<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: talkin</title><link>https://news.ycombinator.com/user?id=talkin</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 20 May 2026 19:59:03 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=talkin" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by talkin in "Everything in C is undefined behavior"]]></title><description><![CDATA[
<p>Fixing easy cases makes the list shorter, so enables more focus on harder cases.<p>And it also signals that you actually do want to improve,  just a little bit of boy scout rule goes a long way.</p>
]]></description><pubDate>Wed, 20 May 2026 08:27:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=48204705</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=48204705</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48204705</guid></item><item><title><![CDATA[New comment by talkin in "Schedule tasks on the web"]]></title><description><![CDATA[
<p>> for some reason the industry stubbornly refuses to solve the "cron job as a service" problem for end-users, whether on the web or in the OS.<p>Such a service will always be destroyed by the bell-ends who want to run spam or worse activities.</p>
]]></description><pubDate>Fri, 27 Mar 2026 12:33:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=47541943</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=47541943</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47541943</guid></item><item><title><![CDATA[New comment by talkin in "Shell Tricks That Make Life Easier (and Save Your Sanity)"]]></title><description><![CDATA[
<p>> cd -: The classic channel-flipper. Perfect for toggling back and forth.<p>And not only cd. Gotta love 'git checkout -'</p>
]]></description><pubDate>Thu, 26 Mar 2026 09:02:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=47528130</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=47528130</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47528130</guid></item><item><title><![CDATA[New comment by talkin in "Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised"]]></title><description><![CDATA[
<p>There will always be early adopters.<p>And maybe more importantly: security tools and researchers.</p>
]]></description><pubDate>Wed, 25 Mar 2026 18:37:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=47521393</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=47521393</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47521393</guid></item><item><title><![CDATA[New comment by talkin in "UUID package coming to Go standard library"]]></title><description><![CDATA[
<p>Or even an autoincrement int primary key internally. Depending on your scale and env etc, but still fits enough use cases.</p>
]]></description><pubDate>Sat, 07 Mar 2026 16:14:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=47288904</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=47288904</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47288904</guid></item><item><title><![CDATA[New comment by talkin in "Turn Dependabot off"]]></title><description><![CDATA[
<p>Most regex usage actually doesnt require near infinite backtracking, so limited unless opted in wouldn’t be that weird.</p>
]]></description><pubDate>Sat, 21 Feb 2026 10:44:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=47099466</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=47099466</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47099466</guid></item><item><title><![CDATA[New comment by talkin in "Bugs Apple loves"]]></title><description><![CDATA[
<p>“Intuitive!”</p>
]]></description><pubDate>Fri, 23 Jan 2026 07:37:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=46729603</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=46729603</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46729603</guid></item><item><title><![CDATA[New comment by talkin in "CSRF protection without tokens or hidden form fields"]]></title><description><![CDATA[
<p>NO. Please don’t spread wrong solutions.<p>Your attempt has similarities to the idea behind Checking Sec-Fetch-Site. Implementing that header is the same amount of work. But this header is exactly meant for this purpose, and referer is haunted with problems.<p>So for officially intended protections, implementing this header and samesite cookies gets you a very long way without any complexity, assumptions, or tricks of old lore.</p>
]]></description><pubDate>Thu, 25 Dec 2025 11:43:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=46383812</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=46383812</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46383812</guid></item><item><title><![CDATA[New comment by talkin in "Libxml2's "no security embargoes" policy"]]></title><description><![CDATA[
<p>No. The Regex DoS class of bugs is about infinite backtracking or looping inside the regex engine. Completely isolated component, just hogging CPU inside the regex engine. It may also have ‘DoS’ in its name, but there’s no relation to network (D)DoS attacks.<p>It could still be a security error, but only if all availability errors are for that project. But after triage, the outcome is almost always “user can hang own browser on input which isn’t likely”. And yes, it’s a pity I wrote ‘almost’, which means having to check 99% false alarms.</p>
]]></description><pubDate>Thu, 26 Jun 2025 06:51:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=44384851</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=44384851</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44384851</guid></item><item><title><![CDATA[New comment by talkin in "Base44 sells to Wix for $80M cash"]]></title><description><![CDATA[
<p>Backup/restore tends too look less important until it isn’t. ;)</p>
]]></description><pubDate>Thu, 19 Jun 2025 14:02:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=44318782</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=44318782</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44318782</guid></item><item><title><![CDATA[New comment by talkin in "Getting free internet on a cruise, saving $170"]]></title><description><![CDATA[
<p>Interferes with the business model. ;)</p>
]]></description><pubDate>Mon, 16 Jun 2025 21:37:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=44293640</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=44293640</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44293640</guid></item><item><title><![CDATA[New comment by talkin in "Tesla sales dropped 60% in Germany"]]></title><description><![CDATA[
<p>> Well, I don't think most folks could name a CEO of another car company.<p>Yup, and I don’t care. I liked the brand better without the drama queen.</p>
]]></description><pubDate>Wed, 12 Feb 2025 22:03:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=43030229</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=43030229</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43030229</guid></item><item><title><![CDATA[New comment by talkin in "Mad at Meta? Don't Let Them Collect and Monetize Your Personal Data"]]></title><description><![CDATA[
<p>Spreading the message inside FB helps the mission. The people who already stopped don’t need to be convinced anymore. ;)<p>But sure, ironic and counterintuitive.</p>
]]></description><pubDate>Fri, 07 Feb 2025 11:50:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=42971587</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=42971587</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42971587</guid></item><item><title><![CDATA[New comment by talkin in "A story on home server security"]]></title><description><![CDATA[
<p>Nobody said you shouldn’t do any due diligence. But 1 sprint vs 2 months of review really smells like ‘processes over people’. ;)</p>
]]></description><pubDate>Sun, 05 Jan 2025 17:23:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=42603285</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=42603285</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42603285</guid></item><item><title><![CDATA[New comment by talkin in "Redis is trying to take over the all of the OSS Redis libraries"]]></title><description><![CDATA[
<p>All true, but lets be honest: For the technical users searching a library, nothing beats having The Keyword being part of the name.</p>
]]></description><pubDate>Tue, 26 Nov 2024 11:42:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=42244841</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=42244841</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42244841</guid></item><item><title><![CDATA[New comment by talkin in "Upcoming Hardening in PHP"]]></title><description><![CDATA[
<p>Yes. Just like the Log4j issue root cause. Too powerful and abstract features to wield securely.<p>Or maybe if we keep intent out of it; features were added in a time when we all worried less about security and internet implications.
I would like to say ‘in the security dark ages’ but we are probably still in that era. ;)</p>
]]></description><pubDate>Fri, 15 Nov 2024 12:45:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=42146401</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=42146401</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42146401</guid></item><item><title><![CDATA[New comment by talkin in "Upcoming Hardening in PHP"]]></title><description><![CDATA[
<p>This comment and all siblings fight over PHP vs Pyhton etc, but that just isn’t the bottleneck in most apps.<p>By far, for most apps, the biggest bottleneck is the database.</p>
]]></description><pubDate>Fri, 15 Nov 2024 12:39:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=42146357</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=42146357</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42146357</guid></item><item><title><![CDATA[New comment by talkin in "Upcoming Hardening in PHP"]]></title><description><![CDATA[
<p>To be specific about static analysis: Lots of tools catch this. Sure, making some checks native would be nice, but for instance PHPStan always catches this, and more.<p>Regardless of the ‘improve the language angle’: Is somebody isn’t running PHPStan (or Psalm, Sonar, etc), then they’re missing out.<p>PHPStan is currently so good that using it should be non-negiotable. So the question would then even be: “I’d like rule 123 of the tool to be native, we helps with the RFC?”</p>
]]></description><pubDate>Fri, 15 Nov 2024 12:34:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=42146325</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=42146325</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42146325</guid></item><item><title><![CDATA[New comment by talkin in "HTML Form Validation is underused"]]></title><description><![CDATA[
<p>You’re technically right but that doesn’t matter.<p>That you’re correctly using html forms won’t quickly lead to browser improvements.. so the result is that users will hate your forms.
Users/your customer might possibly even think that you’re to blame, and not $browserVendor.</p>
]]></description><pubDate>Tue, 29 Oct 2024 07:31:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=41980377</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=41980377</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41980377</guid></item><item><title><![CDATA[New comment by talkin in "Chromium uses web search for .internal TLD instead of opening URL"]]></title><description><![CDATA[
<p>> I think it's the autocomplete in particular that leaks a lot of private data.<p>That’s the beauty. The whole unified input can be presented as a UX simplicity gain, while this quote points at the actual business value. ;)</p>
]]></description><pubDate>Thu, 24 Oct 2024 06:52:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=41932694</link><dc:creator>talkin</dc:creator><comments>https://news.ycombinator.com/item?id=41932694</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41932694</guid></item></channel></rss>