HNHacker News
TopNewBestAskShowJobs

felipemesquita

1,189 karma · joined January 17, 2016

submissionscomments
felipemesquita··on Ruby Was Ready from the Start
Author argues that values long embedded in Ruby culture (testing, readability, design) are very useful for collaborating with AI, gives an example os asking Claude to follow tdd
felipemesquita··on Why I'm not rushing to take sides in the RubyGems fiasco
He writes about controversial topics on his personal blog, and is on the right side of the political spectrum
felipemesquita··on Why I'm not rushing to take sides in the RubyGems fiasco
While I agree, I think that was where Justin’s experience could contribute some nuance to the overall narrative.
felipemesquita··on The Omarchy Manual
I find this recently added rails default a bit too restrictive, especially because iOS doesn’t allow 3rd party browsers and only offers browser updates via system updates:

> In addition to specifically named browser versions, you can also pass :modern as the set to restrict support to browsers natively supporting webp images, web push, badges, import maps, CSS nesting, and CSS :has. This includes Safari 17.2+, Chrome 120+, Firefox 121+, Opera 106+.

https://edgeapi.rubyonrails.org/classes/ActionController/All...

felipemesquita··on The surprise deprecation of GPT-4o for ChatGPT consumers
Are you on the pro plan? I think pro users can use all models indefinitely
felipemesquita··on The surprise deprecation of GPT-4o for ChatGPT consumers
I’m on Plus and have only GPT-5 on the iOS app and only the old models (except 4.5 and older expensive to run ones) in the web interface since yesterday after the announcement.
felipemesquita··on GPT-5 for Developers
I’m not sure yet if it’s better than Claude, but the best way to use GPT-5 it is https://github.com/charmbracelet/crush
felipemesquita··on Jules, our asynchronous coding agent
The codex thing inside ChatGPT, the copilot thing in the github web ui
felipemesquita··on Vanilla JavaScript support for Tailwind Plus
A love letter their rails users indeed. Congratulations to the tailwind team for shipping this! Disclosure
felipemesquita··on Human Stigmergy: The world is my task list
I frequently place my car keys inside or under a thing I need to take with me when I leave. Costs me having to search for my keys, but only in the times when I would have otherwise forgotten the thing.
felipemesquita··on Show HN: BreakerMachines – Modern Circuit Breaker for Rails with Async Support
I’m usually weary of long readmes with too much styling as that indicates to me a high likelihood that they were written by ai and the author might not have even read all of it. The use of generic ai images also gives a bad impression - for example, there’s an image captioned “The green lines? Those are your CPU cycles escaping.” without anything green pictured.

I’m not saying your gem is bad. It’s nice to se an attempt at a circuit breaker that is based on the state machines gem, I will certainly look into the actual code if I have a need for it in the future.

Just wanted to give you this bit of feedback about maybe cutting down on length and loosing the ai images in the readme as I think it might be a turnoff for others as well.

felipemesquita··on The double standard of webhook security and API security
Some do, but it either involves an additional secret specific for this purpose, or it burdens the client with controlling access and exposure of incoming request headers (in logs and middleware) since they would include the token that can actually make api calls to the vendor.

Nevertheless, your question would have yielded a better article.

> but why do we collectively place higher security requirements on webhook requests than API requests?

We really don’t, signing is just more convenient in the webhook scenario. And it’s also completely optional to check a signature, leading even to many implementations not doing so.

felipemesquita··on The double standard of webhook security and API security
The post is about how webhook requests are usually signed and api responses are not.

For me it seems clear that the reason for this different approach is that api requests are already authenticated. Signing them would yield little additional security. Diminishing returns like the debate over long lived (manually refreshed) api keys versus short lived access tokens with long lived refresh tokens - or, annoyingly, single use refresh tokens that you have to keep track of along with the access token.

Webhooks are unauthenticated post requests that anyone could send if they know the receiving url, so they inherently need sender verification.

felipemesquita··on Migrating to Postgres
Rails’ Active Record was named after the pattern as described by Martin Fowler:

https://www.martinfowler.com/eaaCatalog/activeRecord.html

felipemesquita··on Ruby 3.5 Feature: Namespace on read
This post (2019) by David Bryant Copeland about npm security goes into some of the complications that arise when multiple versions of a dependency are allowed to be loaded simultaneously:

https://naildrivin5.com/blog/2019/07/10/the-frightening-stat...

felipemesquita··on One Million Chessboards
I've achieved what seems to be a stable structure outside the edges, https://onemillionchessboards.com/#1347,3624
felipemesquita··on Making Software
The subtitle “A reference manual for people who design and build software” seems at odds with the description:

> This book won’t teach you how to actually make software […] It’s a manual that explains how the things you use everyday actually work. You don’t need to be technical to read this - there are a lot of pictures and diagrams to do the heavy lifting. You just need to be curious.

felipemesquita··on Busy Bar
It’s nice that the phone app is free and works without the device. I’m curious about how “Hardcore Mode (optional)” could work, which the page describes as “Locks apps for the entire focus session with no way to bypass it. The only way to unlock them is a full phone reset.”

I could not find this in the app, maybe it’s Android only, an upcoming feature, or requires the Busy Bar hardware device.

felipemesquita··on 2025 xkcd "April 1": Push Notifications
It does work. It’s actually the only thing Apple Intelligence managed to summarize correctly
felipemesquita··on Ask HN: Would you fund Mozilla to become independent of Google?
I would like a way to donate to Firefox browser development directly.
felipemesquita··on Backyard Cyanide
In NileRed’s video “Does cyanide actually smell like almonds?”[0] he purchases some bitter almonds to measure the amount of cyanide in them. He is also worried about the baseless health benefits claims.

[0]https://www.youtube.com/watch?v=WYagO-nup6c

felipemesquita··on Laravel Cloud
Not really. While I prefer rails’ stance of “you can’t pay me for my open source”, laravel having a commercial model around developer tooling made them at least more responsive to their community’s dx wishes.

Still, for me, having a fully open source first party tool like kamal is much better than a commercial offering, no matter how convenient it may be.

felipemesquita··on Ask HN: Recommendations for a Linux Distro and Laptop?
Checkout https://omakub.org (web dev focused setup script for Ubuntu) and https://frame.work
felipemesquita··on The Pathetic Billionaires' Club
I'm more inclined to agree with mere multimillionaire DHH on the the motivations of billionaires[0]:

> I can thus completely understand why the likes of Elon Musk or Mark Zuckerberg continue to show up for the daily cage match of running high-profile companies. Why the appeal of sitting on a beach is limited to that of the occasional break, not a permanent arrangement. It's because the drive that got them to where they are isn't extinguished by achieving personal, material wellbeing.

That said, I had not considered that, for some, keeping themselves on top of the capitalism leaderboards might also play a petty role.

[0] https://world.hey.com/dhh/staying-in-the-arena-1ff9f285

felipemesquita··on Campsite switches to Creative Commons Non-Commercial license
A creatively named basecamp.com competitor
felipemesquita··on Campsite switches to Creative Commons Non-Commercial license
I understand the concern with calling something licensed with CC BY-NC “open source”, but I’m very interested in reading the complete source of a modern comercial app.

It’s rare that we get to see the complete picture of something that has many paying customers like this, and I’m thankful for the Campsite team for sharing it.

felipemesquita··on The Origins of Wokeness
From the article’s first couple sentences: > The word "prig" isn't very common now, but if you look up the definition, it will sound familiar. Google's isn't bad: A self-righteously moralistic person who behaves as if superior to others.
felipemesquita··on Mr. Beast Saying Increasingly Large Amounts of Money
From the Methodology section:

>First, for the main source of data, I chose all Mr. Beast videos with uploaded (ie. non-auto-generated) transcripts—a total of 229 out of 837 published videos on his flagship channel. This gave me a source of processable ground truth about where money was mentioned and also limited the videos to those published the last 6 years, which make up the majority of his meteoric rise. Then, I downloaded the videos in 360p and scraped their transcripts for every occurrence of a dollar amount, logging each mention with its sum, video, and context in a database that I would build on top of as I nailed down the exact timing. I used those contextual timestamps to make rough clips that I fed into the open source AI tool Whisper to (a) get a more precise measurement of where “X dollars” was actually said and (b) standardize and double check that my first scrape had gotten the amount correct. Finally, as many of the clips were still off by a few annoying and noticeable fractions of a second in any direction, I made a script that allowed me to go through each entry individually, trim or extend the clip on either end, and modify the amount one last time if my first 2 methods had failed. After all 2800+ were processed—a task that took weeks—I made a final set of clips out of higher quality versions of the videos and used Premiere to make the film’s final dizzying supercut you see before you.

>90% of data science is data cleaning, and I have kept this overview pretty high-level in the interest of making it accessible to a wide audience. A much longer and more technical dive into the steps needed to go from a raw YouTube archive to this video—including everything from token suppression, the comparative benefits of transcription libraries, counterintuitive ways to standardize and parse numbers in natural language, and debugging audio desyncs in clip concatenations - may appear in the future on my website.

felipemesquita··on Ruby's official documentation just got a new look
The rails api docs are also going through a redesign, you can see a preview of the next design in edge: https://edgeapi.rubyonrails.org/classes/ActiveJob.html I think it’s a a change in the right direction that removes the “aggressive wall of text” on longer pages and looks great in dark and light modes.
felipemesquita··on Transformers for Ruby
A relative decline in a segment where the overall total is growing might mean that the segment’s absolute number hasn’t gone down at all.
Page 1 of 4Next →