Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
seldo
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
seldo
12y ago
They're not necessarily a bad candidate, but I have a lot of resumes to scan and this metric works most of the time. I'm okay with getting it wrong sometimes. I didn't intend this to be taken as a personal affront to people
62.
▲
by
seldo
12y ago
Like I said, I ignore Facebook for hiring purposes because I think the context is different. You're not expecting me to go looking at it, so I don't.
63.
▲
by
seldo
12y ago
I'm not a lawyer, but as I understand the situation it's illegal to take certain types of information into account when making hiring decisions (e.g. race, gender, religion I think, sexuality in some states, etc.). It's not i
64.
▲
by
seldo
12y ago
As a hiring manager, I expect candidates to have a LinkedIn profile that is up to date. A LinkedIn profile is a public copy of your resume; other people can see it and flag if you make inaccurate claims. I can also see how you're conne
65.
▲
by
seldo
13y ago
Can somebody more familiar with Cisco products look at the list and break this down a bit? Are these mostly edge-of-network devices, or are these big switches that tons of traffic run through? Does being vulnerable to Heartbleed necessarily
66.
▲
by
seldo
13y ago
http://blog.awe.sm/2012/12/18/aws-the-good-the-bad-and-the-u... TLDR: it's okay for backups, but in critical path it's a world of sadness. Failure modes are too painful.
67.
▲
by
seldo
13y ago
DO's "internal" networking/security group support is still immature. I use DO for personal stuff, but at work we use AWS. Just never EBS. Ever.
68.
▲
by
seldo
13y ago
Update: I was in fact incorrect about the severity of the rubygems.org incident; their issue was a disclosure without a breach, exactly like ours. I've updated the original post and also issued a correction: http://blog.npmj
69.
▲
by
seldo
13y ago
The original abandoning of the self-signed cert was because self-signed certs were a bad idea. The issue that post refers to (it is a little unclear, because we ourselves were a little unclear what had gone wrong at that point) is when we b
70.
▲
by
seldo
13y ago
It turns out we were incorrect about the scope of the Rubygems incident, and have issued a correction: http://blog.npmjs.org/post/80307645782/correction-to-previou...
71.
▲
by
seldo
13y ago
I'm sorry you took it that way. The scope of our security hole was exactly as big as the Rubygems vulnerability. If I'd omitted that comparison, I was sure somebody would say "these guys were just as bad as ruby but they'
72.
▲
by
seldo
13y ago
As a point of honor, I feel obligated to mention that @rockbot and I are very aware of these hazards, but our website was put together in somebody's spare time when Node had like 100 users in total :-)
73.
▲
by
seldo
13y ago
That was certainly the intention.
74.
▲
by
seldo
13y ago
We told them as soon as we found out, because we needed them to go looking for the same hole in all of our code bases :-) As part of the audit, ^Lift audited a lot of the third-party modules we use, and notified the authors of those package
75.
▲
by
seldo
13y ago
npm, Inc. - Oakland, CA We run The npm Registry and are the stewards of the open-source npm client and related open-source projects. We want to make Node.js awesome for everybody. You may have heard of us, particularly yesterday, when we br
76.
▲
by
seldo
13y ago
That is pretty much exactly correct.
77.
▲
by
seldo
13y ago
Any npm downloaded after ~August of 2012, which is when the GlobalSign CA was added to the client: https://github.com/npm/npmconf/commit/d7ef61c8d9ae87f39482c5... I believe we considered adding the npmCA and
78.
▲
by
seldo
13y ago
Correct. It is a GlobalSign cert that was donated to the Node.js project. Once we became a company we had to stop using it, both from an abundance of caution, security wise, since we were not the only ones who had the cert, but also because
79.
▲
by
seldo
13y ago
That's not correct. The latest npm (and any npm configured with ca="") will use the CA baked into your operating system's version of OpenSSL. Our old cert, from GlobalSign, works just fine with OpenSSL.
80.
▲
by
seldo
13y ago
I know you don't know me, but if you ever meet anyone who does, you can ask them about my personal attitude towards censorship of any kind. The idea that I would stoop to censorship for something as petty as somebody voicing legitimate
81.
▲
by
seldo
13y ago
Hi! As I said in the comment's on Rob's own post: we didn't censor any comments. We did no moderation of any kind on any comments today; we were way too busy trying to fix the problem. I don't know what happened to Rob&#
82.
▲
by
seldo
13y ago
Hi! CTO of npm here. I haven't been reading HN today because we were trying to fix the SSL thing, so I was genuinely taken aback to see this article. We didn't censor any comments; we did no moderation of any kind today. I have no
83.
▲
More help with SELF_SIGNED_CERT_IN_CHAIN and npm
(blog.npmjs.org)
29 points
by
seldo
13y ago
|
9 comments
84.
▲
by
seldo
13y ago
Since you asked: I have never tried Erlang because I've heard it's like Haskell but harder to learn, and Haskell already breaks my feeble mind, so I have steered clear. This may or may not be an accurate picture, but it was my dec
85.
▲
by
seldo
13y ago
Agreed. On the front-end, module loaders eventually come in handy but their utility isn't immediately useful. If an "anti-pattern" is something that seems useful but eventually isn't, and a "pattern" is somethi
86.
▲
by
seldo
13y ago
I appreciate your paranoia :-) We are wary of announcing all the stuff we're planning given that we don't know how long it will take to build yet and don't want to be accused of vaporware. However, we are planning to announce
87.
▲
by
seldo
13y ago
It's not accurate to say that Fastly is hosting the registry; Fastly are providing CDN services to our registry -- a globally distributed cache -- for which we're very grateful. As of five days ago ( http://blog.npmjs.o
88.
▲
by
seldo
13y ago
> If you get sick and can't work, is the health care system supposed to pay your mortgage too? In lots of countries, if you get too sick to work, the government will assist you in paying for housing. In lots of countries, they
89.
▲
by
seldo
13y ago
No added value, just haven't got around to implementing anything cleverer, yet. There is an open issue: https://github.com/npm/npm-www/issues/569 Feel free to chime in if you have a suggestion or even su
90.
▲
Dear HN: please use "flag" more often
7 points
by
seldo
13y ago
|
3 comments
More ›