HNHacker News
TopNewBestAskShowJobs

tomfakes

668 karma · joined August 12, 2009

I am a consultant providing expertise to make your Rails app scale. Faster apps make happier customers

Previously, co-founder and Chief Engineer of Offbeat Creations, sold to Playdom in early 2010.

Earlier: 10 years at Microsoft, then various Seattle area startups until I started Offbeat Creations in 2008

http://blog.craz8.com Twitter: http://twitter.com/craz8 email: tom at craz8 dot com

submissionscomments
tomfakes··on Deface (Rails) customizes views without editing the template
This tool would be great for building an A/B testing framework around for various UI color/text/layout testing. You can isolate the testing from the regular code, and provide a set of overrides for a particular test that depend on whatever you segment your users by.
tomfakes··on How 7 Lines of Ruby Will Speed Up Your Heroku Deploys
I think the Heroku Rails 4 buildpack does this automatically. And Rails 4 and Ruby 2.0 build assets faster anyway.
tomfakes··on The case against using RubyGems.org in production
I agree with Starr about having your own Gem repository available for the code you want to deploy to your servers.

However, I don't think this solves the initial problem, and that is that you have to develop a trust with the people writing the Gems.

For the Rails gem, I'm just going to trust those guys, because of their track record, but for a random gem writer with their first Gem, I'm going to read the code of that gem to ensure that it does what it says it does.

Having your own gem server doesn't remove this step, but it does put a roadblock in to stop a gem writer putting in bad code once you've decided to use it.

So this is a 2 step process:

    1. Read the Gem code (or trust some other way)
    2. Create a Gem Server to isolate from un-wanted updates
tomfakes··on Zerigo DNS down again: another DDoS
I have a shiny new DNSimple account I need to add some records to. This might be the time to do just that
tomfakes··on Google Adsense 10 Year Celebration - Play Pong
On my Adsense Dashboard, there's a new logo in the bottom left that, when hovered over, starts a game of pong over the page. All to celebrate 10 years of Adsense
tomfakes··on [dead]
This site seems to be unusable without giving them some of my details
tomfakes··on If Your Business Uses Rails 2.3 You Need To Move To A Supported Option ASAP
I would absolutely use Rails for new projects, specifically because these issues are being surfaced and fixed.

A framework or system with only 10 users will never have the depth of security and bug fixing coverage that a larger, well used system has.

tomfakes··on If Your Business Uses Rails 2.3 You Need To Move To A Supported Option ASAP
Active Admin is getting there in a branch, but I do like to have rubygems.org gems for production apps.

I've just started using the Turkee gem, and this needs the mass-assignment gem with Rails 4 to work correctly. Since I'm new to this one, I need to spend more time with it before I can send in some pull requests to provide patches

tomfakes··on High Performance Rails
The first form generates a method at startup time that can be pre-configured to do all the work necessary.

The second form has to perform a pattern match with the controller and action names to work out which method to call, and then call the method generated by the first form.

This extra pattern match is the overhead, and with thousands of routes, it clearly adds up.

Always use named routes - the first form.

tomfakes··on High Performance Rails
This is a nice overview of how to get the best performance out of modern Rails app.
tomfakes··on Ask HN: Industry standards for locking down a SAAS product to prevent abuse?
Find a good PHP bcrypt library and you'll be ahead of 90% of web sites with your password security. bcrypt is the current Rails best practice password hashing solution.

Stripe is good, as you'll never see credit card numbers, so you'll have no security issues to deal with in that area

tomfakes··on Ask HN: Industry standards for locking down a SAAS product to prevent abuse?
If you are using Ruby on Rails, you can buy a base application with a whole bunch of best practices built in, including many payment systems. This will save you much more time than the cost of the kit.

Check out http://railskits.com/saas/ for the SaaS Rails Kit

* Disclosure - I'm friends with Ben, the owner of RailsKits, and have done work for him in the past.

tomfakes··on Exploitation of an old Rails vulnerability
The problem with an upload is that you rely on someone to re-upload when they change their Gems. Changing the locked Gems means a re-check is needed, as they might have switched to bad versions.

Making this automatic is the key part - if you don't get burned very often, you'll eventually forget to do the right thing manually and open yourselves to badness.

tomfakes··on Exploitation of an old Rails vulnerability
Doh! I just got the landing page setup, and the signup configured, but never pushed it out.

Try it now.

Thanks

tomfakes··on Exploitation of an old Rails vulnerability
On exactly this subject, I'm in the process of building a SaaS app that will alert you of security vulnerabilities in Gems in your Rails and other Ruby apps.

Sign up at my landing page to here more when I'm closer to launch

http://www.rubyaudit.com

tomfakes··on Ask HN: Gave loan to startup which is now profitable. What should be repayment?
I think you may be overvaluing what you have here.

For a loan, under a year, my first thought is a percentage - maybe 5-10%.

If you purchased equity, then you'd be looking at getting a multiple of your money back - but not necessarily on your schedule.

Next time, get the terms up front.

If someone offered me a loan with the terms of 5X on payback, I'd walk away immediately. You need to find out that both sides are not on the same page before the money changes hands. Now that you are in a relationship, this could get quite messy if the expectations aren't similar

tomfakes··on Ask HN: How to invest?
If anyone tells you that they can get you a stable 6-8% per year over the next 12 to 15 years, you should run away immediately.

Interest rates all go down as stability goes up. Typically, buying government bonds gives the best stability, but current 10 year US bond rates are paying under 2%.

The more risk you are willing to take, the more you may earn, but then the more you could lose.

Only you know how much risk you are willing to take, but younger people tend to be able to take more risks, because, over time, the ups and downs of the market flatten out. And if you have 40+ years to leave the money, then the better chance you have of being in the market for good times as well as bad (Oh yeah, timing the markets - to only get the good times - never works over time either).

One absolute certainty though is to make sure you pay as little to the people managing the money as possible. If you buy a mutual fund, the difference between 0.2% annual fee and 1.2% annual fee is astronomical over time.

I have a bunch of money tied up in the Vanguard Total Stock Market Index Fund which tracks the total stock market and charges 0.17% per year. This type of fund, again, over time, beats out almost all actively managed funds. Managed funds will try and bamboozle you with how they beat the market last year, but if you didn't invest the year before, that doesn't matter.

One technique I also use with extra cash is to buy shares of companies I personally have good experience with - e.g. Apple, Starbucks, Amazon. This is much riskier, but can payoff quite well.

I am not a financial advisor!

(Oh yeh, in the US, you could setup a Self Employed Pension plan to save your money tax free, but this has restrictions on when you get access to the money, but it's something to think about to turbo charge your savings)

Good Luck

tomfakes··on Older and Wiser... Up to a Point
Interestingly, I find that a lot of the questions on Stack Overflow are from such noobs that I'd have to spend time explaining how to program before getting to their actual question. This disuades me from participating, as it's hard to find the questions from programmers who I could help.

As a professional, if I can't find a way to contribute my expertise in a timely and efficient way, then I'll get on with something interesting and more lucrative. Which is a shame, because there is a lot of useful stuff on SO, and I'd like to contribute at a high level, but I'm not willing to put in 2 hours a day to find the 1 or 2 questions that would be worth the time.

I'm an older programmer, and this may be one explanation of why older programmers answers on SO aren't as useful - the good ones are not the ones answering questions!

This is just an anecdote, but one that certainly applies to me

tomfakes··on The cost of hand-to-mouth living
Also plan on doing this more than once, and analyze your performance to ensure you get better.

One thing that programmers forget is that, at some point, you weren't good at programming, but over time, you learned and now you are pretty good.

Your business/social skills may be at that same starting level, and this isn't something you read about on the internets and are immediately good at.

Start now, plan on doing this over time, and learn to get better at it. It takes effort, but it will be worth it.

tomfakes··on Alberta man may be first to sell house for Bitcoin
He could spend some of that new-found coinage on wine from the first North American winery to accept Bitcoin for wine!

https://twitter.com/rollingdale

Since they're in BC, they can ship to Alberta too!

tomfakes··on Man steals $33 million from Australian casino in 'Ocean's Eleven'-esque heist
And this is why shoe computers are banned in casinos!

Google Glass will make this hack so simple, the casino's will have to ban them from being anywhere close to a roulette table to reduce team cheating possibilities.

tomfakes··on Baby steps toward replacing Google Reader
The irony for me is that I had no idea Marco had ads on his site, because I get to read his blog content in Google Reader!
tomfakes··on If you are running Rails on Heroku, use this gem to properly serve assets.
I've been meaning to write something like this for the last few months.

Rails apps on Heroku need a number of non-default configurations to work well, and this is one of them.

Thanks for this - I'll add it to a project this weekend and probably do an updated version of my blog post on this subject: http://blog.craz8.com/articles/2012/12/7/heroku-config-for-p...

tomfakes··on Weeks after adding Trader Joe’s, Instacart now supports Whole Foods
I first purchased groceries online in the UK in 1987 - using Prestel and a 1200/75 modem.

I'd guess that the French Minitel service had this available even earlier.

tomfakes··on Why GitHub’s pricing model stinks (for us)
I used to be a big fan of Unfuddle, and I still have an account there, but the reality is that all of the integrations I use (CI is the most recent one) work great with Github and not at all, or are much harder to configure, with Unfuddle.

Github is creating value with their ecosystem, which is great for them, and, since the code is all in Git, not a complete lock-in if you choose to move.

tomfakes··on Ask HN: What's your blog?
Ruby on Rails performance and scalability: http://blog.craz8.com
tomfakes··on Updating Rails
It seems strange that your app is so broken with a minor version update. Are you sure you are changing just the last number in the string, and not trying to jump a full version of Rails?
tomfakes··on Updating Rails
You do not need a patch file

All you need to do is:

    update your Gemfile to the correct version of Rails
    run **bundle update rails** in the root of your directory
    then **git commit -am "update rails"** to save the files
    then **git push heroku** to update on Heroic
The Heroku email has the information for all the Rails versions - if you are running 3.1.4, then you need to update to 3.1.10, if 3.2.X then 3.2.11 is your new version - this should be a safe update. Just pick the latest number for the X.Y version that you currently have in your Gemfile.
tomfakes··on Web Caching For Beginners
A tool like YSlow in the browser, or http://WebPagetest.org will show you what is cached and what isn't

WebPagetest.org shows you the first time call which is generally awesome, but in this context will also show you the second visit experience which takes into account the content cache settings.

tomfakes··on How I Made my Blog 2.3x Faster
I recently wrote a blog post about how Rack::Cache and ETag work http://blog.craz8.com/articles/2012/12/19/rack-cache-and-eta..., which is particularly important to know for Heroku based apps.

The key part is that, for public content (and blog posts tend to be public), the Rack Cache can be used to serve these pages directly from the cache store (usually Memcache) with minor database traffic needed, even for people who have never seen this content.

That last part was the surprise for me - surely ETags are only used by return visitors! Rack Cache makes ETags work for new visitors too.

I think I can get my blog to run almost as fast as a static site, and I'm working towards getting that done and documenting it as I go.

(In addition, Heroku seems to be adding Varnish headers to my responses. They say they don't use Varnish in Cedar apps, but this is clearly not correct)

← PreviousPage 2 of 7Next →