Got Users? How About 100M of Them?
inversoft.com
inversoft.com
It's a bad sign when the very first sentence of your promotional blogpost has no coherent meaning in the English language.
> I am quite sure that if your application actually grew that quickly the rest of your infrastructure would fail spectacularly. But rest assured, Passport will be just fine.
Another thing about writing promotional blogposts: don't belittle your potential clients.
Login reporting is cool... But if you build your own you can get full app reporting. Not sure of the exact value add but I would way rather have reporting on all pages not just login.
Localization? The hard part is translating my entire app. Not sure if I do that work, I'm going to be mad I have to translate the word login and logout
Click reset, store a unique id, send the user an email with a link including the unique id, verify that ID on the request and then allow a password change. Then to be secure that unique id needs to be timed out once it is generated to ensure the link is only good for a short period of time, etc.
Not to say anyone couldn't code all of that, but some of the simple features once fully thought out end up being fairly complex. In my experience many of the out of the box options still need to be extended to be fully realized for enterprise usage.
I don't have a ton of experience with DJango specifically so I could be mistaken - perhaps it does more than I know.
I think adding more systems increases your odds of being hacked, even if slightly lowering the damage of one hack. I would kinda prefer to avoid hacked all together.
I stuck it into the Stanford NLP parser ( http://nlp.stanford.edu:8080/parser/index.jsp ) and the output matched my prior reckons.
Or maybe it is just supposed to mean that a software engineer had to think about, and set up, the login system for each system you log in to at some point.
I presume that's what it's going for, but all in this is one of the worst promotional blog posts I've ever read.
To elaborate, statements like "every time you shake hands with someone, a volcano has erupted" are equally, trivially, true. They just don't mean anything-- anything at all. There exists some volcano which has erupted. Therefore any time you shake hands with someone, eat a meal, go to sleep, push a button, etc... that statement is still true, just like it was and would be with or without your entire existence. At which point you're just saying words to hit some word count or something. Or maybe allude to some unstated connection... ?
Pages like this is literally what CDNs are great for.
https://github.com/paragonie/airship/blob/e24ea5a4605336b171...
This is something that really ought to be baked-in in 2016.
What do you think of compiling PHP plus libs for app compatibility to something like Rust, Ada, or Cyclone where possible? And do you know if anyone has assessed quality/security of Quercus/Resin code in particular? Seems something like that compatible with WordPress or Airship could be quite a boost in defense of code injection at system level. Performance, too, as we saw with HipHop.
In addition to your examples of Quercus and HHVM, someone is currently working on compiling PHP to .NET: http://www.peachpie.io
I'm not aware of any security audits on any of these efforts.
https://en.wikipedia.org/wiki/Phalanger_%28compiler%29
Already runs WordPress, phpBB, etc. Anyone doing this sort of thing on .NET might consider starting with contributions to it. I'm trying to avoid CLR and JVM due to runtime complexity where possible. Aside from Rust, Go is another possible target for a simple runtime.
https://paragonie.com/project/airship
Working on the PKI and plugin distribution system right now, so people can make/share themes and whatnot.
Not that hard to scale static blog post wordpresses.. but man the default is like 4 requests per second bad ;)
I have a cheap VPS and didn't do anything fancy with caching. I just don't code like a n00b.
Also, either use SuperCache or ditch WordPress entirely.
Then again, 400 a second doesn't sound that fast given what HSM's and databases do. Maybe this software is just doing something complicated with each request.
Even being generous and allowing for 10000 logins per second, it will take almost 3 hours for everyone to relogin. Oops.
Ok, so that 100M is clearly not viable for services that actually expect a significant amount of their users to use the service at roughly the same time (that is - it would clearly not handle Facebook amount of load).
A much more relevant metric would be how many simultaneous sessions you can handle while being able to claim good service (say, the 99th percentile being able to login without getting time-outs).
Also, generally speaking, most authentication systems will involve at least a few server-side writes for logins, meaning the difference to new registrations shouldn't be all that big in a well designed and compartmentalized system.
Disclaimer: Yeah, I used to work for a company that did authentication servers for ISPs.
I like how Atlassian does it - they more or less give it away for free for small companies and then once you can afford it they start charging more. Unless I can get going for free, probably a non starter.
That said, inserting "she" everywhere just feels disengenuous, and I notice it everywhere from technical blogs to a16z write ups.
Sure your company is 30% female in all positions (amazing for the industry in this hypothetical) and you're top tech team is all over it. You're core engineer, she's digging through mounds of code with only her team of 2, an african american native inuit, top of her year at stanford, and a trans person.
I would love to see the industry be attractive to all types. However, you can't just swap pronouns because it sounds so fake amd disingenuous. Probabalistically speaking, your engineering team is not 100% women or even close.
idk, maybe blasphemous or inflammatory, just strikes me as a feeble attempt to notmalize something that isnt normal...
edit; wow, I apologize I guess? It seems forced to me that the whole industry changed pronouns (if little else) over night. So I guess I am a misoginist for actually thinking more equitable demographics would be better than some language nuance, which just feels forced
edit2: i deleted some comments that basically said the above, but slightly more rudely. apologies.
Occasionally using "she" to refer to an unknown person is a welcome relief from the abundant writing which solely uses the male pronoun. When documentation uses "he" it doesn't mean engineering teams are 100% male and using "she" doesn't mean the inverse.
Idk, i'm not a femal engineer. Maybe passport was predominently written by female engineers. If I was a minority in some arena,I suspect I would be slightly off put if they just pretended I wasn't
Only about 43% of college students are male. Does that mean it's not normal to have a male college student?
Please take your casual sexism elsewhere.
In a lot of the US, 'you guys' is standard plural you regardless of gender, but we don't have a gender neutral pronoun other than "they" which only works some of the time. https://en.wikipedia.org/wiki/Singular_they
But in this case it would have worked fine: "a software engineer has thought about user registration and authentication. Hopefully they have thought a lot about it."
Let's push for the expanded use of "they" as gender neutral singular rather than pushing "she" down.
edit:
> you are literally saying she isn't welcome
If I literally said that, qoute me...
You are complaining about a single instance of 'she' involving a hypothetical person.
I hope for your sake you are trolling, because you have some warped world of priorities if not.