Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
esrauch
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
esrauch
10mo ago
I worked on these big web products before and the answer then was that no, you couldn't trust it to be honored and it would have been considered a privacy incident so better off just having the redirect and having no risk. You can'
62.
▲
by
esrauch
10mo ago
The reason for the intermediary is because the clickthrough sends the previous URL as a referer to the next server. The only real way to avoid leaking specific urls from the source page to the arbitrary other server is to have an intermedia
63.
▲
by
esrauch
10mo ago
The main claim here is that it is a defacto monopoly, and that there are not "plenty of other platforms", since none of those platforms actually have any reach. It results in most games smaller than Fortnight or Blizzard having li
64.
▲
by
esrauch
10mo ago
Don't they charge you more if you do pay-by-plate though? I always see signs that have a price with local ez-pass, a higher price with out-of-state ez-pass, and an even higher price for pay-by-plate.
65.
▲
by
esrauch
10mo ago
One of the super powers of Lua is that it doesn't need to be very stable: because you are always embedding an interpreter your code and interpreter have a matching version. That's directly contrary to what would make it acceptable
66.
▲
by
esrauch
10mo ago
There's a lot here, to be honest these things always come back to investment cost and ROI compared to everything else that could be worked on. Java 8 is still really popular, probably the most popular single version. It's not just
67.
▲
by
esrauch
10mo ago
Protobuf is the example I had in mind. It uses sun.misc.Unsafe which is being removed in upcoming Java releases, but it has a slow fallback path. It logs a warning when it runs if it can tell it's only using the fallback path but the f
68.
▲
by
esrauch
10mo ago
It's a nice idea but I've literally never seen it done, so I would be interested if you have examples of major libraries that do this. Abstractly it doesn't really seem to work to me in place of simple logs. One test case her
69.
▲
by
esrauch
10mo ago
It doesn't seem to work this way in practice, not least because most libraries will be transitive deps of the application owner. I think creating the hooks is very close to just not doing anything here, if no one is going to use the ho
70.
▲
by
esrauch
10mo ago
I think an example where libraries could sensibly log error is if you have a condition which is recoverable but may cause a significant slowdown, including a potential DoS issue, and the application owner can remediate. You don't want
71.
▲
by
esrauch
10mo ago
Historically that's true, but I don't think it's true in 2025.
72.
▲
by
esrauch
10mo ago
It's very easy to accidentally get misleading benchmarking results in 100 different ways, I wouldn't assume they did no benchmarking when they did the duplication.
73.
▲
by
esrauch
10mo ago
I think what you listed matches with what he suggested, they just have words instead of a letter for the variants. Which is actually better in this example because the "Slim", "Pro" and "Digital" mean what you
74.
▲
by
esrauch
10mo ago
Ah ok, it is true that if there's a lot of fungible offerings that worse but uncorrelated uptime can be more robust. I think the question then is how much of the Internet has fungible alternatives such that uncorrelated downtime can me
75.
▲
by
esrauch
10mo ago
I'm not sure I follow the argument. If literally every individual site had an uncorrelated 99% uptime, that's still less available than a centralized 99.9% uptime. The "entire Internet" is much less available in the form
76.
▲
by
esrauch
11mo ago
I may have misinterpreted "explicit roadmap", to be that implied a directing/organizing entity that is coordinating the exclusion of right-leaning people from professorships, versus your reply here clarifying you mean somethi
77.
▲
by
esrauch
11mo ago
> What about an explicit roadmap? I'm not sure what you're pointing at in the links: I don't see any "explicit roadmap" to exclude mainstream conservative thinkers from professorships documented there. The main e
78.
▲
by
esrauch
11mo ago
I'm not sure what evidence you would expect to see if it was self-selection because of an in-group mentality versus explicit hostility to intentionally keep some out. By comparison, is there some affirmative evidence for the reason why
79.
▲
by
esrauch
11mo ago
I know a number of people who pay very little taxes and enjoy tht benefit of government services, many of them are vocally against government spending despite that they would be personally harmed if they stopped If what you are saying is tr
80.
▲
by
esrauch
11mo ago
I think unfortunately this is a normal thing that happens: passionate people get very attached to something and have trouble dealing with dispute even when everyone is relatively good intentioned. I've seen it in the workplace a dozen
81.
▲
by
esrauch
11mo ago
I'm surprised by this comment; after the drama last week and after seeing this I fully have to side against Rebble. The nature of driving a healthy open source centered ecosystem is that you don't control it under your iron fist:
82.
▲
by
esrauch
11mo ago
It's a completely absurd claim that "most" people think the only reason the government isn't sending million dollar checks is hoarding. The government spending too much and the debt being large is an extremely popular ta
83.
▲
by
esrauch
11mo ago
There's potentially an argument for a ponzi scheme for one-ish more generation after which robots can do elder care and it's not necessary anymore. Japan already bet on it and the robots haven't materialized, so maybe it'
84.
▲
by
esrauch
11mo ago
"Right hand" is practically a bigram that has more meaning, since handedness is such a common topic. Also context matters, if you're talking to someone you would say "right shoulder" for _their_ right since you know
85.
▲
by
esrauch
11mo ago
I'm not sure if I'm following this example. A 500M Yacht concretely uses a large amount of materials/engineers/building expertise, right? It's not the exact same skills as building apartments but it is concrete &quo
86.
▲
by
esrauch
11mo ago
I'm very sympathetic to the premise of slop bug reports being harmful. Somehow zero of this thread has info about the slop bug reports though, it's all focused on one specific seemingly completely legitimate CVE issue.
87.
▲
by
esrauch
11mo ago
Google does not "want this fixed", this isn't a bug report from a team using ffmpeg, it's a security analysis from a whitehat security project. I think really if there's all these machine generated meaningless secur
88.
▲
by
esrauch
11mo ago
Right, Google absolutely should fund ffmpeg. But opening security issues here is not related to that in any way. It's an obscure file format Google definitely doesn't use, the security issue is irrelevant to Google's usages o
89.
▲
by
esrauch
11mo ago
Google Project Zero just looks for security issues in popular open source packages, regardless of if Google itself even uses those packages or not. So I'm not sure what GPLv3 really has to do with it in this case, if it under was a &qu
90.
▲
by
esrauch
11mo ago
Is there really slop here though? It sounds like the specific case identified was a real use after free in an obscure file format but which is enabled by default. If it was slop they could complain that it was wasting their time on false or
More ›