HN user

memorysafety

53 karma
Posts0
Comments34
View on HN
No posts found.

due to some quirk of evolution, Omega-3, -6, and -9 are the ones biological life uses most. As far as I can tell, there's no specific reason they're all multiples of 3. Probably just a coincidence.

This curio bothered me as well. I didn't yet get a fully satisfying explanation for this either.

There's this diagram, showing for example the full pathway of how linoleic acid catabolizes: https://commons.wikimedia.org/wiki/File:Linoleic_acid_beta_o...

It shows dependencies of the process onto several very specific molecular machines we call enzymes.

(main pathway, handling saturated fatty acids)

   ° Acyl CoA dehydrogenase -- removes 2 hydrogens from carbons immediately after the carboxylic head, forming a π-bond (double-bond) between the α-β carbons;
   ° Enoyl CoA hydratase -- adds water as H-OH to that α-β carbons π-bond;
   ° 3-hydroxyacyl CoA dehydrogenase -- converts the added -OH hydroxyl group to =O keto group;
   ° β-ketothiolase -- grabs the two keto groups, and snips off 2 carbons from the chain, carrying them off in bound form as a molecule of acyl-CoA;
(unsaturated side-branch)
   ° Dienoyl CoA reductase -- collapses two neighboring π-bonds into one;
   ° Enoyl CoA isomerase -- converts cis- to trans- variants, making them compatible with Enoyl CoA hydratase. Pathway continues from there.
These, when viewed as a set of combinators, seem perfectly sufficient to metabolize any fatty acid chain. Their chemistry reads pretty straightforward — and it must deal with cis/trans isomerism shenanigans, with neighboring π-bonds, with odd/even parity of the carbon chain. But it apparently handles all that!

Besides catalysis (combustion of the acids for energy), the two other paths for consumed fatty acids are excretion, and laying them into cell walls and membranes. These two paths aren't selective; they mostly don't care about the length of the chain, and where which π-bonds occur in it, if any.

So this must imply, that the "quirk of evolution" lives somewhere on the anabolic (synthesis/production) side of fatty acids; definitely not on the catabolic side.

Idris 2 ruined it for me.

Scientifically, it's cool of course, dependent linear types yaay.

Socially though, incompatible rewrite in Scheme should've been a separate project IMO; but since it's called "Idris 2", community attention faded away from the Haskell implementation "Idris 1". Which caused bad maintenance, neglect, stagnation, of a thing I tried and liked.

CVE scoring is parasocial activity. Hence so much drama.

Similarly to SemVer, the good-faith grader attempts to convey a sizeable blob of knowledge... by compressing it into a one-dimensional number. No matter the scoring formula, this step is lossy.

On the receiving end of this communication, all you can do with the score is add a huge grain of salt to it, then perhaps use to prioritize your review queue. You still must check the details, and work out a judgement tailored to your specific context. There's no other way.

There isn't a choice for the grader either, to skip the obscenely lossy scoring step. Just like with release versions, they must do it, as the audience consists of unbounded number of engineers; faithfully doing it saves mountains of time for everyone involved (present and future).

Just like with dependency upgrades, it's the consumer's choice to disregard CVE scores (version numbers), vulnDB entries (changelogs), or even existence itself of a vulnerability (upgrade). Likewise, it's their fault if consequences arise.

Viewed thusly, can be seen: anecdotes of pointwise drama will continue (even when the bulk of activity chugs along happily, efficiently and quietly) -- because at the core of it, CVE ID's and scores are just that, a communication tool. It mostly can't make strangers exercise care or spend effort more than they're willing to. It can optimise utility of attention that they do pay.

Hey @NamecheapCEO, Ukrainian here. Thanks a lot!

Please notice, there needs to be some sort of verification mechanism. The russians have already figured out that simply setting "Ukraine" in profile data a) works b) might suffice to bypass the upcoming restriction.

I might be a counterexample to your perceived overlap. 3 points:

* It seems that, as a species, we have deep issues rooted in our tribal upbringing. Reaching a global actionable consensus seems as hard (if not harder) as colonizing another planet. The internet only catalyzes the "us vs they" thinking people struggle to get rid of. In one of its many incarnations, it's a nurture of horribly mistaken worldviews — and here I imply climate change denialism, in context. But also flat earth, etc.

* Viewed independently from antropogenic climate change catastrophy -- living on another planet would be extraordinary achievement, would you disagree? Launching a "toy" helicopter is kinda cool, but... living? For some of our greatest ancestors, the coolest achievement has been building millenia-lasting megastructures. Our generations are building fusion testbeds, orbital telescopes & commsat constellations; why wouldn't, say, a giant Earth-shaped globe monument on Mars be great? Perhaps not a globe, yea... but a Statue Of Liberty? Dao temple maybe? A hammer-and-sickle impact crater giga-egraving? Whatever.

* Both viewed together, rationally, Mars colonization is an option to escape extinction on Earth. Not a priority, sure; more like, a backup-of-backup-of-backup plan -- for when all else failed (see point 1). It's not like we can do it soon, either; advance preparations and long practice needed. I won't express any judgement of viability. I do see, however, how ambition and inter-tribe competition can drive this plan to a ready state (see point 2) -- sooner than fossil fuel combustion stops across the world.

I'll cross-post instead of guessing. Another comment here:

URVs were quoted in cruzeiros reais and its intrinsic value was pegged to three price indices and had a fixed parity of 1-to-1 to the daily U.S. dollar exchange rate. [0]

The problem with pegging your currency is that you get a disconnect between the official value and the private value. So introducing this new currency which was pegged, and transferring over only once the disconnect was resolved was the stroke of genius.

[0] https://en.wikipedia.org/wiki/Unidade_real_de_valor

[...] So a quantum computer would be pretty bad for Bitcoin in its current state.

Your reasoning is sound. But it won't be as bad. I'd claim, not much worse than dealing with leap seconds.

For 2 reasons: • Post-Quantum Cryptography exists. • The updated (quantum-resistant) Bitcoin will get renamed back to Bitcoin.

I agree your parent could use a review. I failed to read them any far.

This is exactly my grudge with boilerplate. Code is being read much more often than written.

I don't care if you hand-coded all those buckets of accessors, or your IDE has generated them -- that's irrelevant to that they're still overwhelmingly useless noise. Which I need to read through, which I need to review in PR diffs, skim in "find symbol usage" output, class interface outlines, javadocs, etc etc -- all that 10 as often as during writing. Somehow I'm expected to learn to ignore meaningless code, while producing it is fine?..

Remember the point made in "green languages, brown languages" recent post here on HN? The insight for me there was the source of "rewrite it from scratch" urge which should be very familiar to engineers working in the field. It comes from incomprehensible code or weak code reading skills. Either way, boilerplate does nothing but harm.

So no, while I agree on your point that code exists principally to be read by humans (and as a nice secondary bonus, executed by machines) -- I disagree that boilerplate is "fine" whatever its incarnation. It's not, because it directly damages the primary purpose of code: its readability.

the claim that a lot of people have it turned off is demonstrably false

Not unless you've taken a concrete definition for "a lot of people".

Even 1% of internet users is still a lot of people IMO. Like, on the order of tens of millions, right?.. That's bigger than whole countries.

Also keep in mind how outraging it feels to find yourself in that 1% that someone decided it was fine to ignore and discriminate against the mainstream. We all been there.

I guess you mean The Great Oxygen Extinction Event (2.4-2.0 Ga).

In that case, it's presumed it was indeed a massive extinction (but no data to quantify any % over, due to no microbial fossils preserved).

... But for a different reason. It wasn't due to decrease in oxygen levels; contrary to that. At that time, oxygen was being first ever introduced into the atmosphere. This has left a unique geological trace we observe everywhere across the planet: the white sedimentary + red rust striped 2 Ga rocks.

The "microbes" were the first photosynthesisers. The oxygen was a toxic byproduct. Resistance to it had to be learned by evolution, and that learning took ~1e8 years. Many of life didn't manage to and went extinct.

... which should be taken as a sign of Signal's technical excellence.

Just consider: if you're looking for privacy-respecting, actually secure, reviewed, audited and tested to bone tech -- short of replicating the work yourself, who's assessment can you trust? Perhaps paradoxically, you should foremost trust the unspoken opinions of criminals. Because those people are likely betting their lives and freedoms on the tech choice. Barely any other group will approach such a choice with more vigor.

So, morals aside, that a technology is being used by criminals is actually a compliment to that technology.

You can. It's not even hard to work out: if we take "charging" to mean "buying energy for ₿", then "discharging" ought to mean "buying ₿ for energy".

If you think about it, both of those describe the same economic transaction — just from opposing vantage points (what is "charging" to one party in a transaction, is "discharging" to the other).

Relatedly, consider Switzerland's pumped hydro at Linthal. It'd be hard to dispute calling that plant a "battery" (works on gravity+water); but also consider the economic role it plays: it's an energy price arbitrage facility.

During the night, when grid prices get low, the plant "buys" the energy "for" water volume in the high lake. During the local day, the plant "sells" the water volume back, "for" literal electricity fed back into the grid at a higher price.

... Why have the water?

I didn't say it's unacceptable, neither meant that. In many contexts, it'd be tough without case-insensitive regex matching, for example. Reinforcing my point, //i gains issues once applied to the entirety of Unicode.

It's almost comical: people continue insisting on "letters not code points" knowing very well how computers are bad with guesswork and under-defined notions. Issues stemming from that keep coming up. What if, instead, the norm accepted that 'A' ≠ 'a' and stopped creating problems which computers are known to deal poorly with?

Fair enough. But notice: systems tend to expect that humans interacting with them observe basic rules. "The capital/lowercase variants of western alphabet letters are represented each as distinct character" is one such generic, basic rule with computer systems. Especially if we zoom out of FS's into a broader context (http, json, programming languages, etc) — you can't deny it; it's a fact.

We do have the options to ignore the fact and say "What bytes? I don't care. Guess what I mean, and lie to me as well as you can so I can stay happy in my ignorance" — but, see, coordinating good support for that isn't easy. Minor wrinkles in it continue causing burns, sometimes RCEs. Maybe "doing in Rome as Romans do" isn't such a bad advice after all?

I had exactly that done to me. By a huge 200k+ employees corporate monster... You can taste the humiliation of having to justify every sudo through a ticket system. They censored the internet for employees too, in an of course absurdly broken way. Made me learn to read ASN.1 printouts & detect tampering with TLS certs. Add to that an iconic "Office Space"-ey workplace atmosphere, absolutely toxic... made me _request a headset_ from the company (employees are not allowed to bring their own); 2 weeks of ticketing again, and they deliver: an rj45-plug phone headset, with three obscure boxes on the wire (I can only presume, for surveillance). I've been testing my limits for 3 months with them, and left without saying a word. A lesson is a lesson.

mistakes for no reason

Don't you think that 65 ≠ 97 is sufficient of a reason?..

I mean, 'A' ≠ 'a', in ASCII, Unicode and even EBCDIC. In computers, those are two distinct characters. This fact won't change no matter how you rationalize your expectations.

Thus, pretending that "y.txt" is the same as "Y.txt" is an elaborate lie. Even acknowledging that it's a "white", well-intentioned lie (designed to preserve the mistaken expectation that "y.txt" is the same as "Y.txt") — I don't like when computers lie to me; do you?

As every lie, this one has weird consequences. One of them is the today's RCE in OP. Another one was CVE-2014-9390. Myriads others.

Linux rejects the whole notion of filename case-insensitivity, and demonstrates how computers actually work. It becomes easier on developers and more secure on users.

Lastly, don't feel that I'm attacking you; I'm opposing an idea. So, here's a tip: you can set up case-insensitive filename completion in bash, so that TAB will correct your casing mistakes for you. It's a simply one-line change involving putting `set completion-ignore-case on` into an inputrc.

I find the "Bitcoin burns energy" argument completely laughable. With all due respect, your skepticism appreciated; let me explain.

A more useful perspective is "humanity uses more and more energy for computation". The many devices which enable us to post these comments burn energy. The astronomically high video-traffic these days burns energy. Modelling early universe, protein folding, advanced chemistry... every damn thing we compute has the cost of burning energy.

As an aside, let's not forget how much electricity gets used simply for heating. There's no shortage already of "smart heaters" with a nice side effect of mining you some coins while they keep your house warm. Anything environmentally wrong with that?

See, it's not the endgoal of cryptocurrencies to burn energy; it's simply a cost. Now, thanks to bitcoin, we can have economies of scale drive optimization of that cost: improving the core compute-per-joule ratio of our technology. With all the collateral improvements across the globe with regards to environmental impact.

Could you say that porn distribution industry "kind of by design" lead to people watching more and more porn? Regardless of the answer, thanks to that we can have fast internets now. Similarly with bitcoin: thanks to it, we'll pack more & more bitflips into every joule, up to the thermodynamic limit.

Yes, I'll claim that such programs do exist. But it's rather hard for a human to notice those; beware of survivorship bias.

Having said that, I still support the sentiment that most code is buggy. It's futile to expect pervasive perfection.

Hi Gabriel!

I'm Max @ulidtko, I took over Guake maintenance from Lincoln, did a dozen patches, l10n merges and maybe one release... Together with Pierre we welcomed Gaetan years later.

I'm still using Guake pretty much every day.

It was amazing to contribute, and having burned out from it -- to see the project live on with people continuing contributions & maintenance; and even reaping BountySource rewards for new features! https://github.com/Guake/guake/pull/1415

Really sorry for this situation. It somehow slipped through, I honestly didn't notice it happening. I don't think anyone wished you anything bad, it's just generic inexperience (per the Hanlon's razor).

I, too, remember myself fiddling with copyright lines in translation files. I just had the single goal, to iron out inconsistencies and make adding new l10n's as smooth as possible. Never had intentions to take away credit from noone.

Glad to see you living full life. Sorry again; I'd be among those whose should've noticed and reverted that change. Hope you got a good enough resolution of this issue!

Cheers

Yoda conditions 7 years ago

Look, I'm trying to humanly argue against the statement "Yoda conditions are unnatural". Nature has no boolean conditions. That statement should instead say "Yoda conditions are unfamiliar (to me)" -- at which point it's way easier to see the statement's applicability limits, and dramatically narrow down its consequences.

On the contrary; there're many common contexts where Yoda comparisons looks more "natural", meaning they avoid breaking the surrounding code flow, and bring the important part (the constant) up-front. I even brought up a real-world example. Having read `assert "403 Forbidden" == ` and remembering the context, can't you already guess the RHS (and just skim over it)? Sure you can. Non-yoda loses here.

Be aware: you don't have to take a "for/against" side in this debate, as our buggy brains try to in every flame war. Both sides have a point. Familiarize yourself, and decide on case-by-case basis.

While we're at it: self.assertEqual() is super-ugly and unnatural, in my judgement. Why am I forced to use _thrice_ as much words to express the simple single-word concept of an assert? Why can't I spare the extra pair of parens, and spell == directly? I see nothing wrong with bytecode rewriting; it's amazing they can do it, and I appreciate the effort.

Yoda conditions 7 years ago

So I'm writing a unit test. I bet everyone here can correctly guess the language.

    assert ('Content-Type', 'text/plain') in dupefail.headers
    assert b"registration denied" in dupefail.body
    assert "403 Forbidden" == dupefail.status
I also happen to pay attention to the linter fart^Woutput:
    C: 61,11: Comparison should be dupefail.status == '403 Forbidden' (misplaced-comparison-constant)
I totally admit my thorough hate of pylint, it hasn't really ever helped me once -- mostly led to more `#pylint: disable=…` garbage in the source. I still force myself to use it, as a duty by fellow... other engineers. But that's an aside.

Please, tell me how much more "natural" and "un-ugly" the 3-line snippet would read to you had it the third line assert flipped away from Yoda style, just as pylint suggests. I'm eager to hear you.