HN user

therealjumbo

131 karma

jlzignego[at]gmail.com

Posts2
Comments99
View on HN

My hot take on a better excel: the two things excel sucks at: version control and syncing. On the backend, separate the data and the logic in the spreadsheet and put each into version control. Then use something like syncthing to share documents with colleagues. You might also need something like bitmessage for initial handshake. Now you have a spreadsheet you can collaborate on in real time over the Internet or LAN without screwing around with a server, a google account, a credit card etc.

There's two more things excel is horrible at: choice of extension language and being able to graduate your spreadsheet into a real program. You fix the extension language by using something like web assembly on the back end, and probably bundle one or more compilers to go from $lang to web assembly in order to be user friendly. Lastly you fix the last problem by virtue of doing all of the above. The second two features won't draw in new users much, so they're less important in the short run but make it a lot more sticky.

I'm not in a place in life to put much free time into that project, and ideas are cheap ...

Here's his central point:

This event is significant because it is major demonstration of someone giving a LLM a set of instructions and the results being totally not at all what they predicted.

Replace LLM with computer in that sentence, is it still novel? Laughably far from it, unexpected results are one of the defining features of moderately complex software programs going all the way back to the first person to program a computer. Some of the results are unexpected, but a lot are not, because it's literally doing what the prompt injection tells it to. Which isn't all that surprising but sure anyway...

Obviously it's still very theoretical and can't do anything like that, but the point is more that perhaps Google doesn't have the culture necessarily to truly interrogate their actions.

Oh that's definitely true.

The original reason for banning sales of wild game meat in NA is because species were being driven extinct or extirpated due to hunting. https://www.grandviewoutdoors.com/big-game-hunting/should-yo...

Unfortunately allowing selling of specific species we don't like that reproduce easily would probably just lead to private land owners promoting habitat and food for that species on their land. That's what's happened in Texas on a lot of private ranches due to the popularity of pig hunting. Texas is mostly private land, unlike Montana which is mostly public but still.

I remember reading about the Delta incident a ways back, here they claim it cost them ~$150 million. https://www.datacenterknowledge.com/archives/2016/09/08/delt...

That's not the article I hoped to find however. I seem to remember there was another article where they hired a investigator/consultant to figure out the price to migrate to the cloud and ensure "this never happens again."

My recollection of that was: their scheduling/ops team is also in the same city (Atlanta GA) as this datacenter, and that teams work was brought to a halt by the datacenter outage. The investigator concluded that Delta would need redundant copies of the ops team or the whole effort of moving the software to the cloud would just be at risk to something happening to the human team all in the same city. That would obviously cost to much money, so Delta decided to skip it.

The black bear population in CA has quadrupled since the state banned black bear hunting with dogs a long time ago.

Nonetheless, the humane society sponsors bills: https://www.themeateater.com/conservation/policy-and-legisla... and petitions: https://www.themeateater.com/conservation/wildlife-managemen... to completely ban bear hunting, claiming that "climate change" has decreased the population. When in reality it has not, the black bear population in CA has exploded, and in particular, the Tahoe area now sees a lot more human conflict with black bears due to their increased population and lack of habitat.

You can further see that the humane society opposes any and all hunting (not just hunting predators and bears) on their own website. Like say hunting whitetail deer, by far the most popular big game animal in the US: https://www.humanesociety.org/resources/what-do-about-deer

This political movement is directly opposed the science based management of wildlife. See the WA spring bear hunt ban: https://www.fieldandstream.com/hunting/washington-spring-bea.... Which was done despite the advice of the state's bioligists.

I think they are simply pointing out that you must kill other animals in order to live. There's no way around it.

If your interested in killing the least amount of animals, why not go hunting and fishing, that almost assuredly kills fewer than industrialized agriculture. I've replaced almoat all beef all year round in our family with deer venison kept year round in a chest freezer.

This isn't necessarily a bad thing, but I think that veganism or vegetarianism for most people is very emotional action. Most of the pop media around it focuses on the cuteness of the animal not on the total number of animals killed. and it's ignoring that like in hunting or ethical farming, the animals have a very full happy life.

As a hunter it's interesting seeing this article on HN and seeing no mention of hunting. Also not a bad thing, it's not part of the culture here, but it's interesting to see that bias in the HN culture.

This should be fixed with a shebang and shellcheck. If your shebang is #!/bin/sh, shellcheck will complain loudly about bash-isms. If production is sh and doesn't have bash, there's quite a few other bash-ism you want to check for. You can run shellcheck in CI to check your scripts and return non-zero if they aren't clean, and you can force off warnings for lines that are ok.

EDIT: I should have said, "could be fixed once and for all", "should" is just my opinion.

This is laughable. So poking fun at a projects cost overruns and failures is actually the reason for the failure in the first place? I guess then Jon Stewart is responsible for the failures of the Bush administration then?

Why did your project take 2x as long and cost 5x as much? Because somebody on the internet made snarky comments...

No, this is grift, red tape and incompetence. Go look at other cities in the US, they don't have these costs that are anywhere near SF for the same amount of work.

Democrats have a super majority in SF, have a majority in the CA state government, and PG&E is essentially a state (as in CA) controlled corporation. The democrats have had majorities at both the municipal level and the state level for a long time.

PG&E is not the reason for this particular high cost, but if it was it would be the D's fault. And it's squarely a local level problem. And yet you manage to somehow blame republicans at a federal level...

Why don't you demand some responsibility from your local politicians instead of blaming a caricature of the other party? If PG&E was at fault here, D's are literally doing what you're mad at the Rs for supposedly doing... Incredible.

Do you have inside knowledge of how the recalls are done? It's a lot more complicated than that: https://www.newyorker.com/magazine/2015/05/04/the-engineers-...

Even to the point where an actual horrific accident doesn't necessarily mean that vehicle is any more dangerous than other vehicles on the road, they just don't have that exact failure mode but do kill people nonetheless.

And no amount of money is going to buy perfect safety either. As always, engineering is all about tradeoffs, no way around it. Car companies have dropped the ball on safety in several cases, but just because somebody died, doesn't mean they did.

Yes they have, just not very often and not without a long political fight and not without strong political leaders to push it forward.

Say what you want about the "system" and the two parties and so on, but we the people send our senators and reps to Congress, and the same is true at the state level. This type of thing would be best done at a state level to show people, particularly those in other states that it can work well.

His argument was that a lot of people being armed leads to regular standoffs. CCW being very common and leading to almost no standoffs over stupid arguments absolutely does address it. I'm ignoring comparing individuals to nation states, which is just silly.

CCW is very common in the US now, CCW holders are less likely to commit crimes than police officers. In general CCW or constitutional carry states don't see big wild west shoutouts at grocery stores so no. People are generally good and honest. Criminals are the exception to that, except they don't really care about whether or not carrying a weapon is illegal.

COINTELPRO was a thing, yes, but now almost all news is manipulated. Then stuff related to those stories was, big difference.

The media has always had to kowtow to some degree to local authority,

Yes, that's what I mean, to what degree? That degree is much greater now than it was in the past, except the one doing the manipulation isn't necessarily the government.

Biased and manipulated news is a spectrum like security. You can find instances of anything in the past of you look hard enough. We are currently in a time of more bias and manipulation than the 60s/70s.

Additionally, pointing out that Facebook lacks any fundamental principles and is just a reed in the wind is a great observation.

The equivalent comparison with init scripts would be all the documentation and complexity of every program invoked by the init scripts, not just by sysvinit or rc's documentation and complexity directly. systemd just has most of that built in. And if you're using socket units, the order of what order to start things is essentially outsourced to the kernel, so that's a bit of a simplification.

Try building and maintaining a linux distro without systemd, especially for a large organization that needs to write their own init scripts. And especially when a large number of the devs in that org aren't shell experts, or don't understand the difference between /bin/sh and /bin/bash. And so on.

Here's another example: https://lwn.net/Articles/701549/ before systemd, for complex NFS setups, the sysadmin _had_ to write the init scripts per-site or per-machine. With the solution in the article (systemd generators) one set of unit files shipped by the distro solves the problem for over 99% of users, including most of the aforementioned complex setups.

Some day when I'm rich and bored, I hope to help a distro move in this direction. It'd be really really cool to have a fully, very easily, debuggable and then fixable system where you could debug any running code on the system, and patch it, and recompile and debug again, and decide you like your change, and then push the change as a PR to the distro, in a streamlined process. The distro (like arch) would then help/encourage/nudge you to sending your patch upstream also.

Ubuntu et al, know where their sources come from after all, and how to build each package. I wonder if Arch or gentoo wouldn't be a better fit for this. I do have quite a bit of experience with yocto and buildroot, building distros for embedded systems.

I'm joking about the rich and bored, part. I should just jump in and do it.

And probably https://github.com/pradyunsg/installer https://pypi.org/project/installer/ too, but that one isn't under the pypa org yet, given the author, it probably will be.

All that being said, the deprecations and removals are being done way before the replacements are in place and tested and features/rough edges rounded out, which I guess is python tradition at this point.

IMHO, the repos maintained by pypa should all be part of the core teams responsibility (e.g. pip is maintained by pypa, not core, but its installed as part of the python installer you download from the foundation's website...), along with solving building/installing/packaging/distributing as a whole. But the core team decided their volunteers didn't want to work on that (ok fair) and pypa stepped up to do it, but never really had enough manpower to tackle it well (ok also fair). And none of the tech companies ever thought "gee we rely so heavily on this awesome tool, maybe we should send them some money to keep the lights on..." So instead its just been a giant mess.

I've come to the conclusion that it's a good skill to have since it's (or logging which is basically the same) the only debugging method that's always guaranteed to be available. For example there's lots of build and CI tools out there that have no Real Debugger.

The maintainers of X decided they didn't want to keep maintaining X since it has too much baggage. So they designed/implemented a replacement, Wayland, and have given notice that development on X is going to come to a halt. Unless a different group of maintainers steps forward, but that seems unlikely. So like always, open source is a do-acracy. The people doing the doing, get to make the decisions.

Regardless of "Year of the Linux Desktop" what these maintainers are trying to do in general is minimize their time involvement while making the desktop have the features and support (like for 4K monitors) that people want. Secondly, "the Linux Desktop" isn't a single organization like a commercial entity is. Its a bunch of different groups that all have their own priorities and schedules and use cases and so on. Expecting that process to produce output that is functionally identical to a single commercial entity, is unrealistic.

That isn't just a problem of misaligned incentives, it's more fundamental than that. It's also a problem with how software "construction" tools work at a very basic level. Look around at open source projects, they don't have this perverse incentive, and which of them ship security updates separate from the feature updates?

Nobody does because it causes a combinatorial explosion in code branches, and in testing. This isn't just a problem with the higher level convenience tools like compilers and package managers, its a problem with the actual source code as formulated as it is today. We'd need an entirely different way of writing code in order to do that without a massive increase in programmer/testing hours. Personally I don't think it will ever realistically happen, but I'd love to be proven wrong.

You might want to reconsider holding your breath for that. No they aren't doing E2E encryption, if/when they will, they will announce it. Until they announce something everything else is pure speculation.

I think you have misunderstood the system.

On a technical level I think you're correct. As a holistic approach to the problem, I still disagree. This is too cute for its own good. The PR misunderstanding is a symptom of that.

The second scan applies only for those images which are flagged as positive, which are then accessible by Apple.

In the end, Apples software is scanning all of the images, why is it any more privacy respecting to do it this way? I guess reasonable people can disagree on that, personally I wasn't fully aware of the cloud side scanning either, and I don't think the public was either. This is similar to Snowden's revelations, if you were paying attention you probably already knew a lot of that, but the incident made everyone aware of it in a very blunt way.

The rest of the images stays encrypted

I think this is unclear, Apple can still decrypt those other images, how else could you view them in a browser?

This goes back to what Stratechery said about capability vs policy.