HNHacker News
TopNewBestAskShowJobs

paularmstrong

140 karma · joined April 7, 2011

submissionscomments
paularmstrong··on Lotusbail npm package found to be harvesting WhatsApp messages and contacts
The code is literally right there for you. It doesn't matter what ecosystem or package manager. Someone could distribute the same thing anywhere — it's up to those pulling it in to actually start auditing what they're accepting.
paularmstrong··on An SVG is all you need
> I use ChatGPT to compress SVGs, in particular QR codes

Why? svgomg.net exists, uses far fewer resources, and is going to give you much better results.

paularmstrong··on RCE Vulnerability in React and Next.js
> What does server components do so much better than SSR? What minute performance gain is achieved more than client side rendering?

RSC is their solution to not being able to figure out how to make SSR faster and an attempt to reduce client-side bloat (which also failed)

paularmstrong··on Why Nextcloud feels slow to use
I gave up updating Nextcloud. It works for what I use it for and I don't feel like I'm missing anything. I'd rather not spend 4+ hours updating and fixing confusing issues without any tangible benefit.
paularmstrong··on Intent to Deprecate and Remove XSLT
Parsing the XSLT file fails in Firefox :)
paularmstrong··on Fast TypeScript (Code Complexity) Analyzer
I definitely did pay attention to the description and the playground. The "full metrics" give more information, but they're still just numbers and don't explain to someone _what_ they should do to make something “better”. Again, they're just numbers, not recommendations. Most people could probably just gamify the whole thing by making every file as small as possible. Single functions with as few lines as possible. That doesn't make code less complex, it just masks it.
paularmstrong··on Fast TypeScript (Code Complexity) Analyzer
This is a bit underwhelming because it gives a score and says, "Needs improvement", but has no real indication of what it considers problematic about a file. Maybe as a very senior TypeScript developer it could be obvious how to fix some things, but this isn't going to help anyone more junior on the team be able to make things better.
paularmstrong··on Doomsday scoreboard
The way Cliodynamics, Turchin’s field, is explained feels like a very early and remedial version of psychohistory from the Foundation universe.
paularmstrong··on Show HN: Rift – A tiling window manager for macOS
Moom is an absolute crucial piece of software that I've gladly paid for upgrades to over time to support it.

There's also BetterSnapTool, which I used to use, but I think switched to Moom for specific features at one point in time. It's even cheaper and still receiving updates to continue working.

paularmstrong··on David Lynch LA House
I don't but wanted to say that I love the continuity of them used in different spaces. The whole place really looks like a single vision put together and not a bunch of disparate rooms.
paularmstrong··on Behind the scenes of Bun Install
I also just tried bun install in my main work monorepo vs yarn. bun took 12s and yarn took 15s. This is hardly a difference worth noting.
paularmstrong··on Behind the scenes of Bun Install
How often are you doing a full install of dependencies? Re-runs for me using npm/pnpm/yarn are 1-2 seconds at worst in very large monorepos. I can't imagine needing to do full installs on any sort frequency.
paularmstrong··on Behind the scenes of Bun Install
This is all well and good, but the time it takes to install node modules is not a critical blocker for any project that I've ever been a part of. It's a drop in the bucket compared to human (ability and time to complete changes) and infrastructure (CI/deploy/costs). Cutting 20 seconds off the dependency install time is just not a make or break issue.
paularmstrong··on How well do coding agents use your library?
Needing too sign up before I can see or do anything made me close the tab immediately.
paularmstrong··on Wiki Radio: The thrilling sound of random Wikipedia
No need for an AI. Text-to-speech (TTS) is by far good enough and much easier on CPU/GPU and the environment.
paularmstrong··on Sorry, grads: Entry-level tech jobs are getting wiped out
High paying jobs? yes. Good jobs? no. The organizations are typically dysfunctional and all of the things that the original comment here lead to really poor working environments and burnout.
paularmstrong··on Trump's FCC chair threatens Comcast, demands changes to NBC news coverage
I see we've moved on from "fake news" to "news distortion" to sound more legalese.
paularmstrong··on Launch HN: Sift Dev (YC W25) – AI-Powered Datadog Alternative
What's not recognizable about Duck, Square, Triangle, Asterisk, C, two different cubes, and the letter 'n'?

These, coupled with the random number generator to claim how many logs they're processing makes me wonder if the entire product is just AI generated slop.

paularmstrong··on Understanding the trade-offs of using Tailwind CSS
To add to my original thought here, most sites that people pick up on as "made with Tailwind" are that way because they tend to lack working with a designer to come up with an original design. These sites are often a single developer looking to get things done quickly, who pull together components and CSS from somewhere else, like shadcn and Tailwind examples. Or all the same, they're half built with AI tools.
paularmstrong··on Understanding the trade-offs of using Tailwind CSS
> Potential brand conflicts > > Tailwind makes design choices so designers and developers don't have to. This can result in a recognisable look. Those familiar with Tailwind can often spot Tailwind-built sites.

When landing on this author's site, I immediately thought it looked like it was made with Tailwind. The lengths they went to create their entire own custom CSS and design system to match the choices that Tailwind makes is interesting.

paularmstrong··on Uv's killer feature is making ad-hoc environments easy
It's a plugin that's included by default in Yarn 4: https://yarnpkg.com/api/plugin-typescript

In Yarn 2/3, it needs to be added manually.

paularmstrong··on Uv's killer feature is making ad-hoc environments easy
What actually, as an end user, about pnpm is better than Yarn? I've never found an advantage with pnpm in all the times I've tried it. They seem very 1:1 to me, but Yarn edges it out thanks to it having a plugin system and its ability to automatically pull `@types/` packages when needed.
paularmstrong··on I deleted my social media accounts
They can be taken immediately. Source me, former Twitter employee pre 2021
paularmstrong··on FTC Pushed to Crack Down on Companies That Ruin Hardware via Software Updates
missing the /s

Those labels don't mean much because companies have really worked around and lobbied to make it all a very murky label.

"Organic" labels, for instance, don't mean they haven't used pesticides or other harmful things – just a certain list of them.

paularmstrong··on Roku looks into serving you ads on whatever you plug into its TVs
It's really not. Commercial display TVs without smart features are expensive, but easily affordable to the affluent.
paularmstrong··on I like automations for inclusive development
> A lightweight tool I've used toward this end is Storybook.

Storybook is one of the least "lightweight" tools available.

paularmstrong··on Introducing OneRepo: JS/TS monorepo toolchain for safe, strict, fast development
Hello, author here :)

Thank you for the kind words! I had hoped to do a more in-depth feature comparison and review, but it is an incredible amount of work and I'm afraid that I will totally botch it – I've only gotten _so far_ with other tools because of the various pitfalls and workflow/devex show-stoppers that I've hit for me and my teams.

paularmstrong··on Italy divided over new pineapple pizza
Tomato is a fruit…
paularmstrong··on Cypress.io Blocking of Sorry Cypress and Currents
Playwright has experimental component testing[1] and it's been working great at my company for months.

[1]: https://playwright.dev/docs/test-components

paularmstrong··on Lit 3.0
This in itself is why web components have had such a hard time actually taking off as a viable platform to build on. You need some other library to handle the things you actually need to accomplish.
← PreviousPage 2 of 3Next →