HNHacker News
TopNewBestAskShowJobs

aenario

221 karma · joined February 27, 2013

[ my public key: https://keybase.io/rmfoucault; my proof: https://keybase.io/rmfoucault/sigs/snvWWQ2yNmKOBrTznbs3dKIE7GzFET99tc2BwWrjOTM ]
submissionscomments
aenario··on Fred Brooks has died
> This whole notion of "documentation can get out of sync with the code, so it's better not to write it at all" is so nonsensical.

I do believe that in a lot of case an outdated, wrong or plain erroneous documentation does more harm than no documentation. And while the correct solution is obviously "update the doc when we update the code", it has been empirically proven not to work across a range of projects.

aenario··on Pokemon Card Animation
You might have some success selling this "technology" to wedding invitation printers and similar websites. They always have trouble demonstrating the various paper options / partial glossy / metalic cut out options
aenario··on Automerge: A JSON-like data structure (a CRDT) that can be modified concurrently
You seem to only conceive of the web as "html+JS frontend communicating in real time to some server"

We have decades of distributed systems without a central server. Such as git, bit-torrent, Mastodon, Matrix, and the whole web3 mess. It's for these use-case that CRDT helps solve real problems.

aenario··on Automerge: A JSON-like data structure (a CRDT) that can be modified concurrently
It's a very narrow use-case of conflict-free data type. Sure if you are willing to wait for however long to get a lock before you can edit something.

The main goal of CRDT is for long-split branch such as can happen in federated systems or with offline management. (think git)

aenario··on WebAssembly: The New Kubernetes?
I think your LAMP (Linux, Apache, MariaDB, Python) is a fancy new LAMP (Linux, Apache, MySQL, PHP).
aenario··on Google fined €150M, Facebook €60M for for non-compliance with French legislation
You are complaining that the allergens information takes room on your restaurant menu.

We the people, through our democratic processes, have asked companies for transparency of their tracking process, the industry have decided as a whole to say fuck off and made the process as painful as possible.

Yes, the companies are evil/stupid villains on this case. Not everything needs bloody philosophy.

aenario··on Google fined €150M, Facebook €60M for for non-compliance with French legislation
It was actually refused by ad & publisher networks. They really wanted the capacity to "convince" the user that their tracking is very special and good for them.
aenario··on One programmer broke the internet by deleting left-pad (2016)
That when you need a given feature, you will more probably find an actively maintained package which cover it and is compatible with the rest of your dependencies/framework.
aenario··on Climate change: IPCC report is 'code red for humanity'
*historically contributed

Will contribute 6-10% of yearly emission in the coming years

aenario··on Who Owns My Name?
"The social network" does not make Mark Zuckerberg look bad. He looks like a poor socially inept nerd who got scammed by Parker, it makes one want to pity him.
aenario··on Cyber Insurance Incident Response: Market tends towards commoditization
The very notion of identity thievery is "BigMoney" (banks and credit rating) putting on their customer the responsiblity of what we used to call fraud.
aenario··on Noyb aims to end “cookie banner terror” and issues more than 500 GDPR complaints
We used to have a Do-Not-Track header, which all websites promptly ignored.

The hard part is having a legally-binding standard

Given the current available API, I'd imagine the law-maker could have decided to write in the law 'consent must be collected through a javascript window.confirm() popup'

aenario··on Man who thought opening a TXT file is fine thought wrong
I can see a way this would be useful to use the same abstraction to limit app/user web access to a single domain.

For instance the dropbox binary can only access "/home/dropbox" and "/net/dropbox.com" if this was more well-known/used.

aenario··on The Deno Company
libuv bindings ?
aenario··on The Drivers Cooperative
The interesting thing about coopcycle is that it's actually a coop of coops :

Several local delivery coops (say one per city) collaborate to fund development and hosting of the software solution.

aenario··on Spy pixels in emails 'have become endemic'
Add buttons in your email - "I want to know more" - "It's too expensive" - "Leave me alone"

All open rate tells you is that your subject line was click-baity but the user have no interest in your content

aenario··on Grindr to be fined almost €10M over GDPR complaint
First of all, it's not "don't do marketing", it's don't do "user-tracking-and-profiling based advertising". Marketing is so much more, like actual market research to provide a service users actually want.

You have to handle a "right to be forgotten" query within a month, surely this is enough time for one sysop to run a prepared query. If your database is so byzantine that you cant find all reference to a given customer, you are either google or in need of a new architect.

Backups do not need to be deleted immediately, they should however expires and be destroyed in accordance to your data retention policy (Say what you do, do as you say).

aenario··on Grindr to be fined almost €10M over GDPR complaint
I'd like to sell you some cough medication, it's all natural, made from a concentrate of two south-american plant called "coca" and "tabaco", everyone who tries keep asking for more, even when we increased the price !

Too bad the big bad governement regulation prevent me from selling it. It's absolutely ridiculous, all my customers wants it and I pay my taxes.

aenario··on Grindr to be fined almost €10M over GDPR complaint
As a company/developer starting from scratch, there is really no complexity nor landmines : Do as you say, Say what you do, Give the user options.

You can offer the user the choice between targeted advertising or non-targeted. You can offer the user the choice between paid subscription or advertising.

Cant get enough users to pay or consent ? Then you did not find market-fit in the real world.

aenario··on No Cookie for You
Then you can lobby to change the law because the users-electors are annoyed and it's not your company fault every website is doing it.
aenario··on French watchdog fines Google, Amazon for breaching cookies rules
The GDPR is actually pretty simple : "say what you do, do what you say, let the user say no"

The clusterfuck comes from every single ad-based business toeing the line in a giant tug of war between PR, legal & revenue.

If google had simply written : " Hey, we have a tracker on almost every website in the world, which we will use to monitor all your browsing habits and share with [this list of 100 other business]. This tracking pay for the app you are about to use. [Continue Tracking] [No thanks] "

They would be fine (legally, not financially), instead they use some king of weird pop-up with no meaning, and they now have to pay the price.

aenario··on French watchdog fines Google, Amazon for breaching cookies rules
Ultimately the only cookie an users will willingly accept is the sessionid/rememberme. And the "remember me" checkbox is consent enough under the GDPR.

Behing all the legalese and marketing-speach, all the other purposes boils down to :

    - We are too lazy to setup a matomo, so we are giving google your browsing pattern. 

    - FB is forcing us, so we can pay ever so slightly less for ads

    - Google is offering to tell us your sex and age

    - If we dont track you, we will show you a viagra ad.

    - Through 4 intermediaries, we can pay this totaly-objective-blog which sent you here.
I'd love to hear from someone with a complex cookie consent pop-up, but i'd bet there is about 80% "accept all" (because the users have been trained to do it) 19% "reject all", and no-one is mixed.

So the do-not-track would have been accurate enough.

aenario··on French watchdog fines Google, Amazon for breaching cookies rules
Not quite sure if this is sarcasm ?

The do not track header is about 10 years old, ans was promptly ignored by all websites

     DNT: 1
     DNT: 0
aenario··on Detecting the use of “curl – bash” server side (2016)
Note that for the leftpad incident, the impact was build faillures, not remote code execution.
aenario··on Show HN: Haxon, CLI tooling to retrieve data from Axon police body cams
I think it's not really meant to be used and more along the line of disproving the fabricant-police claims of these devices being tamper-proof and therefore proper evidences.
aenario··on How Go helped save HealthCare.gov
Unfortunately Java seems to bleed its culture everywhere:

Modern PHP development seems to be about how much of a pyramid of class you can build to serve a single request.

Then you have all the new typescript frameworks, proudly inspired by Spring.

aenario··on Spotify revises TOS to allow transfers of user-created playlists
An alternative is to think of data as dangerous chemicals.

You can acquire it and store it, but you have to follow some procedures : - do not expose your employees to it - do not leak it in the environment

It then falls to the company to make the cost/benefit analysis : is this chemical important enough to our process to justify these hasles.

The data export also does not need to be a perfect API, dump a huge json and let third party handle changes.

aenario··on New iOS privacy feature may end an era of personalized ads
The pro-targeting argument always seems to forget the middle-ground of context-based ads.

This new snowboard company can advertise on snowboard-related websites, on snowboard-related google search

The magic "IA assisted silver bullet retargeting" that this snowboard company will be sold by yet another VC-founded adtech company almost always amount to "Oh this guy just bought a new snowboard, he probably needs another one right now, let's pay a mountain of cash to push him to buy another one on every website he visit for a week"

aenario··on API with NestJS #3. Authenticating users with bcrypt, Passport, JWT, and cookies
Nuxt is Next for Vue.js, so it does make sense. Next and Nest are unfortunate, always need to read it twice to be sure.
aenario··on Ask HN: What's your quarantine side project?
I have been working on typescript runtime reflection https://github.com/aenario/tsmirror
Page 1 of 2Next →