3,335 karma · joined April 13, 2011
Bluntly, yes. And so is every other reply to you that says "no this isn't naive", or "there's no reason this project shouldn't have finished". All that means is that you've not seen a truly "enterprise" codebase that may be bringing in tons of business value, but whose internals are a true human centipede of bad practices and organic tendrils of doing things the wrong way.
Yes! Note that I had to use my domain knowledge to sift through the options and eliminate the garbage, but the experience was just _faster_ than repeated searches and digging through ad-laden garbage sites.
Problem: I want an AWS CLI command line that requests a whole bunch of wildcard certificates from AWS Certificate Manager (ACM) for a TLD.
Ostensible solution: the AWS official docs have a small snippet to achieve this, BUT -- the snippet on the official page is inadvisable as it leads to a browser cert warning.
So I (skeptically) asked ChatGPT for a command line to achieve what I was trying to do.
Try 1: got basically the snippet from the AWS official docs (but with the inadvisable flag set to the _Correct_ value, strangely)
Prompt 2: please give me more best practice options
Try 2: get back a bunch of new CLI options and their meanings. 3 are useful. 1 is hallucinated. 1 is deprecated.
Prompt 3: keep going with more options
Try 3: 2 more useful new options, 2 more options I chose not to use
As a skeptic, the overall experience was much more efficient that googling around or even reading a manpage. I put it all on the fact that context is maintained between questions, so you don't have to repeat yourself when asking for clarifications.
Bold of you to come to HN with the breathless hyperbolic marketing fluff that may work on Twitter...
The painful move from IPv4 to IPv6 suggests that this is unlikely. More likely is an overlay over IP, TCP, or even HTTPS.
I don't really know much about this aspect, could you elaborate? I'm genuinely curious.
Lock-in? Once you have a few gigs up on Dropbox, it's a bit of a challenge transferring it elsewhere.
Edit: which is not to say that I'm not welcoming the new instructions with open arms...
You'd be amazed at what a few billion in the bank will attract, especially when it's cheaper to settle than litigate.
And before the Mongo haters come out, remember that WiredTiger was written by about as stellar a database team as you can have.
The "split token" password reset is snake oil. Just store the hash of the token (ideally stretched like any password) in the database and mail the original token out. No need for "split tokens". A password reset token is a temporary password and should be treated like one.
Alternatively, you could restrict your "stolen" model to a smaller domain and use fewer, more targeted examples for training. But at this point, you might as well start blending in predictions from other APIs, perhaps even training one off the errors of another. This is basically a technique that has been around for a long time, and in one incarnation is called "boosting" (see Adaboost).
To add insult to injury, you could outsource the training of your own model to the API too.
And yet, both Facebook and Google have large, monolithic codebases.
Don't rule out the power of acquisitions (see: Firebase/Google, Parse/Facebook). Word on the street is that they're also throwing silly mounds of cash at cloud talent.