HNHacker News
TopNewBestAskShowJobs

marcus_cemes

401 karma · joined September 21, 2020

Switzerland, studied at EPFL.
submissionscomments
marcus_cemes··on How the modern world arose from imaginary numbers
> You can have 5 rocks destroyed in the future.

Exactly, you use it to store some information that has no real quantity but may be converted to a real quantity in the future through some other process.

I'm a polytechnic university student, we use imaginary numbers extensively in all sorts of places, especially whenever there is any oscillatory behaviour, such as an electrical signal or a light wave. A complex number is just a two-dimensional vector with real/imaginary components, whcih provides an amplitude and a phase (angle). An oscillating sinusoidal signal/wave may appear to be zero and completely static if you freeze time at the right moment, but as time progresses, it will continue oscillating, like a swing in a park.

In a way, the magnitude represents the built up "momentum" of the system, whilst the real quantity is the immediate physical value at any given point in time (given by the phase). The amplitude is always the same at any given moment, even when the swing is vertical, it has momentum which will help it reach its maximum height.

Personally, I still think they are just "invented", but I think the vast majority of engineers much prefer them to the alternative, manipulating trigonometric functions (every engineer's nightmare). They're a neat way to represent the exchange of potential and mechanical/electrical energy with a single value and some simplified mathematics (this is an engineer's, not a mathematician's, point of view). Like negative numbers, we could have chosen to have two positive quantities, balance and debt, instead we find use in merging these definitions, whether negative values make sense or not. We have become used to to negative numbers representing the "inverse" action, which makes sense when representing a phyiscal quantity such as velocity.

marcus_cemes··on Use of Google Analytics declared illegal by French data protection authority
For those that missed it and are interested, there was a similar HN discussion around a German GDPR ruling last week. It already has quite a large debate and a lot of opinions on the matter:

https://news.ycombinator.com/item?id=30135264

marcus_cemes··on Swisscom to discontinue MMS service
I just learnt of the blue/green debate recently from a MKBHD video. WhatsApp is suprisingly prevalient here.
marcus_cemes··on Swisscom to discontinue MMS service
MMS was terrible, however people are fine paying 70 CHF/month for unlimited mobile internet nowadays. I find this ridiculous, personally I'm trying to condition myself to only use the 100MB of free monthly data, stricly messaging only. It's a challenge.
marcus_cemes··on Our User-Mode WireGuard Year
Fly.io's blog posts are incredible, they really seem to really enjoy what they do and want to share what they've made with everyone else. I love them for that.

I wish that more companies could be like this and skip the corporate BS, it shows that they really have something outstanding to offer.

marcus_cemes··on Go performance from version 1.2 to 1.18
TypeScript is actually pretty amazing, a lot of people strongly dislike it, but I think it gives a reasonable amount of safety for such a dynamic language, I would use it even if only for the autocompletion. It encourages a better (imo) style of programming than traditional JS that did all kinds of dark magic, like modifying the prototype chain.

Sometimes I wonder what a world with strong ESM support, a slim runtime such as just [1], strong typing (like Rescript is trying to do), a unified format/lint toolchain and a solid standard library would like like, look how far Node.js has gotten despite its numerous flaws.

[1]: https://github.com/just-js/just

marcus_cemes··on Go performance from version 1.2 to 1.18
Yes, Rust guides you though setting up tge MSVC toolchain, then everything Just Works™, I'm not sure which toolchain the Rust sqlite3 bindings crate uses, but it also just works.

Actually, a lot of Node.js is written in plain JS, even large parts of the runtime itself, I've never needed a C compiler. This was mostly to make it easier for contributers that don't want to learn C++.

It's extremely rare for libraries to require any system dependencies, such as a C toolchain. Sharp (libvips bindings) will try to download precompiled binaries from a bucket somewhere, this is all done in ad hoc postinstall scripts, for better or for worse... Other libraries use JS as a C compile target with asm.js, opinions aside, it actually works pretty well.

marcus_cemes··on Show HN: Mailwind – Use Tailwind CSS to design HTML emails
How is this different to https://maizzle.com/?
marcus_cemes··on Go performance from version 1.2 to 1.18
They are painful... Running the executable at the end with such a tiny footprint and outstanding predictable performance is very gratifying, however. It feels like the language and the compiler love you, they just have to work a little harder to deal with the complexity of macros and generics!
marcus_cemes··on Go performance from version 1.2 to 1.18
Thank you for your explanation and fair comparison. I'm sure that a seasoned C/Go programmer would skirt around those difficulties or be using POSIX in the first place, I prefer languages that do not impose any constraints on your choice of OS, even if I do prefer Linux for development, but it's not good enough to replace my daily driver.

I don't think there will be a Rust implementation of sqlite3 in the near future, it would be a monumental task. Having the C bindings just work with static compilation in Rust was a deal-maker for that particular personal project, even if it's just because some crate maintainer went to the extra effort to make a robust cross-platform build script and nothing to do with the language itself, it shows that they put in some effort and pride, but I also get tired of the hype and the Rewrite in Rust catchphrase.

I'm a university student, as part of my student job I had to develop a backend application. Someone has to be able to pick it up after me, hence simplicity and easy of use. In the end, I chose Node.js after strongly considering Go, Rust and Elixir that have more cohesive tooling (formatter, linter, better module system!), it was the easiest to justify. I couldn't trust myself to not find any issues/complications with Rust or Go and I just can't afford them running into these issues and explaining to them "oh, you need to set up a C compiler toolchain on Windows".

marcus_cemes··on Go performance from version 1.2 to 1.18
Fly.io is amazing, I'm very excitied for it! They spin up a long-lived instance on the edge closest to the user and create a Wireguard tunnel in-between. They also have a free tier and reasonable pricing. Heroku is just far too expensive for a hobby project.
marcus_cemes··on Go performance from version 1.2 to 1.18
I just tried it now (a year later), same compiler error (using msys2):

    # github.com/mattn/go-sqlite3
    /usr/lib/gcc/x86_64-pc-msys/10.2.0/../../../../x86_64-pc-msys/bin/ld: cannot find -lmingwex
    /usr/lib/gcc/x86_64-pc-msys/10.2.0/../../../../x86_64-pc-msys/bin/ld: cannot find -lmingw32
    collect2: error: ld returned 1 exit status
The go-sqlite3 GitHub repo has tons of Windows-related issues, one just opened yesterday in fact. I'm not an experienced C programmer, I'm not well versed in compiler/linker toolchains, I know it's super tricky (especially on Windows) but I don't expect my clients to be experts either. I actually spent a few hours trying to solve this last time, time I could have spent coding.

It's not a problem with Go, per se, but it does create non-trivial requirements toolchain setup on Windows, which ruled out Go for me. The whole toolchain just feels a bit... flakey, setting up GOPATH and such (although, that seems to no longer be the case?). Rust's crates, just as an example, are amazing, I've never had a single problem with them (more than I can say for npm..) I know it's just one example, but sqlite3 is brilliant. This immediately ruled out Go for me for that project.

marcus_cemes··on Go performance from version 1.2 to 1.18
Don't mean to advocate, I've had the opposite experience. I love listening to the guys over at the Go Time podcast, but for simple things I reach for Node (that I desperately want to escape!), and for a better language I reach for Rust, it just feels right, although I completely agree about library code being complex to understand and using a lot of magic to squeeze out every last drop of performance.

As a corollary, I still haven't been able to understand Go modules and the way code is supposed to be laid out! In fact, a Go 1.16 broke one of my npm packages as it deprecated `go get` with no real alternative for my use case, without manually creating a go.mod file for the cloned repository (that I don't own) in question. I guess this creates a natural... distate for said language.

I think if I would have started with Go, I would have loved it from day 1, but now it provides too much friction to get stuff done. Yeah, it's fast (but most new languages are), it fools C programmers into thinking it's like C due to its syntax, but people coming from the functional world which they believe to be the holy grail will run away in fear with the number of mutations (no Array.map or iterators) and pointers flying around. I still haven't managed to get SQLite working with Go on Windows (stop! a lot of developers do use Windows!), the Rust crate just worked.

The only language that I've actually had fun trying out recently is Elixir, which completely surprised me. The AoC challenges were fun to write in it, and honestly still quite fast!

marcus_cemes··on Go performance from version 1.2 to 1.18
I kind of have to agree with the guy there, it would be kind of trash if everyone just inlined assembly instructions. Manual SIMD already feels a bit like cheating. Ideally, there should be two solution categories, idiomatic solutions and optimised solutions. I would prefer if the idiomatic solutions matched what the average programmer would write.

I think we worry about performance far too much when choosing a language. However, when performance is important, it's important to recognise the different classes of languages, say {Go, Rust, C} vs {Python, JS, Ruby} in terms of speed and memory footprint vs productivity.

marcus_cemes··on Go performance from version 1.2 to 1.18
WebAssembly is fundamently a very well isolated piece of executable code, and Cloudflare focussed on JS by creating their own stripped-down version of the V8 runtime, so you don't have to ship one. They focussed on some efficient solutions, rather than a versetile "just give us a docker image" approach.

Other cloud providers just let you push code, charge you extortionate amounts of money to build the several hundred MB docker image that includes Node.js and node_modules, the data bandwidth of transfering those images between datacentres, storing the build cache in a multi-regional bucket (why???), then they charge you to store the image in their registry and then finaly give you a 10+ cold start time.

marcus_cemes··on Go performance from version 1.2 to 1.18
If you're coming from C, I understand that 11MB seems like a lot to you. I've done quite a bit of serverless Node.js, a relatively slim docker image is always a few hundred MB and can easily stretch to a GB. However, I don't consider using C a viable alternative for that purpose.

What's cool about Cloudflare workers, for example, is that they provide the V8 runtime, you just provide the code, which like with Lua will be a very small footprint.

I'm curious, as a C developer, would you say that you prefer Go over Rust? I've used both and in my opinion Rust feels closer to C/C++ in terms of control and flexibility that the language gives you. To me (from a web service point of view, not systems programming), Go is just a faster (and better designed) pre-compiled version of JS/Node, it may look like C with it's simplicity (you end up having to write a lot of repetitive code), but still packs a garbage collector and (albeit very fast!) runtime under the hood.

marcus_cemes··on GDPR penalty for passing on of IP address to Google by using Google Fonts
> why aren't we worried about the hops between a website and a user

I asked about this below, apparently it's reasonable and strictly necessary. It's what the user expects. Even though it's technically possible for the infrastructure layer to provide full packet anonymity, until then it's the web developers responsibility. I do not agree with this, but that's my opinion.

marcus_cemes··on GDPR penalty for passing on of IP address to Google by using Google Fonts
Personally, I can see only two parties benefiting from this: the plaintiff and lawyers in general.

Google will continue to be Google. Users will be faced with more annoying consent notices that they don't read. Website developers, of which I am one (bias disclosure), who are not very good lawyers will have more technical complexity in order to respect the law. Small companies who rely on services such as CDNs and font providers are now worried about having to host things themselves and the complexity that will ensue to be GDPR compliant (everyone's new least-favourite term). Hacker News gets a divisive flamewar over the subject and this will be yeeted from the front page.

marcus_cemes··on GDPR penalty for passing on of IP address to Google by using Google Fonts
> it’s technically not very hard to do so, and I quite like it

For the average user, it's yet another thing to click without thinking, just to be able to visit a page.

> Consent is required before exposing the IP address and is must be explicitly given

There's the crux of the problem, it's difficult to know what to consent for without first displaying the website, so you implicitly give consent for "just the bare minimum", until you accept the rest. This sounds great, but is both an absolute nightmare for website developers (it's not very easy to do, with how the internet was designed, inline scripts, fonts, CDN stylesheets) and for "most" end-users who just expect good defaults and don't want to sign a consent form every time they visit a website.

marcus_cemes··on GDPR penalty for passing on of IP address to Google by using Google Fonts
From my experience, I think the average user treats the browser and the internet as a black box anyway, they don't reason about what is happening. As long as they can get to what they want, they don't really care what happens in between. Cookie notices get in the way, and therefore annoy them. Most also just accept the fact that there data gets leaked everywhere and there's not much that they can do about it. I genuinely don't believe that the average user can make sense of the TOS that they agree to when signing up for something...

This is definitely not a good thing, and should change, but I also believe that ad-driven companies will continue to find a way, we just continue to rack up operating complexity, which in turn, favours large companies. This ruling seems like a pretty weird and unhelpful way (in the grand scheme of things) of helping protect user privacy, but then again, that was not the goal of the lawsuit.

marcus_cemes··on GDPR penalty for passing on of IP address to Google by using Google Fonts
I'm not either, and neither are most developers. My takeaway from this is GDPR doesn't care, leaked data is leaked data. I'm just worried about this implications this will have for non-malicious intent that the internet has evolved to use over time. Perhaps this is for the better, but I fail to see that future at the moment.
marcus_cemes··on GDPR penalty for passing on of IP address to Google by using Google Fonts
Sorry, I don't mean to play the devil's advocate, this has already gone way off-topic so take what I say with a pinch of salt.

But technically, the IP is not strictly necessary? I can imagine a feasable future where it could be replaced with an anonymised IP from a larger pool generated by your ISP, with TLS for the payload. This could be solved at the internet infrastructure layer, and not required by to be solved by website developers.

marcus_cemes··on GDPR penalty for passing on of IP address to Google by using Google Fonts
But it has since evolved, greatly, in complexity. Just because things were like something once, doesn't make it easy to go back. Hey, I'm all for more privacy, I'd like to go back to how it was before but keep the good parts from today, but this would make it harder for the small guy without some advancements in IT, private CDNs and easier font management. IT is already a nightmare just to keep it from breaking.
marcus_cemes··on GDPR penalty for passing on of IP address to Google by using Google Fonts
I'm not a layer (web dev in my spare time), but how far does "provide more directly" go? A private ISP? There's no limit, only what seems to be considered by the courts as "reasonable". Then again, that is how law is interpreted most of the time, no?
marcus_cemes··on GDPR penalty for passing on of IP address to Google by using Google Fonts
I didn't, actually, but it's a fun thought experiment :)

Python code is instructions that are executed in a very precise manner, they could, in theory, encrypt a hard-drive. You execute the program the same way you execute binary instructions.

HTML is a description of a problem, there are different interpretations, and different solutions, depending on screen-size, etc. You don't always get the same result. Technically, JS could mine crypto, but I don't believe that's illegal (correct me if I'm wrong?), just very inconvienient, and there wasn't any JS involved here. You could make a browser that leaks data due to misinterpretation of the HTML. The problem also lies with the eager-evaluation of HTML, it's difficult to put a disclosure or ask for consent, such as the responsibility clause of most software licenses, without greatly annoying the user...

> makes developers uncomfortable with this court ruling

Guilty. At the end of the day, we need to get stuff done, without creating a private internet infrastructure for our customer. The small guy is at a disadvantage here, not big companies.

marcus_cemes··on GDPR penalty for passing on of IP address to Google by using Google Fonts
> User, the Human, is not going to be asked weather or not the browser should open every one of the possibly hundreds of references in a web page

Exactly, because we strive for a balance of convienience with complexity. Most people wouldn't mind downloading a font from Google, they already use it directly anyway. This isn't how law works, as an engineer, I'm just trying to find some sanity in what to me seems like an insane court decision with possibly very big repercussions for the rest of the internet.

marcus_cemes··on GDPR penalty for passing on of IP address to Google by using Google Fonts
I agree, but the definition of the law can also be interpreted many different ways, until it's clarified, I guess. This seems to me like a very grey area.

There was no trap, in my opinion, document clearly specifies that an additional resource, here a font, will help the website look as intended by the designer. It's visible and its effects are well known (it's part of a well understood specification) and can be blocked. Websites have a responsibility, absolutely, but this is just feels like going too far...

marcus_cemes··on GDPR penalty for passing on of IP address to Google by using Google Fonts
I'm not trying to put any blame here, we can twist metaphors to support either side of the argument.

I definitely think that websites have a huge responsibility in keeping the user safe, but this feels to me like an over-extension of GDPR that will make websites much more difficult to develop in the future for the layman without a team of layers. It's a font, there was no malicious intent.

marcus_cemes··on GDPR penalty for passing on of IP address to Google by using Google Fonts
Yeah, I guess this stands. But HTML is not executable. It has to be parsed, like words in a book, not chemicals in a tube. Who is liable, the person who creates the poison, or the book (encyclopedia) which describes the process (and therefore the person who wrote it/distributes it)?

Again, I'm not saying what is right and wrong, but I think this issue is fundamentally much, much more complex than the court may have thought, and more importantly, may have repercussions on almost every website out there.

marcus_cemes··on GDPR penalty for passing on of IP address to Google by using Google Fonts
This is, for better or for worse, how the internet works. There may be better alternatives, but we're stuck with this for now. The truth is that an extraordinary amount of websites use a third-party resources, jQuery from CDNs, fonts from Google, etc. This ruling will never stand in higher courts imo, because it would break the internet through fear.

I'm curious to know whether DNS and your IP being in the the header of packets travelling through various different countries that can be sniffed is also considered as unwilful data sharing?

← PreviousPage 3 of 5Next →