Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
alquemist
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
alquemist
6y ago
Rarely. Over a long enough time period though, the probability of a portability event nears 1, and the cost of such event is enormous. Right now there is a credible challenge for the x86 domination in the server, laptop and desktop markets
2.
▲
by
alquemist
6y ago
I am not following WASM closely, but it appears to be deployed in all modern browsers: Chrome, Firefox, Safari, Edge. That counts as 'large scale production deployment', even if there aren't that many websites that take advan
3.
▲
by
alquemist
6y ago
In a WASM + seccomp implementation, the whole WASM runtime runs inside seccomp. Breaking out of WASM leaves one running arbitrary asm inside seccomp, which has exactly the same attack surface as directly running untrusted binaries inside se
4.
▲
by
alquemist
6y ago
That's a bit of apples and oranges. JS/WASM are runtimes executing hostile code, whereas Go apps are trusted code.
5.
▲
by
alquemist
6y ago
Assuming that Intel / ARM microarch implementations are bug free, that is correct. In the real world there are no bug free implementations. Edit. This is the strategy Chrome sandboxing uses: a hardened runtime (JS/WASM) inside a s
6.
▲
by
alquemist
6y ago
* Predictable performance. * A wide ecosystem of mature language toolchains. * Simplicity: JS implementation contain sophisticated JITs, which are harder to prove correct compared to a simple ASM translator. * Portability: not tied to a spe
7.
▲
by
alquemist
6y ago
It's not an either/or. Most likely Shopify runs WASM inside an seccomp enclosure. Possibly inside a VM as well. Defense in depth.
8.
▲
by
alquemist
6y ago
Mock: Adhoc guessing of what methods called on a dependency, but sometimes even between classes in the same module, might return. Guess repeated over and over as new tests are added, sometimes tens of times or even more. For example, https
9.
▲
by
alquemist
6y ago
Agreed. Using mocks while testing vanilla in-process code is never justified.
10.
▲
by
alquemist
6y ago
Fakes are not mocks. The fake is just another module. Assuming no updates, it is written once. Mocks are written 47 times, inconsistently, while focusing primarily on other tasks. If there are updates needed, better to fix them in one place
11.
▲
by
alquemist
6y ago
Fake, don't mock. Write, or ask the team that provide the external dependency to write, a small piece of code that behaves like your external dependency, but in-process. You'll thank me after about the 47th time you're guessi
12.
▲
by
alquemist
6y ago
Fake external storage / rpc dependencies.
13.
▲
by
alquemist
6y ago
Don't mock. Test production code, maybe with faked storage.
14.
▲
by
alquemist
6y ago
"In the beginning was the word". Language shapes reality. As software engineers, the second we accept that 'product owner' is a legitimate title, that second we lost agency to push back on poorly conceived features. Say
15.
▲
by
alquemist
6y ago
https://leanprover.github.io While it is difficult to design a secure procurement chain all the way to the SiO2, we could at least design simple enough hw/sw systems for which formal verification is an economical option. An
16.
▲
by
alquemist
6y ago
Can not resist. The tension between 'basic feature set' and an admittedly superficial reading of the docs is very funny. The manifesto links to https://github.com/commercialhaskell/rio#readme and urges us to
17.
▲
by
alquemist
6y ago
99% of the time a loop works just fine, because there are no measurable gains to be had from parallelism. For the 1% where performance matters, it's usually a bit more involved that simply using a map or fold, and hopefully already pac
18.
▲
by
alquemist
6y ago
'FP' covers 2 meanings: A. Pure functions + immutable data structures. B. Expressive type systems, all the way to compile-time metaprogramming and dependently typed proofs. Writing programs in style A. is tremendously valuable. Ex
19.
▲
by
alquemist
6y ago
Haha, I'm the wrong person to ask. I was fortunate enough to be in a hands on senior role, and I promoted a very light Java++ style, to be learned in a 2 hours seminar: immutable collections, case classes, pure functions, impure loggin
20.
▲
by
alquemist
6y ago
I used Scala2 professionally for a few years. Recently picked up Typescript, it has become a very usable Java++ language.
21.
▲
by
alquemist
6y ago
RAII can be decoupled from ctor/dtor mechanism, see Python's 'with' statement. Javaish pseudocode, similar to a 'for' loop: // on exit the finally fn will be called with 'x' as an argu
22.
▲
by
alquemist
6y ago
Thanks. Then the 'bad' code should look something like: // bad NotifyIcon CreateNotifyIcon() { NotifyIcon icon = new NotifyIcon(); icon.Text = "Blah blah blah"; system.Display(ic
23.
▲
by
alquemist
6y ago
I have to agree with the author. It is extraordinarily difficult to see the difference between bad exception-based code and not-bad exception-based code. In particular, the example of bad vs not-bad doesn't show substantive differences
24.
▲
by
alquemist
6y ago
FWIW, transformers is to sequences what convnets is to grids, modulo important considerations like kernel size and normalization. Think of transformers as really wide (N) and really short (1) convolutions. Both are instances of graphnets wi
25.
▲
by
alquemist
6y ago
Testing page works for me now too. Could have been a temp fluke. Though, for example, https://amiunique.org/stats , ends up being an empty page.
26.
▲
by
alquemist
6y ago
Ironically, amiunique.org is broken with JS disabled.
27.
▲
by
alquemist
6y ago
Thanks. What is the most common user agent out there? Sadly, this is of limited use. Defense against fingerprinting is like herd immunity. If everybody else already has a unique fingerprint, there is not much an individual can do to avoid
28.
▲
by
alquemist
6y ago
And yet, not enough: > Your browser fingerprint appears to be unique among the 2xx,xxx tested in the past 45 days. > Currently, we estimate that your browser has a fingerprint that conveys at least 18.xx bits of identifying informatio
29.
▲
by
alquemist
6y ago
It does! I had to manually disable Javascript in UO settings, which solved the problem for me. FWIW, it doesn't solve the problem at scale, per opt-in / opt-out dynamics. It's a feature worth building into the browser, and se
30.
▲
by
alquemist
6y ago
Christmas came early this year :) Thanks!
More ›