HNHacker News
TopNewBestAskShowJobs

XCabbage

1,167 karma · joined April 11, 2018

markrobertamery@gmail.com https://stackoverflow.com/users/1709587/mark-amery https://github.com/ExplodingCabbage
submissionscomments
XCabbage··on The Law of Leaky Abstractions
Some abstractions are basically perfect and don't require you to understand the layer beneath them at all. Some have that as their ideal, but are imperfect, and sometimes require you to understand a few details of the layer below. But others - the best example that I know of is SCSS - aren't even trying to eliminate the need to understand the layer below. Everything you need to know to write CSS, you still need to know to write SCSS, and then SCSS adds more on top. It's a convenient tool for power users and I wouldn't want to be without it, but for a beginner, using SCSS instead of CSS means you have strictly more to learn; I'd suggest that a newbie on my team not touch SCSS until they've done a few days' work with raw CSS.

While less clear-cut than SCSS/CSS, it seems to me that ORMs/SQL have a similar relationship. Frankly, without knowing SQL, you can't hope to competently use an ORM; you won't know what sort of queries and updates it's capable of or what its performance characteristics will be, let alone more subtle stuff like what indexes to create or how the database's transaction model works. But even once you DO understand the SQL layer, getting to grips with how ORMs work is a major additional hurdle.

For that reason, while I am comfortable using an ORM for projects I work on, I wouldn't recommend that a beginner do the same. If I did, I'd be doubling the amount they have to learn, and creating a risk that they'll give up in despair trying to figure out how something poorly-documented works at the ORM layer because they don't have the knowledge of the underlying SQL layer to intuitively guess what their ORM code must be doing under the hood.

It's perhaps more radical than anything I believe, but I think you can reasonably go further and make the case that the extra learning curve imposed by ORMs is not worth the minor convenience benefit they offer to the proficient, and that for that reason, it's generally better not to use them. The fact that they leak the entire layer underneath them is part of that argument, but not all of it; the other part is that the layer they build on top of that is difficult-to-learn and only adds a small bit of convenience in exchange.

XCabbage··on Sweden reopens Assange rape investigation, to seek extradition
Citation?
XCabbage··on WikiLeaks Founder Charged in Computer Hacking Conspiracy
The press release makes it sound like the entire extent of Assange's involvement in the "conspiracy" was making offhand remarks that the government asserts encouraged Manning:

> During the conspiracy, Manning and Assange engaged in real-time discussions regarding Manning’s transmission of classified records to Assange. The discussions also reflect Assange actively encouraging Manning to provide more information. During an exchange, Manning told Assange that “after this upload, that’s all I really have got left.” To which Assange replied, “curious eyes never run dry in my experience.”

If true, it seems to me like there's no meaningful difference between this and a newspaper approvingly publishing a leak, which I thought was meant to be protected in the US under the First Amendment.

If false, and there's more to it than the press release implies, then the authors of the press release are deliberately trying to make the case sound petty and vindictive, and falsely give the impression that merely making approving remarks about leakers while working with them is a crime - presumably for the chilling effect that this will have on others.

Neither option seems to reflect well on the government.

XCabbage··on U.K. unveils plan to penalize Facebook and Google for harmful online content
And I would be among those mocking the idea, but that's because I think:

1. The supposed harms of particular lies are frequently overblown.

2. The outright lies that have the most potential to do damage to society are those that get peddled by the mainstream media and believed by huge swathes of society, but the conventional "fake news" narrative of progressives focuses instead on obscure dedicated fake news sites run by Russians.

3. The proposed cures for this supposed evil of "fake news" all involve giving large institutions the role of determining what is true and censoring all dissent. That is a recipe for a society whose beliefs are far more divorced from truth than the one we currently live in, not less.

None of that is equivalent to the claim that literally no harm is ever done by lies in the news. I don't think anyone believes that, and I think you're badly misreading those of us who are contemptuous of the "fake news" narrative if that's the interpretation of our views you've walked away with.

XCabbage··on U.K. unveils plan to penalize Facebook and Google for harmful online content
"If [strawman] then [you are wrong because your strawman is stupid]" is not a persuasive argument.
XCabbage··on Dan Robbins, artist who created the paint-by-numbers idea in Detroit, dies at 93
A cynical part of me suspects this idea would get patented nowadays and never take off as a consequence.
XCabbage··on Google may rank sites for queries that don't appear on the page at all
But does this happen because Google is ranking those results above ones that matched both words, or because nothing on the web matches both words? I'm often unsure what's going on when I experience this.
XCabbage··on It is unlikely that built-in email encryption will ever be available in Gmail
> "the CC feature in itself might be a GDPR violation" is a, to use your words, "retarded" idea

Well, yes, I agree.

> This is classic GDPR fear mongering

Well, no. The person who suggested that it's a violation is anti-email, not anti-GDPR; it's implicit that they think it would be a good thing if the CC feature were inherently illegal.

XCabbage··on It is unlikely that built-in email encryption will ever be available in Gmail
Eh? Nobody mentioned mailing lists except you. The guy who brought up GDPR was suggesting that the CC feature in itself might be a GDPR violation. You, on the other hand, are talking about a specific use of CC that people broadly agree is wrong, but presenting that as if it's the same thing as what the first guy said.

This is like somebody calling for a law that bans all cars, someone else calling that retarded, and you coming along and saying Why exactly is it retarded not to drive on the pavements? That's what roads are for!

XCabbage··on Chromium: Secretly stores referer and url for downloaded files (2017)
If an open standard has features that violate user privacy and don't provide sufficient value in exchange to justify it, it's reasonable to discuss violating or reforming that standard for the sake of privacy. The existence of a standard doesn't make the privacy issue go away.
XCabbage··on FBI accuses wealthy parents in college-entrance bribery scheme
I'm happy to concede that it's a violation of the ideal of meritocracy, and already did. But so, for that matter, is buying your child a private jet or buying your child health insurance that others can't afford. It's the fact that money is being spent by a parent on a child who hasn't earned it that makes it unmeritocratic. The case of this being done for a university place is still not special, and it's still not corrupt.
XCabbage··on FBI accuses wealthy parents in college-entrance bribery scheme
It's not "bribing" the school, because what's being paid for is something that the school has the right to give. This comment makes about as much sense to me as saying:

> So, to recap, paying someone to steal my car is bad, but paying me to give you my car is fine. Got it.

XCabbage··on FBI accuses wealthy parents in college-entrance bribery scheme
While this is technically true, it's irrelevant to the comment of mine you're replying to, which had nothing to do with legality in the first place.
XCabbage··on FBI accuses wealthy parents in college-entrance bribery scheme
> It doesn't look to me like paying an admissions officer to admit your child is a crime at all.

I have not had a chance yet to look properly at the case, but I'd assumed the "fraud" charges are for precisely the act of paying an admissions officer to admit a child. Do you have reason to think that's not the case?

> bribing a maitre'd to seat you more quickly is bribing a specific employee to act against the interests of his employer, but it's not a crime

It's petty enough you wouldn't expect anyone to be prosecuted over it, but are you sure it's not a crime?

XCabbage··on FBI accuses wealthy parents in college-entrance bribery scheme
Why is this any more corrupt than any other exchange of services for money?

Yes, there's a system available to the masses that the super-rich are bypassing using their wealth. The same is true of anyone who flies by private jet, or anyone with private health insurance in a country where the vast majority of the population uses the public health system. Are these things "corrupt"? What's different here?

If there's no dishonesty and nobody is harmed, what's the moral issue? Why are universities, unique among all society's institutions, required to operate as perfect meritocracies?

XCabbage··on FBI accuses wealthy parents in college-entrance bribery scheme
Donating a building is a payment to the university. The university then gets to decide to admit your child in return. It may not be meritocratic, but it's not corrupt (except perhaps insofar as by pretending the exchange is a donation, the university and donor manage to cheat the taxman). The donor is simply paying the university to provide a service that they have every right to offer for money. It also benefits other students, which is why the universities take the deals in the first place.

In this case, we're talking about bribery of specific employees to act against the interests of their employer. That's simply corruption.

They might be equally non-meritocratic, but they're definitely not equally dishonest or equally socially harmful.

XCabbage··on W3schools.dev Redirects to Mozilla Developer Network
> w3 is probably correct > It's hardly W3's fault

Note that W3Schools is not the W3, and have no official affiliation.

> They are dumb because it really makes no difference. ... getting butt hurt because of a "Tip"

It does make a difference. If that tip had been true, it would mean I'd been writing HTML that only worked in a subset of browsers the whole time, and I would've needed to go over all HTML forms I'd ever written and correct them to ensure browser compatibility, and educate my colleagues who also left off the attribute. Are you suggesting that I should read something like that, that if true would mean that all the forms I've written are broken, and just ignore it? Or blindly trust it, and demand that my colleagues change their code style on the basis of an unsubstantiated "tip"? What was I meant to do other than dig deeper to try to find out the truth?

> W3Schools gave you the information litterally from teh HTML4 spec

Yes. Which has been obsolete for years, and yet their page isn't updated.

> I checked the W3Schools page and it literally says "Note: Only Firefox supports colspan="0",..." Contrary to what is in your StackOverlflow post

I literally quote the same passage in my post and note, explicitly, that it is untrue. Firefox's behaviour is just like all the other browsers.

Also, a moment ago you were berating me for taking an aside seriously. Now you're also berating for not scrutinising every aside for caveats that contradict the main documentation? It's unclear that there's any approach to reading W3Schools that will satisfy you, other than magically divining the truth from their docs even when what they write is wrong.

> People just need to learn to read

Evidently.

XCabbage··on W3schools.dev Redirects to Mozilla Developer Network
Three observations:

1. These problems caused actual confusion for real developers doing ordinary web development work. One of the linked questions has hundreds of thousands of views.

2. You suggest I'm being a pedantic dick to people who are "helping others", but W3Schools doesn't help anyone - at least compared to the counterfactual of them not existing. It would hypothetically be right to say "okay, they have errors, but they're better than nothing" if the realistic alternative was "nothing". But the realistic alternative is that MDN would rise to the top of search results. The complaints about W3Schools' accuracy come in the context of them having skillfully SEOed their content above basically everything else, including huge amounts of not-for-profit content that is vastly superior to theirs. That does cause their very existence to do damage to the world, and make them worthy targets of criticism.

3. Remedying the point about the behaviour of colspan in real browsers being misdocumented doesn't require W3Schools to "write a novel" about anything. It just requires to them to remove content they've included which is false.

XCabbage··on W3schools.dev Redirects to Mozilla Developer Network
Lots of people are commenting to say that W3Schools is now fine. I disagree. On the rare occasion that I end up interacting with them in some way, I find errors.

My Stack Overflow post history contains three mentions of W3Schools, all of which involve W3Schools making an error:

* https://stackoverflow.com/q/20610930/1709587, about W3Schools stating falsely that it's necessary to explicitly add `type="submit"` to submit buttons in HTML to ensure cross-browser compatibility.

* https://stackoverflow.com/a/52355253/1709587, in which W3Schools makes false claims about the `colspan` attribute - both about what the specs say about it, and about how browsers implement it.

* https://stackoverflow.com/a/46866568/1709587, where W3Schools suggests a JavaScript function to shuffle an array which both technically invokes undefined behaviour under the ECMAScript standard and which does not fairly shuffle arrays in practice in real browsers.

None of these things are fixed. The fact that they tidied up the specific errors that the W3Fools team listed, in response to the biggest ever hostile PR campaign that W3Schools ever faced, does not mean that they are now a decent, error-free source. Far from it.

XCabbage··on W3schools.dev Redirects to Mozilla Developer Network
Yeah, but that approach is annoying and pointless. Typing that is no faster than scrolling past the w3schools results when they appear, so why would I do it?

I Google loads of stuff each day. I want to drop w3schools from all my results, automatically.

XCabbage··on Full-stack developers are in fact stuck at mid-level. Don’t go down that path
That's arguably true. But if it's what the parent comment meant, then it's illogical for him to deride another programmer as a failure for a post where he admits that working full-stack has led to him not internalising things like the details behind types of SQL indexes.
XCabbage··on Full-stack developers are in fact stuck at mid-level. Don’t go down that path
When you say

> My understanding of how software is built surpasses any language specifics

do you mean that sure, you don't understand all the language specifics, but that's unimportant because you understand the high level? Or do you mean that you keep track in detail of developments in each of the five languages you've listed (to the level of detail of reading all their release notes and testing every new feature, knowing about the characteristics of all different flavours of index in SQL databases, and knowing best practices for managing state in React components, as suggested in the article)?

If the latter - if you truly have an encyclopaedic knowledge of every tool you use - then, well, congratulations, but I hope you realise that nearly all of us who work with a diverse array of technologies never achieve that mastery.

But if, on the other hand, you're casually conceding that you also don't have the low-level mastery of the tools you use that you would if you worked with only one of them every day, then... maybe you shouldn't be disdaining the author as a failure for failings that you also have?

XCabbage··on Full-stack developers are in fact stuck at mid-level. Don’t go down that path
Why? Old-school pre-ES6 explicit prototype wrangling was confusing, but what's wrong with using inheritance if you're writing in TypeScript (or, for that matter, a JavaScript version with classes)?
XCabbage··on Falsehoods programmers believe about economics (2016)
Obnoxious. The other "Falsehoods Programmers Believe" taught me things I didn't know and pointed out mistakes I'd made in the past. This is just a load of patronising progressive preaching which teaches me nothing.
XCabbage··on Ask HN: Is it just me, or is CSS too damn hard?
I don't see get why anyone thinks that CSS skills and design/UX skills somehow go together. It seems to me that the skills needed to write CSS have more in common with those needed for programming than for UI design.
XCabbage··on 35-year-old vulnerability discovered in scp
I've been a web developer for over 5 years and never once worked somewhere where I'd have any imaginable way of physically accessing the disk of a server. Everything's been cloud-based. I don't know the exact ratios, but I'd expect my experience not to be unusual.
XCabbage··on 35-year-old vulnerability discovered in scp
Yeah, I thought that sort of quip might come along. ;)

On the one hand, you have a real point. On the other, JavaScript running in my browser has significantly less power to do anything bad to me than arbitrary executable programs running directly in my OS do.

XCabbage··on Security Checklist
I don't get it. The word "whitelist" doesn't appear anywhere on the page, for me. Has the content changed? Or are you sincerely suggesting that nobody should ever load a webpage from a non-trusted domain?
XCabbage··on 35-year-old vulnerability discovered in scp
What you're missing is very simple: downloading files from a server need not imply that you trust the server even slightly. That's true whether you're downloading them via HTTPS (e.g. to view this web page) or via SCP.

Many of us have jobs in which we typically only use SSH to connect to servers that we trust and control. But that assumption is no more baked into the security model of SSH than it is into the security model of HTTPS. The argument that "you trusted this server enough to connect to it and download a file, therefore you clearly should trust it enough to permit it to execute arbitrary executables on your machine" is false in both cases.

XCabbage··on Most of What We Read on the Internet is Written by Insane People
Okay. Still doesn't change anything. Stack Overflow has officially made plenty of official announcements on political issues that I oppose, despite being an active user.
← PreviousPage 5 of 7Next →