HNHacker News
TopNewBestAskShowJobs

mpeg

3,207 karma · joined January 19, 2012

Marcos Perona

Tech & Product things

Ex: Experian, Salesforce

Email: mperona@gmail.com

[ my public key: https://keybase.io/mpeg; my proof: https://keybase.io/mpeg/sigs/_rF1YPWP7nnvj_MEQioqkQvf_IHCEkfpSqLnTkm4kHA ]

submissionscomments
mpeg··on Cloudflare acquires Astro
Yes and no, php didn’t give you any tools to manage this, most people writing php sites back in the day (including myself) were writing js that was coupled to a specific markup yet was maintained separately. This didn’t scale well.

Then along came libraries like mootools, knockout, etc all the precursors of react, then react changed the game around encapsulation of markup and code into one place, and straightforward data flow.

SPAs were inefficient so server side rendering of js became ubiquitous, islands are a further optimisation of ssr.

This hasn’t happened in a vacuum, if you look at modern php frameworks like inertia they have a lot more in common with Astro than they do the good old 90s php

mpeg··on Cloudflare acquires Astro
Not sure how to feel about this! I’ve been known to use em dashes every now and then, but I am indeed a fellow human.

I’m close to the vite plugin in particular and have contributed to multiple frameworks around cf integration (simply because I use cf), that’s why I chose it as an example (and it’s one of Astro 6’s biggest features)

mpeg··on Cloudflare acquires Astro
Oh right, yeah I get what you're saying now. Indeed I think .astro templates make sense at the page level say to define a layout, and I actually like the syntax of stuffing the server js into a frontmatter style block, it's pretty nice.
mpeg··on Cloudflare acquires Astro
Yeah, I know, but since by default the front-end islands are server-rendered with no hydration the lines are blurred between what you would use an .astro component for, and just using for example react.

Personally I only ever use .astro components if I'm 100% sure I will never need any client side interactivity, otherwise it's just easier to ignore them.

mpeg··on Cloudflare acquires Astro
Yes, that's part of the problem, deploying nextjs to cloudflare in the first place used to be an absolute nightmare, let alone the dev experience (I think it's better now)
mpeg··on Cloudflare acquires Astro
To be fair, vite does a lot of the heavy lifting when it comes to supporting extra frameworks. If you look at the code required for astro to integrate with a new technology you'll see it's relatively straightforward.

For example, here's all the code in the svelte integration: https://github.com/withastro/astro/tree/main/packages/integr...

mpeg··on Cloudflare acquires Astro
On inter-island communication, I actually think less is more – I find a lot of the recent big features like this they have added unnecessarily constrain you to doing things a certain way, while the reason I liked Astro in the first place was the simplicity.

You can easily add any global store library to your project to communicate between islands from the very simple (nanostores) to more complex stuff (are people still using mobx, redux, etc?)

I actually would prefer if Astro kept the core more simple, I never understood the point of Astro components for example; always thought their game plan would be to build their own client-side framework like what remix v3 is doing, but currently their components are too limited to make them worth using over just doing everything in react, svelte, or whatever floats your boat.

mpeg··on Cloudflare acquires Astro
The key difference between islands and what we used to do back in the day (js on a static page) is that with an islands approach you architect your site with a components-driven approach where everything encapsulates the js/css/html it needs, then you mark it as an "interactive" island if you actually need client-side js to run – the code is the same, but it either runs only in the server (default) or in both server and client.

I know this sounds similar, but, compared to the more traditional approach, there is a certain simplicity to having everything just be javascript. You can often run the same libraries on both server and client depending on your needs, plus it fulfills the promise of web components in a way that is easier to work with (though WCs have also come a long way!)

mpeg··on Cloudflare acquires Astro
Same reason vercel buys open source... it makes cloudflare always a great deployment option for all Astro sites, which in turn helps cloudflare's core business.

For example, Cloudflare released their vite plugin which makes it effortless for frameworks that use the vite env API to run inside workerd (meaning you get to use cloudflare service bindings in dev) back in April and only React Router had support for it. Nextjs has no support, the draft PR to add support for Sveltekit has been parked until the next major version, Astro only just added support in their beta 6.0 release 3 days ago

With this acquisition, Astro will probably be first to future updates that increase compatibility with cloudflare. It's smart, and was probably not very expensive (more of an acqui-hire)

mpeg··on Cloudflare acquires Astro
This is cool, I use astro when I just want to spin up a quick site without having to fight the framework (looking at you, Nextjs) and the main thing I disliked was the initiatives around paid extras they had going

Astro and Tanstack are probably the best full-stack routers these days, and Astro wins in terms of the wide support for almost any client-side tech

mpeg··on The <Geolocation> HTML Element
This element has an autolocate attribute that will request permission automatically, plus it doesn't supersede the JS api, it simply provides a declarative alternative to it, so sites that follow this negative pattern will keep doing so.

At the same time, there is no reason to not implement this pattern today and require user intent prior to requesting the permission

mpeg··on Creators of Tailwind laid off 75% of their engineering team
You can use a product and still be critical, especially when layoffs happen, truth is there are a lot of things we don't know about their finances – tailwind definitely is successful by any metrics, they have corporate sponsors that alone give them a healthy MRR (I count at least $100k/month from the sponsors page alone)

I sympathise that it sucks having to fire people, been there. But it sucks more to get fired.

mpeg··on Creators of Tailwind laid off 75% of their engineering team
Yeah, I was referring more to the fact that tailwind didn't have that many other ways to monetise compared to other OSS projects. Their paid templates and courses kinda fulfilled their goal in that way, they made the founders wealthy, but is there a sustainable business there?
mpeg··on Creators of Tailwind laid off 75% of their engineering team
Very good point, and I imagine part of the issue here... everything they sell is one-time payment, more of a reason they should have been preparing for the music to stop
mpeg··on Creators of Tailwind laid off 75% of their engineering team
I believe you, I'm just going out of the figures they have published. If they had "several times more" annual revenue, then not having a warchest for situations like this is puzzling.
mpeg··on Creators of Tailwind laid off 75% of their engineering team
But surely the co-founders pay themselves too. I don't understand the logic in not counting them as part of the company.
mpeg··on Creators of Tailwind laid off 75% of their engineering team
I think a problem is that tailwind has no moat compared to most of those. If it never received any further updates today it would still be effectively feature-complete, save for the occasional new css features.
mpeg··on Creators of Tailwind laid off 75% of their engineering team
Apparently they were 8+ people, in 2024 team size was 6 and were hiring 2 more [0] and in 2020 they had $2m+ ARR [1].

Honestly, while I feel bad for the people who lost their jobs the news aren't exactly surprising. Overhiring is a game for VC funded OSS like bun, not usually a good idea for bootstrapped companies.

[0]: https://tailwindcss.com/blog/hiring-a-design-engineer-and-st...

[1]: https://adamwathan.me/tailwindcss-from-side-project-byproduc...

mpeg··on Stardew Valley developer made a $125k donation to the FOSS C# framework MonoGame
They use a lot of open source libraries, yes, but I think it's about how much of the end product depends on the OSS tool/library. Studios using unreal engine probably don't use that much critical OSS directly – their licensed software probably does. And the software vendors / big studios do donate to tools they depend on, for instance Epic Games donated $1.2m to Blender
mpeg··on Stardew Valley developer made a $125k donation to the FOSS C# framework MonoGame
Stardew is probably one of the most (if not the most) popular game ever made with MonoGame

AAA studios don't really use MonoGame.

mpeg··on A super fast website using Cloudflare workers
CF pages is built on top of workers, you can serve static html assets from either of them too.
mpeg··on Zpdf: PDF text extraction in Zig
Exactly this, I like to give the benefit of the doubt to people but pushing huge chunks of code this quickly shows the whole thing is vibe coded

I actually don’t mind LLM generated code when it’s been manually reviewed, but this and a quick look through other submissions makes me realise the author is simply trying to pad their resume with OSS projects. Respect the hustle, but it shows a lack of respect for other’s time to then submit it to show HN

mpeg··on Zpdf: PDF text extraction in Zig
thanks, claude, I guess haha

as others have commented, I think while this is a nice portfolio piece, I would worry about its longevity as a vibe coded project

mpeg··on Zpdf: PDF text extraction in Zig
very nice, it'd be good to see a feature comparison as when I use mupdf it's not really just about speed, but about the level of support of all kinds of obscure pdf features, and good level of accuracy of the built-in algorithms for things like handling two-column pages, identifying paragraphs, etc.

the licensing is a huge blocker for using mupdf in non-OSS tools, so it's very nice to see this is MIT

python bindings would be good too

mpeg··on We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
Yes, but this is not a particularly high access level bug.

Depending on the target, it's possible that the most damage you could do with this bug is a phishing attack where the user is presented a fake sign-in form (on a sketchy url)

I think $4k is a fair amount, I've done hackerone bounties too and we got less than that years ago for a twitter reflected xss

mpeg··on We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
I think that's unfair to say about a company that pays bug bounties at all.

A lot of other companies would have ignored the email for weeks or threatened legal action.

mpeg··on We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
For a reflected XSS? Tell me who is paying that much for such a relatively common bug...

To elaborate, to exploit this you have to convince your target to open a specially crafted link which would look very suspect. The most realistic way to exploit would be to send a shortened link and hope they click on it, that they are logged into discord.com when they do (most people use the app), that there are no other security measures (httponly cookies) etc

No real way to use this to compromise a large amount of users without more complex means

mpeg··on Post-transformer inference: 224× compression of Llama-70B with improved accuracy
I really don't mean to attack you, I hope you will take these messages to heart and at least consider talking to a mental health professional. The writings in your substack are not a good look, regardless of whether your work is correct or not.
mpeg··on Catala – Law to Code
You clearly don’t even speak the language and are just fishing for an argument. I have already explained why your comment is incorrect, have nothing else to say to you on that subject if you insist that the accent mark will completely change the meaning without understanding that the accent in català follows the normal ortographical rules while the accent in mà is diacritic, a special rule that only applies to often monosyllabic words.

mà / ma does not break the general rule because the word does have an accent mark, it just also falls under the diacritic special rule.

On your point about the author’s last name, it’s fair, but also you’re ignoring that the last name comes from the same word and is thus a spelling variation from French/Occitan, further proving your assertion of Catala != Català as wrong.

mpeg··on Post-transformer inference: 224× compression of Llama-70B with improved accuracy
I think this definitely sounds like a case of LLM induced psychosis: https://ryanshamim.substack.com/p/the-theory-of-everything-h...

OP needs medical help

← PreviousPage 4 of 32Next →