HNHacker News
TopNewBestAskShowJobs

octalmage

315 karma · joined September 7, 2014

[ my public key: https://keybase.io/octalmage; my proof: https://keybase.io/octalmage/sigs/O_lVn8xYsrt3rAEs7crWzoR8pJ1ho3MJw-EnfTk4XQY ]
submissionscomments
octalmage··on Compiz: Ubuntu Desktop's little known best friend
PixelBook has something like Expose, but it’s no where as smooth. It snaps into place in weird ways and that kills the magic.
octalmage··on The iPhone SE was the best phone Apple ever made, and now it’s dead
I sold my razer to get the N-Gage and I loved it. I am a gamer and loved the games available to it.
octalmage··on 1/0 = 0
I’ve run into this a bit with progress related stuff. I bet if you looked at progress bar libraries they’d have similar logic built in.
octalmage··on Kanban for E-Mail
I’m glad you mentioned this. I worked on an email client like this for a bit, but I found email difficult to work with. Basically I wanted to be able to whitelist important senders and have those emails appear to my desktop, then the rest I could get to when I had time to open my inbox.

I know ahead of time who I want to be able to reach me immediately. My boss, his boss, my team and my girlfriend. Everyone else can wait.

octalmage··on Hundreds of Bitcoin Wannabes Show Hallmarks of Fraud
We don’t have the stats on the number of households the payment processing industry and banking industry could power. Not saying that it’s more or less, just something I considered.
octalmage··on Drupal Remote Code Execution vulnerability exploited widely
I noticed this too. I wrote a WordPress plugin to trigger a TravisCI build when I publish a post and this works great, but it takes 5 minutes or so to publish a new version of the site. For me this isn’t a huge deal, although waiting 5 minutes to fix a grammar issue sucks, but for some this is going to be a bigger deal when they’re used to being able to make changes instantly.

I noticed that the Gatsby WordPress plugin hits every endpoint on your site to build the graphql data store, you could probably modify it to just hit the ones you need. Additionally I feel like there should be a way to do persistent incremental builds. At least there should be a way to cache the graphql stuff. Maybe a incremental webpack build plugin exists.

octalmage··on Snapchat launches Spectacles V2
I would expect them to post to Snapchat as you take photos.
octalmage··on Ask HN: Any cool ARKit or ARCore apps out there right now gaining popularity?
These are pretty cool:

https://lensstudio.snapchat.com

I’ve seen them show up a bunch online and on Snapchat.

octalmage··on Slack's bait and switch
Yeah anytime Slack is mentioned at work someone brings up IRC. So I get what he’s saying.
octalmage··on Azure Functions vs. AWS Lambda – Scaling Face Off
AppEngine standard can actually scale down to 0 instances when not in use to save money. Still very different from a serverless architecture though.
octalmage··on Chrome is Not the Standard
Apple is doing similar stuff by refusing to implement the payment request API and instead implementing their proprietary Apple Pay API. So you can use one API to target Chrome and Firefox and another for Safari. This is starting to sound a bit like IE. They were invited to join the working group for Payment Request and decided not to take part.
octalmage··on Comcast is injecting 400+ lines of JavaScript into web pages
When you run code on a website you don’t own you have to be extremely careful. You’ll learn this quick building WordPress themes and plugins. They’re pretty careful not to directly affect the website by running their JavaScript in a scoped context and using IDs in the CSS selectors, but there is nothing to prevent the website front modifying their pop up. For example if my website had the .closebn class with display: none !important, a visitor would not be able to close the pop up. That’s a pretty common class name. To prevent this you should use dynamically generated class names that get swapped out at build time, or in this case even inline styles. Something like the close button of an injected pop up is pretty critical and inline styles would guarantee that it wouldn’t be messed with.

(I haven’t tested any of this, this is based on a quick glance at the code)

octalmage··on Comcast is injecting 400+ lines of JavaScript into web pages
Just a small note that as a customer I would prefer to be redirected to a notice hosted on your website so there is no confusion about the source of the notification. If I saw this pop up on a website I visited daily I would probably think it was spam and ignore it.
octalmage··on Comcast is injecting 400+ lines of JavaScript into web pages
Exactly. The first thing I thought about when I saw this was the implications of having JavaScript that has not been tested in the context of a website running. You have no clue how it will conflict.

As a website owner you should have the right to verify all code that will run on your website to be sure that it won’t cause issues since only you have the context needed to make that call. What if there’s a global DIV selector that hides the close button, the website visitor is screwed! And they’ll just think it’s a problem with your website.

One more note, there are way better ways to do what they’re trying to do. Even with how terrible IFrames are, they prevent CSS and JavaScript conflicts. A simple position fixed div at the bottom of the screen containing an iframe seems more appropriate. If you are going to run code on my site, make sure it’s as small as possible. This could have been accomplished in 2 lines of code (excluding iframe host).

octalmage··on Comcast is injecting 400+ lines of JavaScript into web pages
Time Warner did show up at my door when they updated their speeds. I thought it was strange,and asked him to have Time Warner call and schedule a time, but it worked. He was going door to door.
octalmage··on Parcel – A fast, zero configuration web application bundler
You can totally do all of this. There are projects that just pipe the output of Babel into uglifyjs into a file and call it a day. You still “need” to use npm to install those packages though. npm puts command line utilities in node_modules/.bin to not pollute your machine. npm just stores packages as tar.gz files though, so if you wanted to you could wget them yourself.
octalmage··on Jekyll Static Web Hosting – Deployment Pipeline on AWS
I use Firebase with Cloud Functions for form handling and other data related tasks (like caching API calls). I'm loving the integration between the two.
octalmage··on Stockfish Wins Chess.com Computer Championship
This is super cool! Are there any posts about how the fishtests work? I love reading about how people solve interesting testing problems.
octalmage··on Brave expands Basic Attention Token platform to YouTube
The token is an Ethereum token, so it's totally possible to do it in a decentralized way using a smart contract.
octalmage··on Ask HN: Best tech for a web site 2018? (PHP, Rails, Django, Node, Go, etc.)?
Very interesting! The first static CMS I've seen that isn't just an API. I've used http://prose.io in the past to edit content in GitHub, but this seems nicer. Currently I'm using WordPress as a CMS and Gatsby as a frontend, mostly due to custom post type support. I need more than posts/pages.

Does this support custom post types? I believe Hugo does.

octalmage··on Ask HN: Best tech for a web site 2018? (PHP, Rails, Django, Node, Go, etc.)?
I've been using Rails and React for a couple of projects, one using Rails API mode with a separate React front end, and one using react-rails. I'd argue that with webpacker built in, there's no reason not to use React. You get server side rendering built in, automatic production builds and hot reloading. It's a great Dev experience out of the box with no setup.

Of course this depends on your frontend and your goals. If you're just going to have a minimal static frontend, then maybe React isn't a great choice. Although I'd still use React and just render it to static HTML at build time.

octalmage··on Ask HN: Best tech for a web site 2018? (PHP, Rails, Django, Node, Go, etc.)?
Tests have nothing to do with it. You can have 100% coverage on your API and it can still not be "quality". The best APIs I've seen have been "API First" design.
octalmage··on Backdoor with root access found from OnePlus phones
Does the iPhone 6s have a similar flaw? I'm still using one.
octalmage··on Go at Digital Ocean
I also think Rust is the more interesting choice, but the company I work for went with Go. It does seem to be the more popular choice.
octalmage··on Firebase Predictions Beta
Google is investing a ton of money into their cloud offerings, and it seems like Firebase is a part of this strategy.
octalmage··on How the Kodi Box Took Over Piracy
But, those little known free streaming services are also losing money here. It's those sites that are really losing.
octalmage··on How the Kodi Box Took Over Piracy
I have very fond memories of those days. I remember the first time I saw the Linux boot loader after a successful exploit using Mech assault, my buddy and I high five'd.

The project has obviously come along way since those days, and could probably not be as successful with Xbox in the name or with the stigma attached to it. Hence the rebrand. Their only chance at making it is to distance themselves as much as possible from the piracy.

The reason it's attractive to (pirate) plugin developers is that it's cross platform (they've already figured out how to get it on AppleTV for example), and a generic enough API. You can write Python to hit a webpage, find a URL, and tell Kodi to play it. Kodi has also solved distribution (repositories) and auto updates. I get it.

octalmage··on How the Kodi Box Took Over Piracy
They're ripping from sites that are ad supported. So the site doesn't get the ad impressions, and the plugin developer could (if they put ads in the plugins). Site operators hate it, and are constantly blocking them.

Basically, they reach out to about 80 sites and scrape for links, then resolve those. It's a pretty insane process, but they've got it working just well enough.

octalmage··on How the Kodi Box Took Over Piracy
My dad got one on because a coworker told him about it. It's a Fire stick you can buy on eBay that comes preloaded with Exodus. He has no clue how or why it works, just that it has every movie and TV show for free. Which is better than all of the other services combined.

I pirated a bunch of stuff when I was younger because I didn't have cable, but now it's easier to pay thanks to Netflix and all that. But like others have said I'm not going to pay $10 a month for each network. They need to work together to get their content on a single platform. People are going to do the easiest thing, and currently Exodus is winning.

octalmage··on Show HN: 4chan on the Ethereum blockchain
I experimented with this some. When you think about the costs of scaling and managing a database, the costs to post might not be so bad.
Page 1 of 4Next →