HNHacker News
TopNewBestAskShowJobs

homebrewer

5,064 karma · joined September 5, 2024

Left.
submissionscomments
homebrewer··on Scriptc by Vercel: TypeScript-to-Native compiler, no JavaScript engine in binary
Christ. Imagine if bridges, skyscrapers, dams, cars, airplanes were designed and built like that.

I vibeslopped thousands of pages of blueprints, nobody reviewed them, but another team of digital monkeys with the intellect of an ant have already built the bridge, and it seems to not have collapsed yet, so we're already directing traffic there.

I can't imagine actual engineers feeling anything but deepest contempt for this industry.

homebrewer··on Firefox 153.0 Beta
It's better than any of them for random bullshit you've found somewhere on the internet since it provides a far stronger security boundary than any standalone pdf reader. For trusted documents, I agree.
homebrewer··on Modder Makes GTA: Vice City Playable Inside GTA 3 Inside GTA: San Andreas
Here's the actual video for those unable to use adblockers and unwilling to deal with kotaku's ads:

https://youtube.com/watch?v=X_w6fo4KVy0

homebrewer··on Lobste.rs is now running on SQLite
It's been fairly unstable recently, pages sometimes render for several seconds which I've never seen under MariaDB. Used to be instantaneous, always.

Sometimes (maybe 5% or less) the request won't render at all, and you get a browser error page.

Today they ran into this bug, lost a bunch of voting data, and went into read-only mode for several hours:

https://github.com/rails/rails/pull/57128

I wonder how much of this is usual bugs which crop up during major database migrations, and how much is caused by choice of SQLite.

homebrewer··on SQLite should have (Rust-style) editions
Firebird can be embedded, although neither the database itself, nor the embedded mode are as popular as they once were.

It's a fully featured database though, with everything you expect from one, including actually working ALTER TABLEs.

homebrewer··on SpaceX bond worth 10% less than issue price – heading for junk bond status
https://gitlab.com/magnolia1234/bypass-paywalls-clean-filter...
homebrewer··on Vancouver PD website features Quick Escape button that wipes itself from history
Firefox already has "forget this site", which removes all traces of you ever visiting the site, but it's only available from the history modal.

Been there for probably decades, yet another thing mostly known to/used by "advanced" users.

homebrewer··on Ghostel.el: Terminal emulator powered by libghostty
https://ghostty.org/docs/features/ssh
homebrewer··on EF Core 11 makes your split queries faster
Is this not what you want? Seems like it's part of the SQL standard.

https://www.postgresql.org/docs/19/ddl-property-graphs.html

homebrewer··on What's the best way to do authentication in modern applications
Cookies can be encrypted and signed and contain whatever information you want, not just some random token that has to be looked up in the database to be actually useful.

This is what aspnet core does by default if you enable cookie-based authentication. Gives you the best of both worlds.

homebrewer··on My thoughts on the Bun Rust rewrite
Ghostty, TigerBeatle. The other two poster children.
homebrewer··on Microsoft Needs Windows Lite
They receive updates on time. I've been supporting a few LTSC machines for friends and relatives, haven't ever seen them receive any unnecessary junk through Windows Update. Just bug and vulnerability fixes.
homebrewer··on I am a person who will look at the Steam Machine and cry
I've long wished for rich western societies to run extensive student exchange programs with low income countries. Living even one year in most of the world will change your outlook for the rest of your life.
homebrewer··on Project Valhalla, Explained: How a Decade of Work Arrives in JDK 28
It was neglected during its last few years at Sun. Oracle started moving it forward at never before seen pace, while mostly maintaining backward compatibility (unlike .NET that "did things right from the start", which is what .NET Framework/.NET Core/.NET split/rewrite is according to some in this very discussion. And .NET had Java to copy and learn from, but still fucked up.)

Same with MySQL, btw. "Dead" according to this site, risen from the dead under Oracle for those who actually know it.

homebrewer··on Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages
No, it's completely valid. The arch home page warns you that you're the one responsible for your system, and get to keep both pieces when something breaks. Everything is assembled with this philosophy in mind. This message is reinforced ten times more before the system is even installed and is up and running.

If this is not for you, that's fine, but it's been working very well for some of us for... decades, at this point? I'm not amused by the amount of people here wanting to turn arch into another Ubuntu, most of them having zero familiarity with how the AUR works, or arch more generally.

homebrewer··on Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages
A package maintainer has to be interested and willing to support it. Sometimes packages get dropped from the official repositories into AUR when the maintainer loses interest, and noone else wants to pick up the slack.
homebrewer··on Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages
I don't know how it works these days, but a few years ago GitHub was happy to give away usernames from users who haven't touched their accounts in a long time to anyone who asked. Several people I know got vanity usernames that way. All you had (have?) to do is drop an email to GitHub's support.
homebrewer··on Tailwind and slop apps
And for some reason you're describing it as it's a bad thing. I don't care much for tailwind, but bootstrap is still used for intranet applications, and is an excellent pick in that category. Why waste time writing CSS, reimplementing what has been done millions of times before you, when working on an application where function has strict precedence over form? I'd rather listen to users who fill hundreds of forms daily, understand where they struggle, and spend effort on optimizing their workflow than on pointless eye candy.

(In my experience, it's never been "this doesn't look as good as the latest version of Discord", or whatever.)

homebrewer··on Upcoming breaking changes for npm v12
Your own link says that a proper package manager (e.g. pnpm) supports this out of the box.

If there are other use cases that really need post-install scripts, you can whitelist just those in pnpm. In projects I'm working with, there are often zero post-install scripts that must be enabled for everything to work properly, and it's usually from poorly cobbled packages that use them to download prebuilt binaries (well written packages, like biome or tsgo, use per-architecture subpackages).

You enable just one or two of those, and block everything else.

homebrewer··on Upcoming breaking changes for npm v12
One distinguishing feature is their optional install strategy: running packages directly from compressed archives instead of unpacking them into node_modules.

https://yarnpkg.com/features/pnp

Very similar to using .jar's in Java instead of directory trees of .class files.

It's somewhat hacky though, and editor/tool support varies.

- since there are far fewer small files, it can be faster especially on Windows if you're forced to work on it for some reason

- the archives can be stored into the git repository (through git-lfs or friends), removing dependency on the internet and the package registry

homebrewer··on Malicious npm packages detected across Red Hat Cloud Services
This has been improving recently; one large project built on several heavy libraries that I've been supporting since 2018 currently installs ~180 dependencies without loss of functionality compared to how it worked, and what it depended on, back in 2018.

IIRC 6 years ago the full dependency tree congealed into more than 2000 packages. One small example is React itself:

- 5 deps: https://www.npmjs.com/package/react/v/15.6.2

- 0 deps: https://www.npmjs.com/package/react/v/19.2.6

Another is switching from create-react-app with its hundreds of transitive dependencies to vite, which, according to the test I've ran just now, currently has 15. Etc.

homebrewer··on Malicious npm packages detected across Red Hat Cloud Services
How large a project do you typically use dotnet for?

IME dotnet dependency situation is a tire fire, not a month goes by without another dependency biting the dust or going fully commercial with no notice. Which is fair, I suppose, but Go and Java ecosystems don't have it nearly as bad.

homebrewer··on NPM packages from Red Hat have been compromised
You can isolate it through bubblewrap; I moaned about it here and there's no point in repeating it:

https://news.ycombinator.com/item?id=45041798

If you only ever use js/ts for frontend projects (like we do), it closes one major hole that I'm aware of, which still leaves at least two:

- the editor possibly starting random binaries from inside the mode_modules (such as biome, vitest, tsgo)

- escape from sandbox by using some kernel vulnerability, of which there have been many recently

homebrewer··on Openrsync: An implementation of rsync, by the OpenBSD team
It seems to be a widely repeated "fact" which can't be traced to anything particularly authoritative:

https://archive.is/pt5fQ

https://britannica.com/topic/Claude-AI

Looks like the 2023 NYT article started it, and it uses this as reference:

> depending on which employee you ask, was either a nerdy tribute to the 20th-century mathematician Claude Shannon

Personally I always associated it with the silent protagonist from GTA3.

https://gta.fandom.com/wiki/Claude

homebrewer··on Mercurial, 20 years and counting: how are we still alive and kicking? [video]
I've never rm-rf'ed a git repo (why would you voluntarily remove the reflog?) while also being a very mid-tier developer. The types that do also tend to reboot machines every time something goes wrong instead of looking for the exact cause of the problem and fixing it once and for all; to screw around with SQL (move subqueries here or there, add and remove indexes at random) until it runs acceptably instead of building proper understanding of how their database works, and so on. At least judging by what I've seen. Not really something to be proud of.
homebrewer··on Mercurial, 20 years and counting: how are we still alive and kicking? [video]
You can ignore them once and then edit to your liking, git will not notice any changes to them and will assume them to be untouched.

https://git-scm.com/docs/git-update-index#Documentation/git-...

homebrewer··on Leaving the Physical World
In poor countries like mine (and looks like GP's too), IT positions are very limited indeed. Nevertheless, it has been one of the very few sectors open to nobodies, helping us to pull ourselves out of poverty, open to those who weren't born to the right family with the right connections, or to a sugar daddy who can cover the first 25 years of our lives to go get a good education in Europe or the US.

Looks like it's being slowly taken away from us to make a few billionaires into proper trillionaires. Can't see this ending well for humanity.

And the common advice you hear on this site ("just migrate to country X") doesn't really apply to most of us. Even if you can name many examples of people doing just that, you're seeing a very narrow slice of the population; I can find many more counterexamples for each one of them.

Your weak passport won't impress anybody, almost all of the world is closed to you, you can't travel anywhere (forget migrate) without going through a lengthy and expensive process where you're treated with suspicion, and can be denied with no compensation, on every step of the way. I'm still talking about traveling here; finding work is much more difficult.

So it's really hard to move anywhere decent if you're not at the top of your profession, which in large part depends on your innate abilities, not just how many hours you put in.

I've become jaded and extremely cynical; if worst comes to worst, there's always one universal way out, which is what keeps me going for now.

homebrewer··on Google Cloud Fraud Defence is just WEI repackaged
Lots of supposedly technically advanced users switched to Chrome en masse and promoted it on every occasion they could, because it was so much faster, simpler, safer, etc etc. Don't excuse useful idiots from their share of the blame. People warned about dangers of Chrome's growing domination for about as long as I can remember, back to at least 2012, only to be dismissed as paranoid.
homebrewer··on Maybe you shouldn't install new software for a bit
IT is (was?) one of the very few ways for us in third-world countries to pull ourselves out of poverty by our own bootstraps, since social mobility is quite limited if you lack the right connections. I'm pleased with you being so happy about it being taken away to make more money for billionaires.
homebrewer··on Maybe you shouldn't install new software for a bit
Has everyone here already forgotten about the WireGuard tire fire?

https://lwn.net/Articles/850098

https://news.ycombinator.com/item?id=26507507

tl;dr: deeply insecure WireGuard implementation committed directly into the FreeBSD kernel with zero review.

Was this process problem fixed?

Page 1 of 28Next →