HNHacker News
TopNewBestAskShowJobs

tommyage

63 karma · joined November 25, 2019

submissionscomments
tommyage··on Mistral Large 4
> Of course. As I noted before, dripping in European condescension. Nothing you can actually point to, just condescension from a region that has been left behind over the past century.

Let's see about that; Just me, some small guy with no knowledge on the topic.

> Which right or in what way has the right to privacy been attacked?

The US scans your device if you enter their land, e.g. Oh; I heard ICE uses cameras to spy on their own citizen? What about the raising Flock Cameras?

> But I do not think privacy in the US today has suffered. Please educate me.

A giant corporation just attacked another one. There were no repercussions. If you think that isn't privacy: How about leaking civilian data to outsiders of the government? DOGE, anybody?

> I am not implying anything. The Freedom Act curtailed a bunch of activities. You are implying nothing has changed. All of the Snowden revelations implicated many European countries: intelligence agencies spying on each others populations. I am asking you if you believe nothing has changed in the US do you 1) have any evidence of this and/or 2) believe that anything has changed in Europe? You've answered neither.

Why does he has to provide evidence but you don't? Also, I have never heard that an European Country spied on civilians from another country. That's an US and Chinese business model. Things changed in the US. It is now a lawless country. A war mongering state which dumps its allies for their own benefit. They are actively hostile. Your second question is so unspecific I have to require elaboration: "believe that anything has changed in Europe?" - I assume you are referring to Privacy Laws? We had plenty of new laws _protecting_ consumers in this regards. Handling data responsible. Wait; What are you guys doing over there? Ah, right: You are pushing Age Verification and demand information on our criminal record systems. You are pushing biometric tracking. You are telling buys of your weapons that you have the right to disable them. Honestly: The US sucks right now. You guys have elected the stupidest idiot, twice. And now without any regulation you are actively supporting a technology which will undermine _all_ citizen in the world.

> Do you understand that the mass surveillance of European people was done at the behest of the intelligence agencies of those countries? And ditto for the NSA. The agreement was "you spy on mine and I'll spy on yours and we'll swap the intel". I am not talking about espionage. Foreign intelligence agencies spying on foreigners...what did you think they did?

Again: You are accusing all twenty five member states in one statement. To me you are just yelling polemic nonsense. EUROPOL is _cooperating_ with the US. They are hunting people breaking our laws. If any individual is lawless within our boundaries of justice, European states have the rights to try to prosecute them.

> God, it's so painful. Yes in the same way that you talk about the US as a monolith and not 50 individual states. You don't care what Rhode Island does any more than I care what Latvia does.

You are implying your behaviour. The US has _one_ president in order to bundle the power. Your states have their national rights. If you compare the US to the EU you are not informed.

> Christ you guys are insufferable. It's no wonder everyone is leaving in droves.

By appearing with such statements on the Internet as an European Civilian you are undermining our values. Maybe if you can not align with them you should proceed your journey.

tommyage··on The AI boom is making the cheapest smartphones disappear
They already did, didn't they. Should be an applicable law in 2027. Though I can not refer or interpret the actual laws, sorry.
tommyage··on On caring for user data: NeoVim caused Vim undo files to be deleted
Another one:

`:earlier 1d`.

persistant undo is like a second brain to consolidate.

tommyage··on On caring for user data: NeoVim caused Vim undo files to be deleted
`:h 'undodir'`. Also undofile is off by default.
tommyage··on On caring for user data: NeoVim caused Vim undo files to be deleted
Maybe neovim should advertise like: Your fully configurable vim instance as a full IDE on your developer machine, only.

Driven by <3, passion and bravery.

Anyhow; I switched back to vim after one year of neovim shrugs. Still a Junior, here.

tommyage··on e is a customizable self-aware Emacs-like editor written in Chez Scheme
Chapter 12.2, Guideline 1: https://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1... Program names should be between 2 and 9 characters; As a thing to consider. Also, searching for `e` may be weird.
tommyage··on GUIs should be fully keyboard-driven
A GUI is indeed superior to a TUI. And keyboard driven should be both. But neither is my preferred UI. I want CLI programs callable from my shell.

This way I can quickly repeat an action from the past. I get a history of commands inserted. _And_ I can bind my own keyboard shortcuts if necessary. TUI and GUI do not meet this level of platform independence.

If a tool is TUI only I will not adapt it. That's not the case with a GUI, though.

tommyage··on Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
I, temporarly, banned some ip range. I didn't find a source for pinpointing countries; though I am interested. Could you point me to some sources which, deterministically, resolve to some countries? To my knowledge you can not reliably identify countries by ip since this would be dependent on DNS servers. Though I am just a application programmer!

Thanks in advance.

tommyage··on “Code was never the hard part” is an insult to all programmers
I want append:

We have studied. We constantly educate ourselves (I have still not yet managed to work through the entire SICP on my own). Our tools are changing constantly. We are juggling information through devops, requirement engineers and customers. We advise daily. We get consolidated if something is complicated to summarize. We do forensics. Constantly under the pressure that some bit rot may open a new urgent bug we have to investigate. Money AND reputation on the line. It is a damn stressful job. So if we do our craft, we do it with incremental knowledge. Carefully. We build community of trust in our free time to get connected and improve. Any new member gets welcomed and onboarded. His knowledge im the future will supplement ours. So we mentor additionally.

Now comes AI. Collects the knowledge and hands it over to anyone. And we know: It is UNSAFE. Don't get me wrong; I consolidate it now as well, just to keep up with the increasing pressure to investigate. But the thing is:

While we did our craft so that we won't have to touch it in the next five years, the complexity increases every single day. And its out of our hands. If some junior comes in and starts writing decent code with ai it is nice. Until it breaks and AI won't help. Or worse: Gets applied on customer data in the wrong way.

A new ticket for the greybeards (by no means, I am not such). I think we are on the wrong track. Using ai decreases my abilities. It increases the load.

I think we should get twice the salaries. It has become unbearable.

Could you imagine that your local file server for your family consists of a enterprise database, a key-value store, possibly multiple reverse-proxies, a vector database.... my point beeing: Complexity. Invariants, frameworks to get familiar with... And the tool to supplement the demand is intransparent (but probably deterministic? Idk). It feels just so wrong.

tommyage··on Developers are attached to tools because tools encode trust
Wait; So you say you outsource development to a LLM fully knowing that it will not write sound/deterministic code and your quality requirement are your test cases, right?

I further suppose you are not writing the test cases in its whole by hand. But you try to specify them before you hand out the development task to the LLM, right?

It sounds like you just introduces a new team member which is not trustworthy yet. Normally you would review each change of him and explain how to improve hisself and the code. But that's not possible to a fixed-state LLM. That sounds exhausting.

If your Markdown Files should aim at improving the LLM contributions, you are again stuck with the fact that it did not follow in the first place.

So I conclude: You pay for an Intern who is not trustworthy and pay additional input token on Markdown Files to still no be certain about future contributions.

I just don't grasp how we as engineers are accepting this and integrate it into our craft. And: Everybody using External LLM Services, possibly providing the entire project as context, is allowed to let the source code of your company be leaked to some third party. I hope that party is trustworthy and does not have a track record of copyright infridgement. Because this would be fairly naive and reason to be fired. So we as Engineers knowing the implications should therefore point to these issues at the correct management level.

At least that's what I am doing shrugs

tommyage··on LLMs corrupt your documents when you delegate
All of software is hard-coded algorithm.

If you differ between AI source code and engineer source code say so. "Getting things done" is a business need. Which things get translated to a deterministic language executable by a computer is code.

There are entire languages dedicated for lesser engineers/domain experts to formulate business requirements.

Anyhow; What's your point? That we received a framework for "soft algorithms" where the output does not need to be correct and deducible? What's even the point of putting it into software. Just forward your input to the reader and let him judge on its own.

tommyage··on Ferron – A fast, memory-safe web server written in Rust
I am also wondering about this.

To me, your FAQ quickly addressed all questions I had to get a first grasp of the capabilities. It appears to me that you had a determined scope and I very much like that!

tommyage··on Thunderbird 115
https://www.thunderbird.net/en-US/get-involved/

Your professional input may be desired. Though I did not contribute to Thunderbird either (, yet?). Thing is, your critique may result in guidance to make part of these changes according to your skillset! But I am just a hopeless dreamer in the good of many things.

tommyage··on Saying Goodbye to GitHub
> Unfortunately moving to Gitlab or Sourcehut doesn't really help, because the underlying model (GPT-x) is trained on the entire internet, so that includes all scrape-able websites. The only way for your data not to be used in GPT (and therefore Copilot) is to not to put it on any website or make it very difficult to access, like encrypting it.

Having the entire git history decorates specific chunks (at least entire commits) with context by the commit message. So you may not only process the entire repo at one specific state in time, but the entire history in at this point in time. There is valuable knowledge while making sense of it; But this is not accessible to us. It relies in the knowledge base of one company (or two).

tommyage··on Designing Good Interfaces
> Thanks for your reply! I will need more research to reflect on the examples you give.

Please note my sibling answer which shows I am opinionated. I have memorized my own takes from such terms so researching about my answer may be time not used well. Sorry.

> - https://www.eiffel.org/doc/solutions/Design_by_Contract_and_...

Does indeed overlap. I only read about contract-based programming; contract by design via API documentation in a java environment.

> and it seemed to me the main concern was program correctness/consistency

It is. There are multiple factors to deploying correct software though.

> Maybe I mix up different concerns and good interface design is more about satisfying use case?

Apparently your are on the right track. But I would strongly agree on the latter. Such formal correctness proves didn't cross my career yet. But I am assuming safety-critical systems or systems haed to update may benefit here the most. Which would explain my lack of certainty.

Keep it up; Sorry.

tommyage··on Designing Good Interfaces
> Invariants are not a synonym for mixins, I'm not even sure where that idea might have come from. Invariants are assertions that are true throughout a program or subset of a program (like loop invariants). Where did you get this notion they were synonyms for mixins and what would that even mean?

It was my own understanding; Thanks for suggesting clarification. I falsely associated such mixins with encapsulated behaviour. It was my take on mixins and may have translated the term invariant wrong. Appreciated.

tommyage··on Designing Good Interfaces
> Is this what we refer to as design by contract?

No. One need a specification of the intended behaviour. Behind this specification lays the interface (data type, here a Object-class). This data type on the other hand can have different representations.

Design by contract is a term i didn't read as an agreed scientific term. It is used in OO-languages for some pattern, where you "generate" (read imply) a specification. E.g. two unrelated services use the same data type within their communication. This may be injected or included within their dependencies. To me its related to code generation. It may aid the collaborations between multiple developers across multiple projects to 'move faster'. I have limited and bad experience with this.

> If so, what about invariants? Are invariants related to good interface design?

Invariants in my book are then a synonym for mixins. Which in OO-Design would be represented via dependency inversion. Invariants can be necessary at best. Its no measure for a good interface. If your data types are specified such that invariants do not missbehave, they can be used.

But don't trust me on this.

tommyage··on European Lisp Symposium 2023
> Are square brackets part of the spec now? I can't get over ((((( for everything with no real easily visible distinguishability between parts of a definition. Clojure gets the Lisp-like syntax as right as possible IMO.

Square brackets are replaced by normal parenthesis to my knowledge.

Though I have to admit that I strongly dislike them. They put more cognitive effort into the syntax than they aid.

tommyage··on ChatGPT broke the EU plan to regulate AI
People posting such articles (from sites highly neglectable) without their informed take is ruining this community as well.

We shouldn't raise any questions but leave participations to themselves.

tommyage··on Ask HN: How do you test SQL?
Relational databases rely on math. You may test your implementation; Or the input to your statements.
tommyage··on GitHub is sued, and we may learn something about Creative Commons licensing
> How are you a "creator" (in an attribution-worthy sense) if you are producing an unoriginal implementation of an old algorithm that thousands of coders have produced before you?

So your requirements are pseudo-code which you simply have ti translate. I see. No creativity required. Jepp.

> Most coding is not innovative, and that is the kind of code that these tools are producing and derived from in most cases.

I see what you want to suggest. Then it woulnb't be required to learn on these datasets and simply build a "fair use" product which covers these cases with a snippet engine.

Don't be naive.

tommyage··on Five Walled Gardens: Operating systems are holding browsers back [pdf]
> Can someone ELI5 what Mozilla did to deserve this derision?

Assumption: People have troubles with certain web applications like MS teams, goto-meeting,.. or youtube. Mozilla has to adapt to undocumented changes. There are an increasing amount of applications which do not support firefox (strange, because the web should be browser independent). People think Mozilla is responsible for this.

Mozilla does not generate income with Firefox (besides dontations!). Why is it so important to have the biggest market share with a browser? I suppose there is data to be collected by the other players.

tommyage··on A plain-text file format for todos and check lists
You are right, I didn't wanted to imply that these lists can only be used by speakers fluent in english. I wanted to imply that grammars of languages are best represented in ASCII.

There are languages written from right to left or top to bottom. No standard I know of are supporting such flexibility in syntax. And it shouldnt be necessary - if the <user text> items within the grammar support unicode but the keywords are ASCII only it can MORE easily adapted than supporting unicode....

tommyage··on A plain-text file format for todos and check lists
> - doesn't support UTF-8 checkbox emoji

That's a good thing. Its also unicode, not utf-8. Your plugin can display it with a unicode character. Having a simple ASCII char set helps portability _a lot_. No benefit in supporting unicode code points.

> - doesn't support nested lists

If you can tick all items within a nested list, why bother writing it with dedicated TODO items? Additionally, you can just create more files for elaboration. Your file system is at your dispense. Additionally, that can be implemented in your plugin of choice. Goes with your first point in hand.

> - specifies a specific space character when a character class would be better

ASCII has no official character class. If your are refering to tabs; I don't think this is bad or good. Maybe you can follow uo on the use case..

> - not clear what "item must not contain blank lines" means

Probably that a blank line is used as a separator

> - description indentation limit of four space characters is a problem for nested items

I don't see why. The fixed amout of four characters obviously lines up to the start of the text from an item. This helps readability a lot. And is a simple standard for identation rules.

> - description supporting blank lines (properly indented) would be useful for longer descriptions

I disagree. A TODO list should be simple to grasp. Details and elaborations can be put in a dedicated directoy and refered to. Also, it is a _very bad_ idea to work with invisible lines. Users are dump and quick to judge.

> - date should support an ISO or other standard date format

This is the most portable standard, but extended for human editing..

> - timezone is necessary for events happening in specific timezones or across timezones

I tend to agree. But the person hosting the list should probably be the one defining the time zone. But I haven't read anythinf about time zones in the primer. Nothing stops one to simply append it to a time. No need for the standard to define such.

I think it is well put and the first one which checks all the boxes for me. Congratz to the author.

I don't see why such a comment is #1.

tommyage··on Coping with Copilot
Who should fix the bugs in the future? Nerds? Where are they coming from 60 years from now?

E(very) S(ingle) W(ord) S(hould) be (no [ACCEPTED] completion here) W(ritten) W(ith) C(onscience). You should be responsible for your code submitted. Are your feeling confident?

Won't touch Co-Pilot. Probably you are spending equal time proof reading than _understanding what needs to be written_ in advance. At least that is what I am hoping about. Of course you don't have to proof read, and most things can probably be grasp in a glance. But you rely on a black-box. From a corporation. To me that sounds like agreeing with a dictator.

Wouldn't promise my craftmanship for things I didn't grasp in advance. But maybe that's a culture hindrance. I like it though. I want to know the code I am corrected about. I want to archive mastery.

tommyage··on Uno platform: Build single-codebase applications across all platforms
C# can be natively compiled, doesn't it?
tommyage··on No, you cannot trust third party code without reading it first
> Postponing dependency updates is very, very bad for security. That is not a solution to supply-chain attacks.

You are right; This underlines the thought and care some distributions put into their package management system...

> The whole point of APIs is that we do not need to understand the inner workers of code that we're calling. How many of us use bcrypt and couldn't tell you anything about the underlying algorithm?

That is right, but code written by unknown developers can be a huge risk. Of course you are not assumed to read up upon any dependency, but from external sources. A quick glimps on the imports and dependencies goes a long way, I think. In the end your team is responsible for security issues, even if they appear in an external dependency. Companies with direct customer sales are spending tons of money for mitigation strategies. Maybe a chunk of this money should be spend on validating this beforehand.

tommyage··on No, you cannot trust third party code without reading it first
> OK, so we're drawing an arbitrary line of what we read and what we don't.

Imo the line is not arbritary. You are including an library/framework for a purpose. The code path for this purpose should be explored. Recently I allowed a friend of mine to DDOS my server. He used unvisited software. Now my server suffers from thousand wild guesses daily. Previously, I had ten visitors a day. Therefore I conclude that the software leaked my server. And his learning: Don't trust any software; Exspecially if the software is for malicious purposes in the first place..

> A basic web application at this point is going to import at least 10k lines of other people's code. A React app probably uses millions.

I think it is a valid assumption to increase the trust in frameworks with a giant user base. React is from Facebook, isn't it? So I would have read the path _and_ random internals to picture the trustworthiness.

> There's just no way around this. We all trust code we haven't read and have to continue doing it.

It shouldn't be black-and-white thinking. When introducing a _new_ dependency I see myself responsible for estimating the trustworthiness. But yes, with an increasing amount of dependencies the process of updating such needs more effort as well. But then, we can postpone such updates, if the application under development is safety critical...

> Reading code doesn't even guarantee finding security flaws. Most of us aren't security researchers, and none of us can understand an entire project's source code the first time we read it.

Well, one should be able to judge about the workings imo. Otherwise maintainability can get painful in the long run. So better grasp it before deciding to build upon it.

Another comment stated that we are trusting cars we drive, etc. etc. This is about the users running our code. A proper craftsman will inspect its material, before using it in quality products. When building a throwable tool for his work, he doesn't spent to much time worrying, of course.

tommyage··on Apple Silicon is an inconvenient truth
Please cross compile on x86 for arm64-apple-darwin with gcc. After doing this, you should have more insight about these macs.
tommyage··on GnuCash – Open-source personal and small-business accounting software
Sorry for the late reply. I missspelled the library. Probably there is also a missunderstanding due to "lost in translation".

Here is the link: https://aquamaniac.de/rdm/

I integrated all my accounts of Kreissparkasse and DKB. Works flawlessly. I also tried all alternatives to connect to these institutions. I wouls recommed this setup.

Page 1 of 3Next →