Hacker Newsnew | past | comments | ask | show | jobs | submit | mrclark411's commentslogin

Long live the Queen!


Data centers actually are a huge bonus to the county's taxes. It's a huge (to the point of being a risk) portion of the County's revenue.


I've lived here 20 years and never met anyone who works at a data center.


logback is *gpl, I think that scares folks away.


Logback is dual-licensed under EPL v1.0 and the LGPL 2.1, as per the licensee's choosing [1]. In particular, it is not licensed under the GPL.

[1] http://logback.qos.ch/license.html


It scares away people who see 'GPL' and refuse to read further, perhaps. Not only is it dual licensed, but both licenses (EPL and LGPL) freely allow linking with proprietary software.


We got a SOC2... and still get questionnaires. It's the worst. Companies are just outsourcing their security reviews to the vendor. Rather than rely on a 3rd party audited document companies want their custom questions answered. BUT - they aren't custom questions - it's the same questions for every vendor and they are very often poorly worded. Then when we turn them in - there's no follow up questions which to me implies that no one is reading them. Security theater...


I would argue it is "Compliance Theater."


I was going to just skip over this by reading the comments. Thank you for suggesting I go look. Extremely moving.


Any thoughts on the NDA signing portion of the process when answering requests for detailed, private documents?

Getting legal involved is a whole other level of time/expense.


Stacksi is happy to sign (and has signed!) numerous NDAs with our clients.

If you're talking about the NDA process between vendors and assessors, that is a whole different can of worms which we have not really waded into at this point.

In my experience as a startup founder, the easiest way to handle these types of situations is to just read over and sign whatever NDA the bigger company has sent over.


> the easiest way to handle these types of situations is to just read over and sign whatever NDA the bigger company has sent over.

That can cause problems down the road for a receiving party. For example:

1. Some NDAs include terms that assign ownership of newly-developed IP to the big company — this once resulted in Stanford University losing part-ownership of one of its biotech patents to Roche, in a case that Stanford (unsuccessfully) took all the way to the U.S. Supreme Court. [0]

2. Many, many old-fashioned NDAs still require the receiving party to return or destroy all of the disclosing party's confidential information. That can be quite burdensome and expensive for electronically-stored information. (Imagine having to search all your emails and backups to identify the disclosing party's confidential information.) And in any case, as insurance for possible future litigation, the receiving party would want to keep an archive copy to document what it received — and by implication, what it didn't receive — from the disclosing party. [1]

[0] Federal Circuit case: https://scholar.google.com/scholar_case?case=679137785502826... Supreme Court case: https://scholar.google.com/scholar_case?case=168732492844241...

[1] Additional information: https://toedtclassnotes.site44.com/Notes-on-Contract-Draftin... (my course materials for the law-school business contracts class I teach; it's a still-crude interim draft)


You're totally right, which is why I said to read over the NDA before signing :)

I fully admit that we do not have the legal expertise to try and tackle that problem at this point.


Legal is often where agreements go to die. This is a tough one, and one that so far, we've opted out of until we can create a better process for doing so than what exists out there.

FWIW, I think pima (pima.app) does a pretty good job with this.


Interesting that no anti-virus type software is mentioned.


I also don't see stuff like MDM software or Active Directory type licenses etc. Are they counting IT management as an outside service?


We use Okta (which is in the list) for AD purposes and JAMF (which I'll ask to add to the list but is on https://about.gitlab.com/handbook/business-ops/team-member-e... ) for Mobile Device Management (MDM).


Same here. I wish it was a little faster in changing configurations (I move some speakers around to different rooms and different pairings from time to time), but the last time I did so - it was faster/better than before.


Induction works fine. Our house is all electric. On the coldest winter days the heat pump needs some help using some resistance heat which isn't as efficient - but it does just fine. No need to have gas.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: