Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
szmarczak
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
szmarczak
14d ago
Please no AI slop. I don't want another app that spams my server megabytes per second because my proxy failed and the programmer didn't acknowledge the server can ever go down (talking about Immich - their retry mechanism used to
2.
▲
by
szmarczak
27d ago
Unfortunately doesn't support Vulkan decoding/encoding (ffmpeg 8 does).
3.
▲
by
szmarczak
2mo ago
I wonder if the code was written by AI?
4.
▲
by
szmarczak
2mo ago
> The development team You mean the one guy who prompts Claude?
5.
▲
by
szmarczak
3mo ago
It's another vibe coded slop
6.
▲
by
szmarczak
3mo ago
> Jarred was already writing slop well before he had access to LLMs. I don't see anything business related in that statement. What's this new level of gaslighting? "It was not because of me, but because of the business sit
7.
▲
by
szmarczak
3mo ago
This is good. However, it still sends info about the players ~200ms ahead which still makes you lose.
8.
▲
by
szmarczak
3mo ago
Why does the website render a word or two per line on mobile
9.
▲
by
szmarczak
3mo ago
> memory monitoring would be part of the application monitoring stack You don't need it if you have everything allocated upfront. TigerBeetle does this, everybody else can. Using something like Rust is already a huge win when compar
10.
▲
by
szmarczak
3mo ago
> this leads to application crashes instead Same happens if the page file is full. In that case, why don't those programs use disk directly instead? No such problem would've ever occured if programs hadn't allocated more t
11.
▲
by
szmarczak
3mo ago
> Does this result in programs more frequently erroring/crashing because they can't allocate? I run Firefox, VSCodium with LSP, Discord, Signal and there's still space left for a game like CS2. I'm not a heavy user by
12.
▲
by
szmarczak
3mo ago
Settings -> View advanced system settings -> Performance (Settings) -> Advanced -> Virtual memory (Change...) -> No paging file
13.
▲
by
szmarczak
3mo ago
I have disabled overcommit both on Windows and on Linux. I hate having random programs being killed. Unfortunately, many programs commit 2x memory than they actually use. Often I see ~32GB committed and ~16GB resident.
14.
▲
by
szmarczak
3mo ago
The wording is so ambiguous, they should've determined what's the threat first. Or else anybody could point at anybody and say "active threat". Most likely they still would've been kicked, but without being detained
15.
▲
by
szmarczak
3mo ago
Ah yes. Let me detain you for 8 hours for doing what you're legally allowed to do. Sorry for my mistake, it's all paid by the taxpayers anyway.
16.
▲
by
szmarczak
3mo ago
> They were “just doing their job,” It's always this one exact excuse. They were simply "following orders". The police don't have their own brains capable of thinking.
17.
▲
by
szmarczak
3mo ago
> claiming it's the fastest across all datasets I never claimed so. Please stop stating I said something when I didn't. > as a general purpose hash table That's what I claimed. The question IS about hash tables. If you
18.
▲
by
szmarczak
3mo ago
No. Fundamentally it's not possible to be faster.
19.
▲
by
szmarczak
4mo ago
> isn't available in all cases Which ones? Websites that ship no JavaScript? All browsers support this. > can in some cases completely break sessions Or you can just remove local storage from window and have it just for yourself,
20.
▲
by
szmarczak
4mo ago
There's color space and there's color depth. You may be using D-P3 with 8 bit, which is worse (less accurate?) than sRGB with 8 bit. And there's bandwidth. Your monitor may not be able to handle 4k 240fps 16 bit.
21.
▲
by
szmarczak
4mo ago
> There's a reason "don't use local storage for security sensitive stuff" is part of the OWASP cheatsheet Local storage was released more than 16 years ago, and back then PHP was wayy too popular. XSS is almost imposs
22.
▲
by
szmarczak
4mo ago
> XSS which local storage does not [mitigate] True. However it's not impossible to mitigate that: https://news.ycombinator.com/item?id=48563286 But arguably it's harder to do so. > this doesn't protect
23.
▲
by
szmarczak
4mo ago
> You have to mitigate CSRF server-side (with a CSRF token > when you're using tokens in JavaScript then you don't have to worry because you already have your CSRF token No reason to have a dedicated CSRF token because your
24.
▲
by
szmarczak
4mo ago
That's why I wouldn't say the below. > A lot of times local storage is much less secure Without XSS, local storage is actually more secure. You don't have worry 'did I set up this right' because there is nothing
25.
▲
by
szmarczak
4mo ago
> they tend to require disabling HttpOnly for not very good reasons First time I'm hearing that frameworks require disabling HttpOnly. > Disabling iframes doesn't fix CSRF. You can still <form method="..." /
26.
▲
by
szmarczak
4mo ago
> I've always wondered how they do it as well. See https://news.ycombinator.com/item?id=48574402 > So are they moved to a simple variable then? Yup, it has to exist somewhere .
27.
▲
by
szmarczak
4mo ago
Except you do. https://developer.mozilla.org/en-US/docs/Web/API/Window/unlo... What happens if you lose power? You're logged out because it didn't save the token back. Verified this by pau
28.
▲
by
szmarczak
4mo ago
> A lot of times local storage is much less secure than using cookies. Is it? If an attacker can't do XSS then it's as strong as cookies. Supply chain attacks aren't an argument here because they can also happen with cooki
29.
▲
by
szmarczak
4mo ago
What are you running, Android 9.0?
30.
▲
by
szmarczak
4mo ago
Have you verified what caused the crash via logcat? Firefox has never crashed in my case, not even once (but I'm not running a low ram device).
More ›