HN user

jurassic

3,628 karma

Enamored with Golang.

Posts8
Comments604
View on HN

Sorry you are having a rough search. I was part of a large layoff so I know plenty of people who’ve been through it recently, some more than once if they went into another company that then had layoffs. I’d say the average search in my circle for those actively looking was about 3-4 months, with people who were very junior taking perhaps double that. I got some rejections that shocked and upset me at the time, but now that time has passed I’m glad I’m not in those roles because I found something later I liked much better.

For myself, referrals were a huge part of getting a job somewhat quickly. As more people are looking, the slush pile of resumes gets bigger which causes employers to feel they can be more picky. So if you’re relying on a cold application turning into an interview, that will definitely have a very low success rate.

I know only one person who didn’t get a job for an entire year, one of the smartest people I worked with at my last job, but to be honest it seemed like they were having some mental health / mid-life crisis things going on and not actually applying much if at all. I don’t know you and your situation, and I’m not saying this is the only explanation for a long and fruitless search, but if you think you might be like this person then I’d encourage you to reach out to someone who knows you and get the support you need. Marinating in negative thoughts won’t get you anywhere. This stuff has to be addressed because attitude, emotional state, and overall vibes can bleed into the entire interview performance and undermine what is otherwise a solid showing.

I hope something good comes your way soon.

A small percent of tech workers struggling to get a job doesn’t change the overall picture that most people working in tech are living relatively prosperous and comfortable lives. We are paid at a level that means we don’t feel stressed at the grocery store figuring out how to feed our kids or wonder how will we get to work when our cars break down. And as a bonus, we get to sit comfortably in air-conditioned rooms and spend a good chunk of our day thinking about things we actually take some enjoyment from.

None of this is true for the “underclass” mentioned above who have little to look forward to each day; the labor they provide is in various amounts boring/tedious/demeaning/physical, and doesn’t pay enough to give them the middle class lifestyle they feel entitled to (e.g. home ownership, healthcare, etc).

I and many people I know have gone through job searches over the last 18 months. Yes, it was more work than we’ve come to expect over the last 10 years. But ultimately everyone I know has landed on their feet. As an industry we are still incredibly privileged compared to most.

Not as I understand it. When I've seen this discussed, a "logout requirement" has usually meant some stakeholder thinks they need a way to prevent previously issued access tokens from being used even though the tokens are signed by the trusted authorization server and not expired (i.e. still valid). This requirement asks that you find a way to instantly shut off access even though the auth server has previously issued access tokens that should entitle the bearer to perform actions against protected resources until the token expires.

Blocking refresh in the authorization server is trivial, but trying to implement the same on access tokens in the resource server at the point of use breaks the entire security model of JWT. It's unreliable, because now every resource server has to take on partial responsibility for authorization which multiplies opportunities for mistakes. As the OP points out, you need to keep track of some sort of block list and lose out on many of the benefits of JWT (i.e. a resource server being able to rely fully on claims in a signed token before allowing an action).

When people show up with this kind of requirement, in my experience, it is often because they foolishly configured a client with a very long expiration on access tokens (e.g. ~months/years instead of ~minutes/hours). This creates a problem when some aspect of a user's access needs to change (e.g. disgruntled employee was fired, customer didn't pay their bill, etc). You can address this more easily by pairing a short access token lifetime with a long refresh token lifetime.

The more confidently people make blanket pronouncements, the less you should believe them. There are a lot of use cases for OAuth2 and OIDC that are not covered by “just use a web session”.

The real thing to push back on is the logout requirement. Everyone pretends they need this, when what almost everyone should do is just mandate appropriately short token lifetimes and revoke refresh tokens as needed.

I don't think this specifically is a great example of "being mean", but in the broader ecosystem it's definitely a problem that can wear down maintainers over time. I think it boils down to a widespread sense of entitlement from users of free software. It's amazing the demanding and disrespectful things people will say when the project you've shared with them, for free, doesn't meet their exact needs or preferences.

If something is provided free of charge and it's not working for you, there are constructive ways to engage and help nudge a project in a beneficial direction. But if you're not up to doing that, just move on.

It’s basically impossible to rent a place worth living in Boston without paying a broker fee. Even the listings you find yourself on craigslist won’t rent to you unless you pony up the fee.

When I rented a place in Cambridge in 2019, the rent was $3200/month. To get the lease signed I had to write a check for 4x that amount (first+last+security deposit+broker fee). $12,800 before even dealing with any moving costs.

The worst thing about it is that it increases the cost of moving very significantly. So people are coerced into accepting large rent increases as long as the increase is less than forking out another broker fee to move to a cheaper apartment.

Could be, I'm not really old enough to remember how linear TV dealt with new television series. Perhaps it is mainly a problem of perception. When you turn on the hotel TV and see a Law & Order rerun playing for the umpeenth time you aren't really thinking about all the other shows that never got beyond a pilot because they couldn't outperform a juggernaut like Law & Order and earn a slot in the schedule.

The way Netflix seems to drive every season into a cliffhanger ending and then cancel seems pretty short-sighted though. If they just let stories be a little more self-contained, then these one-season shows (dare I say "miniseries"?) would accumulate into a catalog of stories that are actually worth a damn for the audiences that find them later. Every piece of content in the library that they don't have to pay to license can earn back an ROI from a niche audience over a much longer period of time since they don't have to optimize the limited number of hours in the schedule like linear TV.

I think there is an emotional difference also that plays a role here. With traditional TV, people I think were maybe more accustomed to the idea of "you get what you get". Don't like what's on? You can change the channel, but you can't pick out exactly what you want, so you have to get used to settling for "good enough". So you leave Law & Order playing in the background even if, really, police procedurals aren't something that inspire passion in you. But with streaming, there is the illusion of infinite choice. The magic of it is getting exactly what you want exactly when you want it, and the magic fizzles the moment the thing you like and very much want to continue watching gets unceremoniously cancelled. It feels like having a choice taken away.

a graveyard of prematurely canceled originals

This is the crux of the issue for me. I lost interest in even trying new Netflix shows because they developed a reputation for cancelling lots of good, not great, shows with loyal followings because they weren't pulling in blockbuster viewership numbers on the level of Stranger Things. This spray and pray strategy is fundamentally disrespectful to the audience.

I find this difficult to believe; no matter how small your camera is, photography is about light. Art reproduction photography is surprisingly hard to do if you care about the quality of the end result. Unless you can surreptitiously smuggle in a studio lighting setup, tripod, and color checker card… sure you can take an image in secret, but not one that is a good representation of the real thing.

I tend to agree. There’s too much room for subjectivity in this definition for it to be a useful statistic. Physical violence is relatively unambiguous and severe, but these emotional/verbal boundaries have no clear definition. My mother got insulted the other day when I added mayo to a sandwich she made for me because she finds it distasteful.

While verbal and emotional abuse are absolutely real, there are many parts of aging that inherently feel undignified. Are they really being talked down to or insulted in all these cases, or are they just being made to hear something they don’t want to hear? Like, grandpa, we love you but it’s best for everyone if you stop driving now. Mom, stay out of my bedroom (I’m an adult now and this is my house).

Of the people I know who got laid off in the last year, pretty much everyone got a job after seriously pursuing one for 3 or 4 months. By seriously pursuing I mean preparing, applying, networking, and interviewing for >20 hours per week. If you aren’t talking to people in your network to find warm leads and obtain referrals and introductions, you’re doing it wrong.

Things seem toughest for the very young. If you have <2 years of experience and get laid off, you are neither new nor experienced. That seems like a tough sell. Companies have a pipeline of new grads for junior roles and are hesitant to give bigger titles to people that are still relatively inexperienced. This goes double for anyone afflicted with imposter syndrome and unable to tell the story of their experience with a bit of salesmanship.

Also, even though more experienced folk are in great demand in general, finding the right role that aligns your interests and expertise with what a company needs and values is still a lot of work. You may be awesome, but you aren’t as interchangeable as somebody with say 4-8 years of experience. For leadership roles (staff+) hiring managers can get very picky and specific about what they want to see.

It’s best not to get discouraged by this but just recognize the rejections as a necessary step in the process.

I suppose part of the challenge here is that music and video content holds value much longer. Studios can invest in music and video content and see a return from the catalog over a long period of time as more enduring hits are produced and the duds fall away. But with news, they have to make the money on it now because yesterday’s news isn’t worth much no matter how expertly crafted.

While I'm not against security and 2FA in general, making PyPI 2FA mandatory ahead of any kind of org support is a major pain for big projects with more than one maintainer. This week I was forced to link my company's pypi account to a personal device to unblock our latest release and now none of the dozen other maintainers I work with can get access. Things will get spicy if someone in my position were to die, leave the company on bad terms, etc and a big project can no longer be managed.

PyPI announced orgs back in April, but it seems they still haven't figured out the details on pricing, etc. No telling when those will roll out, but I sure hope it's soon. I'm cynical, but the sequencing of work here very much feels like somebody at Google (or wherever) wanted to push a big open source security project to advance their personal promo case rather than thinking through the needs of serious project maintainers.

I had the same experience in a big building. I basically rendered my own kitchen unsafe for human food preparation with all the poisons I tried, but still it hardly made a dent because there was a near infinite population of german cockroaches waiting to recolonize my unit from the walls and surrounding units.

If your time is so valuable, why are you spending it creating throwaway accounts just to hate on somebody else's content? If you don't like it, just move on. You're not adding anything to the conversation here.

I don't know about Rolexes specifically, but there is definitely a male subculture of people obsessed with watches who will be impressed by somebody sporting the right bling. I'm not into it, but I can see why many people are given they roll art, engineering, collecting, and conspicuous display of power/wealth all into one.

Having worked with a huge Jenkins deployment at a large company somewhat recently (>10,000 jobs), I found it worked okay enough that company leadership never felt it was worth the pain if switching. But all the friction points added up to a system that was rarely touched by anyone who hadn’t learned where all the bodies were buried. Over time that meant as an engineering org we were underinvesting in CI; there was a lot of quality-oriented stuff beyond unit testing that never got implemented in CI because the typical dev was unaware of how to change it or fearful about trying to change it. The relative accessibility of Github Actions (and other config as code alternatives) transforms the average dev’s relationship to CI from consumer to owner/developer/maintainer, and I think that is extremely worthwhile even if these tools bring some new problems of their own.

Familysearch took down a photo of my grandparents because it they were kissing. It is the only picture I have of that grandfather, but they say no PDA of any kind allowed so I guess his appearance will just be lost to history. Pretty weird if you ask me that they treat a peck on the cheek the same way they handle full nudity / porn / etc.

The OP seems to think we should approach cover letters with the same care as if we were writing the great American novel. I disagree. They are meant to be somewhat canned, but a good one will efficiently direct the reviewers attention to the parts of your resume which are most relevant to the job and give the impression that you are specifically interested in the role. This is a task generative AI can accomplish with appropriate direction.

Obviously a generic prompt is going to get a generic response, but if you put in the work to create a prompt with adequate context and descriptions of what you specifically want then I've seen it produce output that is a reasonably good starting place. If you don't want it using overly flowery, weirdly deferential language and copying specific phrases from the job description then you can address that by including those instructions in the prompt: "Be concise. Use a confident and conversational tone, and avoid using specific phrases from the job description."

The problem is most people aren't going to spend 20-30 minutes creating a really customized prompt. But people who can't write a good prompt probably also weren't going to handcraft a great letter either. Mainly because of the investment of time it requires to create a fully bespoke piece of writing by hand for each place you want to apply.

Another thing I want to mention is that it seems that many people don't realize yet that if you don't like the initial output you can give feedback and ask for revisions. E.g. "Can you make it shorter", "Eliminate flowery adjectives", etc or even just "Can you show me some different variations of this letter?"

If you're writing a lot of these, it's worth putting in 20 minutes or so to make a prompt that creates output that doesn't suck but which you can easily reuse for other companies and roles with minor tweaks.

Most of my frustrations with GHA arise when doing something useful conflicts with someone’s idea of security. For example, branch protection rules intended to stop devs from yoloing commits blocking me from pushing a version bump commit during a release workflow.

The parent post is referring to the "golden parachute" execs are entitled to when fired by new ownership in situations like this. This is different from getting the $54.20 for shareholders. The purpose of these payments are to help align the incentives of leadership with shareholders so they cooperate in getting these complex deals closed.

I also haven't heard any updates.

The cold weather performance is significantly worse, and as somebody who lives in a region with snowy winters I'm tired of the way environmental activists and car manufacturers both seem to be on the same page about pretending this isn't a problem. It also masks a big part of the cost of ownership, since in winter you need to charge a lot more often to drive the same distance as in warmer months. People can plan for shorter range, but they need to know what to realistically expect so they don't end up stranded on the side of the road in winter (this has happened to people I know). I plan to keep at least one ICE vehicle for longer trips and winter use until they are outlawed or we see a revolution in energy tech that makes this a non-issue.