HNHacker News
TopNewBestAskShowJobs

wieghant

24 karma · joined March 20, 2017

submissionscomments
wieghant··on Three things to never build yourself: auth, notifications, payments
It's monumentally stupid to think auth is easy. Yes there are standard cookbooks and checklists out there. The hubris to think that auth fails due to a crypto scheme choice is why average programmers consistently fail at it.

The yearly report of leaks in Fortune 500 companies should be proof enough of this.

EDIT: To elaborate. Crypto scheme is only one tiny facet of a successful authentication solution. Where do you store the hash? What language and stack are you using? What is the maturity of libraries available to you? What protocols? And many more seemingly tiny decisions. All it takes is a lazy developer that imports an insecure transient dependency or snoozes on a CVE.

wieghant··on Should the Web Expose Hardware Capabilities?
Yet we are as of right now where even our OS will go behind our back and act like malware to collect data even when we explicitly say no.

The native apps are also all trending to online first and cache offline.

I don't understand how a native app going behind your back and asking only for internet connection permission (and not hardware) is viewed as more secure. Why do we trust these native apps more?

Arbitrary psychopathic outsiders have already been here for quite a while. Even if you're running super paranoid homebrew linux distro.

wieghant··on Should the Web Expose Hardware Capabilities?
Exactly. But for the savy it's easier to see from network tab in dev tools where your data is sent.

No such luck with native apps. I don't almost never use wireshark to figure out what my native apps are doing.

Also. The entire argument falls apart when you factor in the ability to proxy data. E.g google.com -> bit-shady-site.com -> for-sure-shady-site.com

wieghant··on Ticketmaster admits it hacked Songkick before it went out of business
During my time in conscription, one thing that stuck with me was 'Forbidden Order'.

If a superior gives you an order that violates set rules or laws (e.g shoot civilians). You HAVE to obey and BOTH parties will be accountable.

It's crazy how severity of ignoring an order can be worse than tribunal. However I totally agree with accountability.

Though corps would figure out a way to weasel past this regardless.

wieghant··on Ask HN: Any luck negotiating better terms for on-call?
Left and wished I had done it earlier. Once I gave my notice, that's when they gave a counter offer but I had made up my mind.

Cost the company upcoming tenders and my entire team soon followed. Not something I'm proud of. But priority 1. should be personal wellbeing.

One thing I learned from this is, that I fail to convey severity of issues to certain type of managers. Framing the issue in dollars helps in those cases.

And if it is understood and still ignored. Welp, time to move on.

wieghant··on Show HN: Base32H, a human-friendly duotrigesimal number system
I just recently understood the deep connection between bytes and hex, hex and decimal.

Can someone ELI5 what would be the use case for having data represented in Base32H? I understand it conveys more info in less runes but it feels hard to keep in my head. Is this just something that takes practice and getting used to or I'm not supposed to try to use this to read binaries?

wieghant··on Show HN: Primo – all-in-one IDE, CMS, component library, static site generator
Feel like we've gone full-circle for the umpteenth time.
wieghant··on Show HN: Open-source Disqus alternative, with hot-reloading and guest commenting
This is great. Clean. Simple. No nonsense. WebSockets is a cherry on top!
wieghant··on Public hacker test on Swiss Post’s e-voting system
So I hear the cons for e-voting all the time. It's absolutely true no system is sound and secure. However consider this: most politicians aren't exactly tech-savy. There are way more cost-effective methods to "rig" elections (for the Swiss scale). Dead people voting. Volunteering staffers. Depending on country method of vote transfer. Human error when counting.

Having helped with an e-election system myself, I saw first-hand how it caught "bugs" in the process. For example some district entering wrong information (lots of cross-referencing checks tripped an "alarm").

In the U.S sure, I can see why people would be concerned. No offence, but the systems in place for social and other citizen-related info ain't excellent. If there's an entire market for false identities it's saying something. Taxes not being done automatically. Social security number being the one way to identify. Online banking being a pain in the ass.

Scalability is an issue. If a system is open to billions, there is more incentive to work on "theoretical" exploits. But let's not pretend paper-voting is a better alternative. E-voting doesn't solve the corruption problem, but it makes it easier to find.

Tom Scott and some of the pen-testers that shit on on the concept have good points. However they all are based on the idea that staffers manually counting works better. Tom Scott's New Hampshire example is anecdotal – that system was an insult to the word naïve. The pen-testers taking a dump on Estonian system were picking on stuff like WiFi passwords being visible and seeing over the shoulder an admin's terminal. The systems responsible for the counting weren't connected to the WiFi and it was there for guests. Lot of good staring at a terminal did with no access to the actual machines holding the program.

I don't see e-voting becoming a thing due to all the FUD spreading. But I hope it will be reviewed as a means of double-checking. Perhaps some studious people might actually go out and study the actually proposed architecture. It's really never as simple as one program doing the counting with a flavor of auditing. At least when done right(ish).

wieghant··on Ask HN: Is it just me, or is CSS too damn hard?
I liked the no bootstrap section. People lack the foresight of shooting themselves in the leg. Currently working on a project where the front-end guys ended up using !important for literally everything due to lack of knowledge on how Bootstrap works.
wieghant··on RIOT: Operating System for the Internet of Things
Recently needed multi-threading with Arduino. Going to give this a shot. I'm sure people more well-versed with non-POSIX may have gripes, but I'm just doing this for hobby purposes. I'm familiar with Linux, I need multi-threading and maybe a network stack. Given that, this seems like the thing for me.
wieghant··on Show HN: Fine Wordclocks: more than a time piece, they are a piece of art
It's a cool project and I admire the attempt, however

1) It's been done before, it's not original

2) The cost is outrageous (I see you use more expensive materials, but it's not $1400 more expensive material)

3) Likely copyright infringement

wieghant··on Merlin: A cross-platform command and control server and agent written in Go
I just find Go a more pleasant experience. The source code is easily readable and understandable. I don't run into weird wrong version or dependency problems ever. Go get, go build and i'm done. Or if i download the binary, just dump it in a bin folder and it works without even having Go on the system. I haven't written anything in Rust or Erlang yet, but I have run into trouble when building Rust packages from source. Maybe it was the package maintainer's bad every time, the system setup or I'm just dim, but I just need to get stuff done and not go down the rabbit hole. I also personally don't like the hassle with Python version environments.
wieghant··on Show HN: Select Star SQL, an interactive SQL book
Why did you choose executions over something mundane like blogs or comments? Reading last statements isn't exactly something I want to be distracted by. The data is interesting sure and if this just happened to be based on something you did recently, I get it. It's not something I'd recommend to students doing data science or getting acquainted with SQL when there's less morbid source material out there. The interactivity provided is cool though, no doubt.
wieghant··on A female engineer's opinion on why there are fewer women in tech
My goal wasn't to bolster a "fruitful professional relationship". She probably wouldn't have been hired if that was not the case. She excels at her work and there are no HR problems. Article focused on women feeling anti-social in the workplace. I don't think it implied being anti-social will put you in a rut. It will however deter future generations. Goal of the 'merger' was not to put her on a scale and see if she measures up to be in our "in-group". The goal was to get to know our new employee. That being said, it was clear that there is a culture divide and while the relationship is fruitful, it's not as fruitful as it could be.
wieghant··on A female engineer's opinion on why there are fewer women in tech
That's not really what I was getting at. Most of the guys are just like you described. We usually can't even settle on a video game to play. However, even with the one thing in common with the whole group (slight interest in board games) we just didn't hit off. And it's not like a singular attempt or case either. It's like there is a cultural divide. Now that's not the case with everyone, my example is anecdotal. I have female friends that dig board games and some video games and there's no divide there but just in the workplace, that is not the case. From my current experience and environment it seems very unlikely I'll ever meet someone like that though.
wieghant··on A female engineer's opinion on why there are fewer women in tech
HackerNews isn't really a place to wave a empathy stick at. This is a place where years of work on startups and concepts come to die. If you came to find yes men, this is sadly the wrong place. Having said that, there are an unusual lot of people empathizing and acknowledging the issue that women are more alienated and that we should fix that. There is a severe lack of empathy on the other side though that cannot seem to fathom why men heed cautionary tales and choose not to risk their career over fighting for equity.
wieghant··on A female engineer's opinion on why there are fewer women in tech
But I'd rather stay up all night and clear Black Temple.
wieghant··on A female engineer's opinion on why there are fewer women in tech
We recently got a new female analyst. We invite her for lunch and sometimes have small talk. Thing is, there's literally zero chemistry. We can't include here in our dumb Skype chat because its usually filled with incredibly dumb offensive memes - so we just try to keep our laughs down. We tried invite her to video game night and even organized board games just because she wasn't into video games that much. But again, there just isn't any chemistry. I genuinely think that the border isn't just between anti-social/pro-social. I also wouldn't ever consider making deprecating jokes towards her. What's considered inappropriate is too blurred also. I can make fat jokes/racist jokes/generally inappropriate jokes with most guys, since we know there's no malevolent intent. It's kinda cathartic and it's a two-way street. I genuinely don't think I can be like that with any woman in the workplace. I know comedians can have such a relationship though, so maybe there is a chance? Maybe not now when people are publicly executed for speaking their mind but in the future.
wieghant··on Say no to Electron: use JavaFX to write a fast, responsive desktop app
> It's better than it once was, but you're going to have to check every single feature of HTML5 you use to figure out which browsers implement it

There's tools for that and i'm pretty sure just writing plain html and css or some compile-to-js would have shaved off significant time from that 8 month full dev time.

wieghant··on Say no to Electron: use JavaFX to write a fast, responsive desktop app
> Then you have the language creep (Typescript, Dart or anything to paliate JS deficiencies; LESS/SASS), the JS framework creep, the libraries decay, etc.

That is totally a thing in Java too. Languages: Groovy, Kotlin, Scala. Framework: GWT, Spring, Struts, Vaadin, Grails. Libraries decay: commons, apache, different parsers, different db drivers.

On top of that though, you need to think about your JVM? What dependency manager: Ant, Maven or Gradle. Then figure out which JDK to use, cause that's a thing. Then figure stuff out like facets. Sure this is more IDE field but the fact Java app architecture can be so whack that something like 'facets' needed to be abstracted only proves my point.

> If multiplatform support is not a requirment, the desktop languages and tooling are way ahead in term a ease of use.

Ahead with the size of muddle yes. Web stack is just very good and fast at emulating the amount of it.

wieghant··on Say no to Electron: use JavaFX to write a fast, responsive desktop app
His just complaining and electron eats memory (supposed 200MB on startup). Find it funny he brings Java as a better alternative to the table.
wieghant··on Say no to Electron: use JavaFX to write a fast, responsive desktop app
As a language both are insane in parts. Not just architecture but the muddle of tooling also.
wieghant··on Say no to Electron: use JavaFX to write a fast, responsive desktop app
Look. I agree, that you shouldn't make desktop applications in Electron. The thing is, when you have a fresh grad student that was taught PHP as a web framework for most of the time and maybe Node, what do you think they will gravitate towards? I understand veterans feel like Qt, GTK and JavaFX are intuitive in their architecture and syntax but that is simply not true. Heck even XML can be jarring.

So here's what i've found people trip up with JavaFX mostly.

1) FXML. Why do you need so much information just to view "Hello world". You need to define a scene, then you need to define what's inside the scene (You'll need to go look up a reference guide on JavaFX to find what objects you can attach just to get started), then you need to describe that a text node is connected to the thing inside the scene. For HTML it's always gonna be <html><body></body></html>. Inside the body it doesn't matter what structure you create, you'll be cutting off "sections" with plain html+css. HTML5 got it's canvas if you need more advanced functionality. Why would people who have been taught to use canvas and DOM revert to this?

2) Custom CSS. Fantastic, more syntactic sugar and another reference guide to search through... people get effects/animations with greensock or css nowadays, it's fairly competent stuff and frankly more intuitive. Just a gem from the reference: background: white; -fx-text-fill: ladder(background, white 49%, black 50%);

Without reading the reference I'm thinking it's filling the color. What does ladder and it's arguments mean I would have no idea. What does is this: "Use the following if you want the text color to be black or white depending upon the brightness of the background." – right, cool but there's filters and stuff made for this very thing in plain old CSS.

3) JVM hot code reload. The entire section is confusing to people using Node that learned to implement a watcher in Tutorial 1 of setting up package.json. Good luck explaining intricacies of JVM to grads that struggled to get bare bones Java application running in Eclipse. "I find it hard to believe that anyone would prefer the webstack to working with a sane environment like the JVM." – I profusely disagree. The fact you need to have a virtual machine for your code to execute is a lot for people outside the bubble to comprehend. The fact you have two types of dependencies, runtime and compile, already confuse new people coming into the field. Gradle which is supposed to make lives easier is still way more confusing than fiddling with package.json. It's perhaps not Gradle's fault, I think the blame is more with veteran developers that like to be 'clever' and manage to obfuscate something as simple as launching an application.

4) SceneBuilder. "It can be integrated into all Java IDEs, making it easy to create new views.". What the author has forgotten to mention, is that it can be a pain to use and integrate (Haven't tried this in IntelliJ and i'm sure it's better there but it's still more hassle than opening your flavor of browser inspection). You'll most likely end up ditching the GUI and do everything programmatically, at which point you'll ask yourself why are you doing css and js in Java. The example in the article is a simple "Hello World". Anything more complex and you'll find people falling into the habit of doing everything inside of Java.

5) ScenicView. "To start it with your application, just download the jar and pass the option -javaagent:/path-to/scenicView.jar to the JVM." – that line might as well be written in Chinese if you're a person coming from the Node scene.

6) JavaFX does not automatically refresh stylesheets. You need to build a whole seperate function and implementation just to refresh a stylesheet. "This works in Mac, Windows and Linux Mint. But this was one of the only two problems I had related to differences in OS's (the other one was the icon in the system tray on Mac does not work, but there is an ugly workaround for that). JavaFX abstracts that away pretty well, most of the time!". Well that's reassuring there is an iffy solution to a problem that shouldn't be there to begin with.

I also feel the author is quick to throw anyone using electron under the hipster title and then proceeds to call the webstack a mess yet ignoring the mess that Java is. Need I remind you why Node stuff was so popular? Because people required entire days to figure out how to get a simple ToDo Spring application working. And Spring is supposed to be easy. Think about that. You need to spend dev time on something as obscure as 'JVM tuning' at one point or another. Or fixing some bizarre leak/overflow because hurr-durr imperative programming. And the 20 years of patterns and best practices wasn't good enough. We have shit like JPerf to figure out why all those stern-toned articles still lead to shitty code and JRebel to sweep the problem under a rug.

"We've been writing desktop apps for decades. The web, on the other hand, only really got started less than 20 years ago, and most of that time it was only used for serving documents and animated gifs, not creating full-fledged applications, or even simple ones! To think that the web stack would be used to create desktop applications 10 years ago would be unthinkable." – And here we are with Java still remaining the clusterfuck that it is.

"If people are preferring to ship a full web browser with their apps just so they can use great tools such as JavaScript (sarcasm) to build them, something must have gone terribly wrong." – yeah, that something was the JVM. Kinda funny we now have all this compile-to-js stuff when there's still uppity aura revolving around JS. Heck I remember having trouble with just the JRE back when I hadn't learned any programming.

wieghant··on “Millennial savages me on Glassdoor for giving constructive feedback”
Ughh, more pretentious mockery of millennials. So sick of being looked down on. You know what's more immature than being a 23 year old with inflated ego? Having the experience, yet proceeding to ridicule knowing full well that's not the approach.
wieghant··on The stupidity of crowds
* The Boaty McBoatface is /r/iamverysmart territory. It was lighthearted and brought interest from across the world - not everything has to be named after a Greek tragedy.

* As for Brexit. Well, the public in general was unaware of the benefits of being in EU to begin with. Ultimately it was the 'experts' - the people in charge of conveying information - who failed. Not democracy. Democracy is by no means perfect, the metrics for who are qualified to vote hasn't been set.

* The language barrier. For some reason I really doubt that's true. What polls are in questions? I can't find any sources in the article. 4% deviation is completely normal if the question was asked from same people a year later.

Crowdsourcing is amazing, as long as your target group is set properly. This entire article is regurgitating intro into statistics. I do agree with the consensus part. The very problem was relevant in assessing difficulty of 'stories' in software development. When devs were asked to just number the difficulty, people lost sense of responsibility and would normally vote for extremes (very easy or very hard). Hence, the people who chose lowest and highest had to explain why they chose that specific number.

wieghant··on Silicon Valley CEO Pleads ‘No Contest’ to Abusing His Wife
Corporal punishment in my opinion is lazy parenting. I've thought about this a lot. My parents divorced early, I was raised by my father. He loved me and my brother no doubt but after a hard days work he had no interest in doing normal parent things - like camping/fishing activities or just spending time with us. We got punished when we screwed up. Sometimes unjustly, like him having heard rumors and acting on them. If he had spent more time with us growing up rather than watching TV he would have known our character. I would of appreciated it a lot more if he had bothered to wither us down with kindness and patience. Now that things are a lot better between us and i'm a working adult, corporal punishment is one of my dads regrets.
wieghant··on Silicon Valley CEO Pleads ‘No Contest’ to Abusing His Wife
Disgusting. People defending his actions with culture and religion are even more so.