HNHacker News
TopNewBestAskShowJobs

levigross

68 karma · joined October 28, 2010

twitter.com/levigross www.levigross.com
submissionscomments
levigross··on A Go “clone” of the great and famous Requests library
Whats wrong with "demand-creating" channels? The Go stdlib does it within their network library https://golang.org/src/net/singleflight.go#L67
levigross··on A Go “clone” of the great and famous Requests library
I know... But as you said (and I agreed) :) dependencies add complexity...
levigross··on A Go “clone” of the great and famous Requests library
I agree with this sentiment and therefore my Response method is also an `io.ReadCloser` (exposing the http.Response.Body io.ReadCloser that Go has to offer).
levigross··on A Go “clone” of the great and famous Requests library
I agree with you.

I wrote this library because I didn't want to rewrite those functions every time I started on a new project. I put it online because I figured that I would be useful to others as well.

levigross··on A Go “clone” of the great and famous Requests library
I am not trying to do things in the "Python way". I am trying to bring some of the same flexibility I get when using the Python requests library to Go.
levigross··on A Go “clone” of the great and famous Requests library
Jerf,

1. Thank you for the feedback

As you have already seen, I submitted my library to /r/golang and have gotten a lot of feedback – from which I modified the constructs (originally the functions returned channels).

I want to write something that is useful to as many people as possible (all while not alienating anyone) and therefore try not to force users (like I originally did) to use the "asynchronous APIs".

I didn't expect this to end up on HN and was going to start a discussion on golang-nuts on the pros and cons of this construct. Based on that, I was going to remove or keep the APIs.

levigross··on A Go “clone” of the great and famous Requests library
Originally the API was completely asynchronous (every "request" function returned a channel).

I got a lot of feedback that I shouldn't do that, so I moved the asynchronous requests to specific functions e.g GetAsync and made the standard API synchronous.

levigross··on A Go “clone” of the great and famous Requests library
yes
levigross··on A Go “clone” of the great and famous Requests library
I am not very good at naming things and figured to just slap a 'g' on requests => grequests.

I figured that I would write the code and decide on a name later...

levigross··on A Go “clone” of the great and famous Requests library
Jerf,

Thank you for the suggestion. I plan on adding some functionality to make asynchronous APIs friendlier to use (like a `Do` or `Apply` function etc...). But if you don't choose to use the asynchronous APIs everything still functions the same (in fact the asynchronous APIs use the synchronous functions and slap channels on them)

levigross··on A Go “clone” of the great and famous Requests library
I agree! The README is really sparse right now (I didn't expect so much exposure right). It is just a matter of time before the README has more information.
levigross··on A Go “clone” of the great and famous Requests library
Thanks – I wrote this library because I like using requests when writing in Python and wanted something similar when writing in Go.
levigross··on Web App Security Best Practices
This is true, however with creating applications with Django you are protected against most basic attacks. The ORM uses parameterized queries, all unsafe output is automatically escaped, Protection against CRLF injection within the framework and protection against HTTP response splitting.

The framework isn't fool proof (no one can protect developers from themselves). But I feel that Django does what it needs to do when it comes to protecting its users.

levigross··on SSH Key Audit on Github (required)
They also added a audit log so you will be able to track and address any future issues.. https://github.com/settings/security
levigross··on How to answer "What is your greatest weakness?"
I always answer "bullets" and get a blank stare in response.
levigross··on Diginotar confirms security breach
This is an Über Failure if I have ever seen one. They detected the breech on July 19th but didn't think to check to see if anything was amiss?!? I think that OS companies and browsers must come down hard on compromised certificate authorities. A ZERO tolerance policy should be enforced resulting in a permanent BAN if your private keys are compromised!
levigross··on Gmail.com being MITM'd by Iran using this certificate
This attack could of hit people in other countries as well. Small well places malicious BGP updates can reroute traffic into Iran.....
levigross··on Mark Cuban: What Business is Wall Street in?
I don't mean to praise wall street but Mark Cuban made his initial cash from stock options the same things the people on wall street trade. So he knows very well what businesses they are in.. They made him rich!
levigross··on Microsoft Responds To Google’s Response To Microsoft’s Response
+1 on the title
levigross··on Tom Pinckney: Why I gave up on Java and switched to Python
I agree that number 2 doesn't make any sense. I know that code quality is measured by defects in KLOC (1k lines of code) but this isn't a reason.

P.S Even though within the article the python the he explains what he means (with type bugs) such issues won't be by moving to python.

levigross··on The Mother of All Interview Questions
It seems to primarily be an ego issue. This person must of thought that since he/she is so smart any system that isn't understood obviously shouldn't exist.
levigross··on Auditor's response to "Our security auditor is an idiot" (Update 3)
Then again, after working at startups my whole career, maybe I'm just naive about how messed up the real world is. I second this... Working in a startup every time I see someone having to work around corporate BS to get something simple done, this comes to mind.
levigross··on Violated: A traveler’s lost faith, a difficult lesson learned
IMHO There are bad people out there and some of them will want to hurt you. You don't have to sacrifice who you really are because of them. You just have to live a little bit differently. means don't use AirBnB
levigross··on A lesson in timing attacks
Additionally Sidechannel timing attacks against EC2 instances have been very successful. The attackers have been able to get very close to the machines and in some instances on the actual box.
levigross··on A lesson in timing attacks
If you look at the Golang source code (copied here: https://gist.github.com/954801 ) you will see that they have something similar. But they use two's complement as well to compare the true or false.
levigross··on Confirmed: Samsung is not shipping keyloggers
certificate fail!
levigross··on New Flash zero-day exploit that allows system takeover
Most software companies will put security bugs on a uber priority fix list. Everything else goes to the back of the line :).

One of the best ways to get any bug fixed in any Library, OS etc... is to find a way to exploit it.

levigross··on New Flash zero-day exploit that allows system takeover
I think 0-day means something a little different http://en.wikipedia.org/wiki/Zero-day_attack
levigross··on First dump of Anon BofA Documents is up
The documents may be up but that site keeps on going down.
levigross··on US and Israel were behind Stuxnet claims researcher
ughhhh another article on stuxnet......
Page 1 of 2Next →