Please send me an email if you're interested: carter@gameclosure.com.
255 karma · joined August 24, 2010
I've done extensive work designing real-time web technology. I wrote the spec proposal for what is now Websocket; I am officially recognized by the W3C for this work.
Other Open Source projects I've created:
http://orbited.org http://hookbox.org http://github.com/mcarter/js.io
Comet Session protocol: http://orbited.org/csp
Please send me an email if you're interested: carter@gameclosure.com.
Basic idea is this: You put all your real-time stuff in a message queue (MQ) which communicates directly with the browser. For authentication / authorization and various other forms of permission / logging, you have the MQ communicate with the web framework via http callbacks (Webhooks) and a standard REST API. So the architecture is:
User <--Websocket--> MQ :: publish/subscribe
MQ --Webhooks--> PHP/Django/Servlets/etc. :: user signed on, user joined a channel, etc.
PHP --REST--> MQ :: publish(msg), remove(user, channel), etc.
The key is to include cookie information in the callbacks from MQ -> PHP so the callback happens in the context of the user session. Suddenly you can do things like write a chat app in 30 lines of php + js, or a persistent time series in 20, and it really feels magical.
I actually started Hookbox almost as a statement of irony, because I was really frustrated about the major pushback I was getting to sockets in web browsers at the time. I'd just finished writing/submitting the initial proposal for Websocket, and I wrote this tongue-incheeck piece about the mismatch between typical web development and network server programming: http://svwebbuilder.wordpress.com/2008/10/20/html5-websocket...
So Hookbox started as a 2-3 day project that took on a life of its own for a while and ended up being really useful. This project was one of my smaller open source codebases and to this day I receive tons of interest and requests for maintenance, though I've abandoned it for years due to time.
I'm sure there's a huge market for this sort of thing. It's great to see Pushpin, I'll definitely check it out!
Yet, there seems to be quite a bit of this on here.
Rather, it's about the optimistic spirit, the emotional strength, and ultimately the endurance to keep going even when it's so hard you don't want to get up out of bed.
If you figure this part of entrepreneurship out, as Eric has, you can probably build something amazing.
That's the point! According to you, they were a piracy haven, and they were shut down. Without SOPA. So why do we need SOPA again?
This is pretty clearly an anti-SOPA talking point.
The problem is that it's a lot easier to imitate the talking points of successful startup than it is to actually imitate the success.
Maybe the world would be a better place if you had influence over that kind of semi-arbitrary wealth transfer as opposed to whoever has it now.
In order to return the $6 mm there needs to be $400 mm of exits.
But I don't think it's reasonable to assume that the successful companies wouldn't take additional funding past series A. More likely, any successful company would also take series B funding. Then we'd need to see ~$500 mm - $800 mm to break even.
My guess is that these investments aren't really intended to be profitable. I would guess that they're instead a gateway into future deals that will be profitable.
Facebook could add a ten page signup form and I doubt it'd substantially impact their legitimate signup rate.
If a developer has an application that works in other browsers, then hey, they should go distribute those apps in more places than just the Web Store. But it only really makes sense to position the Web Store as a Chrome-specific application repository b/c Google is only really guaranteeing that these apps work in Chrome.
Google isn't lying, much in the same way that Apple isn't "basically, lying" when they fail to point out that you can play Angry Bird on Android just as easily as you can play it on an iPhone.
(Assuming Patrick is even using Twilio and that the code is in any way relevant.)
Google crawls Facebook's data, by request (robots.txt.) You, me, Facebook, and the world do have access to Google's complete data set... its called the world wide web.
Facebook, on the other hand, does anything it can to get a hold of private data owned by individuals, and then hoard and monetize it.
Gmail Contacts is an example of private data, as is the Facebook social graph. These are directly comparable, unlike Facebook's social graph and the greater WWW that google uses for building search indexes.
Instead of sending a cookie, send a piece of javascript code (as part of the SSL-cloaked login handshake) that generates a new cookie for each request, and consider each new cookie in this sequence a "one time use" token. You can turn off SSL for subsequent requests and just use one of these new cookies each time to verify identity because an attacker won't have your cookie generator.
This javascript is really just an encryption key and algorithm, and if you implement it correctly, it should take quite some time for snoopers to reverse engineer the encryption key based on a sequence of one-time-use cookies.
Logistically, I suppose you would run into some trouble setting a new cookie for each request depending on how the page is loaded. For instance, if the user pastes a url into a new tab manually, then this system wouldn't have a chance to set the new cookie first.
However, I think you could architect a system that solves this. For instance, put the javascript token generator source in local storage. If a new page loads with an invalid key, that new page can just get the cookie generator code out of local storage and manually refresh the page's content by making a request with a valid token. This should be quick enough for most users not to notice, in the rare case that they circumvent the site's usual navigation.
A downside is obviously that the content itself is still not safe, but at least the account would be. Any thoughts?
Based on my experience, I doubt they need their "highly sophisticated" PHP to do this -- plain old normal PHP would probably be fine so long as they choose the right out-of-the-box software to pair it with. (nginx, postfix, certain non-sql databases, and the right mysql setup)
This seems fundamentally incorrect to me. Wouldn't research all around just fail if no one ever reported their negative results, thus dooming many other researches to performing the same fruitless experiments?
pquerna, gridspy, thanks for your responses! I didn't mean to sound quite so cynical. Mainly I am venting my frustration at the lack of a dedicated developer to maintain the project, especially after I've seen so many success stories.
wrt AGPL: In orbited's case -- b/c it is a socket proxy -- the AGPL would really have no impact whatsoever on users. No one would be linking any of their code in-process, and so there would really be no requirement for them to AGPL any of their custom back-end logic. Besides, I don't really believe in trying to force users down a particular path. My hope is always that freedom and choice helps build trust with your user base, which ultimately results in the healthiest community.
Yet, when I started Orbited 3-4 years ago, I never intended to be married to the project forever. My hope has always been that some people/projects/companies that are depending on the Orbited would be willing to commit substantial engineering resources to fix bugs and implement new features, and from those contributions some new core committers would emerge. Unfortunately, my work still accounts for about 95% of the 0.7.x branch which is the last stable release.
I feel like Orbited is far behind, considering I haven't been involved in a release in about 2 years, and no one else has really stepped up. I am always shocked, truthfully, when I hear success stories and see people building applications with it still. The code base has remained unchanged through about 10 browser releases.
Great, that's their prerogative... its MIT licensed software. But I can tell you, after this sort of interaction for years, I no longer invest my time in Orbited, and instead I bill $250/hr to share my expertise with consumer facing internet startup companies.
One actual data point to add this discussion anyway.
[ edit for spelling ]
http://en.wikipedia.org/wiki/Mark_Spencer_(computer_engineer...
I don't why this "matters" in copyright infringement litigation except perhaps in calculating damages. However, even in the absence of proven profits by Google on account of the alleged infringement, or losses by Oracle, there can still be statutory damages[1] which, in many cases, could be pretty steep.
[1]: http://en.wikipedia.org/wiki/Statutory_damages_for_copyright...