HNHacker News
TopNewBestAskShowJobs

Androider

4,272 karma · joined November 3, 2013

submissionscomments
Androider··on Intel’s Alder Lake big.little CPU design, tested: it’s a barn burner
The 12900K MSRP is $589, the AMD 5950X MSRP is $799.
Androider··on Man left shocked as his house is 'stolen'
> Once the house was sold to the new owner for £131,000 by the person impersonating Mr Hall, they legally owned it.

That's nuts. Why isn't it the case that the person who failed to properly vet the seller is out of £131,000 and the house? So I can "buy" a local mansion and then say "oops, I didn't know this random guy didn't own it. Oh well."

Androider··on Vscode.dev
Surely shoving VSCode into a tab is just step 1. Think about what this could do, that your local app couldn't.

Off the top of my head: Complete remote state. Open vscode.dev on your desktop, work for a while. Then open vscode.dev on your Macbook Air later, and be in _exactly_ the same state. I don't mean, the same project, I mean the text cursor is at the same position in the same file with the same set of tabs open.

Need a GPU for some CUDA work? The only question is how many GPU cores would you like.

Could your next engineering hire's onboarding guide be: open vscode.dev/company/workspace, click the "run all tests" button. OK, you're done, please pick the topmost "ready to start" ticket from the queue.

Androider··on What if performance advertising is just an analytics scam?
Most accurate results possible you say? https://www.latimes.com/business/story/2019-10-10/hiltzik-fa...

Long-term strategy? https://www.businessinsider.com/facebook-allowed-fraud-hacke...

Androider··on Tricks I wish I knew when I learned TypeScript
The beginner programmer copies the property definition.

The advanced programmer simply writes "type Ensure<T, K extends keyof T> = T & { [U in keyof Pick<T, K>]-?: T[U] };", thus removing the need to copy the property.

The master programmer copies the property definition.

Androider··on And you will know us by the company we keep
Personally I'd like the exact opposite. The people who post every day, I'm not really missing much if I don't see their latest posts. But the friend who posts once a year? I want to see that post, even if it's from a while ago already and I haven't logged in since.
Androider··on How did the plain green lawn become the central landscaping feature in America?
"Perfect lawns" are like plain white Wonder Bread to me. I know it's the best seller, but please just give me literally anything else.
Androider··on Git password authentication is shutting down
And they'll charge you the full seat price for it :/
Androider··on Git password authentication is shutting down
Hopefully they'll enhance the other authentication methods. I was quite surprised how complicated yet insecure the GitHub Actions and personal access token mechanisms are just last week.

GitHub Actions tokens are scoped to the single repo they operate in, so for anything that you need covering any cross-repository or org access the official docs immediately tell you to just use a PAT instead. But PATs have no repository scoping whatsoever, it's all or nothing. So although both PATs and GHA Tokens have these complex scope requests, it's completely missing the most basic use cases in my opinion, like creating a PR in repo X, allow installing a package from GitHub Packages in repo Y, check out code from repo Z etc. You either go full mono-repo for everything, or you use PATs for everything with no repository boundaries at all, yikes.

Androider··on I made a mistake with Terraform and Azure made it worse
In my opinion, databases are not cattle, and don't need to be automatically created (and destroyed!) in your main Terraform plan.

It's perfectly OK to have a completely separate Terraform project that just configures the DB initially (or even manually, I see lots of places running DB's that predate Terraform with immutable infrastructure for everything else), and applies minor non-destructive changes in the future. This way you get the benefits of IaC, but the DB plan doesn't participate with the rest of your infrastructure that IS ok to blow away and re-create at will.

BTW, Amazon RDS backups work the exact same way: Destroy the database and the backups are also destroyed. Therefore, same region automated RDS backups are fine for day-to-day, but in a true "DB goes poof" disaster you should expect that you WILL lose them too! You need cross-region, or even better, cross-account DB replication or snapshots to survive this.

Androider··on Stripe Identity
https://www.quora.com/What-programming-languages-does-Stripe...
Androider··on MDN Plus
Surprised at the focus on individual developers. That's a tough market.

Company teams where the buyer isn't also an user is the only way this is going to make any sustainable money. Sell an MDN Plus Teams and Enterprise flavors as upgrades to the free "hobby" variant, and market it as table-stakes that every valley dev team has an MDN Plus subscription, same as they have a paid GitHub account, because what kind of crappy outfit are you even running here if your devs don't have MDN Plus access day one? MSDN used to be 4-6 figures for teams of various sizes, so asking developers how much they'd be willing to pay doesn't really tell you anything, I'd be surprised if developers know what their GitHub hosting, CI, etc. is priced at.

Androider··on Stripe Payment Links
Hate to be a party pooper, but what about Sales Tax handling?
Androider··on The Tether Ponzi Scheme
TLDR: ~ 7% of Tether is in risk-free, short-term, liquid assets. The other 93% may very well be dog shit wrapped in cat shit.

Some additional good reading https://www.mymoneyblog.com/tether-stablecoin-risk.html

Androider··on Crypto crash deepens, stocks slip
A Ponzi scheme doesn't require a return. Tether is paying out existing investors with new investor's money, while skimming and investing the reserve in risky assets.

Here's a good write up of the recent disclosures and the bag of shit that is Tether's reserves: https://www.mymoneyblog.com/tether-stablecoin-risk.html

"Instead of 100% risk-free, short-term, liquid assets, Tether is less than 7% risk-free, short-term, liquid assets. Commercial paper? Backed by whom exactly? Fiduciary account? At which remote offshore bank owned by a third-party? They could be pointing to a half-eaten sandwich and calling it collateral."

Androider··on Security keys are now supported for SSH Git operations
SSH secret key file exfiltration by running "npm install" or the like is a concern, and by using YubiKeys this type of attack is eliminated.

You can also enforce usage of YubiKeys, but you can't really enforce every developer sets a passphrase on their locally generated SSH key file.

And it's a convenient, and consistent way of authentication: Your work Google Workspace account uses and enforces a YubiKey, your AWS account login uses and enforces a YubiKey, and now your GitHub account also uses (but cannot not yet be made to enforce AFAIK) a YubiKey. It's less hassle than using one-time codes with fifty-seven different apps and cloud environments, so there's not much user push back.

Androider··on Security keys are now supported for SSH Git operations
GitHub now supports ecdsa-sk and ed25519-sk type keys. OpenSSH have supported those keys since 8.2, but GitHub has not until now.

With the -sk keys, you no longer need to install any software (gnupg, pinentry, yubikey CLI etc.), or run gpg-agent which has always had reliability issues etc. It should all Just Work out of the box now. GitHub was the last piece of the puzzle for us, and for example I can now change our team's onboarding docs from "follow this long OS specific guide to setup SSH w/ gnupg and ykman" to "run ssh-keygen -t ed25519-sk".

There's some confusion in this thread, but you can use ssh-keygen to generate either a public and private key pair, with the private file being a stub and the validation still happening on your physical YubiKey, OR you can omit the private key stub entirely with "-O resident" option to ssh-keygen allowing you to add your key to your ssh agent on any machine you plug it in (for good and bad).

Androider··on Nvidia cripples cryptocurrency mining on RTX 3080 and 3070 cards
They do, the mining specific cards are more expensive / hash rate. It's just market segmentation.
Androider··on Mighty Makes Google Chrome Faster
In case you're seriously wondering, it's vastly preferably for a business to spend $10/month in opex instead of $360 amortized over 3 year in capex. That's why everything is going rental and outsourced, even the plants in your average fancy office are rented by the month.
Androider··on Mighty Makes Google Chrome Faster
This is a stop-gap before the web apps are rendered server side and streamed to the client. Not as HTML and JS, but as 4/8K 60FPS video, like Stadia or Xbox cloud. The reason is simple, your smartphone, tablet or laptop can already view a Netflix HDR 4K stream but still cannot render Gmail or Figma with acceptable performance. You can also do things like remove ads and telemetry which the service providers would really you rather not.

The app will display exactly as the provider intended, all compatibility issues will be eliminated, and the performance will be entirely uniform and in the provider's control, provided by AWS, Azure and Google Cloud. Stadia for gaming is OK, but Stadia for Adobe Creative Cloud, Figma and Visual Studio is much more interesting, coming to your browser tab soon.

Androider··on The unreasonable effectiveness of print debugging
Speed of iteration beats quality of iteration.

You can step through the program, reason about what's going on, tracking values as they change. But if you missed the moment, you have start again from the beginning (time traveling debuggers being rare). Or maybe you're looking at the wrong part entirely at this stage, and just wasting time.

With print debugging you write a bit of code to test a hypothesis. Then you run it, and you keep running it, and especially if it's an UI program you play with the UI and see how the values change during that run. Ideally the loop to change the code -> see the result should be a few seconds.

You can then git commit or stash your prints, switch branches and compare behavior with the same changes applied. And at the end of the day if you walk away, your prints will still be there the next morning. The debugger doesn't produce any comparable tangible artifacts.

Once you do know where the problem is, and if it's not apparent what the problem is (most problems are pretty trivial once located), that's IMO the time to break out the debugger and slowly step through it. But the vast majority of problems are faster to solve through rapid iterative exploration with prints in my experience (C, C++ for over a decade, Python, now JS/TS).

Androider··on New Google Fi Cell plans – unlimited data for $30
That sounds like a great way to get your entire Google Account permanently banned with no appeal.
Androider··on New Google Fi Cell plans – unlimited data for $30
Unlimited free international data, text and calls for the Plus plan sounds really convenient for travelling, no need to swap to local SIMs. Can you bump your plan up to that for a month in the app, and then back down, hassle free?
Androider··on 1Password Secrets Automation
I don't understand why people think it's some nefarious dark pattern. It's perfectly clear, the old 1Password app is winding down, the future is their hosted version.

The only way to even download the app is if you already knew about it's existence before. It's not a dark pattern, it's just directing people who sign up for 1Password today into their actually supported product instead of the end-of-lifed one. Your app will continue to work for some reasonable amount of time until some version of macOS breaks it, then you can either pick another one from numerous competitors or go with their hosted version. Sounds to me like you'll need look into the alternatives given your requirements. It is what it is, no need to attribute it to malice.

Androider··on 1Password Secrets Automation
The company is clearly focusing entirely on their SaaS version, which just makes sense in this day and age. They provide the stand-alone version for people who know about and want to continue using it, but obviously they don't want to drive any new users to this end-of-life product.

In my opinion, it's not a dark pattern, it's just softly winding down the old app. That's not an unreasonable thing to do. If you want a traditional app, there are other choices.

Androider··on Problems with low DNS TTLs
Similarly, AWS Route 53 alias records use a 60 second TTL and there's no way to change that, so that's probably about a quarter of the Internet right there. Also when creating a manual record in Route 53, the default is 300 seconds and you'd have to go out of your way to pick another value.
Androider··on Launch HN: Pry (YC W21) – Finance for Founders
I think what would help is, and what I've seen other companies do:

- First add a security page, I need to know you're doing basic things like encrypting the data on your end etc. Hopefully you're using at least something like KMS for your at-rest encryption (all DBs and disks) if using AWS.

- Then also publicly state on the security page something to the effect of "No Pry employee has the ability to access customer data without your explicit approval, and all access is audited". Meaning, if you need to work a support case for some customer, you have to ask them before you look at their data, and you have to track when this access occurs

- Ultimately you'll get something like a SOC2 cert to show that you actually have these controls in place that you say you do

I think with this, you'll be able to overcome some of the fears. Native apps is a shrinking market and a distraction for you IMO. Your customers are already fine with cloud solutions, since they're using Quickbooks Online, Xero etc. by definition, you just need to convince them you're trustworthy as well.

Androider··on Google Cloud vs. AWS Onboarding Comparison
That's what it says, but in practice I've asked some really general and technical questions of AWS support and always received a helpful reply without a paid support plan as well. With a paid plan the response time is better.

In general the AWS support has been great. In many cases, they've forwarded our requests to product teams who have even fixed bugs we've run into and contacted us directly.

Our other experience is with paid Azure support, which did little else than direct us to the (not related to the question) docs. They also had a really hard time understanding our technical questions about specific APIs. To their credit, they did eventually escalate to the PM of the service in question.

In general, the team responsible for the service really must be able to help out with support requests. In AWS this is definitely the case, in Azure as well but there's a bit of gatekeeping. Does developers and PMs in GCP participate in support?

Androider··on Silicon Valley’s Safe Space
From the article:

Mr. Srinivasan said they could not let that kind of story gain traction.

“If things get hot, it may be interesting to sic the Dark Enlightenment audience on a single vulnerable hostile reporter to dox them and turn them inside out with hostile reporting sent to their advertisers/friends/contacts,” Mr. Srinivasan said in an email viewed by The New York Times

Androider··on Apple redirects Google Safe Browsing traffic through proxy servers in iOS 14.5
Google's revenues are closing in on 200 billion a year. If the hardware business makes, say, 2 billion a year, it's safe to say that the hardware is a pretty insignificant part of the overall business. The data gathered from that hardware on the other hand...
← PreviousPage 3 of 14Next →