Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mattstir
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
mattstir
3mo ago
They either just ban E2EE messaging or add a client-side scan of the content before "encrypting" it.
32.
▲
by
mattstir
3mo ago
Just wanted to say I'm impressed with the speed of progress! There's clearly a lot of passion being poured into the project, and I appreciate that folks are responding really quickly to things. It looks like you've already fi
33.
▲
by
mattstir
3mo ago
How much of this is vibe coded? The widget demos about halfway down seem half-baked; the currency input allows letters and letter inputs visually disappear when you unfocus it. The calendar input appears to select the day before the one I c
34.
▲
by
mattstir
4mo ago
Apple is also an absolutely enormous company. Even if Valve wanted to lock in prices, they're simply too small for RAM manufacturers to notice on their radar, unfortunately.
35.
▲
by
mattstir
4mo ago
That's true for arrays of these value classes. Scalarization would help for larger local values though, since those would avoid pointer indirection for purely local values.
36.
▲
by
mattstir
4mo ago
> But the difference in memory is fundamental. The JVM can now store the values themselves in the array, laid out densely one after another: 8 bytes per point (plus a possible null flag), in a contiguous block. No headers per element. No
37.
▲
by
mattstir
4mo ago
Is this at all coherent...? The author really seems to be comparing cookies to JWTs as if they exist in the same category, but it really is apples to oranges here. In fact, one of the first articles they link to spell that out explicitly: &
38.
▲
by
mattstir
4mo ago
Yes? It's unclear how they'd do their job without extensive fingerprinting. I don't like it either, but pretending like it's not better positioned from a privacy standpoint is odd. At very least, turnstile isn't ran
39.
▲
by
mattstir
4mo ago
> or maybe one of them could just invest in packaging custom html elements, instead of assuming I'm going to use one of a handful of unnecessary "component" libraries ... are these not the same thing? I suppose from a tech
40.
▲
by
mattstir
4mo ago
> Reduce risk of failure through artificial intelligence. CQL contains an embedded automated theorem prover that guarantees the correctness of CQL programs. Man, it's a rough environment right now marketing-wise. I don't know i
41.
▲
by
mattstir
4mo ago
Could you elaborate on what other disclosure models you're referring to? I can't imagine something being "more responsible" for the public than privately notifying the owning party to give them time to fix the issue, bef
42.
▲
by
mattstir
4mo ago
> So it’s not quite as horrible as it sounds. I don't know about you, but if a random webpage takes 60+ seconds to load, I just close it and choose to never interact with that site again (unless it's my bank, which is a real an
43.
▲
by
mattstir
4mo ago
At which point it exists solely to punish real human users? What scraper bot is going through checkout?
44.
▲
by
mattstir
5mo ago
The vast majority of Python's AI/ML ecosystem is already written in C/C++ and uses interop glue to call it from Python. But agreed on the transitive dependencies, it's a nightmare
45.
▲
by
mattstir
5mo ago
I've seen microkernels mentioned a few times between these LPE posts and I'm curious about why. Would they be fundamentally more secure against forgetting to add bounds checking, or assuming user-provided input buffers should be w
46.
▲
by
mattstir
5mo ago
> select the previous-to-latest version For supply chain attacks that simply bide their time, or for dependencies which involve interacting with other subsystems, it's possible you miss a critical security update by doing this. Of c
47.
▲
by
mattstir
5mo ago
You only miss supply chain attacks that are eager to begin exploiting. If everyone begins waiting a week to update dependencies, attackers just need to wait 2 weeks before actively using their attack vectors.
48.
▲
by
mattstir
5mo ago
Maintainers attempt to reduce the likelihood of that somewhat by giving security patches boring-sounding commit messages. When there are thousands of patches for every kernel release to sift through, that adds a small barrier for would-be e
49.
▲
by
mattstir
5mo ago
> Presumably npm exempts security updates from its minimum release age Why would it? Then an attacker would just push compromised code as a "security update". Since the majority of these npm attacks are account-based, the attac
50.
▲
by
mattstir
5mo ago
I don't think there's much that's accidental about it. The giant corporations with near-monopolies in web-related markets (browsers, search...) are going to be incentivized to put restrictions in place that protect that monop
51.
▲
by
mattstir
6mo ago
Is that actually confirmed anywhere? It certainly sounds possible given some of the wording ("At this point, any app installed on a certified device in these regions must be registered by a verified developer.") but it would be ni
52.
▲
by
mattstir
6mo ago
You can if you jump through Google's dubious hoops to enable "advanced mode" as described here: https://android-developers.googleblog.com/2026/03/android-de... The steps are rather insulting and arb
53.
▲
by
mattstir
6mo ago
If you're building data structures that have specific requirements and you know you'll implement it correctly, you can use raw pointers like `*mut T`. That's why they're in the language, for when you need to do something
54.
▲
by
mattstir
6mo ago
This is a nice article! I think it introduces some concepts that Rust beginners might question ("what is `Copy` and what implements that?", "what's interior mutability? Doesn't that break the aliasing XOR mutability
55.
▲
by
mattstir
6mo ago
This is an interesting concept. I was initially thinking that this would only lower the memory usage of the stack by moving everything to the heap, but of course you can skip heap allocation if the struct you'd be instantiating is &quo
56.
▲
by
mattstir
6mo ago
To what end though? 4 billion addresses is not enough on its own, even if they were reallocated from hoarders. I think that NAT and especially CGNAT have been very detrimental to the shape of the internet, where it's nearly impossible
57.
▲
by
mattstir
6mo ago
> If a rebase conflict occurs, the operation pauses and prints the conflicted files with line numbers. Resolve the conflicts, stage with git add, and continue with --continue. To undo the entire rebase, use --abort to restore all branche
58.
▲
by
mattstir
6mo ago
I hope that GitHub continues copying Graphite's homework in terms of functionality, because from what I can see they don't have equivalents to `gt split`, absorb, and so on. Those can be very useful in the right contexts.
59.
▲
by
mattstir
6mo ago
It appears the CLI is only half-baked so far. Given how many things they've borrowed from Graphite (a tool which adds this type of workflow), it should only be a matter of time until they add a `split` command. Graphite lets you split
60.
▲
by
mattstir
6mo ago
That is genuinely horrifying. I wonder what the stats are for an average "artisan, hand-typed" project would be if it got as much attention as OpenClaw has. But 1.8 CVEs a day should scare any rational people away from the softwar
More ›