618 karma · joined December 4, 2013
West is becoming more like semi-urban India as the vice-versa... flattening.
A collection of individual tools that can be cherry-picked to solve nitty-gritty problems.
Convention > configuration
The easier it is to get going and contribute, the more people will use it. (Haskell pushed hard on this later on and has really benefited. Node did it early.)
There's political ammo now to make necessary changes in how things are done to make sure OpenSSL, TLS WG doesn't continue with business-as-usual.
Also, Google Express is way ahead given the number of trucks and cars going about from Costco and other local merchants, which is coming at Amazon from the other side.
Building it would effectively be starting from scratch and competing with FedEx, UPS, DHL and everyone else. And if it doesn't work, they'll be stuck with capital tied up in it.
Further, it's going to take a long time and a LOT of capital, and it still might not work AND still not be any better/cheaper, whereas FedEx is a known quantity that works. FedEx has a lot more experience than just delivery: it does lot of logistics and emergency logistics outsourcing for a lot of companies... and it would still be viable revenue if Amazon controlled them.
It's just optional, and therefore doesn't get used much on open source projects. So the average quality of code suffers.
Whereas something like Go where extra import are hard errors, making best-practices mandatory keeps code to certain standard and it's zero work to setup.
Java as a language though was a primary response to over-correct and over-optimize for secure, correct, safe code based on the history of C's shortcomings. There's are many other lessons that have been learned since.
Java is really hard to beat apart from specialized formal methods verifiers (coq, CVC4), strongly-typed functional languages Haskell and similar derivatives for embedded industrial systems. If you're involved in safety critical systems, you should be using the simplest and easiest to understand formal methods tools as possible. If something's too esoteric, fewer people will be able to double-check the work.
For wider participation, it's a tradeoff to use one of the more popular languages that lack correctness aspects because of the absence of a learning curve.
Static compilation and compilation speed make Go very attractive for large projects.
FedEx/UPS + Amazon merger would still be a good move and lock up last-mile distribution that only WalMart would be able to touch, but then WM would have to pay a premium for whichever chair would be left.
There were two, subtle factors in play: soft ageism and PI's hiring their clones (in thought, gender and race).
So the dept gravitated to predominantly two minorities, at least in terms of staff, faculty, visiting researchers and grad students.
In other news, I ported LibreSSL to OSX today[0].
Here's the go version I wrote, so there's no need for dep on Python/Ruby/etc on the target system:
setuser USERNAME COMMAND [args...]
# how to build it
go get github.com/steakknife/my_init/setuser
go build github.com/steakknife/my_init/setuser
# creates setuser exe here
[0] FR issue submitted as https://github.com/bruceg/daemontools-encore/issues/18 waitport [-u] port [timeout (float)] # -u = UDP instead of TCP
go get github.com/steakknife/my_init/waitport
go build github.com/steakknife/my_init/waitport
# creates waitport bin hereIf not, then this suggests a lack of clear guiding principles of what is in-scope and what is not &| insufficient questioning of adding new features.
Just gotta make sure OSPF, (E/I)BGP and L2/L3 drop these ranges though.
Also, accelerate the sunset of older specs so that deployed code will have to stay more current to even function, rather than interop'ing with old code that will never be patched.
https://github.com/steakknife/ruby-net-ldap
Shameless self-promotion: Clients call for this devil if something's hard or something's broken.
Edit: Can't take all the credit, client hacked together the first version but we managed to extract it for "the greater good." Also fun stuff like XML-RPC (Xen API -> gem xenapi, VMware (gem rbvmomi)), which wasn't bad and worked OOTB. Wished MS exposed their APIs as RESTful endpoints, because WinRM + gem winrm just doesn't cut it with some products... generated powershell run by an agent instead. For some products, even having the (.someextiforgot) files that describe the API, there's no MS docs on them, so lots of trial-and-error in PowerGUI to find the right objects and methods (Yuck).
Ruby: recompile with minimized OpenSSL 1.0.1+ (LibreSSL when possible) and with patches that improve Ruby's default OpenSSL security.
https://gist.github.com/steakknife/8228264
https://gist.github.com/steakknife/10092587
https://gist.github.com/steakknife/10096008
For Rails apps: use brakeman as one part of security audit strategy
For gem authors, sign them (please!): I wrote waxseal to make it dead simple
[sudo] gem cert --add <(curl -L https://gist.github.com/steakknife/5333881/raw/gem-public_cert.pem) # adds my cert (do once)
[sudo] gem install waxseal --trust-policy HighSecurity
For gem users, find which aren't signed Add this to ~/.gemrc gem line:
--trust-policy MediumSecurity
or just if there's no gem: .... already:
gem: --trust-policy MediumSecurity
For anyone using git, sign your tags (git tag -s ...) and commits (git commit -S ...) por favorhttps://raw.githubusercontent.com/steakknife/my_init/master/...