HNHacker News
TopNewBestAskShowJobs

Jenk

3,616 karma · joined February 7, 2013

submissionscomments
Jenk··on Most RESTful APIs aren't really RESTful
It's a delimited string. There are many fields within that string already.

    "2025-07-10T09:48:27+01:00" 
That contains, by my quick glance, at least 8 fields of information. I would argue the one field it does not carry but probably should is the _name_ of the timezone it is for.
Jenk··on Most RESTful APIs aren't really RESTful
Exchange/GMail/etc. already has this problem/feature. Their response is simple: Follow the organiser's timezone. If it's 9am on the organiser's calendar, it will stay at 9am on the organiser's calendar. Everyone else's appointment will float to match the organiser.
Jenk··on Typr – TUI typing test with a word selection algorithm inspired by keybr
Monkeytype.com has many "code" dictionaries to choose from.
Jenk··on Using Microsoft's New CLI Text Editor on Ubuntu
Ed was designed in an age where the visual interface was a printer - so it is most assuredly a cli tool :)
Jenk··on Using Microsoft's New CLI Text Editor on Ubuntu
Before vim was vi. Befote vi was ex. (Before ex was ed - the first editor for unix)

Vim has ex built in - `Q` in normal mode to enter Ex mode, 3-5 command lines will show at the bottom and you can Ex away. I don't know of practical uses, I've only done it for the novelty.

Obligatory: To exit Ex mode use `:vi[sual]` - and that's probably where Vi got its name.

Jenk··on Using Microsoft's New CLI Text Editor on Ubuntu
`ZZ` to save and quit, `ZQ` to quit without saving. Sorry, I can't help myself.
Jenk··on Cursor 1.0
> So I wouldn't be so dismissive that anyone frustrated with Cursor is a bot.

Not GP, but my suspicions are actually of the other end of the spectrum - i.e., it's the glowing reviews of AI things that make my bot-sense tingle.

Though I usually settle on the idea that they (the reviewers) are using LLMs to write/refine their reviews.

Jenk··on GitHub Copilot Coding Agent
That the number of successful (as in, merged and works) contributions are greater than those that did not.
Jenk··on A Common Lisp jq replacement
And jaq: https://github.com/01mf02/jaq
Jenk··on Man pages are great, man readers are the problem
I page man (and many other things) through bat[0] which improves my experience.

[0]: https://github.com/sharkdp/bat

Jenk··on Microsoft's many Outlooks are confusing users – including its own employees
CoPilot takes the crown of most overused moniker now.
Jenk··on Whose code am I running in GitHub Actions?
This has been in GH's docs on security hardening for a while[0], and I can't recall which tool it was, but I have seen reports that warn when not using SHAs. Pretty sure there was a linter that would even show the warning in my neovim setup that uses some kind of gh action LSP, but it has been a minute.

[0]: https://docs.github.com/en/actions/security-for-github-actio...

Jenk··on Apple has locked me in the same cage Microsoft's built for Windows 10 users
Win8's UI was terrible because Microsoft are terrible at UI, not because of the duality.
Jenk··on Advertising Is a Cancer on Society (2019)
"all the good things advertising does" is doing a lot of the leg work without much being specified.
Jenk··on Why we use our own hardware
Exactly this. It is culture and organisation (structure) dependent. I'm in the throes of the same discussion with my leader ship team, some of whom have built themselves an ops/qa/etc. empire and want to keep their moat.

Are you running a well understood and predictable (as in, little change, growth, nor feature additions) system? Are your developers handing over to central platform/infra/ops teams? You'll probably save some cash by buying and owning the hardware you need for your use case(s). Elasticity is (probably) not part of your vocabulary, perhaps outside of "I wish we had it" anyway.

Have you got teams and/or products that are scaling rapidly or unpredictably? Have you still got a lot of learning and experimenting to do with how your stack will work? Do you need flexibility but can't wait for that flexibility? Then cloud is for you.

n.b. I don't think I've ever felt more validated by a post/comment than yours.

Jenk··on The Albuquerque "Broken Arrow" Nuclear Accident
The presidential missile code was "00000000" throughout many years of the cold war.

https://arstechnica.com/tech-policy/2013/12/launch-code-for-...

Jenk··on Deprecating Outdated Issues on the GitHub Public Roadmap
Despite the opening statement about clarity and transparency, GitHub have rather opaquely closed many planned features.

I am rather dissapointed that #636 (Shared workflows secrets), #347 (Comments for un-changed lines in PRs), and #552 (Replies to comments) have been closed with no rhyme nor reason given.

Jenk··on Wonder is acquiring Grubhub
In the UK and EU they certainly are.
Jenk··on I got dysentery so you don’t have to
> Do you have any source for this statement?

I note a total absence of sources for your claims.

Jenk··on Winamp deletes entire GitHub source code repo after a rocky few weeks
> Actually, under the GPL, this fact is immaterial. If the Winamp player contained any GPL code at all, modified or not, then it is a derivative work of that GPL code and anyone receiving a copy of Winamp is entitled to demand the full corresponding source be provided under a GPL license.

That's just not true, surely? Lest everyone using any flavour of Linux is liable to the same problem?

How many apps out there are using GPL code? Android, for example.

Making a derivative in the sense of adding functionality to it, I get, but using it as-is as a component or library surely doesn't - and cannot - fall foul of the license else the entire technosphere is liable.

Jenk··on Show HN: I made a git rebase TUI editor

    git config --global core.editor "vim"
Jenk··on Why the ISO format has to die
I came in here thinking I was about to witness some slander against the ISO8601 date time format.
Jenk··on RabbitMQ 4.0
I lost a lot of respect for the RabbitMQ maintainers when they refused to honor the semantic versioning scheme in package managers like nuget/maven/etc. "Safely upgrading" was impossible. 3.5 => 3.6 saw the removal of an argument.

They didn't lose my respect for the removal of the argument, however, they lost my respect for whatabouting the conversation calling SemVer a "no true scotsman" fallacy, then trying to claim that removing a redundant argument is not a breaking change, and other reality-warping nonsense, before blocking myself and other complainants from their issues - and even deleting some of their own comments to mop up some of their own terrible reasoning.

I'm sure there is no love lost on their side, either. Personal rant over.

Jenk··on Ask HN: Does anyone use sound effects in their dev environment?
Continuous testing tools would make good use of audio. It's been a minute since I have been in need of such a tool, but I could appreciate differentiating sounds for passed/failed.
Jenk··on Pick Your Distributed Poison
I think it is CAP theorem and perhaps the author isn't familiar with the name?
Jenk··on Owners of 1-Time Passcode Theft Service Plead Guilty
I'm gravely naive to modern security methods (both defense and offence) but I work closely with some infosec guys in a big-fish company and they often share tales/experiences that I find fascinating because of their ingenuity and temerity.

Some examples:

We have had multiple attempts to use AI as imposters to convince well-wishing colleagues into doing things they shouldn't - a complicated technique that has seen success for the hackers on some occassions[0] - which requires infilitrating numerous accounts etc. This one is the "hollywood romanticized" idea of hacking because it is in realtime with actual people operating the stolen accounts, but using AI to mask their appearance and voice.

Sleeper infiltration - someone will find and breach an exploit, only to patch it, but leave a new backdoor. They then let it sleep for many months, eventually coming back to use it only to (attempt to) completely remove any trace of their presence. inb4 anyone says "ah but they probably copied/did something else you don't know about!" We've had those, too, but some really do just exploit, patch, then leave. Probably to deny someone else or something.

A really fascinating moment for me was watching a seceng spinup a honeypot and it took less than a minute for some attacks to start hitting it.

[0]: https://www.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-k...

Jenk··on Data Exfiltration from Slack AI via indirect prompt injection
https://www.theverge.com/2023/2/28/23618353/lastpass-securit...

An employee (dev/sysadmin) had their home device compromised via a supply chain attack, which installed a keylogger and the attacker(s) were able to exfiltrate the credentials to lastpass cloud envs.

Jenk··on Data Exfiltration from Slack AI via indirect prompt injection
Techies aren't immune either, before we all follow the "blame management" bandwagon for the 2^101-tieth time.

CEOs aren't the reason supply chain attacks are absolutely rife with problems right now. That's entirely on the technical experts who created all of those pinnacle achievements in tech ranging from tech-led orgs and open source community built package ecosystems. Arbitrary code execution in homebrew, scoop, chocolatey, npm, expo, cocoapods, pip... you name it, it's got infected.

The LastPass data breach happened because _the_ alpha-geek in that building got sloppy and kept the keys to prod on their laptop _and_ got phised.

Jenk··on &udm=14 for Safari (iOS/iPadOS)
DDG user here, worth the switch?
Jenk··on 13ft – A site similar to 12ft.io but self-hosted
> The next step

Should that read "Previous"? :)

← PreviousPage 3 of 26Next →