1,476 karma · joined March 30, 2007
my public key: https://keybase.io/inklesspen; my proof: https://keybase.io/inklesspen/sigs/2c2qJegXY1ShQoGtmBOkBKFB4fkCAXJlyMX3N8U8X1Y
On the other hand, you can still put Apple on your resume, so it's not all bad.
This refers to "puffery", a common advertising/marketing term. For example, the owner of a hamburger restaurant is permitted to claim he serves "the best hamburgers in the world" without actually producing an empirical study backing it up, because that claim is puffery, and nobody would reasonably take it literally.
I don't know which claim of Apple they are saying is puffery, but they do produce a lot of it ("magical" iPad, anyone?)
2. Cryptographically strong random numbers isn't strictly required for a bcrypt salt, I guess. But if I'm building something which I plan to share with other people, I'd rather err on the side of too strong.
I found myself in this situation when I tried to find a bcrypt implementation for Common Lisp. There wasn't one. Folks in #lisp suggested I adapt the blowfish implementation in Ironclad, since 'bcrypt is just blowfish anyway'.
I ended up writing a Lisp wrapper around one of the C implementations, a process documented at my blog (http://www.letsyouandhimfight.com/2010/07/14/cl-bcrypt-a-fir...), but it's unsatisfactory for a couple of reasons:
1) Both the current C implementations are designed to be integrated into libc. The Openwall implementation does have the code factored out into its own file, but there is no support structure for building a shared library. (Python's bcrypt bundles a modified version of the Openwall C source directly with it, for example.) Common Lisp's FFI is intended for working with installed shared libraries
2) There appears to be a bias in the Lisp community towards pure-Lisp implementations, for (hopefully obvious) reasons, so an implementation as hacky as what I came up with is unlikely to see much use.
If I do go back to trying to write a webapp in Common Lisp, I think I will find myself having to reimplement bcrypt in Common Lisp. First, I'll have to find a sufficiently portable method of getting cryptographically secure random numbers; as of the writing of that blog post, there wasn't one that I could find anyone recommending. The more difficult part will be to convert the C code into Lisp code without missing any places where operations on the C types don't precisely correspond to the same operations on the Lisp types (due to, say, overflow).
I'm worried I might get something wrong, but I can't just use the crypto code written by wiser folks than I, because, at least in the Common Lisp community, that code doesn't seem to exist.
Sign up (no email or password, just a UUID), track as many authors or stories as you like in one Atom feed. It will let you know when wordcount changes even if there's no new chapter, or when your favorite author has a new story.
True, France has had some steps backwards lately, such as the expulsion of Roma. However, I think it's still reasonable to hold the middle eastern countries to a higher standard than they currently maintain. So I'm not sure what you mean by "it also helps that Western countries are eroding freedoms"; it helps who? what?
This sacrifices availability. Remember, the cluster doesn't include only the servers; it also includes the clients, since ultimately the point of a database server is to provide the data to the clients upon request.
In the rest of your post, you seem to be sacrificing consistency; one server is down, and thus not receiving any updates from the other servers when data gets updated.
I'm not sure you understood the point of the article, so I'll try to restate it: When part of your system goes down (and it will), you can choose between refusing requests, in which case you sacrifice availability, or serving requests, in which case you sacrifice consistency, since the part of the system which is down cannot be updated when you update data, or cannot be queried in the case of data which is insufficiently replicated. You _cannot_ choose both, since that would require communicating with the downed server.
Granted, many of them limit shariah law, such as in the case of Jordan, which limits it to "matters involving personal law such as marriage, divorce, inheritance and child custody." But they still have it.
It's a simple "personal portal", I guess you'd call it. My email address is the first thing listed, followed by my erratically updated programming blog, github, twitter, flickr, linkedin, and resume.
I'd rather keep all those links in one place and just hand out my domain link, rather than have to update things everywhere when I add a new link.