Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jmileham
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
jmileham
5y ago
Just to note that at least once delivery is the best case scenario if you configure Delayed::Job correctly, we just made it impossible to configure otherwise in our fork. The only alternative is at-most-once delivery, which puts you in Side
2.
▲
by
jmileham
5y ago
As you say, looks like redis-raft is capable of solving durability and consistency in a replicated environment as of 2020, which is welcome news: https://jepsen.io/analyses/redis-raft-1b3fbf6 At Betterment we use our O
3.
▲
by
jmileham
9y ago
Because this research exists, there can't possibly be a market for a security product whose threat model might not include a malicious hardware manufacturer?
4.
▲
by
jmileham
9y ago
But explaining something in simple terms is a necessary step to teaching the concept. Only once the concept is understood can you put a name to it and keep climbing the ladder of abstraction. This article doesn't devalue proper termino
5.
▲
by
jmileham
9y ago
> It's really cool hearing what they heard in the studio control room for the final mix. And often surprising. But that's not quite what you're hearing - you're typically hearing what happens after the final mix is sh
6.
▲
by
jmileham
9y ago
As long as there's recorded audio up there, you might as well reproduce it well, and even standard CD-audio goes up beyond 20KHz. Also there's plenty of individual variance in people's hearing. No need to fit to the lowest co
7.
▲
by
jmileham
9y ago
I wonder if there's any effect that in-ear headphones are cheaper to produce but have advantages in accurate low frequency response? Of course all this is confounded by the fact that music will tend to sound best on speakers/headp
8.
▲
by
jmileham
9y ago
I definitely don't see it as hypocritical. Humanely designed systems are thoughtful in where they deploy implicitness. Implicitness can cut down on boilerplate for experts while simultaneously cutting down on confusing minutiae for new
9.
▲
What’s the Best Authorization Framework? None at All
(betterment.com)
3 points
by
jmileham
10y ago
|
0 comments
10.
▲
by
jmileham
10y ago
http://www.nytimes.com/interactive/2015/12/29/world/countrie...
11.
▲
by
jmileham
11y ago
This is a great way to spin not having a query planner as a feature, but I'm glad to have one every day that I write and compose semantic bits of SQL that can and should have different execution plans depending on the context in which
12.
▲
by
jmileham
12y ago
Trite one-liners aside, I think you'll find in practice that some good teams rebase commits on feature branches all the time in order to keep the commit history readable. The implicit contract in that case is that nobody else consider
13.
▲
by
jmileham
12y ago
This works great unless you're rebasing and the commit hash you reference falls out of use. In PR comments that I expect to rebase again before release but for which I don't expect changes earlier in the file I'm referencing
14.
▲
Arms race among online financial advisors gives investors much more, for less
(finance.yahoo.com)
5 points
by
jmileham
12y ago
|
0 comments
15.
▲
by
jmileham
12y ago
I'll take the non-false dichotomy, please. Having enough capacity to meet the streaming demand of your current customers during peak times is a solvable problem that doesn't require a full gigabit for everybody, all the time. The
16.
▲
by
jmileham
12y ago
The decision to push 4k streams certainly would carry repercussions for Netflix both from a storage and transit standpoint, even absent paying interconnect fees to Comcast. As a cable subscriber, I expect that when paying for N Mbps of band
17.
▲
by
jmileham
12y ago
I don't think he'd refute that he'd have more to worry about had he not been lucky enough to be on an unaffected version of OpenSSL. I believe his point was that the use of stunnel to terminate SSL connections mitigates some
18.
▲
by
jmileham
13y ago
Painful how? It sounds like the author was genuinely moved by the game. It has to be a good thing that a AAA console title can have that effect, even if it only took 30-odd years for us to get there.
19.
▲
by
jmileham
13y ago
The description of security by obscurity in this article reads a lot like Kerckhoff's principle, which when employed correctly is actually a virtue. Not to defend cybercrime, but completely covering your tracks (digitally or otherwise
20.
▲
by
jmileham
13y ago
Cool. In the comments from that post, there's another article that traces that inverse square root implementation back even further - almost 20 years back at this point: http://www.beyond3d.com/content/articles&#
21.
▲
by
jmileham
13y ago
One caveat comes to mind about the approach this technique supports. Anonymizing your production data and distributing it to developer laptops is something you should think hard about before doing it, and approach very carefully if you do.
22.
▲
by
jmileham
14y ago
Good point, repeatable read is a pretty useful guarantee, though I would be loathe to give up global integrity constraints. Read committed seems to put a lot of work on the application developer's plate, though, and it's not clear to me wh
23.
▲
by
jmileham
14y ago
In order to reconcile ACID with CAP, this defines a weakened form of ACID to mean whatever-some-databases-currently marketed-as-ACID-compliant-support in order to say that you can still offer effective ACID compliance and still choose CA ov
24.
▲
by
jmileham
14y ago
There's power in the concept of chain of custody. I agree that you don't want to associate negativity with this stuff, but identifying an owner who understands the code and whose job it is to fix or find the right person to fix has huge me
25.
▲
by
jmileham
14y ago
.gitignoring will hurt anybody deploying via git (e.g. heroku) in the absence of some ENV magic. It'd be fine to have the regenerated file checked into each user's repo as long as they have the good sense not to push that repo up to a publ
26.
▲
by
jmileham
14y ago
In this app's case the setup.rb is an ideal candidate for generating a new secret_token (and raising an exception on startup until you've generated a token).
27.
▲
by
jmileham
14y ago
This has a big (but easy to fix) security flaw. Don't deploy this publicly without changing the secret token or else you are effectively publishing your app code for analysis by attackers. https://github.com/SquareSquash/web/blob/master/c
28.
▲
by
jmileham
14y ago
If you're consuming even one third-party XML API using multi_xml, that means you're open to RCE if that API provider is malicious or itself compromised, as well as man in the middle attacks if you're not consuming the API via SSL. Harder to
29.
▲
by
jmileham
14y ago
Actually paperclip doesn't rely on HTTParty, but def check out your Gemfile.lock anyway -- it's a pretty common library dependency.
30.
▲
by
jmileham
14y ago
ImpulseSave (TechStars Boston Fall 2012) is looking for a senior full-stack engineer Cambridge, MA ImpulseSave is reinventing the way people save money by making saving as easy and rewarding as spending (we think of ourselves as the anti-ma
More ›