Yes, correct on the second part also.
56 karma · joined February 20, 2007
Yes, correct on the second part also.
A larger, more complex framework does present serious problems when you have to architecture everything in strange ways to meet scaling needs or otherwise.
Note how much the twitter guys were so scared by ROR's complexity that they resisted doing the most trivial modifications? I want to understand my framework "all the way down." This is much the same reason I use linux.
\But\ from the beginning, everyone using webpy has seem to know flup sessions to be the recommended way of doing sessions:
http://webpy.org/track/wiki/SessionsWithFlup
Let's look at this another way though. If you really need security, then which is better: a simple, quickly verifiable codebase like webpy, or a massive, magical code base like django and turbogears? Do any frameworks make any guarentees of security?
I have seen several high profile sites within the last two years with major, obvious security problems. As hard as this is to believe, I no longer think that security is what will determine the success of most any web app -- at all. Unless you have special needs, feelings of security should not be your primary metric in evaluating a framework.
90% of people in general are not net savvy.
I highly recommend webpy.
edit: downvote?
If you are wondering about the volume of planning we do, there's no question that I've thought about marketing for a huge amount of time.
I don't care for the founders much at all. They obviously got very lucky in choosing their product. Their technology is as boring as they come (PHP et al.)
More that I don't like about facebook, the product:
They "sell" privacy. So much of their marketing revolves around the idea that what you do on facebook will only be known among those you want it to. And yet here, facebook fails miserably. It lets in exactly the worst people: law enforcement, employers, school officials.
Oh and the content of their photo galleries is trash because the design encourages people to upload every single picture on their harddrive. Early, early myspace even had them beat in this area.
I don't know, I just never liked it or them much at all.
What must it be, 1 in 100,000?
Second, my argument has always been that the browser should not harass the user of a site that has not taken part in this PHONY identification procedure.
Heck, even google adsense has seen through this scam and not bothered to pay the fee.
Edit: To clarify, most users equivocate signed SSL certificate == trustable site. That is WRONG. Verisign does not vigorously establish the non-evilness of your site.
Example: http://blog.washingtonpost.com/securityfix/2006/02/the_new_face_of_phishing_1.html
I believe that you misunderstand the technology.
Because the authorities trust anyone who pays them 20 bucks. THEN, the users trust any site where the address bar turns yellow. Do you see the break in the chain here?
These certificates have nothing at all to do with "authority." Just think about it, what exactly do they prove?
Why should you only be allowed to speak in confidence with well identified parties (not that verisign remotely attempts to identify anyone)? Think carefully.
Related: http://www.schneier.com/blog/archives/2005/12/new_phishing_tr.html
So you guys were flat out wrong in the other thread when you said this guy got all of his traffic from SEO.
But, shouldn't we be asking the poster "why"? If the "why" is because he wants to be good at programming, then I would suggest that he first does some light c, a tiny bit of assembly, and a get a basic understanding of FP languages and the insanity of advanced OO in java.
In the end though, be sure you are using Python. Heck, even if you get bored along the way, throw some python in.
A [Warning] though: python will spoil you. Good luck going back to a more verbose, rigid language, should you be forced to.