I’m going to out myself, but you just do it anyway…
HN user
MitchellCash
[ my public key: https://keybase.io/mitchellcash; my proof: https://keybase.io/mitchellcash/sigs/PX5OzxkSr8RZsFZxwWJMVnOwN4dU7d_hqNWRm9So1KY ]
It's the ISBN of Edward Snowden's book "Permanent Record: A Memoir of a Reluctant Whistleblower". The numbers in the poster differ because it's the ISBN of the Swedish translated copy of the book.
a change in the indentation used in our bundle files (4 spaces -> 2 spaces)
I find it interesting that one of the reasons given for the reduction in package size is due to such a simple indentation change from 4 spaces to 2 spaces.
Not interesting that 2 bytes are less than 4 bytes, rather, TypeScript is a large project and it would be interesting to know how much size was saved from this one specific change? Seems like a trivial change, so why not do it sooner? And assuming readability isn't required in the bundle output why not bundle with no indentation at all and put everything on a single line, would this not be even smaller again?
I replaced my companies Google reCAPTCHA validation with Turnstile and so far the implementation experience has been fine. Not so different from the Google implementation and no major issues I have come across thus far.
In terms of how it actually performs, it’s only been deployed in staging and a limited user preview version of the site so far, so it’s yet to experience much of the bad traffic or edge cases that might hit the production site.
As a child my cat would favour drinking water from our chlorinated pool rather than her water bowl. Interesting to read another anecdote about cats and chlorine. They say curiosity killed the cat, but maybe I’ll take the gamble and see if I can find an answer as to why!
Not the author, but they look like they’re from Balsamiq.
I haven’t used it for a while, but I remember Balsamiq being a great tool, especially for quick low-fi UI wireframing.
The third field of the triplet is for the operating system identifier [1] which can be expressed as two fields in the form of `<sys>-<abi>` [2] as well as just `<sys>`, when applicable. The LLVM docs also refer to the second part of the operating system identifier as the "environment type" [3].
Examples of allowed operating system identifiers could be `freebsd`, `linux-gnu` or `linux-android`. So, while it seems like four components, the last two seem to get combined to refer to a single "operating system identifier".
I'm no expert here, so corrections welcome, I was just curious from your comment and thought I'd share what I had found.
[1] https://wiki.osdev.org/Target_Triplet
[2] https://clang.llvm.org/docs/CrossCompilation.html#target-tri...
I think we can get the best of both worlds by hiding lock files by default and always showing any actual code file diffs. Performance may be a factor for very large diffs, but this would actually be my preference to how the default behaviour would work as I agree with you and the parent post.
I prefer to run Ubuntu machines and at least in terms of provisioning a new secure server I built an Ansible playbook I called 'ANU' (as in A New Ubuntu). I'd expand to other distros, but then I'd have to change the name!
https://github.com/MitchellCash/ansible-anu
It is based on the DevSec OS/SSH hardening playbooks, but I lean closer towards ease-of-use over security where I think it makes sense. For example, I disable forced password rotation and I keep the default umask value of '022' instead of the more secure '027'.
When I come across something the upstream playbooks change that "gets in my way", I will disable it if the security trade off makes sense for me. I'm not running highly sensitive systems, so these trade-offs make sense for me, and maybe they will for you as well!
In terms of ongoing security upkeep, I run the usual `apt update && apt dist-upgrade` when I can, but I’ll be keeping my eye on this thread for additional advice.
Yes, to both Vue and Nuxt via Open Collective. I use both tools so I like to give back to ensure work continues. I also like the idea of backing the 2nd horse in the race, so to speak, to keep competition active. A lot of backing and money is already behind React and its ecosystem, so putting my money towards Vue development feels like a win for me as well as potentially keeping the other frameworks and tools innovative.
Continuing work to restructure Firefox’s JavaScript memory management to be more performant and use less memory.
I went back the last few versions major release notes and didn’t see mention of the initial work to improve the JavaScript memory management. Is anyone aware of this work/what’s going on to improve memory management here? Interested to read more about the technicals!
Under Swiss law, it is obligatory for a user to be notified if a third party makes a request for their private data and such data is to be used in a criminal proceeding.
They’re not explicit with regards to the activist, this would mean the activist was notified upon ProtonMail receiving the request?
I’m not sure there’s much you can do but lawyer up if you receive such a notice, but potentially the activist could have immediately started using Tor (maybe too late though, because to read the notice they might have already leaked their IP).
I did, it was non-mandatory and most of the (small) company would be on the call each day. I would turn my camera off and opt for just audio, but others would leave theirs on.
I enjoyed it for being able to have a quick back and forth when I had a question for something that was stopping my current task. Alternatively, I would be waiting on an unknown response time to a chat message which lead to a lot more task switching mid progress. But most of all, I just enjoyed the general talk that comes from being on a non-specific all day call - sports, family, news, etc. I learnt a lot more about my work mates that I otherwise wouldn’t have, which made us closer and work more enjoyable, plus working remotely can just get lonely sometimes.
I say all this and must mention that this call would happen daily for 6 months or so, but has slowly lost participants or only happens every other day as the company changes/grows. For me, I would like to see it come back!
I have an identical setup to this, painless to deploy updates/blog posts and zero cost.
I was previously using Jekyll, but moved over to Gatsby a few months ago and have enjoyed the built-in features of Gatsby and it’s surrounding ecosystem so far.
I have also considered integrating a git based CMS like Netlify CMS, but because it’s so easy to make new blog posts with just a git commit and a push I haven’t taken the time to change the workflow.
Links:
The CyberWire is a daily (Mon - Fri) podcast for cyber security news. Each episode goes for around 20 minutes and breaks down any significant news from the last 24 hours/weekend.
This is about the only cyber security news I directly follow and it tends to keep me abreast of the major going ons and the 20 minute length is short enough to digest daily.
I can see use cases for a delete function, but as people mention it’s all about how you manage abuse.
If a project owner really wanted they could just delete the whole repo (which includes issues et all) with no warning or confirmation from collaborators. But that’s a larger more destructive move, whereas, deleting a politically fuelled issue can be abused with far less repercussion.
Not on an issue, but I did once have a moment where I could have used a delete function on a pull request. I merged a pull request with my personal account on a repository I had only been working on under a pseudonym. From memory even resetting to an earlier commit and re-merging again with the correct identity didn’t work as GitHub kept a record of the original merge on that pull request. Which only further tied my two identities together as I tried to correct the mistake.
Nice work releasing!
There were two things I thought could use some improvement.
First were the two images of a list of hyperlinks that look clickable. I tried clicking on the links to no avail thinking they were broken, only to realise I was clicking on an image. The two images in particular are the News Sections and Newsmakers images on the homepage.
The second point was that I initially couldn't figure out how to access the service. I had to click on "Read the U.S. edition" which sounded like a sub-section of the site, not the main news aggregator service. What threw me off was the website slogan of "Daily news from around the world", I was trying to find the rest the news, not just the U.S. edition. If this is the only option right now, it could possibly just say "Read the News". Take this with a grain of salt though as I am not a U.S. citizen, so I might not be your current target audience right now.
It seems to be that the background colour value is set to `rgb(1,1,1,0.65)` and is missing the alpha channel in the attribute.
I made an identical page using `rgba(1,1,1,0.65)` and it looks better on iOS.
https://countdownto.xyz/c/jnfztcj0
This seems to be only a WebKit issue, you can produce the same results on desktop Safari. Other browser engines must detect when an alpha channel value is used with an `rgb` CSS attribute and update that attribute to `rgba` accordingly as an assumed fix.
Some analysts predict YouTube to bring in $15 billion in ad revenue in 2018. If so, they are losing around $28,000 for every minute they are down.
Very disappointing, this was my go to weather app. Any other recommendations? I'm using iOS in Australia, but also like an app that can track international weather.
I'm experiencing the same jumpy Live Photos on Firefox for iOS. Latest version of both iOS and Firefox.
I almost never use the Facebook website or app, but I haven't quit for the sole reason of Facebook Messenger. I still find it the most convenient means to contact my family and friends who are living overseas because Facebook is still widely used amongst these people.
I've tried to move my friends onto alternative means of communication, predominately Signal, so I could disassociate myself from Facebook, but my friends just don't stick it out. We converse as per usual over the first couple of months, but then their replies slowly dwindle down and if I go back and message them again over Facebook Messenger they respond as soon as they see the message.
Although them not moving to Signal is a pain for me, it's a bigger pain for them to move to an alternative messenger. Why would they want to use two different applications to message friends, let alone to just message one friend. A lot of these people aren't the technologically minded folk of Hacker News, these are the type of people who are Facebooks primary target audience. They don't care about how invasive Facebook can be with advertising or that their communications actually aren't that private.
I would love to see all my friends and family messaging me over some encrypted and decentralised messaging application so I can leave Facebook for good, unfortunately I just don't see that happening for the circle of friends and family I have.
My stack looks fairly similiar, give or take a few pieces of software, SABnzbd instead of NZBGet for one.
I would highly recommend checking out Radarr (https://github.com/Radarr/Radarr) to replace CouchPotato as I find CouchPotato a very inconsistent experience, and sometimes I am outright confused as to what it is doing (seemingly not snatching the movies I want it to).
Radarr is actually a fork of Sonarr, so you can expect a pretty good experience right from the start and the development has been very active since it was announced around a month ago. The project only being a month old is the only caveat as I am still uncovering minor bugs, but the devs are quick to fix.
...the client did not look very native on macOS (poking around revealed a lot of .exe files...
I also noticed this. But I have the mind frame that they are still a fairly "new" company, 3 years old, compared to Dropbox, 9 years old, and their growth and features continue to improve. In saying that, I would definitely prefer a more native look on macOS.
Besides that sync was quite slow compared to Dropbox.
I'm from a place in Australia with a generally slow Internet speed, especially upload speed, and may not have noticed this pitfall as much as others might.
No, that's also my understanding.
"Gitless is an experiment to see what happens if you put a simple veneer on an app that changes the underlying concepts. Because Gitless is implemented on top of Git (could be considered what Git pros call a "porcelain" of Git), you can always fall back on Git."
If not Dropbox, what solution are others turning to?
I recently signed up for Sync.com, due to their prioritisation of security features and they seem like a good company. I have come across some minor bugs, but I sent these onto their customer support who were reasonably responsive. Even with these minor bugs I'm still happy with the trade-off to move off Dropbox.
I must admit the most difficult part was definitely the services I used that directly integrate with Dropbox, like 1Password syncing. So I also had to find solutions to not just Dropbox, but also third-party services that integrated. For 1Password, I signed up for their Account option where they handle the syncing for you at a cost of $2.99 per month. Again, another trade-off I was happy to make.