Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
badgar
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
19 ms
·
31.
▲
by
badgar
14y ago
> But 'deleting' an account probably doesn't do much more than remove the data from the immediate web services. If you think they delete the data at all from anywhere you're out of your mind. Records are tombstoned, moved to cold(er
32.
▲
by
badgar
14y ago
You are responding to a stray Apple fanboy who spelled "come on" as "common." I recommend disengaging.
33.
▲
by
badgar
14y ago
An more detailed writeup, but hardly satisfying. Like most of Heroku's technical choices made in the name of "simplicity" and "robustness." But I guess I should accept that Heroku will never be a technically impressive PaaS provider. Just t
34.
▲
by
badgar
14y ago
I don't think we should be too surprised with how FB will use the new data. I'm just wondering who Facebook is going to share this data with. I know a guy who works at one of Facebook's "partner companies" that pays gobs for FB user data. T
35.
▲
by
badgar
14y ago
> Heroku still requires authentication, but doesn't filter access by ip. Which means unauthenticated access to the postgres port as I said in my post. I didn't say "unauthenticated access to postgres" which would be plainly ridiculous
36.
▲
by
badgar
14y ago
> Any system that allows unrestricted access to the PostgreSQL network port, such as users running PostgreSQL on a public cloud, is especially vulnerable. Heroku allows unauthenticated access to the Postres port to anyone on the Interne
37.
▲
by
badgar
14y ago
> 1k req/min Also known as <17 requests per second... or a trickle of traffic. Hooray for using bigger numbers and a nonstandard unit to hide inadequacy! Does Heroku use req/min throughout their service? I can't understand why the
38.
▲
by
badgar
14y ago
Engineers for startups are paid poorly and almost always work on technically uninteresting problems. Where are you going to get people who can write good code? And again, why would you bother if the hard part of startups is everything excep
39.
▲
by
badgar
14y ago
Why should they settle for third tier cable stations? I want HBO, Showtime, ESPN. If you're in the clear rebroadcasting Fox News you're in the clear with ESPN. How could -or would- you possibly see a difference? Copyrighted content is copyr
40.
▲
by
badgar
14y ago
Slide decks are created for different reasons. Some are made to fully contain and communicate ideas then widely circulated - these decks are content. These decks don't need someone to deliver them. Decks accompanying presentations aren't th
41.
▲
by
badgar
14y ago
Quality of software is pretty much irrelevant for startups. The code is usually crap and gets thrown away over and over anyway. The real focus is on people.
42.
▲
by
badgar
14y ago
Your friend is a genius and might be the next pg.
43.
▲
by
badgar
14y ago
You're forgetting his loaded and well-connected parents.
44.
▲
by
badgar
14y ago
To be clear, the opening force almost all comes from the wrist. The force you apply to the knife with your finger to get it going is quite negligible.
45.
▲
by
badgar
14y ago
The "meaningful distinction" is that "assisted-opening" knives require a non-zero amount of force in the direction that the knife actually opens. Switchblades can just have a button. The former takes a few minutes of practice to open smooth
46.
▲
by
badgar
14y ago
> The high property taxes (or property values or however the market works it out) doesn't make the schools good, it filters out people who are indifferent to the school quality, and filters in people who place a high value on education.
47.
▲
by
badgar
14y ago
Extortion is one of the better possible reasons for their DDoS. Eventually, when the money doesn't show, its in their best interest to stop attacking. While new extortionists will keep showing up, they won't likely come back. Ideological or
48.
▲
by
badgar
14y ago
> Sure it is, obviously you don't take any small amount of blocks as a signal. You do realize spammers are extremely good generating large amounts of things, right? > By getting a significant amount though and looking at each person
49.
▲
by
badgar
14y ago
Comments like yours are great reminders of why real legal counsel is so valuable.
50.
▲
by
badgar
14y ago
Thank you for identifying that Krugman is both an economist and an ideologue. HN readers identify closely with the former so they often ignore or excuse the latter.
51.
▲
Google Public DNS Now Supports DNSSEC Validation
(googleonlinesecurity.blogspot.com)
5 points
by
badgar
14y ago
|
0 comments
52.
▲
by
badgar
14y ago
This isn't a Fermi problem. It's analysis. Math. How many keys do you have? Not something you should guess. How many bytes per key are you saving? Not something you should guess.
53.
▲
by
badgar
14y ago
AFAICT Rails does point releases by just taking whatever's at head on the 3.x master branch, building a release candidate there, and iterating until nobody is reporting bugs. This isn't a security patch - a stable branch with deliberately
54.
▲
by
badgar
14y ago
Oh, I agree. I think I misunderstood. I didn't realize this is the first MongoDB release for which you can even reasonably do capacity planning. How did people plan before if there were no metrics?
55.
▲
by
badgar
14y ago
Not every comment on Hacker News is useful. I'd say I was going for poignant if anything.
56.
▲
by
badgar
14y ago
Github's code doesn't rely on the security flaw to function. Their code should keep working after the security fix. Anyone who has ever consumed an API to build something they don't want to break understands this.
57.
▲
by
badgar
14y ago
The point isn't that they had a security flaw, it's that the patch release fixing it changed the god damn default ORM's semantics!
58.
▲
by
badgar
14y ago
Yes, I was pointing out that Rails made backwards-incompatible changes to core functionality in a point release primarily targeting security. I don't know how much more succinctly I could have originally put it, and I thought that it was ob
59.
▲
by
badgar
14y ago
Rails security point release breaks apps by changing the ORM. News at 11.
60.
▲
by
badgar
14y ago
> you had to know both data and index sizes across your most common usage patterns. This is called capacity planning. If you can't estimate what resources you use, I wouldn't expect great success scaling.
More ›