Hacker Newsnew | past | comments | ask | show | jobs | submit | m90's commentslogin

So how do the recurring airstrikes help the protesters?


Get the guys who got them - they seem cheerful https://x.com/visegrad24/status/2027840034150178952


Easy: decapitate the leadership of the military, IRGC, Basij and let the revolution stand a chance.


Except not, the Iranian revolutionary system is very much designed around the desire to be able to rapidly replace people. The list of targets for a decapitation strike might just be way too long to be feasible.


Kill enough that the rest decides to flee for Moscow rather than risk getting lynched.


Much easier said than done. But hey, perhaps this will be the biggest and greatest air campaign ever.


It's the biggest military buildup since 2003. Kinda looks like they plan on overthrowing the regime. Which would be amazing for world peace considering Iran is building drones for Russia and supporting Hezbollah and Hamas. But we'll see...


> It's the biggest military buildup since 2003. Kinda looks like they plan on overthrowing the regime. Which would be amazing for world peace

Almost as amazing for world peace as when the US overthrew Saddam Hussein's regime and gave birth to the Islamic State.


> considering Iran is building drones for Russia

Not a meaningful supplier anymore, Russia just took the designs and onshored the manufacturing.


Russia is building Shahed derivatives themselves, Iran is not a significant supplier of anything besides the design.


Because historically, we have a fantastic record when it comes to regime change.


Japan and Germany turned out great.


Yeah -- it only took a world war, massive global alliances, and tens of millions of deaths. Also, I’m not sure how political and military competence from about a century ago has any relevance to today.


And a whole lot of fail ever since.


Wouldn't this just make the number of packages that can be targeted smaller? E.g. I publish a testrunner that needs to install Headless Chrome if not present via postinstall. People trust me and put the package on their allowlist. My account gets compromised and a malicious update is published. People execute malicious code they have never vetted.

I do understand this is still better than npm right now, but it's still broken.


Security is usually full of incremental improvements like that, however. Reducing the scope from all of NPM to the handful of things like test runners would be an enormous benefit for auditors and would encourage consolidation (e.g. most testing frameworks could consolidate on a single headless chrome package), and in the future this could be further improved by things like restricting the scope of those scripts using the operating system sandbox features.


Security is layered, no layer will conclusively keep you safe, but each one make it harder to pierce to the core. For example, the impact of the recent SHA1-Hulud attack would be much less, as compromised packages (that previously did not have any scripts executing at install time), would not suddenly start executing, as they are not allowlisted.


You spell out a lot of examples, but all of them are purely technical. What is it that you can deliver to the user using Node that you cannot deliver using Django? This is a genuine question.


There is nothing you can't do, given a Turing-complete language.

That doesn't make it reasonable or convenient to do so, though.


Location: Berlin, Germany

Remote: Yes

Willing to relocate: No

Technologies: JavaScript, Golang, Python, PHP, Web Application development and (cloud) infrastructure

Résumé/CV: https://www.frederikring.com/experience/

Email: frederik.ring [at] posteo.de

I help individuals and small teams move fast by taking ownership of ambiguous, complex or unpredictable projects.


Congrats on building this. But, please do not auto translate your website content, English is fine. For my language the part about trust is really cringe, which is not really building trust, you know.


Only tangentially related, but maybe helpful still: If you struggle with OCD, the books by Sally Winston and Martin Seif are pure gold. There's nothing that helped me finding a way to deal with OCD like they did.


Typo on your landing page: "GitHub PR Intergration" -> "GitHub PR Integration"


SEEKING WORK | Remote | Berlin, Germany

Freelance software engineer with experience across a wide range of areas in web and software development. Skilled in delivering projects that require autonomy and focus.

Expertise includes JavaScript, Go, Python, and PHP, along with frameworks such as Node.js, Django, Flask, and Laravel. Proficient in cloud and infrastructure tools, including AWS, Kubernetes, Terraform, and Serverless.

Capable of handling static websites, web applications, and custom cloud solutions with a focus on simplicity and thoughtful design.

  Contact: frederik.ring@posteo.de
  CV: https://www.frederikring.com/experience/
  GitHub: https://github.com/m90


This is a well known concept called the "Hedonic Treadmill", which exists since the 70ies, not "doomer psychology". It also does not say treating depression is not possible. Depression is a disease.


SEEKING WORK | Remote | Berlin, Germany

Freelance software engineer with experience across a wide range of areas in web and software development. Skilled in delivering well-defined, scoped projects that require autonomy and focus.

Expertise includes JavaScript, Go, Python, and PHP, along with frameworks such as Node.js, Django, Flask, and Laravel. Proficient in cloud and infrastructure tools, including AWS, Kubernetes, Terraform, and Serverless.

Capable of handling static websites, web applications, and custom cloud solutions with a focus on simplicity and thoughtful design.

  Contact: frederik.ring@posteo.de
  CV: https://www.frederikring.com/experience/
  GitHub: https://github.com/m90


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: