Yes. But using USB devices has a practically infinitely greater attack surface that parsing data embedded in a QR Code. It's not like yo have to read QR Codes and go "echo $QRData | sudo bash"
"BadUSB is a computer security attack using USB devices that are programmed with malicious software.[2] For example, USB flash drives can contain a programmable Intel 8051 microcontroller, which can be reprogrammed, turning a USB flash drive into a malicious device.[3] This attack works by programming the fake USB flash drive to emulate a keyboard. Once it is plugged into a computer, it is automatically recognized and allowed to interact with the computer. It can than then initiate a series of keystrokes which open a command window and issue commands to download malware. " -- https://en.wikipedia.org/wiki/BadUSB
I mean, this thread has itself very clearly turned into some crypto-fetishist fan fiction, completely departed from reality. I guess it’s just what came to mind.
You nailed the term I didn’t know I was looking for, that’s exactly it! As a fantasy I’ve thought about creating a secret identity and have researched how to keep it absolutely safe. This is very hard and you can spend quite a bit of time designing ever elaborate schemes.
Ok, that was the first time I heard the phrase ( recreational paranoia ) and I am now lost in a sea of links. Can you elaborate on it? It sounds fascinating to me from context alone.
No. That is just naive pattern-matching against a hot-button issue that you read a lot about on HN. For both this story AND Boeing, the explanation is more complicated than “outsourcing bad!”
It's also an example of the really irksome thing that happens on American sites where people will quickly steer the conversation away from non-America stuff to America stuff because they feel more comfortable talking about something that they know about than just not participating in the conversation and watching other people talk about stuff that they are knowledgeable of.
Which is kinda silly because if they just sat back and listened they could learn more about the thing that other people are talking about so that the next time this topic comes up they won't feel uncomfortable and can jump in and add something to the conversation instead of just nervously pivoting to talking about Alatucky or Boeing or the number of street poops in SF.
I for one look forward to learning more about the medical system of Brazil from this post.
It is noticeable but this seems a bit circular though.
If the user-base is predominantly American then of course if you tally up the random nonsense comments on any given day, they will also be predominantly made by Americans, due to probability.
I think the issue is that some people ( and this may be HN-specific ) think that medicine in general, and maybe even diagnostics in particular, is almost exactly like software testing. In a lot of ways, it really isn't. Some reasons get a little esoteric, but the more important one is rather simple: until more recently, software did not have a direct impact on life and as such was mostly given a pass on some otherwise heavy blunders. That is slowly changing, but missing something during quality control is not likely to have the same impact.
But this brings me to the other important reason, statistical check can only get you so far and that is assuming we can now trust it was even done. Some people do rely on being able to say, 'this was false positive once, you know what are the odds of it being false positive twice'? Now, we add variable of uncertainty into the system in the form of 'well, it was outsourced so there is a non-zero chance it is bs anyway'.
In this particular case you're saying you need to test the organs once at the outsource place and then again at the hospital? Why not just get rid of outsourcing then?
No, that is not what the parent said. "Check an verfiy" can come in diffrent forms and tastes eg. having some samples (not all) checked by another lab, asking for standards and inspection performed by 3rd parties, asking and checking for documentation...the hell how do you think anybody could work with suppliers?
> eg. having some samples (not all) checked by another lab,
I don't think that is useful at all in case of rare diseases. You would just get two reports saying that the random sample is free of HIV.
Much better would be to send some known control samples. Making sure that some of the samples is known HIV+, and then check if the supplier can tell which ones are those.
You can still do this kind of audit, but you need to test a statistically significant number of samples in your "spot check" such that you know you some of them will be infected. The number will vary depending on the incidence of a particular type of infection present, but this is data that should be available.
I agree that sending control samples can also be effective, though. But if you need to send the whole organ to the test lab (and not just a small tissue sample), you probably don't want to be wasting healthy organs by infecting them. Better to just wait until you have an organ that's known to be infected already.
> But if you need to send the whole organ to the test lab
Why would you need to do that? Realistically the sample needed here is a small vial of blood from the organ donor’s body.
> You can still do this kind of audit, but you need to test a statistically significant number of samples in your "spot check" such that you know you some of them will be infected.
Nah. It really doesn’t work. The problem is that HIV is very rare. (HIV incidence per 1000 population adults 15-49 in Brazil is between 0.34 - 0.45[1])
Let’s be ultra conservative and set the “spot check” rate at 100%. That is you are sending samples from every single body to two labs. Because of the low incidence rates you would still expect hundreds and hundreds of those samples to return as negative from both labs. This might work if you would somehow have a “gold standard” lab you trust and an other “less trusted lab”. But in reality there is no such a thing as a “gold standard” lab you can trust without QA. (And if there would be you would just use them, instead of the other lab.) Even with that ridiculously high “spot check ratio” you wouldn’t know if you are getting negative results because they are in fact negative, or because both of your labs are falling for some reason and giving you constant false negatives.
In conclusion spot checking the results with a second lab simply doesn’t work. Even if you spot check every single organ donor you would be still blind for even the most basic error cases for unacceptably long times.
On the other hand if you intermingle a control sample into every single batch that changes the game. Lets say they run the tests on batches of 10 and you make sure that a random one of those is always known to be positive. Now if something goes wrong and they don’t detect the sample you can straight away reject the whole batch of tests as faulty. And it only costs you an 11% extra over not doing any QA.
So with the “spot checking” test you can pay as much as 100% extra and still not know if the tests are having the most elementary kind of fault for hundreds and hundreds of organ donors. Or you can go with the “control sample” strategy and have a reasonably high confidence for every batch right away at much less of a cost. Yeah you can do the “spot check” audits but it is ridiculously bad at catching issues even if you spend a lot of money on it.
I agree with you, also the bogus argument of "since most people are HIV free..." assumes direct testing instead of pooled testing (using modern information theoretic optimized pooled testing).
A bit of data is most informative if the entropy is 1 bit as well. A signal that is true most of the time, or a different signal that is false most of the time is less informative. Use pooled testing such that the result is true or false half of the time.
Had information theoretically justified pooled testing been applied from the start, then:
* 1) control-testing the testing contractors would have been straightforward and passing 10 control samples by chance would have a likelihood of 1 over 1024.
* 2) it would have made obvious that saving money on control-testing the contractors would hardly save any money
* 3) even in the bad scenario that control testing was skipped, the issue of contractors cheating would have surfaced much faster, since combining the pooled tests to identify which patient tests positive would constantly result in mysteries, meaning control-testing needs to be enabled, not the mathematics of pooled testing brought in doubt.
* 4) testing pharma industry hates pooled testing, as it means technological competition instead of sales growth by abusing the naive but false "common sense" that you need as many tests as patients tested.
on a side note: assuming tests with different operating point on the RoC curves (having different false positive vs false negative ratios) have different prices, do we know if the operators blatantly provided fabricated results, or if they blatantly ignored basic mathematics and thought the more expensive tests could be substituted by the cheaper ones even if intended for a different purpose?
consider a test designed for telling a patient that we diagnosed HIV, and then consider a test designed for screening an organ to be inserted into a patient.
do you think they should both use the same test? or do you think it wiser to have the diagnosis test have lower false positive rates, and the organ screening test to have lower false negative rates?
Yes, why not? You don't re-test every single one, though: you spot-check a statistically significant percentage of them. Or maybe you do check all of them, but only for a one month period every year (a month that changes every year, and isn't known to the testing lab, so they can't game the system).
Another option is to send "control samples" to the testing lab, something you know already is infected with something they should be testing for. Do this enough times, and you'll know if they're accurately reporting the bad samples.
This type of thing is the only way for anyone in any kind of organization to verify that their outsourcing is effective and they're getting the result they want.
Outsourced companies deal similar issues internally while also forcing you to trust their management. Internally this kind of corruption is more difficult because you have more control, and fewer people are going to cooperate. Similar to how companies can regularly use untrustworthy low level employees handle cash.
You can still get rogue employees in ether case, but an outsourcing company is like a ready made conspiracy where any corners cut automatically turns into money.
> Internally this kind of corruption is more difficult because you have more control
If we anthropomorphise the regulatory body, sure. In reality, there isn’t evidence either way. Corrupt governments handing work to the private sector is a proven efficiency booster. Meanwhile, competent governments Severn Trenting everything is textbook (on the political left).
Outsourcing and corruption isn’t limited to government agencies. Quite a lot of it is from companies to other companies or governments to company A and then from company A to company B where the subcontractors are at issue.
Outsource to 2+ contractors, use pooled testing, and use control tests to steer that percentage of tests towards those contractors that score better on the control tests. Obviously the contractor should not be allowed to know which samples are control tests.
If your reaction is that Apple’s core competency is in marketing and design and not manufacturing then i will ask if the same pattern couldn’t be applied to Boeing.
Further context: In Brazil since we have universal health care provided by the government, generally speaking non outsourced or contractors becomes public servants.
The issue is: Public service in Brazil is expensive and is virtually impossible to fire anyone. On top of that the cost of public service has second order effects in the public balance sheet for the municipalities plus it has a huge burden in the public retirement system.
Not saying that is right or wrong, but this is very common in the Brazilian heath system.
> Clients are often influenced by hype. A few years ago, it was "Linux is a toy." Now, it's "Why bhyve and not Proxmox?" They ask, "How can they sell FreeBSD? There's no AI, there's no Cloud, there's no Kubernetes, there's no blockchain – there's nothing!"
I am very confident that this is more ‘fan fiction’ than the author would like to admit. The sort of hypothetical that someone cooks up on their head to anger up the blood and to then self-soothe by thinking about how much better than everyone else they are.
Why does everything have to be so bloody religious? If you like boring tech, stop politicising it.
I made a semi-successful blockchain based product 5 years ago. At two, separate employers, I was urged to make a blockchain based solution to.. well actually the problem was not described in either case, only the use of blockchain.
If the described people understand so little about tech, it doesn't even matter what they say. You can try to educate them or say something even more BS for them to agree with (blockchain 2 on kubershmetes).
Yeah, as if Linux has AI and Blockchain and these don't exist on BSD systems...
Admittedly, Linux really isn't boring enough for me. By boring I mean I don't really want to notice that OS exists, I want a distro that has most answers to any noob question on Google, all drivers for all hardware out of the box, no fancy package managers like snap or cool future technology like ZFS, no way to shoot myself in the foot however hard I try... But in fact almost all cool future technology comes to Linux from BSD, but it has less drivers, less packets, and googling yields less results. Everything else is pretty much the same everywhere and always comes with caveats.
Yep. Not rebooting for a decade is in most cases an irresponsible ‘advanced rookie’ move. I’m more than aware of the greybeard-era uptime fetishism. I’ve more than dabbled in it. I’ve typed /exec uptime into my IRC client more times than I dare admit.
But come on…
All that’s been said about security updates etc aside (some of which can be mitigated with that fancy in-place kernel update stuff), If something hasn’t rebooted in 10 years I’m going to be a bit nervous about what happens when it does reboot. If it’s in an uptime fetishist environment, chances are that it’ll be rebooted at a time that’s…inconvenient to say the least. Are you SURE that nothing has changed in that time? Some people are! Moreso than others at least. But that’s extra work, and my bet is most places with these high-uptime machines aren’t putting that work In, or think they are and are doing it poorly.
“Boring” in this instance obviously means some weird tech culture virtue signal. The situations in which Linux isn’t at least ‘just fine’, and a BSD is better enough to justify SWITCHING, are, well, I’m skeptical of the author’s reasoning.