HNHacker News
TopNewBestAskShowJobs

elliotanderson

162 karma · joined July 23, 2010

http://hnofficehours.com/profile/username/
submissionscomments
elliotanderson··on .IO domain name reliability issues and how we’re working around them
We migrated from serving production JS assets off our .io domain to .com after we found a number of corporates/schools in Ireland blocking the domain at the TLD level.

Since then, the number of inexplicable error reports has dropped dramatically.

elliotanderson··on Biscuit: a multi-region key value store for your AWS infrastructure secrets
You can use the new AWS-EC2 auth backend in Vault 0.6

https://www.vaultproject.io/docs/auth/aws-ec2.html

elliotanderson··on Kel: An Open-Source, Kubernetes-Based PaaS Built in Python and Go
You should have a look at Deis v2. Built on Kubernetes and has push to deploy.
elliotanderson··on Material Design Lite Components in HTML/CSS/JS
You might be interested in ember-paper and ember-cli-materialize if you are looking at Material + Ember.js

- https://github.com/miguelcobain/ember-paper

- https://github.com/truenorth/ember-cli-materialize

elliotanderson··on SendGrid employee’s account was compromised and used to access internal systems
> I've seen proofs of concept that trivially lift the secrets from Google Authenticator.

Android specific?

elliotanderson··on Lenovo Caught Installing Adware on New Computers
Looks like the certificate and encrypted private key has been found in "Visual Discovery.exe" - http://pastebin.com/N42Qfm5p (credit to @paul_pearce)

More context at https://twitter.com/supersat

elliotanderson··on The Horror of a 'Secure Golden Key'
If not DNS, then via Server Name Indication (SNI)

http://en.wikipedia.org/wiki/Server_Name_Indication

elliotanderson··on What was your best passive income in 2014?
I bought your Math & Physics book a few months ago. Only got a chapter or two in thanks to time constraints, but I really enjoyed the approach. Hopefully I can finish it in the coming months. Cheers!
elliotanderson··on Sublime Text Development Status
$70 is hefty?
elliotanderson··on Mayhem – A hidden threat for *nix web servers
... Because nothing communicates over HTTP except for crawlers, bots and malware droppers...
elliotanderson··on Xkeyscorerules100.txt
Not a Google employee - but the linked file looks more like a simplified DSL for analysts.
elliotanderson··on Plasso: Payments Made Simple
He ran into trademark issues with http://www.plastiq.com. Same payment space, and they beat him to filing a trademark by a year (by his account he was waiting to secure the domain name first, which cost him that year). Ended up getting a demand to transfer the domain to them for free [1]

[1] https://twitter.com/drewwilson/status/446708094911799296

elliotanderson··on Ask HN: Do you have a side project you want to sell?
For websites there is a $19 listing fee and a 10% success fee.
elliotanderson··on Am I evil, or is killing patents just plain fun?
Filing a patent application costs around $180-$280 [1], not including the other Patent Office fees for Examination/Maintenance. Add onto that the legal fees for marking up the claims, charged out in the $XXX/hr range and you are looking at a few thousand easily.

A quick search turned up a 2011 American Intellectual Property Law Association survey suggesting a median cost of $10k [2].

Having in house legal team to take care of it may reduce the costs but Patent Office fees still make it at least a grand to get one. If the community can chip in a few hours to crush the patent then I would think it is time well spent.

[1] http://www.uspto.gov/web/offices/ac/qs/ope/fee010114.htm [2] http://www.quora.com/Whats-the-average-cost-of-a-software-pa...

elliotanderson··on Results of the GitHub Investigation
Based on what evidence?
elliotanderson··on Update on Julie Horvath's Departure
Chris took over the role as GitHub's CEO from Tom at the end of January. Given the timeline in the TechCrunch article, these events unfolded under the previous CEO's tenure so it would be appropriate to reinvestigate the claims independently of any previous findings.
elliotanderson··on What It's Like When the FBI Asks You to Backdoor Your Software
Bit of a risk, considering that impersonating a federal employee is a felony.
elliotanderson··on Finally, A Bill To End Patent Trolling
It's because you can have "good" NPE's. Take ARM Holdings for example, they do not manufacture their own chips but rather licenses their designs to other semiconductor manufacturers.
elliotanderson··on iPad Air
Out of curiosity, what would you consider "revolutionary"?
elliotanderson··on iPad Air
Plenty of third parties already filling that space - I don't think Apple sees the need to move in that direction.
elliotanderson··on Bruce Schneier has changed his PGP key to 4096 bits
Bruce's article on staying secure from the NSA[1] talks about using an air gapped computer to avoid being compromised via the network. If he hadn't been keeping his keys on such a machine previously - recent disclosures may have changed his mind and forced him to regenerate his keys.

[1] http://www.theguardian.com/world/2013/sep/05/nsa-how-to-rema...

elliotanderson··on REST Hooks - Stop the polling madness
I don't see how a company being involved with this "initiative" affects the core concept - it's a net benefit for both API consumer and producer in moving to a subscribe/push model. Less requests, less load, closer to real time updates. Swap Zapier with any other consumer and the result is the same
elliotanderson··on Progressive Enhancement Is Dead
Try viewing meta.discourse.org without Javascript on then look under the hood - it's a pretty easy problem to solve with some <noscript> tags. Other approaches use PhantomJS to create a "rendered" copy that is accessible to primitive clients/scrapers.
elliotanderson··on Upgrading a cPanel plugin
Kinda scary, considering this is the developers website (hosted on the same server as zamfoo.com) right now: http://meccahost.net
elliotanderson··on Introducing GitHub Sudo Mode
How would serving everything through SSL and "enforcing" workstation locks on people mitigate XSS and CSRF attack vectors? Requiring additional privilege elevation drastically reduces this.
elliotanderson··on Status Board
If you are after something similar to run on a TV without having to buy an TV + Apple TV + iOS Device - the guys over at Librato [1] have a post about how they turned a $50 Android mini PC into their office dashboard

1. http://blog.librato.com/posts/2013/03/how-50-can-turn-your-t...

2. http://www.rikomagic.co.uk/

elliotanderson··on The Jellyfish Entrepreneur
I've had a tank on my wish list since I first saw it on Kickstarter.

Sadly, we only have one distributor in Australia and they mark the price up 110% for just a basic tank setup. There's an untapped market over here, only problem is in the distribution channel.

elliotanderson··on Why we're moving away from Ember.js
I've done something similar with a Symfony2 application I'm working on, but with a tweak.

The app is basically one big REST endpoint, but it does some header sniffing to handle requests with a "text/html" Content-Type. If it encounters one, the request to the still goes through and returns JSON, but that response is then injected as a preloaded datastore into the template being rendered. This bypasses the whole double load scenario that Twitter once was. Discourse is a great example of this in action, just have a look at the view-source://

elliotanderson··on Preventing Unsubscribes in Forwarded Emails
Even working on the copy text would decrease accidental unsubscribes.

Something as simple as "This email was sent to somebody@example.org, if you are this person click here to unsubscribe somebody@example.org" then display the email address again prominently on the unsub page

elliotanderson··on Stanford Grad Sues Snapchat Claiming They Stole His ‘Million Dollar Idea’
Kinda reminds me of Whartonite Seeks Code Monkey:

http://whartoniteseekscodemonkey.tumblr.com/

Always good for a laugh

Page 1 of 3Next →