Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mnahkies
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
mnahkies
5mo ago
In the UK tax on interest earned on plain savings accounts isn't deducted at source - so if you have a rainy day pot chances are you're required to register for self assessment and pay tax on it (particularly now that interest rat
32.
▲
by
mnahkies
5mo ago
Yeah that seems like a massive reach. Does banking count as a "supporting service"? After all a prediction market isn't very useful if you can't get money in/out.
33.
▲
by
mnahkies
5mo ago
My first full time job after university was using hg, and particularly https://tortoisehg.bitbucket.io/ made it really pleasant. Prior and post that I'd always used git but I'll always have a bit of a soft spot fo
34.
▲
by
mnahkies
5mo ago
They do take a cut of 5.5%, (as they should)
35.
▲
by
mnahkies
5mo ago
Yeah I think a read replica might fit the bill - though I suspect active logical replication counts as a connection in this context. Using a cloud provider read replica might not (as I think that might use block level replication) - but the
36.
▲
by
mnahkies
5mo ago
I wanted to try doing something similar to this in our dev environment (think shared dev database but per branch clones), but this limitation seemed tricky to accept: > The source database can't have any active connections during cl
37.
▲
by
mnahkies
5mo ago
I use GitHub environments to require a manual approval (which includes MFA) in GitHub, prior to a pipeline running with a oidc token capable of publishing. Would this have caught the cache poisoning? Unsure, though it at least means I'
38.
▲
by
mnahkies
5mo ago
Completely agree on the axios part - one implication of that is you can't statically type the error response shapes (since exceptions can't be typed). Where as with fetch you can have a discriminated union based on the status code
39.
▲
by
mnahkies
5mo ago
I was really surprised when this hit, and I discovered the protocol was essentially undocumented / unspecified. I was trying to find indicators of compromise and that was made more difficult by the lack of documentation. It was really
40.
▲
by
mnahkies
6mo ago
You can pool credits through open router (afaik, I'm only using a single user account), but if you top-up $10 per user, per month, any unused credits will rollover. Tbh I think it still works, but only because the new allowance will li
41.
▲
by
mnahkies
6mo ago
My paper white is about 7/8 years old, and is still holding up fine though the battery is noticeably degraded - charging it approximately once a week now. I was also having a play with a demo model of the latest one in a store and the
42.
▲
by
mnahkies
6mo ago
Aside from data consistency issues mentioned, you can also quickly get yourself into connection pool exhaustion issues, where concurrent requests have already obtained a transaction but are asking for another accidentally, then all stall ho
43.
▲
by
mnahkies
7mo ago
I don't disagree, but I think there is a distinction between "everything is e2ee, but specific conversations may be MiTM without detection" and "nothing is e2ee and can be retrospectively inspected at will" that goe
44.
▲
by
mnahkies
7mo ago
I like to follow conventional commit style, and some repos I work on have CI checks for it. It's been fixed now, but for a long time the validator we were using would reject commits that included long urls in the body (for exceeding th
45.
▲
by
mnahkies
7mo ago
Personally I'm using haproxy for this purpose, with Lego to generate wildcard SSL certs using DNS validation on a public domain, then running coredns configured in the tailnet DNS resolvers to serve A records for internal names on a su
46.
▲
by
mnahkies
8mo ago
> I used to throw every scrap of code onto GitHub in the vague hope of “sharing knowledge” I looked at a random repo today, and used some of its (MIT licensed) code as a starting point. It was an expo plugin for managing android key stor
47.
▲
by
mnahkies
8mo ago
We've only raised a handful of support cases with GCP the past 5 years, but we happened to raise one this week and they've put us onto a preview feature that solves the problem we were facing - I'm suddenly wondering if we sh
48.
▲
by
mnahkies
8mo ago
Heh, that's my PR. Initially I thought it would be a trivial change, but then I realized I hadn't considered how it should interact with MDM / device posture functionality - these aren't features I'm personally usin
49.
▲
by
mnahkies
8mo ago
I think the interface breaking on newer screens is a key point - AOE2 definite edition looks great on a 4k screen now, but when I tried one of the other variants beforehand the UI didn't scale properly and so all the elements were tiny
50.
▲
by
mnahkies
8mo ago
I had a similar idea as a teenager - calculate md5 hash and store that plus a hint/offset to then brute force the original content. I had dial up and wanted a more practical way to get large files. Anyway I emailed the Winrar developer
51.
▲
by
mnahkies
8mo ago
The licence terms / variation on MIT is interesting - unless this file is part of some standard I'm unaware of I'd expect it still shows as plain MIT for most automated SBOM collection/licence checks which feels problema
52.
▲
by
mnahkies
8mo ago
One of the more annoying things I've found moving country is the unavailability of keyboards / laptops with the layout I grew up with. I find it especially annoying as the country I'm from uses a US layout which I naively ass
53.
▲
by
mnahkies
9mo ago
Something that struck me earlier this week was when profiling certain workloads, I'd really like a flame graph that included wall time waiting on IO, be it a database call, filesystem or other RPC. For example, our integration test sui
54.
▲
by
mnahkies
9mo ago
I use a fairly niche provider ( https://go-acme.github.io/lego/dns/zonomi/index.html ) and it's supported - I'd go further and say they support most providers
55.
▲
by
mnahkies
10mo ago
I was going to make the same observation - typically this will be defined in your secure development policy or similar, and be part of your ISMS controls for whatever frameworks you're aligning to. It's possible this is more relev
56.
▲
by
mnahkies
10mo ago
I felt unsure whether to include that particular comment, but landed on including because I think it's a real danger. I've got no problem with people using AI and do use it for some things myself. However I don't think you sh
57.
▲
by
mnahkies
10mo ago
We do have both a span id and trace id - but I personally find this more cumbersome over filtering on a user id. YMMV if you're interested in a single trace then you'd filter for that, but I find you often also care what happened
58.
▲
by
mnahkies
10mo ago
That was difficult to read, smelt very AI assisted though the message was worthwhile, it could've been shorter and more to the point. A few things I've been thinking about recently: - we have authentication everywhere in our stack
59.
▲
by
mnahkies
10mo ago
I'd consider myself pretty familiar with postgres partitioning, and even worked with systems that emulated partitioning through complex dynamic SQL through stored procs before it was supported natively. But TIL, I didn't realize y
60.
▲
by
mnahkies
10mo ago
My understanding of the issue is that even if you don't use server components, you're still vulnerable. Unless you're running a static html export - eg: not running the nextjs server, but serving through nginx or similar
More ›