Hacker Newsnew | past | comments | ask | show | jobs | submit | reffaelwallen's commentslogin

At my company we only use UUIDs as PKs.

Main reason I use it is the German Tank problem: https://en.wikipedia.org/wiki/German_tank_problem

(tl;dr; prevent someone from counting how many records you have in that table)


What stops you from having another uuid field as publicly visible identifier (which is only a concern for a minority of your tables).

This way you avoid most of the issues highlighted in this article, without compromising your confidential data.


I'm new to the security side of things; I can understand that leaking any information about the backend is no bueno, but why specifically is table size an issue?

In my old company new joiners are assigned an monotonic number as id in tech. GitHub profile url reflected that.

Someone may or may not have used the pattern to get to know the attrition rate through running a simple script every month))


This was a great read, thank you for sharing!

Appreciate it!

How come Plain looks so much like Django?


Because it's a fork


It's a fork of Django. It says clearly on the docs.


It's a fork of Django.


Third sentence on the page.

Third sentence.


I usually click through to the repo, and it isn't in the README for some reason. I don't blame GP for missing it. https://github.com/dropseed/plain

Of course, GP would've noticed it's like Django on the web page. The screenshot containing Django-like example code is above the fold, though - the Django mention is below the fold.


Logo reminds me of the old slack logo


We use https://www.lindy.ai/. I wonder why it's not on the map; I thought it was widely used.


lindy is voice activated?


maybe its about allowing you to create your own cloud, not using a third party vendor's software? its not a computer you hook up to a cloud, it is its own cloud? i only know about aws outpost tho, so I might be wrong


> "not using a third party vendor's software"

Wouldn't you still be using 3rd party vendor software, it'd be Oxide software now?


Please add sustain pedal as well, you will get 10x positive reactions


We have the sustain pedal implemented in the standalone MuJoCo simulation, e.g. see https://www.youtube.com/watch?v=VBFn_Gg0yD8. I just couldn't figure out how to do it with Tone.js :(


I feel like the sustain pedal is to the piano what the beauty filter is to facebook.


Impactful to Square?


Maybe, depending on how much of their revenue comes from hardware sales.

Eventually they'll just be an app that runs on the phone, making it significantly easier for a business to signup to use their service.


Square is a different market segment, more of the first year, trendy-but-still-playskool retail merchant setup.


Could you expand how Square is different market segment? I thought POS terminal was one of their primary products.


Square is for small or entry level merchants who may be in their first year and can't afford an actual production grade POS or web integration, stripe is for those who've realized they've reached that point or have encountered Square's limits, and by them moving into the entry level market by supporting this method of transacting with iDevices, I'd say square should be considering their next move.


In what way would you consider merchants to be scale-bifurcated along the card-present/e-commerce line?


At my local farmers market every vendor uses Square to accept payments, but also seems to have iPhones themselves.

With this announcement I can very much see Square being removed from the equation in this small business without fixed store front scenario.


Title is misleading? Could be that the podcast owner removed them?


Why would Joe Rogan remove his own episodes?


cynically, to increase the controversy (I doubt that's what happened though)


Pressure?


When something crazy happens these days, I can't help but think it was a calculated buzz generation tactic.


They need to fix their iOS app also


Please, report any issues to MuseScore devs via GitHub.[0]

[0] https://github.com/musescore/MuseScore/issues


That's not the iOS or Android app. Confusingly, they (who's they, not 100% clear) publish proprietary read-only apps for mobile which are not the same as the main Musescore. Also, the playback at Musescore.com uses some proprietary web tools (built on FLO ones in part I think) which are themselves separate from Musescore the main software.


> Confusingly, they (who's they, not 100% clear) publish proprietary read-only apps for mobile which are not the same as the main Musescore.

If so, report details about those iOS/Android apps to MuseScore devs team on Twitter[0,1]

[0] https://twitter.com/Tantacrul

[1] https://twitter.com/musescore


holy, what industry?


I don't know. They never gave me any training, never told me what the product was or who they were selling it to. It might not seem possible to not know the industry, but I responded to a job ad, so all I knew was the address and the name of the company. I posted a longer version on my website: https://lancebachmeier.com/trivia/bad-job.html


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: