9,726 karma · joined June 23, 2018
<first letter of my company name> at 9dev.de
[ my public key: https://keybase.io/radiergummi; my proof: https://keybase.io/radiergummi/sigs/_bPlsZ-Tii8Qag-Ne5n2bNSqVB8CDqke1kLgzTytb-s ]
The sprawling code comments are becoming the most draining part of code review though, that's really killing me from the inside.
Sort of like a person with an amazing taste in fashion, dressing shoddily - but in such a camp way, it's very obviously purposeful in its shoddiness, making it a fashion statement again.
...but yeah, I stumbled across that sentence too.
It’s rather that I think we all ought to stop making software that is primarily useful to businesses, because there is no more joy in that with AI-written PRs driving maintainers into burnout. Big tech finally has no more excuses as to why they don’t maintain all the bedrock libraries themselves. So I say, let them do that.
And on the other hand, since anyone can vibe code something now, the value of GitHub projects as CV material has gone down significantly, so I’d expect less people to do that. Good! Open Source as a community, as a movement, doesn’t need these people.
Let’s get back to the roots.
There is no compliance officer required by law, at least not in any regulation introduced by the EU.
> The lower thresholds applies from 250 employees. I still have the same obligations as larger companies!
If you have more than 250 employees, you really should have both a higher salary than a garbage man and be able to afford someone to take care of your compliance duties.
> You expect me to do stuff for free. Or can I demand extra money to match minimal salary on my tax return?
I don't expect anything. You run a business. Anything you do related to that business is your own working time, just as anything I do in regard to compliance or data protection is of course billed working time. You file your taxes in your working time, you pay your bills in your working time, and of course you also read up on laws you need to comply to in your working time. Those are table stakes for doing business everywhere. Do you think American companies don't have to comply to regulations?
> Because I have social responsibility to make some rare stuff available, as you would put it!
All props to you for making that choice, then, but it's still your decision to have a company and that means you have to abide the law.
> But EU is not making it any easier!
The EU is responsible for so many things you just take for granted: A single market larger than the USA with a single currency; hundreds of EU-funded programs for small businesses with grants available easily; common standards across the entire union; protection from foreign traders; cross-border regulation and mobility; even things like funding for public infrastructure, art, and education all around you that you don't know of, because you never cared to look.
Just because you have a responsibility to think about and extra work to enable handling data your customers entrust you with carefully doesn't invalidate all of these efforts.
> So at end I should hope for the best right and relly on merci? My gov just loves to skull fuck "capitalists"!
You should try to think about protecting the personal data you handle responsibly and be ready to demonstrate that when somebody asks. Again, I am in the same spot and have been for years. This is doable.
You don’t need a dedicated data protection officer, because your company is too small for that. You also don’t have to abide by lots of regulations that only apply to bigger businesses. But you still need to comply with the basic requirements, and that is your job as a business owner. I know what I am talking about, because this is part of my job. So unpaid doesn’t really match the reality here, right? Or do you consider filing your taxes as unpaid regulatory bullshit work too?
> Keep on mind I get lower salary than garbage man!
It doesn’t sound like your business is very worthwhile of keeping up, then? I don’t say this in spite, but if you don’t have a reasonably good income from your company, why do you put up with all the hassle in the first place..?
> I do not "store data",.
Sure you do, if you sell anything. You need to know where to ship stuff, customers contact you, pay you, all that. And as your customer, I don’t want you to store that longer than necessary or sell it to someone else.
I know this sounds all lofty and Brussels ivory-tower-ish, but I'm absolutely convinced it's the only sensible way to deal with personal information - even if American companies insist on forcing a new normal of lacking privacy on all of us.
You also have to keep up with other regulations; that’s the price of doing business. And the churn you’re talking about is way less than you make it to be; it’s not like there is change every month.
We never even once got fined, because we try our best to only store data we need, not track users, and secure the data we have to store as well as we can.
If you indeed do end up with authorities auditing your business, they absolutely value if you’ve tried your best as opposed to not caring at all; I’ve seen that multiple times with friends in various places .
In contrast, the GDPR demands that you properly ask for consent if you want to process somebody's personal information, inform them why that is necessary, and only process the data if they agree to the processing.
There is clearly a difference here, and IMHO the EU is quite correct here.
Then you can let it run, and when it stops, point a fresh session to the ledger to pick up the work from where the previous one left off.
You can get more fancy by using something like GitHub issues for coordination too and have multiple sessions create issues and epics and others to work on that in isolated worktrees, but the spec-plan-ledger approach usually works great for small to medium large projects.
That is also the core problem for reestablishing trust with the rest of the world: Even if a Democrat or just a sane Republican wins in 28 and tries to revert many of the destructive policies the current administration enacted, there is now solid evidence the much-hailed system of checks and balances doesn’t work as advertised. And that means there is not really a legitimate argument to trust the US as much as countries and businesses did, which calls a lot of things into question—the bond market, the petrodollar, investments in the USA, dependency on American services…
On the flip side, I'd argue that the current centralisation of user agents (in the classical sense here) that benefit from programmatic content negotiation in form of a handful of harnesses like Claude or Codex is a great lever toward forcing the ecosystem to adopt better practices: If Anthropic added content negotiation as described in this thread to Claude, many sites would be incentivised to improve their web servers.
I am well aware that few sites are taking that much care of their API in terms of HTTP features, but all of the problems discussed here have solid and battle-tested answers.
Link: /some-page rel="canonical"
Link: /some-page.json rel="alternate" type="application/json"
Link: /some-page.html rel="alternate" type="text/html"
Link: /some-page.md rel="alternate" type="text/markdown"I take the point that it makes caching harder, but I don’t think that should overrule ergonomics concerns.
It's really pretty cool.