HNHacker News
TopNewBestAskShowJobs

ericlavigne

393 karma · joined August 22, 2008

http://ericlavigne.net

http://github.com/ericlavigne

http://ericlavigne.wordpress.com

.

submissionscomments
ericlavigne··on Top Mistakes in Behavior Change
The best part is the link to captology at the end. I especially like this video. (I replace "simple" with "easy", because I think it's a better description of what he's talking about.)

http://vimeo.com/2094487

The difficulty/easiness of an action has six components: time, money, physical effort, brain cycles, social deviance, and non-routine.

Thus, the overall difficulty/easiness of an action depends on the resource profile of the person performing that action. That profile varies wildly from person to person, as well as according to context. Awareness of your own resource profile is important for self-control, and awareness of other people's resource profiles is important for persuasion.

The captology site also discusses using triggers to tilt the odds in your favor. The most effective variety of trigger depends on both difficulty and motivation level.

http://captology.stanford.edu/projects/behaviordesign.html

ericlavigne··on A tour of the Clojure landscape
That's similar to what I'm aiming for :-)
ericlavigne··on A tour of the Clojure landscape
I was imagining using the number of watchers and forkers as a measure of popularity. Looking at overlap based on WHO is watching/forking sounds like a better idea. Thanks for the suggestion.
ericlavigne··on A tour of the Clojure landscape
I will definitely create an auto-refreshing version eventually. For now, though, I'm trying to stay focused on my original goal. As I mentioned at the top of the article, I'm trying to create an entire directory of Clojure libraries. That directory will tell you about the relationships between libraries and help you to find specific libraries that could help your project. There could also be a list of featured projects, which will deliberately be spread all over the network of projects.

For now, I need to focused on improving my calculations, fetching all the data I need (what I showed in the article is just the tip of the iceberg), and finding better ways to infer relationships between projects.

ericlavigne··on Developer-driven development
> I'd highly suggest reading Drive by Daniel Pink.

This video shows Daniel Pink delivering an 18-minute presentation at TED on the same topic: http://www.ted.com/talks/dan_pink_on_motivation.html

ericlavigne··on Arbor.js - HTML5 graph visualization library
The sample project on Github includes some interactivity - dragging and dropping nodes.

https://github.com/samizdatco/arbor/tree/master/docs/sample-...

ericlavigne··on Reddit/HN clone in Clojure
That's an interesting article. While I feel less certain of my original position, I am still skeptical about a timing attack based on the time required to compare two password strings for equality.

Note that while the article deals with similar sources of noise, it also deals with a larger signal. They are trying to time a decryption process, which has a high computational complexity by design. We are talking about timing the difference between checking for equality of the first few characters of a string, versus checking for equality between all characters of strings that are unlikely to be more than 20 characters long.

Chrome tells me that it took 109 milliseconds to load a 50-line stylesheet on my personal website.

http://ericlavigne.net/

A quick and dirty experiment showed that the following comparison of short strings takes between 3.5 and 5.9 milliseconds for 10,000 runs.

(def partial-password "abra")

(def guess1 "abrab")

(time (dotimes [i 10000] (= partial-password guess1)))

Whereas a similar comparison of longer strings takes between 5.8 milliseconds and 6.0 milliseconds.

(def password "abrakadabra")

(def guess2 "abrakadabl")

(time (dotimes [i 10000] (= partial-password guess1)))

So the operation we are trying to time shows a lot of variability even if you can isolate it by running that code directly in a terminal, and a typical small HTTP response takes up about a million times more runtime.

Yes, these are very crude estimates. Good profiling is much harder than this. Still, if I knew this was the only security hole in my application, I'd be feeling very safe.

ericlavigne··on Reddit/HN clone in Clojure
The difficulty of programming depends a lot on your tools. I haven't used Play!, but I've had more experience with Java, Java frameworks, and Java libraries than is healthy. They tend to make programming a lot harder than it should be.
ericlavigne··on Reddit/HN clone in Clojure
"Also, the password authentication finishes early if it detects a mismatch between the given password and the one in the database. This makes it fairly easy for an attacker to get people's passwords with a straightforward timing attack. To fix it, always go through all the characters in the strings to compare them."

The password check is a database query that, since there are no indices on the users table, will check for string equality in every row of the table. Timing the response tells you a lot about the number of users, and the instantaneous server load, not so much about how closely the latest guess matches someone's password.

Even with a more optimized program, I'd be surprised if "fairly easy" were an accurate characterization of the effort to separate timing of comparing one extra character of a password from all the other stuff going on during a request: database access, routing, parsing query parameters, load from other requests, garbage collection pauses, network latency... The signal-to-noise ratio is just too low.

ericlavigne··on Show HN: My Weekend Project - Multiplayer TicTacToe
Nice work.

After waiting 10 minutes for an opponent, I opened a second tab and played against myself. Until your application becomes immensely popular, and this issue goes away, it would be nice to have an estimate of wait time.

Just keep track of recent "new opponent" events (keeping times of the most recent 10 events is sufficient) such as new visitor arriving, game ending, or server starting up (the last one just handles the edge case when you are the first player to load the application). Time elapsed since the earliest event (including only the 10 most recent events) divided by the number of events (again, this is at most 10) yields a reasonable estimate of wait time.

Alternatively, you could pair someone with a computer player if they've been waiting for more than a minute. https://github.com/ericlavigne/tic-tac-toe/blob/master/src/t...

ericlavigne··on Show HN: My Weekend Project - Multiplayer TicTacToe
This application looks like it would make a very nice introductory example for asynchronous web programming. Is the source code available?
ericlavigne··on "In Haskell we think for quite a long time before starting typing"
It looks like you started with some important points, and then let them lead you to the most unproductive possible conclusion.

> The more bugs in the system, the shorter you can think ahead.

Very true. Too many bugs prevent me from thinking ahead, forcing me to program very slowly by trial-and-error.

> If you have to work with some buggy system over which you have little or no control, which is often the case, you are limited in how much you can think ahead.

There are many buggy systems over which I have little or no control. I often, however, can decide not to work with such systems in the first place. Since such buggy systems have so much effect on my productivity, it is worth putting a lot of effort into avoiding them.

> This may be why so many Haskell examples are math-centric: it allows you to look the farthest into the distance.

It may also explain why Haskell has so much built-in error checking, why Haskell programmers have been pioneers with respect to new testing strategies (Quickcheck), and why Haskell programmers try to separate `pure` and `impure` code so that as much of their program as possible can be math-centric. They are trying to spend as little time as possible with buggy code that slows them down.

> That's no doubt true, but that can only get you so far

Thinking ahead is great only under ideal conditions, as you pointed out. If you accept whatever conditions are there, thinking ahead can only get you so far. Taking responsibility for such conditions, and trying to change them, can get you much farther.

--------------

I actually don't use Haskell very much, but Clojure has a lot of similarities. Like Haskell, Clojure has a lot of support for abstraction and allows you to do a lot with very little code. Perhaps even more importantly, Clojure libraries tend to be simpler, easier to understand, and less buggy than their Java counterparts.

ericlavigne··on Staging Servers, Source Control & Deploy Workflows, And Other Stuff
Patrick's reference to "capacity problems" was in regards to deciding whether to clear memcached. In a large scale deployment, such as Facebook, clearing the caches could overwhelm the servers. Patrick is small-scale enough to not worry about that, and prefers clearing the cache to avoid stale-cache-related bugs.

I do agree regarding how nice it is to use Heroku. My only issue with them is that they only support Ruby and Node.js, so I need to take my Clojure applications elsewhere.

ericlavigne··on Lift: 10x more productive than any mvc framework
What is your strategy for making money with boring crud applications? Consulting? In-house software developer? How much are you earning with this strategy?
ericlavigne··on Captain Crunch needs your help
The amount of money could be discussed in more detail on http://savingcaptaincrunch.com/

There is already a paragraph towards the bottom that discusses how the money will be used. It could also say that you are still researching treatment options. $10,000 is an optimistic estimate for what it will cost to save your arms, and you're collecting up to $30,000 which will help you to get the best medical care possible. Any money not spent on medical care will be returned.

Just throwing out an idea. I've never run a charity campaign and don't know what works. Just make sure to get those links on webcrunchers so everyone knows that it's really you who's asking for help and not some scammer. ;-)

ericlavigne··on Captain Crunch needs your help
The profile for that Twitter account has a broken link:

http://www.en2go.com

It is common for celebrities to be impersonated on Twitter, and this is not a verified account.

John Draper is a security expert. His MySpace page has a video of him talking about how to avoid getting scammed online. Surely he understands the need to establish his identity before asking for money online. Yet, I don't see any mention of this situation on his website.

ericlavigne··on Captain Crunch needs your help
Mark Abramov said the following on the Facebook page you linked. I hope John Draper follows this advice (and that the surgery goes well):

"Captain, it would be great if you connected your known web identity (webcrunchers.com) with your identity on facebook (this account) and/or the donation website. Put a link on the sidebar or something because some people get suspicious.

Hope you get well soon."

ericlavigne··on Captain Crunch needs your help
There's no mention of this on John Draper's personal website or MySpace page. How do we know this message is from John Draper?

http://www.webcrunchers.com/

http://www.myspace.com/jdcrunchman

(Found webcrunchers via Wikipedia http://en.wikipedia.org/wiki/John_Draper and found MySpace via webcrunchers.)

ericlavigne··on Zed Shaw: Tir Web Framework Officially Up
You can also find continuation-based web frameworks in Common Lisp and Scheme.

http://common-lisp.net/project/cl-weblocks/

http://common-lisp.net/project/ucw/

http://docs.racket-lang.org/web-server/

ericlavigne··on I just need a programmer
I love your front page.

Have you gotten much response from businesses that want to use your service? How are you advertising?

ericlavigne··on Who is living off their startup fulltime?
I just signed up to try it out. May I have an invite?

Name: Eric Lavigne

Email: lavigne.eric@gmail.com

Twitter: ericlavigne

Something I made: https://github.com/ericlavigne/island-wari

ericlavigne··on On Hiring Haskell People
> strict:lazy::manual memory:poorly optimized GC

Replace "lazy" with "non-strict" and I think you're on to something. Strict and lazy both specify a particular evaluation order, but you are talking about leaving the evaluation order unspecified and letting the compiler or runtime decide which evaluation order is best.

I love today's GC, which allows me to mostly forget about memory management, but if GC still meant waiting hours for a collection I would be more inclined to manage my own memory.

Clojure's lazy sequences, combined with doall to force strict evaluation when you want it, seem like a nice compromise for now, but will likely seem archaic when a good evaluation-order optimizer is developed.

ericlavigne··on How I built 7books in under 4 weeks
I highly recommend this free, online book for learning more about jQuery.

http://jqfundamentals.com/

(AJAX is chapter 7)

ericlavigne··on Rebecca Murphey: An Online jQuery Class
Thanks, that makes a lot more sense. My projects so far have included well under 1000 LOC of my code per page. If and when this changes, I will watch out for this issue and consider Closure Compiler as a possible solution.

I also wonder if (runtime-checked) pre/post-conditions could bring much of the benefits you speak of, with the option to use them sparingly and avoid the "drag" part. In other words, make the type annotations optional and only put them where it looks like the extra safety is important enough to be worth it.

In any case, I'll cross that bridge when I get to it. Thanks for the heads up.

ericlavigne··on Rebecca Murphey: An Online jQuery Class
The instructor of this course has also written an excellent book, jQuery Fundamentals, and I am convinced that she would be an excellent instructor as well. The $350 seems steep to me as well, but I might be willing to pay it if I expected jQuery to be my main development tool.

(I'm more interested in Clojure, and would have gladly paid the $1k in expenses to attend the Clojure Conj if my employer hadn't offered to cover it. http://clojure-conj.org/ That was just a two-day event, rather than a whole month of training.)

ericlavigne··on Rebecca Murphey: An Online jQuery Class
Hi, I'm you from two years ago (loving jQuery, moving more code from server to browser, never used Closure Compiler). I'd like to take your advice, but I'm confused about something.

It sounds like you said (1) you had a great experience with jQuery, (2) writing Javascript is a much worse experience with Closure Compiler, (3) therefore use the Closure Compiler and not jQuery.

Could you please explain why you like the Closure Compiler, so I can understand the jump to (3)?

(1) "running circles around fellow devs", "JS, with it's loose typing and object notation was just a fast place to write code" (2) "now, I'm writing typed code, in a non-typed language, and there's not much to really like about the language" (3) "Start using the Closure Compiler, and use less jQuery"

ericlavigne··on Clojure Web Infrastructure
Leiningen works well on Windows. Look for discussion of lein.bat in Leiningen's README.
ericlavigne··on Ask HN: Who Plays Go?
I just found out that Go is a popular game among Clojure programmers. This is how the speakers at the first Clojure conference celebrated the night before the conference.

http://twitter.com/cemerick/status/28359615311

ericlavigne··on Ruby Koans. Best way to learn Ruby.
There are also functional koans. Same idea for some other languages.

http://github.com/relevance/functional-koans

Each of the following languages has its own branch: Clojure, FSharp, Haskell, and Scala.

ericlavigne··on Structure and Interpretation of Classical Mechanics
The dimension of the configuration space of the juggling pin is six: the minimum number of parameters that specify the position in space is three, and the minimum number of parameters that specify an orientation is also three.

The quote comes from section 1.2 on configuration spaces. http://mitpress.mit.edu/sicm/book-Z-H-9.html

Can somebody explain this? Isn't the number of parameters that specify an orientation two, totaling five?

Pick two atoms in the pin and specify the location of one atom. Now the other atom can only be located on a sphere around the first atom. The sphere is a 2d surface for which you need two parameters.

It is not enough to specify the position of two atoms. You need to specify the positions of three atoms. The first atom can go anywhere, so it contributes 3 parameters. The second atom is limited to the 2-D surface of a sphere around the first atom, so its position only contributes 2 parameters as you said. The third atom is limited to the 1-D edge of a circle around an axis that connects the first two atoms, so its position contributes 1 parameter.

If you choose the position of the point of a pencil, and also a point in the center of the pencil's eraser, the pencil can still spin, with the pencil lead as the axis.

Another problem is that you can encode two real numbers into one, for example by interleaving digits. So you could specify the entire pin with one real number. What exactly is the problem here and how can you eliminate it? You need to impose more conditions than simply continuity, because you can make a continuous bijection [0,1] <-> [0,1]^2?

The concept of dimension of a vector space is handled much more rigorously in proof-oriented linear algebra textbooks. This book gives a loose definition for the dimension of a configuration space, which is just good enough to be able to follow the issues they are talking about. You looked too closely at their definition and discovered a flaw. Dimension is not really the number of parameters required for encoding a position in the space, but this can still be a good enough working definition for many problems if you don't get too fancy about your encoding.

← PreviousPage 3 of 5Next →