Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
chaz72
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
91.
▲
by
chaz72
11y ago
> Until there's a free, easy, maintainable, and actually existent solution to SSL certs, enforcing HTTPS-only is just downright extortion. True - but the second that solution exists, I can't think of anything that should stick
92.
▲
by
chaz72
12y ago
The first proposition tests the blackness of ravens. The second proposition tests the non-raven-ness of non-black things. When abbreviated, it sure looks like a paradox.
93.
▲
by
chaz72
12y ago
It's about 99% of "people who have no idea how to install a new browser", so that kind of skews those numbers.
94.
▲
by
chaz72
12y ago
Yes, I think so. I mean, it is ridiculous and horrible, but ... After thinking through it for a few minutes and pairing it with an XSL schema translator, this could enable some integration on systems where there is no code and it's all
95.
▲
by
chaz72
12y ago
If they explicitly say they will stop in the release version, I would accept that argument. If not...
96.
▲
by
chaz72
12y ago
Ah, now that is what I was looking for but didn't know how to ask. A few starting points I might trust would go a long way.
97.
▲
by
chaz72
12y ago
For those already using PGP, that sounds great. For me, who is not using PGP, my set of trusted keys is currently empty. So it is unverified. Which, arguably, might be safer than being overly trusting of my "trusted CAs", which is
98.
▲
by
chaz72
12y ago
Never mind, I see a higher ranked comment got an answer to this. I see the concept of keys signing keys and gpg --list-sigs. (Still no idea who might be at the end of that chain that I could actually verify though.)
99.
▲
by
chaz72
12y ago
Thanks, I will look into this.
100.
▲
by
chaz72
12y ago
That's very thorough, thank you! I understand all those things in general, but I don't know the specific mechanism by which my local PGP install recognizes who else trusts this PGP key. I grant you that if the key is protected fro
101.
▲
by
chaz72
12y ago
I have to ask: how are the PGP keys verified?
102.
▲
by
chaz72
12y ago
Dependencies from other repos. Is there a better way that's the equivalent of a Subversion external?
103.
▲
by
chaz72
12y ago
Oh, no doubt Subversion has its downsides and Mercurial is really good at what it does. I was just musing through my own tradeoffs. It is a very narrow point but one that I hope is in the spirit of the article. Partial repo checkouts, SVN e
104.
▲
by
chaz72
12y ago
If they follow through, we will finally have a mass market PC maker recognize the importance of a clean install. If they follow through completely enough to get Microsoft's "Signature" branding, then I just might have to star
105.
▲
by
chaz72
12y ago
I have been wondering whether to go back to Subversion myself. The distributed option really doesn't apply to me, my minimal branching needs are met by Subversion, and oh my god, git's submodules get confusing.
106.
▲
by
chaz72
12y ago
The developer should absolutely be involved in that discussion, as the person with the best information on the cost of supporting that long tail. If complexity makes the system less reliable for the 98%, supporting the 2% may be a fool&
107.
▲
by
chaz72
12y ago
Will you have automatic upgrades for the life of the device?
108.
▲
by
chaz72
12y ago
I agree, but I do see one distinction that I find interesting: if someone tries to pick a lock on a county building and they try 44 different lock picks, is that one charge or 44? Even once is a serious charge, but I'm not sure there w
109.
▲
by
chaz72
12y ago
Or perhaps "well rounded"
110.
▲
by
chaz72
12y ago
Will OpenBSD look to pull from their updated C++ libraries?
111.
▲
by
chaz72
12y ago
A lot of confusion about why this is going on. My take as a very interested user who has been actively tracking down info about this Node's next release and possible fork for some time is this: Node.js's last supported release use
112.
▲
by
chaz72
12y ago
As a recent convert to Node who switched to it because I thought we'd be closing in on 1.0 this year and instead got ... crickets. For my part, "pulling more regularly from V8" is enough all by itself.
113.
▲
by
chaz72
12y ago
Ah, now that is an interesting belief. Is it based on anything you can share?
114.
▲
by
chaz72
12y ago
I used TypeScript for a project earlier this year. As a C++/C# expert and a JavaScript noob, I found the clarity, the readability of my code to be far superior with TypeScript, well worth the extra tooling. Then I found that after work
115.
▲
by
chaz72
12y ago
Actually, no, that was just a prediction. I am making an assumption - and maybe not a fair one - that because Google mines user data on the web that they also mine user data on the phone. Skepticism seems warranted. With Apple, I try to be
116.
▲
by
chaz72
12y ago
Until Apple promised it so explicitly, I'd have said you might be right. True, Google and Facebook make zillions off of monitoring people for advertisers. That will make it harder for them to follow suit, there will be far more weasel
117.
▲
by
chaz72
12y ago
That definitely could imply they have received an NSL. But as a user, when I say "they would leak that they're fighting it", I would consider that completely insufficient. If they are pulling the kind of crap you say they are
118.
▲
by
chaz72
12y ago
Then they better have perfect security so there are no leaks proving that, or they're gonna lose their business anyway. I don't buy it, they'd fight that and they'd leak that they're fighting it.
119.
▲
by
chaz72
12y ago
I intend to. But my initial position is that it's far more likely that Apple will fail to be perfect than that they are intentionally orchestrating a coverup. That said, I think all this syncing and cloud stuff - in its early days, at
120.
▲
by
chaz72
12y ago
Apple has staked their reputation on the line and said "send us an NSL if you like, we have nothing we can give you". And the cryptographic principles, if executed properly, are sound. Maybe they're lying. Maybe Snowden 2.0 w
More ›