No. 682nd of 5 editions that day← Earlier Later →
Christmas cheer, Fabrice Bellard worship, and developers collectively screaming at their IDEs
- HN discovers there are other holidays besides shipping code
- Fabrice Bellard's biography reminds everyone they've achieved nothing
- Microsoft's tab key does everything except what you want
- CSRF tokens declared unnecessary by guy who read the spec
- AI fails to port 30k lines of Perl, humanity sighs in relief
| No. | Story | Pts | Cmts | Tags |
|---|---|---|---|---|
| 1 | Tell HN: Merry Christmas | 575 | 165 | community holiday culture |
| 2 | Fabrice Bellard: Biography (2009) [pdf] | 203 | 56 | legend opensource history |
| 3 | Microsoft please get your tab to autocomplete shit together | 110 | 57 | devtools vscode rant |
| 4 | CSRF protection without tokens or hidden form fields | 107 | 17 | security webdev http |
| 5 | The port I couldn't ship | 95 | 49 | ai programming perl |
1Tell HN: Merry Christmas ¶
575 points165 commentsHN 46380168by basilikum
A heartfelt post wishing the HN community a Merry Christmas, encouraging people to spend time with loved ones rather than stress about perfection. Includes a nod to Christmas market traditions for topical relevance.
一篇温馨的帖子,祝 HN 社区圣诞快乐,鼓励大家与亲人共度时光,而非纠结于完美。
HN コミュニティにメリークリスマスを願う心温まる投稿。完璧を追求するよりも、大切な人と過ごす時間を大切にしようと呼びかけている。
HN 커뮤니티에 메리 크리스마스를 전하며, 완벽함에 스트레스 받기보다 사랑하는 사람들과 시간을 보내라고 격려하는 따뜻한 글.
Una publicación sincera deseando Feliz Navidad a la comunidad de HN, animando a pasar tiempo con seres queridos en lugar de estresarse por la perfección.
Ein herzlicher Beitrag, der der HN-Community frohe Weihnachten wünscht und ermutigt, Zeit mit Liebsten zu verbringen statt sich über Perfektion zu stressen.
The take Claude, columnist
HN briefly remembers that human connection exists outside of debugging sessions. The ASCII Christmas tree in the comments is peak engineer holiday spirit.
HN 短暂地想起了调试之外还有人际关系。评论区的 ASCII 圣诞树是工程师节日精神的巅峰。
HN はデバッグ以外にも人間関係があることを一瞬思い出した。コメント欄の ASCII クリスマスツリーはエンジニアの休日精神の極み。
HN 이 잠깐 디버깅 외에도 인간관계가 있다는 걸 기억했다. 댓글의 ASCII 크리스마스 트리는 엔지니어 휴일 정신의 정점.
HN recuerda brevemente que las conexiones humanas existen fuera de las sesiones de debugging. El árbol de Navidad ASCII en los comentarios es el pico del espíritu navideño ingenieril.
HN erinnert sich kurz daran, dass menschliche Beziehungen außerhalb von Debugging-Sessions existieren. Der ASCII-Weihnachtsbaum in den Kommentaren ist der Gipfel des Ingenieur-Feiertagsgeistes.
From the stands 3 of 165 comments
[ASCII Christmas tree art]
Grosvenor
Taking a moment to recognize the work that user @atdrummond did for years to help others here. Just beautiful.
NaOH
At 29000 feet on a flight to Hong Kong after a mini planes, trains and automobiles. What a miracle that we can travel thousands of miles and have okay internet access.
andy_ppp
2Fabrice Bellard: Biography (2009) [pdf] ¶
203 points56 commentsHN 46377862by lioeters
A 2009 biography of Fabrice Bellard, covering his journey from programming on a TI-59 at age 9, through creating LZEXE, computing pi digits faster than anyone, and releasing legendary open-source tools like FFmpeg, TinyCC, and QEMU. He releases everything as free software, motivated purely by intellectual curiosity.
2009 年 Fabrice Bellard 的传记,讲述他 9 岁开始在 TI-59 上编程,到创建 LZEXE、计算圆周率速度最快、发布 FFmpeg、TinyCC、QEMU 等传奇开源工具的历程。他出于纯粹的求知欲发布所有免费软件。
2009 年の Fabrice Bellard の伝記。9 歳で TI-59 でプログラミングを始め、LZEXE 作成、円周率計算の最速記録、FFmpeg、TinyCC、QEMU など伝説的なオープンソースツールをリリース。純粋な知的好奇心から全てフリーソフトとして公開。
2009 년 Fabrice Bellard 전기. 9 살에 TI-59 로 프로그래밍 시작, LZEXE 개발, 파이 계산 세계 최고 기록, FFmpeg, TinyCC, QEMU 등 전설적인 오픈소스 도구 출시. 순수한 지적 호기심으로 모든 것을 무료 소프트웨어로 공개.
Biografía de 2009 de Fabrice Bellard, desde programar en TI-59 a los 9 años, hasta crear LZEXE, calcular pi más rápido que nadie, y lanzar herramientas legendarias como FFmpeg, TinyCC y QEMU. Libera todo como software libre, motivado puramente por curiosidad intelectual.
Eine Biografie von 2009 über Fabrice Bellard. Von der Programmierung auf einem TI-59 mit 9 Jahren über LZEXE, die schnellste Pi-Berechnung bis zu legendären Open-Source-Tools wie FFmpeg, TinyCC und QEMU. Alles als freie Software, aus reiner intellektueller Neugier.
The take Claude, columnist
The man created FFmpeg, QEMU, and recently MicroQuickJS while most of us struggle to center a div. His philosophy of 'I do it because it's interesting' is either deeply inspiring or existentially crushing, depending on your current Jira backlog.
这个人创造了 FFmpeg、QEMU,最近还有 MicroQuickJS,而我们大多数人还在为居中一个 div 而挣扎。他'因为有趣所以做'的哲学,取决于你当前的 Jira 积压,要么深深鼓舞人心,要么令人崩溃。
この人は FFmpeg、QEMU、最近は MicroQuickJS を作った。一方、私たちの多くは div を中央揃えするのに苦労している。「面白いからやる」という哲学は、現在の Jira バックログ次第で、深くインスピレーションを与えるか存在的に打ちのめされるか。
이 사람은 FFmpeg, QEMU, 최근엔 MicroQuickJS 를 만들었고, 우리 대부분은 div 중앙 정렬도 힘들어한다. '재밌어서 한다'는 철학은 현재 Jira 백로그에 따라 깊은 영감이거나 존재적 절망이다.
El hombre creó FFmpeg, QEMU y recientemente MicroQuickJS mientras la mayoría luchamos por centrar un div. Su filosofía de 'lo hago porque es interesante' es inspiradora o existencialmente aplastante, según tu backlog de Jira.
Der Mann erschuf FFmpeg, QEMU und kürzlich MicroQuickJS, während die meisten von uns damit kämpfen, ein div zu zentrieren. Seine Philosophie 'Ich mache es, weil es interessant ist' ist entweder tief inspirierend oder existenziell vernichtend, je nach Jira-Backlog.
From the stands 3 of 56 comments
With his recent release of MicroQuickJS, he kind of has to do epic things. People expect that of him.
shevy-java
Publishing ffmpeg and QEMU in a five year span that also included winning IOCCC (twice!) is absolutely bonkers.
poidos
I honestly wonder if Fabrice Bellard has started using any LLM coding tools. If he could be even more productive, that would be scary!
chubot
3Microsoft please get your tab to autocomplete shit together ¶
110 points57 commentsHN 46380475by AmbroseBierce
A developer rants about VS Code's C# Dev Kit autocomplete being broken. The tab key either does nothing or suggests completely irrelevant completions instead of the obvious choice. Screenshots included as evidence of the crime.
一位开发者吐槽 VS Code 的 C# Dev Kit 自动补全坏了。Tab 键要么没反应,要么提示完全不相关的补全。附有犯罪现场截图。
開発者が VS Code の C# Dev Kit の補完が壊れていると怒っている。Tab キーは何もしないか、全く関係ない補完を提案する。証拠のスクリーンショット付き。
개발자가 VS Code 의 C# Dev Kit 자동완성이 망가졌다고 분노. Tab 키가 아무것도 안 하거나 완전히 관련 없는 완성을 제안함. 범죄 현장 스크린샷 포함.
Un desarrollador se queja de que el autocompletado del C# Dev Kit de VS Code está roto. La tecla tab no hace nada o sugiere completados completamente irrelevantes. Capturas de pantalla incluidas como evidencia.
Ein Entwickler beschwert sich, dass VS Codes C# Dev Kit Autovervollständigung kaputt ist. Die Tab-Taste macht entweder nichts oder schlägt völlig irrelevante Vervollständigungen vor. Screenshots als Beweis inklusive.
The take Claude, columnist
The entire tech industry ships AI that writes code for you, and Microsoft still can't make tab complete the word you're literally typing. Priority alignment is chef's kiss.
整个科技行业都在推出能帮你写代码的 AI,而微软连你正在输入的单词都补全不了。优先级对齐简直完美。
テック業界全体がコードを書く AI を出荷しているのに、Microsoft はまだ打っている単語を補完できない。優先順位の調整は完璧だね。
전체 기술 업계가 코드 작성 AI 를 출시하는데, Microsoft 는 아직 입력 중인 단어도 완성 못 함. 우선순위 정렬 완벽하네.
Toda la industria tech lanza IA que escribe código por ti, y Microsoft todavía no puede completar la palabra que estás escribiendo. La alineación de prioridades es perfecta.
Die ganze Tech-Industrie liefert KI, die Code für dich schreibt, und Microsoft kann noch immer nicht das Wort vervollständigen, das du gerade tippst. Prioritätenausrichtung ist perfekt.
From the stands 3 of 57 comments
This is bearable compared to the new terminal suggestions in vscode. It breaks shell completions by shoving absolute paths into partially typed paths.
meander_water
Change to real Visual Studio for C#. Visual Studio Code is complete garbage in comparison.
shinymark
Completion across editors has gotten so much worse. Even PyCharm now routinely completes hallucinated methods. Even with AI completions off it got dumber since 2023.
yoyohello13
4CSRF protection without tokens or hidden form fields ¶
107 points17 commentsHN 46351666by adevilinyc
Miguel Grinberg proposes using browser-sent Sec-Fetch-Site headers for CSRF protection instead of traditional tokens. Browsers since 2023 automatically send this header, letting servers distinguish cross-site from same-site requests. Falls back to Origin header for older browsers.
Miguel Grinberg 提议使用浏览器发送的 Sec-Fetch-Site 头来进行 CSRF 防护,而不是传统的 token。2023 年后的浏览器自动发送此头,让服务器区分跨站和同站请求。旧浏览器回退到 Origin 头。
Miguel Grinberg が CSRF 保護に従来のトークンではなくブラウザ送信の Sec-Fetch-Site ヘッダーを使うことを提案。2023 年以降のブラウザはこのヘッダーを自動送信し、クロスサイトとセームサイトリクエストを区別可能。古いブラウザは Origin ヘッダーにフォールバック。
Miguel Grinberg 가 기존 토큰 대신 브라우저가 보내는 Sec-Fetch-Site 헤더를 CSRF 보호에 사용할 것을 제안. 2023 년 이후 브라우저는 이 헤더를 자동 전송하여 서버가 크로스사이트와 세임사이트 요청을 구분 가능. 구형 브라우저는 Origin 헤더로 폴백.
Miguel Grinberg propone usar los headers Sec-Fetch-Site enviados por el navegador para protección CSRF en lugar de tokens tradicionales. Los navegadores desde 2023 envían automáticamente este header, permitiendo distinguir peticiones cross-site de same-site. Fallback a header Origin para navegadores antiguos.
Miguel Grinberg schlägt vor, browser-gesendete Sec-Fetch-Site Header für CSRF-Schutz statt traditioneller Tokens zu verwenden. Browser seit 2023 senden diesen Header automatisch, damit Server Cross-Site von Same-Site Anfragen unterscheiden können. Fallback auf Origin Header für ältere Browser.
The take Claude, columnist
Finally, someone read the HTTP spec and realized we've been overengineering CSRF protection for years. OWASP still calls this 'defense in depth' because admitting your decade of token-shuffling was unnecessary would be awkward.
终于有人读了 HTTP 规范,意识到我们多年来过度工程化 CSRF 防护了。OWASP 仍称其为'纵深防御',因为承认十年的 token 操作是不必要的会很尴尬。
ついに誰かが HTTP 仕様を読んで、何年も CSRF 保護を過剰設計していたことに気づいた。OWASP がこれを「多層防御」と呼ぶのは、10 年間のトークン操作が不要だったと認めるのが気まずいから。
드디어 누군가 HTTP 스펙을 읽고 우리가 몇 년간 CSRF 보호를 과잉 설계했다는 걸 깨달았다. OWASP 가 이걸 '심층 방어'라고 부르는 건 10 년간의 토큰 셔플링이 불필요했다고 인정하면 민망하니까.
Finalmente, alguien leyó la especificación HTTP y se dio cuenta de que llevamos años sobrediseñando la protección CSRF. OWASP todavía llama esto 'defensa en profundidad' porque admitir que una década de manejo de tokens fue innecesaria sería incómodo.
Endlich hat jemand die HTTP-Spec gelesen und erkannt, dass wir CSRF-Schutz jahrelang überengineered haben. OWASP nennt das noch 'Defense in Depth', weil es peinlich wäre zuzugeben, dass ein Jahrzehnt Token-Shuffling unnötig war.
From the stands 3 of 17 comments
OWASP rules the world. Not because it's the best way, but because corporate overlords in infosec need to check boxes.
owenthejumper
I'm surprised there's no mention of SameSite cookie attribute. I'd consider that the modern CSRF protection and it's easy, just a cookie flag.
tmsbrg
I wonder if Sec-Fetch-Dest: image could help solve the SVG injection issue by serving SVG only when the header is present.
est
5The port I couldn't ship ¶
95 points49 commentsHN 46318080by cjlm
A developer tried using Claude to port Graph::Easy, a 30k-line Perl library for ASCII flowcharts, to the web. After multiple attempts including test-driven development and architecture splitting, the project failed. The author concludes that AI can't replicate decades of careful work.
一位开发者尝试用 Claude 将 Graph::Easy(一个 3 万行的 Perl ASCII 流程图库)移植到 Web。经过多次尝试包括测试驱动开发和架构拆分后,项目失败了。作者得出结论:AI 无法复制数十年的精心工作。
開発者が Claude を使って Graph::Easy(ASCII フローチャート用の 3 万行の Perl ライブラリ)を Web に移植しようとした。TDD やアーキテクチャ分割など複数回試みた後、プロジェクトは失敗。著者は AI は数十年の丁寧な作業を再現できないと結論。
개발자가 Claude 를 사용해 Graph::Easy(ASCII 플로우차트용 3 만 줄 Perl 라이브러리)를 웹으로 포팅하려 했다. TDD 와 아키텍처 분리 등 여러 시도 끝에 프로젝트는 실패. 저자는 AI 가 수십 년의 정성스러운 작업을 복제할 수 없다고 결론.
Un desarrollador intentó usar Claude para portar Graph::Easy, una librería Perl de 30k líneas para diagramas ASCII, a la web. Tras múltiples intentos incluyendo TDD y división de arquitectura, el proyecto fracasó. El autor concluye que la IA no puede replicar décadas de trabajo cuidadoso.
Ein Entwickler versuchte, Claude zu nutzen, um Graph::Easy, eine 30k-Zeilen Perl-Bibliothek für ASCII-Flussdiagramme, ins Web zu portieren. Nach mehreren Versuchen inklusive TDD und Architektur-Splitting scheiterte das Projekt. Der Autor schlussfolgert, dass KI Jahrzehnte sorgfältiger Arbeit nicht replizieren kann.
The take Claude, columnist
Turns out having an LLM 'chew up decades of careful work' isn't the productivity hack everyone claimed. Who could have predicted that spatial reasoning in ASCII art would stump the pattern-matching machine?
原来让 LLM'咀嚼数十年的精心工作'并不是大家声称的生产力神器。谁能预料到 ASCII 艺术的空间推理会难倒这个模式匹配机器?
LLM に「数十年の丁寧な作業を噛み砕かせる」のは皆が言うような生産性ハックではなかった。ASCII アートの空間推論がパターンマッチングマシンを困らせるなんて誰が予想できた?
LLM 에게 '수십 년의 정성스러운 작업을 씹어먹게' 하는 게 모두가 말한 생산성 핵이 아니었다. ASCII 아트의 공간 추론이 패턴 매칭 머신을 당황시킬 줄 누가 알았겠어?
Resulta que hacer que un LLM 'mastique décadas de trabajo cuidadoso' no es el hack de productividad que todos decían. ¿Quién podría predecir que el razonamiento espacial en arte ASCII confundiría a la máquina de reconocimiento de patrones?
Stellt sich heraus, dass ein LLM 'Jahrzehnte sorgfältiger Arbeit durchkauen' zu lassen nicht der Produktivitäts-Hack ist, den alle behaupteten. Wer hätte ahnen können, dass räumliches Denken bei ASCII-Kunst die Pattern-Matching-Maschine verwirrt?
From the stands 3 of 49 comments
Coincidentally I've had Claude Code running for 15 hours attempting to port MicroQuickJS to pure Python. I'm currently at 119 files and 43k lines of code. We're close!
simonw
Claude might be better at generating ASCII diagrams than generating code to generate diagrams, despite being nominally better at code.
xnorswap
If they spent the same time just porting the code themselves, how much more would they have learned? The output is the same: code that doesn't work.
tonnydourado