Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jamiesonbecker
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
91.
▲
by
jamiesonbecker
6y ago
The "boxes" to be checked are actually asking open-ended questions about that, and asking you to provide copious written documentation backing up what you are claiming. This process takes weeks or months and is quite expensive.
92.
▲
by
jamiesonbecker
6y ago
Annex A is a subset of 27001, but 27001 is focused on security. https://www.iso.org/isoiec-27001-information-security.html (Even so, your point is well taken. The overall 27000 series is more business continuity (DR etc)
93.
▲
by
jamiesonbecker
6y ago
> Given the current political climate, Not sure what politics have to do with it. > such a SOC-2 auditor should be outed by name. That would be defamatory, and potentially extremely unfair, especially if someone lied or was just incor
94.
▲
by
jamiesonbecker
6y ago
I see your point: if they were competent, they wouldn't overlook it. My point was more that because SOC-2 is more pedantic (than, say, HIPAA), it's harder for a SOC-2 auditor to mess this up.
95.
▲
by
jamiesonbecker
6y ago
> any SOC2 audit would overlook this because they're just going down a checklist From the GP, "They also stored (1) all the production database and server passwords in a plain text file accessible to half the company and (2) no
96.
▲
by
jamiesonbecker
6y ago
> But you won't be more secure. I respectfully disagree. A cloud has many more vectors for attack, and even the largest clouds have blind spots. For example, check out AWS's (lack of) response to a vuln report that I filed with
97.
▲
by
jamiesonbecker
6y ago
In an ideal world, these are mostly reasonable questions, even if a bit specific to the OP's requirements, but unless you are purchasing SaaS software on a large, enterprise-style license (i.e., 6 figures or more), it probably won'
98.
▲
by
jamiesonbecker
6y ago
> If you don’t use a cloud provider: why not? This makes it sound like it's a negative, but a solid argument can be made controlling your application all the way down to the metal is a more , not less, secure way to go. We can all
99.
▲
by
jamiesonbecker
6y ago
Still doesn't seem like much of a win compared to the jQuery :) $(".classname").addClass("darktheme")
100.
▲
by
jamiesonbecker
6y ago
> jQuery is very big on not breaking behaviour even for small things You answered your own question :)
101.
▲
by
jamiesonbecker
6y ago
Fair point. Thanks for bringing it up!
102.
▲
by
jamiesonbecker
6y ago
This kind of code grows explosively in a moderately-sized project, and the sheer volume and verbosity makes it hard to debug. Not to mention requiring more tylenol ;)
103.
▲
by
jamiesonbecker
6y ago
Nice, thanks for this!
104.
▲
by
jamiesonbecker
6y ago
Somewhat true, but this was also old jQuery :) Even the old jQuery seems easier to read than the modern ES6 equivalent (IMO). jQuery: $(".classname").addClass("darktheme") ES6: document.querySelector("
105.
▲
by
jamiesonbecker
6y ago
> In the real world... From experience... Does jQuery (est. 2006) have more bugs in it than your code?
106.
▲
by
jamiesonbecker
6y ago
Good point. This is what I was referring to: https://en.wikipedia.org/wiki/Encapsulation_(computer_progra...
107.
▲
by
jamiesonbecker
6y ago
Are you being sarcastic? But, either way, it really depends. If you are writing a large application and jQuery saves thousands of lines of boilerplate, then it's totally worth it. For a tiny library (which is what this page is targeted
108.
▲
by
jamiesonbecker
6y ago
> Hidden complexity you don't control is the most expensive kind I think. That's called encapsulation. :) Seriously, encapsulating complexity is the foundation of most programming paradigms.
109.
▲
by
jamiesonbecker
6y ago
Are you sure? AFAIR, jQuery has used native (hardware-accelerated) CSS transforms since 2014.
110.
▲
by
jamiesonbecker
6y ago
Agreed! Especially for a smaller library or one that wouldn't adequately take advantage of jQuery shortcuts (or if you're using another library for DOM/shadow DOM, like react/angular/vue/etc) Counterpoint, if y
111.
▲
by
jamiesonbecker
6y ago
It's ironic that there's probably no bigger sales pitch for jQuery than this site. In every single example, the jQuery version is basically one or two lines of code, versus 10-15 lines for the alternative. (and the jQ version seem
112.
▲
by
jamiesonbecker
6y ago
Nothing like old money.
113.
▲
by
jamiesonbecker
6y ago
Also, can you feed live data for a constantly-updating presentation, or is it more intended for more static data that highlights a particular trend that might not be otherwise obvious?
114.
▲
by
jamiesonbecker
6y ago
This looks cool! It'd be great to see a demo video or some more screenshots explaining how it works and especially what the output formats are (web, exportable html, pdf infographic?)
115.
▲
by
jamiesonbecker
6y ago
Sorry, what's a fact?
116.
▲
by
jamiesonbecker
6y ago
libc and sdl
117.
▲
by
jamiesonbecker
6y ago
I started hacking on this again as well (especially classic Unreal Tournament/UT99). Would love to play some Facing Worlds, but was not able to get it to work on a modern 64-bit MX system w/ nvidia binary drivers.. however, did ge
118.
▲
by
jamiesonbecker
6y ago
Can't remember which, but I think Telemate also had programmable macros that I used to jump in and out of hyperspace in one of the multiplayer door games..
119.
▲
by
jamiesonbecker
6y ago
GP is correct. 0.0.0.0/0 is all possible IPv4 subnets.
120.
▲
The Cares Act: What You Need to Know About Emergency Small Business Relief
(venable.com)
2 points
by
jamiesonbecker
7y ago
|
0 comments
More ›