Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
steventhedev
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
steventhedev
2y ago
This is a really good demonstration of the curse of dimensionality[0] [0]: https://en.m.wikipedia.org/wiki/Curse_of_dimensionality
32.
▲
by
steventhedev
2y ago
You are writing this as if security was a newly invented thing. Having done systems level security development for 12 years, anything that can be produced maliciously will be. By using JSON, you've invented a new vulnerability class fo
33.
▲
by
steventhedev
2y ago
The danger I see is that JSON has lots of edge behavior around deserialization, and some languages will deserialize a 100 digit number differently. If the main benefit is removing the broker and the need for rate limiting - it could have be
34.
▲
by
steventhedev
2y ago
I should probably just write it up into a post, but the git mailing list at the time is the source (I remember reading it from the side a few months after convincing our VP R&D to switch from svn to git). We were chuckling around the sa
35.
▲
by
steventhedev
2y ago
I'm gonna disagree with you there. The difference was with stat patterns, and the person at Facebook who ran the tests had something wrong with the disk setup that was causing it to run slowly. They ignored multiple responses that repr
36.
▲
by
steventhedev
2y ago
I can imagine the EU is far more interested in an EU flagged company doing business with Hezbollah who are a designated terrorist organization and subject to sanctions. If there's one thing you learn quick in fintech - it's you ab
37.
▲
by
steventhedev
2y ago
Please note that this is distinct from yesterday's incident - these are for a different set of communication devices - from what I can see, they went off at 16:58 local time - notably 2 minutes prior to Nasrallah's planned speech
38.
▲
by
steventhedev
2y ago
Doesn't matter. Hezbollah are subject to sanctions by the EU as a designated terrorist organization. Presumably, that applies to all companies operating within the EU. Sanctions violations are very much a "do not pass go" sty
39.
▲
by
steventhedev
2y ago
Having done nearly 100 technical interviews (with multiple questions each), the bug squash question gave us the biggest signal on candidates. Our question was far simpler: it was a simple class (java + python variants, no fancy syntax) and
40.
▲
Git-PR: patch requests over SSH
(pr.pico.sh)
209 points
by
steventhedev
2y ago
|
103 comments
41.
▲
by
steventhedev
2y ago
They were only granted that gTLD because in their application they explicitly said they would never allow GA registrations. Google did extreme evil with .dev, with the blessing of ICANN.
42.
▲
by
steventhedev
2y ago
> This long-term investment that began on the mobile-first foundations of the Android Open Source Project has produced a full mixed reality operating system used by millions of people. Which gives some context to the calls for Google to
43.
▲
by
steventhedev
3y ago
There are a few key things that you get by targeting a terminal for your UI: * Remote desktop forwarding through tmux, ssh, mosh, etc * Instrumentation of your UI - simply replay the input * Screen recording with asciinema Not to mention th
44.
▲
by
steventhedev
3y ago
Yet another study comparing handwriting with one handed typing. Actually worse than that - they didn't even display the letters typed. Even if that were somehow ok, they should have seen greater visual engagement for hunt and peck one
45.
▲
by
steventhedev
4y ago
Keepassxc and syncthing. I sync two databases across Mac, linux, ipads, and android phones. One for work, one for personal.
46.
▲
by
steventhedev
4y ago
The invasion was in response to Confederate attacks on Union forts - starting with Fort Sumter. Saying the civil war is not about slavery because the invasion was about responding to Confederate belligerence is like saying that someone who
47.
▲
by
steventhedev
4y ago
100% about slavery (from the mouth of the southern states themselves): https://www.battlefields.org/learn/primary-sources/declarati... That was just the first result from searching for "letters of secession&q
48.
▲
by
steventhedev
4y ago
At an old job I spent my first week on the job documenting the process from a wiki page into a bash script (albeit with some comment sections that said "do this manually"). A year later, one of our devs was up for a laptop upgrade
49.
▲
Identity Crisis: Sequence vs. UUID as Primary Key
(brandur.org)
6 points
by
steventhedev
4y ago
|
0 comments
50.
▲
by
steventhedev
4y ago
These content filtering schemes are usually legally mandated, and the age of 18 is set by law. More likely than not, this got caught up in a regular job that scans DNS zones for new domains to "filter". It's just a matter of
51.
▲
by
steventhedev
5y ago
brotli on the raw word list gives 17194 bytes. gzip gives 32352. A lot can be done in 3014 bytes, but what's the difference in code size for the ascii trie vs. a flat list/gzip/brotli?
52.
▲
by
steventhedev
5y ago
The fact that it broke anything for anyone is a strong argument that it never should have been created in the first place, alongside .home and .corp. They were aware of the issue, buried it in the report and reneged on their promise to keep
53.
▲
by
steventhedev
5y ago
Git is split into two parts: the plumbing, and the porcelain. It's a toilet metaphor. You don't directly work with the plumbing unless you really know what you're doing.
54.
▲
by
steventhedev
5y ago
That seems to imply that LSHs are a subset of DRs. Are there LSH techniques that are not applicable to DR?
55.
▲
by
steventhedev
5y ago
It seems like this approach could be adapted as a dimensionality reduction technique: select a set of k random hyperplanes denoted p_i, then map each point to a new vector r such that r_i is the distance to the hyperplane p_i. My gut tells
56.
▲
by
steventhedev
5y ago
I'm sorry to hear that you got bit by the docker networking thing. It bit me twice in the past. Once with a new server and once when they changed the config format from envvars to json (we were disabling dockers iptables nonsense). Do
57.
▲
by
steventhedev
5y ago
There's an entire class of vulnerabilities caused by having separate verification and parsing logic, typically with fields that usually only one is used, but the format supports multiple. The verifier checks the first one but the parse
58.
▲
How often should you beat your kids? [pdf]
(fermatslibrary.com)
3 points
by
steventhedev
5y ago
|
0 comments
59.
▲
by
steventhedev
6y ago
It's sad the difference between expiry and eviction isn't explored more fully. There are plenty of posts describing cache eviction strategies that barely touch on expiry issues, and a handful of posts about cache expiry that barel
60.
▲
by
steventhedev
6y ago
With containers, both the kernel and the hypervisor are shared. With vms, only the hypervisor is shared. It's a matter of having a smaller attack surface. There are plenty of container images that run with root access by default, which
More ›