HNHacker News
TopNewBestAskShowJobs

mqzaidi

237 karma · joined July 25, 2010

submissionscomments
mqzaidi··on Ask HN: What is wrong with Reserve Bank of India?
Recurring subscriptions are live on paytm.com.
mqzaidi··on Jon Ronson: How a Tweet Can Ruin Your Life
I remember this too. When sendgrid was ddosed, as a company that entirely depended on sendgrid to send mails (I had joined recently), we were affected too. Since then, we run postfix and use multiple email providers behind it, but ironic how a tweet affected so many people.
mqzaidi··on Io.js 1.0.0
For a comparison, node.js contributors are (http://nodejs.org/about/core-team/)

TJ Fontaine Alexis Campailla Fedor Indutny Trevor Norris Nathan Rajlich

Rather strange to see Fedor as a core team member in both projects, or at least one of them (likely node.js page) is out of date.

mqzaidi··on India Opens 15M Bank Accounts in Modi’s Inclusion Drive
lets give them credit cards.
mqzaidi··on Maintaining digital certificate security
The CCA is so aware of its own vulnerability, it refrains from the use of SSL on its own page http://cca.gov.in/cca/index.php - no https here :)
mqzaidi··on India's Pointless Search for 'Black Money'
Your evidence is anecdotal. The article, to its credit, has actual references, as in what Baba Ramdev said, and a good deal of people believe him.

Just see a gamut of India opinions here, https://in.toluna.com/opinions/1277868/what-will-happen-if-a...

mqzaidi··on M64.pl – how I learned that the default settings are not production settings
You should also run logwatch - it will show you all the attempts that keep happening on any public servers running ssh. I once had to look at a box compromised, which was then used to brute force other servers, and it contained a file with 100-200 passwords for other hosts it brute-forced.
mqzaidi··on Pluto Mail – Unsend Emails
Now that google fetches the images from its own servers once and then renders for all, would this even work?
mqzaidi··on Consciousness as a State of Matter
quantom factorization, hilbert spaces, fourier transforms and error correcting codes, all of these would be found in any quantum mechanics 101 course, definitely far from unrelated.
mqzaidi··on Vim.js - JavaScript port of Vim
Rule 34 for software: If it exists, there IS a javascript port of it.
mqzaidi··on Use a Google Spreadsheet as your JSON backend
You can also use the Google query language to do more with the API - see http://qzaidi.github.io/2013/10/05/quranjs/
mqzaidi··on Mozilla Labs: TogetherJS
Looks like this would be great for customer support, and could be a nice alternative to olark. It can be configured to automatically post the invite url to another dashboard, where one of the CS execs can pick up and walk the user through.
mqzaidi··on Google Analytics Launches Real Time API In Beta
After I wrote a script to scrape this data client side (https://qzaidi.github.com/2013/06/23/dashboards-with-dashing...), I guess this was bound to happen. Murphy's law
mqzaidi··on Buy An Ad, Own a Browser Botnet
Iframe sandboxing is the solution - removing allowscripts permission will fix this.

http://www.html5rocks.com/en/tutorials/security/sandboxed-if...

Now it may be argued that genuine Rich HTML ads do need javascript, for example, to expand or interact with the page. To me, the solution to this is to limit what sort of javascript is allowed to run. We need an mraid.js for the web, which specifies the subset of javascript that could be run.

I don't think it will happen until there is a major attack. Other than botnets, javascript can mess with cookies, steal data, and do a lot of damage.

mqzaidi··on Texas teen in jail for his Facebook comment
Thinking out loud and trying to extrapolate, but how is this different from a thought crime? If tomorrow tech progresses to a point when people's crazy thoughts could be read, would it be justified taking pre-emptive action like this.
mqzaidi··on Product Managers, Stop Pissing Off The Engineers
There are 2 specialized positions (not roles) that I have been able to eliminate in a couple of successful projects (in a startup). These are Product Management and Quality Assurance. I think both the tasks are important enough to be entrusted to engineers, rather than getting someone else do it.
mqzaidi··on Ask HN: could an EC2 microinstance handle being on TechCrunch or front page HN?
Not worth the risk. While the micro instances can handle the load and have good burst performance, they aren't good if the load is sustained. So if you get a sudden burst, and load average jumps, expect EC2 to penalize you.

See steal time and stolen CPU - http://www.newvem.com/whats-cpu-steal-time.

I have seen a micro instance become unaccessible to even ssh after a prolonged activity.

mqzaidi··on Autoscaling on AWS
We enable auto applying security updates in the AMI, and the first thing the provisioning script does is update packages. That said, I would definitely want to explore alternatives - not needing to update while provisioning will take a few seconds off the provisioning time.
mqzaidi··on Autoscaling on AWS
You are right - committed a fix, but looks like github is taking longer to rebuild the pages.
mqzaidi··on Autoscaling on AWS
Thats dashing from shopify. Its really awesome, took me only an hour or so to setup with the integrations. Here's the original https://github.com/Shopify/dashing.

I am using the nodejs port though - npm install dashing-js

mqzaidi··on A Popular Ad Blocker Also Helps the Ad Industry
While browser/device fingerprinting has made great strides, if this was really pointless, you wouldn't see so much of hue and cry over some mozillas decisions to block third party cookies. (http://www.iab.net/mozilla).

Flashcookie and localstorage based techniques are hardly legal. Store user profiles server side, but you will still be fooled by a different visitor id in the cookie (and fingerprint for that matter), won't you?

mqzaidi··on A Popular Ad Blocker Also Helps the Ad Industry
That's already been implemented. With the shift to CPC, there are people who write that kind of software and sell to sleazy publishers. On the other side, ad servers have a fraud detection module that looks for those random clicks.
mqzaidi··on A Popular Ad Blocker Also Helps the Ad Industry
I have always wanted to make an extension which would use a random cookie (from any of the users) instead of just blocking ads. This would totally mess up their targeting and reports. It would not help the ad industry at all.

Given that I have spent years working in the ad industry and writing ad servers, this is somewhat ironic.

mqzaidi··on Amazon India is now live
Its not just cultural, but financial, unless you consider tax evasion a part of culture. A lot of Indians don't want to spend via credit cards because the money is 'black', i.e. unaccounted for. This is a big reason for COD, esp. among the business class.
mqzaidi··on Gmail: Introducing Actions in the Inbox
Same here, didn't work. Tried it on an app domain and @gmail.com address as well.
mqzaidi··on Why a man eats another man's heart
Maybe its not politically correct to point it out, but here is a bit of history.This isn't unprecedented in Arabia.

Hind, the pagan wife of Abu Sufyan, hired a slave to assassinate Hamzah, an uncle of Prophet Muhammad, and then chewed his liver. http://en.wikipedia.org/wiki/Hind_bint_Utbah

What kind of people do that? People who feel Hind is worthy of emulation and respect, because she eventually accepted Islam.

mqzaidi··on HN no longer supporting SPDY
spdycheck.org should also check the other assets on page to see if spdy is supported.

In a lot of cases, it makes sense to only switch the asset/cdn server to spdy. Maybe there should be something like partial support, which should indicate what fraction of requests (by count and by size) support spdy.

mqzaidi··on Show HN: Use your phone to present slides on any screen
Looks awesome from the demo,but I can't sign up because you are classifying my perfectly valid .me email as invalid address.
mqzaidi··on PHP is the right tool for the job (for all the wrong reasons)
Try dropping files in an environment where apache / php is not installed, or where db drivers or gd bindings are missing. Or try to set it up with nginx and php5-fpm.

There is a big difference in being ubiquitious and being easy to use, and lets not infer casuality where there is none. Most popular PHP projects come with a good installer, but go to sourceforge and try a lesser known project. Or go back to the 90s and see if installing drupal or wordpress was as easy.

I can argue that shell scripting is the best programming language by this logic.

mqzaidi··on Why GitHub’s pricing model stinks (for us)
because the npm modules are proprietary and can't be open sourced.
Page 1 of 2Next →