HNHacker News
TopNewBestAskShowJobs

jonafato

242 karma · joined June 2, 2010

jon AT jonafato DOT com

[ my public key: https://keybase.io/jonafato; my proof: https://keybase.io/jonafato/sigs/0nj0parv3VYKXIAOc86v2t0KJCxmdd-0B-vx1_ogRTc ]

submissionscomments
jonafato··on Ask HN: If you use keybase.io regularly, for what do you primarily use it?
Off topic, but related: I have some keybase invites available, and I'm sure others do as well. Contact info in my profile if anyone would like one.
jonafato··on GitHub Security Update: Reused Password Attack
http://www.dongleauth.info/ maintains a list of sites supporting U2F devices. There aren't many yet, but it looks like a Wordpress plugin exists that may end up in core. There are also a handful of additional sites listed in issues and pull requests on the site's GitHub page (https://github.com/Nitrokey/dongleauth).

(I'm not affiliated with the site, I just check it periodically and thought it might be of use here.)

jonafato··on Disabling npm's progress bar yields a 2x npm install speed improvement
This should be used with virtualenv, not as an alternative to it. I have a bunch of libraries and tools in almost all of my virtual environments that are not application dependencies and have no business being installed in my production environment (e.g. bpython, tox, flake8, and neovim). This approach also handles things like a dependency being dropped gracefully (if some library no longer needs a dependency, it magically gets removed from your locked requirements.txt next time you compile requirements.in). Python's package management tools are making great strides (see pip's recent peep-style hash checking support), and pip-compile is a big win in that category in my opinion.
jonafato··on Disabling npm's progress bar yields a 2x npm install speed improvement
This is a good start, but it has issues. You probably don't want all of your locally installed packages in a requirements.txt file. Instead, they should be curated. I've been using pip-compile [0] for a while now (see the author's blog post [1] for a detailed explanation) and have become a big fan of it. With this model, you should enumerate only what your application uses directly and let pip-compile convert this list to a full version-locked requirements.txt. (Shameless plug: I also wrote a bit about why this is the best currently available option for specifying Python dependencies [2].)

[0] https://github.com/nvie/pip-tools#example-usage-for-pip-comp...

[1] http://nvie.com/posts/better-package-management/

[2] https://www.jonafato.com/2015/12/15/Rethinking-requirements-...

jonafato··on The Python Road Not Taken
I'm not arguing there aren't upgrading pains, but --no-site-packages has be on by default in virtualenv for over three years (https://virtualenv.pypa.io/en/latest/changes.html#id31). There are certainly issues when it comes to compatibility between the languages, but I'm not sure that's one of them any more.
jonafato··on Ask HN: Establishing an open source project organization
Regarding assignment, you're not required to have a work for hire agreement in place, and if you do, there's nothing stopping you from releasing code that you own and paid for under the open source license of the project. Take a look at Django's contributor license agreement (https://www.djangoproject.com/foundation/cla/) as well, as it may be a useful construct in your work. Gratipay may make sense here if you're looking to fund general development toward a specific contributor, where as BountySource is a more feature-specific. If you do decide to go the non-profit organization route, your contributions now will be deductible if / when 501(c)(3) status is granted (http://www.irs.gov/Charities-&-Non-Profits/Charitable-Organi...). Either way, your best bet is probably to reach out to the developer behind the project to discuss the details.
jonafato··on Ask HN: Establishing an open source project organization
Can you elaborate on your post? It's currently a bit vague.

There are many examples of organizations created to support open source software: the DSF (https://www.djangoproject.com/foundation/), the ASF (https://www.apache.org/foundation/), and the GNOME Foundation (http://www.gnome.org/foundation/) are a few prominent ones. Are you sure you need this level of formality at this point, though? This carries a certain amount of overhead, and if you mean 501(c)(3) when you say "non-profit", it's a long process that may not go well (http://blogs.gnome.org/jnelson/2014/06/30/the-new-501c3-and-...).

It sounds like you're talking about a relatively new project with a small number of contributors. Would it be possible instead to make an arrangement with the core developer(s) to support the project financially? You may be able to structure this as a normal contractor agreement or via services such as Gratipay (https://gratipay.com/, formerly gittip) or BountySource (https://www.bountysource.com/). This would allow you to contribute while deferring the overhead of an organization until there are more people and resources involved.

jonafato··on PyGotham Python + NYC
Right now, there's no PyGotham specific mailing list. Joining the NYC Python meetup group (http://www.meetup.com/nycpython/) will definitely ensure that you get all the announcements, though. We'll work on getting a mailing list together for 2015 updates.
jonafato··on PyGotham Python + NYC
If you're looking for Python events in NYC, NYC Python (the same group that's putting on PyGotham) does several free events every week: http://www.meetup.com/nycpython/. If you're looking for something more specific (e.g. Django, data-focused, etc.), there are also several other groups that would fit your needs. Feel free to reach out (email is in my profile); I'd be happy to point you in the right direction to NYC tech events.
jonafato··on PyGotham Python + NYC
We're going to start planning PyGotham 2015 shortly after this one ends. Expect an announcement within the next couple months.
jonafato··on PyGotham Python + NYC
Clickable: http://pygotham.org

Registration info: http://pygotham.org/registration/information

Scholarship application (for those who would like to attend but cannot afford a ticket): https://docs.google.com/forms/d/1PYFBd-vFKu_UguO9yeCYKMiI7I1...

Talk schedule: http://pygotham.org/talks/schedule

jonafato··on An iOS Client for the AeroFS Private Cloud
I tried out ownCloud as well, and I ended up moving to Seafile (http://seafile.com/en/home/). I don't have any hard numbers to show for comparison, but it was easy to get up and running, everything is open source, and it seems to handle large files better than ownCloud did for me. Currently using it across ubuntu, OS X, iOS, and android, and I haven't had any real issues yet.
jonafato··on Why open-office layouts are bad for employees, bosses, and productivity
I haven't seen the references you mentioned, but is it possible that the cause and effect here are swapped? It seems more likely that increased drinking leads to increased noise.
jonafato··on Rage Against the Algorithms
I normally disagree with this type of comment, but based on the actual survey they refer to [1], you appear to be correct. The most probable way I see that they've come to this number is by using the other side of "24% of consumers never use online reviews". The rest of the data is "27% of consumers regularly use online reviews" with the remaining 49% checking occasionally.

The way the statement is worded, I feel that many would read it as "A recent survey found that 76 percent of consumers regularly check online reviews before buying" even if that's not how it's written. A better statement would make the breakdown of regular vs. occasional checkers clear.

That said, single word comments don't add much to the conversation. As stated, and if the survey is to be believed, the line is factually correct even if it is misleading. I'm not sure if "bullshit" refers to how you interpreted the statement or the results of the survey. Without clarifying your objection, though, it will likely be ignored by most.

[1] http://searchengineland.com/study-72-of-consumers-trust-onli...

Edit: added link to the survey

jonafato··on Replace Dropbox with BitTorrent Sync and a Raspberry Pi
They released support for file recovery a few days ago, along with their android app (http://blog.bittorrent.com/2013/07/17/now-in-beta-bittorrent...). Instructions to recover files and set the recovery history time here: http://forum.bittorrent.com/topic/16410-bittorrent-sync-faq/.
jonafato··on I tried Google Glass (feat. Don Knuth’s answer on humans & machines)
cache: https://webcache.googleusercontent.com/search?hl=en&q=ca...
jonafato··on Bypassing Gogo’s Inflight Internet Authentication
IANAL, so take the legality of this with a grain of salt:

The airline would not have the right to charge the "thief" because the airline is not the victim. The only people able to charge the polluter (sticking with my other analogy) are those who paid for access to the network or someone representing them. They wouldn't do this because 1) it's kind of a ridiculous thing to do, and 2) the damages are far smaller than the cost of taking action.

The sensible way to do this (if stopping the practice outright was impractical) would be to grant some authority (the airline) the power to issue citations related to the pollution. It's then carried out similarly to regulating noise pollution. This is problematic, of course, because it requires identifying offenders. If we can identify offenders, we can simply stop the offense, so issuing any kind of ticket no longer makes sense.

This brings me back to a point I made above: the airlines will stop this practice. It's solvable, profitable, and generally beneficial to those who want it enough to pay.

jonafato··on Bypassing Gogo’s Inflight Internet Authentication
I don't normally take sides in these arguments, but I think you're misunderstanding the economics of this situation. This isn't analogous to file sharing, because file sharing doesn't affect the availability of the original file. Consider these numbers (made up, but probably not wildly inaccurate):

- Access costs $10

- Total bandwidth available is 5Mbps

- 10 users purchase access for an average of .5Mbps per user

If 10 more users pay for service, the original 10 are getting half of what they used to for the same price. In response to this (see other comments about "gouging"), airlines raise the prices of access. This act preserves some minimum level of service for those who are willing to pay.

If, instead of the scenario above, the second 10 users go on to use the service without paying, the first are "cheated" out of being able to get their minimum acceptable level of service even if they would choose to pay a higher price. When this happens, prices can be set arbitrarily high without having the intended effect of reducing the strain on the network.

Based on this logic, I disagree with your analogy to file sharing, but I also agree with you that this is not theft. It's more akin to pollution than anything else. If one chooses to smoke in a bar that doesn't allow smoking, everyone else suffers. In the same vein, if I access this service without paying, all of the paying users really do get less than they're purchasing.

The airlines are left with two choices here:

1) Plug the hole so this is no longer possible. This is the path they'll choose because it's profitable and it satisfies the already-paying users.

2) Open it up for everyone. This is impractical. If you've ever used Wi-Fi on a Bolt or Mega bus, you know that it can be painfully slow. There's no incentive for the provider to upgrade, because they can't profit by doing so.

This isn't really about taking from the big, bad corporations. It's about taking from your neighbor. It would be great if we had in-air broadband, but until that day, we'll have to find some way to regulate the use of a limited resource to prevent it from becoming over-saturated.

-----

Edit: formatting, clarity.

jonafato··on YC, what is it worth to me?
It's worth noting that if this is true (my gut says it is), what you're measuring is successfulness of companies that go through YC (implies that the company is good enough to be accepted), not that of companies that apply. In any case, correlation != causation. This should be based on how you think YC would benefit you and your company, not potentially misleading statistics.
jonafato··on Ask HN: Will my game benefit from being open source?
To me, it sounds like you'd want to take on a mentor / partner for some sort of profit share. If you describe the game a bit, you might find a few people around here that are willing to help you out.
jonafato··on Ask HN: Downvoting
Therein lies the the problem though. It seems to be the general consensus that people should down vote only for unhelpful / irrelevant / factually incorrect comments, however voting is used to show agreement / disagreement. Before voting, I usually ask myself why I'm doing this. If it's to promote an opinion, I leave it alone.
jonafato··on LulzSec Topples EVE Online, Minecraft, League of Legends and other Servers
To clarify, by "they have to", are you stating a fact or making a demand? One would have thought that Citigroup would have had some pretty tight security as well.
jonafato··on LulzSec Topples EVE Online, Minecraft, League of Legends and other Servers
Probably from Ted Kaczynski:

"David Kaczynski had once admired and emulated his elder brother, but had later decided to leave the survivalist lifestyle behind.[74] He had received assurances from the FBI that he would remain anonymous and that his brother would not learn who had turned him in, but his identity was leaked to CBS News in early April 1996."

http://en.wikipedia.org/wiki/Ted_Kaczynski#Arrest

jonafato··on Ask HN: assertEquals, assertEqual, or assert_equal?
This is a nitpick, but "A equals B" uses the verb "equals", and "A and B are equal" uses the adjective "equal", describing a state of being. That said, reading code like English would probably suggest something like assertEqual(A,B) or A.assertEquals(B). At the end of the day, it's all just what looks best to you.
jonafato··on I know I belong in computer science, but sometimes I wonder.
I absolutely agree with you. This wasn't my point though. My point was that Person A's 10,000 hours is worth more than Person B's intelligence advantage, not that Person B will not overcome Person A.

You only learn from encountering situations in which learning is necessary. I think the smarter person encounters these learning experiences more quickly, but people don't instantly become great at something.

jonafato··on Ask HN: Which managed VPS will you recommend?
Linode is great. Even if you don't use them (you should), their docs are definitely worth looking at, as they have tutorials on most of the setup and config stuff you'll want to do.
jonafato··on My Startup: Become the King Conquer the Venues. It's mysterious?
The top line there doesn't make much sense to me. It sounds like it means "The first 1000 to join get the Premium Theme Pack for free!", but I'm not sure what the "more share" part is.

I'm not so into this kind of thing, so I don't want to join up and take someone's spot and wind up not using it.

jonafato··on My Startup: Become the King Conquer the Venues. It's mysterious?
Clickable: http://challengein.com

Based solely on the tagline, it sounds like foursquare. The graphics remind me of board games though, leaving me questioning my previous conclusion and thus mystified.

jonafato··on I know I belong in computer science, but sometimes I wonder.
Because so often, computer science education boils down to "code this, now here's your degree" without requiring any of the mathier stuff.
jonafato··on I know I belong in computer science, but sometimes I wonder.
Doesn't this go against the 10,000 hours thing? Sure, taking someone who is smarter and has more experience than other students and putting them in front of a computer will yield these results. However, someone who is solely smarter and does not normally program will not likely produce good code. Expertise is much more about practice than raw ability. Most of the really good programmers out there are really good because they're both smart and well versed, not just smart.
← PreviousPage 2 of 5Next →