HNHacker News
TopNewBestAskShowJobs

robmil

335 karma · joined April 6, 2012

https://robm.me.uk r@robm.me.uk

[ my public key: https://keybase.io/robmil; my proof: https://keybase.io/robmil/sigs/x_AOtOjtMev0kghH-FH4D5BvfrDlPtKBKlRF83jdcxs ]

submissionscomments
robmil··on Teller on theft in magic
Stewart Lee has a brilliantly cutting routine about Joe Pasquale's joke-stealing, if anyone hasn't seen it: http://www.youtube.com/watch?v=0YE9Kthyaco
robmil··on Teller on theft in magic
There's also an interesting parallel with standup comedy. At least here in the UK, the stealing of jokes by mainstream comedians from alternative performers is — while not accepted — viewed by the victims of the theft as just one of those things that happens, something to be ridiculed rather than something that can or should be fought.
robmil··on Teller on theft in magic
The argument (which I'm by no means seeking to make) would presumably be that knockoffs don't necessarily have to capture the same spirit as the original in order to devalue the original — and, indeed, the very fact that they don't capture the spirit of the original is what makes their devaluing influence most powerful.
robmil··on Teller on theft in magic
That's the big question, with a universal application: that tension between the fact that knockoffs have a diluting effect on the original, and the idea that if your idea can so readily be copied it's perhaps not worthy of protection.
robmil··on Teller on theft in magic
Especially interesting when viewed in the context of recent patent disputes in the tech world. To hear Teller talk and to hear his performances described conveys that ethereal, intangible quality that "the real thing" has and that knockoffs generally fail to capture — a quality that seems instinctively to be deserving of protection.
robmil··on Virgin Mobile leaves six million subscriber accounts wide open
An alternative might be for the user to be able to request that the block is cleared, and for that process to send out an automated email; if the user clicks the link in the email, the block is cleared.

It's no less secure than a password reset and would mean that legitimate account owners can't be locked out of their accounts by attackers.

robmil··on Virgin Mobile leaves six million subscriber accounts wide open
Instead of freezing the account until it's unlocked by customer service, why not just lock it for increasingly longer periods of time? 2 seconds after the third failed attempt, 3 after the fourth, 5 after the sixth, 10 after the seventh, etc.

Not too inconvenient for legitimate users trying to remember their passwords, but it surely makes bruteforcing impossible (if by the 1,000th attempt they're having to wait an hour between attempts).

robmil··on OSX password script for everyone to know
Is this sarcasm? You clicked "Allow"; what would you expect of an application to which you granted access to your keychain, other than for that application to thereby gain access to your keychain?
robmil··on Show HN: We built a better solution for customer analysis and support
That's not what a double negative is: neither of those words are negatives. Pejorative, maybe, but it's not as though they cancel each other out like "not not" does.
robmil··on Deadbook, the Long-term Facebook
I'm not sure if it is excessively literal, though; if Facebook disappears within 10 or 30 or 50 years, presumably all of the data on Facebook will disappear with it.

Even ancient civilisations kept orders of magnitude more records than have survived now, and they even had the added bonus of being physical — with linguistics the only obstacle to future generations' reading of their content. Our mass of data that seems so permanent is wrapped up in proprietary file formats; it's stored on volatile media; and it's kept around by companies who, in the context of centuries, are flashes in the pan.

How much of the digital information you possessed even ten years ago is still readily accessible? I know in my case there's not a great deal. Now extrapolate that forward 50, 100, 150 years…

robmil··on Why passwords have never been weaker—and crackers have never been stronger
Since MD5 hashes and bcrypt hashes are recognisably different: when the user next successfully logs in, check if they have an MD5 hash; if they do, use the password they just submitted (that you know is correct) to generate a bcrypt hash and then update your password database with that.

If you have a large number of inactive users, this might not be as effective (you'll still be left with lots of MD5 hashes in the event of a dump) but for other sites it can be quite useful.

You can also use the same strategy to increase the work rate of your bcrypt hashes in the future.

robmil··on Racter: a 1980s, oddly (randomly) profound "AI"
Also interesting is this collection of "poetry" generated by Racter after it was released to the general public: http://www.101bananas.com/poems/racter.html

It's interesting how, long after one is aware of the complete randomness of output like this, one's monkey brain is still prepared — against all rationality — to read profundity into gibberish.

robmil··on How To Write Good Log Messages
underscore-cli is utterly brilliant for this, even better — dare I say it? — than traditional log files with cut/grep/awk. Being able to treat logs as a dataset that can be mapped/reduced/flattened/grouped/otherwise analysed is life-changingly good.

About the strongest endorsement I can give is that it makes me wish more of my logs were in JSON format, rather than wishing that less were as I always had before.

robmil··on Textmate2 Goes Open Source
Vintage mode is admittedly getting more complete every day, but as a regular Vim user the absences that exist are often a jolting distraction — attempting to use some command that doesn't exist jerks you out of your flow and it feels so inefficient to then have to remember the Sublime way of doing things.

I find it more annoying than the lack of, say, Cmd + T in MacVim, so I've found myself spending more and more time using that — even after a concerted effort to use SublimeText for a while.

robmil··on Textmate2 Goes Open Source
Oh, not at all — but it does make the potential hubris of a rewrite (slightly) more understandable. When you have no time for a rewrite because competition is fierce, the question never really comes up; it's not necessarily the conscious avoidance of "second system effect" that it might seem.
robmil··on Textmate2 Goes Open Source
That, and a reflection of the ecosystem as it was when TM2 first started development; it's a lot easier to countenance a full rewrite when you're by far the dominant player in your particular market.
robmil··on Automatically avoiding mixed-content warnings when using SSL
While that's true, is there any scope for attack through images?

It's a generally interesting point though, that feeds into questions of what the general purpose of SSL is. This still has benefits for the end user — the café owner/hotel company/etc. can't modify their connection — and so surely is better than nothing, but is it enough?

robmil··on Lazy Loading Social Widgets
There's a great project for doing the actual lazy-loading, called Socialite.js: http://www.socialitejs.com/

You can work to whatever actually hooks you want (onscroll, onhover, etc.), and then just call Socialite to actually replace the links.

← PreviousPage 3 of 3