Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ratorx
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
121.
▲
by
ratorx
2y ago
It doesn’t, quoting strings does solve almost all issues, but it does leave potential footguns for the future. If you don’t enforce it, in the future the “subset of YAML” property might get weaker, especially if someone else is modifying th
122.
▲
by
ratorx
2y ago
Whilst YAML is an option, if the choice is between having the unnecessary extra features of JSON5 or YAML, JSON5 seems like the clear winner. Allowing multiple types of quotes may be an unnecessary feature but it is a clear lesser evil comp
123.
▲
by
ratorx
2y ago
Right, but they are not the official defaults. If you are changing the official defaults, then you might as well do it in a more principled way. If you are going to need to optimise with performance metrics anyway, then why not stick to jus
124.
▲
by
ratorx
2y ago
I think it would be really useful to have a “Why Not?” section for each option as well. Some of these feel like tradeoffs and setting them blindly without understanding the downsides seems incorrect.
125.
▲
by
ratorx
2y ago
> 100% agree I don’t think it’s necessary to agree completely. You could start by codifying a minimal set of things that the majority of people agree on (user data sanitisation, authentication handling etc) and then build on it over time
126.
▲
by
ratorx
2y ago
Well, I can see how someone would naively think that was true, because only a fixed set of events have already happened in the past, so there is a correct answer. I think it also stems from the way it is taught in schools, where there is a
127.
▲
by
ratorx
2y ago
Not exactly. A private repo is entirely private. You might have an open source project which has some deployment secrets etc that you want to check in to git. All the code and config is perfectly safe to expose to the internet, but you want
128.
▲
by
ratorx
2y ago
> don’t see the use case for first encrypting and then giving the key to the forge You might only want to keep the files secret from the broader internet, rather than a (trusted) forge, which can make the unencrypted secrets available vi
129.
▲
by
ratorx
2y ago
How would you validate whether a certificate was signed by a registrar or not? If the answer is to walk down the DNS tree, then you have basically arrived at DNSSEC/DANE. However I don’t know enough about it to say why it is not more w
130.
▲
by
ratorx
2y ago
Ah, I forgot about that and never really considered it because GPG is so annoying to use, but it is fairly reasonable. I don’t see how it has too many advantages (for the internet) over creating your own CA. If you have a mutually trusted g
131.
▲
by
ratorx
2y ago
> if I want to host a website … The fundamental problem is a question of trust. There’s three ways: * Well known validation authority (the public TLS model) * TOFU (the default SSH model) * Pre-distribute your public keys (the self-signe
132.
▲
by
ratorx
2y ago
Definitely, there is a lot of iterative design as well - but in my experience usually when changing an existing system rather than building a new one, which is what system design focuses on. I agree about the continuum of projects as well,
133.
▲
by
ratorx
2y ago
I think the context is important in the question. I’d argue that a system design question is optimally answered differently depending on the size of the company and the scope of the internal tech stack. Doing more of the design up front is
134.
▲
by
ratorx
2y ago
> collaboration requires trust and common cause Much more fundamentally collaboration requires communication. In a hierarchy, a manager is a fan-in/out point. It is essential that a manager knows what their team members are doing to
135.
▲
by
ratorx
2y ago
I’m not sure if it exists, but it definitely seems doable (a regular debugger has to map instructions to lines of code). If the browser starts treating JS as assembly, then there would probably be a greater onus for features like this.
136.
▲
by
ratorx
2y ago
This is mostly a solved problem in regular compilers, and sourcemaps etc do currently exist for JS. I agree that the tooling/UI around this could be better, but by focusing on this approach, things like Typescript get better as well.
137.
▲
by
ratorx
2y ago
I think explicitly stating what it doesn’t guarantee is the right thing to do. Otherwise, the API becomes tied to your implementation through implicit details, which can prevent future generic performance improvements (e.g. unordered_map po
138.
▲
by
ratorx
2y ago
How does this have any relevance to my comment?
139.
▲
by
ratorx
2y ago
Contributing to an open standard seems to be the opposite of the classic example. Assume that change X for the web is positive overall. Currently Google’s strategy is to implement in Chrome and collect data on usefulness, then propose a sta
140.
▲
by
ratorx
2y ago
This is making a pretty big assumption that the web is perfectly fine the way it is and never needs to change. In reality, there are perfectly valid reasons that motivate QUIC and HTTP/2 and I don’t think there is a reasonable argument
141.
▲
by
ratorx
2y ago
Having read through that thread, most of the (top) comments are somewhat related to the lacking performance of the UDP/QUIC stack and thoughts on the meaningfulness of the speeds in the test. There is a single comment suggesting HTTP&#
142.
▲
by
ratorx
2y ago
It depends on whether it’s meaningfully slower. QUIC is pretty optimized for standard web traffic, and more specifically for high-latency networks. Most websites also don’t send enough data for throughput to be a significant issue. I’m not
143.
▲
by
ratorx
2y ago
If you only want first-party, you can presumably implement the spec yourself and do whatever you want with the data? My example was only to point out that there exist self-hostable passkey providers.
144.
▲
by
ratorx
2y ago
Can you not just set up a new passkey using a different provider (eg. Bitwarden)? It is a bit inconvenient, since it has to be done manually for every site.
145.
▲
by
ratorx
2y ago
AFAIK, you can register your passkeys using your own provider (eg. Bitwarden). I’ve not personally used it too much, but the option is there. The remaining issue is moving the credentials between providers, which is an annoying limitation.
146.
▲
by
ratorx
2y ago
I think retries are sketchy. Sometimes they really are necessary, but sometimes the API can be designed around at-most-once semantics. Even with a retry scheme, unless you are willing to retry indefinitely, there is always the problem of mi
147.
▲
by
ratorx
2y ago
Re: logging URLS In my example, the URLs are not the issue. What I was trying to say, which you actually ended up agreeing with is that they would have to publish the changes that allowed talking to the internal protocol. All I added to tha
148.
▲
by
ratorx
2y ago
Well, it doesn’t matter as much for GPL because there are no requirements over the network, which means no requirements for SaaS (which is exactly what AGPL addresses). And also, software distribution is different. Typically, you don’t bund
149.
▲
by
ratorx
2y ago
I think this is the most privacy-friendly and reasonable approach. However, as a devil’s advocate, this is still pretty fingerprintable. “Most users load n pages with ankles, the likelihood of a user only loading a single page with ankles i
150.
▲
by
ratorx
2y ago
> not great for the re-seller If the AGPL is exactly as you say, I don’t see why this would be a problem for a re-seller. For a pure re-seller I don’t think the value add is provided by modifying the software. E.g. take the example that
More ›