HNHacker News
TopNewBestAskShowJobs

hurricaneSlider

194 karma · joined April 23, 2015

CEO at game tooling startup https://wbbl.co

Former CTO at https://stitch.money

Hobbyist game developer: http://ncthbrt.itch.io/

submissionscomments
hurricaneSlider··on PKCE: What and Why
For scenarios where third party clients clients require delegated access to users, you can combine these two approaches, giving you the best of both worlds.

For example we have configured our implementation of OpenID Connect to use PKCE for retrieving an authorization code, and then when calling the token endpoint, requires that the the client authenticate using a client_assertion JWT (as detailed in https://tools.ietf.org/html/rfc7523#section-2.2)

hurricaneSlider··on A Kubernetes operator to sync secrets from AWS Secrets Manager
If you're looking for a gitops alternative that can make use of AWS KMS, Azure KeyVault and Google Cloud KMS, would highly recommend kamus (https://kamus.soluto.io/). Allows secrets to be safely managed in source control and also has an AES mode ideal for local development.
hurricaneSlider··on First Impressions of GitHub Codespaces
Unity feels like it runs best on Windows to me. Metal bugs caused quite a few Unity issues for me when I was developing on a Mac. That was a year or so ago, so maybe the situation has improved.

Also a lot of useful 3d content creation software is Windows only, or only supports CUDA acceleration, so implicitly rules out Mac from being a first class citizen (e.g. substance painter)

Obviously not every game is the same, or needs fancy tooling. But Windows feels like it just works for game dev.

hurricaneSlider··on GraphQL Query Generator
That's fair. I haven't used it in that context.
hurricaneSlider··on GraphQL Query Generator
Have you looked at Hasura (hasura.io)? Allows you to carefully expose your database as an API, while allowing you to build serverless endpoints for validation, business logic and side effects. Bakes in authorization as a first class concern. There are some other similar alternatives that do much the same.

Think it's a mistake to consider GraphQL as a drop-in replacement for REST, writing a vanilla GraphQL server is indeed quite arduous as there is a lot of important concerns like auth that you don't get out the box.

But if you're just wanting to expose your database in a controlled and secure manner, with a smattering of business logic, think some of the technologies that have evolved around GraphQL like Hasura and PostGraphile can make it a joy to use.

Think the wonder is that the schema definition language/schema introspection wasn't just tacked on at the end (unlike REST w/ Swagger and OpenAPI) so all these tools have developed around the tech. There is also a bit less of an object relational mismatch than in REST.

hurricaneSlider··on “This resentment runs deep and is stunningly widespread”
Seen a lot of comments to the effect that 30% is not a lot.

But what about corporate taxes, what about things like the game engine getting a cut (often an additional 5%), etc?

Apple Developers end up getting a slice of a slice.

That 30% is large enough to make whole business models unviable. You need 30% more sales or raise prices commensurately. That's a lot.

You'll probably have to spend more on customer acquisition to achieve those numbers as well as you start to eat into the long tail of customers. This eats into profits.

The cut probably also impacts the quality of experience, particularly for things like freemium games, as you need to monetize more aggressively to make up for the Apple tax.

hurricaneSlider··on How and why GraphQL will influence the Sourcehut alpha
The transport API I was referring to was written in .NET Core. I think .NET core is great at what it does, but runs into the same kinds of problems that GraphQL tries to address from the start once your API becomes sufficiently featured, which is likely to happen if you're offering an API as a service.

I actually think that unless your company is massive or has a lot of expertise in GraphQL already, using it for private APIs may not be the best idea, as it could be a sign of certain internal dysfunctions or communication problems within or between engineering teams.

----

An example, however of the kind of filtering I was referring to, and why I still think it would be non trivial to do, even in something like ASP.NET, is the following: https://www.gatsbyjs.org/docs/graphql-reference/#filter. This of course isn't something you get out the box in GraphQL either, but the structure of the system made this (relatively) easy to do.

Of course you could add something like OData to your REST API which would definitely be a valid alternative, but that also would have its own warts, and is subject to similar criticisms as GQL.

hurricaneSlider··on How and why GraphQL will influence the Sourcehut alpha
> usable only for internal projects where you have full control of who has access to your system, and can't bring it down because you forgot an authorization on a field somewhere or a protection against unlimited nested queries.

As someone who is building a public facing GraphQL API, I would disagree with this. Directives make it easy to add policies to types and fields in the schema itself, making it amenable to easy review.

A restful API also has the problem that if you want fine grained auth, you'll need to remember to add the policy to each controller or endpoint, so not that different.

The typed nature of GraphQL offers a way of extending and enriching behavior of your API in a very neat, cross cutting way.

For example we recently built a filtering system that introspected over collection types at startup to generate filter input types. We then built middleware that converted filter inputs into query plans for evaluation.

I previously worked at another company that offers a public REST API for public transport. Public transport info is quite a rich interconnected data set. Despite efforts to ensure that filtering was fairly generic, there was a lot of adhoc code that needed to be written to handle filtering. The code grew exponentially more complex as more filters were added. Maybe this system could have been architected in a better way, but the nature of REST doesn't make that exactly easy to do.

Bottom line is that I feel for public APIs, that there is a lot of demand for flexibility, and eventually a public facing RESTful API will grow to match or even exceed that of a GraphQL API in complexity.

hurricaneSlider··on It's Time to Act – A Response to Marc Andreessen
Twitter allows you to import blocklists I believe. Some of these lists have been widely circulated.
hurricaneSlider··on Show HN: DOME, a framework for making 2D games with Wren
You've obviously put a lot of time and effort into building and documenting this framework.

Would highly suggest adding more visuals and some way of very easily playing with runnable demos. Games are inherently audiovisual artifacts, so the lack of audiovisuals on the site is a bit of a negative signal.

hurricaneSlider··on Amethyst: Data-driven game engine written in Rust
And I think the engine is generally heading in the right direction now.
hurricaneSlider··on Amethyst: Data-driven game engine written in Rust
> OTOH there's Unity, who never developed a large game themselves, only demos and samples.

Possibly to the engine's detriment (though a cottage industry of add-ons in the assert store has helped bridge the most serious gaps)

hurricaneSlider··on Show HN: Learn angel investing and VC with some skin in the game
Note to andrewpierno and Donny Mack. I'm not necessarily attacking you for copying legal notices, but it's important to ensure that such notices are accurate and relevant to your company.

For instance there is still the mention of lodging Form ADV Part 2A Brochure with the SEC. If you have not done so, this may be in fact a fraudulent claim and could get you in trouble later on.

hurricaneSlider··on Show HN: Learn angel investing and VC with some skin in the game
If you look at legal disclosures on the website (https://seedcamp.io/disclosures), it mentions AH Capital Management LLC. Which is the same company name as Andreessen Horowitz (https://www.bloomberg.com/profile/company/1299044D:US)

Unsure if that is significant, actively misleading, or simply coincidence. I'd lean towards the former given that both are apparently registered with the SEC, though my confidence bounds here are quite wide as I am not sufficiently knowledgeable of the rules behind company names in the US.

A final possibility that I've only just considered is that this disclosure was (poorly) copied from a16z's website.

hurricaneSlider··on .NET 5
The current version of `dotnet publish` allows you to specify a runtime identifier. It then proceeds to produce an executable for that runtime.
hurricaneSlider··on Build and Deploy Serverless React Apps with Next.js 8 and Zeit Now
Azure Web Apps are pretty close.
hurricaneSlider··on Memory usage of a toy C# server and client with 500K concurrent connections on
Mono still exists for the same reason .NET 4.X still receives updates, amongst other things. It also has better mobile and crossplat support for targets outside of the server realm
hurricaneSlider··on When a Bike Company Put a TV on Its Box, Shipping Damages Went Down (2017)
Completely unnecessary racist comment. Removing just that one word would have made it acceptable.
hurricaneSlider··on How DOOM fire was done
There actually has been a lot of work done to make it suitable for use cases such as 2d, racing, etc.

An engine like unity basically provides utilities such as physically based rendering, camera systems, visual editors, scripting environments, a scenegraph editor, preview windows, io, asset import and conversion, audio, etc. Some games are of course easier to make than others in such engines, but they aren't that prescriptive.

hurricaneSlider··on How DOOM fire was done
I guess I've only been exposed to the independent scene (which I would assert accounts probably for the majority of releases, if not the sales volume)

That you're using a handrolled engine is fine, I'm sure your company knows what they're doing. But in the context of this post, and for people who'd like to start game development/design, saying that most devs write their own engine is in my opinion damaging, as I really don't think that most smaller studios do. It increases the barrier to entry, and perpetuates a certain amount of elitism, which really considering the make up of the industry is no help at all.

hurricaneSlider··on How DOOM fire was done
Most game developers do not code their own engines. In fact unless you're doing something special (e.g. claybook, Miegakure, anything with true videos, or an unusual development pipeline/platform), it is immeasurably more economical to use an engine like unity/unreal with their large communities, asset stores, support and decent tooling. Even many 'AAA' games are now starting to use these commoditised engines (possibly with their own extensions/forks)
hurricaneSlider··on Session types in programming languages (2016)
Haha actually did read it. But eyes must've skipped over the header.
hurricaneSlider··on Session types in programming languages (2016)
Thanks zozbot123
hurricaneSlider··on Session types in programming languages (2016)
Didn't write this but thought it was interesting as it seems to address pain points I've felt when building out a typed actor system (requirements for adapters, etc)
hurricaneSlider··on Serverless Computing: One Step Forward, Two Steps Back
I really wish that one of the big cloud providers was building out actors as a service. That would address a lot of the shortcomings of FaaS, whilst still having many of the important benefits.
hurricaneSlider··on For-Profit College Chain Closes, Shutting Out Nearly 20k Students
To be fair, I don't think they're referring to your job when talking about 'parasites'
hurricaneSlider··on Show HN: An experimental Github/trending User Interface
Think you might not be encoding the language filters correctly. I'm seeing a lot of C when filtering by C#
hurricaneSlider··on ASP.NET Core 3.0 will only run on .NET Core
Yes, at least when I last checked, that stuff wasn't present.
hurricaneSlider··on ASP.NET Core 3.0 will only run on .NET Core
> Does this mean .NET framework is being dropped slowly for new projects?

Unfortunately, yes. I would've liked to have seen support for netstandard rather than a particular runtime, I worried that it means people will get sloppy and just target whatever their web framework is targeting.

You've luckily got three plus years of support, so hopefully in that time you'll be able to make a plan about 3rd party dependencies.

hurricaneSlider··on ASP.NET Core 3.0 will only run on .NET Core
I somehow doubt it, most of the APIs (with the notable exception of some of the reflection APIs) are at parity and the language is the same.

This is more like a major library dropping support for a legacy runtime going forward.

Page 1 of 3Next →