Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mrmr1993
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
mrmr1993
4y ago
I think this may have been this issue[0], which was fixed in [1]. Seems like the limit has crept up from 3 to 25 at some point in the last decade-ish, but in theory it should be undoable with 25X (or by mashing X to undo as many x commands
2.
▲
by
mrmr1993
4y ago
Indeed, that is what they decided. However, I still find the interpretation very surprising. The GDPR reads as if its authors had a different understanding. For example, the 'data minimisation' principle indicates that you should
3.
▲
by
mrmr1993
4y ago
The UK's ICO took a different stance[0] when the Washington Post tried to do this a few years back. For companies that want to do business in the UK, it probably makes sense to follow that more conservative decision. The decision that
4.
▲
by
mrmr1993
6y ago
Where possible, I prefer making the syntax opt-in, and explicitly so. For example, stealing OCaml's syntax: let check_exp (g : Elliptic_curve_pt.t) (x : int) (y : int) = let xy = x * y in let open Elliptic_curve_pt.Num_syntax in
5.
▲
by
mrmr1993
6y ago
I think that exceptions are a problem and cause this developer burden only because they are invisible. If they appeared in the type signature, for example as () -[DatabaseReadError]-> () then they would be part of a function's '
6.
▲
by
mrmr1993
6y ago
It doesn't always make sense to plan the types ahead of time; letting the compiler do the work while you code and then creating a nice interface after is a reasonable way to work.
7.
▲
by
mrmr1993
6y ago
> Potentially dumb question here, but would it be generally possible to create a permissions system for browser extensions that can distinguish between an extension that is actually sending information based on sensitive sources like pag
8.
▲
by
mrmr1993
6y ago
> Just because someone once committed a broken build, doesn’t mean I’ll never again trust them with access. I don't think this analogy is useful. An error in execution can be quite different in an error in judgement. To offer an alt
9.
▲
by
mrmr1993
6y ago
The current position is "sorry for breaking your trust, please trust us". It's hard to find it compelling. > Given the prevalence of comments like this, I wonder why any company would ever bother offering an apology or ret
10.
▲
by
mrmr1993
7y ago
Not a comment on the article, but it seems like the GDPR compliance overlay for securitymagazine.com isn't GDPR compliant. To quote the GDPR at (4)(11): > ‘consent’ of the data subject means any freely given, specific, informed and
11.
▲
by
mrmr1993
7y ago
> It's against Facebook's terms: > > 8. You must not use or make derivative use of Facebook icons, or use terms for Facebook features and functionality, if such use could confuse users into thinking that the reference is
12.
▲
by
mrmr1993
7y ago
> The language designer saw fit to include both. === wasn't introduced until ECMAScript 3 in 1999, originally there was only == when the language was created in '95. The accepted wisdom is to prefer the newer === in the interes
13.
▲
by
mrmr1993
7y ago
To my mind, a unit test should test a unit: something which functions independently, and which is interacted with through an abstraction layer. Type systems are good tools for clarifying and catching bugs around these abstraction layers. Ma
14.
▲
by
mrmr1993
8y ago
I would have thought that Coffeescript's optional chaining, present at least as early as v1.0 in 2010[0], would have counted as prior art. [0]: https://github.com/jashkenas/coffeescript/blob/1.0.0/li
15.
▲
by
mrmr1993
8y ago
Agreed. (Although it's (2^m) sequences, where m is the largest index of the n.)
16.
▲
by
mrmr1993
8y ago
> It’s going to seem incredible, almost magical, but be assured you there are no tricks involved. The trick involved is: BitSequence.find is a naïve brute-force search, but the predicates only check n bits (for some n), and laziness ensu
17.
▲
by
mrmr1993
8y ago
We would and should expect that it is be possible: unless Firefox signs configuration changes per-user, server-side (violating their privacy intentions), the whole configuration code is open source, and can easily be easily used or reverse
18.
▲
by
mrmr1993
8y ago
Yes, this leads Firefox to be fairly conservative with its permissions. In general, blocking userspace from installing extensions and otherwise running malicious code stops FF from being exploited. Blocking all of these options blocks the O
19.
▲
by
mrmr1993
8y ago
I can agree in general, but, for now, disabling a firefox --install maliciousaddon.xpi and firefox --setconfig keyyoudontwant=valueyoudontlike is enough barrier to stop a majority of bad actors. None of us want users to click yes through in
20.
▲
by
mrmr1993
8y ago
This seems to be by design: when these things are available, spyware -- especially on Windows -- will be quick to make malicious changes in all these if they can. It's a pain, but I can see the compromise. If it makes the average Firef
21.
▲
by
mrmr1993
8y ago
I've always thought the permissions model of Chrome/Firefox/Edge extensions is a bit upside-down: extensions need permissions to access data, perform actions in the browser, and modify/contact specific or arbitrary URLs,
22.
▲
by
mrmr1993
8y ago
From GDPR Article 4(1): > ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular
23.
▲
by
mrmr1993
8y ago
As a general rule, if the data can be used to identify some users, it falls under the GDPR. From Article 4(1): > ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifi
24.
▲
by
mrmr1993
8y ago
For the EU, the definition in the GDPR should cover this. From Article 4(1): > ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who ca
25.
▲
by
mrmr1993
8y ago
> But instead of working the way the languages do now, instead of constantly walking through all the layers of indirection that can be used to implement all this at every call site and for every call, what if you could do something like
26.
▲
by
mrmr1993
8y ago
My reading of it was that you need either consent or a legitimate business purpose, not both.[0] [0]: Article 6(1), https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
27.
▲
by
mrmr1993
8y ago
This is all true, but it does do something to start redressing the balance. Once we're at the stage where content creators have some of the control back, then we can start looking at reducing the stakes for non-profit content, limiti
28.
▲
by
mrmr1993
8y ago
The complexity here is that there are multiple parties involved: the copyright holder, who suspects there may have been an infringement; the uploader of the potentially infringing content; and the host, who wants as little to do with copyri
29.
▲
by
mrmr1993
8y ago
They'll be in the same situation. It might be worth shooting them an email with a link to the official policy ( https://git-scm.com/about/trademark ) to give them a heads-up.
30.
▲
by
mrmr1993
8y ago
That's essentially a historical accident. From the same email[1]: > The USPTO initially rejected our application as confusingly similar to the existing trademark on GitHub, which was filed in 2008. While one might imagine where the
More ›