HNHacker News
TopNewBestAskShowJobs

undecidabot

232 karma · joined January 4, 2016

Hi, I'm Matt. I like programming languages!

Website: https://www.lezgomatt.com

submissionscomments
undecidabot··on I Don't Like LLMs
Are you using Cloudflare's DNS (1.1.1.1)? If so, it won't resolve[1].

[1] https://news.ycombinator.com/item?id=19828317

undecidabot··on GLM-5.2 is the new leading open weights model on Artificial Analysis
It got 46.2 on DeepSWE in Z.ai's own run[1]. That would put it between Opus 4.7 xhigh and Opus 4.8 medium.

[1] https://z.ai/blog/glm-5.2

undecidabot··on Familiarity is the enemy: On why Enterprise systems have failed for 60 years
PG wrote about this back in 2004: https://www.paulgraham.com/pypar.html

> Hence what, for lack of a better name, I'll call the Python paradox: if a company chooses to write its software in a comparatively esoteric language, they'll be able to hire better programmers, because they'll attract only those who cared enough to learn it.

undecidabot··on Tinycolor supply chain attack post-mortem
Trusted publishing is a thing now for many package registries, including npm: https://github.blog/changelog/2025-07-31-npm-trusted-publish...
undecidabot··on The Essence of Compiling with Continuations (1993) [pdf]
Also worth reading: Compiling with Continuations, Continued (2007) [1]

[1] https://www.microsoft.com/en-us/research/wp-content/uploads/...

undecidabot··on I like Odin
System programming languages also used to refer to non-scripting languages. See this paper by John Ousterhout (creator of Tcl) written in 1997: https://users.ece.utexas.edu/~adnan/top/ousterhout-scripting...
undecidabot··on Ask HN: Best books under 200 pages for developers?
Ullman's book is really accessible and what introduced me to SML as well, but for those looking for something that goes a little deeper, do read "ML for the Working Programmer" by Lawrence Paulson (author of Isabelle). It has one of the best introductions to ML's module system and even covers building a (toy) tactical theorem prover. Oh, and it's now available online for free as well [1].

Another great book on FP is "The Functional Approach to Programming" [2], which is a bit like SICP but using Caml (OCaml without the O) instead of Scheme.

[1] https://www.cl.cam.ac.uk/~lp15/MLbook/pub-details.html

[2] http://pauillac.inria.fr/cousineau-mauny/main.html

undecidabot··on Ask HN: Best books under 200 pages for developers?
Brian Kernighan (the K in K&R and AWK) also wrote a similar book with P. J. Plauger called "The Elements of Programming Style" [1]. There's even a talk by him about it online (2009) [2].

Kernighan also co-authored a (imo) really great book with Rob Pike (once an assistant of Penn & Teller [3]) called "The Practice of Programming" [4]. Unfortunately, this one is a bit over the 200 page limit.

[1] https://en.wikipedia.org/wiki/The_Elements_of_Programming_St...

[2] https://www.youtube.com/watch?v=8SUkrR7ZfTA

[3] https://youtu.be/z4iVAcYyWN0?t=180

[4] https://en.wikipedia.org/wiki/The_Practice_of_Programming

undecidabot··on Equal Access: Automated accessibility checker for web projects
Relevant GitHub issue: https://github.com/w3c/wcag/issues/695

Also, a related HN discussion: https://news.ycombinator.com/item?id=21357638

undecidabot··on SSH Agent Explained
You can configure ssh-agent to ask for confirmation if you set the `-c` flag in ssh-add or by setting `AddKeysToAgent` to `confirm` in your ssh config [1].

Once set, authentication will require confirmation via a GUI dialog provided by the ssh-askpass command. However, it does not mention the command or process requesting for authentication.

It works great on Linux, but I couldn't get it to work on macOS with the system keychain.

[1] https://man.openbsd.org/ssh_config.5#AddKeysToAgent

undecidabot··on JPEG XL: Next-Generation of Image Format for the Internet [video]
Slides: https://www.slideshare.net/cloudinarymarketing/imagecon-2019...

Background: JPEG XL is a combination of Cloudinary's FUIF [1] (successor of FLIF [2]) and Google's Pik [3].

Committee Draft (Aug 2019): https://arxiv.org/abs/1908.03565

Technical Details: https://www.spiedigitallibrary.org/conference-proceedings-of...

Features / Goals:

- high quality compression (> 60% over JPEG-1)

- royalty-free with open source implementations available from the start

- versatile: supports alpha transparency, high bit depth (16-bit), lossless compression, animations

- progressive decoding / "responsive by design"

- legacy-friendly: reversible transcoding of JPEGs with 22% size reduction (demo available [4])

Comparisons:

- JPEG 2000, JPEG XR: only marginal compression improvements

- WebP: limited (8-bit, 4:2:0), no progressive decoding

- BPG/HEIF (HEVC): patent-encumbered (not royalty-free), no progressive decoding, complex

- AVIF (AV1): no progressive decoding, complex, slow?

[1] https://cloudinary.com/blog/introducing_fuif_responsive_imag...

[2] http://flif.info/

[3] https://github.com/google/pik

[4] https://google.github.io/brunsli/

undecidabot··on Fundamentals of Python Programming [pdf]
I apologize for going off topic, but if the author is reading this (perhaps I should email him instead), please be informed that your work has been plagiarized on Amazon, by a book called "Python Programming: A Step By Step Guide From Beginner To Expert" [1]. Read the first few pages of the print book's "Look inside" and you'll see a word for word copy of the book.

Not only did they plagiarize your work, but they did a really poor job of it too. The print is full of formatting issues. The code blocks are not properly indented, which is not only poor style but also broken given that python is white-space sensitive. And bizarrely enough the letter "q" is continuously in bold throughout the whole book. You can easily verify this from the pictures by the reviewers. I don't actually own a copy of the book myself.

To make matters worse (or better?), they only decided to include the first four chapters, ending at "Conditional Execution". Yes, the plagiarized book claims to be a guide "from beginner to expert", yet it didn't reach the chapters on loops and functions!

If you read the reviews, you'll quickly notice that it's full of fake five-star reviews with very vague sentences, some of which don't even make sense. You'll also (now) see a lot of real one-star review, which means that quite a number of people have fallen for this scam.

Surprisingly, one of the fake reviewers even got in Amazon's top 100 reviewer list. Check the profile of "Kip Krenz" [2], who is currently at rank #53. Somehow he managed to review two to four books on a near daily basis for maybe a year or more, mostly five-stars (the rest are four-stars) and full of generic sentences. The books reviewed are most likely "fake" as well. They often fall under one of the following: a beginner book, a self-help book, a cookbook, a trading book, or a book on one of the latest fads.

This book is unfortunately just one of the many fake books (not the jazzy kind) that have proliferated on Amazon. If you look at the other recommendations, you'll probably find another one of these books (Python seems to be one of those profitable topics).

A common technique used by these books is to put themselves under some niche category in order to get a high rank. For example, this book categorized itself under "Microsoft C & C++ Windows Programming" [3], and is currently at #9 there (it used to be #1, but thankfully the real reviews probably dragged it down). For a more peculiar example of this, take a look at what's #1 under "Windows XP Guides" [4].

Sorry for going on a tangent with such a long wall of text. I spent a night "investigating" this whole thing a few weeks ago, and after seeing this post, thought that it would be best to spread awareness of the issue here.

[1] https://www.amazon.com/Python-Programming-Beginner-Intermedi...

[2] https://www.amazon.com/gp/profile/amzn1.account.AGXMOOP4UKWV...

[3] https://www.amazon.com/gp/bestsellers/books/3967

[4] https://www.amazon.com/gp/bestsellers/books/6134002011

undecidabot··on TypeScript vs. ReasonML
If the lack of action creators is a serious concern, then the one-liner-each action creator I suggested should be sufficient without adding much bloat. How would the ReasonML example deal with that change though? Can the variant constructors take in optional parameters?

Using Murphy's Law is not very convincing. Even with action creators Murphy's Law guarantees someone would have just constructed the objects manually anyways. Having to grep the tag is not ideal, but it's not likely to be a problem in practice.

I doubt that the bundle would be significantly larger (especially after compression). Using actions creators introduces additional (function call) overhead too (and that would be insignificant as well).

undecidabot··on TypeScript vs. ReasonML
I don't have experience with Redux so I cannot comment on that, but I do believe my rewrite is equivalent to the ReasonML example (it should express the same thing and still be typesafe).

While I'm sure the author did not intentionally try to make TypeScript look bad, (imo) they didn't put enough effort to make it look good either. There's a lot more to TypeScript that this post fails to mention. ReasonML is a good language (I think OCaml was just fine though), but TypeScript is good too.

The author says "ReasonML is everything TypeScript tries to be (and a bit more) without all that JavaScript weirdness.", but I strongly disagree. Embracing "all that JS weirdness" is the whole point of TypeScript, and what makes it so successful. Unlike most typed languages, TypeScript (for better or for worse) adapts its type system to the developer's code, not the other way around. This is why its type system is much more expressive than many other type systems including ReasonML's.

undecidabot··on TypeScript vs. ReasonML
Yes, I eliminated the action creators. I don't see why they're necessary (maybe there's something about redux I'm missing?). The type constructors of ReasonML cannot be used as functions, so I think my rewrite is fair.

If you insist on having the action creators, they can easily be written as one liners each, which is a lot less bloated than the original example.

  export const addMovie = (movie: string): Action => ({ tag: "AddMovie", movie });
What's the issue with passing object literals? I know it looks a bit hacky and messy, but if it's typesafe (which it is) then it doesn't seem like a real issue.
undecidabot··on TypeScript vs. ReasonML
Looks like another biased comparison to me. You could easily rewrite the TypeScript reducer example (which fails to compile btw) to be similarly concise while being as safe.

  interface State {
    movies: string[]
  }

  // you may also use { tag: "Action", payload: string }
  // if you prefer something more structured
  type Action =
    | ["AddMovie", string]
    | ["RemoveMovie", string]
    | ["Reset"]

  const defaultState: State = { movies: [] }

  const reducer = (state: State, action: Action): State => {
    switch (action[0]) {
      case "AddMovie": return { movies: [action[1], ...state.movies] }
      case "RemoveMovie": return { movies: state.movies.filter(m => m !== action[1]) }
      case "Reset": return defaultState
    }
  }

  const someAction: Action = ["AddMovie", "The End of Evangelion"]
TypesScript's type system is actually very flexible and advanced [1] compared to most type systems since it had to adapt to the very "dynamic" structuring of JavaScript in the wild.

[1] https://www.typescriptlang.org/docs/handbook/advanced-types....

undecidabot··on HTTP Security Headers – A Complete Guide
Nice list. You might want to consider setting a "Referrer-Policy"[1] for sites with URLs that you'd prefer not to leak.

Also, for "Set-Cookie", the relatively new "SameSite"[2] directive would be a good addition for most sites.

Oh, and for CSP, check Google's evaluator out[3].

[1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Re...

[2] https://www.owasp.org/index.php/SameSite

[3] https://csp-evaluator.withgoogle.com

undecidabot··on Essentials of Compilation – An Incremental Approach [pdf]
Link was taken from the course website[1]. TeX source is also on GitHub[2].

[1] https://iu.instructure.com/courses/1735985

[2] https://github.com/IUCompilerCourse/Essentials-of-Compilatio...

undecidabot··on Next steps toward Go 2
It's mentioned in the design doc under "Properties of the proposed design": https://go.googlesource.com/proposal/+/master/design/32437-t...
undecidabot··on Impending kOS (2014)
For those who want to see it in action, there's actually a talk about kOS on YouTube: https://www.youtube.com/watch?v=kTrOg19gzP4.

The talk is by the fourth member, Geo, who also frequents HN (geocar).

undecidabot··on If not SICP, then what? Maybe HTDP?
Another great but lesser known CS book is "The Functional Approach to Programming". It uses Caml (a predecessor of OCaml). Like SICP, it covers a wide range of CS topics, although it's probably not as accessible as HtDP.
undecidabot··on Factor: An impressive stack-based language environment
For those who want a taste of Factor, check: http://re-factor.blogspot.com/ (You might want to scroll down past the release notes.)
undecidabot··on The next 700 programming languages (1966) [pdf]
I don't think ML has the `where` clause. Haskell got it from Miranda, which got it from SASL, which got it from ISWIM.
undecidabot··on Lisp and Haskell (2017)
A similar distinction was made by Yegge before [1], which he (unfortunately) labeled as "liberal" and "conservative". It was quite controversial [2].

Another similar idea is Fowler's software development attitude [3]. He uses the terms "enabling" and "directing" instead.

[1] https://plus.google.com/110981030061712822816/posts/KaSKeg4v...

[2] https://news.ycombinator.com/item?id=4365255

[3] https://www.martinfowler.com/bliki/SoftwareDevelopmentAttitu...

undecidabot··on Ask HN: What web framework would you recommend for a greenfield project in 2018?
Is this project a serious one? If it is, go for something mature and something you are familiar with even if it's "unsexy" like PHP and jQuery [1]. Learning a new technology while building your product can be fun, but it is often counterproductive. Unless your project has specific needs which only a few technologies can fulfill, it'll be just fine. Choosing something familiar allows you to focus on your project instead of your tech stack.

Don't worry too much about choosing the "wrong" language or framework. What you build matters more than how you build it. For example, many would recommend Postgres over MySQL for good reasons, yet those who use MySQL are doing just fine [2]. Their advantages are often insignificant in practice, so feel free to ignore the hype (especially here on HN)!

Angular, React, Vue are all fine choices for building SPAs. Rails is kind of out of place here (it's not a front-end framework). The hype around it has died, but Rails itself is still very much alive, and it's very mature. ClojureScript and Elm may need a bit more getting used to depending on your experience. Their communities are relatively small though, so you'll have less resources available.

[1] PHP gets a bad rap for its past, but modern PHP really isn't so bad (very Java or Ruby like, depending on the framework that you choose). jQuery is "old", but reliable. Not a good idea if you're building something highly interactive, but if you only need "a little bit of JS" then it seems like a good fit. SPAs have many advantages, but are also much more complex, so avoid building one if you don't need to.

[2] https://www.mysql.com/customers/

undecidabot··on How to start a Go project in 2018
It's still a bit new, but I think pipenv [1] is the new standard now. No need to directly work with pip or virtualenv anymore, and the equivalent requirements file works more like npm/yarn.

[1] https://github.com/pypa/pipenv

undecidabot··on Parsing: a timeline
One of the most interesting parser libraries I've encountered uses GLL. It's a clojure library called Instaparse [1]. The author had a nice presentation on it [2]. I'm not sure how well it works in practice though. Another great article on the subject [3].

[1] https://github.com/Engelberg/instaparse

[2] https://www.youtube.com/watch?v=b2AUW6psVcE

[3] https://epsil.github.io/gll/

undecidabot··on The secret life of NaN
A little "fun" fact about NaN: they are never equal to each other, even if it's the exact same value and variable.

How can you check if a variable is NaN then? Well, if it's not equal to itself then it must be NaN!

undecidabot··on A Visual History of Eve: 2014 - 2018
Are you planning write a postmortem on this project? I really hope you do. I'm sure you have plenty of insights to share that would be super helpful for other people exploring this space.

Many of us here would really love to read up on the ideas behind each iteration, the specifics on what went well, what didn't go as expected, the target market and their feedback. It doesn't need to be a fancy paper, even a short but detailed bullet list for each iteration would be fine.

From my outsider perspective, it seems like you were trying to build a "silver bullet". For example, both FiveSquare Eve and WikiEve look promising. FiveSquare could be a great WYSIWYG website/app builder. WikiEve could be a great note taking tool. Just because they aren't the future of programming, doesn't mean they aren't useful!

undecidabot··on A Visual History of Eve: 2014 - 2018
Just to clarify, the STEPS Project has ended (Oct 2012). HN had a discussion on their final report not too long ago: https://news.ycombinator.com/item?id=11686325
Page 1 of 2Next →