HNHacker News
TopNewBestAskShowJobs

mdpm

224 karma · joined January 26, 2011

submissionscomments
mdpm··on It's time to abolish the HTTP referer
I've seen this as a security issue several times, where older enterprise tools have embedded URL session keys (horrible, I know) or other private data, and act as the referrer to public sites. This either exposes more of these tools' data and functions to traffic sniffers, or malicious site operators.

There is no legitimate purpose to the referrer within applications that isn't replaceable via internal claims based tokens, or external sites' parameterised (thus, opt in) source tracking.

mdpm··on Spies should be able to monitor all online messaging, says David Cameron
A repeat of the same idiocy; You cannot solve cultural problems with process or technical solutions.
mdpm··on FizzBuzz Enterprise Edition
Why would you need more than one?

(my version - https://gist.github.com/vai/4647768 )

mdpm··on How Short Can You Write Fizz Buzz?
I liked my 4 (non boilerplate), readable lines in nemerle -

https://gist.github.com/vai/4647768

mdpm··on Ask HN: Productivity tools for windows 8?
conemu provides the drop down natively too :)
mdpm··on Ask HN: Productivity tools for windows 8?
preme, listary, cmder/conemu. that's a good start.
mdpm··on Using implicit operator overloads to keep your C# API discoverable and open
The only justification for not using fixed static values here (ala enums - an enumeration of possible values) is the potential case of having values that are dynamic at run-time, rather than design-time.

Being as that the article consistently refers to these being fixed values, and that they're optimising for 3rd party use of their library, that doesn't seem to be the case.

This seems to be the classic case of a solution looking for a problem.

mdpm··on Deluxe Paint III (1989)
I just had to add - http://i.imgur.com/vipChuH.jpg

3 disks.

mdpm··on Deluxe Paint III (1989)
I grew up with this (actually have the box next to me!), PageStream for DTP, and Scala for video titling. I was utterly flabbergasted when I discovered DOS and mouseless PCs (back when we still called them IBM compatibles).

Ah, nostalgia.

mdpm··on Omaha: Software installer and auto-updater for Windows
Haven't managed to get it to actually work, more than once (Tried to follow docs when it was shimmer, dead ends, ditto now)
mdpm··on Dependency injection is not a virtue
When looking at code, I like to separate design-time concerns from runtime ones. Tests are a design-time affair, and if you are substantially altering the run-time composition of your application to accommodate such things, the approach is likely wrong.
mdpm··on Show HN: I think I re-imagined IRC on mobile devices
also, fwiw, irssi itself can be a persistent proxy, so you could just implement a native client.
mdpm··on Show HN: I think I re-imagined IRC on mobile devices
right. I'm on android so not too familiar with the iphone's clients. It's just the simplest works-everywhere (mobile, desktop, laptop, etc.) scenario for me, and I'm in the same place, same windows, buffers.
mdpm··on Show HN: I think I re-imagined IRC on mobile devices
screen + irssi? http is a less than ideal fit for messaging, especially when you're simply wrapping an existing protocol.
mdpm··on Engineering pornography - underground power cables gone wrong
while ths is a classic, my snark is thrashing against its bonds.

I could have sworn it said 'news' up there.

mdpm··on 30kloc and $0 revenue. Lessons from my failed startup (& code release)
First: a time / value mismatch; students don't want to spend more time doing something, then waiting before they get feedback, and your PhD students are taking longer to crit, annotate, explain their reasoning etc. through an interface than they would take vocally. In fact, a paid telephonic [ VOIPic? - Ed. ] mentorship service would probably do better.

Second: you didn't understand the market, not just your customers. The market is _everyone_ you have to deal with, not just those that buy the bread.

Third: I'd place PG's #5 (Obstinacy) covers both your 'knowing how to code' problem, and the fixated / obliviousness.

Knowing how to do something is just knowledge. Knowing why, when, and when not to is wisdom. In the end, it sounds like you're glad that you could afford the lessons.

mdpm··on Top 20 Motivation Hacks
There is only only one motivation, ever. Actual desire.

In short, these articles exist because people are trying to rationalise their way past the cognitive dissonance of wanting to want things, without being willing to actually change themselves.

Decision making is fundamentally a process of "I want, there is no greater want, I can, so I will". If you're not getting to do what you want, it's simply that you have a greater want. Sometimes that's just a want to not actually exert effort.

tl;dr - you will not change what you do without changing what you are.

mdpm··on "F# async on the server side" - node.fs in waiting?
cough

There are things like https://github.com/panesofglass/frack already. That's not the only one. This entire approach running on the stack and frameworks it can is a massive deal, and running silent at present.

mdpm··on ICANN Approves generic top-level domains
yes, and we could continue into checking something is actually listening for mail there, etc. But you get my point :)
mdpm··on ICANN Approves generic top-level domains
uh, nope. Email validation should check there's a valid MX record for the domain in question, and leave it at that.
mdpm··on Google reminds users to "Call Dad", makes users angry
There are a few sides to this one:

On the practical, implementation detail side of this, users should have been allowed to remove the item. I'm sure the reason that didn't happen is simply because of the way it was implemented, and implementing the item as something that was actually per-user would simply have pushed into the 'not happening' zone.

As regards, morals, sensibilities and where the hell 'right' is on the larger picture the answer is 'who knows?' - Personally, I think the fact that a slight prompting would have resulted in millions of tiny acts of goodness, and a few larger ones of users being upset, but there's no particular metric one can apply there. My intuition says the balance falls largely on the side of it being a net postitive for their users at large, and their families too.

As far as those offended go, I'm sort of reminded of the parallels with doctors and malpractice suits - hundreds of lives saved, helped, made more comfortable, and it' can take one slip-up to undo all of it. No, it's not a 'gtfover it', but it's not so much the message appearing as the inability to control it that led to a small slight being taken as an offense. Anger is almost always fear, and fear almost always a simple desire to not be hurt, and the inability to stop it continuing to prompt them - that likely just resonated with the aspects of whatever hurt in the first place, whether it was mortality, abuse or anything else.

No one meant any offense, and there was a person, and then people who thought they'd do something they thought would be good, and might make a few people happier (and possibly serve their employer's larger aims too).

They didn't do a bad thing. They did a good thing, badly.

mdpm··on Ask HN: How many employees before you can call yourself CE0 & not sound foolish?
'Chief' is sort of redundant if there are no other 'executive officers'. 'Officer' too if it's just you.

I prefer 'Director'.

edit: as per https://secure.wikimedia.org/wikipedia/en/wiki/Executive_Dir...

mdpm··on ASK HN: Can any of you solve this?
most of that is simple geometry (heh). The interesting parts creep in with the 'non-ideal' conditions.

You're not just referring to the percentage of the surface area of a sphere (which earth isn't), atmospheric distribution isn't uniform even if we go by volume (or should we be going by density?), then there's the curvature of light in the atmosphere to take into consideration, and the arbitrary descisions as to what height above sea level our observer is standing at, the variable nature of the tropopause ...

an interesting problem, but likely more interesting as a mental exercise than in actual execution.

mdpm··on Google Chrome Hacked?
the video is edited, right about when he's showing process explorer post-exploit. the cursor suddenly leaps across the screen, so assuming they're covering up the other child process of the main chrome process is fair. strangely, process explorer's 'process count' only goes up by 1, despite launching calc, and (seemingly) another child process. To be over-zealous, the single row of visible pixels for that other process is consistent with rundll32.exe.

That still doesn't mean that it's not a chrome bug - the exploit may use flash to retrieve the payload, make use of flash-js communication, flash-chrome communication quirks etc.

mdpm··on Fossil Versus Git
... or just go install your own gitorius, and continue benefiting from all the tooling support you already enjoy.
mdpm··on Joe Hewitt : I'm an indie developer now.
are you aware of https://code.google.com/p/css-x-fire/ ? Round trip editing is ... life altering.

I've enjoyed webstorm, and that add-in is really the icing on the cake.

edit: ... and then I read the next comment :)

mdpm··on Ask HN: Beginning freelance web developer: no clients - portfolio?
> If the former, you'd be guilty of overengineering and missing your client's objective (by being too costly, too complicated, etc). If the latter, why would you care to explain and "do the right thing" (the client will not pay for things he doesn't know are important)?

Too often developers do what we see as 'right' technically, which is not necessarily 'right' for the client / project. It's not something to be 'guilty' of, just something to be aware of. Although there is a balance - I've often fought for things and had them save the client's ass later.

And as for explaining why something is important - because the client should have an appreciation for why they hired _you_, not someone else.

mdpm··on Ask HN: Beginning freelance web developer: no clients - portfolio?
I've been freelancing and doing contract work my entire career - nigh on 13 years now. There's a mass of things I could tell you, but I'll try be succinct and tell you what I think will be most valuable.

Technology doesn't pay the bills. Clean code, good architecture, solid frameworks - they count far, far less than you wish they did. As developers, we're systems oriented, looking for the ideal approach, the 'right' way. 90% of clients are more worried about the right shade of cornflower blue. Don't lose your idealism about making use of the right tech stack, and where pragmatic, don't miss an opportunity to explain why it's important.

But don't make the mistake of thinking that's what counts for clients. There will be exceptions, but generally the guy with the purse strings isn't technical, and is in no position to appraise your use of tech.

You need to practice business as much as you plan to demonstrate technical competence. Negotiation, selling, conflict resolution (it'll happen), knowing when to walk away (that too) and probably the hardest thing - embracing risk. Many chant the 'fail fast' mantra, but I'd rather point out that our caveman brains are badly suited to accepting that risk is vital. Cold calling is terrifying, as is naming a price, telling a client they're wrong, and so many parts of simply staying alive.

Otherwise, go make some luck.

mdpm··on Joel Spolsky: Lunch
The best place I ever worked at was small: ~7 people.

We ate together every day. Every day of the week, it was someone's duty to make lunch. I mean that, make it. You started an hour before lunch, went to the kitchen and made a meal. Generally a full hot meal. We got every variety you could think of - people enjoyed the time out creating someting different, something else for their co-workers to enjoy, and it Worked.

We got to sit outside, in the garden, next to the pool, and eat lunch (and yes, there was beer). And if it was Friday, well. Then we started a fire, and had some more beer. And there may have been instruments. And our respective children running about.

Not bad for a bespoke dev company. Not bad at all.

To address some of the other points raised in the comments -

No-one was forced to be there, if they wanted to go out for lunch they could. Few did, and rarely. More important than an individual's 'desire to associate' is whether they fit in. If they don't, they likely don't belong on that team. Ditto for if they can't communicate honestly (positively or negatively) about/with peers/managers.

mdpm··on Finally someone makes sense of JavaScript's this keyword
dear coffeescript,

thank you for =>

← PreviousPage 4 of 5Next →