Readit News logoReadit News
trulyme commented on pnpm: Fast, disk space efficient package manager for JavaScript   pnpm.io/... · Posted by u/modinfo
5e92cb50239222b · 4 years ago
Containers don't provide much protection from malware, unless you're running it rootless under an unprivileged user (no sudo access, no ssh keys or anything else interesting in the home directory, etc; and even then it's limited because the attack surface is enormous).
trulyme · 4 years ago
I mean, of course? Especially, why would I put ssh keys and similar in the container?

This still doesn't mean that one can install just any package, but it does make it much more difficult for it to do much harm. Breaking out of a container is not as trivial as it once was. That said, it is not a perfect solution, so I'd be happy to hear of better ones. Any suggestions?

trulyme commented on pnpm: Fast, disk space efficient package manager for JavaScript   pnpm.io/... · Posted by u/modinfo
xiphias2 · 4 years ago
As a person who uses npm just for some hobby coding projects, it's quite frustrating that there are new partly incompatible package managers for the javascript ecosystem: npm, pnpm, yarn, yarn 2.

Some packages need one, some another, so I tried to switch to yarn (or yarn 2) for a package that I wanted to try out, but then other packages stopped working.

If there are clearly better algorithms, why not refactor npm and add them in experimental flags to npm and then setting them to default as they mature (with safe switching from one data structure or another)?

trulyme · 4 years ago
Given what a dumpster fire npm ecosystem is security wise, it's best to run the whole build chain in a container anyway, at least for frontend apps. This way you also don't care about the chosen package manager or node.js version - you can just set it as you wish in the Dockerfile. It does take more disk space though, but to me it's a nice compromise.
trulyme commented on FTC sues Intuit for its deceptive TurboTax “free” filing campaign   ftc.gov/news-events/news/... · Posted by u/Kesseki
runako · 4 years ago
> those with non-wage income

This is a lot of people now, thanks to the gig economy. Similarly, farmers plus people who work for tips (at employers that do not centralize tips).

trulyme · 4 years ago
Genuinly curious: do people in US report tips on their tax forms? (forgive my ignorance - tips are much less common around where I live)
trulyme commented on Zulip 5.0: Threaded open-source team chat   blog.zulip.com/2022/03/29... · Posted by u/srijan4
sho_hn · 4 years ago
We used to be on Zoom for video meetings, then it lost favor due to fears of industrial espionage (the encryption crisis, etc.) and via Office 365, Teams snuck up. Initially as a Zoom replacement only for video meetings, too, but lately folks seem to be discovering the other functionality and it's creeping in.

Atlassian (Confluence/JIRA) otherwise.

trulyme · 4 years ago
Not a fan of Zoom myself, just - it seems to be used quite a lot around me. For me Jitsi is king for video conferencing.

Sorry about Jira. :)

trulyme commented on Zulip 5.0: Threaded open-source team chat   blog.zulip.com/2022/03/29... · Posted by u/srijan4
sandermvanvliet · 4 years ago
I might be living in a different Europe than you but from what I see around my Slack is very pervasive and Teams is only used for video meetings because companies are already on office365.

Nothing but hate for the chat/collaboration features…

trulyme · 4 years ago
There seem to be quite a few Europes around. The one I live in uses mostly Zoom, with some Teams, Skype, Slack and even Jitsi thrown in the mix.

Yeah, Teams is the worst of them in every dimension.

trulyme commented on Killed by Microsoft   killedbymicrosoft.info... · Posted by u/sandebert
trulyme · 4 years ago
Lync is getting killed? Nice! Can we please take care of Teams next?

Deleted Comment

trulyme commented on MDN Plus   hacks.mozilla.org/2022/03... · Posted by u/sendilkumarn
hipjiveguy · 4 years ago
I only realized this a bit ago, but the docs of every product are essentially press pieces. They can't really call out "we suck at this", or "product X is way better, use it instead". Only third parties ever do this, so that's what this is so often the case.
trulyme · 4 years ago
OSS actually sometimes does that - here is what we do, and hey, someone else is doing something similar.
trulyme commented on The illusion of evidence based medicine   bmj.com/content/376/bmj.o... · Posted by u/pueblito
cosmotic · 4 years ago
This should not be considered evidence that other quack medicines have any superiority over modern medicine.
trulyme · 4 years ago
True. It is just evidence that sometimes modern medicine doesn't have any superiority over quack medicines either.
trulyme commented on Google “hijacked millions of customers and orders” from restaurants – lawsuit   arstechnica.com/tech-poli... · Posted by u/JaimeThompson
lmkg · 4 years ago
It can't deduct the value of lawsuits until it gets training data.
trulyme · 4 years ago
The data is incoming, no worries.

u/trulyme

KarmaCake day500January 28, 2021View Original