HN user

ashishb

1,056 karma

Software engineer & blogger - https://ashishb.net/about

Posts37
Comments508
View on HN
ashishb.net 4d ago

Find What SaaS Tools Competitors Use via Sub-Processors

ashishb
8pts0
ashishb.net 16d ago

EMF and Kids

ashishb
2pts0
ashishb.net 2mo ago

I was asked to install malware during a fake interview

ashishb
54pts10
github.com 7mo ago

Amazing Sandbox (asb) – a Docker-based sandbox for running third-party code

ashishb
1pts0
ashishb.net 7mo ago

The real lock-in in GitHub is not the code, but the stars

ashishb
6pts7
www.infoq.com 7mo ago

Reddit Migrates Comment Back End from Python to Go Microservice to Halve Latency

ashishb
6pts1
ashishb.net 9mo ago

Best practices for using Python and uv inside Docker

ashishb
7pts0
ashishb.net 11mo ago

Family Ties in Your DNA: Some relatives are closer than others

ashishb
2pts0
ashishb.net 11mo ago

To keep your machine secure, run third-party tools inside Docker

ashishb
13pts9
ashishb.net 1y ago

In defense of ad-supported products (2024)

ashishb
2pts0
ashishb.net 1y ago

Maintaining an Android app in Google Play Store is a lot of work

ashishb
156pts79
ashishb.net 1y ago

Google Search is losing to Perplexity

ashishb
8pts0
ashishb.net 1y ago

How to Run Python in Production

ashishb
34pts30
ashishb.net 1y ago

Continuous Integration ≠ Continuous Delivery

ashishb
2pts0
github.com 1y ago

Gabo: GitHub Actions Boilerplate Generator

ashishb
3pts1
ashishb.net 1y ago

It is hard to recommend Python in production

ashishb
33pts37
longform.asmartbear.com 1y ago

The Serengeti Plain: Fallacies that aren't fallacies

ashishb
2pts0
ashishb.net 1y ago

The Indian startup bubble is insane

ashishb
11pts19
ashishb.net 2y ago

Hermetic Docker images with Hugging Face machine learning models

ashishb
2pts0
blog.rajivayyangar.com 3y ago

What happened to Tandem (virtual office)

ashishb
5pts0
play.google.com 5y ago

MusicSync: An Android App Alternative to Google Play Music

ashishb
1pts0
advisors.ashishb.net 6y ago

Show HN: Advisor List (Find advisors for your startup)

ashishb
2pts0
ashishb.net 6y ago

Docker 101: A basic web-server displaying hello world

ashishb
1pts0
autosnoozer.com 6y ago

Show HN: AutoSnoozer – take back control of your Inbox

ashishb
4pts2
calendarbot.ashishb.net 6y ago

Show HN: Create calendar invites by forwarding emails

ashishb
1pts0
go.ashishb.net 6y ago

Show HN: Voicenotes Android App

ashishb
1pts0
ashishb.net 6y ago

Keep your dotfiles bug-free with Continuous Integration

ashishb
5pts0
news.ycombinator.com 8y ago

Ask HN: How to manage professional connections?

ashishb
14pts10
ashishb.net 12y ago

Fixing tech recruiting

ashishb
2pts2
ashishb.net 12y ago

Random thoughts on Nokia's android phone

ashishb
2pts0
Kimi Work 2 days ago

This is true for all CLI tools on Mac and Linux (and other operating systems from that era).

Historically, everything you ran was trustworthy.

Android and iOS were invented in an era that does not allow this because the risks became evident by then.

That every other vowel letter also can is English's low level of phoneticism

The level of phoneticism between English language and its latin script is not evenly spread.

For example, the letter "c" might mean /s/ or /k/ sound. However, the letter "k" almost certainly means /k/ sound.

In some ways, the schwa sound in English the worst as there is no symbol which is committed even partially towards it.

it is Rāma, and 'a' represents the schwa.

Sure, but if my name is Rāma, I have to choose either "Ram" or "Rama" or "Raama" for my passport name. Or legal name in most places, non-alphabetic symbols do not work with all modern systems.

Many other languages using the Latin script (German, Italian, Finnish) don't have this problem, what you see is what get.

English imports spellings from other cultures and adds its own layer of pronunciations. Other languages probably don't do it as often.

It's Ram, not Rama, it's yog, not yoga'... And they have no idea what schwa deletion is.

It is neither.

The fundamental issue is that there is no way to represent the schwa sound in English[1]. All of a,e,i,o,u have been used to communicate the schwa (or schwa-like) sound in English.

  - The `a` in about
  - The `e` in taken
  - The `i` in cousin
  - The `o` in button
  - The `u` in upon

1 - https://ashishb.net/linguistics/schwa/

Many of my friends are surprised that I purchase mp3s and store them in Google Drive instead of listening on Spotify or YouTube.

Heck, I even wrote a player for this [1] The problem is that licensed media like this are always going to become inaccessible over decades.

It happened with Apple[2] and Microsoft (PlaysForSure[3]) as well.

1 - https://musicsync.ashishb.net/ 2 - https://www.nytimes.com/wirecutter/blog/you-dont-own-your-di... 2 - https://www.cnet.com/culture/playsforsure-officially-dead/

Are you actually claiming English isn't a mother tongue to anyone?

I gave a specific example where neither the coffee wholesaler nor the buyer probably operates day to day in English. But they would still use English for the official agreement.

That does not take away from other benefits of English like being spoken by millions as a primary language and probably billions as a second language

Sanskrit was widely spoken and understood just like Latin or Avestan, in its heyday. Otherwise it wouldn’t be part of the liturgical traditions of Buddhism, Jainism and Nastika traditions.

I think, and it is just my speculation, that for most of Indian History, Sanskrit was the link language.

Just like "Latin" in the USA and Europe of the early 17th and 18th centuries, when all academic instructions were carried out in Latin!

So, nobody used Sanskrit as the primary language, but everyone could or knew someone who could convert Sanskrit to the local dialect.

It is almost like how Chinese and Colombian traders might sign a contract for coffee purchase in English. Neither might use English in most of their daily operations.

Languages do matter.

And I think the only sensible backend languages when starting a new for-profit project is Python, Go, and Rust for 99% use-cases.

In other cases, third-party packages, tooling, integrations, and telemetry starts to suffer.

Because I'm confident nothing will happen if it does

Well, best of luck.

1. Amazon has shipped backdoored packages - https://aws.amazon.com/security/security-bulletins/AWS-2025-... 2. Scanners like Trivy have been compromised - https://socket.dev/blog/trivy-under-attack-again-github-acti... 3. Redhat is shipping backdoored FOSS packages - https://access.redhat.com/security/vulnerabilities/RHSB-2026... 4. Even fake and malicious ESLint packages have been published - https://gbhackers.com/eslint-package-attack/

But in this particular case isn't the problem that it's sending everything in the sandbox?

If a CLI is touching certain files, they are likely to be leaked one way or the other.

Why not reduce the attack surface?

When does someone visit your house? Do they get unfettered access to your bedroom & safe as well?

Half-Baked Product 19 days ago

Listen to any on the Elon Musk interviews, he knows more technical intricacies of his 1000+ employee companies than your average startup founder with 10 employees.

1. Docker (or any Linux container runtime, for that matter) is not intended for, designed for, or effective as a security boundary.

This has been discussed in detail earlier - https://news.ycombinator.com/item?id=47612726

Further, on Mac OS, you can use `--mode=native` for Mac's native sandboxing (seatbelt).

2. Root containers run as root on the host. The "sandboxed" processes have full capabilities, as far as the kernel is concerned with them.

That's not always the case. You can run rootless containers or you can use containerization like Podman which does not run as root.

For dependabot it's as simple as cooldown.default-days: 1

Most people stick to default of 0. In fact, I am realizing over time that it is best to make it 7-14 days.

Hypothesis: a big accelerant of these rapid repository compromise (from Red hat to GitHub to Amazon to small startups) might be GitHub+dependabot automatic dependency updates.

So, just like COVID-19 used air travel, modern malware attacks are relying on GitHub+dependabot to speed up the spread.

Even for single page website built using Vue, I would get about 5 updates a week.