HNHacker News
TopNewBestAskShowJobs

jsaxton86

626 karma · joined May 30, 2011

https://jsaxton.com/
submissionscomments
jsaxton86··on Launching our Data Science and Big Data Track
It seems that the majority of Big Data/Data Science applications are designed to give advertisers insight into things I don't really want them to have insight into. That really sucks, because the technology is cool, but I don't want to help build that kind of future. It's kind of analogous to how I feel about Computer Vision: there are a handful of legitimate purposes for it, but most applications of the technology fall somewhere between "I don't like that idea" to "that's totally unethical".
jsaxton86··on 9/11 Suspects Can’t Mention being Tortured during Trial because Classified
This sounds like an onion headline. Is this story being reported by more mainstream sources?
jsaxton86··on Ask HN: What are you working on and why is it cool?
I just signed up for an account, only after the fact to find out that you don't have data for the Portland, OR market, which is unfortunate since this is definitely a tool I'd like to use in my upcoming apartment search. Two things I wanted to mention about the sign up process:

* Before giving you my email address, I'd like some reassurances that you won't spam me, etc.

* It took 10-20 seconds to create my account. Not sure what's going on there, but you might want to investigate that. This doesn't appear to be a fluke. When I logged out, then logged back in again, it also took 10-20 seconds to log in after entering my credentials.

Also, if I log in, then go to the Kwelia home page, then click on "Apartment Ratings", it brings up a login page stating that I'm already logged in, whereas I would expect it to take me to the Apartment Ratings page.

This tool looks really promising. Let me know if you ever add support for Portland, OR.

jsaxton86··on Can you break my home rolled encryption?
This is a really cool idea, I like it a lot.

With that said, I'm not convinced that your pseudocode actually works. Specifically, the following doesn't make sense to me:

pos_a = key[0];

pos_b = key[1];

pos_c = key[2];

...

pos_a = key[pos_b] % key_size;

It would be really cool if you posted functioning encrypt() and decrypt() methods to github. Something that people can actually compile/run/analyze. In fact, if you do that get in touch with me and I'll try to crack it.

jsaxton86··on Why I gave up my US passport
This isn't perfect, but it's a good start:

http://en.wikipedia.org/wiki/File:2008_Top1percentUSA.png

http://en.wikipedia.org/wiki/Income_inequality_in_the_United...

jsaxton86··on A simple git branching model
Git is designed so that branching is cheap. Why not create your own development branch off of the feature branch? Then use the feature branch as an integration-only branch?
jsaxton86··on How Your Brain Becomes Addicted to Caffeine
I used to drink two cans of Mountain Dew per day. I was 100% dependent upon it -- without my Mountain Dew I couldn't function at all. Anyway, I recently took a few weeks off between jobs, and during that time, I decided to quit caffeine cold turkey as well. I feel great! Some benefits include:

  -Sleeping better

  -Being awake and functional in the morning, even before the caffeine kicks in

  -Having a consistent energy level throughout the day

  -24oz of soda/day is not healthy, so getting that out of my diet was definitely a good thing
The only downside is that the startup I work for now has a tab with a number of local coffee shops that I can't take advantage of :(
jsaxton86··on Estonian E-Voting Source Code Made Public
There are two parts to this story:

-Estonia has an internet voting system

-Estonia just released the source code to their voting system

Even if internet voting is a terrible idea, a transparent election system is a very good idea, and releasing the source code for your voting system is a big step in that direction.

jsaxton86··on The Linux kernel MultiPath TCP project
What advantages does this have over existing link aggregation implementations?

Edit: one advantage I can think of is you don't have to ask your users to set up a bond0 interface, for example. Any other advantages?

jsaxton86··on Ask HN: What should I do if one of my startup founders does not work enough?
This link might be helpful: http://blog.eladgil.com/2013/01/how-to-fire-co-founder.html
jsaxton86··on Why I Haven’t Hired a Single Developer in Canada
Let me get this straight. You're saying that you're entitled to a salary that is substantially higher than developers with more experience (and likely more skill), and you're the one who feels insulted? Give me a break.
jsaxton86··on PostgreSQL 9.2.4, 9.1.9, 9.0.13 and 8.4.17 released
From the FAQ originally shared by edwinvlieg, you are still vulnerable:

The vulnerability allows users to use a command-line switch for a PostgreSQL connection intended for single-user recovery mode while PostgreSQL is running in normal, multiuser mode. This can be used to harm the server.

jsaxton86··on 600K concurrent HTTP connections with Clojure and http-kit
Does anyone know how they managed to not only bypass the C10k limit, but bypass it by a factor of 60?
jsaxton86··on Email transparency
"We use Gmail for email and Google Groups for lists."

"What we have today works pretty well for our current size—around 45 people."

So if I can manage to get the Google authentication credentials for just one of Stripe's 45 employees, I can get access to the vast majority of Stripe's email? I hope they require two factor authentication.

jsaxton86··on Use long flags when scripting
A much simpler solution is to comment your code:

# Invoke curl in silent mode (-s), pipe the output to grep

# and use an extended regex (-E) to only show the resulting

# digits (-o: only print matching text, not the whole line):

curl -s checkip.dyndns.org | grep -Eo '[0-9\.]+'

jsaxton86··on 'Red October' cyber-attack found by Russian researchers
A more technical overview can be found here: http://www.securelist.com/en/analysis/204792262/Red_October_...
jsaxton86··on New Zero Day Java Vulnerability Being Exploited in the Wild
This family of JRE attacks is far too common. Basically, when an unsigned applet runs, the JRE tries really hard to prevent it from creating a ClassLoader object. However, if you manage to create a ClassLoader object, it's game over -- you can break out of the sandbox and do whatever you please.

<shameless plug> For those interested, a recent blog post of mine analyzes a similar attack that uses CVE-2008-5353: http://jsaxton.com/fun-with-wireshark-and-ie-java-exploits-p... </shameless plug>

jsaxton86··on The Unreasonable Effectiveness of C
You can wind up with "an unmaintanable mess riddled with security holes" in any language -- that's not unique to C. Regarding the flaws you have mentioned in C:

Its flaws are very very well known, and this is a virtue. All languages and implementations have gotchas and hangups. C is just far more upfront about it. And there are a ton of static and runtime tools to help you deal with the most common and dangerous mistakes. That some of the most heavily used and reliable software in the world is built on C is proof that the flaws are overblown, and easy to detect and fix.

jsaxton86··on Show HN: Password.ly - Per site password generator from a master password
KeePass works on almost all mobile platforms, even those without web access, and KeePass isn't going to have downtime like password.ly.
jsaxton86··on Favorite Unix Commands
You can get a fancy status bar with screen, you just need a screenrc file: http://www.mbeckler.org/blog/2012/11/28/my-screenrc-file-cir...
jsaxton86··on New school C
Yeah, I had the same thought. In fact, in the interview, the author actually picks up a copy of K&R C and looks through the index for "threading" and finds nothing, whereas Go was designed with concurrency in mind.

On the other hand, as the author said, C is over 40 years old. Many consider that a weakness, but he considers it a strength, given the large number of C libraries available, whereas you don't have the same number of libraries with native Go bindings. Ultimately, of course, it comes down to using the right tool for the job. That may be C, that may be Go, that may be a higher-level language like Python, Ruby, etc.

jsaxton86··on Patio11 Wrote A Book On Conversion Optimization For Software Companies
I would assume patio11 doesn't intend to directly make a lot of money off of this book. Instead, he wants to be able to tell potential clients he has written a book on conversion optimization, which allows him to charge a higher rate.
jsaxton86··on Why was Pinball removed from Windows Vista?
I disagree. Sure, in the short term, taking on that technical debt may have made sense, but in the long term, this is a perfect example of how technical debt added significant maintenance costs to a project.

What if dropping Pinball was not an option? The cost to the shareholder would have been much higher than it needed to be.

jsaxton86··on Exploit Information Leaks in Random Numbers from Python, Ruby and PHP
I think the author was alluding to the following: http://www.cigital.com/papers/download/developer_gambling.ph...
jsaxton86··on Post mortem of a failed HackerNews launch
This post mortem has me thinking about the best way to handle the situation in which you can't SSH into your server. The OP decided to trigger a kernel panic/restart on OOM errors, but I have a couple of concerns about this approach:

* If memory serves correctly, if your system runs out of memory, shouldn't the scheduler kill processes that are using too much memory? If this is the case, the system should recover from the OOM error and no restart should be needed.

* OOM errors aren't the only way to get a system into a state where you cannot SSH into a system. It would be great to have a more general solution.

* Even if you do restart, unless you had some kind of performance monitoring enabled, the system is no longer in the high-memory state so it will take a bit of digging to determine the root cause. If OOM errors are logged to syslog or something, I guess this isn't a big deal.

I suppose the best fail-safe solution is to ensure you always have one of the following:

* physical access to the system

* a way to access the console indirectly (something like VSphere comes to mind)

* Services like linode allow you to restart your system remotely, which would have been useful in this scenario

jsaxton86··on Silicon Valley's dirty secret - age bias
Yeah, I do. I think the only constant thing in software engineering is that you need to be able to learn and adapt. If you spend 25 years at a single organization where you aren't forced to continuously learn and adapt, you'll be at a disadvantage when you are inevitably forced to do something outside of your comfort zone.
jsaxton86··on Silicon Valley's dirty secret - age bias
I've also worked with developers in their fifties who are awful.

Age bias is awful, and I have worked with a lot of older developers who know their stuff and are extremely competent, but the idea that 25 years of experience automatically makes you a better programmer is wrong. Good developers are able to learn and adapt quickly, and often older developers can't do that.

jsaxton86··on Using Erlang, C And Lisp To Fight The Tsunami Of Mobile Data
I think the value of 20 seconds is arbitrary, but there's a good reason why they don't lower it any further. With a protocol like TCP that guarantees reliable delivery, sometimes packets get resent to the server. If the server receives this resent packet after the connection has been closed and a new connection has been opened, it is possible that the server will accept this packet. As such, as part of closing a TCP connection, the connection sits in a TIME-WAIT state for 2*MSL seconds (MSL = maximum segment lifetime).

If you decrease the amount of time a connection sits in a TIME-WAIT state, you will increase the probability that a new connection could receive a packet from a previous connection. Given the latency of mobile networks, I would expect the probability of receiving a packet from a previous connection to be even higher.

If you're interested, the beginning of the following paper provides a great overview of the problem: http://www.isi.edu/touch/pubs/infocomm99/infocomm99-web/

jsaxton86··on My open source cure for brain cancer
To be fair to the original poster, you didn't post his entire statement. If you look at the entire statement, he made several intelligent points about TCM, any one of which could have been the starting point for an intelligent conversation if you disagreed with what he had to say. Lots of comments on HN could be considered a "middlebrow dismissal," but this is not one of them.

On another note, the original statement in question kind of reminds me of a Steve Jobs quote:

"I really didn't want them to open up my body, so I tried to see if a few other things would work."

jsaxton86··on Silicon Valley Is Filled With Liars
Look, if you're talking to investors, you're most likely making a sales pitch. Any competent salesman is going to of course emphasize the positive aspects of what he's trying to sell. If you can say, "We’re operating at X run rate" and investors are going to react positively to that, you'd be stupid not to and it doesn't make you a liar, even if Mr. O'Neill doesn't find it to be a valuable metric.

I agree that there's a fine line between making a legitimate sales pitch for your startup and lying to your investors, but the article doesn't address that point at all.

← PreviousPage 3 of 4Next →