HNHacker News
TopNewBestAskShowJobs

tav

1,544 karma · joined December 10, 2008

Call me Tav.

I'm a hacker from London who works on decentralised systems.

Feel free to contact me for help/advice or just for a friendly chat:

tav@espians.com

http://tav.espians.com

https://twitter.com/tav

All content produced by me on HN is dedicated to the Public Domain:

* http://creativecommons.org/publicdomain/zero/1.0/

Use it however you want :)

[ my public key: https://keybase.io/tav; my proof: https://keybase.io/tav/sigs/mWU8_7ohyVhbWe4CC4-BULZt9ko__aSLRFa1T-GJ5xc ]

submissionscomments
tav··on We should retire Aaron's number
Nice thought Dave. Aaron did already address this in his "If I get hit by a truck..." post: http://www.aaronsw.com/2002/continuity

And Sean is most definitely on the case. But please give him some time and space.

tav··on Aaron's domain registration runs out in Sept. We should archive it in his memory
If IRC chat logs are legally admissible, I can provide documentation going back to at least 2001 of Aaron being in favour of putting all of his work into the Public Domain.
tav··on Introducing Contributions
As a fanatical user of calendaraboutnothing in the past, I'm stoked to see the streak graph on the profile page. As others have mentioned, it can be extremely motivating!

However, I really don't care for most of my popular repos or some of the external ones I've contributed to. My ideal would be to hide repos that I don't care about and to highlight the ones that I want to showcase.

The "Contribution Activity" stuff is totally fine, but given how much the public repos reflect the "personality" of an individual, I am a little saddened that it's being lost in the sea of popularity. It'd be nice to be able to reclaim some control over that.

Edit: To clarify, two of my popular repos with a few hundred watchers between them are efforts I spent all of a few evenings on. I am as proud of them as some notes I scribbled last week. In contrast, I have repos which I've poured months of effort into which I would rather highlight.

Likewise, one of the repos to which I recently contributed is of such subpar quality that I'd rather not be publicly associated with it so prominently. Whilst I'm happy to help others out, knowing that it'd be displayed in such a prominent manner acts as an anti-incentive to partake in low quality projects.

So, if any GitHubbers are listening... please replace "Popular Repositories" with "Highlighted Repositories" and give us more control over what gets displayed with regards repos we've contributed to. And, oh, whilst I'm at it, perhaps "Most Recent Streak" would be more motivating than "Current Streak" which I imagine would be at an awe-inspiring 0 for many of us way too often.

tav··on Galcon 2 Fully Funded on Kickstarter
I wouldn't normally post a Kickstarter, but as a startup founder I've found Galcon to be an amazingly fun way to take quick breaks. The best bit about it is the community — which has a surprising number of fellow startup founders who are really supportive. In recent games I've played with one of the guys behind an a16z-funded startup, a TechStars founder and a YC alumni.

As a multi-player strategy game, Galcon [1] is a lot of fun! And the guy behind the game, Phil Hassey, has made a lot of valuable open source contributions to the Python community like tinypy [2]. So, if you are looking for a good experience, Galcon 2 would be well worth it!

[1] http://www.galcon.com/fusion/

[2] http://www.tinypy.org/

tav··on Rust 0.5 released
I love both. If you are writing a production app today, I would strongly recommend Go. However, if you want to write an app that you want to take over the world with in a year or so, I would strongly recommend coding it in Rust.

Go is a beautifully minimal language and very easy to learn. Rust isn't quite as productive, but it won't be too foreign for most coders either — unlike the Erlangs and Haskells of this world. And whilst I've never missed generics in Go, I've already found them useful in Rust.

Rust's memory model takes a bit of time to understand, but it provides a lot more power and flexibility than Go is ever likely to. To get the same kind of fine-grained memory management in Go, you have to manually allocate and manage []byte slices. Not only does this get tedious, but you end up losing most of the benefits of static typing as well.

Rust is also exciting due to the lower-level nature of tasks (the unit of concurrency in Rust). Goroutines are awesome, but you are at the mercy of Go's runtime/scheduler. In Rust, the potential is there to even do interesting things like dynamically load new tasks at runtime — opening up possibilities like Erlang's hot swapping so that code can be changed without ever stopping the system.

However, despite the awesomeness of the language, Rust suffers from a terrible standard library at the moment. Even when Go was first released in 2009, it had a really impressive standard library. And, today, thanks to having superstar hackers like agl and bradfitz on its team, Go has some of the highest quality libraries around — especially in crypto, networking, http, etc. In comparison, Rust's standard library is rather poor with little attention having been paid to API design.

Rust also suffers in comparison to Go with regards tooling support. The 'go' command-line tool is awesome. I've not had a single dispute over style guides due to 'go fmt' and 'go doc'. The 'go fix' command really helped in auto-updating my Go code as the language evolved. The 'go build' tool saves me from having to write build scripts and Makefiles. And Go's (non-existent) package management system is absolutely brilliant — just 'go get github.com/user/repo'!

But, neither problems — quality of the standard library or tooling — are intractable in Rust. In fact, now that the language is starting to stabilise, I am highly confident that a lot of love and attention will be given to both of those issues. This is also an area where we, the community, can also help out a lot. Myself, I've slowly started working on a port of the 'go' tool called rusty:

* https://github.com/tav/rusty

And, having found the Rust developer community to be extremely friendly on #rust on irc.mozilla.org, I'm pretty sure they would be happy to have other interesting hackers join in too!

tav··on ITU Approves Deep Packet Inspection Recommendation
Out of interest, like what?
tav··on London Hacker News meetup: Thursday, 18 Oct
There is also Flagon's Den this evening if anyone else fancies going: http://london.flagonsden.com/
tav··on AWS Growth - Adding a Third Availability Zone in Tokyo
It's nice that they are expanding. But I really wish they would add IPv6 support for EC2 instances. It sucks to not be able to natively use IPv6 for UDP applications on EC2 :(
tav··on Will Go be the new go-to programming language?
This is one of the main reasons that I use Go. Its libraries are of significantly higher quality than most other languages. And since most libraries are native, it's much easier to expand on their capabilities without having to resort to forking some C extension like with Python.
tav··on The Coolest iPhone Photography Accessory You've Ever Seen.
Because it is a pretty cool project? Linking directly to the Kickstarter would have been more useful though: http://www.kickstarter.com/projects/impossible/impossible-in...
tav··on ToS;DR — TL;DR for Terms of Service and Privacy Policy
Make each of the line items clickable to reveal the detailed info. And perhaps move the current button to the top right of the block and rename it to something like "Expand All".
tav··on The weakest link by far is Apple
Even if Apple fix the account recovery process, the fact that any flaw in iCloud security could easily lead to all attached devices getting remotely wiped is extremely scary. All of your work gone in moments!

Don't get me wrong, remote wipes are useful. But they should be protected by some kind of a "Remote Wipe Authorization Passphrase" that the user must set up. Otherwise we are all simply at the mercy of the next access control vulnerability in iCloud.

tav··on Do you check HTTPS certificates in your API clients?
Sadly, that M2Crypto script doesn't check for certificates which are not trusted for issuing SSL server certs. So whilst it happens to skip a few, it will include over a dozen inappropriate certs in the final output!!

This is exactly the problem that https://github.com/agl/extract-nss-root-certs was written to solve. I'd strongly recommend using it.

tav··on Do you check HTTPS certificates in your API clients?
Disclaimer: I don't particularly agree with the Certificate Authority mechanism that we currently use with TLS.

However, given that it's what we currently have, I'd strongly advice taking advantage of the security that it provides. Requiring API client library authors to ship certs will make for poor security. Not only do certificates expire, they also get compromised.

It would be easy to conduct MITM attacks using revoked certs and API client library users would be none-the-wiser. Instead, it should be the responsibility of HTTPS client libraries to use the latest cacerts data and support features like OCSP [1] for validating certificate revocations, etc.

[1] http://en.wikipedia.org/wiki/Online_Certificate_Status_Proto...

tav··on Do you check HTTPS certificates in your API clients?
When you validate server certificates from HTTPS clients, please be sure to use the right set of root certs. Mozilla maintain a decent list of these [1], but it's not in the PEM format that most HTTPS client libraries expect, e.g. Python's ssl.wrap_socket(sock, ca_certs="certs.pem").

Mozilla's list also includes distrusted certificates, so you need to be careful to leave them out when generating the PEM-encoded format. In fact, I'd strongly recommend using Adam Langley's excellent extract-nss-root-certs tool [2] which takes care of the subtle details for you.

And, if you are willing to trust me, you can download my pre-generated PEM-encoded cacerts file from a month or so ago [3].

[1] https://mxr.mozilla.org/mozilla/source/security/nss/lib/ckfw...

[2] https://github.com/agl/extract-nss-root-certs

[3] https://github.com/downloads/tav/ampify/distfile.cacerts-201...

tav··on OAuth 3.0: the sane and simple way
Thanks — pushed that change.
tav··on OAuth 3.0: the sane and simple way
Great question. Unfortunately, it's not easy to do DNS queries from within today's browsers. However, all modern browsers already support [1] cross-origin XMLHttpRequests and the Access-Control-Allow-Origin header [2].

Thus a fixed URI like /.well-known/oauth.json would allow us to potentially do everything from service discovery to authorized requests from within client-side JavaScript apps without the need for server-side proxying or interpretation.

[1] http://caniuse.com/#feat=cors

[2] https://developer.mozilla.org/en/http_access_control

tav··on OAuth 3.0: the sane and simple way
My apologies. As donatzsky correctly assumed, I haven't checked the site on Windows for a long time. An overwhelming majority of my readers have tended to be on OS X or Linux. But thanks for letting me know. I'll make sure to test on Windows too the next time I do a design update. Cheers!
tav··on OAuth 3.0: the sane and simple way
Author here. I wrote this draft a few years ago after getting frustrated with OAuth 2.0. And, whilst I am grateful for llambda for posting it to HN, it was never meant to be published in this unfinished state. So please bear this in mind as you come across incomplete sections.

I never bothered to finish it back in 2010 since everyone seemed quite content with OAuth 2.0 at that time. However, now that it has been posted, I would love to know if anyone would like to see a completed version.

[Edit: Also, any criticisms of what's already there and thoughts on anything else you feel should be included would be really appreciated. Thanks!]

tav··on Google launches BigQuery - Analyze big data on the cloud
The Wikipedia dataset `publicdata:samples.wikipedia` is described here: https://developers.google.com/bigquery/docs/dataset-wikipedi...

Unfortunately it's not that interesting as it holds just the revision history. Earlier this week I was contemplating on writing a script to import the entire Wikipedia dataset into BigQuery. Has anyone else already done this or be interested in such a script?

tav··on Followup to “Not as SPDY as You Thought”
Seems to be down here too :(

Google cache: http://webcache.googleusercontent.com/search?q=cache:www.bel...

tav··on Kickstarter Redesign
Not seeing a redesign here... perhaps they are rolling it out gradually?
tav··on Plumbum: Pythonic Shell Combinators
It's not. The reasons that one might use `plumbum` are similar to the reasons that one might use `fabric` instead of just running local/remote shell scripts, i.e.

- Ability to leverage the richness of Python to pre/post-process the inputs/outputs from other shell commands.

- Easier to parameterise and maintain.

- Familiarity with Python over the likes of bash, zsh, etc.

tav··on Darcs - Another open source version control system
It's a sad day, the day a hacker refuses to look at something because they'd "have a very hard time getting others to do the same". By that same token we should avoid looking at the likes of Haskell, Erlang, Rust, etc. You are absolutely right that Git has come out on top, but Darcs definitely merits a look at least.

For what it's worth, I was in the Monotone [1] camp against Darcs back in the day... :)

[1] http://en.wikipedia.org/wiki/Monotone_(software)

tav··on Python Anywhere. Share Python/Bash/SQL console instances.
Together with Python e-learning courses this could be a real winner. I say this because back when I tutored compsci students, my most effective method was to use shared (GNU) screen sessions. The pair programming and the ability to see how others worked helped students become confident with Python a lot faster.

Unfortunately back then, students tended to use Windows and setting up Cygwin scared a lot of them before they even got around to doing any programming. A tool like Python Anywhere would definitely be a far more attractive approach if I were to do something similar today.

tav··on 7 Years Of YouTube Scalability Lessons In 30 Minutes
When Youtube refers to Vitess as being RPC-based, they are not referring to Sun RPC (callrpc), but rather to the generic design pattern of exposing service calls over the network. In particular, Vitess makes services callable [-] using either BSON or JSON serialisation over HTTP CONNECT calls.

[-] http://code.google.com/p/vitess/source/browse/go/rpcwrap/

tav··on JQuery Scroll Path - Scroll a page along a custom path
You can also be the 988th kind person to tweet this.

The use of the Tweet count to create the custom "tweet this" message is pretty cool.

tav··on Why we need Python in the Browser
Yes, you can compile PyPy to JavaScript. There even used to be a JS backend as part of the RPython translation toolchain, but it got dumped since no-one was interested in working on it [1]. There've been more successful attempts like RPythonic [2] in translating from RPython to JavaScript by going via Emscripten [3], i.e.

  RPython -> LLVM -> Emscripten -> JavaScript
And, then, there have been efforts like my own which have focused on building a WebKit bridge [4] to PyPy.

[1] http://www.mail-archive.com/pypy-dev@codespeak.net/msg03946....

[2] http://pyppet.blogspot.com/2011/04/rpython-to-javascript.htm...

[3] https://github.com/kripken/emscripten

[4] https://github.com/tav/naaga/tree/master/webkit_bridge

tav··on JSDev: Executable comments (by Douglas Crockford)
schmerg and I added support for this in UglifyJS about a year ago. Use the define parameter to define values for constants, e.g.

    uglify --define DEBUG=true
It will then replace all uses of the DEBUG symbol to true. And when you set it to false, it will even strip away dead code like:

    if (DEBUG) ...
We even added support for define-from-module which allows you to specify and use the exported symbols from a nodejs module instead of defining them on the command line. I tend to have dev.js and prod.js setup for this purpose.

Hope these features address your requirements. Apologies if we didn't make the feature visible enough. It's documented on the UglifyJS frontpage...

tav··on Google now supports link rel="canonical" in HTTP headers
The Link: header has been a part of the HTTP spec since forever. The following example from the HTTP/1.1 spec [1] should look familiar:

    Link: <http://www.cern.ch/TheBook/chapter2>; rel="Previous"
We should be applauding Google for supporting standard headers instead of making up new ones. The Link: header is even mentioned in the HTTP 1.0 spec [2] and, as mentioned in the OP, there's even an RFC acting as a registry for the various Link relation types [3].

Though I don't always agree with standards, I hope you'd agree that it really does make sense in this case...

[1] http://tools.ietf.org/html/rfc2068#section-19.6.2.4

[2] http://tools.ietf.org/html/rfc1945#appendix-D.2.6

[3] http://tools.ietf.org/html/rfc5988#section-5

← PreviousPage 2 of 6Next →