Hacker Newsnew | past | comments | ask | show | jobs | submit | mustaphah's commentslogin

Location: Baghdad (UTC+3, CET+2)

Remote: yes

Willing to relocate: depends

Technologies: Java (5y), TypeScript/Node (4y), Ruby/Rails (3y), frontend (JS/Dom, React, Tailwind, ...), Microservices & Distributed systems (4y), REST & GraphQL APIs, RabbitMQ, Pub/Sub, Postgres/MySQL (8y), Redis, Elastic Stack, Prometheus, Splunk, Kubernetes/Docker, Ansible.

Website: https://hadid.dev

Résumé/CV: https://hadid.dev/resume/

GitHub: https://github.com/mhadidg

Email: career+hn @ [my website domain]

---

Hi! Product engineer with strong backend & infra/DevOps experience here. I have 9 YOE with a mix of enterprise and startup; 3+ YOE working remotely in a globally distributed team; looking for a backend or backend-leaning fullstack role.

Early in my career, I led the technical side of a workflow automation project at Earthlink - a big local enterprise. Later, I contributed 3+ years to Automattic (US) - the company behind WordPress. I've built and maintained time-sensitive, high-throughput services processing millions of ops daily.

While I'm a technical guy by title, I've worked very closely with business - collaborating with customers and product owners to understand and translate their needs into systems.


Haidt, in his great book "The Righteous Mind," has been arguing that reasoning evolved not to discover truth but to win arguments. There's a lot of scientific research backing his idea.

Haidt's metaphor is the rider and the elephant: the elephant (intuition) leans, and the rider (reasoning) invents the justification afterward and then defends it like a lawyer, not a truth-seeker.

Intelligence doesn't fix this - it just makes people better at coming up with hard-to-defeat arguments; that explains why smart people disagree all the time.


If you enjoyed TRM, his other book The Happiness Hypothesis surprisingly covers this and other concepts in much better detail relative to the OP.


This is just one flavour of abuse. GitHub does NOT give a shit about the scale of the malware problem.

I've seen so many forms of malware repos working on a GitHub trends newsletter [1], mostly about crypto, NFTs, KMS, and similar stuff.

In the first runs of the project, I was so surprised by tens of malware repos that looked like trending repos. A lot of them share some common traits that made filtering feasible:

- Made by a fresh GitHub user - many created in the past few days.

- The average creation date of Stargazers accounts is very close to the repo creation date. If you take the mean time diff, those bad repos get exposed.

I reported 10s of malware repos, but then I gave up as I felt GitHub was not really doing enough to fight back. I was like... these guys don't seem to care, why should I?

God knows how many people have been abused by these malware repos on GitHub.

---

[1] https://github.com/mhadidg/gh-trends


This is the problem with software/services being taken over by big entities: they no longer have to care under the umbrella of "too big to fail".


If most malware repos are created in the last few days by a fresh user, then it sounds like GitHub is taking action against them? Or where are the old ones?


Well, my trend detection logic rewards recent stars more than older ones [1]. Recency is an important factor for many custom and public tools that track GitHub trends. I think the bad guys intentionally recreate repos - I actually noticed that.

That being said, they do take action if you report the repo. So I'm guessing good users are doing the heavy lifting here with reporting. I don't believe GitHub is taking enough proactive measures, or maybe they do, but it's not working well, obviously.

https://hadid.dev/posts/github-trends/#growth-based-approach


Yea, I'd change it to, they care about the malware and will remove the repos, but above everything else they don't want to slow down the signup flow


I have no idea of the kind of investment this would take in terms of time and money, but is it beyond the realms of possibility to run code submitted to GitHub through a basic filter? Genuine question - I have no experience of systems at that scale. But the fact that Microsoft is able to replace URLs in emails with ones that redirect through their systems so they can block malware URLs makes me feel like it should be possible.


You can probably catch a big pie of those with simple heuristics to flag suspicious repos for expensive review (human- or AI-based). I did that with public account & repo data, and I believe they can do much more given the amount of private data they have access to.

I'm talking about 10s of repos flagged in a few hours. I don't think the volume would be that big for an expensive review.


It exists, although people complain it is too noisy. You can hook in any if your own tools too.

https://github.blog/security/how-to-scan-for-vulnerabilities...


Most of HN doesn't give a shit about the malware problem. They will happily click "Give XYZ App ... permission to act on your behalf" to all of their repos with zero knowledge of what permissions are being requested. Github's Auth system doesn't tell the user what permissions are being requested

Note: Github has 2 auth systems. OAuth, and Github Auth. OAuth lists permissions but most apps use Github Auth which does not. So that app that gives you a badge or lets you comment could asking for write permission all your repos. You have no idea.


You want my email voluntarily for the whole purpose of telling me "Hey, Fable is back"?

Everyone would be screaming the moment that happens. No, Thanks!


I finished The Lean Startup a few days ago, and I really felt the power of the ideas you've shared there coming from a heavily technical background; incredible work.

It's already been 14+ years since you wrote the book; I wonder if a second edition is something you have in mind, or at least on your consideration list


I've thought about it over the years, but never pulled the trigger. This used to drive me crazy when I was younger. When an author who became "older and wiser" decided to make a new edition of the book in which they hedged all their bold claims with all the caveats that they had gained through experience. I always thought such old people were cowards. Of course, now I understand why they do it.


If I was going to do a new edition, what would you want to see in it?


You would probably be better off reading learnxinyminutes.com/zig/


Agreed. Love that site.


I have a strong feeling the whole thing is distracting the people - the real question is, distracting from what?


The unreleased files.


Sam Altman and other big figures tend to shape their narratives around their personal and organizational interests. When people were skeptical, they pushed hard into the "God-like AI" narrative. Now that safety concerns are growing and their growth plans are in danger, they're pushing back against what they used to advocate.

Even if they genuinely believe what they’re saying, their perspective is still fundamentally biased and should always be taken with a healthy grain of salt.


I think they just say shit. And then they say the exact opposite shit, without blinking. Maybe that's why they confuse next token prediction with thought, not to ennoble "AI", but to absolve themselves.


I hate to say it, but I'm becoming less and less interested in structured content, and more interested in disorganized, messy content over time. I don't like the thought of how this may end up in a few years for me.


This ^. The moment I open an article/post and see subtitles in *bold*, emojis everywhere and/or symmetric paragraphs, I start to suspect instantly whether it's AI.

> more interested in disorganized, messy content over time

Same, that kind of content kinda forces me to use my brain (yeah.. sounds obvious..) to organize the message, understand it, agree/disagree, and actually CONSUME the content, like the old days..


"AI bubble" in the title, count me in.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: