HNHacker News
TopNewBestAskShowJobs

kellros

159 karma · joined December 7, 2011

I am a software developer and consultant focusing on small to enterprise size systems and business growth.
submissionscomments
kellros··on Ask HN: Which is harder Front end or Back end?
I'd suggest that /you/ start him off with neither - your best bet is to turn him on to something like teamtreehouse.com's html/css/javascript course if he's already computer literate. Otherwise computer literacy is first priority and linda.com has some pretty good videos.

You should then after the 30 day trial be able to judge his passion by how far he gets. If he doesn't even complete the first chapter, then you would have wasted your time trying to teach him something he has no interest in.

I believe the way to introduce someone to web development is by teaching them something that has a tangible reward - e.g. design a static web page you can host, or have the ability to edit the HTML/CSS in a CMS or e-mail template.

My opinion is that anything is hard if you have no idea what you're doing. The biggest factor I've seen that determines if someone can become a competent programmer is passion.

kellros··on Gwan – a fast 150kb web server supporting 14 scripting languages
Looks interesting, but the C# benchmark is horrible.

There's no way a properly written C# program would take IIS + ASP.Net C# ............ 171.8 ms! A bare bone Katana/OWIN self-hosted hello world echoing endpoint can easily surpass 5K+ req/s while the equivalent ASP.NET MVC hello world echoing endpoint can surpass 3.5K+ req/s with the standard routing.

I suspect the biggest contributor to the slowness is all that string concatenation - because every 'version' of a string is hashed and stored in memory e.g. "a" ["a"], "a" + "b" ["a","b","ab"] etc. (use StringBuilder or write directly to the output)

I suspect the Java benchmark also suffers due to this. (use StringBuffer)

kellros··on Ask HN: Open-source equivalent to Ink File Picker?
It depends entirely on what you need.

Here are some alternatives for client side:

https://github.com/blueimp/jQuery-File-Upload

http://www.plupload.com/

Given that under normal circumstances that development time is expensive, you'll save a lot of money even if you have to pay $29+ a month.

kellros··on Ask HN: Alternative careers where software development skills are useful
Let me start this off by saying that I sympathise with you. But, you should start thinking outside the box. Software development is a craft - and as such, it plays a part in achieving outcomes. I don't consider the ability to program a super power - anyone with a technical background is able to learn programming given time and the proper resources.

Start thinking more about what you are trying to achieve (the goal) and why you are approaching it in this particular way (the purpose). "Meaningless work" is often the result of decisions made on a whim - take the responsibility to investigate the goal and alternative methods to achieve the same result.

In order to find your work more meaningful, you should become more focused on the business aspects. Sometimes the best approach to solve a problem is meaningless work - but at least then that would be a comfort.

If you want to try something outside of your day job and you consider yourself good at web-related things, there's little stopping you from setting up an e-commerce store and selling things. Shopify is an e-commerce solution on a platter, but there are many alternatives. I've recently setup a Wordpress + WooCommerce website + bought a theme (Kallyas) for my wife - http://www.swartsbooks.com - still busy working out the kinks. Even though I could have built the store myself, I opted for the practical solution. My current side project focuses on addressing communication issues (e.g. complaints, notices, notifications, sharing of documents) in micro communities such as complexes, estates, shopping centres/malls and corporate parks.

You could also write e-books about your craft, similar to what Authority (http://nathanbarry.com/authority/) suggests and sell them on gumroad.

If you like doing business, you might consider doing consultation + web development. I occasionally did this the past 2 years and made about $6K at $36/h for development and $30/h for consultation. The consultation part revolves around advising the best approach to take regarding the technical side and the impact on business concerning the technical side. You could also do some research on behalf of your client if you consider yourself more knowledgeable.

The moral of the story is that you do not necessarily have to find your day job meaningful (and most people don't), as long as you can do other meaningful things.

kellros··on Go 1.3 beta 1 released
Intellij IDEA with http://go-ide.com/ works for me. Some useful features:

1. Quickly run/restart your application 2. Run specific unit test (all in package, all in file or specific one) 3. Parameter and func signatures are more detailed via CTRL+P (parameter info) than what you would get with GoSublime and GoCode.

There's only one thing so far I found a bit quirky:

Say you got a function with the signature func() (err error) and pass it as a parameter to another function that has the signature func F(f func() error), it will complain that the signatures don't match, but it will still compile.

kellros··on Simon Ritter talks Project Lambda in Java 8
Interesting decision to go for dynamic invoke. Does anyone know if the implementation is similar to that of LINQ in terms of using an AST? Would type erasure allow for composing lambda expressions?
kellros··on Salted Password Hashing – Doing it Right
Pretty good article, I especially like the idea behind doing linear time comparison using XOR.

Although, the XOR comparison implementation seems flawed as it will only compare min(supplied password length, existing password length); which would allow the attacker to identify the existing password length by providing a sufficiently long password. Instead the existing password should be padded to the length of the supplied password in order to hide the length of the existing password.

My issue with the XOR comparison implementation is irrelevant as password hashing should use stretching (ex. PBKDF2, BCrypt, SCrypt) which means the hash of the supplied password and that of the existing password would be the same length.

The implementation of the PBKDF2 is also flawed.

Iterations: The recommended PBKDF2 iterations has long surpassed 10,000 (it's closer to 100,00 now). See here: http://security.stackexchange.com/questions/3959/recommended...

The rule of them is that given a sufficient length salt, the number of iterations should take about 8ms on the hardware it is running on.

Salt Size: The recommended salt size is 128-bits/16 bytes (not 24). See here: http://security.stackexchange.com/questions/17994/with-pbkdf...

That stackexchange question also recommends using SHA512 as it requires 64-bit arithmetic operations which GPU's are supposidly not great at.

I believe I read stackoverflow and most big websites store about 24 bytes of the hash. The salt is generally prefixed to the hash and that is stored (ex. salt size 16 bytes + password hash 24 bytes = 40 bytes).

If I wanted to version a stored password, I'd simply use the first byte as an indexer to select a password hashing function instead of prefixing the hash with the number of iterations which seems non-portable.

Even if you do everything right concerning the hashing of passwords, account security extends beyond passwords - such as alternative methods of authenticating (forgot password, secret questions, authentication tokens). OWASP is a great authority in regards to this: https://www.owasp.org/index.php/Password_Storage_Cheat_Sheet

kellros··on Why is broadband more expensive in the US?
South Africa would have made that chart look totally out of proportion :) I believe 1Mb/s is going for around $35-$60/month
kellros··on Hacker News Effect
Be sure to check out http://conversionxl.com/blog/ for marketing how to's/tricks/growth hacks - it's one of the best sources.

I like the idea. I'd suggest some effort be put into the grammar on the website and blog because small things like that create a negative impression for some people.

Example, from:

Poucher lets you generate discount vouchers, for the restaurant or bar you like. The more Poucher users in a restaurant or bar means more discounts. So pick the nearest venue with highest population and enjoy your live discount.

To:

Poucher lets you create a discount coupon for the restaurant or bar you visit. The more Poucher users in a restaurant or bar, the higher discount you'll receive. Get Poucher now and start enjoying your live discounts! *Disclaimer: Discount coupons are only available for participating venues and valid for the visit - (see our list for participating venues near you.)[link]

kellros··on Ask HN: How to get out of paralysis by analysis?
In the end, the only opinion that matters are those of your users. You should talk to them - find out what they like and don't like ( to gain some perspective ) and then iterate on what works.

Try to reduce the amount of things you are working with to the bare minimum - ex. actors + action = result - and revisit the models you designed and determine how the action should change their state. Workflow diagrams sometimes help to visualize complex interactions too.

kellros··on Where to find C# developers for freelance work
Hacker News is a pretty good place to find passionate developers. How many hours of development per month do you require? When do you expect to collaborate regarding the projects ~ business hours?

I found in my consultation gigs it's largely beneficial to have someone whom you can meet face to face with occasionally.

If you're interested in having a chat; send me an e-mail to the address listed on my profile.

kellros··on Do most programmers honestly enjoy programming?
Depends on the client!
kellros··on How to improve our Landing Page
If you can, try to pull in some of the reviews from App Store/Google Play. Your primary sell is to get people to give it a try and there's no better way to do that than by testimonies.

Can you perhaps give a better translation for the copy than what I'm getting from google translate?

- With heythere you'll always know what's happening around you. Let me show you interesting places in your area and tell others what is happening at your place.

- Look at how heythere works

Your copy should answer the following questions:

1. What is this website for? (The picture of the mobile suggests it's some kind of app)

2. What is this app and what do you use it for? -> Answer this question in terms of what your target market wants to hear. The copy will be different for business owners and for regular users.

3. Why should I give this app a try? The video looks nice, but it should be optimized to answer question 2. What other options have you considered showing off the like/comment functionality?

You should also let people subscribe to a mailing list. You can setup one for free with Mailchimp if you stay within their free usage tier. This will allow you to communicate with your target audience things such as updates, offers, competititions, greetings or sale pitches.

It would also be good if you started thinking about how you could use the app as a tool to offer business services (ex. competitions, advertising).

Hope that is helpful. Best of luck.

kellros··on Why cant we build web pages using absolute positioning?
There's numerous reasons why this is a bad idea.

There's a difference between a fixed width layout and an absolute positioned layout - the fixed width layout can adapt.

The biggest issue with absolute positioned layouts (as with design for print) is they can only scale, but not adapt to the various resolutions and pixel densities we encounter on clients viewing websites.

Web design is first most the design of a pattern of design in order to achieve consistency via reuse. If everything has fixed dimensions; it wouldn't be very reusable.

On the topic of using JavaScript to perform the layout:

1. JavaScript performance in newer browsers are pretty good, but ranging from extremely to pretty bad on older browsers (don't forget the mobiles!)

2. You'll have to resort to using CSS anyway for specific layouts (ex. keeping an element always visible) as repositioning an element on streaming events using JavaScript tends to be really slow.

3. The amount of reuse you'll get from even writing a decent interface for layout functions will be pretty low.

4. Behavior of CSS using a reset is more consistent than JavaScript implementations. You'll probably need to normalize between different browser versions - that means using something like jQuery, Moo Tools etc. which adds a hefty payload.

5. Waiting for your JavaScript to be downloaded and interpreted to reposition elements (after the DOM has already rendered) will be an ugly sight.

You should invest time in pre-processors such as Stylus, Less or SCSS (you can write reusable mixins that you can include on different projects and use variables to customize them). If you haven't, you should read up on object-oriented CSS: http://coding.smashingmagazine.com/2011/12/12/an-introductio...

kellros··on Top Algorithms for Coding Interview
Thanks for the post. You made a typo on 'toCharyArray' - I'm pretty sure that's not a method :)
kellros··on How much does a Lyft driver earn?
Lyft. Someone is being taken for a ride! +1!
kellros··on Ask HN: Tips on how to drive traffic to my content?
What's the link to your blog?

Even if your blog is 3 weeks old, it generally takes a few months for a domain name to gain reputation. Organic SEO (self-discovery via search terms) requires quality and quantity - you might have the quality right considering you got so much traffic already, but 4 articles is still a long way from 'quantity'.

The trick is to consistently create good quality content for a long period of time (ex. once a week/forever).

What's your motivation for the blog? Hobby? Interest? Work related?

kellros··on Ask HN: What's the most convenient payment method for enterprise customers?
The primary reason why a lot of SaaS businesses charge a monthly premium instead of an annual premium is due to purchasing policies at corporates - which usually dictate that purchases over x amount (x=$500/$1000+) require multiple sign-off and follow long-winded acquisition processes that tend to take forever. By charging less than the threshold or by charging a large amount that would normally exceed the threshold over time; it's a lot easier to get such purchase orders signed off. Credit card is the preferred method for smallish amounts (< $2000).

Without generalizing too much - corporates are generally price insensitive - they would rather pay a preferred supplier more than risk their business on a cheaper alternative (without great motivation).

It's in your best interest to dictate the terms that are the least risky for you - they won't choose another supplier because he offers payment via cheque and you don't. If they do, I'm not sure that you do want them as a client considering the hassle you would potentially have to go through to get your money (good luck if the corporate is in another country!).

kellros··on Show HN: Get feedback for your website and learn from the mistakes of others
It looks interesting, but since we are on the topic of usability - the colour contrast needs some work and the font looks blurry. The site also just loads with an 'undefined' header and then after a second or two shows the page - I'm not sure if this is because it's a JS app. I'll revisit the website in a while.
kellros··on Whitespace delimited Scala
Good job, I like it. I think it would be good though to still optionally allow braces as a way of scoping.
kellros··on Developers are the autoworkers of our generation
I agree with you that this is the direction in which we are heading, but not that professional developers will become obsolete.

I believe if we ever reach that point where programming is common-skill; the real developers will stay ahead due to demand. I honestly don't see corporates with millions/billions of revenue trusting newcomers with a few weeks of experience to handle core business automation; in the same way as you don't trust a clerk to sort out your legal issues.

Perhaps when the time comes; professional developers will become like the attorneys in the law system; where specialist skills demand even a higher rate and requires less time invested (which might mean the same salary as now but only working 'part time').

I don't have any issues with people wanting to learn to code; I even mentor some myself. It really comes down to hours (or rather years) invested in learning and fine-tuning your skills; which I see the majority of new developers not willing to invest in.

As such, I believe the demand for better developers will increase. Look to the tech companies with open positions looking for 10x/star developers - even though there are developers available, they just don't make the cut.

kellros··on Levelling Up as a Developer
Good article, just a bit distracting to read (for me) at that font size (the content area is very wide at 1920x1080) - try setting style.css -> p { font-size: 16px; line-height: 24px; } for large sceens ( >= 1100px )
kellros··on This coupon code is a slap in the face
An alternative approach would be to create a 'claim coupon' form and point your couponeers to that so that they may redeem the coupon. The trickier part would be then to keep track of the coupons in a similar fashion to the 'Items in Cart' (either via session based tracking or link it to their account).

This approach would also allow for implementing coupons in different ways (ex. time-based, limited), reduce mental stress by being able to retry codes till you found a valid coupon (some providers allow for coupon codes but no way to verify it's valid) and not distract from the check-out process (it would simply require showing which of the redeemed coupons are applicable to the purchase).

A plus side of this approach is that a coupon is enough to persuade potential buyers to create accounts to keep their coupon (while it's valid - for later use) and thus also reducing friction in the check-out process which should lead to more sales.

I do also now believe the existing 'coupon' implementation is at fault by leaving too much on the table.

kellros··on Ask HN: Is there a Hacker News type of website for game development?
Have you tried reddit?

http://www.reddit.com/r/gamedev

http://www.gamasutra.com/

kellros··on Ask HN: How do you determine which database(s) to use for a project?
From a technical viewpoint it all comes down to the CAP theorem and what is priority: http://en.wikipedia.org/wiki/CAP_theorem

Not mentioning all the other factors that are involved in choosing a database (ex. current staff skills, who will be maintaining the project if you decide on x but everyone uses y, what licenses do you already have etc.), you should consider the CAP theorem when choosing between a RDBMS, NewSQL, document based, graph based, key-value or file based storage.

Each database was designed to solve a specific problem, even though most databases are advanced enough for general use cases (ex. you can use a RDBMS in a similar fashion to a key-value store).

I'd say unless you have tried out what's available, it's going to be hard to make a choice - so get started!

kellros··on Ask HN: Making money is really hard. Help
tptacek makes some valid points in regards to securing revenue.

You must have heard of The Lean Startup and like most people get confused about what a MVP really is. The vision behind building a MVP is to identify the most valuable prospects (that make you money) and to get that to the market earliest.

As soon as the MVP starts generating revenue, any further development requires less out-of-pocket investment because the revenue generated will be substituting the cost. This allows for more breathing room to automate, improve, reduce waste, innovate and grow the product.

The biggest secret regarding business is possibly the concept of perceived value. Perceived value is not about 'faking' value, instead it is about defining it.

Example being, instead of charging $ x per hour for web development; break it up into different tasks and charge accordingly: website design, graphic design, copywriting, SEO, marketing (social media, ppc/ppv), system design, consultation (ex. to determine best path forward), training, support, analytics, business analysis etc.

Once you have defined the tasks involved, you can be honest with your client in terms of your strengths and every task will be judged according to its merits (what defines success?). Most clients would prefer paying a qualified copywriter the same amount (or less) than he would be paying a non-qualified web dev.

Defining what you do will allow you to reduce waste and distribute work more easily on your team.

The real trick behind successful software development/consultation is the focus on building systems instead of services. Systems being defined workflows concerning components and participants, focused on re-use. Because lets be honest, real software design reuse either require building generic systems that allow for all scenarios (or can be extended) or defining interactions and components (ea. a design 'pattern').

kellros··on What I learned using unit tests/TDD
Thanks for sharing, I agree with the points you made. The only thing I would add is that not everything is testable in the sense of given: input, expect: output.

A common scenario I encounter is that sometimes when you are refactoring a method and refactoring it into multiple methods (for better readability or segregation); that you are required to make the new (sub) methods publicly available for testing purposes. This goes against the intention of improving readability because now you have to expose certain methods that you would rather haven't be called independently. In such way, TDD helps identify artifacts with too many responsibilities.

The best tip I can think of to give someone approaching/doing TTD is to make a check-list beforehand of what you are trying to achieve. This helps to focus your attention on usage patterns and identify 'end-points' (end points being testable artifacts). Just because you're doing TDD, doesn't mean you don't have to have a plan to start with.

kellros··on Monster Energy logo as SVG and animated with CSS
Very cool
kellros··on Ask HN: JetBrains vs NetBeans vs Eclipse for PHP, Python and Ruby.
I'd say you should definitely download the trials and work in them for at least a couple of days. I personally am a big fan of the JetBrains products. I was fortunate enough last year when they had the 'end of the world' special to grab RubyMine, Webstorm, PyCharm, IntelliJ Idea and Resharper for less than $150. I honestly haven't worked with the IDE's much, but from my experience they are pretty good. I wouldn't bet much on the plugins per se, but I'd say you're in pretty good hands if you choose to work with an IDE specifically designed around a particular language/framework since a lot of languages are very opinionated about development (ex. Rails, Golang).
kellros··on Ask HN: HIPAA hosting provider
Windows Azure and AWS both support HIPAA compliance

http://www.windowsazure.com/en-us/support/trust-center/compl...

http://aws.amazon.com/about-aws/whats-new/2009/04/06/whitepa...

I know a couple of things regarding HIPAA compliance, first-most you need a very high level of security on the transport layer (I believe it's 256 bits AES or higher for SSL - some spout that 128 bits is sufficient, but effectively a standard SSL certificate doesn't cut it). The second is HIPAA compliance is multi-part (see http://luxsci.com/blog/what-makes-a-web-site-hipaa-secure.ht...) and the infrastructure can only support HIPAA compliance (ex. if you're using AWS S3), but your application is responsible for the implementation thereof.

Your application cannot be branded to be HIPAA compliant simply because your infrastructure supports it. You'll have to go through the requirements list in order to construct your infrastructure to support it and then enforce the rules on the application and systems thereof (at least via unit/behavioral testing). You cannot really prove your application is compliant without proper test cases that enforce the rules.

← PreviousPage 2 of 7Next →