HNHacker News
TopNewBestAskShowJobs

marifjeren

255 karma · joined January 25, 2018

submissionscomments
marifjeren··on Ask HN: If you don't read books, what do you read?
I have an RSS opml of about one thousand blogs that I follow. Actually a majority of them are RSS feeds of people who have posted here in hacker news.

I also like to try to read research papers every now and then. On weekends I'll print one out and sit with a french press and pen and read through it, and it's a nice time. (Today I'm reading "Fruit and vegetable intake and the risk of cardiovascular disease, total cancer and all cause mortality" by Aune et. al 2017)

marifjeren··on U.S. economy lost 23,000 jobs in July, a sudden reversal
Jobs down, threat of increased interest rates down
marifjeren··on The Dark Night of Mathematics
> why must this result in less joy

Well I think you answered it:

To become a developer, I disciplined my mind to do impressive and useful things. The resulting feelings were pride and speciality and therefore sometimes joy.

And those feelings are gone now that software engineering has become a low-discipline, low-barrier to entry activity.

Am I immoral or vain for having derived joy from that -- I think is another matter, and one which doesn't resurrect the joy no matter how it's answered

marifjeren··on The Dark Night of Mathematics
Grateful for this essay. Made me feel seen.

Someone said:

> No one is stopping you from doing what you enjoy.

But that's wrong. LLMs are creating an environment in which some things are no longer enjoyable.

For example there is less joy to be had in learning a programming language in 2026 than there was in 2016, because there is less utility in it now.

marifjeren··on The cost YAGNI was never about
Thanks. I missed that.
marifjeren··on DocumentDB – a MongoDB compatible open-source database
Name it anything else for god's sake. DocumentDB is already what everybody calls Amazon DocumentDB
marifjeren··on The cost YAGNI was never about
The article does not say this.
marifjeren··on The cost YAGNI was never about
Interesting. How do chip companies plan such projects? Do they use agile, waterfall, or some other non-software-industry frameworks?
marifjeren··on The cost YAGNI was never about
> This is not an argument that prediction is hard, as if a sharper architect escapes it.

I disagree with this. The argument _only works_ if prediction is hard.

marifjeren··on The Singularity will occur on a Tuesday
Correct.
marifjeren··on The Singularity will occur on a Tuesday
> I [...] fit a hyperbolic model to each one independently

^ That's your problem right there.

Assuming a hyperbolic model would definitely result in some exuberant predictions but that's no reason to think it's correct.

The blog post contains no justification for that model (besides well it's a "function that hits infinity"). I can model the growth of my bank account the same way but that doesn't make it so. Unfortunately.

marifjeren··on Show HN: TimeProofs – Prove when data existed without uploading it
To me that's "what it does" whereas I'm wondering when it would be useful.

In other words, I can't think of a use case in industry or academia or daily life or whatever, where someone needs to prove that a file existed at a specific time

marifjeren··on Show HN: TimeProofs – Prove when data existed without uploading it
That's cool. What's an example of when this would be useful?
marifjeren··on Go away Python
No, I'm being cheeky. It's not fun. It's a "15 standards" situation https://xkcd.com/927/
marifjeren··on Go away Python
> don't want to have virtual environments and learn what the difference between pip, poetry and uv is

Oh come on, it's easy:

Does the project have a setup.py? if so, first run several other commands before you can run it. python -m venv .venv && source .venv/bin/activate && pip install -e .

else does it have a requirements.txt? if so python -m venv .venv && source .venv/bin/activate && pip install -r requirements.txt

else does it have a pyproject.toml? if so poetry install and then prefix all commands with poetry run ...

else does it have a pipfile? pipenv install and then prefix all commands with pipenv run ...

else does it have an environment.yml? if so conda env create -f environment.yml and then look inside the file and conda activate <environment_name>

else does it have a uv.ock? then uv sync (or uv pip install -e .) and then prefix commands with uv run.

marifjeren··on The World Happiness Report is beset with methodological problems
My criticism is about how the dramatic language differs from the banal content of the article.

Titling it "The World Happiness Report Is a Sham" and calling it "beset with methodological problems", I would expect some more serious scientific malpractices, like data fabrication, calculation errors, sampling problems, p-hacking, etc., not "I think there are some problems with this variable".

marifjeren··on The World Happiness Report is beset with methodological problems
The only problem the author points out is that he doesn't like the Cantril Ladder question.

I get it if you feel like that question falls short of representing your own personal concept of happiness, but that question is the standard in positive psychology research for measuring self reported subjective well being, and hardly enough to say the report is "beset with methodological problems".

marifjeren··on Shai-Hulud compromised a dev machine and raided GitHub org access: a post-mortem
> """ I'm strongly in favor of blocking post-install scripts by default. :+1: This is a change that will have a painful adjustment period for our users, but I believe in ~1 year everyone will look back and be thankful we made it. It's nuts that a [pnpm|yarn|npm] install can run arbitrary code in the first place. """

- a pnpm maintainer 1 year ago

https://github.com/pnpm/pnpm/pull/8897

marifjeren··on Programmers and software developers lost the plot on naming their tools
There is actually a good reason not mentioned, not to name tools by their purpose:

- the purpose will change

Your "silicon-valley-bank-integrator" tool will eventually need to be updated to do something else.

Or your "login-page-config-service" tool may eventually do more than just logins.

Using gibberish or mythological names gives a nice memorable name that doesn't lead (or mislead) you to believe it does a particular thing which may or may not be correct anymore.

marifjeren··on ULID: Universally Unique Lexicographically Sortable Identifier
Sorry, I'm not familiar with the ULID spec. You seem to be, hence my asking. Are you saying monotonic/sequential ULIDs are just (or just as easily enumerated as) Base32-encoded integers?

Oh and yeah, I guess I do think lots of script / AI kiddies would be discouraged by, or fail to see an opportunity when presented with, something that does not look like the numbers they saw in school.

marifjeren··on ULID: Universally Unique Lexicographically Sortable Identifier
> If you need a sequential ID, just use an integer

Are monotonic/sequential ULIDs as easily enumerated as integers? It's the ease of enumerability that keeps a lot of folks away from using sequential integers as IDs

marifjeren··on 1D Conway's Life glider found, 3.7B cells long
What does 1D mean here? It's a single row of length 3.7b?
marifjeren··on Study finds memory decline surge in young people
Why would that differentially affect young people?
marifjeren··on NPM debug and chalk packages compromised
Definitely sounds like spear phishing targeting you specifically.

Kudos to you for owning up to it.

As others have said, it's the kind of thing that could happen to anyone, unfortunately.

marifjeren··on Sheafification – The optimal path to mathematical mastery: The fast track (2022)
Not much attention given at all to explaining what order in which these should be read or what optimality means. This is just a list of books some guy is proud to have read
marifjeren··on Emailing a one-time code is worse than passwords
> This is terrible for account security

It's "terrible" because the author can describe exactly one phishing vector?..

Have you ever tried resetting a password before? Passwords have a similar phishing vector, plus many other problems that magic links and one-time login codes don't have.

If six-digit login codes are less secure than passwords, the reasons why are certainly not found in this article.

marifjeren··on Self-Signed JWTs
> How do you pre-register them then?

Exactly my complaint. You still have to go into some web portal and install your public key, I guess.

> What prevents someone else from trying to register or push my JWKS to the API owner?

Well for one thing they wouldn't have access to your public key since you won't be hosting them publicly somewhere. But for another thing it will be useless to them unless they have access to your private key

marifjeren··on Self-Signed JWTs
> In both cases the underlying identity model is actually based on DNS, IP, and internet domains - whoever controls those for your email/JWKS controls

Hmm I wonder if you are thinking that the JSON webkeys of the user need to be hosted publicly. I don't think they technically do. It's a common convention to do so (especially at some well-known URL).

But the user actually could instead send their public key on each and every JWT-bearing request they send, and as long as that public key is both (1) pre-registered with the API owner and tied to some identity the API recognizes as some authorized user and (2) can successfully be used to validate the signature, it should work just fine.

marifjeren··on Self-Signed JWTs
> Visit our website. Create an account. Verify your email. Create a project. Add your credit card. Go to settings. Create an API key. Add it to your password manager. Drop it in your .env file. Download our SDK. Import it. Pass your env var in. Never share your API key. Make sure you never commit it to source control.

None of this "BS" actually goes away with self-signed JWTs, right? Just replace mentions of "API Key" with public/private key and it's otherwise a similar process I think.

marifjeren··on Ask HN: What is so good about MCP servers?
Text-to-text LLMs can only do one thing: output text.

These other capabilities that chat tools provide are actually extras built on top of the output sequence:

- reading and editing files

- searching the web

- executing commands

If your favorite chat tool (ChatGPT, Gemini, Claude, Cursor, whatever) already has all the tools you want, then you don't need to add more via an MCP server.

Page 1 of 3Next →