HN user

dfcowell

772 karma
Posts3
Comments188
View on HN

This is solved by the agent having its own identity and credentials. Why would you share your login and identity with your AI agent?

Access control and permissions should be handled on the backend by enforcing IAM on well-defined principals, not with MCP middleware. Claude can already bypass MCP and call APIs or use CLIs if it runs into blockers using MCP, so it’s not an effective point to implement the control.

I’ve solved this by keeping my laptop keyboard uncustomized, while using Colemak-dh and home row mods on my desktop split keyboard.

I’m proficient enough that I can work on anyone else’s machine well, and I have the comfort and speed benefits on my main workstation.

The spec requires negotiation between the devices to deliver any nontrivial amount of power. A data connection is necessary to enable charging.

Author here. At the time, Angular relied a lot on the AOT compiler and tree shaking to keep bundle sizes down. No idea if this is still the case.

If we built the app with the stable branch the bundle size was orders of magnitude smaller: less than 200kb. Still a bit of a chonker, but more reasonable than the ridiculousness the experimental SSR branch spat out.

Author here. That’s the takeaway I was going for.

It could have been any technology. The silver bullet is choosing the right tool for the job.

I don’t have an attachment to any particular tech. At the time React was what I knew, and I was coming off the back of building a server side rendered React site when I joined this company. I had a team of JavaScript-focused engineers to work with.

Author here. It was a gamble, but I was fighting against a very strong sunk cost fallacy in leadership at the company at the time, and there was a general lack of trust in the entire technical team. I *would not* recommend this approach as a typical way of doing business, and maybe I didn’t do a good enough job at communicating that in the post. This is the only time in my career I’ve delivered this kind of ultimatum.

Everything about this particular situation was exceptional. I focused on the decision to do a rewrite in the post because I thought it was the more interesting part of the story. In hindsight I might have gotten that wrong.

Ha, no, that was a far more mundane issue. The CMS I'm using requires double opt-in to subscribe, meaning you need to enter your email address and click the confirmation link.

It also apparently requires double email configuration, meaning it has two places where you can configure your mailer. I had only set it up in one place, meaning the confirmations never got sent.

Bit of a facepalm moment.

I’m reminded of PGP signing parties where people built a web of trust via key signing.

There may be a resurgence of this kind of thing as people use social heuristics to decide if any given creator is likely to be producing generative content or not.

Ghost is ridiculously good out of the box. Part of that comes from the opinionated stack it demands - support for only one database server, very specific and minimal config options.

I self-host Ghost and Plausible Analytics (along with several other services,) on an Unraid box at home, fronted by Cloudflare, and it holds up well to load. Costs next to nothing, too, since it inherits hand-me-down parts from my main desktop PC.

This is a really good addition, and something I wish I’d thought to cover. I’ve added a link back to this HN thread to the post so that people who find it from other sources can benefit from your perspective!

This is a really great point, and it’s awesome when a team strikes the right balance. In my experience these engineers tend to be rarer than the group I talk about in this post, but when you find them they’re worth their weight in gold!

I’m not the author, but I’ve gone down the same path as them (Plex + ripped CDs.)

My breaking point was when - as a premium subscriber already - Spotify insisted on promoting their family plan, Taylor Swift’s new album and whatever the flavor of the current week was via full-screen modal popups in the app with no way to prevent them. I asked support several times and was told they didn’t have a toggle.

I tried moving to Apple Music, but the discovery patterns in that app didn’t align with what I was looking for, and offline play has been nerfed so hard I can’t find any way to do it any more.

I’m now on Plex + Plexamp for music and happier for it.

I’m basing my feedback on Will Larson’s Staff Engineer archetypes (https://staffeng.com/guides/staff-archetypes) so read that first if you’re unfamiliar.

It sounds like you’re in a company that only has Tech Lead and Right Hand staff+ roles available, and the responsibilities of those roles are at odds with what you want to be doing.

I would actively seek out companies that offer Solver or Architect roles. These tend to be non-tech companies with large internal technology teams, so you might need to look further afield than the organizations we typically see represented on HN.

Overall though, optimize for your happiness at work. If you suffer through a role you don’t find fulfilling you will burn out.

I wouldn’t worry about the optics of your CV. Any place with a decent culture (i.e. somewhere you would actually want to work,) will listen to your story and appreciate your self-awareness and candor.

I think a lot of this sentiment comes from the fact that people buy into and hype up an ecosystem that is very up-front about how much responsibility lies with the individual (all of it!) and those same people get upset when they get taken for a ride and lose their shirts.

Play with fire, get burned. If you don’t want these things to happen, stay in the regulated financial system where guard rails exist against market manipulation.

Personally, I’ve done my due diligence and decided that the crypto community is a raging dumpster fire that is speedrunning the last 200 years of centralized financial fraud and somehow failing to learn any of the lessons along the way. For that reason (and because I lack the time to exhaustively vet every project that looks interesting,) I’m staying out of it.

Pretty much, however I can vouch for the quality of the poster’s other newsletters.

He’s also very good about sending only what he says he’s going to send, when he says he’ll send it and deleting the list afterwards.

Of course, you need to deal with the quirk of the material only being available by email, which isn’t the worst fate in the world.

This is a fantastic question that doesn’t get asked enough by new managers. Great to see you’re actively trying to build the management skill set!

Manager Tools is great for the “nuts and bolts” of management, regardless of industry. They have a book and paid membership, but start with the podcast hall of fame/HOF episodes to see if their methodology works for you: https://www.manager-tools.com/all-podcasts?field_content_dom...

More engineering-specific, The Manager’s Path (book) is fantastic.

Radical Candor (book) is excellent when working out how to build relationships, coach and communicate effectively with your team.

If you’re working in a multicultural environment The Culture Map (book) is very helpful.

I’d also recommend joining this Slack community to find a wealth of wisdom from experienced engineering managers, and to share your journey with other newcomers: https://engmanagers.github.io/

Good luck, and welcome aboard!

I’m sure it’s a better shifting experience, but I’d never tour with a Di2 shifter.

I was doing a group cycling tour with 3 friends, one of whom had a Di2 GRX shifter. He pinched the Di2 cable in the rear axle when reassembling his bike and shorted the whole system. Needed to replace everything. That ended the trip for him, had to go back into town and get it fixed.

The system might provide a better shifting experience, but from a durability and field-repair standpoint I think mechanical shifting still has the edge.

All valid criticisms, especially the slowness and heavy page sizes. Another perspective on 3 of your points though (and a free quality-of-life tip!)

For a while, we had tickets in done states that just roll over to the next epic, like they were still open. Nobody knew why, and it went away with nobody making any fixes to anything.

I almost guarantee someone forgot to set the resolution field when creating a workflow transition, noticed and went back and fixed it.

Bulk operations are just a PITA

Agreed that the UI is jank AF, but it works reliably on the order of tens of thousands of tickets at a time.

UIs that have drag & drop, but don't support simultaneous scroll are annoying. I have to wait for the view to move at JIRA's speed, which is ofc., slow.

Almost every operation you want to do this for can also be done by right-clicking and “move to.” There’s “move to top of backlog”, “move to sprint x”, “move to top of column”, you can also ctrl/cmd click (or shift-click) to select multiple issues.

There are plenty of sub-500k TC engineers getting around, and the vast majority of companies are “lower-tier” by your implied definition.

These companies won’t succeed if they try to act like they’re working with mature engineers, because they’re usually not.

Skills like knowing how to unblock yourself, how to identify systemic problems in a team and correct them don’t come naturally to a lot of people.

If you’re not encountering teams like this I’m happy for you, but lower-performing teams often benefit by adopting a rigid methodology to kick-start the process of self-improvement.

In an ideal world, they further transform their working style into something that works for them by reflecting on their experience on a regular basis.