Viewing profile — jkrems
jkrems
HN member- Joined
- Tue, Jan 22, 2013, 11:29 PM UTC
- HN karma
- 1,145
- Public activity
- 365 items
- HN profile
- View on Hacker News ↗
About jkrems
No profile information was provided.
Recent public activity
-
comment
Comment #48489721
> I'm constantly thinking about that Microsoft guy who posted something like "we want 1 million LoC per engineer per month", which basically read as satire to most engineers I talk…
-
comment
Comment #46223746
I mean... "as configured" can me either an allow OR a denylist. That sentence doesn't really prescribe doing it one way or the other..? You have to parse the denylisted elements be…
-
comment
Comment #46037025
pnpm is the better comparison maybe in this context. Most of Deno's approach to security is focussed on whole program policies which doesn't do much in this context. Just like pnpm…
-
comment
Comment #46036993
Vendoring wouldn't really affect this at all. If anything it would keep you vulnerable for longer because your vendored copy keeps "working" after the bad package got removed upstr…
-
comment
Comment #46036931
They didn't deploy the code. That's not how this exploit works. They _downloaded_ the code to their machine. And npm's behavior is to implicitly run arbitrary code as part of the d…
-
comment
Comment #45968399
Looks like it's back again!
-
comment
Comment #45269530
Afaict many of these recent supply chain attacks _have_ been detected by scanners. Which ones flew under the radar for an extended period of time? From what I can tell, even a few …
-
comment
Comment #44357286
Nothing to do with "smart", or at least that's mostly irrelevant to this observation. But it's definitely age-dependent. No matter how "smart", it's not fair to expect young childr…
-
comment
Comment #43850187
> Why the South? What about the North? Symmetric globe? The globe isn't symmetric when it comes to these terms. They don't refer to the actual two hemispheres, split at the equator…
-
comment
Comment #43795083
Could this be trivially solved client-side by the editor if it just encoded the slashes, assuming it's HTML or markdown that's stored? Replacing `/etc/hosts` with `/etc/hos…
-
comment
Comment #42732493
> The gap between design and engineering has never been wider. This seems like such a weird claim to make. This used to be "here's a JPEG, you may beg for the PSD". Not saying that…
-
comment
Comment #42511264
Being spec compliant means being compliant with the entire spec, not just a "reasonable subset of the spec", picked by the author of the ponyfill/polyfill. And being secure only in…
-
comment
Comment #41946304
Many (most?) traits require energy to develop and maintain. A stronger muscle will need more energy so there's always pressure to reduce it. That pressure may just be countered by …
-
comment
Comment #41558832
> When doing so, caches SHOULD first normalize request content to remove semantically insignificant differences, thereby improving cache efficiency, by: [...] That part sounds like…
-
comment
Comment #41534061
So you don't use a spam filter in your inbox? You just subscribe to more emails that you _do_ want to drown out the spam? It's easy to say "just counter with more speech!" but it's…
-
comment
Comment #39009171
Apart from the "it just explained the already ordered groups in the question" problem, it didn't even explain one of the groups correctly. "Something about coat(ing) and food" is n…
-
comment
Comment #38252296
If you have a static frontend bundle, isn't that just SSG (static site generation)? And if you can generate the site at build time, what's the fundamental difference between any of…
-
comment
Comment #38233468
The dataset seems pretty unreliable. For example this page claims both that "Kai" isn't a name used in German: https://mixedname.com/name/kai . But then half of the "celebrities na…
-
comment
Comment #37434859
Congrats on 1.0!
-
comment
Comment #36418206
And that article says: > Perl regexes have become a de facto standard, having a rich and powerful set of atomic expressions.
-
comment
Comment #35758870
That's a question of policy, not of repo structure. A monorepo can still have certain parts of the repo protected by access control. One repo doesn't mean "all files share one read…
-
comment
Comment #32027909
What they said was: > in the neighborhood of the difference between the fair current market value (~20B$?) and the purchase price (~44B$). The difference is 24B$ which is implied t…
-
comment
Comment #31886010
Because people generally have elevated rights when it concerns themselves? E.g. I have the right not to be touched and it will (generally) outrank your right to touch me.
-
comment
Comment #31369767
Until very recently it was a thing in all browsers, with a variety of lower bounds depending on which browser. It was meant to prevent accidental busy-loops when developers forgot …
-
comment
Comment #30878543
I think you misread that paragraph. It refers to situations like this: "You selected that you want to jointly apply with another individual. Do *they* live in the same household as…