HNHacker News
TopNewBestAskShowJobs

ss3000

578 karma · joined October 13, 2019

submissionscomments
ss3000··on Next.js 9.5
I haven't really kept up to date in this area so would love to hear some experts weigh in here: Do search engines (or really just Google) still penalize sites that are pure SPAs on that fact alone?

Or does it have more do do with properties generally associated with SPAs like large bundle sizes or slow time to first interaction?

I'm mainly wondering if you can build a SEO-friendly SPA marketing page today using techniques like dynamic imports and code splitting to lazy load just the scripts and content needed for the initial render instead of going all the way to static generation or server side rendering.

ss3000··on Windows on Raspberry
Curious if you have a source on the x64 part I can read up more about?

Mainly wondering if I buy an ARM Windows device today, is it just a matter of upgrading Windows somewhere down the line for x64 support? Or will I have to shell out for brand new hardware?

ss3000··on Front End Interview Handbook
That's fine, but FWIW if I had to strictly choose between the two, I too would also optimize for passion over expertise (of course it's never a binary choice in the real world).

Though I think it has more to do with the kind of developer I am and the kinds of developers I've enjoyed working with in the past than anything intrinsic about how much value they might be able to provide to the company.

Luckily for me, I've noticed that frontend developers (especially those who like to work for startups) tends to be a very self-selecting group that biases towards passion. Those who don't have at least some amount of passion for frontend development would probably very soon realize they'd be happier specializing in some other ecosystem and migrate away (as you yourself did).

ss3000··on Launch HN: Reflect (YC S20) – No-code test automation for web apps
Had very similar experience with Cypress here as well. The command queuing API that abstracted away async operations sounded awesome in theory and I totally drank the coolaid.

But once I started to write tests with it, I realized the model was optimized for simple tests where you can afford to act only as the end-user, whereas for the more complex flows we're interested in testing, you need to act both as the end-user as well as, say, someone in the operations team doing a bunch of manual approval steps, or say, the email/sms system that delivering some secret out-of-band (through a staging backdoor API), interleaved between the end-user actions, and not being able to precisely coordinate those async interactions between these distinct actors made those tests extremely awkward to write compared to something using playwright/puppeteer, where you just coordinate promises like you usually do.

That's before we get into the limitations around single domain per test which meant we couldn't effectively test our login flow that uses a separate domain for login for OIDC.

ss3000··on Launch HN: Reflect (YC S20) – No-code test automation for web apps
I asked this elsewhere in the thread to a different user, but it seems relevant here as well:

Curious how your service would handle a app that mandates non-email based MFA like SMS or TOTP.

Additionally, what about testing a onboarding flow that might require some form of manual approval?

Thanks!

ss3000··on Building a Developer Cult
That's fair and valid, but shifting your culture from one that's laser-focused on shipping features that work to one that cares about shipping polished features that delights users definitely gets exponentially harder as your company scales in size.

The sweet-spot for making that transition is essentially as soon as you've found product-market fit, no later and no sooner, and missing that sweet spot even a little bit can make the transition very difficult and very costly. But the dilemma is, as most successful founders will likely tell you, we're only good at identifying product-market fit in hindsight, long after it happens (and it may never actually happen).

I've worked at plenty of companies that pay lip service to wanting to ship polished features that delight users while still overwhelmingly shipping features in a very utilitarian, timeline dominated fashion, long past the point where they've demonstrated product market fit.

As with anything in product/engineering/design, it's all about tradeoffs and striking the right balance, and where the right balance stands will always keep shifting under your feet as you make progress...

ss3000··on Launch HN: Reflect (YC S20) – No-code test automation for web apps
It sounds like you're running these tests on a schedule against production?

If that's the case, curious how you might build a test that can handle something like a MFA token request on login.

ss3000··on NewPipe – ad-free, open-source Android YouTube client
Yes the app itself is closed sourced, but FWIW their MicroG fork is not: https://github.com/YTVanced/VancedMicroG

Their stance on why they can't open source it sounds reasonable: https://github.com/YTVanced/VancedWebsite/issues/10

But I agree that if you have sensitive data on your google account you should make a value judgement yourself on if the extra convenience/features on Vanced is worth the risk over NewPipe.

I personally use a different mail provider so I don't have much sensitive information on my Google account, basically just using it for YouTube and Play Store.

ss3000··on Lies, damn lies, and front-end tracking
One thing important to note is for certain use cases of Optimizely like A/B testing, it's actually desirable to block rendering until it's initialized as otherwise you end up with a flash of the default variation that then gets switched to the appropriate one afterwards.

Though after working with a few of these A/B testing vendors, I'm firmly convinced that you'd be better off long term implementing your own A/B testing service on top of some internal admin UI builder like Retool.

ss3000··on NewPipe – ad-free, open-source Android YouTube client
Piggybacking on my own comment, I'd love to hear if anyone has ideas on how to block Ads on a Chromecast...
ss3000··on NewPipe – ad-free, open-source Android YouTube client
> This is the best youtube client, bar none. It keeps local history and "subscriptions" without requiring you to log in to google.

Isn't it funny how one man's feature is another man's bug?

Not supporting logging in with a Google account to keep subscriptions and history synchronized across devices is exactly what disqualifies it from consideration for me, and I suspect I'm not alone here.

For those like me there's YouTube Vanced, which is almost an exact clone of YouTube except without the ads, allows you to disable a bunch of distracting "features" like info cards and watermarks, and with the ability to use MicroG in place of Play Services for the actual logging in with Google feature: https://vanced.app/

Isn't it great that we both have the ability to choose the YouTube replacement app that works best for us despite Google technically "owning" the platform though? This is why I love Android. (EDIT: Re-read this and realized this could be seen as inflammatory. Really did not mean to start a platform war. Just glad that Android is a choice that's available to those who value this kind of thing.)

ss3000··on WebTorrent Desktop 0.23
I've been using Webtorrent Desktop for quite a while now, and really enjoy using it generally, but there are some glaring issues around random freezes on fast connections, plenty of open issues on it with other users reporting the same experience: https://github.com/webtorrent/webtorrent-desktop/issues?q=is...

I've personally been working around this using a custom fork that messes around with the simultaneous connections settings of the webtorrent library, and it seems to help a bit, but I still get freezing from time to time when I download a large number of torrents simultaneously.

I wonder if an alternative Webtorrent implementation (not Webtorrent Desktop) in Rust on top of WASM might make those kinds of issues easier to avoid with its safeguards around concurrency and just generally making more efficient use of resources.

(Slightly edited repost from an earlier thread about Webtorrent, feels a lot more relevant on this one)

ss3000··on Skypack – A new kind of JavaScript delivery network
Yeah, I think a service like this might be very useful for quick prototyping and proving out an MVP thanks to the native es6 modules, but I personally wouldn't rely on it for anything critical.

Coincidentally jspm.dev, a similar ES modules CDN in this space recently released a new version as well: https://jspm.org/jspm-dev-release

Their release post had a lot more technical details (including their strategy for code splitting which is critical for the production use case) so I'm inclined to trust them a little bit more for production use cases. Curious where I could read more about the architecture behind Skypack?

ss3000··on Libtorrent adds support for the WebTorrent protocol
I've been using Webtorrent Desktop for a while now, and really enjoy using it, but there are some glaring issues around random freezes on fast connections, plenty of open issues on it with other users reporting the same experience: https://github.com/webtorrent/webtorrent-desktop/issues

I've personally been working around this using a custom fork that messes around with the simultaneous connections settings, and it seems to help quite a bit, but I still get freezing from time to time when I download a large number of torrents simultaneously.

I wonder if an alternative implementation in something like Rust on top of WASM might make those kinds of issues easier to avoid by making more efficient use of resources.

ss3000··on Valve secrets spill over in new Steam documentary app
I used to be a huge Valve fanboy, but throughout the years they've managed to burn away all of that goodwill through a combination of not building good games anymore (or at least not releasing them, as I learned in the article), and pioneering microtransactions and loot boxes (read gambling) added to their existing games that profit mainly off of gamers with poor self control (most of whom are literally children).

Although I also blame the gaming community as a whole for collectively rejecting the subscription model for games, which made the much more exploitative f2p + microtransaction/lootbox business model the only real viable option for games that require ongoing development.

ss3000··on Firefox Android: Camera remains active even when the phone is locked
> Regardless, an app like Firefox should not be doing this, or even offer it as an option.

Why shouldn't I be able to use a website called imgettingpulledover.com on Firefox instead of an app to do the same thing that you just described?

EDIT: posted this before the edit, edited version makes sense.

ss3000··on Elevator.js – A “back to top” button that behaves like a real elevator
This is interesting, I've often found the buttons to be useful at times on mobile, so was wondering where all the hate came from, and turns out it was because iOS already has the feature built-in (I use Android, which doesn't really have an equivalent afaik).

Though to play devil's advocate, I'm willing to bet 80%+ of iOS users have no idea the feature even exists, so removing it just because it's available as a system feature doesn't sound like a particularly compelling argument to me.

I think having some kind of sticky navigation instead of scroll to top makes for a much more compelling UX though, since it accomplishes the same goal without the downsides of hitting it by accident causing an irreversible loss of context.

ss3000··on Elevator.js – A “back to top” button that behaves like a real elevator
The music gave me a small heart attack as well since I was just watching a movie earlier and had my volume turned way up.

Had a good laugh about it afterwards haha...

ss3000··on Ask HN: How to avoid over-engineering software design for future use cases?
> How far should we go in making things generic?

My rule of thumb for this is to repeat yourself at least 3 times before trying to build an abstraction to DRY them up.

3 use cases is obviously not always sufficient inform the design of a good abstraction, but IME:

- abstracting at 2 use cases is very often premature and results in leaky/brittle abstractions where the harm from added coupling between fundamentally incompatible usages far outweighs whatever little harm can be introduced by keeping the 2 usages as repeated code, and

- with any more than 3 use cases, the maintenance cost of keeping the usages in sync starts to scale non-linearly, so at the very least thinking about a design for a potential abstraction at that point becomes a worthwhile exercise, even if we end up deciding it's not yet appropriate (hence the "_at least_ 3 times").

ss3000··on Mozilla VPN
I love Mozilla and Mullvad, but 5 simultaneous connections just isn't enough for me. I know they can't allow unlimited devices due to the potential for abuse, but is something like 20-30 connections so I can use it for all my devices/VMs isn't too much to ask for?
ss3000··on Reverse Engineering Snapchat: Obfuscation Techniques
In my experience, SafeteyNet bypass on rooted devices has been a solved problem for a long time through Magisk Hide.
ss3000··on George Floyd Protest – police brutality videos on Twitter
Disgusting. After things settle down, in addition to all the systematic reform that will hopefully take place, I hope we can look back at these videos and put all of these officers in jail for violating the constitution and betraying their oath to protect and serve their communities.

It's finally time to put all that facial recognition tech to good use.

ss3000··on George Floyd Protest – police brutality videos on Twitter
What does the existence of riots have anything to do with these instances of police brutality on _peaceful_ protestors?
ss3000··on Just Eat Takeaway to acquire Grubhub for $7.3B
> they aren’t willing to tip

I wish everybody would stop tipping.

If nobody subsidized delivery workers' wages with tips, delivery companies would have to start paying workers enough to make it actually worth their time to begin with, and pass those costs onto VCs and eventually consumers.

More reliable income for the delivery workers, more transparent delivery pricing for consumers. What's not to like?

A similar dynamic will likely play out in other industries where tipping is common as well.

Alas, I do end up tipping in real life because I don't want delivery workers to suffer more than they have to in the mean time until not-tipping becomes the norm and wages increase as a result, so it's a bit of a chicken and egg problem.

ss3000··on A Visual Guide to React Mental Models: UseState, UseEffect and Lifecycles
I would say the biggest JavaScript inflicted pain when working with React is the lack of a notion of value equality in the default mutable collections.

Coming from a ClojureScript background, it pains me to have to deal with all the idioms in React that hack around this fundamental impedance mismatch by forcing users to carefully maintain reference equality for collections between renders for perf optimizations, and more recently for correctness in hooks like useEffect.

ss3000··on Tell HN: Triplebyte reverses, emails apology
An apology is a company's best shot at damage control after a PR disaster. A well crafted one has obvious benefits in that it might win some people back, as can be seen from the people defending Triplebyte in this very thread.

Just because it doesn't work for everybody doesn't make it not worth doing.

FWIW the apology doesn't do jack shit for me.

ss3000··on Tell HN: Triplebyte reverses, emails apology
> Processes are fine for preventing operational mistakes, but when it comes to ethics and executive judgment, they’re a poor substitute for having trustworthy people making the decisions.

Exactly this. The only thing that _might_ actually make me trust Triplebyte with my data again is if their current CEO actually stepped down to a less influential role. If I were part of the board I'd actually be advocating for him to step down or be forceably removed if possible.

He didn't put a stop this catastrophic breach of trust after being made aware of it. Even worse, he seemed to have actively drove this forward in spite of opposition. I'm simply not willing to trust a company where he's the top-level decision maker with data as sensitive as they're dealing with, apologies or not.

ss3000··on Tell HN: Interviewed with Triplebyte? Your profile is about to become public
You know what, it's clear that you've put a lot of thought into this from the product & strategy side, and these are genuinely great ideas with significant potential social impact that are worth exploring further.

But it really is a shame that from this incident, myself and many others will no longer be willing to trust you and your team with the data needed to execute on these ideas.

At the end of the day, we entrusted you with extremely sensitive data in order to use your service that could threaten our very livelihoods if exposed. Your choosing to expose this data without explicit opt-in shows an alarming lack of empathy for your users and that you were never deserving of this trust.

ss3000··on Tell HN: Interviewed with Triplebyte? Your profile is about to become public
Who knew Triplebyte was another social media company in stealth mode all this time?

Brilliant launch strategy, coming out of stealth and dragging all of its users out of stealth along with it. /s

ss3000··on Tell HN: Interviewed with Triplebyte? Your profile is about to become public
At the moment of writing I had to go to page 3 of the comments to find the CEO's response:

https://news.ycombinator.com/item?id=23280120

Piggybacking on this comment and linking here so people can more easily see how completely tone-deaf it was.

More from his comment history here:

https://news.ycombinator.com/threads?id=ammon

← PreviousPage 2 of 4Next →