Messages via JSON
refl.me
refl.me
I think not needing to bother with any kind of third-party is hard to beat in terms of simplicity.
> I don't think this app will ever work on iOS, due to Apple's policies.
I've not much experience on iOS, so apologies if the answer is obvious, but is there no scheduled task API you could use?
At least, you're not supposed to keep the app working in the background in Android either - however, the app's use-case should still be doable with the background scheduling API.
That's why many monitoring tools are now pull-based (Prometheus) instead of push (Graphite).
This should probably be an HMAC construction at the very least, and MD5 in general just should be discarded entirely in favor of BLAKE2b, SHA-2 or SHA-3. And ideally, it'd actually validate the rest of the contents as well.
Posting comments in favor of a service without disclosing your’re its author is usually seen as a conflict of interest and, as such, a bad thing.
Not sure why, since it isn't in any practical or philosophical sense.
I judge the merits of a post by the content. I don't know if you're Celebrity X or Author of Y and I don't care much. Yes it would be useful to reference other statements, but that's something you often sacrifice in an open (even moderated) online forum. It's a strength of the platform as well.
Given that, you might as well just use an unchanging token or Basic Auth. Assuming https, that wouldn't be terrible for this kind of use case. But put it in an Authorization header, not in a query parameter, so it doesn't end up in logs.
Sounds like a cool little thing, but wouldn't mind a standard to use on non-mobile platforms.
reading that has me curious; if one can do that for any arbitrary string, and then iterate that process, doesn't that stand to reason that with enough work, one could make any two given strings calculate out to the same crc? I guess maybe not because that one byte constraint isn't specified as far as where it occurs and whether it's an insertion, deletion, permutation etc, but the way I see it if you can do it with one string to another, you could likely keep chaining that indefinitely and get countless strings that come to the same crc.
sorry if this is old news or anything I was just struck by that thought while reading your comment
And producing two strings with same CRC is trivial to the extent that it is how you are originally supposed to use the algorithm. Notice that CRC-32 of every valid ISO9660 filesystem is 0xffffffff ;)
But yes, people saying "CRC" when they really mean "checksum" or "signature" is a pet peeve of mine, and I treat it as a code smell. CRC has a precise defined technical meaning.
For the curious: CRC is linear with respect to XOR. This means that if you XOR two equal-length strings, the CRC will be the individual CRCs XORed together. It's also a bijection for messages of length equal to the polynomial (typically 32 bits): every input maps to a distinct output and vice-versa. Together, these mean it's trivially invertible for a message of length equal to the CRC: the CRC function can be represented as a square matrix over GF-2 (i.e., bits + XOR), which can be inverted with standard Gaussian elimination to produce the inverse function: generate a (short) string from any CRC.
More fun CRC tidbits: it's not a given that two arbitrary CRC functions, or a CRC and another linear(ish) checksum (e.g. ones' complement), are linearly independent. This can bite you when you try to use two different CRCs to get "more" error protection, or when you use "independent" CRCs to route work at two different points in a system. Again this is easy to verify using linear algebra (just check that the GF-2 matrix formed by the concatenation of your two functions is of full rank).
So, a reinvented wheel that doesn't work on roads.
It might meet with some success. To people who don't know about RSS, it's a new thing.
32% of Americans use RSS every month just for podcasts alone.
There is something to be said for things being similar but not the same. This app can grow features in the direction of alerting, whereas an RSS reader wouldn't be growing in that direction without becoming bloatware because it's main job is to catch you up on reading material.
I can see myself using it, and it has been something I have consider building myself - although I had a different angle - an API for a person so you can send me a message (if I trust you... maybe I give each friend a different token!) and we can avoid using email or a proprietary chat alltogether. Such a service could work in tandem with this app.
Based on that you could make a distributed "facebook" of sorts.
Once the iPhone app of this come out I can see myself setting up a little nodejs server and aggregating some stuff to send down. Weather, email, SMS, maybe some favourite google searches (when they change) or hn.algolia.com searches.
> although I had a different angle - an API for a person so you can send me a message ... and we can avoid using email or a proprietary chat alltogether
If you want to exchange messages avoiding email or proprietary chats, you have a wide variety of open chat protocols and free and open source chat applications to choose from. XMPP, Matrix, IRC, mastodon, rocketchat, mattermost, ... dozens of them!
JSON isn't, but REFL.ME+JSON appears to be.
There is a nice substratum of curl services, like wttr.in or getnews.tech that follow a similar concept
I hope this is the beginning of a gopher + JSON + curl services era
Pushover is push based, while this looks to be pull based.
(I use pushover, and it rocks. But there you POST the message to pushover, here you host them on your own machine(s))
How charming.
Not sure what "guaranteed connectivity" has to do with it, your phone is connected to network ~90% of the time, and when it is, it has a socket connection with the Google Cloud Messaging API (or iPhone equivalient) which pushes down data as it comes into the queue. If messages come in while you're disconnected, you get them all the next time data is pushed.
From the Apple Developers Documentation [1], "On initial launch of your app on a user’s device, the system automatically establishes an accredited, encrypted, and persistent IP connection between your app and APNs."
This persistent connection is, in fact, an XMPP session (likely, a modified one) [2].
Google's FCM too uses XMPP [3].
[1] https://developer.apple.com/library/archive/documentation/Ne...
[2] https://www.quora.com/What-technology-does-the-iOS-Apple-Pus...
[3] https://firebase.google.com/docs/cloud-messaging/xmpp-server...
The current absence of direct XMPP mentions on Apple Deveoper website might mean that they consider their internal technology not important for developers, or it might mean that Apple had changed the protocol for some reason (they could have opted to use some binary protocol, for example), but claiming that push notifications work on iOS devices by polling servers is beyond ridiculous. VoIP pushes arrive in ~1 second. Such response times would require 40000 poll requests/day or more
I was referring to earlier comments by nicolas314, sorry if it wasn't clear.
> I was developing iOS apps in the 2010-2012 time frame and never saw a mention of XMPP
I might have been more attentive to these details because XMPP was relevant for my projects. Anyway, Apple definitely does use port 5223 [1][2] for push notifications. What protocol is known to use this port?
Speaking of proprietary, it is very likely that they have modified it (by stripping it down, mostly). Many XMPP features are excessive or inefficent for push notifications, but core functions - message routing and persistent TCP connection are extremely well suited for serving several billion devices.
Then why not make a relay, i.e. a server that forwards messages from a webclient to Whatsapp, email, etc.?
Well, it receives data by hitting a specific endpoint with a specific protocol. It’s “simpler” in that it may be easier to implement, but you still have to modify your service to get that to work. And if you must modify your service, you may want to implement something that’s better supported and doesn’t require users to install (and configure) yet another app.
So is this just polling an api that responds in JSON and then updating your phone if something in the response changes?
I would have done it using server-sent events instead.
$json_array = array('reflapp'=>true,'message'=>'test');
shouldn't that be $json_array = array('refl.me'=>true,'message'=>'test');Why?
I think this is aimed at people who already are or can expose data via an HTTP endpoint and want notifications when that changes/updates. This includes the wide array of software developers who work on large OS projects that support sending notifications via services like PushBullet/Pushover/etc. Also, presumably, web services would just add a new endpoint with some auth token to easily send push notifications to their users without managing an app and everything else needed (push tokens, certs, GCM/FCM, apns, it can be a headache, trust me).
Personally I see pushover-type services (I use pushover so I'm only speaking from that experience) as more useful since I can "push" out of my networks much easier than a service can "poll" me. That said pushover has always been a little clunky IMHO with trying to get a service to send me notifications. So a simple "Paste this url into the refl.me app to get notifications from us" is a pretty attractive alternative for certain use cases.
[EDIT] damn, beaten to the punch.
It seems likely you’d need to proxy most services anyway. With numerous FaaS providers these days that seems trivial.
In my mind it's in the same category as google throwing garbage or while(1){} loops at the start of their JSON responses to prevent XSS JSON reflection attacks. I know it's not the same thing at all but idk, thats what comes to mind for me.
EDIT: Of course I think of a better comparison as soon as I hit submit: Sort of like LetsEncrypt looking for a .well-known/acme-challenge to validate your domain.
It is genius.
Neat idea, low barrier to entry. Can't tell from docs how authz/authn are handled.
And client app will eat my battery because one more service is constantly polling now ?
Would be nice if you could override this client side as well.
Push notifications function on the principle that when a state change happens, the notification is pushed to the device.
Pull notification is when device polls some service for data, detects change, and then emits notification if change has occurred.
There are benefits and drawbacks to both.
Or just go here: https://refl.me/?lang=en