HN user

mik3y

2,119 karma

just a guy who loves building stuff!

write a little at hoho.com

elsewhere: @mik3y

Posts41
Comments155
View on HN
github.com 7mo ago

Uv-outdated: Show outdated packages in your uv projects

mik3y
3pts0
support.stripe.com 2y ago

Changes to Stripe Billing

mik3y
67pts53
ssballiance.org 2y ago

The Small Software Business Alliance

mik3y
1pts0
www.youtube.com 2y ago

How an 18th Century Sailing Battleship Works

mik3y
1pts1
medium.com 2y ago

Open Letter to the Board of Directors of Gitlab Inc

mik3y
4pts1
github.com 2y ago

Generative agents: LLM-driven interactive simulation “inspired by The Sims”

mik3y
5pts1
verticalmag.com 3y ago

Dropped iPad implicated in fatal Rotak Chinook helicopter crash

mik3y
295pts174
github.com 3y ago

Django-spicy-id: “Stripe-style” self-identifying row IDs for Django

mik3y
2pts0
linkml.io 3y ago

LinkML – Linked data modeling language

mik3y
1pts0
www.justice.gov 3y ago

Former Startup CEO Charged in $175M Fraud

mik3y
28pts6
www.youtube.com 3y ago

Gazex Avalanche Control System

mik3y
1pts0
adsb.cool 3y ago

“Awesome ADS-B”: A curated list of ADS-B tools, projects, and so on

mik3y
2pts0
www.npr.org 3y ago

Anatomy of a Bank Takeover (2009)

mik3y
8pts0
magoo.medium.com 3y ago

A blameless post-mortem of USA vs. Joseph Sullivan

mik3y
66pts30
lcamtuf.substack.com 3y ago

Fake Books

mik3y
5pts0
twitter.com 3y ago

macOS is background scanning and following downloaded QR codes?

mik3y
213pts85
twitter.com 3y ago

An InstantNeRF (neural radiance field)

mik3y
1pts0
brickexperimentchannel.wordpress.com 4y ago

Building a radio-controlled submarine with automatic depth control

mik3y
152pts34
medium.ethyca.com 4y ago

Our Mission Patches

mik3y
1pts0
gist.github.com 4y ago

My Heroku Values (2013)

mik3y
1pts1
reddit.com 4y ago

Reddit is being funded by a fake company?

mik3y
125pts97
www.railwayage.com 4y ago

“It Is Getting Worse. People Are Leaving”

mik3y
560pts360
news.ycombinator.com 4y ago

Tell HN: After 3/31, Amazon appstore will not allow updates for older devices

mik3y
1pts0
blog.adafruit.com 4y ago

Thumbing Through a 2022 Estes Print Catalog EstesRockets

mik3y
1pts0
thespaceabove.us 4y ago

The Space Above Us – “A podcast about the history of NASA human spaceflight”

mik3y
2pts3
www.facebook.com 4y ago

San Jose Fire had an impossibly complex incident scene (2019)

mik3y
260pts164
github.com 5y ago

Map of Reddit

mik3y
2pts0
developers.google.com 6y ago

Writing Inclusive Documentation

mik3y
2pts0
gist.github.com 6y ago

My Heroku Values (2013)

mik3y
1pts0
en.wikipedia.org 7y ago

Self-replicating spacecraft

mik3y
2pts0
Om Malik has died 27 days ago

I had a very similar single experience with Om: I was introduced completely randomly while he was at True Ventures; he couldn't have been nicer, more curious, or more genuine despite me almost certainly reading like a total waste of time.

It's both heartwarming, and bitterly sad, to see so many other posters confirm he was one of the good ones.

Layoff announcements are this kinda tricky class of corporate comms where you need to speak to at least 3 different constituents, with 3 different messages, which are often in conflict.

It's something like:

(A) To the public (e.g. prospects, customers, investors): "This is a good thing and we're going to be an even better bet!"

(B) To the remaining team: "This is tough and I feel your pain and will do better."

(C) To the laid off: "It's not you, it's me, thank you and good luck."

It's hard if not impossible to handle all three of these authentically, concisely, and in the same message. Which is why you can almost immediately find something not to like..

Sure: I think you're essentially missing a whole set of concerns - ones that are not purely technical - behind why this method is popular; and so your arguments wouldn't convince someone actually responsible for one of these scripts to change or cease the practice.

Nobody would argue that it's categorically safe/good/smart to blindly pipe a script into your shell; and for the record, I agree. I would also readily agree that habituating users to doing this probably creates new, more general risks especially among how less-technical users interact with their CLI.

However, the realities of the "real world" make it popular for a reason, in light of those negatives; tons of scaled projects continue to offer a 1-liner. So we have to ask, why? They'd probably say that's because it (a) improves project adoption, and (b) reduces "install broken" tickets.

You have to address the non-technical merits and goals to get behavior to change here, and sadly, I don't think anyone has done that.

But who cares about me? I'm not currently maintaining one of these (though I did once). My suggestion to bring your argument to an active project was genuine: try it! I'd be delighted to see you bring about the change you want.

[PS: The commenter I replied to originally used the term "bad faith", which they've since edited]

Bad faith, or perhaps just ignorance. It reminds me of purist junior engineers - and I have been one - refusing to understand or tradeoff in the world beyond their own.

Rather than argue with those of us who are pointing out messy realities, this commenter might be better served filing a bug against any number of the projects that offer installation this way, asking them to remove it, and see if it lands any better.

Technical purity/superiority isn’t the only factor, or even the most important one, driving projects to offer quick installers like this.

The ideas aren't mutually exclusive, and I've never seen an open source project support "curl | sh" without also supporting those methods.

Indeed, plenty of these scripts often act as a "what OS and packager do we have" mux. Just look at the source of this one, for example.

When you support an open source project at scale and/or with less savvy users, you come to see the benefit of "here, just f'ing slam this into your shell and we'll figure it out" installers. I know I have.

I am genuinely curious what it tells you, as "curl https//.. | sh" has long been an enormously popular approach to distribution in the open source world. Homebrew, to name just one example, advertises a similar method.

(pi.sh also documents other install methods, like `npm`, on their homepage)

If trust and security is the issue, unfortunately "better" ideas like hashpipe [1] never achieved critical mass

    [1] https://news.ycombinator.com/item?id=9318286

I really wanted to dislike the anonymous operator for the careless project (and the hilarious pomposity of the IRC subagent it spawned).

Then I imagined the real-but-unknowable chance it was all set up by some kid just getting into computers, just seeing what’s possible, getting excited by a much bigger world at reach — and remembered my own expensive mistakes with long-distance BBSes & the like.

I sorta hope for that, anyway. Curiosity is a beautiful thing.

    > How could it be better?
On a purely language basis, I'd start with the things the BrighterScript [1] folks have done to clean up the warts and inconveniences of the language.

Personally I'd rather it not exist. Roku would be more pleasant to develop on had they chosen a more popular, existing language as the basis (e.g. Python). Then the task of developing for the platform ~mostly reduces from "learn a new language and a new framework" to just the latter.

I suppose it hasn't inhibited their success, of course.

    [1] https://github.com/rokucommunity/brighterscript
[dead] 12 months ago

Yes, seeing periodic 5xx errors (though eventually succeeds).

Interestingly `bun upgrade` catches "GitHubIsDown" as a specific case:

    $ bun upgrade
    Bun v1.2.20 is out! You're on v1.2.18
    Downloading [38003/21788202] Bun upgrade failed with error: GitHubIsDown
    
    Please upgrade manually:
      curl -fsSL https://bun.sh/install | bash
(Appears to have been triggered by a 503 for https://github.com/oven-sh/bun/releases/download/bun-v1.2.20...)

Ugh, you gave me bad flashbacks of the same committee.

I tried to re-license a previously-released project (like from GPL to MIT or similar) and they wouldn't budge. I had written all the code.

In the end, I decided that them suing (or firing) me to assert their ownership of $VALUELESS_PROJECT, so they could then license it back, was ridiculously unlikely, said fuck it, and did it. And I was right.

A very well-written and persuasive critique, thank you for it.

(And god I hope you’re not a state-of-the-art summarization LLM.)

Thought this was going to be an mmWave sensor with an "AirBnB host friendly" UI of some sort.. turns out it's just a network sniffer? Seems.. defeatable.

    > How it Works
    > 
    > Party Squasher uses the presence of mobile phones
    > as a proxy for the presence of people.  You start by
    > connecting our small sensor to your property’s internet
    > router. [...]

I've been interested in doing this as a side project too, ever since "unwiring" my jeep in a similar fashion (rip out modem).

My quick-and-dirty idea was to stand up a Discourse forum with categories for each make, threads for each model (or possibly model + model year range pairs).

If anyone wants to collaborate / provide some extra motivation, hit me up..

Lovely read, and great to see a happy ending - I remember your previous blogs here.

As a sometime-bootstrapper and having failed at a previous hardware startup, I can relate to many of the emotions you narrated through. It may be too early, but my biggest curiosity is whether you think you will bootstrap something again?

(In my case, after the hardware business and some time off, I found that taking a swing at a “pure software” idea was the right balance for me, after the considerable challenges and occasional joys of building physical things..)

    A big problem that came up at the domain level was what I'd call
    a _trustworthy domain with untrustworthy subdomains_, specifically
    where those subdomains represent user-generated content.
The Public Suffix List (PSL) [1] to the rescue! It can help with this kind of disambiguation.

Paraphrasing, it's a list of domains where subdomains should be treated as separate sites (e.g. for cookie purposes). So `blogger.com` on the list means `*.blogger.com` are separate "sites".

[1] https://en.wikipedia.org/wiki/Public_Suffix_List

Berrypatch: https://github.com/berrypatch/berrypatch

The pitch: Want to run stuff on Raspberry Pi, but dread having to remember how to set it all up again when the sdcard fails? Try this homebrew-like interface for common stuff.

Backed by docker + docker-compose + a template system. Not really a package manager but has similar qualities. You can see supported apps at [1].

I've been using it for a couple years to keep by ADS-B system running, but it's half-baked since it never reached any adoption = limited set of packages.

[1] https://github.com/berrypatch/berryfarm/tree/master/apps

Propublica has a nonprofit explorer (similar to Guidestar, but free) and tax filing viewer here: https://projects.propublica.org/nonprofits/organizations/460...

According to their FY2021 990 filing, they had $442k of "other" expenses.

It seems like they're required to disclose what those expenses are on the Schedule O form if they exceed 10% of all expenses, which they do, but I don't see the expenses enumerated there. (edit: oops, now I see)

I am, err, not a tax professional so I stopped here..