HNHacker News
TopNewBestAskShowJobs

alexjeffrey

342 karma · joined July 18, 2012

http://www.alexjeffrey.me
submissionscomments
alexjeffrey··on Ask HN: How do you find freelance/contract gigs?
in my experience, if you can grab a couple of not-too-underpriced gigs on a freelancing website (my preference is PeoplePerHour as it's less price-war-y) and can get a few regular clients from that, they'll be more happy to pay a reasonable fee for a reliable and familiar developer. Bear in mind that there are a LOT of unreliable and flaky developers on these sites so once you've proven your value to someone they'll be more likely to pay higher rates to retain you.
alexjeffrey··on Facebook Launches Flow, Static Type Checker for JavaScript
a cryptographically secure pseudorandom number generator would be nice, too.
alexjeffrey··on Tesla: The Origin Story
no problem at all - thanks for all the hard work you put into the book!
alexjeffrey··on Tesla: The Origin Story
for anyone else wanting to read Elon Musk's story in more depth, I can't recommend "The Engineer" by Erik Nordeus enough. He basically compiled titbits of information from various interviews and articles and reconstructed the timeline of Elon Musk's public life into a great biography.

https://leanpub.com/theengineer

alexjeffrey··on Mark Zuckerberg Answers Q&A in Mandarin at Chinese University
white privilege? don't you mean anglocentricism? the bias would be equally present if Mark was African-American or Asian-American.
alexjeffrey··on Can Google's search engine find profits? (1999)
we still are - plenty of startups don't even start making money before they're acquired.
alexjeffrey··on Mining Bitcoin with pencil and paper: 0.67 hashes per day
truly the most hipster art project of all time. I'd back it!
alexjeffrey··on jQuery.com Malware Attack Puts Privileged Enterprise IT Accounts at Risk
... and it's impossible to know for sure that a hash is secure against collisions. For example, MD5 was the standard for hashing for quite some time but is considered broken today due to attacks that have since been discovered. By implementing the hashing using merkle trees, you increase the avalanche effect relative to the data, making it much harder to force a collision.
alexjeffrey··on jQuery.com Malware Attack Puts Privileged Enterprise IT Accounts at Risk
realistically you would want to use a merkle tree to hash the source, to make it more secure against a chosen plaintext collision, but aside from that this'd be a great addition.
alexjeffrey··on Sinquefield Cup: One of the most amazing feats in chess history
it should also be mentioned that Jerry's commentary is _hilarious_ - he's basically the SeaNanners of chess.
alexjeffrey··on Richmond Italian restaurant waging war on Yelp
but with all the publicity surrounding their actions, will they become more well known which will in fact counteract their star rating on Yelp? My guess is yes.
alexjeffrey··on Boeing-SpaceX Team Split Space Taxi Award
you say that, but minecraft is worth actual money because it sells a product that lots of people want to buy and has a lot of potential for further attached products (servers, DLC, etc). A more apt comparison would be whatsapp/instagram/whatever ridiculous social app facebook is buying this week for $X billion, without any revenue or business model to speak of.
alexjeffrey··on Boeing-SpaceX Team Split Space Taxi Award
that's just PR - PR companies wouldn't do so well if they pushed stories that showed their clients in a negative light.
alexjeffrey··on Why Scotland looks like the canary in the independence coal mine
these figures are deceptive considering the UK's comparatively-socialist tax attitude. The biggest thing I would point out is that we have nationalised free healthcare for everyone, which takes a big bite out of PPP but also means that being poor isn't a health concern. We also have a pretty comprehensive benefits system which, although unpopular, provides a large safety net for the unemployed, disabled and otherwise non-working.

The UK isn't some pauper state where everyone's living on the breadline, we just take a different approach to the USA.

[edit] replaced GDP with PPP for better clarity/relevance.

alexjeffrey··on Black Triangles
I think black triangles are only really possible if you're working on software architecture - that bit when you "go into the tunnel" and are working in purely abstract space comes with such a payoff once you reach your project's "black triangle". There's really nothing like it, it's a great feeling!
alexjeffrey··on Tramadol Is Not a Natural Product After All
I'm not the parent (I'm GP), but my position is that organic certification is good, but the universal association of "natural = good, synthetic = bad" is only harmful.

Yes, farmers pump animals full of chemicals and this should be documented and, if you are concerned about this, it's a good thing that there are organic food certs out there. However, whole industries fuelled by bullshit have sprung up off the back of this very common fallacy. There are people out there who don't take scientifically-proven medicine because it's "not natural" and lean towards quackery like homeopathy, and this is what I'm opposed to.

To reiterate, IMO organic or free-range farm produce is a good thing and I'm sure most people would agree with that. That's not what I was talking about so don't get rude with people based on a misinterpretation of the subject, it's unnecessarily disruptive.

alexjeffrey··on Tramadol Is Not a Natural Product After All
more importantly, the use of "natural" to describe a product with the implication that it being synthetic would be a bad thing is a fallacy.
alexjeffrey··on Practical Kleptography [video]
your assumptions about cryptographically secure pseudorandom number generators (CSPRNGs for short) are incorrect - one of the key requirements of secure random number generation is the inability to predict future state given previous state. See http://en.wikipedia.org/wiki/Cryptographically_secure_pseudo..., particularly the part about the next-bit test.

The bit about RSA aiding the NSA is spot-on though, if dual EC DRBG is in fact backdoored.

alexjeffrey··on Show HN: Hacker Experience – Online hacking simulation game
uplink is fun, and considered a classic of the genre.

In terms of education, the real thing is more interesting - check out places like hackthissite.org or smashthestack.org for some real life (ish) hacking in a contained environment. Hold your breath though as the smell of teen angst may overpower you on some of these sites.

alexjeffrey··on Show HN: Hacker Experience – Online hacking simulation game
I agree, but the race condition kind of kills it - 2 people editing the same file at the same time.
alexjeffrey··on Show HN: Hacker Experience – Online hacking simulation game
looks like fun! I've been holding out for a modern retake on the uplink series or some other fun hacking game.

one UI thing that came up for me - going through the university pages, it wasn't totally clear that the green buttons were actually a "next" button. After I read the software page, I saw the green button said "what if I need help?", thought it was a help button and decided that since I couldn't find a next button, I was free to start playing. Confusion set in when the homepage sent me back to the tutorial.

[edit] in terms of a fix, a simple » or other arrow-icon might fix this

also a few little suggestions that I hope you'll like (as I like this type of game, a lot!):

- Maybe represent the user's balance purely in BTC? the idea of paying hackers in bank transfers seems a little insecure for a security game :)

- You might run into race conditions when editing logs, depending on how it's implemented on the backend - maybe just a checkbox next to each line to quickly delete lines relevant to you? this might ruin some of the fun possibilities re. dropping other people's IPs into logs though.

alexjeffrey··on Interview with an Auschwitz Guard: 'I Do Not Feel Like a Criminal'
There's a term for this exact phenomenon - Little Eichmann:

http://en.wikipedia.org/wiki/Little_Eichmanns

This ties into the concept of the "Banality of evil" which plays out pretty much exactly as you described.

alexjeffrey··on The FBI Says How It ‘Legally’ Pinpointed Silk Road’s Server
I chose the languages above mainly due to their popularity outside the sphere of silicon valley - you are right that I should have included python in this list, but go and haskell are still only popular in a very restricted audience and I myself haven't used them - they may well be better for secure programming, they just didn't come to mind when I was thinking of examples.
alexjeffrey··on The FBI Says How It ‘Legally’ Pinpointed Silk Road’s Server
but on the other hand, it is better than having unknown security properties like e.g. ruby or javascript on node.js. While node is built on the venerable V8 engine which has strong security roots, its core libraries and dependencies are less well explored. Plus javascript is generally a terrible language for secure programming.

I'd rather have ample documentation on how to harden my PHP application than no documentation on how to harden my Node application. Security through obscurity is no security at all. Plus, many of the mitigation strategies are simply rules like "don't use mysql_query" or "use htmlentities with ENT_QUOTES and UTF-8 to escape your output", both of which can be built into a framework. See: laravel.

[edit] downvoting is much easier than formulating a response, isn't it?

alexjeffrey··on The FBI Says How It ‘Legally’ Pinpointed Silk Road’s Server
what would you suggest? for all its faults, PHP has seen a lot of hardening efforts over its lifetime and its security flaws are well known and can be compensated for.
alexjeffrey··on Modern anti-spam and E2E crypto
in my mind, the first email would be encrypted using a public address obtained by asking for the key from the receiver's domain's server, or otherwise leveraging the DNS for the receiver's mailserver.
alexjeffrey··on Modern anti-spam and E2E crypto
having everything come back to money is a good thing though - a user can afford to pay e.g. 1 microdollar per email sent but if a spammer is sending 10 million emails a day, they can't afford that level of operational expense.
alexjeffrey··on First US appeals court hears argument to shut down NSA database
I know I'm going to get called on Godwin's law and/or hyperbole for this one, but this is the exact route Hitler took (using the Reichstag fire) to escalate his authority from Chancellor to Fuhrer.

[edit]

to clarify, the reason I made this comment is to note a case where this strategy has been used in history, as mentioned by the parent post. Not to compare Obama/Bush to Hitler.

alexjeffrey··on Hygiene hypothesis: difference in autoimmune diseases in Russia, Finland (2012)
you make a number of good points, but don't fall into the trap of thinking that autoimmune problems stop with allergies - there are much more unpleasant conditions (like Crohn's disease) that are linked with the same immune system deficiencies/problems.
alexjeffrey··on E-Sports Set Video Gamers Fighting for Real Money in Virtual Contests
a lot of the opening of chess is playing memorized counters to different plays that have been extensively studied - you could fill a library with books dedicated to chess openings, explaining why a particular move is good against another.
Page 1 of 6Next →