3 ms·
It's not actually a reasonable goal. Almost all pieces of software will need some nontrivial amount of data to fulfill their purpose. I am convinced, however,
by vec 9y ago
It's not actually a reasonable goal. Almost all pieces of software will need some nontrivial amount of data to fulfill their purpose.
I am convinced, however, that it is a very useful heuristic. The platonic ideal of a perfectly secure database is a completely empty one. Every step away from that requires individual justification. That doesn't mean your database will be small, but it should mean the database is as small as possible.
I treat permanently storing user data (any data, for any reason) as my solution of last resort. That doesn't mean I don't use it. It just means I have to convince myself I don't have any better ideas before I do.
- danenania 9y agoSo where do you store this data then? Or do you just live with forgetting everything about a user (their name, details, history) every time they switch devices?
- vec 9y agoFirst I try really hard to not need it. e.g. I'm "vec" on HN. They don't know my real name, my physical address, or my Twitter handle. Any features that did need that data are simply not going to be implemented, and the site is designed accordingly. Next, I don't store what I cam fetch or derive. Say I'm using GitHub as an oauth provider. I don't need to store an email, an avatar, or a password hash. I can use GitHub's data. All I have to store is an opaque oauth ID. Finally, if I do really need it and I can't get it from anywhere else then I'll happily store it. I just won't do it first, and I often won't do it until I've had a talk with the designers about what's possible with the data we already have.