Hacker Newsnew | past | comments | ask | show | jobs | submit | replygirl's commentslogin

we are the ones qualified to say what needs to be cut to provide reasonable certainty for the deadline. it is not the job of non-technical stakeholders to mitigate risk in technical projects

it's not about the individual record, it's about correlating records. if you can sequence everything in time it gets a lot easier to deanonymize data


However, if your API has a (very common) createdAt field on these objects, the ability to get the creation time from the identifier is rather academic.


The concern is not limited to access of the full records. The concern extends to any incidental expression of identifiers, especially those sent via insecure side channels such as SMS or email.

In most cases this forms a compliance matter rather than an open attack vector, but it nevertheless remains that one has to answer any question along the lines "did you minimise the privacy surface?" in the negative, or at least, with a caveat.


And that’s why some people are rabid about “no SELECT *”.


Can you provide an example of where you would legitimately have the ID for a medical record interaction, but not a date/time associated?


Email is not secure but sending an email with a link to "Information about your appointment" is fine. If that link goes to `/appointments/sjdhfaskfhjaksdjf`, there is no leaked data. If it goes to `/appointments/20251017lkafjdslfjalsdkjfa`, then the link itself contains PHI.

Whether creation date is PHI…I could see the argument being yes, since it correlates to medical information (when someone sought treatment, which could be when symptoms present.)


Notably, this is an absurd argument. Every system I’ve dealt with right now sends the date/time/location/practitioner clear text in the email (or some variant thereof).

The only thing that seems to be protected is ‘reason for appointment’, and not all systems do that.

Everyone signs paperwork to authorize this when they first engage with the medical providers!


Email may not be secure, but neither are faces and phones, and yet medical professionals use those all the time.


Fat fingered fax... faxes, not faces!


Why would you have Ids of medical events without the details of those events, generally including date+time?


bitwig is the leader in probabilistic sequencing and automation. they entered the space with three big ideas: (1) you can modulate anything by anything else, (2) any modulation can have probability applied, and (3) automation can be applied to individual notes. these ideas were always around but relegated to more niche tools like reason and max. thanks to bitwig, the other daws have spent a lot of the last ten years applying these ideas as well, but bitwig still has the most complete solution. it's a great primary daw for outboard- and plugin-averse recording engineers and bedroom producers; it's the best _secondary_ daw if you use one of the majors for work and want something fresh for play, inspiration, or continuing education.

i use ableton. every time i get excited for an update, it's because i'm finally getting something bitwig users have had for years


i expect to hear "hey replygirl, can we upgrade from ruff to uv format?" from 5 of my coworkers in the next month, and "what's the difference between ruff and uv format?" from another 10. per interaction i expect 2 minutes of reading and explaining, plus an average 5 minutes listening to the other party wax philosophical. so the convenience costs my job $400


I'm just going to ask this: if your coworkers ask "can we upgrade from ruff to uv format," and it takes you that much time to explain it, have you just considered going "sure thing," spending two hours on Twitter, and pushing a commit and getting paid for it?


now i've spent 2 minutes implementing, 1 minute drafting and assigning the pr, 10 minutes checking everything, 10 minutes each of two reviewers' time, 10 minutes of qa's time, and 1 minute reporting. it's also likely i spend 2 minutes explaining what it is to each of our PMs and our CTO and why they don't need to worry about it. then i still need to field questions from devs, this time "why did we change this?" and still "what's the difference?". so that costs the company even more.


You know what would be easier, "no."


so install ruff?


sure, I do, I was responding to someone who asked why not use uvx to run ruff



you'd be amazed what runs at 60fps in 4k if you simply turn down the settings


this takes a lot longer to type than before or after


11 minutes in, he mentions SICP as a book that he ended up working through exercises "in the past year" (so 2012 timeframe, well after the original Doom but before the reboot).


Thank you! :) Provides helpful context vis-a-vis evaluating possible critical-path enabling / contributing factors to achieving a key milestone.


Think how long it would have taken to click the link!


(About 9 minutes, acc. to the parallel subthread. My time on this thread is about 90 seconds so far not incl this current comment.)


Still haven't clicked it, huh? If you did you'd see that the link takes you to straight to the moment in the video where he starts talking about functional programming.


tip: there is a service menu setting to disable ads. webos is much nicer since i toggled that. the entry point with the standard remote varies between models and os versions, but you can also get service remotes on amazon for cheap


instructions unclear. the traveler drowned attempting to wade the atlantic, washed up on the virginia coast, and had willed for their family to scatter their ashes in italy.


Lucky them – I ended up in Ontario!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: