HNHacker News
TopNewBestAskShowJobs

blub

8,878 karma · joined June 22, 2009

submissionscomments
blub··on C Is Best (2025)
There was an interesting video on YT where an engineer from a fastener company joined a carpenter to compare their products with traditional joints.

The traditional joints held up very well and even beat the engineered connectors in some cases. Additionally one must be careful with screws and fasteners: if they’re not used according to spec, they may be significantly weaker than expected. The presented screws had to be driven in diagonally from multiple positions to reach the specified strength; driving them straight in, as the average DIYer would, would have resulted in a weak joint.

Glue is typically used in traditional joinery, so less glue would actually have a negative effect.

blub··on C Is Best (2025)
Google have published a couple high-level Rust blog posts with many graphs and claims, but no raw data or proofs, so they haven’t demonstrated anything.

By now their claims keep popping up in Rust discussion threads without any critical evaluation, so this whole communication is better understood as a marketing effort and not a technical analysis.

blub··on AI will make formal verification go mainstream
In practice it would be encoded in comments, automated tests and docs, with varying levels of success.

It’s actually similar to tests in a way: they provide additional confidence in the code, but at the same time ossify it and make some changes potentially more difficult. Interestingly, they also make some changes easier, as long as not too many types/tests have to be adapted.

blub··on AI will make formal verification go mainstream
There’s two types of slowdown at play:

a) It’s fast to change the code, but now I have failures in some apparently unrelated part of the code base. (Javascript) and fixing that slows me down.

b) It’s slow to change the code because I have to re-encode all the relationships and semantic content in the type system (Rust), but once that’s done it will likely function as expected.

Depending on project, one or the other is preferable.

blub··on AI will make formal verification go mainstream
> No one claims that good type systems prevent buggy software. But, they do seem to improve programmer productivity.

To me it seems they reduce productivity. In fact, for Rust, which seems to match the examples you gave about locks or regions of memory the common wisdom is that it takes longer to start a project, but one reaps the benefits later thanks to more confidence when refactoring or adding code.

However, even that weaker claim hasn’t been proven.

In my experience, the more information is encoded in the type system, the more effort is required to change code. My initial enthusiasm for the idea of Ada and Spark evaporated when I saw how much ceremony the code required.

blub··on Rust in the kernel is no longer experimental
Interesting, I was also thinking of the similarities with Jehovah’s witnesses. It’s as if they somehow got into the building, were offered a job and now want to convince everyone of the merits of technical salvation.

Rust the technology is not bad, even though it is still complicated like C++, has rather poor usability (also like C++) and is vulnerable to supply-chain attacks. But some of the people can be very irritating and the bad apples really spoil the barrel. There’s a commenter below gleefully writing that “C++ developers are spinning in their graves”. Probably slightly trolling and mentioning C++ doesn’t make sense in this kernel context, but such hostile, petty comments are not unheard of.

blub··on Rust in the kernel is no longer experimental
C++ devs don’t care what the Linux kernel’s written in.

But I did see an interesting comment from another user here which also reflects my feelings: Rust is pushed aggressively with different pressure tactics. Another comment pointed out that Rust is not about Rust programmers writing more Rust, but “Just like a religion it is about what other people should do.”.

I’ve been reading about this Rust-in-the-kernel topic since the beginning, without getting involved. One thing that struck me is the obvious militant approach of the rustafarians, criticizing existing maintainers (particularly Ts’o and other objectors), implying they’re preventing progress or out of touch.

The story feels more like a hostile takeover attempt than technology. I also think that many C or C++ programmers don’t bother posting in this topics, so they’re at least partially echo chambers.

blub··on Has the cost of building software dropped 90%?
Business and Enterprise plans have a no-training-on-your-data clause.

I’m not sure personal Claude has that. My account has the typical bullshit verbiage with opt-outs where nobody can really know whether they’re enforceable.

Using a personal account is akin to sharing the company code and could get one in serious trouble IMO.

blub··on The C++ standard for the F-35 Fighter Jet [video]
Maybe the EU shouldn’t have transformed themselves into US vassals then.

Nobody respects weakness, not even an ally. Ironically showing a spine and decoupling from the US on some topics would have hurt more short term, but would have been healthier in the long term.

blub··on The C++ standard for the F-35 Fighter Jet [video]
Actually these kinds of projects are chronically over budget and the US military is notorious for wasting money.

Using C++ vs wishing an Ada ecosystem into existence may have been one of the few successful cost saving measures.

Keep in mind that these are not normal programmers. They need to have a security clearance and fulfill specific requirements.

blub··on The C++ standard for the F-35 Fighter Jet [video]
The exact opposite of what you suggest already happened: Ada was mandated and then the mandate was revoked. It’s generally a bad idea to be the only customer of a specific product, because it increases costs.

> And the F35 and America's combat readiness would be in a better place today with Ada instead of C++

What’s the problem with the F35 and combat readiness? Many EU countries are falling over each-other to buy it.

blub··on Covid-19 mRNA Vaccination and 4-Year All-Cause Mortality
Comparing accurate communication with magic is nonsense.

Both in Europe and the US, the government screwed up badly both mask strategic stockpiles and procurement. Therefore, the official message was that “masks don’t work”. After they were finally able to procure masks, they magically started working. That is the real magic, not demanding competence for people whose jobs were literally not fucking this up.

Meanwhile China and South Korea were producing and using masks as was normal.

The second magical part is the gaslighting about the performance of institutions tasked with pandemic preparation and about the exaggerated and incompetent government measures like fining people for going outside, forbidding people from going to work without being vaccinated or mandatorily tested each day, etc.

Vaccine safety issues were consistently downplayed by the media and in internet forums like this one. In the end, the EU-CDC published clear information on the safety of the AstraZeneca vaccine and it was much worse than for mRNA vaccines. One mRNA vaccine was worse than the other.

blub··on Covid-19 mRNA Vaccination and 4-Year All-Cause Mortality
No, severe swelling and pain, which in the case I know about resulted in a hospital visit.

More info: https://www.thieme-connect.de/products/ejournals/pdf/10.1055...

Fortunately doctors and medical organizations usually take these matters seriously, unlike the average techbro. A good example is how the vaccination recommendations were changed to avoid Moderna for young men to reduce the risk of heart problems.

blub··on Covid-19 mRNA Vaccination and 4-Year All-Cause Mortality
“Doesn’t kill you” is the absolute bare minimum and a very low bar. Because the vaccines were so rushed, it’s still reassuring, but not at all a testament to the safety of mRNA vaccines.

The more interesting studies will be about non-lethal adverse reactions. Changes to menstruation, heart problems, lymph node swelling to name just a few.

blub··on Hardening the C++ Standard Library at scale
The implementations of hardening in libc++ and libstdc++ are available now and are straightforward to use.

https://libcxx.llvm.org/Hardening.html

https://gcc.gnu.org/wiki/LibstdcxxDebugMode (was already available for longer, the official hardening might take this over or do something else)

blub··on Hardening the C++ Standard Library at scale
They rival Rust in the same way that golang and zig do: they handle more and more memory-safety bugs to the point that the delta to Rust’s additional memory-safety benefits doesn’t justify the cost of using Rust any more.
blub··on Hardening the C++ Standard Library at scale
> There is just so much unmodern and unsafe c++ out there. Mixing modern c++ into older codebases leaves uncertain assumptions everywhere and sometimes awkward interop with the old c++

Your complaint doesn’t look valid to me: the feature in the article is implemented with compiler macros that work with old and new code without changes.

See https://libcxx.llvm.org/Hardening.html#notes-for-users

blub··on Migrating the main Zig repository from GitHub to Codeberg
“We build free software so we can tell you to go fuck yourself.”

Sounds like a great thing compared to the sanitized corpo bullshit from nowadays. Microsoft bought themselves into OSS with github and each project has a bland CoC.

It’s pathetic. Even the github monkeys know deep down that this is wrong.

blub··on Several core problems with Rust
It has potential to be the new thing, since several details synergize to make this incident more powerful:

1. Previous claims that Rust code often just works after compiling.

2. Previous claims that low-level error-handling idioms like matching, using Result, etc improve code reliability.

3. Previous claims that using unwrap in example code is ok for brevity. Also, Rust developers would know not to use it in production code.

4. The fact that significant portions of the internet were taken down because a production unwrap from a big, mature player and one of the Rust early adopters.

Sure, Rust is not the problem here, but rather Clownflare being too big and not having their SRE processes fully up to par for their size. Perhaps they are simply too big to operate at the needed level of reliability. However, Rust anti-fans can easily ignore the above and simply press the issue and debate the minutiae of error handling, human reliability, etc. It’s surprisingly effective and might even catch the ear of management.

However, this article is overall not at the level expected of Rust anti-fans in 2025. I commend the author for trying, but they need to improve in several areas like providing iron-clad real-world examples, proving the required level of experience, focusing more on pain points like dependencies and the potential for supply-chain attacks, addressing reskilling issues and internal corporate politics, etc. There was a blog by a veteran Rust game developer a while back which single-handedly destroyed the enthusiasm for Rust in gaming. That is the gold standard of Rust criticism for me.

blub··on Rust in Android: move fast and fix things
You’re mixing up developers becoming more competent with the language becoming easier.

Neither C++ nor Rust are becoming easier unless new features are added which make them simpler to use in some circumstance.

C++11 & co did make many things simpler. For Rust I don’t know the details of what’s upcoming; it doesn’t seem to be getting simpler.

blub··on Rust in Android: move fast and fix things
I peruse Android system code at work and their C++ code base is not designed for safety. It’s just typical C++ code as any large company would write it.

And for a large juicy target like Android, that won’t be good enough to stay ahead of the attackers long term.

Of course, tools like Fil-C or hardware-based security might make Rust vs. C or C++ moot.

Edit: your comment makes a good point. Shame that trigger-happy (c)rustaceans are downvoting everything in sight which is not praising this PR piece disguised as a technical blogpost.

blub··on Rust in Android: move fast and fix things
If the C++ code I worked on looked like that[1] and was actually C with classes, then I’d be switching to Rust too. For Google and Microsoft it probably makes sense to rewrite Windows and Android in Rust. They have huge amounts of legacy code and everybody’s attacking them.

It doesn’t follow that anyone else, or the majority has to follow then. But that’s predictably exactly what veteran rustafarians are arguing in many comments in this thread.

[1] Pointers getting passed all over the place, direct indexing into arrays or pointers, C-style casts, static casts. That (PVOID)(UINT_PTR) with offsetting and then copying is ridiculous.

blub··on Rust in Android: move fast and fix things
The pain will always remain when refactoring or changing code, with modifications cascading in the function and type definitions.

If a language is hard to write at first, it’s always hard to write. The saving grace of C++ is that one mustn’t use the overcomplicated functional aspects, template meta-programming, etc. Through some amazing circumstances, all of the above (or their equivalents) + async is exactly what idiomatic Rust code has become.

Inside Rust there is a not so ugly language that is struggling to come to light and it is being blocked at every step.

blub··on Memory Safety for Skeptics
All of that stuff doesn’t matter though. If you look close enough everything is different to everything, but in real life we only take significant differences into consideration otherwise we’d go nuts.

Memory bugs have a high risk of exploitability. That’s it; the threat model will tell the team what they need to focus on.

Nothing in software or engineering is absolute. Some projects have decided they need compile-time guarantees about memory safety, others are experimenting with it, many still use C or C++ and the Earth keeps spinning.

blub··on Memory Safety for Skeptics
This whole memory-bugs-are-magical thinking just comes from the Rust community and is not an axiomatic truth.

It’s also trivial to discount, since the classical evaluation of bugs is based on actual impact, not some nebulous notions of scope or what-may-happen.

In practice, the program will crash most of the time. Maybe it will corrupt or erase some files. Maybe it will crash the Windows kernel and cause 10 billion in damages; just like a Rust panic would, by the way.

blub··on Memory Safety for Skeptics
Sounds like a straw-man. I know developers who are good enough to achieve it on their own, but they use the tooling anyway, because one can’t write perfect code always: feature requests might be coming in too fast, team members have different skill levels, dev turnover happens, etc.

Furthermore, memory bugs still can be considered by teams as just another bug, so they might not get prioritised.

The only significant difference is that there’s lots of criminal energy targeting them, otherwise nobody would care much.

blub··on Valdi – A cross-platform UI framework that delivers native performance
It’s a bad idea to put the fox (front-end developers) to guard the henhouse (great, consistent user experiences).
blub··on Rockstar employee shares account of the company's union-busting efforts
It’s an amazing game. They released buggy because of management pressure, but fixed it.

GOG is also amazing.

blub··on Affinity enshittification: How Canva's "Four Pledges" aged like milk
For casual users and likely some pro users, there’s still Pixelmator Pro and Acorn. I used to use Photoshop CS for web design many years ago and they’re good enough for that.

This Canva app’s so dumb, even their log-in doesn’t work. I wanted to log in once and then keep it offline, in the hope that they would keep their promise and allow long offline use. If it’s so buggy it will probably accidentally log itself out after a few days.

blub··on Hard Rust requirements from May onward
The general problem is that there’s a lot of activists online nowadays. I used to call myself an activist, but now it’s a dirty word which I associate with obsessive behaviour, harassment, cancellation attempts and being generally obnoxious with the purpose of achieving some goal.

I think it’s a combination of religion decreasing in importance and social media driving people mildly nuts. Many undertakings are collecting “true believers”, turning into their religion and social media is how they evangelize.

Rust is a pretty mild case, but it still attracts missionaries.

So, the people are different, Western society’s different and social media’s giving everyone a voice while bringing out the worst in them.

← PreviousPage 3 of 34Next →