HNHacker News
TopNewBestAskShowJobs

mkdirp

1,232 karma · joined December 17, 2021

submissionscomments
mkdirp··on Hackers claim to have breached Okta systems
> I might also add that Okta DOES NOT support any form of physical 2FA (e.g.: yubikeys), only software-based ones.

Not sure where you got this from, but we've been using yubikeys for a few months now. They even allow policies to only allow physical 2FA methods.

mkdirp··on Vanced Discontinuation
There are archives of them including checksums to ensure the files are not tampered with. I'd rather not post it here as I don't think it's allowed here, but the Vanced subreddit will have quite links.
mkdirp··on Vanced Discontinuation
All stuff they posted prior to shutting down pointed to this NFT not being a joke to be honest. Seems like their claim that it was a joke is more about damage control than it being true.
mkdirp··on Down the mechanical keyboard rabbit hole
I've been looking for a mechanical keyboard with a bunch of requirements, and never wanted to build my own, at least not yet. My requirements were loads but yesterday upon restarting my research yet again, I came across the Keychron K3, which meets all my requirements (wireless, 75%, plenty of other requirements), but what really got me was the slim profile compared to other mechanical keyboards. It wasn't even a requirement for me but when I saw it, and the reviews, I just had to have it. I've ordered it literally about 20 mins ago so it should be here in the next couple of days. I'm looking forward to it and hope it's as good as the reviews say it is.
mkdirp··on I found a security issue on a competitor, got fired and served a summons
> it's clear that someone at his own company dropped the ball and put the blame on him

Hard disagree. Why is he reporting it to his own company? It's in his company's best interest for a competitor to have a security issue. He should have gone directly to the competitor's security team. Could have potentially gone anonymous. Could have gone through another person. A reputable security researcher. Lots of other things he could have done, but didn't.

mkdirp··on Entitlement issues (2009)
While you're right, you can feel cheated, it shouldn't mean that you need to nag someone about it. I've not read the books (though saying I was disappointed with the ending of the TV adaptation, is a massive understatement), but I've had other examples. All that should do is lose trust in that person, and potentially avoid their uncompleted other work, because the same thing might happen.

Taking your example, if my friend doesn't show up, assuming I don't buy his excuse, it means a) I lose trust in him when it comes to something that matter, and b) I'm less likely to ask him to help me move next time.

mkdirp··on Ask HN: Anyone have stock option horror stories?
Young and naive story ahead so I apologise for any anger it might cause, cos I certainly get angry every time I think about it.

First job after I finished university, and I joined a start up that looked relatively promising. It was my first my second corporate job, though the first was a terrible year in industry as part of my studies.

Leadership gave lots of promises (not just to me) about the company and all, and honestly, I'm pretty sure in the early days much of it was okay to promise.

I started on a relatively low salary. Got no options. Moved up the ladder, and got some options. It wasn't a lot, so I didn't think much of it. Heck, here in London, the stock options game for start ups is nowhere near as strong as the US (mind you, I didn't know about this back then either). I was never told about a strike price. I never read the options contract. Lots of mistakes on my part.

About a year and a half after I joined, I got a sizeable pay increase because I suppose I had shown my worth maybe? I dunno. Right around that time, structure changed a little bit. I made the mistake of not checking my pay cheque to validate I had been given my pay rise. For about 6 months I hadn't been given my new pay. I raise it with the relevant people. Because we had hired someone new, and they couldn't find the new contract I'd signed (???), the new person had to go to the CEO to double check. That took another 2 months (don't ask me why).

So I had about 8 months of the pay increase difference not paid, about ~£12k. They get back to me telling me they've confirmed that I was given the pay rise, but they won't be able to pay it in cash, and instead have to pay it in stock options. Without challenging it, I accepted, because I did believe the company would grow.

Fast forward another 1.5-2 years, and I realise the company is a sinking ship, or if not, it's just drifting aimlessly. So I leave. I hand in my notice. Over the next week or so I have meetings with plenty of people to persuade me to stay with all the promises (not even a promise of a pay rise). I'm not persuaded, so our CEO straight up tells me I will lose my stock options if I leave. Didn't even get possibility get my money back. Nothing.

7/8 years later, the company is still drifting. Many aren't paid in full, or on time. It may have been a bunch of costly naive mistakes on my part, but from what I'm hearing it would have cost me more if I'd stayed.

Moral of the story: you should double and triple check your contract, whether you're young or not.

mkdirp··on Vanced has been discontinued
Unless you're a creator or an advertiser, I'm sure who why you'd be so against it, you can just not use it. It's not a "ripoff". It was just the official app with a bunch of mods applied. Ads blocked, sponser segments removed, dislike added and in general it had a bunch of UX improvements too. They never claimed it improved privacy or the recommendations. Those probably wouldn't be possible to improve anyway, since those are likely to be server side.
mkdirp··on My essential Firefox fixes in 2022
To disable pocket, you can set `extensions.pocket.enabled` to `false` in about:config instead of just dragging the button away.
mkdirp··on My essential Firefox fixes in 2022
> I’m delighted when YouTube’s annoying autoplay-next-video is foiled by it.

YouTube has this built-in nowadays. The button is at the bottom of the player, on the right hand side, on the left of the subtitles/captions button.

mkdirp··on Senior devs. Is anyone else insulted by coding exams?
I totally agree, and you should be selective with take home tests. I do very few and the potential role would really have to be worth my time if I were to get hired. I don't believe dream jobs exist. I see a jobs as a means to an end. It's a tool for me to live my life the way I want to live it.
mkdirp··on Scripting with Go
I mostly use executable scripts so I can put it in a dir in my PATH. That way I can just run globally. No need to know where it is, or how to run it.

> The biggest impediment is the ceremony for subprocessing out

Not sure I fully understand what you mean with this, but if I'm understanding it right, gorun attempts to solve this by doing `syscall.Exec()` on the compiled binary. Combined with slight variation on the "comment" hack (see examples in gorun's readme), signals get fully directed your binary.

    // 2>/dev/null ; exec gorun "$0" "$@"
    package main
    // rest of the code
mkdirp··on Scripting with Go
I'll have to check this out properly later. 10 years ago go devs rejected the idea of introducing support hashbangs and now we're left with having to use gorun[0], meaning, people are unlikely to use go for script.

I hope the go devs will reconsider. I'd love to be able to use go for scripting. But as it stands, it's a sad state of affairs because you have to rely on hacks.

[0] https://github.com/erning/gorun/

mkdirp··on Alpine Linux: Brilliant Linux Distro
Instead of using podman directly, and potentially messing with X11 permissions, you could use x11docker (despite the name, it podman support). It attempts to safely share X11 into a container.
mkdirp··on Senior devs. Is anyone else insulted by coding exams?
> I've recently had multiple candidates recently with inflated resumes. Not mere embellishments, but claiming advanced degrees in computer science when they can't solve a simple algorithmic problem (something that can be coded in <10 mins).

I've a BSc in one of the better universities for CS in the UK. I can barely implement any algorithm that I learned during my university years. The amount of times I've been told implement algorithm x, y, and z in the past ~10 odd years in my professional career has been zero. Conversely, the amount of times I've been asked to implement them during interviews has been way higher.

Unless you're hiring someone to implement such an algorithm, you shouldn't be using them as a test, because most, if not all, the algorithms we got taught during my CS degree, have one or more implementations to the point where I can just use those implementations. Heck, I wouldn't even want to waste time re-implementing it, and probably doing a bad job of it, when I can just use someone else implementation, who most likely will do it better than anything most people can.

mkdirp··on Senior devs. Is anyone else insulted by coding exams?
I'm an individual contributor, but I've helped conduct quite a few interviews at my current place (where we have coding tests) and in previous places (where we haven't had them).

I totally understand where you're coming from. The coding test I had to do at my current place took me few hours to do. The company is great, and I'm happy at the place, however, I would be lying if I didn't think twice when I got told I'd have to do a coding test after the initial screening. Certainly, I did feel insulted. The reason I ended up taking it was because it was very obviously just a test (i.e. they weren't trying to get free labour out of me). In the end, it all worked out, and I'm glad I did end up doing it.

On the flip side, sadly I've worked with a lot of people who just don't know how to code. Coding exercising aren't perfect either, but it certainly weeds out a whole lot of bad hires. I've worked with individuals who have essentially become "the documentation person". This is fine if you're in an enterprise, but in a small 3/4 person team, that one person holds back the rest a lot.

I think having a _set_ coding exercise that doesn't get free labour out of the candidate, it can help a lot towards having a stronger team. As a candidate, do be careful whose coding exercise you end up doing. There are still quite a few companies that try to get free labour out of candidates.

So yes, I think it is insulting unfortunately, but it is a necessary evil to build better teams, and avoid those who are, quite frankly, lying and are going to hold the team back.

mkdirp··on PipeWire: A year in review and a look ahead
This sounds about correct. I had a similar hunch, but I noticed it correlating to high memory instead (could be just a symptom, perhaps it was doing more swapping?). I increased my swap partition, which made it happen less often. It could be very well be the CPU.
mkdirp··on PipeWire: A year in review and a look ahead
For me on PulseAudio it consistently switched it as expected, however, it the selected audio profile was quite random.
mkdirp··on PipeWire: A year in review and a look ahead
I'm not a pro user but PipeWire has been mostly great. I originally switched because of PulseAudio was causing a hissing noise on with my bluetooth headset, and switching fixed it. However, there are still two issues that I'm struggling with and haven't been able to find a definitive answer for.

One is the audio sometimes randomly jitters while simply playing music. It seems this only happens when I use my bluetooth headset, but is fine with built-in audio.

The other is, when the automatic switching to bluetooth headset is hit and miss. Sometimes it switches, sometimes it doesn't, and sometimes one applications switch, but others don't. So I'm left to use pavucontrol to switch things over correctly.

My searches haven't returned any fruitful results so I'm not if I'm just searching for the wrong things or I'm the only person who has these issues.

mkdirp··on Cooklang – Managing Recipes in Git
The author didn't go with a space because[0] some things have spaces in them, which would be harder to figure out.

[0] https://news.ycombinator.com/item?id=28999634

mkdirp··on Nintendo is removing switch emulation videos on Steam Deck from YouTube
> A good rule to live by is to ask "what would happen if everyone did X?"

For example: "What would happen if all companies blocked individuals from doing what they want with the hardware they bought?" You get a hacking community and people imprisoned for the unlocked hardware they paid for. Not to mention a whole lot of ewaste that could otherwise work for years.

No, that's not a good example. How about this one: "What would happen if all companies opened up their hardware and stopped forcing people to upgrade for no reason?" Eutopia, that's what! Less ewaste. Less consumerism. People can actually use the hardware they paid for the way they want to use it.

This argument has been (ab)used since piracy has been a thing. I'm not aware of any company going under directly because of piracy, especially not just because of emulators. If there is one, I'd love to know, but even so, the numbers is negligible. Also, emulation is not the same piracy. While emulation can be used for piracy, it is not the main use case.

Corporations like Nintendo are not your friend.

mkdirp··on PHP Pipes in 156 Bytes
I guess I was just removing the need for an unnecessary class, but that's fair.
mkdirp··on PHP Pipes in 156 Bytes
That's what I was wondering too, especially considering there is a helper function that just wraps it. Seems rather unnecessary.

   <?php
   
   function pipe(...$args) {
     // Retrive first argument as initial value
     $value = array_shift($args);
   
     // Call the functions passing $value and assign its return
     foreach($args as $func) $value = $func($value);
   
     // Return computed value
     return $value;
   }
   
   echo pipe("10 WAYS to EAT more HEALTHY", 
     fn($s) => strtolower($s), 
     fn($s) => str_replace(" ", "-", $s)
   );
Works just as well.
mkdirp··on Privacy in email communication: we should use encryption by default
> Can't we give the law a chance?

No because law makers have at every turn attempted to undermine encryption. What makes you think they'll suddenly fine and/or dismantle the assets of the NSA/GCHQ? These are the agencies that have been central to both countries' security in times of war. Times of war that seemingly has never ended.

mkdirp··on Privacy in email communication: we should use encryption by default
> Therefore, in 2022 a daily email traffic of 333.2 billion emails is expected

I mean, sure, but let's be honest, a big majority of that is going to be spam, the next step down from that are silly little things like email verifications, password resets, notifications, newsletter spam, and other similar crap. As a millennial who doesn't touch emails for work or for personal reasons (because there is Slack, Signal or some other alternative to those two), I could very well be out of touch, but I'd be surprised if actual legitimate emails (both business and consumer) are more than 5% of that number.

I suppose 5% is still a big number, putting it at a comfortable ~16 billion emails.

Anyway, yes, we should be using encryption by default wherever possible, but honestly, encryption isn't easy for the common folk, which is going to be the majority of those 333 billion. Heck, I migrated away from PM and I struggled with a lot of it. As someone who mostly lives in the CLI, GnuPG is not easy to use. Something like MailVelope makes it easier, but still not that easy.

Then there is the matter of administration. Your sysadmin, especially of the bigger orgs, do not want encryption on your emails. Especially when the business you're in is regulated. Imagine being able to casually leak something without anyone knowing what's in the content? I know regulation is usually not a good answer for why not, but within a business, yes, it totally is. As a customer of Big Bank Corp, I do not want employees to be able to mess with my data, money, or worse, the money of the bank so that it can fail and for my money (or the tax payer's in case of govt protections) to be gone because everyone's emails were encrypted.

The only viable solution here is something like ProtonMail, which actually makes it easier to use, at $/£/€ 5 per month, not many are able to afford to part with that. And no, their free tier is really not that great. But regardless, even PM doesn't really help if a non PM user sends you an email.

mkdirp··on Hoppscotch: Open-source alternative to Postman
Now do HTTPS.
mkdirp··on Hoppscotch: Open-source alternative to Postman
The syntax of this plugin seems very similar to dot-http[0] and IntelliJ's REST client. Super interesting. Would be really interesting to have these three fully compatible with each other.

[0] https://github.com/bayne/dot-http

mkdirp··on Hoppscotch: Open-source alternative to Postman
Previously called Postwoman, renamed[0] for the following reasons:

> 1. Similarity in name with "Postman" may introduce trademark violations in future.

> 2. We don't want to hurt any other project's goodwill.

> 3. Rather than being an "alternative to Postman", we focus to become the best available testing suite in web.

[0] https://dev.to/liyasthomas/postwoman-is-changing-name-igp

mkdirp··on Dependency injection in Go with Uber-go/fx
A service still needs its own dependencies, thus forcing you to change its factories where needed. With a DI you re-define it in a single place.
mkdirp··on Dependency injection in Go with Uber-go/fx
It does, but having to go through every single error to fix the issues isn't that easy depending on the number of dependants.
← PreviousPage 2 of 6Next →