HNHacker News
TopNewBestAskShowJobs

xPaw

3,202 karma · joined May 12, 2012

my website: https://xpaw.me

creator of https://steamdb.info/

submissionscomments
xPaw··on Node.js is able to execute TypeScript files without additional configuration
That proposal has existed for 4 years, it hasn't gone anywhere yet.
xPaw··on Node.js is able to execute TypeScript files without additional configuration
I wish browsers also supported directly running typescript files.
xPaw··on Why is GitHub UI getting slower?
Githubs performance has been rapidly degrading ever since they started rewriting everything in React.

It's basically impossible to view diffs now because they often fail to load, render correctly, or just are incredibly slow.

xPaw··on The Windows Subsystem for Linux is now open source
Slow IO is why I still use wsl1.
xPaw··on Advent of Code 2024
Yeah, I made a userscript for myself to fix that up: https://gist.github.com/xPaw/4fffaf776fe14d15c9602991f51dbfa...
xPaw··on TinyJS – Shorten JavaScript QuerySelect with $ and $$
You don't need to convert querySelectorAll to an array, you can directly iterate it, or use forEach.
xPaw··on Cloudflare Fonts: enhancing website font privacy and speed
> With Cloudflare Fonts enabled, you are able to see within your Network Tab that font files are now loaded from your own hostname from the /cf-fonts path

Is there a particular reason why is it not using /cdn-cgi/ prefix?

xPaw··on Telegram raises $210M through bond sales
Link? I don't see this in ToS.
xPaw··on Welcome to Threads
Likely blocked by Firefox tracking protection because it uses Facebook domains.
xPaw··on An Update on the Lock Icon
This is a good move for the secure-by-default move.

In The Lounge IRC client, we've also opted to this approach years ago, where secure connections show no icon, and insecure connections show an insecure icon.

xPaw··on Firefox Android now supports Tampermonkey
It really is bizzare, old Firefox used to support all addons, then they shipped a new version and only allowed like 10 addons, and to this day they don't allow any more. It's already been years.

I know my addon works fine on mobile, but they provide no means of specifying that*. I tried to email them for it to become "recommended" but never heard back.

The fact that they allow tampermonkey which allows any kind of script just adds insult to the injury.

* when uploading a new version, it does ask to specify which Firefox desktop/android versions are supported, but this existed before the new Firefox and doesn't do anything.

xPaw··on Ask HN: Those making $0/month or less on side projects – Show and tell
Everything is done on a single server. What makes you think it's low?
xPaw··on Ask HN: Those making $0/month or less on side projects – Show and tell
Games gifted to the bot are used to gain access to some extra info.

I do get game gifts to my personal account from time to time.

xPaw··on Ask HN: Those making $0/month or less on side projects – Show and tell
I know some Valve employees use it.
xPaw··on Ask HN: Those making $0/month or less on side projects – Show and tell
Hetzner.
xPaw··on Ask HN: Those making $0/month or less on side projects – Show and tell
That's still correct.
xPaw··on Ask HN: Those making $0/month or less on side projects – Show and tell
I can, but I have no interest in doing that currently.
xPaw··on Ask HN: Those making $0/month or less on side projects – Show and tell
SteamDB: https://steamdb.info/

I've been running it for over 10 years now, it's a database of Steam games, their updates, price history, charts, and a lot more.

In the early days we took monetary donations but stopped a few years in. It costs less than 100$ a month to run. Cloudflare reports 552.2M requests in the past 30 days, and 6.09M unique visitors.

xPaw··on Cloudflare servers don't own IPs anymore so how do they connect to the internet?
I have tried using cloudflare's client certificate, but it doesn't play well with nginx ssl cache due to increased size on a relatively high load website.
xPaw··on Affinity 2
I purchased it directly from their site, and there is no upgrade option either.
xPaw··on Fix it, Fork it, Fuck off (2019)
> Heck even a tweet at the owner might be good enough.

I disagree with this, don't spam people. Sometimes people even go out of their way to contact you using multiple channels and it gets even more annoying.

xPaw··on 40% of Google users now connect via IPv6
Github also can't send webhooks to ipv6 only hosts.
xPaw··on Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)
What I find mildly curious, that's also the only place where a length was provided as an argument into `Gitlab::Password.test_default`.
xPaw··on Consent-O-Matic: Automatic handling of GDPR consent forms
How different is this from "I don't care about cookies" extension?
xPaw··on Retrieving your browsing history through a CAPTCHA
I rarely see websites that actually make use of `:visited` style as intended, it would be good if browsers had an option to just disable it and prevent this class of leaks completely.
xPaw··on Avoiding the top Nginx configuration mistakes
Another big mistake with defaults is that you need an explicit `server` block with `default_server` for all the `listen` directives you have.

Otherwise if you have a listen directive for some host that doesn't have a default, this server will be used as the default for this particular listen directive.

For example doing `listen 80` and then requesting any non matching host will still return this server.

xPaw··on IP Addressing in 2021
I have experimented with IPv6 only, but a lot of stuff still doesn't support it. For example Github and Discord webhooks fail to send.
xPaw··on Wordle Is a Love Story
The word list is in Wordle code, so you can just grab that.
xPaw··on Show HN: I redesigned my landing page to be as unprofessional as possible
It's currently returning 502 Bad Gateway, so the title is very fitting.
xPaw··on Security issue related to the NPM registry
There's more: > vulnerability that would allow an attacker to publish new versions of any npm package using an account without proper authorization.

> We determined that this vulnerability was due to inconsistent authorization checks and validation of data across several microservices that handle requests to the npm registry. In this architecture, the authorization service was properly validating user authorization to packages based on data passed in request URL paths. However, the service that performs underlying updates to the registry data determined which package to publish based on the contents of the uploaded package file.

Page 1 of 4Next →