HNHacker News
TopNewBestAskShowJobs

0rzech

188 karma · joined October 18, 2022

submissionscomments
0rzech··on Malicious Rust crate Arrayref runs a build-time payload
There are more differences.

Packages can release updates arbitrarily, while standard libraries tend to have longer release cadences.

It's also more difficult to put arbitrary code into an stdlib, because stdlibs are scrutinized better.

Also, it's harder for some random anonymous developer to gain push access to stdlib repository.

One of the reasons so much Rust code is in libraries is not because there are no people to write it (duh), but because putting these in std commits maintainers to keeping backwards compatibility and slows down included package's release cycle.

0rzech··on Malicious Rust crate Arrayref runs a build-time payload
They won't, but the less attack vectors, the better.
0rzech··on Malicious Rust crate Arrayref runs a build-time payload
Is Rust ecosystem really that much better, if at all? This is a genuine question.

You can't disable build.rs, Rust Analyzer executes proc macros as soon as you open the project (and it needs to execute them in order assist the developer), minimum days since release has not yet made it into stable (though luckily it is planned for 1.100), and the number of project dependencies goes easily into several hundreds (still better than npm's few thousands, though, and I know that some deps are from Cargo workspaces), and on top of that, lots of packages stick to 0.x version for years.

Personally I see Rust community's packaging and security culture more akin to that of JS than to Java et al.

0rzech··on Malicious Rust crate Arrayref runs a build-time payload
It absolutely is a culture thing. I've seen many threads asking about backend frameworks in Go, and every time there were lots of answers akin to "screw framework dependencies, stdlib is more than enough".
0rzech··on Flutter 3.47
This is not true on many levels:

  * Most of the team stayed at the company.
  * The layoffs hit mostly DevOps and infra people in Flutter team.
  * At least part of the laid off roles were moved offshore to Germany, India etc.
0rzech··on Flutter 3.47
I started with https://pub.dev/packages/flutter_bloc and then migrated to https://pub.dev/packages/state_beacon for my app, and so far I've settled on it. But when I publish libs to pub.dev, I stick to built-in SDK stuff.
0rzech··on Flutter 3.47
The fact is, more and more companies are actually picking Flutter. :) Sony praises Flutter on embedded. LG has added extension to allow Flutter apps on its WebOS. Toyota is developing a Flutter game engine, which is already used in some of its cars.
0rzech··on Flutter 3.47
Correct. At the cost of using more RAM, of course.
0rzech··on Flutter 3.47
Completely opposite experience for me.

I love working with Dart (which IMO is _not_ "worst parts of Java and Javascript (...) turned (...) into a language", "Terrible to write, terrible to read, terrible to use" - quite the opposite, actually) and its toolchain, including Flutter.

I find the architecture simple to follow, no need for "either print apps as fast as possible or to emulate some Clean Code like behavior", though I do think some people use overcomplicated state management solutions. But nobody forces anybody to do that.

My experience with Web has been fine so far and I've seen fully cross platform Flutter apps working absolutely fine on mobile, desktop and web.

This is not to gaslight your experience, YMMV after all.

And React Native, with its dependency hell, project rot, npm ecosystem under the hood, and transpilation with lax runtime leaking into TS, is a total no-go for me. Though I base this opinion partially on my experience with NodeJS, and partially on that of my friends who use RN.

Btw. Does your platform support bundling UI in addition to streaming it from the server? How large is the bundled runtime?

PS. Clicking on "see all supported platforms →" on your project's homepage gives 404 for https://docs.hypen.space/docs/adapters .

0rzech··on Flutter 3.47
While the server side is still growing and obviously not as huge as Java etc., Dart definitely is being used on the backend. For instance, https://pub.dev/ itself is written in Dart: https://github.com/dart-lang/pub-dev . :)

The language, like any other, does have some weaker parts, but in general is _very_ nice to write in - thanks to both the language itself and the toolchain built around it.

The apps compile to native binaries for production and are run in Dart VM during development. The SDK is multi purpose. You can write "scripts", you can write CLI apps, servers and with Flutter - the rest of them.

0rzech··on I regret migrating to Codeberg
We're back to square one, then. :)
0rzech··on I regret migrating to Codeberg
Oh, I didn't know that. Thanks!
0rzech··on Introducing selfie for sign-in: a new way to access your Google Account
At this point it's probably better to switch to Firefox or Brave.
0rzech··on Introducing selfie for sign-in: a new way to access your Google Account
> Your Google Account holds a lot of valuable information, from cherished photos to important emails and documents.

No, it does not. I create an account only when I'm forced to, e.g. on Google-certified Android phones, where I keep all synchronization off.

I'm eagerly waiting for official GrapheneOS phones. Pixels are a no-go for me because of the price-to-perf/quality ratio.

PS. It takes about 50 minutes to hunt down and turn off hopefully all the data grabbing features on a Samsung Android phone. Madness!

0rzech··on I regret migrating to Codeberg
Radicle uses its own P2P protocol - Gossip. Indeed, Tangled uses the same protocol as Bluesky - ATProto. https://forgefed.org, on the other hand, is based on the ActivityPub protocol, like Mastodon, PeerTube and Pixelfed.
0rzech··on I regret migrating to Codeberg
> No idea where yet; I don't want to go to Github, and I believe there were similar concerns about Gitlab, so I don't know where to go yet.

Perhaps https://radicle.dev or https://tangled.org would be fine for you?

0rzech··on I regret migrating to Codeberg
> I'll admit that their blog post [1] is more inclusive

Amongst other unwanted activities, their blog post mentions "Projects written and maintained with heavy use of LLMs". If you often chat with LLM, or ask the agent to review your changes, it's writing and maintaining the project with heavy use of LLMs too.

IMHO, this is even more restrictive and ambiguous than "projects that mostly consist of code written by "generative AI"-tools".

And what if a project is hand-written, but the tests are LLM-generated and then refactored by a human? Well, tests are part of a project, so it's bad too.

Also, while reading their blog post, I couldn't shake the feeling that they disdain niche single-person projects. Apparently they never intended to be a "dumping ground", as many people from their community now claim. But it's insulting to assume that when you share your small single-person project, you just "dump" something, as if it is some kind of trash by definition.

0rzech··on I regret migrating to Codeberg
I think your impression is right, at least judging by https://codeberg.org/ethical-foss/open-slopware .
0rzech··on I regret migrating to Codeberg
Interestingly, nothing happens in my case, even after unblocking JS on their site. I suppose it's because I do block JS by default.
0rzech··on I regret migrating to Codeberg
They warn against JavaScript being on by default and recommend using it only on trusted websites. It's a solid advice.
0rzech··on Warm Burnout: editor and terminal color scheme
Looks great aesthetically and props for the author for both the theme and its homepage!

What I look for in a theme is:

    1. Being easy on the eyes.
    2. Easy distinction between different keywords etc.
    3. Good contrast.
Unfortunately, the light version of this theme succeeded in only 1. for me (I tried it in JetBrains IDEs). The background color is great, though.

The best light theme I've seen so far is Selenized for VSCodium [1] and for VS Code [2]. There's a Selenized light for JetBrains IDEs too. [3]

[1] https://open-vsx.org/extension/santoso-wijaya/helios-selene

[2] https://marketplace.visualstudio.com/items?itemName=santoso-...

[3] https://plugins.jetbrains.com/plugin/23800-selenized-theme

0rzech··on Zed 1.0
Congrats on the 1.0 release to the team!

I tried Zed once, but unfortunately had to give up because of:

    - constant CPU usage when idle,
    - blurry fonts,
    - low-contrast light themes.
0rzech··on The 1944 Warsaw Uprising, in Color
We can only guess if it would mean war or not, but it looks like Churchill assumed it would, given he tried to campaign for taking Poland from USSR by force. I know that not only Poland was sold.

It was a horrible betrayal in both how it was done and in its outcomes. Embargoing those countries by the West, which the same West has sold to Stalin in the first place, was just a cherry on top.

0rzech··on The 1944 Warsaw Uprising, in Color
Yes, that was awful. Not to mention pushing Poland into Eastern Bloc and then putting embargoes on it.
0rzech··on The 1944 Warsaw Uprising, in Color
There was a version which considered leaving 15%-20% of the Polish population to be slaves, but "In 1941, the German leadership decided to destroy the Polish nation completely, and in 15–20 years the Polish state under German occupation was to be fully cleared of any ethnic Poles and settled by German colonists.[16]: 32 A majority of them, now deprived of their leaders and most of their intelligentsia (through mass murder, destruction of culture, banning education above the absolutely basic level, and kidnapping of children for Germanization), would have to be deported to regions in the East and scattered over as wide an area of Western Siberia as possible. According to the plan, this would result in their assimilation by the local populations, which would cause the Poles to vanish as a nation.[46]"

https://en.wikipedia.org/wiki/Generalplan_Ost#Poland

0rzech··on DeepSeek v4
Nowhere in my comment have I cheered "the downfall of the west" or whatever. Don't put words in my mouth.

I was and am strictly addressing your defence of being arrogant.

0rzech··on The 1944 Warsaw Uprising, in Color
And the parent comment has been flagged to death until now. What for?

Muzeum Powstania Warszawskiego [1] indeed makes an exceptional work of walking people through the dramatic story of the Warsaw Uprising.

[1] https://www.1944.pl/en

0rzech··on The 1944 Warsaw Uprising, in Color
> though Polish people are anti-Chinese for religious and communism (maybe also religious) reasons

Where did you get that from?

0rzech··on The 1944 Warsaw Uprising, in Color
A story of Witold Pilecki [1] would be more than enough.

[1] https://en.wikipedia.org/wiki/Witold_Pilecki

0rzech··on DeepSeek v4
Q.E.D. :)
Page 1 of 5Next →