454 karma · joined November 28, 2024
I am not an idiot. Recent developments in the open source world should already give everybody a better idea of where they should spend their time and energy.
Wow, didn't expect someone to pull off such accusations so quickly the SECOND time.
I probably wrote more code in pull requests than your HN comments combined.
The build should come from the official maintainer. Period.
And participating in open source? Oh, I can assure you I am a seasoned open source contributor, but I am not going to just contribute to a random project. Wasted too much time on issues and pull requests that nobody looked at.
Easy to criticize other people, right? What have you done?
The train of logic has run way off the rail in this thread.
And is there any evidence that VSCode is not secure, by Node.js standard? Has there been significant security incidents that were not handled properly? Has VSCode been neglecting security issues?
No to all those questions, based on my experience. Node.js inherently is loose on permissions -- by default you can do IO/connect to Internet however you want -- but that's not VSCode's fault. Otherwise, VSCode team has been very responsive at handling security issues.
(Saying this as an experienced VSCode user and extension developer.)
Of course, with notable exceptions. See Apple Car, Android tablets etc.
You need some extraordinary evidence to claim things like that.
To stretch things a bit, it's like saying, while male dominated the field of engineering in the 60s (and still do), it was exactly that kind of environment that made it possible for humans to get to the moon. Can you actually prove it? Really?
It's hard for me to imagine using git will slow down kernel development compared to sending patches in emails.
The first two tasks could be easily done by asking ChatGPT to write a script for you. Scraping a website can be a bit more tricky. Still, I don't see why you have to rely on "computer use" for these tasks -- there are much more efficient and reliable approaches to the tasks.
* it's not a "random third party". You know to whom the data is being sent, and at least according to service agreements, most services don't use your data for training. If you don't trust Claude, you could trust AWS hosted version, or GPT/Deepseek hosted on Azure. Well, if you think Amazon/Microsoft is not trustworthy and they may misuse your data in these cloud services (not some random consumer facing service where you are the product), you might as well give up your digital life.
Completely non-technical ones are few, and you can always choose to ignore them.
The feed is also non-personalized. It's not going to show a few more article on politics just because you linked on one.
By comparison, reddit is much, much worse, almost the opposite of HN. Just a bit better than Twitter, maybe. Most of my reddit browsing/participation falls into tech/hobby, yet I always find that spend more time than I'd like on meaningless stuff, and reddit keeps pushing/promoting political content (even in the context of technology).
My solution? Don't browse reddit unless I really need to for some reason (or if I really don't have anything else to do at that time).
Even if that were true, I have absolutely no problem with MTA grabbing some well deserved money.
I have brains and can verify if it's correct or not.
I enjoy writing code, but I enjoy seeing getting a feature out even more. In fact, I don't quite enjoy the part of writing basic logic or tweaking CSS which an intern can easily do.
I don't think anybody is writing prompts all day long. If you don't actually know how to write code, maybe. But at this point, a professional software engineer still works with a code base with a hands-on approach most of the time, and even heavy LLM users still spend a lot of time hand writing code.
One thing that is not mentioned -- code review. It is not great at it, often pointing out trivial or non issues. But if it finds 1 area for improvement out of 10 bullet points, that's still worth it -- most human code reviewers don't notice all the issues in the code anyway.
You really think you are the first person smart enough to come up with this idea? If this worked, it would have been automated many many years ago. We probably would not even need pilots.
How is the design of the APIs? How stable are they?
Does Jane Street respond to bug reports/pull requests (if any) quickly?