HN user

v3xro

152 karma
Posts0
Comments53
View on HN
No posts found.

I think I'm mostly just mourning the fact that I got to do my hobby as a career for the past 15 years, but that’s ending. I can still code at home.

It could hardly have been a hobby if people were willing to pay you for it (and good rates too)?

I will rephrase it like this - the market has shifted away from providing value to the customers of said companies to pumping itself instead and it does not need to employ people for that. Simple as.

No, you outsource it because it's not your core competency. I think humans should be able to do anything and not narrowly specialise as narrow specialisation leads to tunnel vision. Sometimes you need to outsource to someone because of legal reasons (and rightly so, mostly because the complexities involved do require someone who is a professional in that area). Can some things be simplified? Of course they can, and there are many barriers that prevent such simplification. But it's absolutely insane to say - nah, we don't need to think at all, and something else can do all the work.

The only way I see out of this crisis (yes I'm not on the token-using side of this) is strict liability for companies making software products (just like in the physical world). Then it doesn't matter if the token-generator spits out code or a software engineer spits out code - the company's incentives are aligned such that if something breaks it's on them to fix it and sort out any externalities caused. This will probably mean no vibe-coded side hustles but I personally am OK with that.

You don't have to 5 months ago

This really resonated with me, thank you for writing it <3

Companies value velocity and new launches and shipping first at all costs because of course they do; it’s table stakes. Speed of delivery is basically the number one corporate value of every organization whether they admit to it or not.

Yeah this one is again one of the causes of where we are today (alongside profit extraction, or perhaps because of it). It used to be the case that you would find companies that would offer quality at a slightly higher price, and people would be more than willing to pay for it. Now the feeling is that this is all marketing driven and there is no 'higher quality' because everyone gave up and went after speed of delivery. And well, as the old saying goes, that's valuable when you're catching fleas.

There's nothing to recover from, what are you even talking about? I'm not a token user (and I can't make predictions about the future and whether it will force me to use token but still). That the industry is collectively having a delusion about what constitutes good software (in all senses of the word - functionality and consequences for society) is clear to see, something I too fear we might never recover from, but I stand quite clearly on the side of people not of corporations hoping to extract more more more.

If I can somehow hate a machine that has basically stopped me from having to write boring boilerplate code, of course others are going to hate it!

Poor author, never tried expressive high-level languages with metaprogramming facilities that do not result in boring and repetitive boilerplate.

What hype? I have and will continue to be anti-BigAI from the very beginning. Until the mechanism is no longer that of a probabilistic model, the data gathering that of massive copyright infringment and the runtime that of a "let us burn more fossil fuels to power as many transistors as we can" I will continue to avoid it without any regrets about missed "productivity" or whatever.

That's not a technical problem though is it? I don't see legal scenarios where unverified machine translation is acceptable - you need to get a certified translator to sign off on any translations and I also don't see how changing that would be a good thing.

What prohibits Google from offering a way to register your long-term app signing key without identity verification, publishing apps that are still verified by their automated tooling and then opting in to the usual denylisting/app store banning methods if those apps are malicious? This identity verification requirement is basically just an easy way for illiberal governments to find ways to crack down on apps they do not like (such as say, ICEBlock or whatever)

Perhaps the focus of the team behind the compiler has changed over the years - but there is still backwards compatibility (via TaSTy), the new syntax changes are not mandatory (for the moment) and when they do become so there will be a fully automatic (and correct) rewrite. There are new libraries exploring "direct style" but you can still use cats-effect or ZIO if you prefer. If anything, Scala has a "too much choice" problem (and kinda a community one).

The AI coding trap 10 months ago

To add to the above - I see a parallel to the "if you are a good and diligent developer there is nothing to stop you from writing secure C code" argument. Which is to say - sure, if you also put in extra effort to avoid all the unsafe bits that lead to use-after-free or race conditions it's also possible to write perfect assembly, but in practice we have found that using memory safe languages leads to a huge reduction of safety bugs in production. I think we will find similarly that not using AI will lead to a huge reduction of bugs in production later on when we have enough data to compare to human-generated systems. If that's a pre-existing bias, then so be it.

There are already hefty fines for owners of businesses where the people are not working "legally". There's a "share code" that employers are supposed to check to verify visas. All the laws and machinery is already there and it does not look particularly high-cost to me.

living at taxpayers' expense

Presumably the form for applying for benefits has a reasonably high bar for identifying the fact that you are in fact legally present in the country? Or how else do you imagine people living at "taxpayer's expense"? Just begging on the streets?

I am sure by now it has been explained by others. But basically - an ID document is like a bearer token that does not need to call a central authority every time it is verified. I am sure there are cases where it is, but a digital token that is linked to location every time it is verified is a quite different thing. Currently in the UK the law states that ultimately only a court can force you to identify yourself - by which time hopefully the purpose for which identification is being done is quite a serious and valid one. Making it cheaper to track people is not exactly a goal worth pursuing in my (not so humble) opinion.

To add to this - there is very rarely in my mind a need for someone to actually identify themselves - there are plenty of examples where it's useful for *audit* purposes to have a record, or to have a role-based credential to be able to do a thing, but *identity*?

But artificial intelligence doesn’t care about optionality. It rewards specificity, domain expertise, and the ability to produce measurable results.

I'm sorry what parallel universe are you living in? My dog produces measurable results regularly, twice a day in fact. This article is a joke.

If you have malware that can read your disk, then you have bigger issues than MFA?

In other words - focus on solving the real issue (ability to give more fine-grained permissions to programs) rather than restricting the ability of users to do what they want with credentials they already have on hardware they control.

What I see is that it's trivial to 'self-host' locally - go buy a product from Synology/QNAP etc. - they have an ecosystem, easy setup, apps, everything. Three issues from my perspective: 1) cost and 2) security+privacy 3) not so easy to integrate networking (visibility from internet side) for things like email hosting.

I can also see it possible to 'self-host' things once you use a cloud where you can do 'confidential computing' stuff aka. the hosting provider does not have access to whatever it is you're running. That functionality is there on the major clouds now (EC2, Azure, GCP) all have the Intel/AMD/Arm TME/SEV/RME stuff implemented but finding it on a device that you can self-host in your little storage cupboard is impossible right now (EPYC 9004 seems to be the lowest available with that technology). At a minimum you want secure boot + attestation + memory encryption if you are not in control of the hardware space itself.

There's Immich https://immich.app/ and https://ente.io/ which are both E2E encrypted and not locked to any ecosystem (besides, e.g. Apple only has E2E encryption when you have Advanced Data Protection enabled, and even then not on shared albums). So those apps are strictly an improvement (and I use them). I also do not have Facebook/Instagram/whatever else people are using that don't care about their own or related people's privacy.

While we can't wish it away we can shun it, educate people why it shouldn't be used, and sabotage efforts to included it in all parts of society.