Viewing profile — insanitybit
insanitybit
HN member- Joined
- Fri, Sep 16, 2022, 4:57 AM UTC
- HN karma
- 4,589
- Public activity
- 1,874 items
- HN profile
- View on Hacker News ↗
About insanitybit
Rapid7 -> Dropbox -> Grapl -> Datadog
Recent public activity
-
comment
Comment #49219465
It's not that companies won't pay for it, it's that it is banned . Legal teams at these companies set the policy.
-
comment
Comment #49219459
The issue is that AGPL is flatly banned at many companies, so now any company that even wants to test this database out is going to have to seek a contract, which they won't.
-
comment
Comment #49219409
People have rapidly adopted far less tested databases when the dbs have claimed to solve real problems.
- comment
-
comment
Comment #49212496
Sure, that seems reasonable enough. I'm pretty skeptical that it will happen, but it's not like it's impossible.
-
comment
Comment #49196218
I'm not debating you at all. I'm asking what the model looks like since you've stated (and I've agreed) that a language model wouldn't work. I think it would make sense to explain …
-
comment
Comment #49192364
And I'm asking you to describe the model.
-
comment
Comment #49192250
It's unclear what you are talking about then. Because the idea of training "ciphertext -> plaintext" for language models is absolutely bonkers, so what are you suggesting?
-
comment
Comment #49191454
I'm referring to the first selection process.
-
comment
Comment #49189960
How much am I expected to charitably interpret the joke? They said "only", I'm taking it at face value because it's obviously intended to be commentary and the obvious implication …
-
comment
Comment #49186092
> No way to prevent this says only package manager where this regularly happens "only"
-
comment
Comment #49185174
Only if the jury believes in nullification, which isn't common. The jury is instructed to follow the law. The selection process asks "even if you think they were right, if it's aga…
-
comment
Comment #49185057
That axiom is clearly false. AI can interact with external systems, which means it is not just compressed knowledge - it has the ability to access new information.
-
comment
Comment #49174152
left-pad is totally irrelevant to this conversation.
-
comment
Comment #49174137
Yes, it has nothing to do with the design of npm (relative to similar languages/ repositories) and everything to do with the popularity.
-
comment
Comment #49174129
I just don't think that this is that unique to javascript, it's absolutely not about npm, and I don't think that this is well supported as a relevant feature that leads to these at…
-
comment
Comment #49172659
Yeah, my point is just that other package managers aren't in a great spot. NPM even lets you separate out "publish" and "release" now where you can publish to the registry but you …
-
comment
Comment #49172258
No build script control though.
-
comment
Comment #49172194
162k vs millions. That's not even getting into package update velocity, authorship, the totally divergent goals, etc. I just think it's utterly pointless to compare.
-
comment
Comment #49171904
Debian's scale for package distribution is tiny and explicitly curated by maintainers. Everything funnels through Debian. The goals are completely different. Debian packages what's…
-
comment
Comment #49171879
I think that's barely meaningful. Which of the compromised packages would have been part of any reasonable stdlib?
-
comment
Comment #49171260
Ruby is worse. crates.io is arguably worse.
-
comment
Comment #49171250
I don't consider these comparable in any way that's worthwhile. The scale and goals are completely different.
-
comment
Comment #49171245
Arguably crates.io is worse. NPM has cooldowns and has for a while, it has had Trusted Publishing for longer, it has human-approved releases that separate CI/CD from actual publish…
-
comment
Comment #49171234
Yep, I'd recommend it.