini hay bales for sale in supermarkets. They're about the size of a MacBook and go for around $10.
My guess is that what would be most cost-efficient for you is to find a garden center or regional big box hardware store that sells seasonal decorations, so that you can make one large delivery to where the people are.
If any of your neighboring farms have pumpkin patches, maybe they'd be interested in selling hay bales to the public. We went to three pumpkin patches this year, and while all had hay bales for their own use, none had any for sale to the public.
Just a thought from someone who's not a farmer, but has always had an interest in farms.
Son of a farmer, living in a farmer community. Alfalfa hay doesn't have seeds unless you harvested it waaay too late, and then it's probably worthless.
I've only ever heard of straw referring to wheat straw - the wheat stems (and grainless heads) left in the field after harvesting.
Hay, on the other hand, is the whole plant (well, not the roots) of alfalfa (a legume), or brome (a grass) or prairie hay (mix of native grasses).
This may be slightly different in other areas, but the above is how it is in Kansas.
In what modern situation would a whole plane parachute actually help save lives? The vast majority of the (extremely rare) commercial aircraft disasters occur during takeoff or landing, when a parachute would provide little utility due to the distance the aircraft is from the ground. Other notable recent disasters had either instantaneous destruction of the aircraft (Metrojet 9268, Malaysian 17) or were caused by pilot error or murder/suicide (Germanwings 9525, Colgan 2407).
Perhaps the only incident I can think of where a parachute may have helped was US Airways 1549, where a bird strike caused loss of power to both engines. In that case, however, sufficient safety controls existed to enable landing on the Hudson river, and the aircraft functioned as designed (engines broke off when hitting water, the aircraft floated long enough to ensure safe evacuation of all passengers, life rafts deployed, etc). I would argue a parachute would probably have resulted in loss of life as a giant A320 parachute falling uncontrolled on to New York City would probably kill people crashing in to a building.
Rather than focus on superfluous, impractical safety measures, commercial aircraft designers have instead spent time on things that actually save lives, such as Traffic Avoidance and Ground Proximity warning systems.
Note that parachutes do exist for smaller planes, where the risks and benefits are substantially different. A good example is the Cirrus SR-22. It seems that most cases of deploying the parachute on the Cirrus is due to pilots running out of fuel, a failure which is extremely improbable in commercial aviation.
> Perhaps the only incident I can think of where a parachute may have helped was US Airways 1549 [...]
Another is United 232, the Sioux City crash during a landing where all hydraulics had been lost, leaving the pilots with only differential thrust to steer with.
Perhaps TWA 800, if I'm recalling correctly that the explosion basically decapitated the plane leaving the passenger section largely intact.
Also maybe Aloha 243. That plane was able to land after a large chunk of the cabin blew out with no fatalities other than a crew member who was sucked out during the initial blow out, so like USAir 1549 a parachute would not have saved any lives in that particular incident. In that type of incident, though, it probably would have been a good option. Such incidents leave the pilots with a plane that is flying at the moment, but that has severe structural damage leaving them with no idea what maneuvers they can do without tearing it apart and no idea if it is even going to hold together in stable level flight. That would probably be an incident where your probabilities would be better with popping the 'chute.
I was just thinking about how the idea has been around a long time. Even back in the early 2000s I was working on a project that used a camera on a special tripod that would let you take pictures in 360 degrees and stitch them together with some software in post (quicktime I think?).
But I think the neat thing is using readily-available GoPro cameras and stitching the video together quickly. That takes a lot of processing power to do on the fly.
QuickTimeVR Toolkit. It was painfully slow on my Quadra and the stitching usually had to manually corrected by nudging the images around (didn't help that this was pre-digital cameras and errors in slide registration and scanning compounded) but I thought it was close to magic - even if it was running in MPW ;-)
We looked at doing things like logging git commit frequency to try and provide realistic estimates to users of their time that they could then confirm or alter. Realistically, with the diversity of talent we have here (both technical and non-technical) and the time it would take to do well, it didn't really seem too practical.
It would be awesome if WakaTime and others provided some way of interfacing with an API, so that individuals could track time in a way that made sense for them while reporting in a relatively consistent standard to a central system used for accounting and billing.
Yeah, I built (and later shut down) didlog http://www.didlog.com/ a while ago which I had hoped would eventually turn into something like this. Track code commits, calendar events, emails, files changing, etc to try to put together a map of everything you're working on.
I knew I'd be biting off more than I could chew if I tried to tackle time tracking from the start so I was hoping I could build something useful before moving into that area. Turns out, I couldn't (given my limited time and resources).
Like everything 18F produces, Tock is a work of the US Government and is in the public domain. There's a link to the GitHub repository in the blog post (https://github.com/18f/tock). We don't intend to launch Tock as a service, rather, it's something we made for internal use that is open for others if they find value in it.