HNHacker News
TopNewBestAskShowJobs

mathewpregasen

110 karma · joined March 24, 2017

submissionscomments
mathewpregasen··on BYOK library for tracking AI search, MIT License
Thanks for the kind words !
mathewpregasen··on BYOK library for tracking AI search, MIT License
Hey! We made an open source AEO tool. It's not better (or worse) than any other AEO tool, but it's open source, BYOK, free, and MIT license. Have fun!
mathewpregasen··on We made Postgres writes faster, but it broke replication
Personally I have Canola and Sunflower oil tied. Vegetable Oil I guess deserves a mention here too.
mathewpregasen··on We made Postgres writes faster, but it broke replication
Yeah, in general, I think a lot of businesses would love to skip ETL pipelines if possible / consolidate data. Postgres is a very much a neutral database to extend upon, maybe a wild analogy but it's the canola oil of databases
mathewpregasen··on Supabase MCP can leak your entire SQL database
Oso posted a blog post [1] about this yesterday that's quite informative. I separated posted it on HN [2], but linking here.

[1] https://www.osohq.com/post/why-llm-authorization-is-hard [2] https://news.ycombinator.com/item?id=44509936

mathewpregasen··on Why don't we have a permanent OSS license?
this is helpful feedback, thank you. Could you elaborate on 1 though?
mathewpregasen··on Why don't we have a permanent OSS license?
A little piece I wrote. I might add more to it later, but I'd love any feedback. I feel like I might be missing something.
mathewpregasen··on parrot.live
this is what Hacker News was made for
mathewpregasen··on Authorization Migrations: From Chaos to Clarity with Oso Migrate
Neat new launch from Oso on authorization migration
mathewpregasen··on Is an all-in-one database possible?
a short article I wrote a while back on a topic that's always been at the back of my mind — will databases ever get "JSON/Javascript-fied?"
mathewpregasen··on ClickHouse saved our events engine problem
yes I've met the founder actually! I have not played around with it yet though
mathewpregasen··on The Danish Sugar Beats Auction pioneered privacy-first multi-party computation
dammit, i cant spell :/
mathewpregasen··on The Danish Sugar Beats Auction pioneered privacy-first multi-party computation
This was a crazy topic to research and write — multi-party computation is one of those white-paper heavy topics with tons of hypothetical scenarios, but limited implementation. One of those implementations, however, was the 2008 Danish Sugar Beats Auction.

Since then, MPC has barely been used, ignoring some noteworthy exceptions.

mathewpregasen··on Was Y Combinator worth it?
was a great experience for me, even with the pandemic sabotaging our demo day last minute
mathewpregasen··on SF cops, firefighters vent prior to big vote on driverless car expansion
"Cruise, Waymo pitch: First responders should train to disable self-driving cars" this is a crazy sentence
mathewpregasen··on Secure multi-party computing never delivered on its promise
FWIW, Apple (and other's) leaked password check algorithm is a big mainstream adoption, but it's hard to count Private Set Instruction when it's a fundamentally easier problem and minimizes the "multi" out of MPC.
mathewpregasen··on Secure multi-party computing never delivered on its promise
When researching this piece, I was shocked how the world's first adopter of MPC was the 2008 Danish Sugar Beats Auction of all things. Sad to see it's one of the very few, even today in 2023.
mathewpregasen··on Why SMTP still matters today
I think the real question is if you ever see SMTP ever getting replaced by a newer protocol
mathewpregasen··on Redshift versus ClickHouse
I've done a lot of ClickHouse versus X comparisons for Posthog. This one was particularly hard because Redshift keeps issuing big updates, but I'm pretty happy where it ended up and wanted to share it.

It does amaze me how ClickHouse does hold up against a lot of these databases backed by BIG companies—it really is a drag racer (Robert Hodges' analogy, not mine).

mathewpregasen··on Ask HN: Headless CMS with access to underlying data?
thank you, I'll check it out!
mathewpregasen··on Are Widgets Cool Again?
I'm convinced that website widgets are cool again. Back then, widgets were these sort-of janky modules you'd add to a site to get some repeatable functionality. Social buttons, comments, etc. Then they went away when every site was trying to be in-brand through and through.

Nowadays, I think they're back. They've just branded to "embedded apps", and have much more features (and integrations) than before.

mathewpregasen··on Anime.js – A lightweight JavaScript animation library
I am actually writing a piece right now on the best animation frameworks for React (Framer Motion, react-spring etc.)

Was including Amine when I found this very recent HN post. I'm curious, in your perspective, what are the benefits of using Amine over something like Framer Motion? And would you recommend using the react-amine npm package or doing a custom binding—couldn't tell if that package was official.

mathewpregasen··on Is ORM still an anti-pattern?
I think most ORMs support transactions at this stage!
mathewpregasen··on Is ORM still an anti-pattern?
It's more that ORMs are often perceived to be far slower on average, but in reality, they are not that much slower most of the time, and only far slower in choice scenarios.

But yes, agreed on your comment on general abstraction.

mathewpregasen··on API integrations are making the internet less secure (opinion piece)
Keys of higher risk should be done more frequently. How frequently is more a matter of risk (is your company a target?) + engineering bandwidth to do it.

All keys should at least be refreshed once a year. At least.

It's worth mentioning that refreshing keys could also introduce security risks if you don't have a defined process. For instance, if an engineer is consistently emailing new keys to another engineer, that's probably (most definitely) a bad idea.

mathewpregasen··on Has an API key issuer ever leaked customer API keys
I know 3Commas and Cloudflare’s 2017 breach is sort-of this, but curious if a company have ever leaked API keys they create / manage and had to cycle every customer’s keys as a result
mathewpregasen··on JavaScript data visualization libraries in 2023
A blog post I wrote on data visualization libraries for my friends at Explo. Explo isn't a data visualization library but had to commit to one early on, so we did a deep dive on the pros and cons of D3, Vega, Vega-Lite, and Highcharts.
mathewpregasen··on What Happened to ChatOps?
Recently wrote a piece on ChatOps, which is a bit of a curious term that's gone out of style but remains a pretty common DevOps pattern.
mathewpregasen··on Launch HN: MagicBell (YC W21) – embedded notification system for your product
We use Courier ourselves and LOVE your product