HNHacker News
TopNewBestAskShowJobs

avolcano

3,882 karma · joined March 12, 2011

I write JavaScript and Python and other languages sometimes.

website: thomasboyt.com

submissionscomments
avolcano··on A Picture of Java in 2020
I wrote a comment about this a couple months ago: https://news.ycombinator.com/item?id=23355513

I'm still planning to write a longer blog post about it with more details. I think in terms of enterprise usage, there is no equivalent to a batteries-included framework like Spring Boot - especially not one with paid support available for big companies.

avolcano··on A Picture of Java in 2020
My takeaway from this is "I should probably bite the bullet and learn about Spring Boot." I started writing server-side Kotlin about a year ago and find the JVM ecosystem mostly really nice (leagues better than the Node/TypeScript world I escaped from - as much I still like writing TS on the frontend, server-side TS is still too immature to recommend), but I could not wrap my head around Spring/Boot. My understanding is that Spring Boot wraps a bunch of the same libraries used in Spring MVC into an easier to comprehend package, but it still seemed like a very intimidating ecosystem.

I went ahead and used Javalin, which I'm a little bummed to not see represented on the survey - it's meant as a successor to Spark (which I haven't used), and I really like it. It uses similar patterns to Koa/Express in Node, which made it easy to understand. The big downside of not using an integrated ecosystem like Spring Boot, of course, is more glue code, but I actually haven't found it _that_ bad.

avolcano··on Bevy 0.2
Something delightful about this update: it has a lot of new features, some very early, but all by different authors. Seems like such a community effort compared to most early-stage projects, which usually are driven by one author in relative secret until they are closer to some dream "1.0".
avolcano··on Nova by Panic
It's so hard to target web development with how fragmented the ecosystem is, so it's nice to see they have a lot of extensions already.

That said, because of how fragmented the ecosystem is, it is difficult for me to jump in. For example, my main side project right now is a Vue app that uses SCSS syntax in components, which the Vue extension for Nova does not yet support. This might sound like a small detail, but it's a total dealbreaker - and while, if this was a totally open source editor, I might be interested in contributing to the extension, I can't say that I'm interested in paying $100 and then helping out. It's a very difficult chicken and egg situation.

avolcano··on At JPMorgan, productivity falls for younger employees at home
This has been a massive issue for me. I've had the same problem off-and-on over the past few years, whether in offices or at home. The work I do feels rather pointless in a world collapsing around me with no short or long term future. I at least sometimes get pulled back into feeling good about what I work on because it's a consumer app that does have a large userbase that depends on it for their happiness, and I do feel good about contributing to that, but if I was working in finance? No way.

Anyone who has been able to stay productive, let alone get more productive, in this reality is either in denial or far more optimistic than I'll ever be.

avolcano··on Nikola: How to Parlay an Ocean of Lies into a Partnership with GM
"Hindenburg Research" is already an excellent name for a short seller, but in this case, they are short selling a company creating cars powered by hydrogen fuel cells. 2020 continues to be an incredibly on-the-nose year.
avolcano··on A Superspreading Event: The Sturgis Motorcycle Rally and Covid-19 [pdf]
The amount of travel involved in this thing is staggering:

> The cellphone tracking data showed about 10% of Sturgis attendees hailed from within South Dakota, with about 19% from border states and 72% from across the rest of the country, with heavy attendance from Arizona, California, Colorado, Iowa, Minnesota, Nebraska, Washington and Wyoming.

I find this aspect far more upsetting than the stupidity of the event itself. It's one thing when a bunch of locals decide to congregate in an environment they really shouldn't be, but another thing entirely when it's 400,000 people biking across the country.

Ironically - or perhaps not - I saw an NPR article ~a week ago[1] indicating the infection rate in Sturgis and its county, while certainly higher than it was before the rally, wasn't as catastrophic as you'd expect. Apparently, many people who live in Sturgis left town or just tried to avoid contact with anyone that weekend. Can't find any up to date information on whether the infection rate has increased since then with more time/testing, though.

[1] https://www.npr.org/sections/coronavirus-live-updates/2020/0...

avolcano··on Costs of running a Python webapp for 55k monthly users
Nice writeup! Always appreciate transparency with these sorts of things, as someone who writes a lot of tiny personal projects and sometimes wonders how much I'd have to invest if they ever actually gained any traction. Congrats on having so many users, and good luck on monetization.

For the server instances, I can't imagine 4 CPUs/8 gigs RAM is really needed 24/7, but can imagine it being needed in bursts, and I assume GCP has various "elastic" auto-scaling products for that. Would love to know if your metrics indicate that this is the smallest box you could comfortably run on, or if it's just a best-guess. Could potentially spin down blue-green environments after some set amount of time (once you know a deploy "succeeded"), as well.

For Metabase, I can't find any "system requirements," but I'm not _super_ shocked by the price tag. I've always liked the idea of hosting my own tools instead of relying on some SaaS's free/trial tiers (particularly for things like analytics, logging, or metrics), but a lot of the open source options out there assume you have a pretty hefty box to throw it at. At the same time, I haven't found any better alternative other than just doing ad-hoc analyzing in SQL (using a GUI like Postico).

avolcano··on Gitlab reducing free tier CI/CD minutes from 2000 to 400 minutes
$4/mo for 2000 minutes is reasonable. GitHub Actions does 2000 minutes for free/3000 minutes for $4, wonder if they'll drop their free tier a bit without the competition.
avolcano··on Patreon Raises $90M Series E at $1.2B Valuation
The two questions to me are (a) what content will they ban and (b) how badly do they want to increase their cut of pledges?

For (a), they've already banned a lot of adult content (thus the rise of OnlyFans, until they follow suit), and they'll probably ban more if they get enough attention from either media, angry card processors, or both.

For (b), they've already narrowly avoided fucking this up once back in 2017 (https://blog.patreon.com/updating-patreons-fee-structure). They increased fees in 2019 (https://support.patreon.com/hc/en-us/articles/360024952552-P...) but at least grandfathered in past users, preventing their existing userbase from being too much of a flight risk.

avolcano··on GitHub Container Registry
This is good to hear, and makes sense to me. I'll also admit that, now that I've thought it over, I'm doing a bit of apples-to-oranges comparison, given the $4/mo is not just "for 2 gigs of storage," since it also includes Actions minutes and I think a few other bonus features (private wikis?). At that point, it's more fair to compare it to what e.g. GitLab offers, than what you'd get from Azure Container Registry or similar.

I'm not sure the Container Registry on its own will necessarily be attractive to people just looking for commodity-priced container storage, but GH Actions + Container Registry does make for a pretty compelling CI/CD story, I have to admit.

avolcano··on GitHub Container Registry
I'm sad that you quoted that sentence without linking to the grim story that it referenced, which I hadn't heard before: https://gigaom.com/2014/06/30/the-dark-side-of-io-how-the-u-...
avolcano··on GitHub Container Registry
Good callout. The GitLab.com registry has a "soft cap" of 10 GB, which seems like plenty of room for most projects, as long as you don't require a long history.
avolcano··on GitHub Container Registry
Nice to see the registry is free for public images, but does anyone know where I can see pricing for private images? Is it still the same as the packages pricing[1], because 2 gigs seems incredibly low storage space when it comes to Docker images, right?

To me, the price to beat is the $0.04-$0.20 a month I pay for Google Container Registry (price depending on whether I remember to go back and delete older images or not). I'm guessing it's not going to get to that level of commodity priced, but I don't see this product being competitive without giving a heck of a lot more space for cheaper.

[1] https://github.com/features/packages#pricing

avolcano··on YouTube please give back option to stop seeing an ad
The particularly fascinating aspect of this I haven't seen discussed is that every other ad I've ever seen on Youtube has a "stop showing me this" option. Trump ads do not. I had no idea that "feature" could be disabled with a high enough sale.

I've stopped using the Youtube app on my iPad since I have no way of blocking ads there (probably what's going to get me to finally set up a Pi Hole).

avolcano··on Facebook account now required to login to Oculus devices
Facebook has a policy where they can arbitrarily ban you for failing to "prove your identity" if they believe your account does not use "the name you go by in real life." One of the ways they ask you to prove your identity is to send in a license.

Unsurprisingly, this ends up hurting all sorts of people who do not use their legal names online: people who have just chosen other names, people who want to avoid being targeted or stalked, trans people, etc. They've updated this policy to allow for some of these situations (https://www.cbc.ca/news/technology/facebook-real-names-1.336...) but folks still get banned for failing to comply.

avolcano··on Apple announces Apple Music radio
Thanks for this rec! I see it's also actually archived on Apple Music as well, which is nice. Really wish Beats 1 surfaced their non-celeb-hosted shows like... literally anywhere in the Browse interface.
avolcano··on Apple announces Apple Music radio
They've been running Beats 1 for the last 5 years (now rebranding to just Apple Music 1). I like the idea of a pop & pop-adjacent radio station with a lot of different shows for different subgenres (it's obviously patterned after BBC Radio 1), but it never seemed to have the "right" mix of variety, and unlike Radio 1 it didn't really have any tentpole stuff to center around (like e.g. Essential Mix), just a lot of random short-lived celebrity-presented shows. Adding country and pop hits stations isn't exactly going to improve it, but I assume that's for people who found it a bit too left-field.

Kind of astonished it's quietly been on air for so long, and I wonder if the rebranding means they're actually going to revitalize it in some way or if this is just going to lead to them quietly dropping the more interesting aspects of it.

avolcano··on I Love MDN, or the cult of the free in action
Microsoft gates plenty of training content behind Visual Studio subscriptions. Also, who is the "provider" of the web platform?
avolcano··on I Love MDN, or the cult of the free in action
I totally agree with this. I should have clarified that when I say "funding open source," I think of that differently from "paying for software/resources" - this would not involve paying for access, just paying for continued development and maintenance.

Of course, as other commenters have been pointed out, it's hard to sell companies on paying something they "have" for free. Which is why companies will shell out big money for the O'Reilly Learning Platform or MSDN ($500/year/seat for the former!) but not even think about spending money on a community resource.

avolcano··on I Love MDN, or the cult of the free in action
Rather sad the two proposals here are either "giant browser vendors should pay for it" or "independent web developers should pay for it." It's one thing for developers to pay for things that will develop their independent careers, but MDN is a reference as much as it is a learning resource; it's something developers constantly use at their jobs. Their employers, big or small, should be the ones paying for it.

Of course, we all know that asking startups to actually fund open source (whether code, documentation, or learning resources) is like pulling teeth. I'd say maybe the collapse of some larger open source project(s) could convince companies to start actually giving a shit about whether or not the maintainers of the technology their entire businesses rely on have enough money to continue developing said technology, but it's more likely the companies would just say "well, let's put 10 engineers on this problem for a month to replace this dead open source technology with something new and shiny" and not recognize how much more they've had to spend. Or, y'know, they'll go with paid support of a Microsoft product or something.

avolcano··on Ansible 2.10
Ansible has been nice for replacing a bunch of ad-hoc shell scripts for my Digital Ocean boxes for personal projects. I have a bunch of simple provisioning scripts I can re-run as many times as I want, and I have simple deploy scripts that automatically skip unnecessary steps. Cannot imagine a better tool for single-host devops, really - if I were putting together a list of "how to run your own small infrastructure" it'd be higher priority than anything else.

I am curious, as a bit of a devops outsider, how it fits into the toolset of a modern application. From what I can tell, a lot of the aspects of Ansible are made redundant in a world of _hosted_ containers - you don't need Ansible if you're, say, deploying container images to EKS/ECS/whatever - but if you were to self-host your Docker hosts (or... whatever the Kubernetes is equivalent is called), Ansible still seems to me to be the best tool around for standing up and maintaining those hosts.

avolcano··on Mozilla has laid off their dev tools people and the entire MDN team
Firefox Dev Tools were how I sold other devs on trying Firefox. I think the number of devs who liked the tools and stuck by them is the only reason why as much of the web renders well on Gecko as it does. Certainly, I've worked at small startups where no one used Firefox that turned out to have significant visual bugs on Firefox for months, because no one ever bothered to check it out.

I understand why Mozilla wants to make more money new ways. I think everyone does. I was going to get their VPN as soon as it became available on Mac. I also completely understand that they can't monetize Firefox, at least not in its current state. Users would obviously rebel against any kind of proprietary features that live behind a commercial license, and I don't think they can make any compelling hosted services that integrate with Firefox either. But I don't understand why Mozilla seems to be trying to speed along its death.

avolcano··on Inside A £30 Record Player
Yeah, I didn't mean to imply you had to break the bank to avoid damaging your records. And good note on the anti-skate tracking as well!
avolcano··on Inside A £30 Record Player
I'm a pretty casual vinyl listener (mostly got into it since I like having a physical representation of the music I love, and to reclaim some sense of ownership in a world defined by Spotify and Apple Music). I enjoyed this post, and more or less agree with the author's opinion that claims of superior vinyl audio quality are bunk - and particularly meaningless in a world where most new music is recorded or produced digitally in the first place.

That said, I probably still would avoid a cheapo player like this that does not have an adjustable tone arm. For one, it's more likely to have issues skipping when you can't adjust it properly. The second concern - which I'll admit I have no data to back up, and since this is an opinion from the audiophile community, may warrant some skepticism - is that cheap players with unbalanced tone arms are infamous for supposedly wearing down records more quickly over time by applying too much pressure.

The author's note about the stereo output being unbalanced, by the way, is a relatively common side effect of an unbalanced tone arm (though there's various other reasons it can occur).

avolcano··on RBS, Ruby’s new type signature language
apologies, meant to add that as a link when I referenced Stripe in the first sentence!
avolcano··on RBS, Ruby’s new type signature language
You're correct in your assumption you'd need to generate methods, from my quick investigation into how Sorbet handles it - see https://github.com/chanzuckerberg/sorbet-rails for some details.
avolcano··on RBS, Ruby’s new type signature language
Didn't realize Square was interested in Ruby type checking, just like their competitors over at Stripe. Lots of money riding on Ruby, I guess :)

It does seem useful to have a _standard_ for type definitions - RBS as the equivalent to a .d.ts file - as that allows for different type checking implementations to use the same system under the hood. This was a big problem for Flow, and why it lost the fight as soon as TypeScript's definitely-typed repository started gaining momentum - users wanted to use the type-checker that they knew had definitions for the libraries they used.

On the other hand, RBS as hand-written seems rather dangerous, to me. Nothing wrong with using them to define previously-untyped external code, as long as you know the caveats, but I think you really want to have definitions generated from your code. Sorbet cleverly (and unsurprisingly, given it's Ruby) used a DSL for definitions in code, which had the (excellent) additional boost of runtime checking, so you actually could know whether your types were accurate - by far the biggest pain-point of erased-type systems like TypeScript.

Given that Ruby 3 was supposed to "support type checking," I'm surprised that it does not seem to have syntax for type definitions in code, and instead will focus on external type checking. I might be missing a piece of the full puzzle not covered in the blog post, however.

avolcano··on Ask HN: How to nab and block a creepy user?
Many apps nowadays use phone numbers for verifying new accounts. Obviously, it is far from impossible for a malicious user to get a new phone number if they care enough, but it does usually have a monetary cost, which will keep a significant portion of malicious users out. This also can help prevent some forms of fraud.

This is somewhat obvious, but take care in designing social interactions on your app, and introduce easy reporting systems and user-controlled blocking systems (e.g., even if you don't respond to a user's report in a timely manner, a user should still be able to block communications from another user using a button in the app). You may want to allow users to choose to only allow messages from users who have been on the site for a certain amount of time, or have some kind of additional level of verification. Also consider introducing active, paid moderators who actively respond to reports as they come in, if your budget allows.

Allowing users access to open text fields on the internet is inherently dangerous. I have tried to avoid it in all of my apps (for example, I've made games that use randomly-generated user names rather than allow users to input their own, and I only added user comments to an app I was building _after_ I'd built a user reporting system and ensured I got an immediate alert on my phone if a user sent a report). It is your responsibility to try to design your app, and moderate your community, to mitigate these risks.

avolcano··on Amazon Honeycode – build web and mobile apps without writing code
Looks like a competitor to Retool, interesting. The focus on data permissions, mobile support, and push notifications is really interesting because none of those features are ones that Retool focuses on, I believe - those features being front and center makes me think Amazon has looked at the competition and wants to focus on what they offer that others don't, rather than just trying to be yet-another-tool in the space.

On the other hand, I absolutely loathe every single UI that has ever come out of AWS, and there is absolutely no chance I give the editor they've built here a shot without hearing lots of positive reactions first.

edit: actually going to pull back slightly on this comparison, since apparently Honeycomb is a little closer to something like Access, where there is a database _in_ the app, whereas Retool is built around connecting to an external data source (e.g. a SQL database). This surprised me because I assumed the entire reason you'd want an AWS version of this kind of tool is to integrate with the broader AWS ecosystem, like frictionless hookup to a DynamoDB or whatever. It may have this but just not spotlight it on the marketing pages?

← PreviousPage 2 of 14Next →