HNHacker News
TopNewBestAskShowJobs

kkirsche

576 karma · joined November 3, 2014

Hey!

My name is Kevin, and I am a cybersecurity developer and penetration tester for an ISP, developing tools such as DDoS Mitigation solutions, security evaluation tooling, vulnerability management tools, and much more. I enjoy building complex projects comprised of front end, back end, and various integrations, as it pushes me to stretch my design, programming, and architecture skills.

The thoughts and opinions I express on Hacker News are my own, and I look forward to having great discussions with the community.

submissionscomments
kkirsche··on Astral to Join OpenAI
Happy for the team, sad for users. I just don’t believe their work will continue under new ownership
kkirsche··on Ask HN: Do you also "hoard" notes/links but struggle to turn them into actions?
I’d recommend checking out Nick Milo’s ideaverse. The idea is about how to capture in a way that sparks ideas and actions not collects
kkirsche··on Sunny days are warm: why LinkedIn rewards mediocrity
This has been my experience. Just a bunch of ego stroking
kkirsche··on PEP 760: No more bare excepts
I wish people would stop holding onto compatibility as if it is some amazing feature. It has benefits, but also comes with many drawbacks to innovation and improvement in established ecosystems
kkirsche··on Canva has acquired Affinity in an effort to compete with Adobe
I love their software and am happy for the humans behind it all. As a customer who doesn’t believe they won’t force a subscription on me, I wish I had never supported them
kkirsche··on Atuin – Magical shell history
Many large companies suffer from the concept of shadow IT. The use of software and services that aren’t blessed by the company to accomplish tasks that are blessed. As someone in security at a large company, I expect this is a matter of not every company has people who follows rules. I know I’ve seen and know, even within security orgs, plenty of people who don’t follow the rules because a few bad rules makes them feel that other important rules are also bad. It’s pretty simple to bypass the software companies use to “enforce” the rules
kkirsche··on Why if TYPE_CHECKING?
Broadly speaking, yes, but for some situations like database models with bi-directional relationships that can cause unnecessary maintenance burden simply for the benefit of type checking which this allows you to work around since the cyclical nature is only caused by typing not runtime semantics
kkirsche··on Monaspace
I tried to use custom css in vscode but couldn’t figure out how to get it to work.
kkirsche··on Show HN: TypeScript Style Guide
https://blog.logrocket.com/why-typescript-enums-suck/ may be a good introduction. I love enums in other languages but they can come with some unexpected behaviors in typescript
kkirsche··on If PEP 703 is accepted, Meta can commit three engineer-years to no-GIL CPython
That differs but is a reasonable understanding. I’m instead referring to automations that perform large scale refactoring as handled by Facebook, who would be contributing to this effort.

https://github.com/facebookarchive/codemod

It sounds like what you are describing is what’s known as poly fills which convert code into a variant that maximizes function across implementations which isn’t really applicable here.

kkirsche··on If PEP 703 is accepted, Meta can commit three engineer-years to no-GIL CPython
https://github.com/facebookarchive/codemod

Ironically this is also from Meta which would be contributing to this space increasing the expertise of achieving this result.

kkirsche··on If PEP 703 is accepted, Meta can commit three engineer-years to no-GIL CPython
I think this is where concepts from Rust and Go could come in handy. Things like Go’s race condition detection and rust’s compiler validation approaches can be used to statically analyze code. Sure, it’s a meaningful change from how many Python devs approach the language and challenging problem but not insurmountable given the existing work in the field.
kkirsche··on If PEP 703 is accepted, Meta can commit three engineer-years to no-GIL CPython
That’s not what that library was in my opinion, it was a compatibility layer not a rewriting tool which is what I referenced. Having a layer in between simply prolongs the issue and creates many types of problems based on adoption or not. On the other hand, when rewriting you can apply that either as an author or as an end user depending on the quality which meaningfully allows for different results.
kkirsche··on If PEP 703 is accepted, Meta can commit three engineer-years to no-GIL CPython
Seeing so many comments about how hard it is to just break compatibility and upgrade is sad. Instead of just throwing our hands up and saying it’s too hard, we could adopt the model the JavaScript ecosystem has seen more of which is codemods that upgrade the code for us.

If as a community we invest in those tools and make them easier to build, the cost of upgrading goes down and the velocity of high-impact changes can increase.

kkirsche··on Buying an iPad Pro for coding was a mistake
iPads are amazing for certain professional tasks:

- Artists (still or motion) - Writing (or related tasks like Editing) - Mobile roles (sales, aspects of healthcare such as patient record accessibility, etc)

But, even in these cases with there is good alignment, you still lose productivity over a more traditional setup, usually due to restrictions around file management, keyboard shortcuts (usually due to “less than” applications not that the machine is incapable), security (what happens to data on the device if it’s lost or stolen), and window management (if you end up needing multiple monitors for your iPad is that really the best tool?)

I wish and want the iPad to be a true professional machine, but it’s not. It’s an amazing supplementary machine though as a reference screen, drawing pad, media consumption (e.g., tutorials), etc.

I guess I don’t understand how you end up believing it’ll be the best fit if you’ve used one in the past 3-5 years.

kkirsche··on Docker Acquires Mutagen
Fair, I appreciate the answer. I guess I’ve just seen enough purchases where it’s just for the payday that I’m a bit cynical. Thanks again for taking the time to read and answer, wishing you the best
kkirsche··on Docker Acquires Mutagen
Do you believe given Docker’s history of poor strategy (e.g., monetizing late requiring changes that negatively impact reputation such as docker desktop and hub), communication (e.g., the short notice changes a couple of months ago around free groups resulting in backlash) and in some cases destruction of successful businesses (see other comments in this thread) that this will result in a positive result for end users?

I hope you made bank while the ship continues to sink.

kkirsche··on Authlib: Python Authentication
This makes it a non-starter for a lot of teams I think, in large enterprises it can be difficult to keep track of licenses like this, especially if you have situations like open core but commercial tiers and whatnot.
kkirsche··on Go 1.21 Release Candidate
Can you elaborate on why this is surprising for those who don’t fully understand the differences?
kkirsche··on You’re Not Imagining It–Job Hunting Is Getting Worse
As someone who works for a large company, 100%, and not just that, the restrictions on allowed interview questions can be so limiting that even if we could do better, we aren’t allowed to. It’s frustrating on the hiring side just as it is for candidates. I’m sure this isn’t true everywhere, but just my experience.
kkirsche··on Why not tell people to “simply” use pyenv, poetry or anaconda
I’m not convinced by the argument as it sounds like it’s tone implies that it’s written to people who aren’t aware of who their audience is.

Sure, not all of these tools are right for all audiences, but that doesn’t mean that they aren’t good suggestions for wide swathes of the ecosystem.

I think it’s important instead to think about your largest user groups and provide workflow ideas for those groups. For example, with Python we may have (this is a simplified list):

* Web Development * Data Science * Embedded * Compilation / Transpilation (e.g., PyO3)

Of these groups, I’d expect the tools mentioned to be reasonable for two or three of the groups, but less so in groups like data science where there is a higher concentration of non-development first specialties.

There are always outliers, but I think choosing your target audience is important. On a team, I wouldn’t necessarily want to teach a person a random workflow if the team all uses one of these types of tools.

kkirsche··on This is valid Python syntax
I learned about Python dev mode in this, thanks!

For anyone else:

https://docs.python.org/3/library/devmode.html

kkirsche··on JavaScript state machines and statecharts
Thank you for sharing! Any resource to understand how others have solved or approached this problem is valuable.
kkirsche··on JavaScript state machines and statecharts
This looks amazing. Does anyone know a good resource for creating database-backed state machines? Eg states are defined in the database
kkirsche··on Vice is said to be headed for bankruptcy
I really loved Vice Games, aka Waypoint. The team over there really gave it their all and it showed. Sad to see this happen
kkirsche··on The art of auto engineering
I hope you are doing well these days after what sounds like a challenging journey to get to this point. Thanks for making and sharing this great content.
kkirsche··on Cash App creator Bob Lee, 43, killed in San Francisco stabbing: reports
Thanks for sharing this. If anyone else is curious, there is additional discussion in this thread:

Bob Lee, former CTO of Square, has died after being stabbed in San Francisco https://news.ycombinator.com/item?id=35448899

kkirsche··on Pytest Tips and Tricks
The following link describes the set up used / needed by VS Code to integrate the framework with the IDE:

https://code.visualstudio.com/docs/python/testing

kkirsche··on Pg_jsonschema – JSON Schema Support for Postgres
With pydantic’s funding, it wouldn’t surprise me if they enter this space themselves (the company side not the existing python library side)

Funding Ref: https://pydantic.dev/announcement/

kkirsche··on Common Beginner Mistakes with React
https://beta.reactjs.org/learn/you-might-not-need-an-effect

The beta react docs have a number of great examples of this!

Page 1 of 10Next →