HNHacker News
TopNewBestAskShowJobs

AtNightWeCode

457 karma · joined March 29, 2021

At a dark place
submissionscomments
AtNightWeCode··on SQL Tips and Tricks
Jesus. The problem is not WHERE 1=1. It is WHY people do it. People do it because they then in Python, JS or whatever can easily add conditions. Like QUERY + "AND x='blabla'". There is the problem. Every time you create a unique SQL statement the query will need a new query plan in most SQL engines. Some will cache parts of the query. And you could use parameters along with this paradigm but if you are this bad at SQL I doubt it.

It is kinda funny that op backpedal on this cause to me the whole site is amateurish. I just pointed out what I thought was the worst part. It is likely that it is generated by AI. Either way the post is terrible.

AtNightWeCode··on SQL Tips and Tricks
Not sure I get this. But I think it does matter since you understand why people do it to begin with. I worked on two enterprise solutions over the last couple of years that have this exact problem. That people are using WHERE 1=1 and then add random "AND something=something" that completely trashes the performance of the db. Also, it does not matter as much on-prem. But in cloud envs it does. Since you can't really spike CPU and mem the same way as on-prem.

The reason I pointed out this specific issue is just that I thought it was the worsed of many poor tips. ChatGPT can give better tips.

AtNightWeCode··on SQL Tips and Tricks
Both columns needs the correct type of index. The best thing to do is to use a tool that scans for missing indexes.
AtNightWeCode··on Google Cloud files complaint due to Microsoft's anti-competitive licensing
No, because nobody needs to run anything on WS. Even we people that build stuff for Azure avoids WS. The whole claim is just stupid.
AtNightWeCode··on Google Cloud files complaint due to Microsoft's anti-competitive licensing
I think this is the most desperate and pathetic claim for a long time. I mean, it's Google. Google is a dead company. They destroyed the only hand that feeds them. The search engine. They did this on purpose to increase the number of searches. And then I really hate what they done to Google play.

As a senior Azure architect. We try to run as much as possible on Linux to avoid licenses. I don't even understand how you end up running Windows Server on GCP. Never ever heard of a corp that does this. Also, most of the new stuff from MS is platform independent.

AtNightWeCode··on SQL Tips and Tricks
Read my other comments. I worked with SQL on and off since the last century. It has nothing to do with your poor assumptions.
AtNightWeCode··on SQL Tips and Tricks
A common mistake I see is that people think foreign keys will automatically create indexes. Missing indexes is a general problem in SQL. Missing indexes on columns that are in foreign keys are even worse.
AtNightWeCode··on SQL Tips and Tricks
You can motivate it with the same reasons as trailing commas. Making code reviews easier since changes to WHERE statements does not effect other lines. But if the reason is, as in this case to be able to add dynamic conditions. You will for sure be fired where I work.
AtNightWeCode··on SQL Tips and Tricks
If you use it in the same way you use trailing commas. Fair. But the site says to make it easier to add dynamic conditions. Which is a terrible idea in maybe not all but many SQL engines.
AtNightWeCode··on SQL Tips and Tricks
Which is exactly what the site says. To insert dynamic conditions. I know that you can use 1=1 for the same reasons as trailing commas. But kinda obvious that this is not the case here.
AtNightWeCode··on SQL Tips and Tricks
Yes. "Use a dummy value in the WHERE clause so you can dynamically add and remove conditions with ease:" I don't know how to read this in another way.
AtNightWeCode··on SQL Tips and Tricks
In this case. A query that you build by adding different strings. 1=1 is for adding AND statements to the WHERE clause dynamically. In your code. I never seen it used for anything else. Adhoc is just the practice of running raw SQL queries.

So you end up with things like this.

"SELECT * FROM Music WHERE 1=1" + "AND category='rock'"

The risk is now that you by mistake allow for SQL-injections but also every genre will generate a different query plan. Depending on what SQL engine you use this may hurt performance.

And one would think that this is a thing of the past. But it is not.

AtNightWeCode··on SQL Tips and Tricks
Never use WHERE 1=1. It is both a security risk and a performance risk to run dynamic ad-hoc queries.
AtNightWeCode··on Cloudflare's new marketplace lets websites charge AI bots for scraping
Maybe they could solve some of the core issues instead. It is like CF lost the source code and just pushing new more or less useless features all the time. Even though I think this is a fair change.
AtNightWeCode··on What's inside the QR code menu at this cafe?
Different confs in the same repo. Many CI/CD tools will pick debug/dev conf by default if nothing else is set.

It was just an example. Maybe they knew.

AtNightWeCode··on What's inside the QR code menu at this cafe?
Could be as simple as no auth in debug builds and then deployed it by accident.
AtNightWeCode··on One in five genetics papers contains errors thanks to Excel (2016)
The exponent operator is just short for the POWER function in Excel. So from that perspective it is the correct behaviour I think even if it is mathematical incorrect.
AtNightWeCode··on QUIC is not quick enough over fast internet
For us, what QUIC solves is that mobile users that move around in the subway and so on are not getting these huge latency spikes. Which was one of our biggest complains.
AtNightWeCode··on It's always TCP_NODELAY
Agreed. Another thing along the same path is expect. Needs to be disabled in many cloud services.
AtNightWeCode··on Every map of China is wrong
Some parts of Europe. But now when I looked it up the law was actually changed like 10 years ago. Damn I'm old.
AtNightWeCode··on Every map of China is wrong
Interesting. It is illegal in some western countries too to create your own maps. Another thing with maps is that online services have different maps depending on what country you access from.
AtNightWeCode··on No Abstractions: our API design principle
But the entire API is an abstraction...

So the benefits are:

Audits

Network/infra

Time to market

Single API

Less code

Risk (sometimes)

The downside:

1. Slow or missing propagation of underlying features.

2. Hidden business logic.

3. Risk of changes in pricing models and so on.

4. Single point of failure.

By method, let's talk about the downsides:

1. Not the biggest risk here. But for some reason features that are new or will save you a lot of money does not propagate as fast other things.

2. Many services like payment gateways are expected to hide some aspects of the underlying services. What does this hide?

3. The big risk with something like this used to be vendor lock-in. Today it is almost always acquisitions. Is this really a product? Will it be merged and sold together with something that I don't want?

4. Obvious

Overall I think these types of services are the most useless. Abstractions that are not simplifications should mostly be avoided. I also think one needs to be extra careful if this only sits between you and other services. That is not a product in general.

AtNightWeCode··on The man who killed Google Search?
Wow, that was a red pill. Everything suddenly makes sense. I always thought it only was machine learning that messed it up.

How to replace Google as default search in your browsers (tested on Windows).

Firefox -> Hamburger menu -> Settings -> Search

Chrome -> Kebab menu -> Hamburger menu -> Search engine

Edge -> Meatballs menu -> Privacy, search and services -> Services | Address bar and search

It says something about the state of UX in 2024 when the three major browsers have different icons for the app menu.

AtNightWeCode··on The Performance Impact of C++'s `final` Keyword
Most benchmarks are wrong. I doubt this is correct. Final should have been the default in the lang I think though.

There are tons of these suggestions. Like always using sealed in C# or never use private in Java.

AtNightWeCode··on Hardest problem in computer science: centering things
My experience is that frontend devs mostly wants to write js and not css. The term they use for guys like the op is pixel pusher.

Another annoying thing is when they use colors that are a bit different where is should be the same. For things like buttons etc...

AtNightWeCode··on PuTTY vulnerability vuln-p521-bias
NSA disagrees...
AtNightWeCode··on PuTTY vulnerability vuln-p521-bias
We recommend against ECDSA for internal accounts. I know several of our partners use it though. Hard to not be cynical about this even though this issue seems mostly harmless.
AtNightWeCode··on RFC: Banning "AI"-backed (LLM/GPT/whatever) contributions to Gentoo
I think it is a more general problem. One can't see in GIT what tools have been used to create and validate the code.

It is impossible to use most modern devtools completely without AI. I think it is better to regulate the usage and enforce transparency.

AtNightWeCode··on Lessons after a Half-billion GPT Tokens
The UX is an important part of the trick that cons peeps that these tools are better than they are. If you for instance instruct ChatGpt to only answer yes or no. It will feel like it is wrong much more often.
AtNightWeCode··on Tree-shaking, the horticulturally misguided algorithm (2023)
I have Blazor apps running on Cloudflare pages. They download fast and the performance is great. The load time is terrible though. I think it is unsolvable with .NET. I think the core issue is how everything is entangled by design in oo langs.

Also, the amount of money put into js is hard to compete with. Then to also have copy/paste as a lang feature in js is like cheating.

Third. With Blazor at least you still need js and skills in that area. I think this is my main issue.

← PreviousPage 7 of 34Next →