Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bilalq
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
31.
▲
FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack
(pcmag.com)
197 points
by
bilalq
5mo ago
|
63 comments
32.
▲
by
bilalq
5mo ago
Building a startup on GCP (or even Google Workspace) is an existential risk.
33.
▲
by
bilalq
5mo ago
I'm saying be skeptical of who you give your trust to. You're the one seemingly pushing to trust actors who have a proven track record of not being worthy of that trust.
34.
▲
by
bilalq
5mo ago
What? This is something that's incredibly well documented at this point. Many VPN companies operate as arms of data broker and media companies or they resell data to them. Some of them didn't start out that way, but with the way a
35.
▲
by
bilalq
5mo ago
Using a VPN shifts your risk. Your local ISP can't see as much of your activity, but another company that probably has a business model of reselling your data to governments, intelligence agencies, and ad companies now can. If your con
36.
▲
by
bilalq
5mo ago
Unfortunately, the largest and most well-marketed VPNs are, in fact, less trustworthy than your average ISP.
37.
▲
by
bilalq
5mo ago
The Gemini features would be so cool if they ran locally, but as-is, this reads like a laptop running spyware to me. The Android app casting does sound amazing though and that alone would make a full on Linux machine with MBP level build qu
38.
▲
by
bilalq
5mo ago
When trying to upgrade from the Business Standard to Business Plus plan, Google will reduce your workspace storage from 2TB/user to 0 bytes for up to 24 hours while it upgrades you. These are actual quotes from support: > Upon check
39.
▲
by
bilalq
6mo ago
Let me more clearly instead say that many successful startups knowingly and intentionally broke the law. But I agree that Delve is a special case and should naturally be held to a higher standard here because their whole business is around
40.
▲
by
bilalq
6mo ago
While I do think Delve and the leadership there should be held responsible, it's a bit weird to see YC and others take shots at them for breaking the law when so many of their prized unicorns achieved what they did by being willing to
41.
▲
by
bilalq
6mo ago
I use a wallpaper with a horizontal black bar at the top to make the notch invisible, so this catches me off guard pretty often.
42.
▲
by
bilalq
7mo ago
Look into git reflog. If the changes were committed, it was almost certainly possible to still restore them, even if the commit is no longer in your branch.
43.
▲
by
bilalq
8mo ago
This has its own risk factors. If your domain renewal lapses due to credit card expiry or something and you fail to notice, it's catastrophic. This is just not realistic advice for the average person.
44.
▲
by
bilalq
8mo ago
XCode and Pages are a delight in comparison to VSCode and Notion is certainly one of the takes of all time. XCode is usually the first example that comes to mind of a terrible native app in comparison to the much nicer VSCode.
45.
▲
by
bilalq
9mo ago
These were absolutely incredible when they first opened up right on until covid. The blue-apron style meal kits they had were actually really tasty and the gimmicky integration with Alexa to tell you the next step in the recipe was actually
46.
▲
by
bilalq
10mo ago
This question is surprising to me, because I consider AI code review the single most valuable aspect of AI-assisted software development today. It's ahead of line/next-edit tab completion, agentic task completion, etc. AI code rev
47.
▲
by
bilalq
10mo ago
I already use Graphite today on top of git. Others are using alternatives like Sapling, etc. To go back to your question around why people still use these workarounds on top of git, it's because the CLI is just one piece of it. With Gr
48.
▲
by
bilalq
10mo ago
I have one and a half decades of muscle memory burned in with inoremap jj <Esc>`^ It's not something I can just shift away from.
49.
▲
by
bilalq
10mo ago
This is really exciting. Step functions were a big improvement over SWF and the Flow framework, but declarative workflow authoring sucks from a type-safety standpoint. Workflows-as-code is the way to go, and that was missing from AWS. Can&#
50.
▲
by
bilalq
11mo ago
This is orthogonal to the issue at hand. The problem is a malicious actor cutting a release outside of the normal release process. It doesn't matter if the normal process is automated or manual.
51.
▲
by
bilalq
11mo ago
You're probably already planning this, but please setup an alarm to fire off if a new package release is published that is not correlated with a CI/CD run.
52.
▲
by
bilalq
1y ago
I did a double-take when I read that as well. I went and checked the license under rubygems, and sure enough, it's standard MIT with no warranties. https://github.com/rubygems/rubygems/blob/master/LI
53.
▲
by
bilalq
1y ago
This is an excellent write-up of the problem. New hires out of college/bootcamps often have no awareness of the risks here at all. Sometimes even engineers with years of experience but no operational mentorship in their career. The kit
54.
▲
by
bilalq
1y ago
My objections here are in terms of how this manifests in billing. Especially when you consider the highway robbery rates for internet egress.
55.
▲
by
bilalq
1y ago
Fine for when you have no NAT gateway and have a subnet with truly no egress allowed. But if you're adding a NAT gateway, it's crazy that you need to setup the gateway endpoint for S3/DDB separately. And even crazier that you
56.
▲
by
bilalq
1y ago
Just checked, and it seems like it is. Not enabled by default for some reason.
57.
▲
by
bilalq
1y ago
I really wish ESM was easier to adopt. But we're halfway through 2025 and there are still compatibility issues with it. And it just gets even worse now that so many packages are going ESM only. You get stuck having to choose what to cu
58.
▲
by
bilalq
1y ago
1. This is not 100ms latency for requests. It's 100ms latency for the init of a process that loads this code. And this was specifically in the context of a Lambda function that may only have 128MB RAM and like 0.25vCPU. A hello world a
59.
▲
by
bilalq
1y ago
The root problem here lies with Apple. It's so frustrating how they take a 30% cut for the privilege of being unable to actually have a relationship with your customers. Want to do a partial refund (or a refund at all)? Want to give on
60.
▲
by
bilalq
1y ago
I applaud the idea and love that you made this freely available without bolting on a SaaS subscription on top of it. However, I always roll my eyes when I see high severity risk in dependency chains due to ReDoS vulnerabilities. Sure, it ma
More ›