HNHacker News
TopNewBestAskShowJobs

jamess

301 karma · joined April 15, 2008

submissionscomments
jamess··on Is this a good site idea?
It doesn't personally interest me, but I can imagine there are people who would use it. Why don't you prototype it on Ning and see if the idea gets any traction? That would seem like a quick and easy way to get feedback.
jamess··on Ask HN : Startup and exclusivity contract
If you're going to enter in to any sort of exclusive contact, you're going to want to make sure that the contact specifies some minimum sales volume that you are happy with.

If they won't commit to any such term, or the volume is too low then walk away.

jamess··on Ask HN: what tunes are you working to at the moment?
Ah, my favourite vanity topic. This week I are mostly listening to Survival of the fattest by Prince Fatty.
jamess··on Ask HN: Which job to take?
To some extent, yes, this is short sighted. Languages are all much of a muchness. A decade ago, Perl was the flavour of the month. All the hot new sites used it. Today the same niche is filled by Ruby, and Perl is something of a pariah amongst scripting languages (though still my first choice for anything that needs prototyping.) Whatever flavour of the month you happen to like today will inevitably describe the same arc. That's just the nature of the business.

The good news is that all these skills are transferable. Becoming a better Java programmer automatically makes you a better Python programmer, and vice versa.

What isn't transferable is domain knowledge. If you want to make something of yourself in this industry, you need to specialise in something. Learn everything there is to know about something, be it networking, writing compilers/virtual machines, security or operating system design, etc. If you don't, you're essentially doomed to a career of moving bytes from a to b, applying some trivial transform to them on the way. Which, incidentally, describes neatly the vast majority of web development.

jamess··on Ask HN: Which job to take?
I'd go for the IBM position, regardless of which pays more. For one thing, the advantage of working at a large established company is they'll teach you how to write software. There are a truly vast number of things about writing software professionally that a CS degree doesn't prepare you for.

You could do a lot worse than spending a couple of years at IBM. If your alternative is a web development company, you'll almost certainly be doing more interesting work there.

jamess··on Ask HN: Clients are gone, lots of debt, what would you do?
There are things you should do right now to deal with the debt. First off, the rack space contract. You can almost certainly get out of it by phoning the company and explaining that the choice isn't between cancelling the contract now or getting paid for another two months, but rather cancelling the contract now or fighting other creditors over the non-existent assets of the company at liquidation. As long as you can talk to a real human being who is authorised to make a decision, then that one is a no brainer for them.

Secondly, I think you'll probably find that declaring the company bankrupt won't free you from liability for most of the debt it owes. You should try your hardest to deal with both the corporate and personal debt through some route other than bankruptcy. It isn't a totally unmanageable sum, but it could quickly get that way since we're talking about credit cards here.

I guess your best bet is to look for a full time job as soon as possible. In the mean time, phone your creditors and explain the situation. If they're nice you'll probably be able to organise some form of payment holiday until you're earning again, with a more reasonable rate of interest. With the current economic climate, my guess is lenders are just happy if their customers intend to pay back what they owe, and they'll bend over backwards to help you.

Anyway, sorry to hear about your situation. Its a tough break becoming victim to the economy through no fault of your own. Hope some of this helps.

jamess··on Ask HN: 37 signals loathing mixed content - A possible solution?
Your fundamental assumption is totally wrong. You simply cannot calculate the signature once and then store it and use it forever after, even for static content. That leaves you open to a whole class of attacks from a simple replay on up. To protect yourself, you'd need at minimum a nonce supplied by the client per request.

You've given no thought to exactly what the signature would be over, nor how having one or more untrusted caches between you and the client might affect the content. If you think you can merely sign the payload, not the headers, think again. Where exactly do cookies live? What effect can the status line have on a client's behaviour? Now ask yourself, what are caches allowed to do a request without stepping outside the bounds of the standard? Yes, exactly.

You haven't addressed at all how the client would even get hold of the public key needed to verify the signature. You haven't addressed what the signature is over in the event the server uses some content encoding like gzip, or the chunked encoding. You don't even add the obvious and trivial optimisation that the signature would be best sent as a trailer rather than a header, neither do you define the behaviour if the server wishes to send trailer fields after the HTTP payload.

The only thing that can be concluded from this is that you don't really understand security or indeed HTTP. I'm baffled by the attitude that you admit you don't know anything about these topics, but you're trying contribute something to the field anyway. This is completely arse backwards, and in no other field of endeavour would anyone even consider tolerating it. Would a peer reviewed biology journal look kindly on me if I sent them my thoughts on protein folding? I think not.

The attitude that any software engineer can do security is prevalent in the industry and gets us in to ridiculous amounts of trouble. You wouldn't believe how many software and hardware products I've seen that are completely broken security wise thanks to this. If you're interested in the field, I'd suggest starting by reading the canonical introductory text, Secrets and Lies .(http://www.schneier.com/book-sandl.html) This is not a field anyone is going to thank you if you want to learn on the job.

jamess··on Ask HN: 37 signals loathing mixed content - A possible solution?
I think that would be a fair assessment, yes. Classic case of person with no security training or experience trying to do security. The more I read it, the more painful it seems. You have to do a TLS handshake with the server anyway to get the bloody keylist (apparently the idea of certificate extensions is a bit too much to grasp) so if you have TLS, and you've already established a session why on earth would you need or want to employ this hack?
jamess··on Ask HN: 37 signals loathing mixed content - A possible solution?
Ever hear the term "computationally expensive"? Here's a hint, modular exponentiation of very big numbers is an extremely expensive operation. Encrypting a block of plaintext with a bulk cipher is a very cheap operation. Thanks to the marvels of HTTP keep-alive and TLS session resumption, serving the content over HTTPS is almost guaranteed cheaper than employing this crude hack. This is not even to touch upon the problems not addressed like the HTTP response is designed to be mutable, or that this "solution" offers no replay protection. Also, two words; Hash MAC.

Want a real solution to the problem, here: http://www.sun.com/products/networking/sslaccel/suncryptoacc...

jamess··on A program that is able to disable network connections for a designated amount of time
For Linux, and probably a mac you can do such a thing with a small shell script, possibly even running it from cron if you so desire. Just issue an ifconfig down for the appropriate interface, and possibly swap the sudoers file if you're really weak.
jamess··on Reverse engineering the iTunesDB File Format
Back in the day, I was heavily involved in reverse engineering iTunes to figure out the "authentication" hash sent with DAAP requests. I very quickly got sick of chasing my tail every time Apple unilaterally decided to change their protocols for the sole reason to disable third party interoperation, incidentally breaking old versions of their own software just for the hell of it.

I'm sick of Apple and all their works. If you're a software engineer, and you value open standards and competition, you should never, ever buy an Apple product. Their anti-competitive actions, from breaking their software through misusing legal instruments right up to controlling which apps one can and cannot write for the iPhone, reveal a fundamental distaste for standards, co-operation and even the law.

Every moment spent trying to interoperate with Apple is a moment wasted. For the free software community, most of us have stopped chasing our tail and gone to open standards such as UPnP media streaming. Apple's culture is that of the 70s, the dark ages of personal computing. I can only hope that people inside their organisation like Stuart Cheshire can make some sort of operational change.

jamess··on Twitter Acquires ‘Values of n’, Adds Rael Dornfest To The Team
Call me a bluff old traditionalist, but I really fail to understand new economy 2.0. Companies that have no revenue buying other companies that have no revenue and rejecting purchasing attempts from other companies who have no revenue who would pay for them in shares the value of which scarcely exceeds the value of the paper they are printed on.

Is there some ultimate strategy that the twitters, facebooks and youtubes of this world have that I'm too narrow minded to see but will make these companies bigger than Jesus, or is this the same business model as new economy v1?

jamess··on Rent Books Netflix-style with Online Book Rental
Oy Vey.

You know why netflix didn't happen before everyone had DVD players? Because VHS tapes are bulky and heavy. They cost more to send, and don't fit through many letter boxes. I can't imagine how you can possibly do this with any reasonable profit margin, and it isn't any more convenient than simply buying the books.

jamess··on Ask HN: Importance of a Confirmation Email
You'd be insane to ask for email conformation as part of your sales process. Go to any web store, none of them do it.

Your customer has little motivation to supply a false email address, as they may need support by email at a later date. There aren't any security implications of not confirming the email address in this case.

jamess··on Ask YC: A tough problem - how do I pick African children for a tech scholarship?
Are you sure that's not a bias you're bringing to the situation? I fail to see how it being a "poor country" comes in to the matter at all. You could say the same about any country, that people aren't going to turn down "free money" but in reality they do, on a daily basis. Do you have any evidence to suggest that this is the case, or is that just a knee jerk reaction?
jamess··on Ask YC: A tough problem - how do I pick African children for a tech scholarship?
Have you tried the simplest possible means, merely asking them? Ask students who want the scholarship to apply, and discourage those who already have the means to pay from applying. Then simply award the scholarship to the most able from the group of applicants. Am I being naive in believing that this trivial solution works reasonably well in most other such situations?
jamess··on Offbeat Guides Public Beta: On-Demand, Personalized Travel Books
Aw, man. Don't make me bang my head on the desk.

You can't do this by polling free information from the web! Tourists aren't interested in when the next Linux user group meeting is! You need your own list of events updated from local knowledge. Half the interesting stuff is only advertised by people handing out fliers on the street. That means you need to pay people to gather this information for you, which has the knock on effect that you can't cover the whole world, just the bits of it to which lots of tourists go. Isn't this already obvious to you?

jamess··on Offbeat Guides Public Beta: On-Demand, Personalized Travel Books
I tried a number of cities, your own home of San Francisco, my own of Cambridge, UK as well as some others I'm familiar with like Bangalore and Tapei. I was very disappointed that the San Francisco guide was of far worse quality than the Cambridge guide for example. I would have expected since the company is there, you might have something interesting to say about the city. Apparently not.

The list of events is worse than useless, it's cheap and tacky. For example, the events for Bangalore lists events in places such as Shanghai and somewhere on the Indian coast over 500Km away, as well as events tourists couldn't possibly be interested in such as agricultural machinery expos. You just can't do this sort of thing by pulling events unfiltered from external sources, that just doesn't work. Full stop. I want a sensible listing of events that I can filter by my interests, each one with a map of the location and public transport details.

The issues you have can't be fixed with copy editing. You simply can't produce a guide to a place you've never been, and you really shouldn't try. This talk about covering a "long tail" of destinations depresses me. Leave that stuff to wikitravel, you should be producing a polished commercial product. At a minimum you need to at least have had one person representing the company visiting each place you produce a guide to. You aren't in the business producing a general purpose guide, you're in the business of knowing everything there is to know about a city and giving people a decent interface to filtering it. Quite frankly, I don't see how you can do that without a team of people going to a place for at least a month.

Some features I'd pay for:

* Suggested itineraries for days, based on a database of places and activities filtered by my interests and biased by predicted weather.

* Some sort of more/less detail slider for each page enabling me to customise the text.

* Complete and up to date public transport listings for the destination, cross referenced with the events and places I've chosen to add to my guide.

Above all, if I'm paying for something that costs about the same as the rough guide I want something at least as good quality as the rough guide. You aren't going to get that with wikitravel and creative commons photos.

jamess··on Offbeat Guides Public Beta: On-Demand, Personalized Travel Books
A great idea poorly implemented. Most of the info seems to be cadged without attribution from wikitravel, often with the formatting poorly stripped.

I'd really love to be able to create a guide tailored to my interests, but this isn't anywhere near it. The best thing they could do right now is discard the whole database and start small, with one city at a time done in extreme detail. Know how to get from any point A to point B in a city at any time of the day, by every means and keep that info up to date. List every possible tourist attraction, categorise them and keep that list up to date too. Get more detail on local events. Contract a local contact on a piecework basis to help maintain the city guide and add to it as appropriate. If this is too expensive, do one city and seek funding based on that demo.

As it stands, the guides offered give far less value than an off the shelf travel guide.

jamess··on Worst Idea Ever: SSHKeygen.com
Oh dear god. I can only hope this is an attempt to crack idiots servers, rather than a serious service. I love the "it's your responsibility to secure your key in transit" disclaimer.
jamess··on How can people not use Firefox 3?
I installed a firefox 3 beta some time ago and hated it. I'm still using firefox 2, though I guess at some point soon they're probably going to abandon the branch and push firefox 3 on me via automatic updates. I'm not terribly looking forward to it.
jamess··on Ask HN: what is wrong with asp.net?
Not to mention that the average hacker is usually far better equipped to manage a Unix flavoured server than a Windows server. With small companies who can't afford to have a full time sysadmin on staff, what you know is a powerful motivator. Windows server administration simply isn't the type of thing you pick up while using Windows, while the basics of managing Unixen is something you pick up while using Unix boxes.
jamess··on HTTP Error 418: "I'm a teapot"
It's not really a joke, it's actually from an RFC. The IETF has a noble tradition of publishing amusing RFCs on April 1st. cf. IP datagrams on Avian Carriers, Electricity over IP et al.
jamess··on In Defense of XML
I simply don't buy this argument.

Who cares if there's a wealth of experience out there regarding XML? When you're designing software, if your primary goal is making it easy on your developers, YOU'RE DOING IT WRONG.

There is one situation, and one situation only, where XML is the right tool for the job. That situation is where a computer must produce and/or consume a file that must be read and/or written by a human. That's it. The only time. So, XHTML, ja. SOAP, nein. If a computer is consuming data another computer has produced, why would you want to encode that data in something so hard to parse, and so potentially ambiguous as XML? It's lunacy.

jamess··on Why does Google adsense have an invalid https certificate? (looks SCARY in Firefox 3)
The problem with "not caring who you're dealing with", is that it raises the possibility that who you're actually dealing with is a man in the middle, who is snooping on your traffic. If you get warned that a certificate is self-signed or signed by an untrusted authority, then you either have to check the key fingerprint or take a chance. Not that I'm happy with firefox taking this choice away from you, mind.
jamess··on Why does Google adsense have an invalid https certificate? (looks SCARY in Firefox 3)
They used to have a far more expansive certificate, with a subject alt. name good for *.google.com, and I think google.com as well, so they could use it on subdomains like adsense.google.com. It was a really handy server for testing TLS implementations with big complex certificates. It was also sort of illegal, having both a common name and subject alt. names. However, the certificate expired and they got a new one early this year, and now it's some bog standard thwate issued cert, good only for one year (Hello! You have billions, you can afford to get a certificate issued for more than a year at a time guys!)

Anyway, you should really only be warned in the event of domain name mismatch. This isn't a fatal error. I guess firefox has gone overboard on the treating users like idiots front.

jamess··on Ask YC: Want to learn about GPS/Location Based Programming. Where to start?
There's plenty of code on the Nokia wiki, including a complete compass application: http://wiki.forum.nokia.com/index.php/GPS_Compass

(See also, the location category index http://wiki.forum.nokia.com/index.php/Symbian_C%2B%2B_Locati... )

jamess··on Ask YC: Want to learn about GPS/Location Based Programming. Where to start?
That's nonsense. I know of no phone or device that does this, it's not like the calculations needed are exactly challenging even for your typical phone with a 200Mhz arm chip.
jamess··on 18-year-old hacker need life advice
By all means take a year off before University, but I'd highly recommend going. You'll find that lots of places won't even give you an interview if you don't have a degree, no matter how smart you are.

However, here's something to think about. The degree doesn't need to be Computer Science/Software Engineering. Take a technical degree that interests you. Speaking as a Computer Science graduate, the typical Computer Science degree course is fairly tedious. Take a mathematics degree, or a science degree, or even a mechanical engineering degree. Whatever your interests you most.

During your holidays get some decent software engineering internships in, and you'll be set up.

jamess··on Uncontacted Amazonian tribe photographed
Nah, but now Jacob has told them they need to move the village.
← PreviousPage 2 of 4Next →