Viewing profile — carols10cents
carols10cents
HN member- Joined
- Wed, Oct 27, 2010, 2:19 PM UTC
- HN karma
- 594
- Public activity
- 179 items
- HN profile
- View on Hacker News ↗
About carols10cents
Recent public activity
-
comment
Comment #48505725
How does a user become a Trusted User? Who is paying them to review everything?
-
comment
Comment #47632402
If you're writing the tests after writing the code, you're not doing TDD though.
-
comment
Comment #45279111
Since Shai-Hulud scanned maintainers' computers, if the signing key was stored there too (without a password), couldn't the attackers have published signed packages? That is, how d…
-
comment
Comment #45223855
Yeah, npm has orders of magnitude more users than crates.io. This attack's success, or lack thereof, has no bearing on the savviness of JavaScript or Rust developers.
-
comment
Comment #45047871
So why are you upgrading?
-
comment
Comment #45047855
Who is requiring you to use large numbers of transitive dependencies? You can always write all the code yourself instead.
-
comment
Comment #44130340
Why wouldn't you knit a chicken???
-
comment
Comment #43963347
And the architect is a volunteer for Habitat for Humanity.
-
comment
Comment #43372725
who is going to pay for the review of packages and updates? how do we know we can trust the reviewers? github actions are name-spaced and that didn't help anything here...
-
comment
Comment #41133078
Do not try to equalize a maintainer guarding their time and energy from having to deal with an issue that has already been fixed and users that refuse to search or read with trying…
-
comment
Comment #41131250
No maintainer is obligated to maintain access to a discussion space for their users. > One now doesn't even know and cannot even estimate the number of other issues that must have …
-
comment
Comment #40727100
It's the Charles Anderson Bridge. https://engage.pittsburghpa.gov/charles-anderson-bridge
-
comment
Comment #39907960
What would prevent the sock puppet accounts from signing each others' keys?
-
comment
Comment #39768917
How are these two problems unique to Rust though?
-
comment
Comment #39486736
It looks like accounts can be entirely anonymous. How are you planning on handling moderation of comments? What happens if I post on a neighbor's house "jagoff who lets their dogs …
-
comment
Comment #39389536
Tell me you don't know anyone from Pittsburgh without telling me you don't know anyone from Pittsburgh.
-
comment
Comment #39143104
> these are the folks who do the Lawfare podcast, right? Yep, and they had a podcast episode with the author of this paper: https://www.lawfaremedia.org/article/the-lawfare-podcast…
-
comment
Comment #38880283
I wish Bluey hadn't introduced the concept of a "bush wee" to my kid, I've had to explain that no, we can't pee in someone's yard in the middle of our busy neighborhood...
-
comment
Comment #38028646
Namespaces can't be typosquatted?
-
comment
Comment #38025290
Crates.io has publisher information-- namespacing is not required for that. For example, here are all the crates owned by the `azure` GitHub organization and published by the `azur…
-
comment
Comment #38025253
How do namespaces measurably increase security?
-
comment
Comment #37265465
I'm one of the crates.io team members, and we're very grateful to Phylum for doing this analysis and alerting us! As a volunteer member, I'm also very thankful to the Rust Foundati…
-
comment
Comment #34206443
Making crev part of the official Rust toolchain won't magically make enough time in the day for me to want to volunteer any of it doing code review.
-
comment
Comment #32917415
That's what TideLift's goals are too. https://tidelift.com/
-
comment
Comment #32860655
You're very welcome, I'm glad you like it! <3