HN user

lol768

5,080 karma

[ my public key: https://keybase.io/lol768; my proof: https://keybase.io/lol768/sigs/usirCkduUZATP9tnCZ31ABcanzQ24kzt_MxDbZx2DIE ]

GitHub: https://github.com/lol768

Posts15
Comments1,040
View on HN

If you have a decent IDE, it'll offer you the ability to swap between the "old" and newer way of doing things when you encounter code written in one of the styles.

I can't say I've had any issues getting code using the new syntax through code review though. C# 14 has been out long enough that the team is familiar with much of it, and the IDE is helpful at reminding you to consider adopting new syntax. That aside though, the collection expression syntax is pretty familiar for anyone who's ever written e.g. JavaScript.

Because Google has more resources to secure their browser

They've kneecapped ad-blockers, when ad networks are perhaps one of the biggest causes of malware installs/page hijacking/other unwanted behaviour. I'm not sure how you can consider Chrome remotely secure in this light.

Yes; many (Alpine/Debian) containers in K8s on GKE for production rail ticketing infra in the UK.

There's not tons of noise being made because for the most part it all, Just Works and that's fairly boring. Perf, memory usage etc gets better every release. As an ecosystem, I'm pretty happy with it. I reach for other languages for smaller microservices.

The alternative would be that each school develop their own platform for this

I worked at a university which did exactly this, in the UK.

It was a bespoke platform which integrated incredibly well with the rest of the systems the university used because it was designed from the ground-up to meet the institution's needs, there were regular user groups involving academics to understand what features needed to be built/worked on etc. At one point it was all OSS on GitHub too, in case other universities could've found it useful. It handled plagiarism detection (integrating with Turnitin), marking, exam grids, coursework submissions and feedback, seminar allocations, personalised timetables & mitigating circumstances.

The in-house dev team was vastly cheaper than anything SaaS would've cost, as well. It also maintained software for on-campus parcel deliveries, online exams, opinion surveys, a mobile app for students/staff, the SSO system, the course catalogue, car parking permits, a content management system and more.

They already prevent advertising the sorts of foods that contribute to obesity to children, and encourage you to drink less sugary drinks by applying tax to them (though unfortunately manufacturers have responded to this by reducing choice and adding artificial sweeteners instead of selling something at a higher price that can be enjoyed once every few weeks.

I don't think any of this is unreasonable in a country that picks up the tab through both subsidised dental care and completely free-at-point-of-use healthcare.

They're great for big business at scale

They are wonderful for big business

I (sadly) completely disagree with this. There are still so many basic things they don't expose, and it feels like you're fighting an abstraction designed for a start-up that doesn't want to think about the complexities of payments at all. For example, you have to fight a battle to get the card IIN exposed to you. There's no way to see the electronicCommerceIndicator (ECI) for Wallet payments (it clearly has it, since it's shown in the dashboard if you dig deep enough, but it's kept from you). For their Direct Debit integration, they apply limits on the payment amounts you can initiate, but there's no way to actually see the current value of what these limits are. The same Direct Debit integration also doesn't let you customise the payment references used (GoCardless lets you do this to identify e.g. individual invoices on customer bank statements).

Some of the APIs clearly haven't been thought through - e.g. for disputes you can't programmatically retrieve the evidence submitted by the card issuer. Which means you can't build any sort of sensible custom integration for handling disputes. And besides, they don't even support pre-arbitration (which the card issuers know about and take advantage of frequently because they know their decisions outwith the card scheme chargeback guidelines cannot be challenged effectively).

Their Google Wallet integration is worse that Braintree's and doesn't support the web-based flow.

There's not nearly enough visibility when things go wrong, particularly with their 3DS integration (which was failing for Samsung Internet browser users for us, and we had to fight to get looked at - nothing ever got published on the status page despite the fact this significantly affected your chances of securing liability shift) and you have to escalate via an account manager to get any sort of useful support case response.

One of the first things I did when I was involved in the set-up of online support ticket system for a GB rail retailer was https://xkcd.com/806/ compliance. If the support request body contains the phrase "Shibboleet" the ticket will be assigned to an engineer.

Equally it's not hard to teach front-line when to escalate, and ensure L2 and beyond are approachable. Even better if L2/L3 can keep half an eye on tickets that come in for anything that looks particularly interesting.

Consent-O-Matic 6 months ago

I've found it to happen much more frequently than that, unfortunately. Usually it's because the modal is two DOM elements - a backdrop, that fades out the rest of the content and sits on top of it/prevents interaction; and the actual consent modal. Websites then use various mechanisms to prevent scrolling. uBlock is often only removing the actual dialog, so you end up with a page you can't scroll up or down and can't interact with.

If you're going to turn the filters on, it's worth being aware of this because it's far from flawless.

GitHub Incident 6 months ago

Jeez, what a mess. Some of those issues have over 5000 events on them.

I really hope that didn't send emails out to people.

This looks very cool, some immediate thoughts though:

- "TiXL is an open source software to create realtime motion graphics" - pedantry, but software is an uncountable noun. You cannot have a software.

- It wasn't immediately clear to me from the homepage that it's Windows-only. Appreciate it appears to behave under WINE, but it'd be good to make clearer.

Plenty of UK banks that don't require this, and whose apps will also work on a rooted device. Monzo will display a warning that sets out the fact there's an increased risk, and then lets you be an adult and choose to continue to use the app if that's what you want to do.

The best part is that the Current Account Switching Service makes it very easy to make the jump from a legacy bank like HSBC.

This is consistent with photo licensing

On the contrary, I would say this is increasingly unusual nowadays. There are print restrictions on e.g. iStock content, but there's no attempt to "ration" the number of visitors that see a stock photo at a specific price point.

It's something that's generally put me off from licensing paid fonts - despite the work that has gone into them, because you're almost signing a blank cheque and it's not easy to know how many visitors are scraping content for LLMs.

We are seeing failures for some git http operations and are investigating

It's not just HTTPS, I can't push via SSH either.

I'm not convinced it's just "some" operations either; every single one I've tried fails.

.NET 10 8 months ago

What is the deal with Ubuntu and this version of .NET?

Every since they got rid of the Microsoft packages feed, it's just been a complete mess.

Ubuntu's own documentation states:

.NET 10 will be available in the Ubuntu archive for Ubuntu 24.04+ and included in main upon its official release

But it isn't available?

The <output> Tag 9 months ago

Update 7 Oct 2025: Some screen readers have been found not to announce updates to the tag

I think you are correct. There were similar issues with Firefox rolling out SameSite=Lax by default, and I think those plans are now indefinitely on hold as a result of the breakage it caused. It's a hard problem to solve.

As an aside it's not clear that OCSP stapling is better than short-lived certs.

I agree this should be the end goal, really.

The ship has very much sailed now with ballot SC63, and this is the result, but I still don't think CRLs are remotely a perfect solution (nor do I think OCSP was unfixable). You run into so many problems with the size of them, the updates not propagating immediately etc. It's just an ugly solution to the problem, that you then have to introduce further hacks (Bloom filters) atop of it all to make the whole mess work. I'm glad that Mozilla have done lots of work in this area with CRLite, but it does all feel like a bodge.

The advantages of OCSP were that you got a real-time understanding of the status of a certificate and you had no need to download large CRLs which become stale very quickly. If you set security.ocsp.require in the browser appropriately then you didn't have any risk of the browser failing open, either. I did that in the browser I was daily-driving for years and can count on one hand the number of times I ran into OCSP responder outages.

The privacy concerns could have been solved through adoption of Must-Staple, and you could then operate the OCSP responders purely for web-servers and folks doing research.

And let's not pretend users aren't already sending all the hostnames they are visiting to their selected DNS server. Why is that somehow okay, but OCSP not?

It's such a shame that what was shipped there was so far off what the designs had suggested might be possible [1]

Two years ago we were told:

We're going to build it right, and that means rewriting large pieces of our codebase. We'll ship the remaining stuff when they are ready.

I'm not sure how much more of the designs have actually been realised since then?

[1] https://news.ycombinator.com/item?id=36664515

In 2023, when tourism rates had yet to fully recover from Covid, over 66 million people visited the US from abroad. I don't have more recent statistics, but I'm going to assume that the number is the same or higher this year.

World Travel & Tourism Council says international visitor spending is going to drop by $12.5bn this year (down 22.5%).

How have you found the generation performance? It seems like this should really be a perfect fit for this sort of use-case, and I'd hope the memory footprint and speed are all much more competitive than HTML-based approaches.

The team I'm currently working with are using Gotenberg for things which we can afford to take a little while, and C#/Skia for things which need to be reasonably quick.