1,522 karma · joined August 31, 2020
Reviews are very rarely happening on the commit level, so having lots of small "meaningless" commits (lint fixes, fix spec, add thing) hasn't been an issue but having squashed merge commits (effectively a rebase that squashes everything) has made release management so much easier for our team.
It also has the benefit of just less cognitive overhead of micro-managing my feature branch commits that are WIP or currently in-review.
Yeah, I totally get it. I'm still miffed that they updated the game in a way that leaves me unable to play the version I actually like. I do not find this new update appealing at all.
When Overwatch came out (when I bought it) "live service" games hadn't really reached a critical mass in the market yet so the idea that they would do something like this was kinda unheard of.
I can still play CS:Source to this day, yet they need to shut down Overwatch because the sequel is out? Modern gaming is absolute garbage. This whole "you only purchase a license to play the game" nonsense is getting out of control.
Getting back to my main point though, less the bit of sarcasm, is more of a general rule of thumb that has served me well is that if you already have something like postgresql stood up, you can generally take it much further than you may initially think before having to complicate your infrastructure by setting up another database (not just mongodb, but pretty much anything else).
Being able to take 50 lines of ruby code (manual (anti-)joins and aggregates, result partitioning, etc...) and replace it with a couple lines of sql that is much faster and less buggy is a life changing experience.
The only other time I had such a dramatic shift in the way that I look at building applications is when I learned Scala (functional programming).
Story time.
Our company recently switched to JWTs for our SPAs from regular OAuth2. I told them up front - we need a way to invalidate a token if an account is compromised. The lead on this initiative said we can blacklist any token. I told him that's not practical because you would need to know the exact token to be able to blacklist and because we don't store them in the database and don't log them have any real way to figure out which token is being used by an attacker and which are not that it's basically useless.
I suggested a simple fix: cypher the private key we sign the JWT with the hashed password of the user account we're generating the token for. If an account is compromised, we can reset the password and invalidate all tokens for that one user.
I was ignored and lo-and-behold within a month CTO and tech lead are trying to track down JWTs for a hacked account. I told them we can update the app to cypher the key, it'll invalidate all tokens and people will have to log in again but at least they'll be secured. Nothing has been changed to this day, despite banging this drum for literally over a year. We've recently extracted our authentication into a micro-service (for no reason really, i'm still mad about this too) and still nothing has been done about this issue when it would have been the perfect time to fix this.
I love my job but "priorities" and "business cases" as an excuse for this kind of incompetence is rage inducing.
The point I'm trying to make is. You are most likely using some kind of web framework that can just plug in an authentication implementation, just use that. NIH is very real and it is more than a waste of time, it can be dangerous.
Personally, on my team we use Pivotal Tracker - it tracks our velocity for us and automatically "guesses" our release date based on our velocity. If we aren't happy with the projected date, we reduce scope aggressively. Clients see our backlog and can see when things change. Most of our project planning is completely automated by Tracker - we just create tasks and point them. It's the only thing that has been even remotely successful for us. If I had to give up Tracker for Jira I would quit my job.
Politics is a pendulum, and it won’t be pretty when it swings back.
Ignoring the fact that cloudflare provides we security services and they decided to just give up on it, this leaves a very sour taste in my month. I won’t be giving cloudflare my business anymore. If Kiwifarms users were engaging in illegal activity then just let enforcement do their job.
If we are not able to ask skeptical questions, to interrogate those who tell us that something is true, to be skeptical of those in authority, then, we are up for grabs for the next charlatan (political or religious) who comes rambling along.”
-- Carl Sagan
First thing that comes to mind. The Demon Haunted World changed my life but it seems like the one thing that got wrong isn't that external forces are a threat to "making progress via the scientific method to determine what is true" but science has instead been weaponized from within to push an agenda. This is much more terrifying to me.