Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ris
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
17 ms
·
181.
▲
by
ris
4y ago
> No privileges, no special installation It still has way, way more privileges than a webapp. And arguably, if you have all your valuable information in a single user account, it has the crown jewels already, no admin needed.
182.
▲
by
ris
4y ago
Don't Assume Things About Others Use Cases. In cases where I'm doing some sort of interactive or exploratory data analysis with structures of complex python objects and want to stash a copy of what I'm working with in case th
183.
▲
by
ris
4y ago
There are ways of writing that make one look less like a paranoid conspiracy theorist.
184.
▲
by
ris
4y ago
Was going to post this. "Sharding" seems like a better term for communicating the idea.
185.
▲
by
ris
4y ago
This is everything that's wrong with web development frameworks in the last 5-10 years. Everything's optimized for the seductive "get started in 5 minutes", one file example, and people spend the next 5 years trying to w
186.
▲
by
ris
4y ago
It's particularly fun for them to introduce this in a point release. If this didn't warrant a major version bump I'm frankly not sure what would.
187.
▲
by
ris
4y ago
They more or less can, but people like the physical gear for the "feels" (see also: vintage guitars and valve amps). It's increasingly absurd given that more and more synth modules are almost entirely digital and microcontrol
188.
▲
by
ris
4y ago
And no explanation of fixed points.
189.
▲
by
ris
4y ago
Ah the upstream "we know everything and we will control everything" provider. Who doesn't maintain stable branches with security backports for their bundled dependencies, includes mystery binary dependencies, doesn't car
190.
▲
by
ris
4y ago
As a nixpkgs maintainer I can't tell you how painful Bazel is for packagers. The difficulty of substituting dependencies. Unstable hashes of fetched dependency sources. The infeasibility of building bazel itself fully from source...
191.
▲
by
ris
4y ago
Though I'm guessing it won't get as much use now pattern matching has arrived and is a more general way of achieving the same thing.
192.
▲
by
ris
4y ago
> JavaScript which is an as-dynamic language It really is not. Python allows a huge amount of the object model to be overridden and introspected at any point. Javascript doesn't even allow operator overloading.
193.
▲
by
ris
4y ago
> There is no good reason to use an FNV function nowadays. Implementation simplicity? Sometimes you need a hash function in an environment that's not a Real Programming Language.
194.
▲
by
ris
4y ago
> chooses an imperative language to define circuit topologies hmm.. maybe that's ok if they don't go too overboard and encourage a functional style > uses & as an in-place, mutating operator that's it, I'm out
195.
▲
by
ris
4y ago
Way back when python was seen as esoteric this became known as "The Python Paradox" http://www.paulgraham.com/pypar.html
196.
▲
by
ris
4y ago
99% of things that claim to need a blockchain can do exactly the same thing with https://opentimestamps.org/ which uses an existing blockchain to do decentralized "trusted timestamping". The remaining 1% are probl
197.
▲
by
ris
4y ago
1. The High Level Language of your choice may not be the flavour liked by other members of your team. Ruby? ew please use Python - unnecessary discussion ensues... 2. Your High Level Language of choice would probably require a non-trivial c
198.
▲
by
ris
4y ago
> They don't even document how to mark something as a security issue Only committers can add those labels - it's probably best to flag it in the PR subject line and hope a committer notices it and turns it into a label. Edit: m
199.
▲
by
ris
4y ago
> Besides that, packages in nixpkgs often have known vulnerabilities for months I would be cautious not to assume the alternatives are perfect https://security-tracker.debian.org/tracker/status/release/s...
200.
▲
by
ris
4y ago
> Or something more like Ansible? If you make it more like Ansible, you will end up with ... Ansible. If you want to use Ansible you are perfectly welcome to, but as a Nix person the entire Ansible way looks like a completely wrongheaded
201.
▲
by
ris
4y ago
> And honestly, the package situation is the biggest downfall of nix(os), ... but it has a long way to go. I have a big problem with "it has a long way to go" arguments. "It has a long way to go" in comparison to what
202.
▲
by
ris
4y ago
This might be overly glib, but I suspect that anyone who has time to write up enough information about a project to be useful in a "case study" isn't close enough to the code to know what's really going on. Not to even
203.
▲
by
ris
4y ago
Pragma over "formalism". Every time. I leave the discussion when an architecture astronaut starts talking about Domain Driven Design, Data Mesh Architecture or any other pointy headed nonsense. I will listen if they can convince m
204.
▲
by
ris
4y ago
This could probably do with a (2014)
205.
▲
by
ris
4y ago
This is (partly) why I started using KDE's Kate as my editor. File access is all through a virtual io layer, which supports sftp amongst many others. And I've never switched away from it - long after that project - because it'
206.
▲
by
ris
4y ago
Except that's not how patents are used in the 21st century. Patents are generally written to be as broad in scope as possible while disclosing as little as possible information on how to get said invention to work (if the grantee has
207.
▲
by
ris
5y ago
> and other people can verify that it's doing the right thing by comparing results You're essentially describing the solution I outlined in my original post. What is the proposal in this article actually adding that's no
208.
▲
by
ris
5y ago
No I think that's a perfect example of why this doesn't work. Once you remove the build tool from the assumed-impenetrable GitHub, where are your guarantees of non-tamperability for it? How is what you have now not "just&qu
209.
▲
by
ris
5y ago
There is so much going on in the world of SBOM that seems so wrong-headed to me, and this is a good example. So much of the effort seems to be going into processes and systems that do little more than build a chain of trust back to someone
210.
▲
by
ris
5y ago
> the top comment isn't about asdf which I had hoped to learn about Oh I think you're using HN wrong. To learn about the subject you can read the actual article that's linked to. No guarantees about the comments section.
More ›