HN user

arcfour

955 karma

[ my public key: https://keybase.io/xx; my proof: https://keybase.io/xx/sigs/R62ug0Cx2VKe5381AqjX7h8pS8BBoC-yFb5ir-6IHd0 ]

Posts0
Comments425
View on HN
No posts found.

No, the archive.today (and .ph, .is, etc.) operator configured their nameservers to return invalid responses to Cloudflare's 1.1.1.1 resolvers because Cloudflare doesn't forward EDNS client subnet info (for the privacy of their users). The operator claims to need this information for load-balancing but I don't buy that argument.

As far as I was aware, their issue was resolved, but sometimes I still see failures so I don't really know.

Also, "US-mandated DNS filtering" would be a violation of the 1A except in narrow circumstances (which don't exist here) so I'm not sure that that should be your first thought...

Yeah. My takeaway was sure, on one hand, arguing with your boss isn't going to end well. On the other hand, if arguing with your boss wouldn't end well (meaning you have a well reasoned technical disagreement, not just being insubordinate) then your boss is a bad boss...

[dead] 13 days ago

It sounds like it could be an interesting case but the weird AI slop writing is a bit much to trudge through.

I mean really:

What improved (reported)

Speech, recognition, dressing, continence — multiple functional domains, not a single symptom.

What we cannot conclude

No control group, no formal neuroimaging, no established causality. Spontaneous fluctuation and context cannot be ruled out.

Oh gee, thanks for the reminder on how the scientific method works, Claude. That's most certainly not something you can count on your audience being familiar with already if you're writing about a...medical case study, of course.

And why are these two points formatted as two cards with excessively long subheadings instead of something normal like a "paragraph?!"

TypeScript 7 14 days ago

Okay, so I'm not crazy for thinking that declaring an empty, typed array as `const` and then writing/pushing to it is confusing/feels wrong.

I didn't go to college for software engineering or anything so when I ran into that for the first time I assumed there must have been some good academic reason that was simply beyond me as to why it was done that way.

It turns out that no, it's just as weird to those that do have the formal background, boy am I feeling vindicated ;)

Because companies choose not to support Linux. Some popular ACs like EasyAntiCheat support Linux, but game developers (e.g. Facepunch/Rust) choose to block it.

Sure, the Linux kernel will let you load any unsigned kernel modules you want...but cheating is still possible (and happens) on Windows, so...

(Granted, trying to stop someone from running code on their own computer is a losing battle/stupid idea from the get-go)

F3 29 days ago

But that is 97% of the value proposition.

F3 29 days ago

Yes...my first thought. No way in hell anyone actually trusts this.

(And as if we didn't trust the compiler enough already!)

Why discord domain verification instead of domain-verifications with a dynamic list on entries?

The TXT record itself is already a dynamic list of entries. It's far simpler and easier to iterate through the list and compare the start of each value with your search string until you find "discord domain verification" directly than it would be to do anything else.

Example:

    ;; ANSWER SECTION:
    ycombinator.com.        300     IN      TXT     "openai-domain-verification=dv-QbhxxK0G0JK0dnyZ4YTsNAfw"
    ycombinator.com.        300     IN      TXT     "v=spf1 include:_spf.google.com include:mailgun.org a:rsweb1-36.investorflow.com include:_spf.createsend.com include:servers.mcsv.net -all"
    ycombinator.com.        300     IN      TXT     "MS=ms37374900"
    ycombinator.com.        300     IN      TXT     "anthropic-domain-verification-0qe2ww=yK576oHdDgyTcXgkPfj1KXgGt"
    ycombinator.com.        300     IN      TXT     "ZOOM_verify_2ndw8KZxSRa8PT8NmdyXvw"
    ycombinator.com.        300     IN      TXT     "google-site-verification=KsI69Y_jEVkp4eXqSQ9R9gwxjIpZznvuvrus6UolB9Y"
    ycombinator.com.        300     IN      TXT     "ca3-4861b957e83847c188e45d04ec314ee3"
    ycombinator.com.        300     IN      TXT     "apple-domain-verification=WG0sP5Alm7N6h1Te"
    ycombinator.com.        300     IN      TXT     "dropbox-domain-verification=asc63coma4mv"
    ycombinator.com.        300     IN      TXT     "google-site-verification=GJKdQskycEclAGPua3yXB9m_nVhxbrsVps_y-t9SXV0"
    ycombinator.com.        300     IN      TXT     "Wayback verify for support request 741082"
    ycombinator.com.        300     IN      TXT     "google-site-verification=rivq8jKu6AADGtbbEzJhmOpcqq08B7QxIzXxYV8DtyU"
    ycombinator.com.        300     IN      TXT     "rippling-domain-verification=a660f7a4ab77a3de"
Stop Using JWTs 1 month ago

JWTs aren't stored in a backend though.

Session cookies you exchange an opaque value with the DB for the user info

JWTs the user hands you their driver's license, and you can verify that it's an authentic license for the person who's name is on it

I agree it used to be fiddly at best but in recent years I had found it to be pretty easy in X11.

I haven't had complaints there for Wayland but I will say that it breaking other things has been annoying.

I think it's fair to say that requiring local administrative access to the device is out of scope, since you have already completely pwned the device in that case, which is what what you need to install a CA cert on any OSes.

But it seems likely that in the coming years, people will expect Apple's products to include the latest cutting edge AI (I don't mean useless AI shoved into every possible thing, I mean something closer to a useful Siri). Giving everyone else a 10+ year head start on you is not a good position to be in.

If you choose to outsource your AI to OpenAI/Anthropic/whomever, now you're beholden to another (risky), and for a critical feature of your ecosystem that your customers have grown accustomed to and to expect. And it's not just that they might jack up prices on you, but they can just... get acquired, or go bankrupt, or fall behind on model development...

At any point the interviewer could have clarified if they meant "at work" when they received an inappropriate answer. The fact they did not do this means they did not mean "at work," which makes sense because the questions they ask neither specify that nor are worded to make one believe they are work-related.

What would be the point of conducting an entire hour+ long interview where the candidate is only giving you irrelevant answers and you make no attempt to get them on track?

Because a court said it does not make it true. The captain made the correct choices. The first officer made inexplicably incorrect choices continuously; choices which nobody would ever make regardless of training, unless perhaps you had literally never flown a plane before.

At no point in time would the correct response to a stall warning be to pull the nose up. This is something taught well before you enter the cockpit of a commercial airliner. If you continue to pitch the nose up excessively, you will stall the aircraft. This is also something you learn on day 2 or 3 of flight school.

If the first officer had done literally nothing at all, 228 people would be alive.

There's nothing wrong with writing CLI stuff in Node. It has interfaces to work with terminals built-in that aren't unlike what you'd find in any other language. I say this as someone who has worked with ncurses in C a decent amount (and there is a reason I try to avoid doing so anymore!)

React, however, I do find questionable, even having read about and understanding the idea behind Ink.