4,776 karma · joined October 7, 2011
Mixing the use with other libraries provided by the Python ecosystem is a another scenario. Do you really want to do HTTP in C or do you prefer requests?
Changing the name of the entire Office suite into Copilot didn't make things better. Now you have no idea of knowing what you are really getting. Is Office Copilot? Is Copilot Office? Is Office AI? Is AI Copilot? Is time real or just a concept? Who knows? The strongest product in Microsoft's portfolio with an established name is now gone.
Give it a year and it will be renamed again to Microsoft Teams 365 Copilot Enterprise with Office subsystem for Windows Business. Just to cover all bases.
If one could dream, modules should have to explicitly declare whether they have side-effects or not, with a marker at the top of the module. Not declaring this and trying anything except declaring a function or class should lead to type-checker errors. Modules declaring this pure-marker then automatically become lazy. Others should require explicit "import_with_side_effects" keyword.
__pure__ = True
import logging
import threading
app = Flask() # << ImpureError
sys.path.append() # << ImpureError
with open(.. ) # << ImpureError
logging.basicSetup() # << ImpureError
if foo: # << ImpureError (arguable)
@app.route("/foo") # Questionable
def serve(): # OK
...
serve() # << ImpureError
t = threading.Thread(target=serve) # << ImpureError
All of this would be impossible today, given how much the Python relies on metaprogramming. Even standard library exposes functions to create classes on the fly like Enum and dataclasses, that are difficult to assert as either pure or impure. With more and more of the ecosystem embracing typed Python, this metaprogramming is reducing into a less dynamic subset. Type checkers and LSPs must have at least some awareness of these modules, without executing them as plain python-code.Someone selling a used bike, or other items of similar value, on second hand market and not accepting Swish would maybe not directly be considered criminal, but would for sure raise an extra eyebrow about the origins of the goods.
Otherwise correct, nobody would blink if you use cash for other daily purchases like ice cream or groceries, even if unusual.
Obviously, now the resource server instead becomes your central guard of access, and is far from a local-first crypto based solution as they describe. Just that the way it’s pictured sounded overly dramatic.
The third backup being in a decoupled system on site is what you now count as your ”offsite” backup. Having this last copy is non-negotiable, no matter how many 9s S3 claim to have.
Use typing.Self
This has many benefits, like forcing you to think about the dependencies and layers of your architecture. Here is a good read about why, from F# that has the same limitation https://fsharpforfunandprofit.com/posts/cyclic-dependencies/
As others already mentioned, importing __annotations__ also works.
Can’t the browser do this with HTML and CSS? From there you can go even further with standard tooling, generating from markdown.
This has been the modus operandi since windows xp days where we in all innocence installed random cd-ripping software and bonzi buddies, with full access to the rest of the computer.
It’s hard to argue against convenience. People will always do what’s easy even if less secure. The bigger lesson is why we still haven’t learned to sandbox sandbox sandbox. Here it seems like AI just did a full factory reset on every best practice know to man.
With ssh everybody does TOFU or copies host fingerprints around, vs https where setting up letsencrypt is a no-brainer and you’re a weirdo of you even think about self-signed certs. Now you can do the same with ssh but do you?
For authentication, ssh relies on long lived keys rather than short lived tokens. Yes, I know about ssh certificates but again, it’s a hassle to set up compared to using any of a million IdP with oauth2 support. This enables central place to manage access and mandate MFA.
Finally, you better hope your corporate IT has not blocked the SSH port as a a security threat.
Commit #1 adds a helper function for whatever, looks innocent enough, implementation is correct. Believe it or not, it even has tests, lgtm. Then only by commit #8 do you realize this helper function is not needed at all and the entire approach is wrong. Happens every time.
I started reviewing these chains backwards and refuse starting a review until the whole chain is available. That’s however not always easy either, when commit #2-#5 has incrementally refactored everything into something unrecognizable, so that both the left and right side of the diff are wrong! No, I’m not interested in ”this will be fixed 2 commits down the chain”. I just want to review the final state that goes into production, nothing else matters.
Yes, commits should be made small whenever possible and not include unrelated fixes or refactors. Just please, keep them meaningful on their own.
There are browser extensions like h264ify that block newer codecs but WHY??? Is nobody at YouTube caring about the user experience? It’s easier and more reliable to just download the videos.
Yes, it has a higher learning-curve than incrementally extending your constantly growing deploy.sh-script and there are many moments when it's complex and overkill. When you really need it though, no amount of in-house sysadmin-scripts will cover the same functionality with the same quality. The discussions about it online tend to have a very vocal majority of people from the first bucket, not yet realizing that they are slowly growing into the second.
All that said, it's by no means perfect and some critique is well-deserved, just that a lot of the hate comes from armchair-experts who compare it to running things locally on your laptop.
Very similar in fact to systemd, seen in isolation from an application-developer, it's one more thing to learn getting in your way. Seen from the complete system-administrators point of view, it's a consistent way to manage and secure your fleet.