48 karma · joined May 30, 2012
I wonder if they meant that the default caching was turned off, or that all the queries had "no cache" clauses, or that an additional caching layer (Redis, Memcached) was not implemented?
It really helped to volunteer at a nearby homeless shelter (Pine Street Inn). I was comforted to see some of worst cases (including people I encountered daily) have access to meals, a clinic, a shelter, and treated with courtesy.
I was also struck by how many people seemed normal - not someone who was mentally ill or spent time on the street.
In general America fulfills a lot of need with private charity - which can occasionally be really impressive. When I worked at a large financial institution there were lots of opportunities for matched giving and volunteering opportunities. I wish tech companies would do this more.
Is this someone who needed a creative outlet or is there a specific goal?
However, the analogy is flawed because if you find a loophole in the law and it is discovered you are usually not liable. If, however, you find a "bug" in an inadequately secured system you are still likely to be liable for exploiting it. Similarly, if you find physical security exploit in a building (a broken window, unlocked) you can still liable for taking advantage of it (trespassing, etc).
However, you point was about "admiration" vs. "contempt." This is obviously a matter of opinion, but I don't share admiration for hackers who take advantage "exploits" without at least attempting to report or taking some other "good faith" action. Neither writing software nor governing a society is easy. Finding and reporting "bugs" is a helpful and productive activity, exploiting "bugs" is not.
And Spotify is better than piracy for record labels. (i) Spotify provides useful data for labels (at least those that have an ownership stake in Spotify), (ii) the revenue, in aggregate, is not insignificant and certainly better than revenue from piracy (again this benefits the labels with ownership stakes), and (iii) gives them a measure of messaging control.
Essentially, Spotify is marketing channel for major labels.
There are plenty of physical crimes that are easy to commit. For example, opening up someone's unlocked mailbox is technically a federal crime in the US (even if you don't take any thing and just put a leaflet there). Pointing out that a 'bad guy' could easily steal someone's mail by opening their mail box does not constitute security research.
Yes ultimately you need human eyes and on the product. It also helps to have someone with a QA mentality, who has a developed intuition for breaking things and finding edge cases. But rigorous use of automated testing, code review, and dogfooding greatly reduces the need for dedicated QA.
More eloquently stated: http://www.quora.com/Quality-Assurance-QA/When-is-not-having...
Ideally, most of the testing should be automated and engineers should be writing test cases as they build features.
They are very important if the software is mission-critical or if there is some sort of physical cost to shipping patches. But if you can continuously update the live site its not that big of a deal if a bug gets out. It will be noticed soon, often by your users, and then you fix it and that is it.
This works if the developers and other stakeholders at the company are testing the product themselves and are responsive and can triage bug reports quickly.
Having an up-to-date schedule can often be unrealistic as there can be shifting priorities and developers should be flexible to move around and respond as necessary.
Granted I am also relatively inexperienced. Self-taught and only worked in the field for 2 years. Maybe it would not work as well for someone with more experience. Their name was Jobspring btw.
In the end I had to choose between two offers. They encouraged me to take the slightly lesser paying one because they thought I would be happier in that position.
Talent agency model is definitely the way to go.