<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: neandrake</title><link>https://news.ycombinator.com/user?id=neandrake</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 09 Sep 2026 15:53:12 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=neandrake" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by neandrake in "Getting phpBB 1.4.4 working in Docker"]]></title><description><![CDATA[
<p>I was looking into forum software maybe 10 years ago and came across Flarum. Worth a look<p><a href="https://flarum.org/" rel="nofollow">https://flarum.org/</a></p>
]]></description><pubDate>Wed, 09 Sep 2026 01:47:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=49619771</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=49619771</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49619771</guid></item><item><title><![CDATA[New comment by neandrake in "Paged Out Issue #8 [pdf]"]]></title><description><![CDATA[
<p>Finding this one-page was great! It gave me a new term I didn't have before that leads to all sorts of new materials to go rifling through.</p>
]]></description><pubDate>Thu, 19 Feb 2026 18:02:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=47076838</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=47076838</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47076838</guid></item><item><title><![CDATA[New comment by neandrake in "MongoDB Server Security Update, December 2025"]]></title><description><![CDATA[
<p>>>This [...] vuln is not a breach or compromise of MongoDB<p>>IANAL, but this seems like a pretty strong stance to take? Who exactly are you blaming here?<p>You elide the context that explains it. It's a vulnerability in their MongoDB Server product, not a result of MongoDB the company/services being compromised and secrets leaked.</p>
]]></description><pubDate>Tue, 30 Dec 2025 04:35:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=46429585</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=46429585</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46429585</guid></item><item><title><![CDATA[New comment by neandrake in "Jujutsu worktrees are convenient (2024)"]]></title><description><![CDATA[
<p>Worktrees are useful particularly because they look like entirely separate projects to your IDEs or other project tooling. They are more useful on larger projects with lots of daily commits. If you just use branches then whenever you switch, in the worst case, your IDE has to blow away caches and reconstruct the project layout or build the project fresh. On large projects this takes significant time. But switching your IDE to a different project, there are now two project and build caches to switch between.</p>
]]></description><pubDate>Mon, 08 Dec 2025 17:07:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=46194791</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=46194791</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46194791</guid></item><item><title><![CDATA[New comment by neandrake in "A years-long Turkish alphabet bug in the Kotlin compiler"]]></title><description><![CDATA[
<p>There are OS-level settings for date and unit formats but not all software obeys that, instead falling back to using the default date/unit formats for the selected locale.</p>
]]></description><pubDate>Sun, 12 Oct 2025 22:07:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=45562412</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=45562412</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45562412</guid></item><item><title><![CDATA[New comment by neandrake in "Hypervisor 101 in Rust"]]></title><description><![CDATA[
<p>Render to pdf or ebook to read from an ereader, at least that's what I prefer. I use Instapaper to quickly snag articles while browsing then later use my kobo to sit and read through them.</p>
]]></description><pubDate>Thu, 18 Sep 2025 15:56:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=45291230</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=45291230</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45291230</guid></item><item><title><![CDATA[New comment by neandrake in "Inboxfuscation: Because Rules Are Meant to Be Broken"]]></title><description><![CDATA[
<p>The article presumes the reader is familiar with "malicious inbox rules" and doesn't elaborate or link to further info on it. From what I can find online it seems to be a scenario where an email account has already been compromised somehow and the malicious actor sets up inbox rules to e.g. auto-forward emails to another attacker-controlled email. I assume the intent is to effectively gain access to emails like 2FA and password recovery in the event the target changes their email account password.</p>
]]></description><pubDate>Wed, 17 Sep 2025 02:35:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=45270948</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=45270948</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45270948</guid></item><item><title><![CDATA[New comment by neandrake in "Hardening Firefox – a checklist for improved browser privacy"]]></title><description><![CDATA[
<p>I'm a huge fan of uMatrix too, and have debated getting involved to help revive it.<p>Can you share more information on the bypass you mention?</p>
]]></description><pubDate>Sun, 31 Aug 2025 14:59:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=45083670</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=45083670</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45083670</guid></item><item><title><![CDATA[New comment by neandrake in "Hardening Firefox – a checklist for improved browser privacy"]]></title><description><![CDATA[
<p>Looks like the source to Bitestring's blog is still up, maybe domain registration just lapsed?<p><a href="https://github.com/bitestring/bitestring.github.io/blob/main/posts/2023-03-19-web-fingerprinting-is-worse-than-I-thought.markdown" rel="nofollow">https://github.com/bitestring/bitestring.github.io/blob/main...</a></p>
]]></description><pubDate>Sun, 31 Aug 2025 13:11:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=45082895</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=45082895</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45082895</guid></item><item><title><![CDATA[New comment by neandrake in "Unexpected productivity boost of Rust"]]></title><description><![CDATA[
<p>Thank you, I look forward to watching your presentation.</p>
]]></description><pubDate>Wed, 27 Aug 2025 21:57:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=45045836</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=45045836</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45045836</guid></item><item><title><![CDATA[New comment by neandrake in "Unexpected productivity boost of Rust"]]></title><description><![CDATA[
<p>Rust caught the lock being held across an await boundary, but without further context I'd hedge there's still a concurrency issue there if the solution was to release the lock before the await.<p>Presumably the lock is intended to be used for blocking until the commit is created, which would only be guaranteed after the await. Releasing the lock after submitting the transaction to the database but before getting confirmation that it completed successfully would probably result in further edge cases. I'm unfamiliar with rust's async, but is there a join/select that should be used to block, after which the lock should be unlocked?</p>
]]></description><pubDate>Wed, 27 Aug 2025 21:50:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=45045755</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=45045755</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45045755</guid></item><item><title><![CDATA[New comment by neandrake in "Unexpected productivity boost of Rust"]]></title><description><![CDATA[
<p>Same would be true for any resource that needs cleaned up, right? Referring to stop-polling-future as canceling is probably not good nomenclature. Typically canceling some work requires cleanup, if only to be graceful let alone properly releasing resources.</p>
]]></description><pubDate>Wed, 27 Aug 2025 21:45:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=45045706</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=45045706</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45045706</guid></item><item><title><![CDATA[New comment by neandrake in "How we exploited CodeRabbit: From simple PR to RCE and write access on 1M repos"]]></title><description><![CDATA[
<p>They first disabled rubocop to prevent further exploit, then rotated keys. If they awaited deploying the fix that would mean letting compromised keys remain valid for 9 more hours. According to their response all other tools were already sandboxed.<p>However their response doesn't remediate putting secrets into environment variables in the first place - that is apparently acceptable to them and sets off a red flag for me.</p>
]]></description><pubDate>Wed, 20 Aug 2025 02:59:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=44958271</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=44958271</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44958271</guid></item><item><title><![CDATA[New comment by neandrake in "Jane Street's sneaky retention tactic"]]></title><description><![CDATA[
<p>If your only professional experience is OCaml and you want to look elsewhere for work then your opportunities shrink noticeably. Especially if you're looking for a position that requires experience. It's much more digestible for a company to hire someone out of college and invest in training on tooling. But many companies won't get past the resume if a senior developer has to take more time to on-board.</p>
]]></description><pubDate>Sat, 28 Jun 2025 18:08:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=44406824</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=44406824</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44406824</guid></item><item><title><![CDATA[New comment by neandrake in "Jujutsu (jj), a Git compatible VCS"]]></title><description><![CDATA[
<p>Git’s rerere functionality should address this, right?<p><a href="https://git-scm.com/book/en/v2/Git-Tools-Rerere" rel="nofollow">https://git-scm.com/book/en/v2/Git-Tools-Rerere</a></p>
]]></description><pubDate>Sun, 20 Oct 2024 14:55:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=41895737</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=41895737</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41895737</guid></item><item><title><![CDATA[New comment by neandrake in "Null-Restricted and Nullable Types"]]></title><description><![CDATA[
<p>I don’t even prefer it for indicating that something can return null. In most cases the Option API is more tedious and awkward than a null check and there are existing annotations that can be used to flag nullable return types, for documentation. The only places I’ve found Option to be helpful are where it helps with method composability, or in some  hashmaps as a simple way to distinguish between “lookup not previously tried” vs “lookup resulted in no value” vs “lookup resulted in value” - it’s a hack and looked down upon because the Option value itself is null, but I view it the same as “Boolean” being nullable. As long as the details are encapsulated it’s not too problematic.</p>
]]></description><pubDate>Fri, 02 Aug 2024 10:52:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=41137728</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=41137728</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41137728</guid></item><item><title><![CDATA[New comment by neandrake in "Anti-Cheat Expert: all your pixels are belong to us"]]></title><description><![CDATA[
<p>I mean, the same goes for all crime being a people problem. The anti-cheat keeps honest people honest as they say.</p>
]]></description><pubDate>Tue, 11 Jun 2024 03:08:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=40641846</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=40641846</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40641846</guid></item><item><title><![CDATA[New comment by neandrake in "Ask HN: Founders who offer free/OS and paid SaaS, how do you manage your code?"]]></title><description><![CDATA[
<p>> The technique was called product-line engineering.<p>Thank you for adding this bit of info! We’ve been using this model for a while but I hadn’t come across a label for it. Now knowing this, I’m coming across a ton of great info about managing/sustaining these product families.</p>
]]></description><pubDate>Tue, 14 May 2024 01:43:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=40350776</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=40350776</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40350776</guid></item><item><title><![CDATA[New comment by neandrake in "Ask HN: Which books/resources to understand modern Assembler?"]]></title><description><![CDATA[
<p>I think you misread the original post. They’re referring to LLVM the compiler toolchain, not LLMs.</p>
]]></description><pubDate>Mon, 22 Apr 2024 05:26:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=40111607</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=40111607</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40111607</guid></item><item><title><![CDATA[New comment by neandrake in "Basic Things"]]></title><description><![CDATA[
<p>Great write up. I read through maybe half of the points and skipped to the end, bookmarked to come back and finish later.<p>I’d like if the author could elaborate a bit about the types of projects that influenced these guidelines. Roughly what constitutes a “large” project, were the projects open source, private/commercial, or a mix of both, does web/service platform vs. desktop/local platform have an impact on these, etc.</p>
]]></description><pubDate>Sat, 30 Mar 2024 16:00:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=39876081</link><dc:creator>neandrake</dc:creator><comments>https://news.ycombinator.com/item?id=39876081</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39876081</guid></item></channel></rss>