HNHacker News
TopNewBestAskShowJobs

nulluk

137 karma · joined January 5, 2012

submissionscomments
nulluk··on SEOs Are Not Growth Hackers
I feel this is a little pet issue of mine or maybe even its just due to my limited domain experience but I have still yet to meet a single "SEO" who doesn't feel slimy and feel like a snake oil salesman. Everyone that I have personally encountered have been what seems in my eyes a few months behind, non technical and willing to ultimately screw over the client with stuff that is clearly aimed directly at manipulating google instead of improving the overall user experience for the end customers.

I personally see and feel better taking the approach of building a technically sound websites with good UX, getting a dedicated marketing manager who can write good copy (and not this SEO drivel of 10 paragraphs with no substance) and then know how to engage with customers instead.

nulluk··on ICANN reveals objections to proposed top level domains
Can someone cross reference this to the list of gTLD that were initially submitted? To see what ones weren't objected to?
nulluk··on Ask HN: Are you alone in San Francisco on Thanksgiving?
Give us a follow on twitter @nullUk

There is a preston Geekup to but i'm not involved with it as much as the blackpool one as I work with a few of the people who help organise & run it even though we all work in Chorley.

nulluk··on Ask HN: Are you alone in San Francisco on Thanksgiving?
Geekup (blackpool) generally have a christmas meal. It isn't the same but it's as close as your going to get. Good bunch of guys that go from the NW, most of @wearefarm will be there which are based around the corner from you
nulluk··on Show HN: Powderkeg, a realtime, synchronous, multiplayer HTML5 action game
Really well done & polished. Had a few moments where the lag made it unbearable but besides that it works as expected.
nulluk··on Shorter .uk Internet domain proposed by Nominet
Seems to be a lot of money grabbing going on recently with .xxx and the new GTLDS.

If this is seriously a problem (which I honestly feel it isn't, considering we have gov.uk, nhs.uk, and sch.uk to name a few so .co.uk seems well places for companies within the uk) then why not just allow them to come in tandem? so when you purchase a .co.uk you automatically get the .uk variant as well included in the price.

Controlling a GTLD seems like a really good idea at the moment considering you can effectively just create a market for yourself based on other peoples desired to protect there brand. If you care about your brand your going to have to stump up another yearly registration fee when someones else decides to sell your brand name variant under there GTLD to the highest bidder

nulluk··on Show HN: EasyPost - the Stripe for postage
International is where this could really shine, print out at the location closest to where the letter needs delivering & avoid international prices
nulluk··on Stripe CTF Writeup
Someone else was getting in requests between yours causing the port numbers to increase.

You had to accommodate for it in your script, if you received a number higher than the expected diff then you needed to keep sending the same request till you where sure they hit concurrently.

Basically the time to crack got longer the more people who were trying to crack it, it became an optimisation race in the end about who could get the requests in faster/closer together

I ended up finishing #65 due to not wanting to rewrite my slow python script. It took upwards of an hour to get a single chunk because of the load

nulluk··on Stripe CTF Writeup
unfortunately i ended up with String.fromCharCode, would of made the final code a lot more readable! https://gist.github.com/3527252
nulluk··on HTML5 Boilerplate v4.0.0
Glad to see this stripped right back down again to a useful state, it started to get very verbose & noisey
nulluk··on Apple’s in-app purchasing process circumvented by Russian hacker
This is really easy to do and a fun experiment to learn MITM attacks. My boss was gloating he was the best at jetpack joyride and the whole office had a good laugh knowing that I could always beat his best score by a small amount the day after het set it. Apparently that put a downer on his christmas because he spent so much time trying to beat me.

It did cross my mind whilst watching the traffic if you could spoof in app purchases but never took it any further.

nulluk··on Tuts+ Premium Account Security Compromised
I have talked about & mentioned something similar before but bundeling the whole thing into a browser extension.

Every site you hit gets checked against a local list thats periodically updated. It throws up an information bar with bad security practices associated with the site you are browsing, everything from mailing plaintext password to the idiotic things like above.

If it becomes trusted enough it might move some developers/organisations to actually take action, if not it will at least warn individuals of the obvious problems before they signup and not afterwards like at the moment.

Edit: Last sentence didn't make sense.

nulluk··on Twitter Completely Down
Have just had to add timeouts to a few requests to the twitter API. Was completely hanging a whole site. Learn't something though, to never trust an API to respond in a reasonable amount of time!
nulluk··on Internet-Draft: JSON Hypertext Application Language (lean format for linking)
Sorry to be off topic here but is there a standard for laying out specification documents like this that i can read up on? When ever I come across these they are always well thought out and nicely presented. It would be a nice way to present ideas due to the documents feeling well thought out and structured as apposed to a simple idea scribbled down.
nulluk··on EHarmony confirms password breach
With all these breaches my idea for a browser extension that stores a blacklist of websites & warns you about them mailing plaintext passwords, insecure password authentication or storing credit card details BEFORE I sign up has never been more appealing
nulluk··on Testing 3 million hyperlinks, lessons learned
canonical links are only hints to google (all be it very strong) they always reserve the right to ignore it if they think a webmaster is shooting themselves in the foot, that in itself is where the problem is. If I built up a few hundred links to example.com/1234-this-site-sucks I'm sure google would think that is the correct url rather than the canonical link version of example.com/1234-the-real-slug
nulluk··on Testing 3 million hyperlinks, lessons learned
I wouldn't recommend having the "pretty" part not validated. It can cause some serious issues with google & duplicate content and if someone wants to be malicious they can create a bunch of fake urls that essentially point to the same page, or even worse if they receive enough links they can be indexed at the new "fake" url. A similar thing happened to a newspapers website but I can't recall who of the top of my head.

Another potential solution & my preferred method is whenever a change is made that would affect the url of a page. Update a "legacy" table with the old url and the location of the new url, next time a 404 is going to be thrown do a search against the database & redirect accordingly if a new url is found. I rolled this approach into https://github.com/leonsmith/django-legacy-url and whilst it's not polished it's by far the easiest & probably most automatic/maintainable solution I have found.

nulluk··on Cookie warning on bbc website
I thought you had to get explicit opt in? Simply hitting the page once and refreshing sets the cookie so you will never see the message again doesn't sound like explicit opt in to me?
nulluk··on Can an Algorithm Write a Better News Story Than a Human Reporter?
Credit to them at least the "No" is within the second paragraph as apposed to the end of the article which is normally the case
nulluk··on How To Build A Startup From A Beach
Your site has been hacked and is only showing the hacked pages when the request looks like its from google.

If you wget on of your blog articles you can see an example. (Registering your site with webmaster tools google would of notified you if it sees suspicious activity like this)

There will most likely be a base a base 64 encoded string at the top of your index.php file than when you decode will contain the exploit.

Keep wordpress up to date.

nulluk··on Watch me work: Video of me building a new Rails app from scratch
I'm doing something similar with all my personal projects, but not quite a live video, more a time lapse style so a picture every 30 seconds. It's not for overcoming procrastination for myself, but to focus me & stop me instinctively browsing my regular sites when a difficult section arises.

It's also prompting me to become more efficient as I know when the project is finished & the video compiled it will be watched by my peers who will hopefully provide some insightful feedback!

nulluk··on An employee, whose last name is Null, kills our employee lookup app
There is also the guy who owns bar.com which received alot of mail to foo@bar.com, its worth a read if only for this paragraph.

I MX’d the mail over to a friend’s spam-detection system for about 4 hours one time, but the volume crashed his server and he asked for relief.

nulluk··on We work a 4-day week and just raised $4.75m
I think this article hits the nail on the head regarding 4 day weeks.

I currently work a 4 day week (4x10 hour days) allowing a whole extra day to focus on external activities and interests that i dont get to fully peruse at work due to contraints and/or conflict of interest.

It's such a big change in life style and as Ryan mentioned in the article it fosters such good energy and a totally refreshed feel come a monday morning.

And again just like the employee mentioned in the article it's such a benefit that I wouldn't even consider a move in companies unless it was matched like for like (or better).

nulluk··on Learn to Pick Locks for Fun and an Increased Understanding of Security
After being involved within the family business (lock smiths and security engineers) for 3 years whilst in college, you end up realising how insecure and inadequate 80% of the locks around you are.

Any person with a small degree of knowledge can do some serious amount of damage if they wanted to turn rouge. (Bump keys and Snappers) Saying that it is a very fascinating skill to learn, the social response to stating that you are a trained locksmith in conversations is quite interesting.

nulluk··on Show HN: Worldle- 24 Hour real time boggle HTML5 hackathon game
So far there has been several GIF's embedded. An alert for your document.cookie, and a redirect to another gif. You can safely say it's not escaping the HTML input on the leader board.

Also the matching words shouldn't be passed to the client, keep as much data server side as possible to elevate some of the cheating, your never going to stop all of it but that should deter most people.

All in all though kudos, looks a decent outcome for a hack project.

nulluk··on Django Settings for Production and Development: Best Practices
We have a very similar approach except we encapsulate settings into its own package just for readability/maintainability. So it looks something like the following

    settings/
        __init__.py
        defaults.py
        dev.py
        live.py
        testing.py
        users/
            __init__.py
            *user specific settings*
nulluk··on Earle/django-bootstrap - GitHub
We have been including a similar thing in our project base for some time and have been through quite a few iterations & ways to implement something like this. Thus far we are using something very similar: https://github.com/theorm/django-bootstrap-forms
nulluk··on Ask HN: What's your experience with remote working? as employees/employers?
I have to disclose I am a remote worker for JonAtkinson.

I believe set estimates are not the best way to approach this problem because how do you estimate it? If you are in new territory then what seems trivial to one person may require some research and extra understanding by another. Also when you set a deadline it becomes more of a target for the individual action and instills a time wasting mentality.

It's especially difficult when a new employer enters the company as they feel under pressure that this is the expected deadline. One of the most helpful things Jon has done to elevate this situation when it arises is allow honest conversations without any fear which come from I guess a personal understanding/experience.

I also don't believe this problem is specific to remote working, it's simply a managerial problem within the industry as I am willing to openly admit this (having a problem and not speaking up) also happened at my previous job but the openness didn't exist hence a lot of dodging and ducking was performed until the task at hand was accomplished.

← PreviousPage 2 of 2