Kenton Varda
Everything, newest first — across every channel. Their profile → · Subscribe
Hiding
27 September
16 September
1 September
28 August
15 August
18 May
13 April
24 March
12 March
-
Recommendsrcmnd.app
Money StuffTheir words
here's my understanding, which comes almost entirely from reading Money Stuff, a daily column by Matt Levine. If you are a tech person who wants to learn about finance, I recommend it!
18 February
8 December 2025
13 November 2025
12 November 2025
23 October 2025
14 October 2025
-
Their words
Even the best benchmarks have bias and tradeoffs. It's difficult to create a benchmark that is truly representative of real-world performance, and all too easy to misinterpret the results of benchmarks that are not.
26 September 2025
23 September 2025
22 September 2025
-
Recommendsrcmnd.app
TypeScriptTheir words
With that said, I strongly recommend using TypeScript with Cap'n Web.
19 September 2025
24 July 2025
7 June 2025
-
Recommendsrcmnd.app
Claude CodeTheir words
I really recommend trying it rather than assuming. There's no learning curve, you just install Claude Code and run it in your repo and ask it for things.
27 May 2025
18 May 2025
21 April 2025
5 April 2025
26 March 2025
12 March 2025
17 November 2024
-
Lovedrcmnd.app
CelesteTheir words
Played Celeste. The results were very interesting. I didn't exactly perceive latency, but I did perceive that the game felt wrong. As a result, my favorite game of all time was not fun when playing on Stadia.
16 November 2024
26 September 2024
From one piece Zero-latency SQLite storage in every Durable Object 2 beliefs · blog.cloudflare.com
-
Their words
Even if it does have to go to disk, it's a local SSD. You might as well consider the local disk as just another layer in the memory cache hierarchy: L5 cache, if you will.
-
Their words
More importantly, though, synchronous queries help you avoid subtle bugs. Any time your application awaits a promise, it's possible that some other code executes while you wait. The state of the world may have changed by the time your await completes.
5 April 2024
From one piece We've added JavaScript-native RPC to Cloudflare Workers 2 beliefs · blog.cloudflare.com
-
Their words
The fact is, RPC fits the programming model we're used to. Every programmer is trained to think in terms of APIs composed of function calls, not in terms of byte stream protocols nor even REST. Using RPC frees you from the need to constantly translate between mental models, allowing you to move faster.
-
Their words
RPC is often accused of committing many of the fallacies of distributed computing. But this reputation is outdated. When RPC was first invented some 40 years ago, async programming barely existed. We did not have Promises, much less async and await. Early RPC was synchronous: calls would block the calling thread waiting for a reply. At best, latency made the program slow. At worst, network failures would hang or crash the program. No wonder it was deemed "broken".
1 April 2024
From one piece Why Workers environment variables contain live objects 3 beliefs · blog.cloudflare.com
-
korrents.com
Designing code to be friendly to dependency injection can seem tedious, and it has been worth it every time.Their words
Designing code to be DI-friendly sometimes seems tedious, but every time I've done it, I've been incredibly happy that I did.
-
Their words
Much of this pain comes about because connecting a server to a resource today involves two steps that should really be one step: Configure the server to point at the resource. Configure the resource to accept requests from the server.
-
Their words
Even if you have systems in place to deliver auth keys to services securely (like Workers Secrets), if the key is just a string, the service itself can easily leak it. For instance, a developer might carelessly insert a log statement for debugging which logs the service's configuration – including keys. Now anyone who can access your logs can discover the secret, and there's probably no practical way to tell if such a leak has occurred.
28 September 2023
-
Recommendstheir ownrcmnd.app
Cloudflare TunnelTheir words
But I definitely would recommend Cloudflare Tunnel or Authenticated Origin Pulls (with per-zone certificates) instead of allowlisting IPs.
28 July 2023
From one piece Cap'n Proto 1.0 2 beliefs · capnproto.org
-
Their words
Frankly, I should have declared 1.0 a long time ago – probably around version 0.6 (in 2017) or maybe even 0.5 (in 2014).
-
Their words
As discussed above, this is opt-in today, but in practice I find it’s almost always desirable, and disallowing it can lead to subtle problems.
27 September 2022
From one piece Introducing workerd: the Open Source Workers runtime 2 beliefs · blog.cloudflare.com
-
Their words
First, we can now restrict the global fetch() function to accept only publicly-routable URLs. This makes applications totally immune to SSRF attacks! You cannot trick an application into accessing an internal service unintentionally if the code to access internal services is explicitly different.
-
korrents.com
Calling small services "functions" puts too much emphasis on syntax rather than on what the service logically does.Their words
Some in the industry prefer to call nanoservices "functions", implying that each individual function making up an application could be its own service. I feel, however, that this puts too much emphasis on syntax rather than logical functionality.
14 January 2022
19 October 2021
From one piece Backwards-compatibility in Cloudflare Workers 3 beliefs · blog.cloudflare.com
-
Their words
Second, part of the promise of serverless is that developers shouldn't have to worry about updating their stack. If we start letting people pin old versions, then we have to start telling people how long they are allowed to do so, alerting people about security updates, giving people documentation that differentiates versions, and so on. We don't want developers to have to think about any of that.
Backwards-compatibility in Cloudflare Workersblog.cloudflare.com
-
Their words
But what if the test only worked because of a bug in the underlying platform that caused it to do the right thing by accident? Well, that's the platform's fault. The developer did everything they could: they tested their code thoroughly, and it worked.
Backwards-compatibility in Cloudflare Workersblog.cloudflare.com
-
Their words
In the old world, if the Node.js maintainers decide to make a breaking change to an obscure API between releases, it's OK. Downstream developers are expected to test their code before upgrading, and address any breakages. But in the serverless world, it's not OK: developers have no control over when upgrades happen, therefore upgrades must never break anything.
Backwards-compatibility in Cloudflare Workersblog.cloudflare.com
12 October 2021
3 August 2021
From one piece Durable Objects: Easy, Fast, Correct — Choose three 2 beliefs · blog.cloudflare.com
-
korrents.com
The worst thing an application can do is tell a user their action succeeded when it did not.Their words
The worst thing an application can do is tell the user that their action was successful when it wasn't. If, for some reason, a write cannot be completed, then it's imperative that the application presents an error to the user, so that the user knows that something is wrong and they'll have to try again or look for a fix.
-
korrents.com
Concurrency is hard for novices and experts alike: even experts regularly get it wrong.Their words
Concurrency is hard. It doesn't matter if you're a novice or an expert: even experts regularly get it wrong. It's difficult to think about all the ways that concurrent operations might overlap to corrupt your application state.
17 April 2021
28 September 2020
29 July 2020
From one piece Mitigating Spectre and Other Security Threats: The Cloudflare Workers Security Model 4 beliefs · blog.cloudflare.com
-
Their words
On one hand, V8 is an extraordinarily complicated piece of technology, creating a wider "attack surface" than virtual machines. More complexity means more opportunities for something to go wrong. On the bright side, though, an extraordinary amount of effort goes into finding and fixing V8 bugs, owing to its position as arguably the most popular sandboxing technology in the world.
-
Their words
It is abundantly clear that many more vulnerabilities exist, but haven't yet been publicized. Who might know about those vulnerabilities? Most of the bugs being published are being found by (very smart) graduate students on a shoestring budget. Imagine, for a minute, how many more bugs a well-funded government agency, able to buy the very best talent in the world, could be uncovering.
-
korrents.com
No one has fixed Spectre, not even with heavyweight virtual machines; everyone is still vulnerable.Their words
A dirty secret that the industry doesn't like to admit: no one has "fixed" Spectre. Not even when using heavyweight virtual machines. Everyone is still vulnerable.
+ 1 more
-
Their words
Popular security culture often dwells on clever hacks and clean fixes. But for the difficult real-world problems, often there is no right answer or simple fix, only the hard work of building defenses thicker and thicker.
1 October 2018
13 March 2018
-
Their words
We believe the true dream of cloud computing is that your code lives in the network itself. Your code doesn't run in "us-west-4" or "South Central Asia (Mumbai)", it runs everywhere.
23 October 2017
29 September 2017
-
Recommendsrcmnd.app
RustTheir words
That said, I love Rust and highly encourage more people to use it.
Nothing matches.
What is a korrent?
A korrent is a belief a person has stated in their own words: one sentence stating the claim, backed by a quote and a source, kept at korrents.com.
Under a name here, the quoted block is what they actually said. The korrent beneath it is the claim those words support, in korrents' wording — tap it to see the record, its source, and who else holds it.
Nobody here wrote their own korrents. They are compiled from public statements, and a person can change their mind, which is recorded too.
About the English under a post
Some people here publish in a language other than English. Where they do, this site shows a machine translation beneath the post, in this typeface — the site's own, not theirs.
The post itself is never changed, moved or hidden: what is set in the serif above is exactly what the person published, and it is what to quote them on. A translation can be wrong in ways that matter, especially about tone.
Only the post's own words are translated. A quoted post, a linked article and a belief on korrents.com are left in their original language.