HNHacker News
TopNewBestAskShowJobs

scsh

114 karma · joined December 10, 2016

submissionscomments
scsh··on Show HN: Pipask – safer pip without compromising convenience
Yes in this particular case, where I'm trying to install fastapi, I'd rather it direct me to https://osv.dev/vulnerability/PYSEC-2024-38 which is more fastapi specific and mentions that the fixed version of fast api is 0.109.1. Or even better, give the link and print the fixed version from the advisory yaml https://github.com/pypa/advisory-database/blob/main/vulns/fa...
scsh··on Show HN: Pipask – safer pip without compromising convenience
I like the idea of having vuln reporting in the installation step. Looking at the examples provided though, I think the vulnerability reporting could use a bit more information.

Using the fastapi example, it points to CVE-2024-24762 which, if you're looking at the NIST or CVE pages for it, doesn't give the clearest info for how to resolve.

Maybe consider linking to advisories in the Python Packaging Advisory Database when possible, like pip-audit does. https://osv.dev/vulnerability/PYSEC-2024-38 is a lot clearer that fastapi is affected and which version fixed the vulnerability.

scsh··on Four Years of Jai (2024)
You're describing pretty much every popular open source license here, including the Linux kernel(GPLv2). This doesn't set the expectation that things can and will break at any time. That's also not the approach maintainers take with most serious projects.
scsh··on Show HN: Nue – Apps lighter than a React button
fwiw, I did not have the same take away as you from that part of the comment. I think the intent, and the way I read it, was, "Even when eliminating bandwidth and latency as a factor it still takes 10 seconds to load."
scsh··on AT&T follows Amazon in demanding employees spend 5 days a week in office
I don't think they really care, or feel that they have to care. The way that I've seen it work is they'll make rare exceptions for individuals they absolutely can't lose or wan't to hire but that's it and the exceptions truly are rare.
scsh··on DOJ will push Google to sell off Chrome
It was never required to pay for it. As was common with software back then, the free download was a fully featured "evaluation" version denoted by an "N" appended to the version number. That didn't last long though and it just stayed free.

There was a "Gold" version they sold at retail for some time that had a WYSIWYG editor in it, until they made it standard as part of the Communicator suite.

scsh··on Endlessh-go: a Golang SSH tarpit that traps bots/scanners
The point of this isn't to hide your actual SSH service, but to tie up resources for those who are somewhat blindly scanning/connecting to any open SSH port.
scsh··on Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees
I work for a not so small company with a large international user base and wish I could have the option to geoblock sometimes. While you're not wrong about there being more intelligent ways to block traffic it's substantially more time consuming to apply and get it right so that you allow legit traffic and actually block what you need to.

We also aren't just talking about blocking DDoS and other common vulnerability scanning. Depending on your business there are other potentially costly fraud and abuse scenarios that you are blocking just by blocking other countries outright. Until there are tools to block all this that are as easy to apply as a geoblock, this will probably remain the unfortunate state of things. A lot of businesses just don't have the time or resources to manage all of this without applying geoblocks.

scsh··on Experian is a pile of dark pattern garbage
In addition, if they are sending email through a provider like Sendgrid, etc. you should send an abuse complaint directly to their provider.
scsh··on Womp 3D – The New Way to 3D
That doesn't seem like the optimal way of filtering when you're just trying to get eyes on your product. That criteria doesn't have anything to do with the product itself. This is something that's actually relevant to my interests, looks cool, and I'd like to try it at some point.
scsh··on Womp 3D – The New Way to 3D
I felt the same about having to signup to even see it do something. It's really not about THIS particular product or the people behind it. It's just that I'm expected to do this with seemingly ever new thing that I want to interact with. It's become so common that, for me, the signup gate becomes a decision point where I ask myself "Do I really care/want to see this?". The answer is no a non-zero amount of times and I do bounce off it at that point.

I do get the desire for them to want an audience to give updates to and try to have a consistent user base. The thing that sucks is that not only do they want to email me, so does everyone else. I've never been very protective of my inbox but the volume has gotten crazy recently so that's had to change. If they let me in and then asked for my email to continue after a couple minutes I'd be more inclined to provide it.

scsh··on American Data Privacy and Protection Act
EU laws can often be written in such a way and are a bit looser in their language in ways when compared to how it may be written in the US. EU courts are more experienced with dealing with interpretations of "reasonableness" for a given law when compared to the US, so it's not really a fair comparison.
scsh··on Stripe has decided to nuke my entire business
The TOS can be updated/changed/clarified over time and they could end up falling outside of what they cover as a result. It's not great and sucks as a customer but it can happen.
scsh··on Media confidence ratings at record lows
Absolutely. The Democratic news, as you termed it, is very much responsible for platforming what were, until now, what we'd consider much more fringe ideologies. At the very least they are helping to shift the Overton window in the wrong direction.
scsh··on Facebook sues Namecheap
Not attempting to excuse their lack of action, but there are cases where it's somewhat understandable why a registrar may not take action. For instance, if the only service they're actually providing is registration, the domain belongs to a long time customer, and they aren't hosting the site or dns, they're only left with one very blunt action they can take. It's frustrating for sure, but registrars are very hesitant to take such harsh action on long-standing customers.

In that example the domain is likely compromised though, so you need to be reporting to all the hosting providers involved as well and not just the registrar.

scsh··on Facebook rolls out job posts to become the blue-collar LinkedIn
Eh, I read it as more of a rhetorical question given the phrasing.

why would anyone ever WANT to work for a company that... vs why would anyone ever work for a company that...

scsh··on Tutorial: HTTP Client in C with libdill
Apparently the author and HN user are the same person.
scsh··on Why Some Phishing Emails Are Mysteriously Disappearing
They said it was the first send to their ~14 year old list, so a ton of those addresses probably didn't even exist anymore.
scsh··on Articles on fractals, computer graphics, mathematics, demoscene and more
He's also got a Shadertoy version here: https://www.shadertoy.com/view/MdX3Rr
scsh··on More than 800 startups sign letter objecting to plans to kill net neutrality
Care to explain why this is hypocritical and why there shouldn't be any regulation around non-mobile internet?
scsh··on Postal: Open source mail delivery platform, alternative to Mailgun or Sendgrid
If they aren't paying for a dedicated IP, those emails would be going out across the shared IP pool, and a particular IP's reputation would be affected be everyone who's email went out via that IP.
← PreviousPage 2 of 2