So many problems here, and no signs of an updated SDK that behaves properly on malformed input.
5,103 karma · joined March 7, 2015
GitHub: https://github.com/lol768
So many problems here, and no signs of an updated SDK that behaves properly on malformed input.
Nissan have decent BEVs, though - the new LEAF is great to drive.
I know the United States is significantly behind the curve on EV adoption, but I really don't understand who would want this, it's the worst of both worlds.
Note that nobody (new) can submit to it today; the developer console HTTP 503s and is only available to an allow-list of developers.
Interestingly the API still works for creating an issue (but webhooks weren't fired).
The only winning move now is to start impersonating their app.
I can't say I've had any issues getting code using the new syntax through code review though. C# 14 has been out long enough that the team is familiar with much of it, and the IDE is helpful at reminding you to consider adopting new syntax. That aside though, the collection expression syntax is pretty familiar for anyone who's ever written e.g. JavaScript.
They've kneecapped ad-blockers, when ad networks are perhaps one of the biggest causes of malware installs/page hijacking/other unwanted behaviour. I'm not sure how you can consider Chrome remotely secure in this light.
There's not tons of noise being made because for the most part it all, Just Works and that's fairly boring. Perf, memory usage etc gets better every release. As an ecosystem, I'm pretty happy with it. I reach for other languages for smaller microservices.
I worked at a university which did exactly this, in the UK.
It was a bespoke platform which integrated incredibly well with the rest of the systems the university used because it was designed from the ground-up to meet the institution's needs, there were regular user groups involving academics to understand what features needed to be built/worked on etc. At one point it was all OSS on GitHub too, in case other universities could've found it useful. It handled plagiarism detection (integrating with Turnitin), marking, exam grids, coursework submissions and feedback, seminar allocations, personalised timetables & mitigating circumstances.
The in-house dev team was vastly cheaper than anything SaaS would've cost, as well. It also maintained software for on-campus parcel deliveries, online exams, opinion surveys, a mobile app for students/staff, the SSO system, the course catalogue, car parking permits, a content management system and more.
I don't think any of this is unreasonable in a country that picks up the tab through both subsidised dental care and completely free-at-point-of-use healthcare.
> They are wonderful for big business
I (sadly) completely disagree with this. There are still so many basic things they don't expose, and it feels like you're fighting an abstraction designed for a start-up that doesn't want to think about the complexities of payments at all. For example, you have to fight a battle to get the card IIN exposed to you. There's no way to see the electronicCommerceIndicator (ECI) for Wallet payments (it clearly has it, since it's shown in the dashboard if you dig deep enough, but it's kept from you). For their Direct Debit integration, they apply limits on the payment amounts you can initiate, but there's no way to actually see the current value of what these limits are. The same Direct Debit integration also doesn't let you customise the payment references used (GoCardless lets you do this to identify e.g. individual invoices on customer bank statements).
Some of the APIs clearly haven't been thought through - e.g. for disputes you can't programmatically retrieve the evidence submitted by the card issuer. Which means you can't build any sort of sensible custom integration for handling disputes. And besides, they don't even support pre-arbitration (which the card issuers know about and take advantage of frequently because they know their decisions outwith the card scheme chargeback guidelines cannot be challenged effectively).
Their Google Wallet integration is worse that Braintree's and doesn't support the web-based flow.
There's not nearly enough visibility when things go wrong, particularly with their 3DS integration (which was failing for Samsung Internet browser users for us, and we had to fight to get looked at - nothing ever got published on the status page despite the fact this significantly affected your chances of securing liability shift) and you have to escalate via an account manager to get any sort of useful support case response.
Equally it's not hard to teach front-line when to escalate, and ensure L2 and beyond are approachable. Even better if L2/L3 can keep half an eye on tickets that come in for anything that looks particularly interesting.
If you're going to turn the filters on, it's worth being aware of this because it's far from flawless.
I really hope that didn't send emails out to people.
- "TiXL is an open source software to create realtime motion graphics" - pedantry, but software is an uncountable noun. You cannot have a software.
- It wasn't immediately clear to me from the homepage that it's Windows-only. Appreciate it appears to behave under WINE, but it'd be good to make clearer.
The best part is that the Current Account Switching Service makes it very easy to make the jump from a legacy bank like HSBC.
On the contrary, I would say this is increasingly unusual nowadays. There are print restrictions on e.g. iStock content, but there's no attempt to "ration" the number of visitors that see a stock photo at a specific price point.
It's something that's generally put me off from licensing paid fonts - despite the work that has gone into them, because you're almost signing a blank cheque and it's not easy to know how many visitors are scraping content for LLMs.
It's not just HTTPS, I can't push via SSH either.
I'm not convinced it's just "some" operations either; every single one I've tried fails.
Every since they got rid of the Microsoft packages feed, it's just been a complete mess.
Ubuntu's own documentation states:
> .NET 10 will be available in the Ubuntu archive for Ubuntu 24.04+ and included in main upon its official release
But it isn't available?
> As an aside it's not clear that OCSP stapling is better than short-lived certs.
I agree this should be the end goal, really.
The advantages of OCSP were that you got a real-time understanding of the status of a certificate and you had no need to download large CRLs which become stale very quickly. If you set security.ocsp.require in the browser appropriately then you didn't have any risk of the browser failing open, either. I did that in the browser I was daily-driving for years and can count on one hand the number of times I ran into OCSP responder outages.
The privacy concerns could have been solved through adoption of Must-Staple, and you could then operate the OCSP responders purely for web-servers and folks doing research.
And let's not pretend users aren't already sending all the hostnames they are visiting to their selected DNS server. Why is that somehow okay, but OCSP not?