HN user

adeptima

489 karma

done with @adeptima, mainly known as @reactima

Want to discuss comment or brainstorm. Dont hesitate, text me

https://t.me/reactima https://api.whatsapp.com/send?phone=818047562323

Creating SaaS applications with Reactjs/Python/Golang/TS. If got interested in any of my comments with lot links and github references, feel free to ping me on whatsapp or telegram.

Notes and fragments for LLVM hallucination https://zeroread.com/

Posts15
Comments146
View on HN
newsletter.pragmaticengineer.com 1y ago

Software engineering industry in 2024 what, why changed in 2 years, what is next

adeptima
4pts2
www.youtube.com 2y ago

ThePrimeTime: Gemini Wont Show C++ to Underage Kids "Its Not Safe" [video]

adeptima
3pts0
www.youtube.com 2y ago

How to Reply to Negative Comments (90's Tutorial) [video]

adeptima
2pts1
www.nginx.com 3y ago

Preview implementation of Nginx support for QUIC+HTTP/3 is now available

adeptima
1pts1
news.ycombinator.com 3y ago

Ask HN: What's the status of Microsoft Fluent UI? Soon ready to use?

adeptima
1pts0
chrome.google.com 6y ago

Tech Stories Tab by Hacker Noon

adeptima
2pts0
hackernoon.com 6y ago

Nicole Zhu: Step-by-Step guide building a blockchain like blockchain in Rust

adeptima
2pts0
hackernoon.com 6y ago

App which recommends employee to leave employer if culture is too low

adeptima
1pts0
hackernoon.com 6y ago

Must Read for Laid-Off Engineers: Making Sense of Your Future

adeptima
1pts3
news.ycombinator.com 6y ago

Ask HN: Will you retire after 1000 weeks (~19 years)? Or work another 1000 week?

adeptima
5pts3
blog.hunter.io 8y ago

LinkedIn is killing Hunter.io and related Chrome Ext ecosystem

adeptima
3pts0
twitter.com 9y ago

@Durov @Telegram We had two attempts to bribe our devs by US agencies

adeptima
3pts0
www.linkedin.com 9y ago

Building Remote Team of Russian Speaking Developers

adeptima
4pts1
www.fullcontact.com 9y ago

With 40+ billion records FullContact raises $25M

adeptima
3pts0
www.postgresql.us 11y ago

Crimean developer submits patch to .Org = “possible” violation of Order #13685?

adeptima
5pts1
Vite+ Beta 20 days ago

Extremely happy user of Vite, Vitest, Rolldown, tsdown, Oxlint, and Oxfmt.

I do have lot of hardforked packages, and dont want to look back. Everything just works.

If you confused by the naming, start from Oxlint https://oxc.rs/docs/guide/usage/linter Rolldown https://rolldown.rs/

Did very little changes to tsconfig during past 6 months adoption

My day-to-day process - get the new package unless it some antd6, echart or some rendering engine or geo spatial lib, clean up with Claude, strict and unify type system and align it with my vite, tsconfig, oxlint tastes. The result - no need to follow libs bloat and supply chain attack issues. Easy to read, easy to fix.

OAuth for all 27 days ago

exactly! allowlist or some sort of marketplace or app store like you like or not

OAuth for all 27 days ago

appreciate all your work Hydra, Kratos and my favorite small RBAC lib - ory/ladon

OAuth for all 27 days ago

the original sin of internet - it’s not secure, and for many it’s not the bug it’s a feature to make money or gain power. all nested layers to cover up previous fails. example - nonce, state, encryption bumps in oidc/oauth2.1

OAuth for all 27 days ago

Mixed fealings cause the full context should include plans on both Authorization and Authentication flows at least withing Cloudflare ecosystem. No github examples

Anyway good start in the right direction from Cloudflare, yet still long way to go especially compare to the full Ory's offering its built on. Ory's Kratos handles identity, login, registration, recovery, MFA... https://github.com/ory

IMHO full scope should include plans on user store, SAML, multi-tenant org model. Good example - Zitadel https://github.com/zitadel has managed UI for orgs multitenancy, OIDC/PKCE supports, etc you can even partial glue RBAC to it

Subabase offers managed and opensource https://github.com/supabase/auth

Siding "MCP is dead, Skills forever" what bother me about all of them is planning to plug MCPs and rotate keys ... this start hitting the fan very soon

OAuth 2.0 Dynamic Client Registration (RFC 7591) https://datatracker.ietf.org/doc/html/rfc7591

https://modelcontextprotocol.io/specification/2025-03-26/bas...

Any comments greatly appreciated. Especially in multitenant saas and built-in "AI assistants" context

My expectations to dear fellow humans - more sophisticated personal insults (ex. give me your cute comments), a freudian slips, hidden messages and motives, first viewer experience with the next cool toy from the hype train, sharing all kind of insecurities, heavy f.. word if very dramatic first person experience happened, border line exposure to the insider info, sharing something your corporate HR gestapo wont appreciate but might help another guy on the line, "i knew the guy who actually did it" stories, motivational statement toward my non-native english, etc

->> ◕ ‿ ◕ <<--

Real tip - find someone who loves outbound, can create a funnel outside of Linkedin or convert traffic from Linkedin to something more reliable and can talk about numbers non-stop for hours.

Ex. I never did more than 1k whatsapp messages with 20% open rate in a month ...

Know a friend who is doing 190k MRR with 12k whatsapp messages open rate 40%-60% (no AI SDRs!, fake avatars, etc) and what to double it next year. All he wants to talk is outbound ... and how it will make rich and how it should cost no more than 20% revenue.

99,999% hates outbound with passion, want to dump on someone else, can't retain SDRs for more than 6 months, etc

There are already public memos from large companies where leaders tell their staff that any request for headcount has to come with a justification for why an AI system cannot do the job

spot on! at my place - playwright + prompts instead of hiring QA. data analytic guy is gone ... noone is missing him

today's random quotes

- "AI isn't replacing jobs. AI spending is" ...

- "he job market in India has grown 9% in 2025, so far. 53 million in new jobs. I wonder, how many jobs came from U.S. companies being off shored?"

5 trilllion off the global IT bubble funded by VC money taken somewhere else poured into GPUs and data centers

look at number of linkedin profiles in US companies like Accenture in India .... 450 000 + ... feel really bad biggest transfer of head-counts from US, chatgpt just fuelled it

10+ years in Japan. The message here is much deeper from my perspective. “Let’s jump on the call” is not the solution. The guy was stripped off of his face. I love Japan for being human. Small business bar or restaurant with 3 tables. Not everything should be streamlined for a quick call solution… the process was pushed on his head. Google nemawashi decision making process

Did research on accent, pronunciation improvement, phoneme recognition, kaldi ecosystem, etc … nothing really changed in the public domain past few years. There’s no even accurate open source dataset. All self claimedccc manually labelled dataset with 10k+ hours was partly done with automation. Next issue, model models operates in different latent space often with 50ms chunks while pronunciation assessment requires much better accuracy. Just try to say B loud - silent part gathering energy in the lips, loud part, and everything what resonates after. Worst part there are too many ml papers from the last year students or junior phd folks claiming success or fake improvements, etc

The article itself is just a vector projection in 3d space … the actual reality is much complex.

Any comments on pronunciation assessment models are greatly appreciated

QGIS is a gold standard to verify you tools works fine and data is in a correct format ...

if you are a web based first, you have even better options to build and extend

kepler, protomaps, maplibre-gl-js

https://kepler.gl

https://protomaps.com

https://github.com/maplibre/maplibre-gl-js

the rest can be found on great Qiusheng Wu’s (aka @giswqs) Geo/GeoAI tutorials channels and repos

https://www.youtube.com/@giswqs/videos

https://x.com/giswqs

but what really amazed me is how geo spatial support is growing inside of databases recently

https://duckdb.org/docs/stable/core_extensions/spatial/overv...

all mighty postgis https://postgis.net/docs/manual-3.5/postgis_cheatsheet-en.ht...

https://sedona.apache.org/latest/

https://geoparquet.org/releases/v1.0.0/

and many unlocked dataset compare to other industries

https://docs.overturemaps.org/getting-data/duckdb/

https://www.openstreetmap.org/

https://hub.arcgis.com/search

lot great webtools are comming for sure and you still can be 100% of most of your geospatial pipeline

p.s. want to extend the above list with self-hosted tools with minimum or none dependencies on paid APIs, and recommendations are greatly appreciated

same sentiments with an article author - gpt5 looks like a cost-cut initiative.

my personal feeling gpt5-thinking is much faster but doesnt produce the same quality results as o3 which were capable to scan through the code base dump with file names and make correct calls

dont feel any changes with https://chatgpt.com/codex/

my best experience was to use o3 for task analysis, copy paste the result in https://chatgpt.com/codex/, work outside and vibe code from mobile

Kepler.gl 1 year ago

Foursquare has another open source project worth noting on DuckDB - SQLRooms

https://sqlrooms.org/

“Build data-centric apps with DuckDB An Open Source React Framework for Single-Node Data Analytics powered by DuckDB”

Meilisearch is great, used it for a quick demo

However if you need a full-text search similar to Apache Lucene, my go-to options are based on Tantivy

Tantivy https://github.com/quickwit-oss/tantivy

Asian language, BM25 scoring, Natural query language, JSON fields indexing support are all must-have features for me

Quickwit - https://github.com/quickwit-oss/quickwit - https://quickwit.io/docs/get-started/quickstart

ParadeDB - https://github.com/paradedb/paradedb

I'm still looking for a systematic approach to make a hybrid search (combined full-text with embedding vectors).

Any thoughts on up-to-date hybrid search experience are greatly appreciated

Apache ECharts 1 year ago

Happy eChart user. Added a tiny Reactjs wrapper on the top and ditched all D3 libraries. Never look back. Easy to inline and embed into slatejs based documents. Usable on mobile and responsive enough for my use cases.

Accurate word timestamps seems an overhead and required a post processing like forced alignment (speech technique that can automatically align audio files with transcripts)

Had a recent dive into a forced alignment, and discovered that most of new models dont operate on word boundaries, phoneme, etc but rather chunk audio with overlap and do word, context matching. Older HHM-style models have shorter strides (10ms vs 20ms).

Tried to search into Kaldi/Sherpa ecosystem, and found most info leads to nowhere or very small and inaccurate models.

Appreciate any tips on the subject

And by the way, has anyone researched on GNAP (published 20 March 2024)?

GNAP (Grant Negotiation and Authorization Protocol) is an in-progress effort to develop a next-generation authorization protocol

From spec https://oauth.net/gnap/

GNAP is not an extension of OAuth 2.0 and is not intended to be directly compatible with OAuth 2.0. GNAP seeks to provide functionality and solve use cases that OAuth 2.0 cannot easily or cleanly address.

GNAP and OAuth 2.0 will likely exist in parallel for many deployments, and considerations have been taken to facilitate the mapping and transition from existing OAuth 2.0 systems to GNAP

Doesnt look like GNAP will fly any time soon, however there is a very interesting part - Security Considerations section. Looks like it was made by people who are familiar with all varieties of cyberops and usability issues in OAuth2/OIDC spec.

Security Considerations section

https://datatracker.ietf.org/doc/html/draft-ietf-gnap-core-p...

If any cyberops, pentester pro reading this, please advise how to research more. Thanx in advance.

Thanx for sharing!

What if pre-signed URL is leaked, you cannot invalidate a pre-signed URL without rotating credentials or changing bucket policies, right?

I was thinking about signed cookies or API gateways type of solutions.

Some specs should be mandatory 100% agree

OpenID Foundation seems took a path of making "profiles" like FAPI rather consolidation and enforcing the best practices and depricating the bad.

FAPI (Financial-grade API Security Profile 1.0) https://openid.net/specs/openid-financial-api-part-1-1_0.htm...

I hope the community will combine it all at some point and add specifications for proper policy and resources management too by looking at the full lifecycle of modern applications.

my guess the idea and intension of .well-known was good, so generic end-user libraries can be implement ... the reality is ugly and generate lot of man hours for cyberops consultancies

And this is why OIDC and IDPs exists to expand more with nonce, user agent footprints and other validation mechanisms