HNHacker News
TopNewBestAskShowJobs

AtNightWeCode

457 karma · joined March 29, 2021

At a dark place
submissionscomments
AtNightWeCode··on Bank transfers as a payment method (2021)
I forgot that credit cards comes with insurance in some places. Most apparent is that you can't even rent a car in some parts of US without a credit card. In EU that type of insurance may be included in the legally obligated housing insurance.
AtNightWeCode··on Microsoft lost its keys, and the government got hacked
We use MS for some stuff and did use Okta for others. But... Okta fkd up and can never be used in any enterprise today. We migrated from it. Everybody should. Now we use MS and Google. Okta is probably the most over-priced service in history of CS especially considering the poor sec design. They do however solve the US-Franchise-Corp bs that I guess it was designed for.
AtNightWeCode··on Show HN: Use DNS TXT to share information
Like NSA did not controlled CA:s? Or are you one of those conspiracy nuts that think NSA cracked it?
AtNightWeCode··on Show HN: Use DNS TXT to share information
If TXT-records are proof enough when ownership is to be provided for TLS certs. Then, why not just put the TLS-data into the "trusted" TXT-records and skip the multi-billion-dollar-BS-CA-biz all together?
AtNightWeCode··on Bad numbers in the “gzip beats BERT” paper?
In current times *zip mostly cripples things like the web and Docker. To find out it is the best at something in 2023 is not very likely.

Nice find btw.

AtNightWeCode··on The theory versus the practice of “static websites”
I worked a lot with both SSR and SSG. I think SSG is the correct choice for most sites. There may be reasons to use SSR like if it is the only alternative to problematic client side rendering or in some cases security.
AtNightWeCode··on Bank transfers as a payment method (2021)
"I can dispute the charge and get resolution without any money leaving my bank account."

Really? In what cases can an average credit card user challenge a payment that has not already occurred?

If there is a fraud usually it is quick to get money back if debit cards were used.

AtNightWeCode··on Bank transfers as a payment method (2021)
Why Americans love credit cards so much is a mystery. In Europe debit cards have been the way to go for a long time. Most countries in Europe also have direct payments through mobile apps.
AtNightWeCode··on We spent $20k on Google Play pre-registration ads
I spent some money on GP ads and it was kind of funny that no matter how the views and clicks were distributed in the end the cost for each install was about 1$.

It is "fake" how it works but it is in the agreement. Also Google ads has the worst support ever. Not even helping when you want to invest.

Fun fact. GP actually paid out some cash invested for ads this year. Have no idea why. I am pretty sure I burned it all on ads.

AtNightWeCode··on Laws of UX
Yes, it is incorrect. Some UX designs even try to make you feel like something happens instantly when it is not. Best example I can think of is that Spotify used to have this animation on the play button that was just there to hide the delay between click and play.
AtNightWeCode··on Laws of UX
BS. Google have shown that any time loss in any stage of any payment process directly affect conversion rates.
AtNightWeCode··on Azure AD Is Becoming Microsoft Entra ID
This does make sense I think. All the bs about namespaces that only differs by the prefix Azure or Microsoft. Not so much.
AtNightWeCode··on Kubernetes SidecarContainers feature is merged
Monolith apps can have many dependency checks and it is not really an issue but I get your point. It can become messy. What I have seen gone into sidecars is TLS-termination, caching, authentication, service clients, metrics and logging. Things I would prefer to have in a dedicated proxy layer or in the images.
AtNightWeCode··on Kubernetes SidecarContainers feature is merged
When I first learned about the sidecar pattern I thought it was great. I am not sure about it anymore. Most of it could be propagated to custom images or layers at the boundary. To me this feels a bit sketchy. Too have containers that kinda is part of the mesh but then does not share the same lifecycle as the mesh.
AtNightWeCode··on Meta releases Intermediate Graphics Library
A large part of creating a 3D-engine is to try figuring out what capabilities can be used with what performance across different hardware. If this is only an abstraction it won't solve anything.
AtNightWeCode··on Meta releases Intermediate Graphics Library
You are too kind. Mid to late 90s game. What is up with those shadows. I have written a 3D-engine with better image quality than this like 20 years ago.

At least it is not a teapot.

AtNightWeCode··on Red flags in the Threads privacy policy
What I don't understand is why products like Facebook and Google Analytics (up to 3?) ship PII to US. The owners have data centers in EU and should be able to process the data enough for it to be OK to send to US.
AtNightWeCode··on Red flags in the Threads privacy policy
It is not that difficult for most startups to be mostly GDPR compliant. At least not in comparison with trying to fix it later. In some business areas local law and GDPR clashes though which can be a pain.
AtNightWeCode··on Deno 1.35: A fast and convenient way to build web servers
Cloudflare workers if you want JS/TS.
AtNightWeCode··on Deno 1.35: A fast and convenient way to build web servers
Like over a year ago Deno raised $21M in investments and this is the current state...
AtNightWeCode··on Google search's death by a thousand cuts
I think the article is mostly incorrect. The deep web has been way larger than the open Internet for a very long time. I see other problems with Google search like it does not work as well as it did some years ago.
AtNightWeCode··on Type-safe, K-sortable, globally unique identifier inspired by Stripe IDs
Yeah and Twitter IDs used to be 32-bit integers. In this case it is kind of obvious that the IDs leaks information about internal data types. Which is not ok at many companies.
AtNightWeCode··on Vincent van Gogh's paintings and drawings
I recommend this museum. It did not give me the same jaw-dropping experience as staring into Starry Night at MOMA. But it is a great museum and it spans over the entire life of Van Gogh, his development and tools. There is also a lot humor and distance in the descriptions which makes the experience less dark considering all the misery in his life.
AtNightWeCode··on Type-safe, K-sortable, globally unique identifier inspired by Stripe IDs
That it is a nearly sorted sequence. Typically the first part of the ID is a timestamp. So you may sort the IDs down to the second it was created. But for IDs created at the same time the order is random. This can be used for caching, database performance and so on.
AtNightWeCode··on Type-safe, K-sortable, globally unique identifier inspired by Stripe IDs
An important aspect of identifiers is to not leak any information in the identifier. In some scenarios a prefix might be fine but less important things have been blocked by our dpo department.
AtNightWeCode··on Is ORM still an anti-pattern?
If the code is handwritten or not does not really matter when you are looking at the generated execution plans and so on for troubleshooting.

I worked with several systems not using ORMs that still have the N+1 problem. And if a schema generator also is used it won't forget to add indexes.

My main issue with ORMs is that schema changes over time becomes more and more scary. Another thing is that many libs comes with a bit of magic. A seemingly innocent change can move things from SQL to the client or the other way around. Ending up with large performance impacts.

EDIT: And probably 100% of all the security related issues I have fixed in SQL would have been avoided with an ORM framework.

AtNightWeCode··on Rust fact vs. fiction: 5 Insights from Google's Rust journey in 2022
I mostly looked at Rust to replace tools written in GO and Webapis written in ASP.NET/C#. In both cases there seems to be options in Rust but not reliable ones. With reliable I mean that it is just too few people involved. Not that it does not work.
AtNightWeCode··on Why use OpenID Connect instead of plain OAuth2?
I do not care about you or why you are here. The answer points to a source that have the correct answer to a very basic question. I have no obligations to you or your hubris. You millennials are really something else. How you even manage to tie your own shoelaces amazes me.

When I was a kid the fundamental crime in knowledge was to actually just tell all the answers. You are whining about a meta discussion on a topic where the original answer should have been just fking Google it.

AtNightWeCode··on Why use OpenID Connect instead of plain OAuth2?
I don't think you want ABAC. ABAC is for the cases when a set of attributes will grant access. The more common thing is RBAC. RBAC is that a user have been assigned some roles that comes with access.

A good example with ABAC is if person X uses an IPhone with the latest major updates then access to some wi-fi is granted.

Also, roles comes with a hierarchy. This is important when you work with SOX controlled companies.

Several security consultants will try to sell ABAC as a necessity along with RBAC. It is for sure not.

AtNightWeCode··on Rust fact vs. fiction: 5 Insights from Google's Rust journey in 2022
Rust is for sure much easier to learn than some people claim. Some parts of Rust is different but it is not very difficult. I think the ecosystem is the major problem with Rust.
← PreviousPage 12 of 34Next →