Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
fault1
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
fault1
5y ago
I mean, catering to the needs of the many rather than the few has pretty much been npm policy since left-pad-gate: https://twitter.com/seldo/status/712417019686100992 https://blog.npmjs.org/post&#x
32.
▲
by
fault1
5y ago
I think there is two aspects of the word "trojan", but it does not imply "remote command and control", it's often that, but more broadly it means something that is disguised as one thing, but is not. For example, on
33.
▲
by
fault1
5y ago
> Turns out the author was the attacker, and with that confirmed, it appears that their access was restored so they could proceed with it. I suspect this is how it played out as well. In fact, there was a lot of people on Twitter who wer
34.
▲
by
fault1
5y ago
not to mention that in the case of colors.js he actually owned less copyright than other contributors. they had actually changed more of the code.
35.
▲
by
fault1
5y ago
I would say colors.js definitely can be considered malware. He in effect intentionally spinlocked a lot of packages either directly or indirectly via transitive dependencies, and also intentionally bypassed common semvar rules to maximize t
36.
▲
by
fault1
5y ago
Define "most" people.... To me, this is like the left-pad incident and npm. There was a vocal minority who denounced npm for looking after the greater good, maintaining continuity and transferring the project to someone else. In t
37.
▲
by
fault1
5y ago
It's 2022, so perhaps the committee will approve features from C++17. Now, all things considered, having used bgfx in various languages, I think the Orthodox C++ approach leads to quite clean code.
38.
▲
by
fault1
5y ago
There is also other translations, for example, in pytorch/pyro: https://fehiepsi.github.io/rethinking-pyro/ I would say statistical rethinking is a great way to compare and contrast different ppl impls and languag
39.
▲
by
fault1
5y ago
They probably did. It's because they've heard of other people getting rich off of crypto. The classic get rich quick swindle. Ponzi schemes and all sorts of other marketing schemes are also similar.
40.
▲
by
fault1
5y ago
Usually orthodox c++ looks something like: https://gist.github.com/bkaradzic/2e39896bc7d8c34e042b this is from bgfx
41.
▲
by
fault1
5y ago
Yeah, it's basically Clever Hans. You can see it with the amount of completely nonsensical output you can also randomly get from it if you deviate even a small amount form the input data distribution.
42.
▲
by
fault1
5y ago
That's true, though they said "recently". I don't think time to first plot is that bad anymore. Time to first gradient can be bad in Zygote/Flux.
43.
▲
by
fault1
5y ago
looks good! The ecosystem in Julia is quite strong for MCMC libs because people do not have to lower something to C++ to develop such a library: https://discourse.julialang.org/t/mcmc-landscape/25654/ Of cour
44.
▲
by
fault1
5y ago
How about Dylan? :-) I think one of the nice thing about Julia's "just ahead of time" monomorphization/devirtualization is that it allows a level of dynamism that also works on GPUs/TPUs. This post and linked paper
45.
▲
by
fault1
5y ago
Check out "An Algorithm for Passing Programming Interviews": https://malisper.me/an-algorithm-for-passing-programming-int... of course, it's important (for better or worse) to just grind out a representative
46.
▲
by
fault1
5y ago
turing, mlj, etc are quite good. https://turing.ml/stable/ https://alan-turing-institute.github.io/MLJ.jl/dev/about_mlj...
47.
▲
by
fault1
5y ago
mathematical notation would be kind of unreadable without the terse and compact symbology, imho. it makes it much easier for the mind to parse. mathematics is partially a language (maybe one of the most universal ones), once you learn commo
48.
▲
by
fault1
5y ago
I don't get your point. The repo, gh/npm accounts and such are just metadata and metadata of metadata, which is hosted and distributed based on the terms of service of gh/npm. The thing that matters most is what the npm proje
49.
▲
by
fault1
5y ago
People are going to include the code in question mostly via transitive dependencies. Creating an app with create-react-app will lead to at least 2000+ such dependencies. That's just how the entire npm ecosystem works, and so there is c
50.
▲
by
fault1
5y ago
But with contributors, it's literally not his to "own", in terms of the actual work. Copyright law says roughly that you own the characters you type, unless you assign it to someone else. The guy who actually wrote more of co
51.
▲
by
fault1
5y ago
Well, at least in the United States, it's the default the other way (there are implied warranties) unless licensed otherwise. That's exactly what most open source licenses do to protect the author. That being said, I could imagine
52.
▲
by
fault1
5y ago
yeah, it's just nobody reads every package in that file. apps generated via create-react-app have more than 2000+ transitive dependencies.
53.
▲
by
fault1
5y ago
however, I think the more common case is that they set it to the latest bounded by a minor or patch version (as opposed to a major version) as defined by semvar. at least that seems to be quite common in the npm/js world.
54.
▲
by
fault1
5y ago
But let's not pretend the original maintainer did all of the work or owned all of the copyright. There were a ton of contributors to color, and some dude actually had more lines of code edited than the original maintainer: https:/
55.
▲
by
fault1
5y ago
Nobody stole creds off the project owner in the left-pad incident. npm chose the needs of the many rather the few in that incident: https://twitter.com/seldo/status/712417370686365697 which seems like very much ak
56.
▲
by
fault1
5y ago
Did he own this code? Colors.js had plenty of other contributors, and there was no CLA involved. github user "DABH" actually had more lines of code than marak did: https://github.com/Marak/colors.js/graph
57.
▲
by
fault1
5y ago
> There’s an abundance of supply of people with masters degrees in machine learning? How’s that possible? I thought this shit was supposed to be hard. I think it's just a matter of proliferation of these types of programs, as well a
58.
▲
by
fault1
5y ago
Agreed. MLE in very ML-heavy companies tends to mean SWE who work on ML systems, and sometimes, that can mean as much working on stuff like infrastructure as modeling.
59.
▲
by
fault1
5y ago
Hopefully you aren't equating "eigenvectors" to "complicated linear algebra question". But I agree, a lot of MLE roles don't get asked such things. I think the OP's guide is closer to interviews I've
60.
▲
by
fault1
5y ago
I would say on average MLE roles tend to be more SWEng heavy. But some roles are as much creating infrastructure as running the tools.
More ›