HNHacker News
TopNewBestAskShowJobs

SpikeGronim

776 karma · joined July 25, 2010

I'm a programmer living in Michigan.
submissionscomments
SpikeGronim··on Man Possessing 100,000 Unregistered SIM Cards Arrested In India
SIM cards need to be registered so that the Indian police can track criminals. Personally I disagree with this. Criminals will disregard this law so it will usually only apply to law abiding citizens. Try explaining that to the Indian CBI though...
SpikeGronim··on Apple MacBooks Can Be Hacked Through The Battery
I don't think so. Certainly not for any peripheral that is allowed to do DMA. Though plugging in a malicious firewire peripheral is a lot more practical than replacing the battery...

http://www.hermann-uwe.de/blog/physical-memory-attacks-via-f...

SpikeGronim··on Aaronsw indicted for hacking MIT network to download millions of JSTOR docs
IANAL, but legally speaking unauthorized access is a crime regardless of how easy it was to gain access.
SpikeGronim··on Aaronsw indicted for hacking MIT network to download millions of JSTOR docs
"Does anyone think it's odd that an Acer laptop could write these files to disk faster than JSTOR could serve them?"

Nope. I bet the JSTOR servers are serving many concurrent requests. If he had the servers to himself then yes, that would be surprising.

SpikeGronim··on Greplin's code independence day: open source for Nagios, OOM debugging, and more
I've had good experience with 2GB heap dumps. Actually dumping it was, in my experience, pretty quick. It was essentially as fast as the machine could do that much sequential IO. You get a lot more detail, like what was in those Strings that took up the whole heap. That is usually invaluable for diagnosing what's really wrong.

Actually analyzing a multi-GB heap dump takes 2-3x as much heap for the analyzer. The jhat tool that ships with the JVM is perfectly capable of analyzing a 2 GB heap if it has 6 GB of its own heap to play with.

SpikeGronim··on V8: a tale of two compilers
Have you tried HipHop? https://github.com/facebook/hiphop-php
SpikeGronim··on Scaling a Rails Webservice on AWS/EC2 for a #1 iPhone and iPad App
To clarify they said "availability zones", not "regions", which is a huge difference in terms of latency. And yes, you can tell RDS which availability zone to use.
SpikeGronim··on DNA Logic Gates Calculate a Square Root
You'd need a LOT of grass.
SpikeGronim··on Following the 1st link on Wikipedia leads to 'Philosophy' for 93.4% of pages
A small group of contributors make the most edits by count. A diverse group of contributors write the most prose content, usually on a topic that they're expert in. So the core wikipedians are organizing/wikifying/categorizing and that's the bulk of the edits, but the bulk of the content is a different story.

http://www.aaronsw.com/weblog/whowriteswikipedia

SpikeGronim··on Heroku encourages use of www. prefix for domains after DDoS
No, it is a DNS RFC standard behavior: http://stackoverflow.com/questions/3829966/cname-for-top-lev...
SpikeGronim··on Twitter’s First CTO Greg Pass Steps Down
Purchasing a 50% random sample of all tweets in real time is reported to be $360,000 per year [1]. Apparently you can get the 100% feed for a negotiated price. If they can sell many licenses for those feeds, which I think that they can, they have the potential for real profit growth. I too was very skeptical of Twitter's profit potential until this service launched.

1. http://www.readwriteweb.com/archives/twitter_to_sell_50_of_a...

SpikeGronim··on Why you can't really anonymize your data
The k-anonymity threshold changes as other datasets are released. If you are looking at a dataset with my zip code in it you can calculate a k-anonymous version of that dataset. As soon as somebody else releases another dataset with my zip code in it you must now consider both, and anything you released earlier is likely to be compromised.
SpikeGronim··on Programming error voided Green Card lottery results
Many computers have physical entropy sources, so they can create truly random numbers. http://www.cryptography.com/public/pdf/IntelRNG.pdf
SpikeGronim··on OpenBSD 4.9 Released
No. That was thoroughly investigated and no backdoors were found. http://news.ycombinator.com/item?id=2029175
SpikeGronim··on Lessons Netflix Learned from the AWS Outage
There are several ways to do it. Kill all the instances. Use a firewall to blackhole all the instances. Use traffic shaping to degrade the latency or packet loss of all the instances.
SpikeGronim··on Amazon Web Services Downtime Counter
Well then I was wrong. Apologies.
SpikeGronim··on Amazon Web Services Downtime Counter
"Availability zones are permuted randomly for each customer"

This statement is false. AZs map directly to physical facilities. If you and I both ask for instances in us-east-1b they will have lower ping times than if one of us has an instance in us-east-1c.

Disclaimer: I used to work for AWS.

SpikeGronim··on Linus Torvalds on Garbage Collection (2002)
The drawback with multiple processes is that they each have all the compiled bytecode on their heap. When I "import nltk" my heap goes from ~12 to ~36 MB. Add a few more dependencies and you end up wasting a non-trivial amount of RAM on python heaps.
SpikeGronim··on Did the Microsoft Stack Kill MySpace?
I believe that he's referring to the deal where Google paid MySpace for ad impressions. When that fell through MySpace lost a lot of revenue. http://www.dailyfinance.com/story/media/myspace-in-trouble-o...
SpikeGronim··on Building a recommendation engine, foursquare style
Yelp adds places to their database, and they have had mixed success with Mechanical Turk.

http://engineeringblog.yelp.com/2011/02/towards-building-a-h...

SpikeGronim··on Avoiding Full GCs in HBase with MemStore-Local Allocation Buffers: Part 3
That is an awesome GC and I wish I could have it. AFAIK they are having trouble because they mmap/munmap a lot, and virtual memory systems on modern OS don't do that efficiently enough.
SpikeGronim··on No-SQL injection in Mongo PHP
It is a tradeoff between ease of use and security. These sorts of features require the developer to check every single query string consumer or you end up with gaping security holes. That will result in security exploits in any moderately large codebase with multiple developers, it's just a matter of time. I would much prefer to sanitize everything always and force the app developer to spend the 1 line of code to parse into an array when they want that feature.
SpikeGronim··on Did scientists discover bacteria in meteorites? No.
The question is not "are journals biased?" The question is, are more respected journals less likely to publish a falsehood? If the "better" journals have more accurate reviewers or more reviewers then yeah, they will publish fewer falsehoods.

Re: the formula (1-p)^n. It's http://en.wikipedia.org/wiki/Geometric_distribution . If the observers are independent then the formula holds. If they're not then it holds approximately according to how dependent the different observers are.

SpikeGronim··on Did scientists discover bacteria in meteorites? No.
The scientific method is based on the principle that peer review winnows out false hypotheses. If n observers each detect a falsehood with probability p then the probability of missing the falsehood is (1-p)^n. More reviewers and more accurate individual reviewers decrease the rate of false hypotheses being published. There are many flaws in the peer review system as it exists today. That said, journals with more peer review will publish fewer falsehoods than journals with less peer review.
SpikeGronim··on Did scientists discover bacteria in meteorites? No.
He directly addresses their key evidence: the pictures of the supposed organisms. He interprets the images as inorganic and and calls the paper's claims pareidolia. If outside observers look at the same data and don't see what you're arguing for, you're not making your case successfully.
SpikeGronim··on Did scientists discover bacteria in meteorites? No.
Yeah, it opens with snark. But then the article goes through the arguments and figures in the paper and refutes the hypothesis, so it's not empty snark.

Publishing a paper in a fake journal does damage the validity of the claims. Papers with sufficient evidence for their claims can get published in journals with strict peer review policies. By choosing such a crap journal the authors are essentially admitting that Nature or Science would never accept their arguments.

SpikeGronim··on Ask HN: How did you become a hardcore back-end developer?
One follow up re: how I personally learned distributed systems. This was a great course, and the lecture notes are public: http://www.andrew.cmu.edu/course/15-440-sp11/index/lecture_i... .
SpikeGronim··on Ask HN: How did you become a hardcore back-end developer?
Maybe tptacek just has a really great applicant pool ;). You also have to account for specialization. I have no clue how to do optimized gamedev.

If you want more Lamport goodies: "Paxos Made Simple" (distributed transactions done right): http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.69....

"The Byzantine Generals Problem" (harshest failure model known and how to cope with it): http://research.microsoft.com/en-us/um/people/lamport/pubs/p...

An interview where he talks about his approach to systems, particularly formal reasoning and specification: http://www.budiu.info/blog/2007/05/03/an-interview-with-lesl...

His publication list - http://research.microsoft.com/en-us/um/people/lamport/pubs/p...

SpikeGronim··on Ask HN: How did you become a hardcore back-end developer?
Here you go. http://news.ycombinator.com/item?id=2290675
SpikeGronim··on Ask HN: How to hire freelancers specialized in continuous deployment?
Why does continuous deployment help? It helps by pushing many small updates instead of a few large ones. For a large code base with many developers this is a big benefit. To use it you need excellent automated test coverage and a reliable deployment tool. For a small team, it is probably a waste of time to setup.

I recommend focusing on only the most important tasks for making your product "something people want" (to quote pg). If you're spending a lot of time wrestling with deployment, automate it. If it is a few minutes a day, focus on other things.

I'd also make sure to think carefully about which components you do and do not learn deeply. If Capistrano is important to your product and you're spending time with it, learn it yourself. If you're spending more time on frontend website app development, learn a web dev framework instead. This is a judgement call.

← PreviousPage 3 of 6Next →