HNHacker News
TopNewBestAskShowJobs

theodorejb

1,636 karma · joined May 15, 2014

Software engineer from Minnesota. I enjoy working with modern PHP, SQL, TypeScript, and Svelte.

Email: theodorejb@gmail.com Website: https://theodorejb.me

submissionscomments
theodorejb··on Radical Study Suggests Life on Earth Arose Twice
Design has tradeoffs, and when these are considered I doubt you'd want to trade your eyes for another organism's. The human eye is a marvel of engineering, and even today the best digital cameras we design can't capture even close to the dynamic range our eyes can see (12-15 stops vs. 20-24 stops simultaneously). After adjusting to the dark, the human eye can perceive a single photon striking the retina.
theodorejb··on Radical Study Suggests Life on Earth Arose Twice
> Life didn't spring up fully formed, it developed in stages.

Have these stages been observed, or are they merely a speculative story? No one has ever demonstrated life arising from non-life (a violation of the Law of Biogenesis).

What is semantically incoherent about my perspective that life was clearly designed?

theodorejb··on Radical Study Suggests Life on Earth Arose Twice
We know that intricate machines are designed by smart people; they don't just happen by luck. The idea that living things, which are far more intricately organized at every level than any machine we have made, could have arisen by some unknown series of chance steps is a fairy tale. It has never been observed, and even in the most controlled of environments it cannot be replicated. To me it's far more reasonable to conclude that life was designed by a super intelligent Creator. Just as a piano implies a piano maker (even if we haven't seen them), life implies an original Life-giver.
theodorejb··on Show HN: Elevators
The worst situation I've encountered is after a large conference when everyone is leaving the hotel at once. An elevator quickly fills up on the way down, but then wastes time stopping at every subsequent floor with a call, even though no one else can fit inside. At each floor the elevator stops, the doors open, the waiting people see it's already packed, the doors close, and this repeats on the next 15 floors before finally reaching the bottom where everyone gets off. If the algorithm could know an elevator is completely full and only stop at its destination floors rather than every floor along the way with a call, it would be far more efficient.
theodorejb··on Astrophysicists Puzzle over Webb’s New Universe
The Big Bang is an almost infinitely malleable story, contorted to comport with almost anything we observe. But how is this useful? The predictions of this theory continually fail. The farther we look, the more we see stars, galaxies, black holes, and other structures that shouldn't exist according to this model.

What if the universe doesn't have a naturalistic origin, but was created by God? How much greater would our understanding of the world be if more scientists focused on studying present phenomena rather than trying to fit stories about the past with observed data?

theodorejb··on Astrophysicists Puzzle over Webb’s New Universe
Instead of questioning whether the Big Bang assumption is true, astrophysicists prefer to perform endless "gymnastics" to try to make the mounting contrary data fit their theory about how the universe began.
theodorejb··on Ask HN: So what happened to Facebook "localhost" tracking?
Only if the union is against the unethical request. In some cases the union may be for it, which makes it even harder to push back.
theodorejb··on Ask HN: So what happened to Facebook "localhost" tracking?
You don't need to join a union to push back against unethical feature requests.
theodorejb··on Ask HN: What are you working on? (May 2026)
I've been building PHP Handlebars, a spec-compliant implementation of Handlebars in pure PHP:

https://github.com/devtheorem/php-handlebars

I've also been developing Cropt, a zero-dependency JavaScript image cropper which works great for cropping and scaling profile images before upload:

https://devtheorem.github.io/cropt/

theodorejb··on PHP 8.6 Closure Optimizations
This can be done with curl_multi_exec(), or with $client->getAsync() in Guzzle.

https://www.php.net/manual/en/function.curl-multi-exec.php

https://docs.guzzlephp.org/en/stable/quickstart.html#concurr...

theodorejb··on Does that use a lot of energy?
In my petrol-powered Prius I average 52 MPG, so at the current price of gas ($2.60/gallon) I pay $0.50 to drive 10 miles - less than the listed cost to drive an electric car the same distance.
theodorejb··on The rise of eyes began with just one
How would the photosensitivity and wiring to muscles come about at the same time?
theodorejb··on The rise of eyes began with just one
What benefit is an eye unless there is also the capability of processing and using the information? How would both evolve simultaneously?
theodorejb··on Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
According to the timeline it took more than a week just for Filevine to respond saying they would review and fix the vulnerability. It was 24 days after initial disclosure when he confirmed the fix was in place.
theodorejb··on Shai-Hulud Returns: Over 300 NPM Packages Infected
My guess would be so they don't have to embed an IP address or hostname in the malware to send secrets to, which could then be blocked or taken down.
theodorejb··on Shai-Hulud Returns: Over 300 NPM Packages Infected
Someone could be tricked into giving their npm credentials to the attacker (e.g. via a phishing email), and then the attacker publishes new versions of their packages with the malicious diff. Then when the infected packages are installed, npm runs the malicious preinstall script which harvests secrets from the new machine, and if these include an npm token the worm can see which packages it has access to publish, and infect them too to continue spreading.
theodorejb··on Eating stinging nettles
I can testify that steamed stingy nettles with gomasio (toasted sesame seeds and salt) is very delicious.
theodorejb··on NPM flooded with malicious packages downloaded more than 86k times
One option to make it a little safer is to add ignore-scripts=true to a .npmrc file in your project root. Lifestyle scripts then won't run automatically. It's not as nice as Pnpm or Bun, though, since this also prevents your own postinstall scripts from running (not just those of dependencies), and there's no way to whitelist trusted packages.
theodorejb··on NPM flooded with malicious packages downloaded more than 86k times
Bun also doesn't execute lifestyle scripts by default, except for a customizable whitelist of trusted dependencies:

https://bun.com/docs/guides/install/trusted

theodorejb··on NPM flooded with malicious packages downloaded more than 86k times
I would expect to be able to download a package and then inspect the code before I decide to import/run any of the package files. But npm by default will run arbitrary code in the package before developers have a chance to inspect it, which can be very surprising and dangerous.
theodorejb··on You are the scariest monster in the woods
> Human cognition was basically bruteforced by evolution

This is an assumption, not a fact. Perhaps human cognition was created by God, and our minds have an essential spiritual component which cannot be reproduced by a purely physical machine.

theodorejb··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
Yes it does, since the ignore-scripts option is not enabled by default.
theodorejb··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
Many people have non-JS backends and only use npm for frontend dependencies. If a postinstall script runs in a dev or build environment it could get access to a lot of things that wouldn't be available when the package is imported in a browser or other production environment.
theodorejb··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
In my experience, packages which legitimately require a postinstall script to work correctly are very rare. For the apps I maintain, esbuild is the only dependency which benefits from a postinstall script to slightly improve performance (though it still works without the script). So there's no scaling issue adding one or two packages to a whitelist if desired.
theodorejb··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
It's crazy to me that npm still executes postinstall scripts by default for all dependencies. Other package managers (Pnpm, Bun) do not run them for dependencies unless they are added to a specific allow-list. Composer never runs lifecycle scripts for dependencies.

This matters because dependencies are often installed in a build or development environment with access to things that are not available when the package is actually imported in a browser or other production environment.

theodorejb··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
It absolutely matters. Many people install packages for front-end usage which would only be imported in the browser sandbox. Additionally, a package may be installed in a dev environment for inspection/testing before deciding whether to use it in production.

To me it's quite unexpected/scary that installing a package on my dev machine can execute arbitrary code before I ever have a chance to inspect the package to see whether I want to use it.

theodorejb··on Go is still not good
Note that since PHP 8.0 the ternary operator is non-associative, and attempting to nest it without explicit parenthesis produces a hard error.
theodorejb··on DoubleClickjacking: A New type of web hacking technique
> The exploit requires pages to load instantly.

How so? The page with the double-click prompt immediately changes the parent page behind it to the target location, and it can easily show a loading indicator for a couple seconds to wait for the target page to render before prompting the user to double-click.

theodorejb··on NASA: Mystery of Life's Handedness Deepens
What evidence would it take for more scientists to recognize that perhaps life didn't evolve through some evolutionary process, but was intentionally created? It seems like few ever consider that their starting presupposition may be wrong.
theodorejb··on PHP 8.4
Property hooks are the headline feature, but they seem like something I'd rarely use in practice. It is nice to have the option available though, in case I need to add extra logic to a property without breaking everywhere that it's accessed.
Page 1 of 4Next →