HNHacker News
TopNewBestAskShowJobs

Too

4,776 karma · joined October 7, 2011

submissionscomments
Too··on Exploring PostgreSQL 18's new UUIDv7 support
Your comment here has id 45622189 and the UI tells me in plain sight that you posted it 11h ago. Assuming the ids are sequential, these two combined tells me more about HN vs a uuid ”leaking” something that’s already expected to be public.
Too··on Pyrefly: Python type checker and language server in Rust
Anyone struggling with slow mypy should really update to latest version. This years releases has focused on performance and it has payed off. Add the boost from latest Python versions to that and you can see 50% type checking improvements. Still far from a rust based tool, always something, all without changing your tool chain.
Too··on MAML – A new configuration language
This is answered in the FAQ
Too··on Vibing a non-trivial Ghostty feature
Ubuntu has both Snap and custom APT repositories.
Too··on Vibing a non-trivial Ghostty feature
Tangential question. Why does every app still need its own auto-update framework? Shouldn’t we all rely on app-stores and package managers for this?
Too··on How Apple designs a virtual knob (2012)
Look at the how timers are adjusted in the Clock app on iPhone. Three rotary tumblers that can all be set independently.
Too··on Liquid Glass Is Cracked, and Usability Suffers in iOS 26
This article doesn't even mention the worst part of the update. Frame rate has dropped remarkably. iOS used to have flawless smooth animations, with 0 dropped frames, setting the industry standard. Now every interaction with the phone yanks at least once, it feels like some cheap entry level Android phone from 2008. I don't even mind the translucency, i just want my FPS back.
Too··on Python 3.14 is here. How fast is it?
You write the ffi once and let hundreds or thousands of other developers use it. For one off executables it rarely make sense.

Mixing the use with other libraries provided by the Python ecosystem is a another scenario. Do you really want to do HTTP in C or do you prefer requests?

Too··on Python 3.14 is here. How fast is it?
Not always. See dead batteries: https://peps.python.org/pep-0594/
Too··on Microsoft 365 Copilot's commercial failure
In true Microsoft spirit, they completely tanked the name. This was launched just shortly after GitHub Copilot was the hottest trend. Everyone associates Copilot with GitHub and think it's a developer-product, not an office-product.

Changing the name of the entire Office suite into Copilot didn't make things better. Now you have no idea of knowing what you are really getting. Is Office Copilot? Is Copilot Office? Is Office AI? Is AI Copilot? Is time real or just a concept? Who knows? The strongest product in Microsoft's portfolio with an established name is now gone.

Give it a year and it will be renamed again to Microsoft Teams 365 Copilot Enterprise with Office subsystem for Windows Business. Just to cover all bases.

Too··on PEP 810 – Explicit lazy imports
This is a great compromise given how much would break if this was the default. Making this the default would be better in the long-run, require taming the abuse of side-effects in imports too, win-win.

If one could dream, modules should have to explicitly declare whether they have side-effects or not, with a marker at the top of the module. Not declaring this and trying anything except declaring a function or class should lead to type-checker errors. Modules declaring this pure-marker then automatically become lazy. Others should require explicit "import_with_side_effects" keyword.

    __pure__ = True
    import logging 
    import threading
  
    app = Flask()          # << ImpureError
    sys.path.append()      # << ImpureError
    with open(.. )         # << ImpureError
    logging.basicSetup()   # << ImpureError
    if foo:                # << ImpureError  (arguable)
   
    @app.route("/foo")     # Questionable
    def serve():           # OK
        ...

    serve()                # << ImpureError
    t = threading.Thread(target=serve) # << ImpureError

All of this would be impossible today, given how much the Python relies on metaprogramming. Even standard library exposes functions to create classes on the fly like Enum and dataclasses, that are difficult to assert as either pure or impure. With more and more of the ecosystem embracing typed Python, this metaprogramming is reducing into a less dynamic subset. Type checkers and LSPs must have at least some awareness of these modules, without executing them as plain python-code.
Too··on Offline card payments should be possible no later than 1 July 2026
If your local hairdresser gives you a cheaper price when paying cash, wouldn't you assume tax evasion? (criminal).

Someone selling a used bike, or other items of similar value, on second hand market and not accepting Swish would maybe not directly be considered criminal, but would for sure raise an extra eyebrow about the origins of the goods.

Otherwise correct, nobody would blink if you use cash for other daily purchases like ice cream or groceries, even if unusual.

Too··on Litestream v0.5.0
Serving users is one thing. Then you want to run some interactive analytics or cronjobs for cleanup etc on the db. Even if the load can manage it, how would the admin jobs connect to the database. I’ve never seen a db with only one client. There is always some auxiliary thing, even when you don’t consider yourself a microservice shop.
Too··on Keyhive – Local-first access control
Their claim that every request goes through the hot path of a central auth db is stretching the truth quite a bit. With Oauth2 you get a signed access token once from the Id Provider, then you reuse this token several times until it’s given expiry time has run out. It is up to the resource server to validate the token scope, signature and the expiry time. This can be done offline as long as the resource server has the public key of the IdP. Ssh certificates work the same way.

Obviously, now the resource server instead becomes your central guard of access, and is far from a local-first crypto based solution as they describe. Just that the way it’s pictured sounded overly dramatic.

Too··on I only use Google Sheets
Good advice. Though I’d say you can count the cloud storage as 2 copies. They typically replicate the data to three drives, that covers all the typical failure modes you’d normally get when running a drive yourself. Then with a simple click you can even get a replica in another region.

The third backup being in a decoupled system on site is what you now count as your ”offsite” backup. Having this last copy is non-negotiable, no matter how many 9s S3 claim to have.

Too··on Python developers are embracing type hints
> If the type is a class with methods, then this method doesn't work

Use typing.Self

Too··on Python developers are embracing type hints
Too bad Mojo gave up on Python compatibility on code level. Now it’s just one of a dozen “Python inspired” languages, with the only benefit that they aim for easily calling into other Python code.
Too··on Python developers are embracing type hints
Java on the other hand had the most verbose syntax known to man, especially those early versions of it. Nowadays it’s getting more tolerable.
Too··on Python developers are embracing type hints
This is trivial to solve by simply not having circular imports. Place the types in one file and the usage of it in others.

This has many benefits, like forcing you to think about the dependencies and layers of your architecture. Here is a good read about why, from F# that has the same limitation https://fsharpforfunandprofit.com/posts/cyclic-dependencies/

As others already mentioned, importing __annotations__ also works.

Too··on Typst: A Possible LaTeX Replacement
Why do we need these special languages just to get adequate typesetting and kerning? In the end it’s just a paragraph of text constrained to a column. Because let’s be honest, this is why most people use LaTeX, not because they enjoy how to place a picture in a bullet list with cryptic syntax. Let’s ignore math for now.

Can’t the browser do this with HTML and CSS? From there you can go even further with standard tooling, generating from markdown.

Too··on A Postmark backdoor that’s downloading emails
> Somehow, we've all just accepted that it's totally normal to install tools from random strangers

This has been the modus operandi since windows xp days where we in all innocence installed random cd-ripping software and bonzi buddies, with full access to the rest of the computer.

It’s hard to argue against convenience. People will always do what’s easy even if less secure. The bigger lesson is why we still haven’t learned to sandbox sandbox sandbox. Here it seems like AI just did a full factory reset on every best practice know to man.

Too··on SSH3: Faster and rich secure shell using HTTP/3
I thought the same until I read the page and realized that ssh is quite broken if you think about it.

With ssh everybody does TOFU or copies host fingerprints around, vs https where setting up letsencrypt is a no-brainer and you’re a weirdo of you even think about self-signed certs. Now you can do the same with ssh but do you?

For authentication, ssh relies on long lived keys rather than short lived tokens. Yes, I know about ssh certificates but again, it’s a hassle to set up compared to using any of a million IdP with oauth2 support. This enables central place to manage access and mandate MFA.

Finally, you better hope your corporate IT has not blocked the SSH port as a a security threat.

Too··on Fast UDP I/O for Firefox in Rust
Why are they supporting Android 5? It’s over 10 years old, the devices running it after updates even older. Mobile devices from that era must have a real tough time to browse the modern bloated web. It shouldn’t even be possible to publish to Play store when targeting such an old API level. Who is the user base? Hackers who refurbished their old OnePlus, run it with charger always plugged in, didn’t upgrade to a newer LineageOS, and installed an alternative App Store, just for the sake of it? While novel, it’s a steep price to pay, as we see here it is slowing down development for the rest of us.
Too··on The Theatre of Pull Requests and Code Review
Yeah. While this narrative style tries to explain what things are done, it instead often leaves the question: Why are we doing this at all?

Commit #1 adds a helper function for whatever, looks innocent enough, implementation is correct. Believe it or not, it even has tests, lgtm. Then only by commit #8 do you realize this helper function is not needed at all and the entire approach is wrong. Happens every time.

I started reviewing these chains backwards and refuse starting a review until the whole chain is available. That’s however not always easy either, when commit #2-#5 has incrementally refactored everything into something unrecognizable, so that both the left and right side of the diff are wrong! No, I’m not interested in ”this will be fixed 2 commits down the chain”. I just want to review the final state that goes into production, nothing else matters.

Yes, commits should be made small whenever possible and not include unrelated fixes or refactors. Just please, keep them meaningful on their own.

Too··on Docker Hub Is Down
Sure? --pull=missing should be the default.
Too··on Docker Hub Is Down
Hard to see if this is /s or not. Nobody is forcing you to run images straight from dockerhub lol. Every host keeps the images already on it. Running a in-house registry is also a good idea.
Too··on Terence Tao: The role of small organizations in society has shrunk significantly
Like rock paper scissors, there are multiple dimensions to power and the state doesn’t always possess all of them. Media being the most obvious one (fourth estate). Federal bank another. As the split of government and parliament.
Too··on Yt-dlp: Upcoming new requirements for YouTube downloads
Many performance problems on YouTube are because they now force everyone to use the latest heavy codecs, even when your hardware does not have acceleration for it. I have a laptop that is plenty powerful for everything else and plays 4K h264 no problem. 720p on YouTube on the other hand turns it into a hot slate after a minute and grinds everything to a halt.

There are browser extensions like h264ify that block newer codecs but WHY??? Is nobody at YouTube caring about the user experience? It’s easier and more reliable to just download the videos.

Too··on Yt-dlp: Upcoming new requirements for YouTube downloads
There’s a famous presentation by David Beazley where he implements a WASM interpreter in Python in under an hour. Highly recommended.
Too··on Systemd can be a cause of restrictions on daemons
Kubernetes?

Yes, it has a higher learning-curve than incrementally extending your constantly growing deploy.sh-script and there are many moments when it's complex and overkill. When you really need it though, no amount of in-house sysadmin-scripts will cover the same functionality with the same quality. The discussions about it online tend to have a very vocal majority of people from the first bucket, not yet realizing that they are slowly growing into the second.

All that said, it's by no means perfect and some critique is well-deserved, just that a lot of the hate comes from armchair-experts who compare it to running things locally on your laptop.

Very similar in fact to systemd, seen in isolation from an application-developer, it's one more thing to learn getting in your way. Seen from the complete system-administrators point of view, it's a consistent way to manage and secure your fleet.

← PreviousPage 3 of 34Next →