HNHacker News
TopNewBestAskShowJobs

tav

1,544 karma · joined December 10, 2008

Call me Tav.

I'm a hacker from London who works on decentralised systems.

Feel free to contact me for help/advice or just for a friendly chat:

tav@espians.com

http://tav.espians.com

https://twitter.com/tav

All content produced by me on HN is dedicated to the Public Domain:

* http://creativecommons.org/publicdomain/zero/1.0/

Use it however you want :)

[ my public key: https://keybase.io/tav; my proof: https://keybase.io/tav/sigs/mWU8_7ohyVhbWe4CC4-BULZt9ko__aSLRFa1T-GJ5xc ]

submissionscomments
tav··on Skype vulnerability discovered by Pure Hacking
Skype claim to have already fixed the bug with their release last month on April 14th: http://blogs.skype.com/security/2011/05/security_vulnerabili...

Sadly the fix seems to be only for the 5.x series and there's no indication for holdouts like myself on whether 2.x is affected or not.

tav··on Immediate-Mode Graphical User Interfaces (Video)
Discussion about it: http://mollyrocket.com/forums/viewforum.php?f=10
tav··on Fabric Python with Cleaner API and Parallel Deployment
Thank you for the compliment — I was going to write an article a few weeks ago, but ended up spending the evening redesigning the blog instead: http://tav.espians.com/new-site-design-for-2011.html

Procrastination has its benefits I guess, heh. If you fancy them, the css/templates are in https://github.com/tav/blog and the site is run using yatiblog — https://github.com/tav/ampify/blob/master/src/pyutil/yatiblo... — the source is all public domain, so do with it as you please.

tav··on Fabric Python with Cleaner API and Parallel Deployment
Let me get this right. Due to convergent needs, dozens of Fabric users post various ideas to the issue tracker and mailing lists. And over the years, some people hack together personal branches solving some of these issues and, despite the incredible amount of time that's passed, they fail to get their work into the mainline branch.

Eventually, one hacker comes along — who, having been a Fabric user for a long time, has independently experienced similar needs and finding no decent solution, decides to take on the task of implementing the various features himself — making sure that it's clean, backwards compatible and fully documented. And your response is to accuse him of trying to take credit for other people's work?!

I can understand your frustrations with the pace of Fabric development, but accusing another hacker of taking credit for other people's work simply beggars belief. Even more incredible is that so many people decided to upvote you! For the record, I'm not taking credit for anyone else's work. I came up with the various ideas myself and you can look at the code to see that it's not based on anyone else's work. Thank you.

tav··on Fabric Python with Cleaner API and Parallel Deployment
Whilst forking is always a possibility, I'd rather contribute back to the project and help improve Fabric collectively. The community is made up of really nice guys and it'd be great if we could figure out a way of getting the various ideas to work together.

Thanks for checking out the docs and your encouraging words!

tav··on Common Mistakes as Python Web Developer
I've also explained this in another comment, but basically, the call to `normpath` in his code takes care of this, e.g.

    >>> normpath('ExistingDir/../../parentRestrictedDir/passwords')
    '../parentRestrictedDir/passwords'
tav··on Common Mistakes as Python Web Developer
You've overlooked the critical call in the previous line:

    def is_secure_path(path):
        path = posixpath.normpath(path)
        return not path.startswith(('/', '../'))
The call to `normpath` normalises the path, e.g.

    >>> normpath('./../foo')
    '../foo'
tav··on HN Petiton: Get Google to support SSL on all of its APIs
I'm writing an https frontend in Go which proxies to App Engine. It increases the bandwidth bill slightly, but means that you can take full advantage of the App Engine APIs. You can see the work in progress here:

https://github.com/tav/ampify/blob/master/src/amp/tentproxy/...

In the next weeks, I'll also be adding optional support for WebSockets which could be linked to a local process for support for custom "comet/long polling" use which App Engine doesn't properly support yet. Email me — tav@espians.com — if you'd like to know more or need any help with the code.

tav··on HN Petiton: Get Google to support SSL on all of its APIs
Adam, nice work on getting Charts on HTTPS!

I understand that Google is a large company. But, with Google Maps in particular it seems to be a business decision rather than a technical one. What can we do to help swing a decision in favour of making HTTPS be part of the public Maps API?

2+ years of comments on http://code.google.com/p/gmaps-api-issues/issues/detail?id=5... hasn't seemed to have had any effect...

tav··on HN Petiton: Get Google to support SSL on all of its APIs
Good catch, thanks! Unfortunately, it's now too late for me to edit, but perhaps someone with appropriate powers can make the correction?
tav··on HN Petiton: Get Google to support SSL on all of its APIs
Not true according to Google:

If there's one point that we want to communicate to the world, it's that SSL/TLS is not computationally expensive any more. Ten years ago it might have been true, but it's just not the case any more. You too can afford to enable HTTPS for your users.

source: http://www.imperialviolet.org/2010/06/25/overclocking-ssl.ht...

tav··on HN Petiton: Get Google to support SSL on all of its APIs
On a related note, it would be great to have a listing of all the service providers who do have comprehensive support for open APIs over SSL. Here are a few to get the list started:

* Bing Maps

* Facebook

* GitHub

tav··on Wave accepted into the ASF incubator
I'm surprised at this sentiment. Could you elaborate by any chance?

The reason for my surprise is because a significant portion of the Wave code base is geared around the user interface — which was, in many ways, the least attractive aspect of Wave (at least from the experiences of those I've spoken to). The other main parts of Wave were the various Operational Transform work — which, again, to my understanding from those who have looked at the OT framework released by Google last year, is inherently hard to scale up.

I had always assumed that these and the general market disinterest to be the reasons that Google had abandoned the Wave project — so am very keen to understand why you would be so excited... thanks!

tav··on Google Beatbox
You can see the top 100 here: http://top.searchyc.com/submissions_by_points

Google's New approach to China article is #1 atm — http://news.ycombinator.com/item?id=1048800

tav··on Yahoo/S4 distributed stream computing platform
Original post with discussion: http://news.ycombinator.com/item?id=1870029
tav··on Why we switched from Google App Engine to EC2
It's not a new trend. App Engine has had issues for a long time. Here's an article I wrote early last year about some of its problems and proposed solutions that the GAE team could use to fix them:

* http://www.espians.com/why-app-engine-is-not-appropriate-for...

But, despite the various problems, I still use App Engine for various applications. There are few platforms that can even compare to its power and simplicity. And good luck finding a NoSQL datastore which offers the power and scalability of App Engine's one.

In fact, if there was a decent open source alternative to the datastore, I'd switch away almost immediately.

tav··on Ask PG: How much did the lunch with you sell for?
A lot of users make very valuable comments which are often overlooked for various reasons. I was hoping this would give them some deserved attention. Also, having spent a bit of time looking at various users' comment streams, I've found myself having a better understanding of them — makes for a stronger HN community. And, finally, being able to make decent predictions is a valuable skill for any entrepreneur...

Hope that helps explain why I believe this is beneficial and not just fun.

tav··on Ask PG: How much did the lunch with you sell for?
And while we wait for pg to tell us the amount, I propose a game of HN Predictions. The rules:

* You must make your prediction before the event is determined.

* You can't edit your prediction afterwards.

* As a participant, you commit to going through the winner's past comments on HN and giving them at least 3 karma points. The winner would therefore need to have made at least 3 comments...

Let whoever is the closest to the actual amount, win! At the very least this should make for an entertaining Sunday morning =)

Here's my prediction: $2,400

tav··on Ask HN: Open source web app html/css templates?
Nice! I really like how the different interface elements are packed onto the same page. Makes it extremely easy to make an assessment. It would be super awesome to have a CSS Zen Garden-like effort for Web App themes based around that HTML.
tav··on 4chan Users Try to DDoS Tumblr, Tumblrs Raid 4chan in Revenge
Anyone know the origins of "What is Air?". It seems to be yet another meme that's passed me by, but Googling doesn't yield much in the way of an explanation — just lots of people on Tumblr saying it and finding it seemingly funny... http://www.tumblr.com/tagged/WHAT+IS+AIR%3F
tav··on Datacenter Power Efficiency
The linked slides are a lot more informative than the summary on that page: http://mvdirona.com/jrh/TalksAndPapers/KushagraVaidMicrosoft...

It's interesting that in contrast to the likes of Google and HP who have been stating that the cost of power will soon be greater than the cost of servers — e.g. http://bits.blogs.nytimes.com/2008/11/03/kill-an-energy-hog-... Microsoft seem to be having a very different experience with servers making up 61% of the TCO and power consumption and distribution/cooling only taking up 16% and 14% respectively.

It's also interesting that they haven't (seemingly) adopted the Google strategy of shifting workloads from data centers based on the external weather conditions, e.g. http://www.datacenterknowledge.com/archives/2009/07/15/googl... — This sounded like an ingenious idea when I first heard about it and am surprised that everyone didn't copy it straight away.

tav··on Scoble talks with Paul Graham
Oooh, Scoble is on HN. Welcome Scoble!

Is it just me or have the major bloggers taken an interest in HN recently? I noticed that Dave Winer started engaging about two months ago and now Scoble. Did something major happen to prompt this or is it just a general response to the increasing levels of traffic that we send to the various blogs?

tav··on Reddit’s Astonishing Altruism
Am I the only person who found Reddit generally quite unpleasant?

It really is heart-warming to hear of all the good that those on Reddit have done. But I can't help feel that it's the exact same mob mentality which made me want to leave Reddit in the first place — discussions got extremely polarised very quickly and there seemed to be very little room for reasoned dialogue.

The article makes it sound like a good thing that "comments are generally downvoted by dozens or even hundreds of people with remarkable speed, pushing their noxious posts down into obscurity within minutes". But, since everyone can downvote — hell, I have even see non-controversial statements get downvoted heavily — the quality of dialogue often ends up being at the level of the lowest common denominator.

tav··on NoSQL is a bullshit marketing term
I think you might be confusing Matasano with Monsanto — unless Thomas hasn't told us something... ;p
tav··on NoSQL is a bullshit marketing term
Quite frankly, the anti-NoSQL-as-a-term is getting a bit tiring. As someone who has been working on "NoSQL" systems since 2000, I have been extremely thankful that there is finally a broad-based movement exploring alternative datastore architectures. It used to be extremely depressing to have discussions with fellow engineers on the benefits of alternative architectures and for them to simply reject it on the grounds that "SQL DBMS must be the best since they've had decades of work behind them". At the very best, someone might have been radical enough to contemplate the use of an Object Database.

In contrast, thanks to the NoSQL movement and the exploration of alternative models that it has encouraged, the quality of discussions is extremely different today. More and more engineers are aware of the benefits and issues with various models and are much more open to alternatives. So when I say that I am extremely thankful to whoever coined the damn term and for efforts like NoSQL Summer, I really mean it. It has really improved my quality of life.

Now I get that "NoSQL" isn't a 100% accurate term. But what marketing term ever is? Take something like AJAX — most "AJAX" apps have never dealt with XML, yet the term has been extremely useful. It helped solidify a broad-based effort to explore using JavaScript and thanks to the "AJAX movement" of a few years ago, we now have XHR in all modern browsers and awesome libraries like jQuery!

The real issue as I see it is that projects are keen to differentiate and are thus reacting to being lumped together with extremely different systems. Now no-one who understands the technologies is ever going to compare the likes of Redis, CouchDB, Neo4j, Cassandra and Hadoop as equivalents, but it is understandable that projects are afraid of being considered equivalent by those who are simply choosing a NoSQL system for their project without understanding the differences.

This follows onto another issue — a leader (or two) often emerge once a new domain has been established and the "smaller" projects are cautious of being sidelined by "big boys" like Cassandra/MongoDB/Hadoop. To continue with the AJAX example, in the early days there used to be a whole bunch of options regarding JavaScript libraries: Prototype, jsolait, MochiKit, MooTools, jQuery, Dojo, etc. In contrast, nowadays, jQuery is the default choice for the vast majority of developers. I don't think that there is such a clear winner in the NoSQL field yet. In fact, given the massive fragmentation, we probably haven't even heard of the final winner yet!

That is not to say that the concerns of the various projects aren't totally valid. But the issue is not with the "NoSQL" term but rather with differentiation and understanding — both of which can only be solved by better communication. Phrases like "Online Request Processing Systems (ORPS)" or even "Alternative Datastores" aren't exactly catchy marketing terms. NoSQL may not be perfect, but it's here and it's more than good enough. So can we please stop bashing it and focus on coming up with clearer differentiators? Thanks!

tav··on A VC: Storm Clouds
I can only really see this coming to an end after a Facebook IPO hits the market. Until then, it does feel like a period of "irrational exuberance" all over again.
tav··on Top 5 trends and technologies in software development
Hey Ochronus, I think that's what I said ;p
tav··on Laser Tracking Projection with Kinect and OpenCV
Nice! Here's the description:

What I did was rig it to track contours on the depth image, and attempt to pick out a rectangular object. Then, by using the detected location of the corners, I can apply it as a perspective transform to my laser projector. The end result is that the cardboard box I'm holding becomes a "virtual screen" that is tracked by the laser projection in real time and in perspective :)

Reminds me of Johnny Lee's awesome Projector-Based Location Discovery and Tracking work: http://johnnylee.net/projects/thesis/

Also, there seem to be a fair number of Kinect projects popping up nowadays. Is there a website to keep track of all this? If not, perhaps it would be worth someone's effort to start a blog on the topic...

tav··on Top 5 trends and technologies in software development
The follow-up article from his friend that he links to is perhaps more useful advice:

http://www.muhuk.com/2010/02/top-5-untrends-according-to-me/

tav··on Programming Lessons I've Learned in 20 Years
Damn, not sure how I missed that. Upvoted in gratitude.
← PreviousPage 3 of 6Next →