HN user

Sytten

2,600 karma

meet.hn/city/ca-Montreal

Building caido.io

Want to chat, email emile [@] caido.io

Posts36
Comments601
View on HN
news.ycombinator.com 4mo ago

Tell HN: GitHub Having Issues

Sytten
52pts27
github.com 10mo ago

On-going NPM supply chain attack of Qix packages

Sytten
3pts0
blog.gitguardian.com 10mo ago

The GhostAction Campaign: 3,325 Secrets Stolen

Sytten
3pts0
blog.leapp.cloud 2y ago

Leapp Is Shutting Down

Sytten
2pts0
status.kagi.com 2y ago

Kagi Outage

Sytten
4pts1
www.inc.com 2y ago

Plex Raises $40M

Sytten
26pts29
github.com 2y ago

Show HN: RSS Feeds for Radio Canada

Sytten
9pts0
github.com 2y ago

Rust Async Trait Stabilized

Sytten
21pts4
caido.io 3y ago

Show HN: Caido, a lightweight web security auditing toolkit

Sytten
17pts4
render.com 3y ago

Render Price Hike

Sytten
19pts5
metalbear.co 3y ago

Hooking Go from Rust – Hitchhiker’s Guide to the Go-Laxy

Sytten
17pts1
news.ycombinator.com 4y ago

Tell HN: GitHub Apps bug created tokens with elevated privileges

Sytten
5pts1
cloud.google.com 4y ago

Cloud SQL launches support for in-place upgrades

Sytten
3pts1
how-to-help-ukraine-now.super.site 4y ago

Real ways you can help Ukraine as a foreigner

Sytten
2pts0
wundergraph.com 4y ago

The Complete GraphQL Security Guide

Sytten
78pts16
portswigger.net 5y ago

Portable Data ExFiltration: XSS for PDFs

Sytten
1pts0
cloud.google.com 6y ago

GCP Setting up serverless NEGs

Sytten
3pts0
www.hashicorp.com 6y ago

HashiCorp Terraform 0.13 Beta

Sytten
3pts0
grafana.com 6y ago

Grafana 6.7.4 and 7.0.2 released with important security fix

Sytten
1pts0
www.youtube.com 6y ago

Linux Sucks 2020 [video]

Sytten
2pts0
en.wikipedia.org 6y ago

18F

Sytten
3pts0
grafana.com 6y ago

A GCP Persistent Disk Incident Snowballed into a 23-Hour Outage

Sytten
2pts0
news.ycombinator.com 6y ago

Ask HN: What is a good Google replacement for my parents?

Sytten
3pts7
sobolevn.me 6y ago

Enforcing Single Responsibility Principle in Python

Sytten
2pts0
github.com 7y ago

Microsoft Open-Sourced Calculator

Sytten
59pts18
news.ycombinator.com 7y ago

Ask HN: Good technical GDPR resources?

Sytten
22pts13
news.ycombinator.com 7y ago

Ask HN: Python web framework in 2019

Sytten
1pts1
github.com 8y ago

Show HN: Open source, self hosted, developer-oriented translation tool

Sytten
4pts0
github.com 8y ago

Massgate – The central server for the game World in Conflict

Sytten
118pts41
hackernoon.com 8y ago

Faircode, an alternative to Open Source that aims to get developers paid

Sytten
2pts0

Great terminal, annoying that everytime it updates I have to go back to the settings to disable new AI features or layout changes.

You are inferring your own perception based on my comment, no need to be an asshole here. Like I said elsewhere we do both and they serve different purpose. We also make is very clear and easy to disable in the onboarding. I hope you try to build a business sometimes and open up your perspectives that maybe just maybe you don't have all the answers.

Respectfully I think your argument defeats itself. If you can only speak to your users once every 10-12 months it means your process doesn't scale by definition. Good analytics (not useless vanity metrics) should allow you to spot a problem days after it was launched not wait 3 quarters for a user to air their grievances.

That is just poor analytics IMO, if you have a good harness you can definitely tell if a feature is not well designed. You have to optimize for things like number of clicks to perform an operation not time spent in app.

I used to believe that it was not necessary until I started building my own startup. If you dont have analytics you are flying blind. You don't know what your users actually care about and how to optimize a successful user journey. The difference between what people tell you when asked directly and how they actually use your software is actually shocking.

Interesting product (Caido co-founder here). It is very hard to nail auth, probably the most underlooked aspect by end users. We are working on something similar for PoC reproduction of vulnerabilities.

Fingerprinting is also a hard thing to match perfectly, I would be curious to know what your strategy is on that. My experience has been that unless you bundle multiple TLS lib it is almost impossible to do at 100% because none of the lib cover all the TLS extensions.

I really wish people would stop using the language as an argument and that commenter would also move on to a more interesting debate.

In your discussion the first comment from an ex kuzu dev made an excellent point that rust for databases in an excellent language to ship faster with confidence while reducing real problems of concurrency and corruption.

At some point it becomes intellectual dishonesty to dismiss a language because of vibes instead of merit.

Trademark are always scoped to particular domains it is not universal, if you look up mouser you will see they listed the usage for electronic components, distribution and related. No mention of software. They might fight you since you do have to protect your trademark but in theory you could open a mouser restaurant and trademark that name for food distribution. As long as the customers is able to tell the difference it is fine.

The best thing I did to help with my tinnitus what Cognitive Behavioral Therapy. If you perceive the sound as something dangerous than it bothers you way more.

Like others pointed a bad night sleep definitely increases the perceived sound.

Also the stress in the shoulders doesn't help.

From a technological risk perspective I would never tie myself to a vendor like that. I know people do it all the time, but you are totally at the mercy of the vendor increasing price and having no choice but pay since you are so tightly integrated. Always add an interface is my moto.

I am a caveman, I don't understand the need for a personal assistant. What are you guys using it for?

Security Cryptography Whatever: Discusses in depth cryptography and papers on that topic

Oxide and friends: From oxide conputers, great tech interviews and various tech topics

Geopolitical cousins: weekly take on geopolitics that doesn't feel dreadful

The red line: If you want deep analysis of conflicts and militaries from experts

From my experience at our startup, AI is still pretty shit at Rust. It largely fails to understanding lifetime, Pin, async, etc. Basically anything moderately complex. It hallucinates a lot more in general than JS for comparable codebase size (in the 250k lines range).

We will see when the attacks are public, a lot of the malicious server attacks we have seen in the past were kinda of overblown. Not discounting OP but it is very easy to get into clickbait territory.

Forced savings like done in Quebec, Canada is likely the best model for most people even though I dont like it as an individual that knows how to manage its portfolio. It also has the benefit of creating a sovereign wealth fund that can invest locally and be an economic driver but independent from the government.

And we will all love from fresh water and love, can't wait for that world!

Seriously, you pay for software so people can make a living to improve it. It is a service like anything else.

It is interesting to see yjs with hoccuspocus being used. I am currently considering our options for real time document editing + full text search.

Seems like a common approach is something like using yjs for sync with a temporary LSM storage like rocksdb for updates and then periodically snapshot to postgres for full text search and compaction.