HN user

ObnoxiousJul

6 karma
Posts3
Comments42
View on HN

I studied physics, and I learnt actual programming and assembly language: I actually did this in the real world!

What do you learn in Computer Science then?!

Gibbering useless concepts that makes you non-sensical experts in the field of not delivering your software neither in time, nor in the frame of the specification? Or just

There are so many security issues being unveiled that at this point one might wonder if Rails 4 (and a complete redesign) may not be the way to fix the security issues.

Maybe also, if ruby programmers learned to program (instead of doing banana driven lingo development) or committed suicide throwing themselves from a cliff (along with PHP developers) (like lemmings) we could also have a boring yet more secured internet.

I am voiceless: why would the f*ck would someone loose such that much time on a trivial, yet annoying task?

That is the first lesson you have in assembly language: program in assembly language, then in C because it spares you the time (and the mistakes involved in the process) to do such a thing.

Thousands of men year efforts and wisdom ruined in a post, showing how people have too much time on their hands, and so few imaginations (well he could have written something interesting on how to display p0rn pictures in ASCII art at least).

Well it is a known QA practice: never base incentive on metrics or people will cheat one way or another with the metrics. If your dev have a prime based on SLA or tickets solved guess what? You are giving them an incentive to cheat. You will have nice figures to show your investors, ypur stock options' values will raise and coder will be better paid. Everyone is happy, who cares about the truth, the unfairness, the lie. This is just mis placed moral. Stats that can be tricked are the prozac of our society. It make the metrics describing a situation improve with mutual benefits for (almost) all the stakeholders.

Who cares about the customers or minorities anyway? I mean not on the paper but honestly?

Unless you have a sensitivity to the initial conditions, hence you have a chaotic system. Which happens as fast as n body interactions in a gravitational field (but how many bodies/iterations do you need, which initial conditions makes the error a problem?)

But as I stated earlier, I think I have to check first because I am not that convinced any more on the performance point of view that JS has a problem, and float representation is not a JS problem, but a problem global to all CPUs.

Well it can be more than 10^-12 sometimes and the problem is not in physics but in trading when errors stack up. That's why I prefer when e-commerce solutions are based on fixed point arithmetic.

Even though canvases are still not homogeneous in terms of performance from browsers to browsers, some works fairly well.

Well, I would discourage playing with math if accuracy was important. Just open firebug and multiply

  >>> 10*1.1198 
  11.197999999999999
This limitation is intrinsic to IEEE 754, and no alternative are in the pipe (IEEE854 seems stalled).

I have been working for the web ads industry and canvases were pretty disappointing in terms of performance when the number of sprites were growing up. The funnier part was the inconsistency in result amongst the browsers.

So simulate as much as you want, just don't expect to beat flash or native client in terms of performance...

Are any jailbreaked iphones with privacy patches installed being leaked? Xhi2 analysis is not only about what triggers the correlation, what does not trigger the correlation is also important. My guess is jailbreaked are underrepresented in leaked UDID either because jailbreak is shielding users or because users able to install a jailbreak are more aware of computer security issues. Regular Iphone are cell phones remotely controled by a 3rd party, jailbreaked iphones are computers you control. I am no paranoid freak, I am just a regular sysadmin with a pretty low security awareness.

Well, I like to exaggerate a little bit. Especially since sociopathy/asperger are rather ill defined. So discard all my remarks as pure troll (don't feed the troll :).

The real point is there are no truly acceptable positive feedbacks if one does not equally express negative feedbacks.

So ... one should not whine for getting flamed even if it is socially unacceptable to discard all this work because that's the path for improving...and later maybe getting praised.

because if you are really a coder you prefer negative feedbacks than a false confidence. Even though it is yet socially unacceptable, social rules are stupids.

You cannot earn any glory in publishing your code if people don't tell the truth. To be pleased by one «I love what you do», you should ready yourself to get a couple of «you are doing crap». Coders are not expected to publish good code at first, they are expected to improve their work through sincere feedbacks. That is our culture.

Social norms are unproductive when it comes to work in cooperation.

The fact that Asperger (sociopaths) are 10 times more prevalent in coding expertise might not help.

Excellency in coding is an aristocracy that needs no excuses and don't fear critics. You shall not fear the fight if you believe in your creation, because good design can stand the assault of the best criticisms.

Social norms are only their to protect a hierarchy of status. Truth protect the hierarchy of competence.

If you are just a hipster searching for a social status based on consensus then flee for this is war against you. THIS IS SPARTA!!!!!

[dead] 14 years ago

Thanks. I do despise stupid brainless people: they are a threat to all the things I believe in: democracy, science, fun, sex, good taste & style.

[dead] 14 years ago

Well, upvoting means I think it is interesting. You usually dont upvote hoaxes I hope (especially the unfunny one).

This is clearly an hoax in the first form (JS exploit).

At most (if real) it is just an exploit of a specific browser (version) on a specific OS. If you go on «hacker» news, I am very surprised you have no IT culture. I suggest you should read http://www.newsoftheworld.co.uk/ if you want untrustworthy sensational news, and consider not upvoting when you are clueless on a topic.

Less noise, more signal is a very old hacker motto. You obviously don't get it.

[dead] 14 years ago

@drewcrawford, you can't even read x86 ASM? O_o

The exploit described in stackoverflow, works only for IE and a version of windows where the memory addresses are not randomized (which most modern OS do have (http://en.wikipedia.org/wiki/Address_space_layout_randomizat...) , and where calc.exe is installed (so windows + IE probably).

Hint MOV + JMP are made @ fixed address.

If the code showed is not an hoax (which I highly doubt) it would imply : 1) a specific browser (to break the gate of OS control on memory/permission by using a buffer overflow) and I don't see at first glance a buffer overflow (but let's imagine it exists), 2) a specific old OS (windows 98 or XP maybe) (for having a predictable address to which to inject the shell code)(I can't imagine an ASM code doing base of registry scanning in less than 4k to get an address of a peculiar exec/lib); 3) since it is based on specific 64bits alignment problem and since there are 32bits legacy application) it would target only the 64bits version

This makes the threat looks more like ripples in a glass of water than the tsunami that was announced.

Basically this (if it is not the hoax I think it is) would be just an exploit of a specific browser in 64bits version on a specific OS. It is not a JS exploit, it is a very specific browser name on OS name exploit in 64bits. So to say ... the whole day life in the world of software.

[dead] 14 years ago

well, figure that if it were true, Java, python, Perl, c# are useless tools for delivering cross x86 OS code. (I just develop a side effect of the claim one can inject some code in memory bypassing all the HW/OS control).

Why God these stupid Larry Wall, GvR, MS, Sun, Google, linus torvalds lost their time trying to achieve what a JS code can do in less than 1000 lines?

How can I believe a code I can read and that is obviously a fraud would through the sheer power of obfuscated unused strings become such a revolution in the world of CS?

Plus, I have no demonstration nor readable documents to back up the claims of this so called genius.

Science is accepting what you can understand and reproduce. Not being impressed by obfuscated crap.

I have no doubt this is a mystification, and I don't trust blindly what is written on the internet. I still have a brain.

[dead] 14 years ago

Hum .... Porting C to js... Are you serious?

Where are your pointers, ASM registers in js? The claim you could inject arbitrary code from JS into your memory and make it executable from user space (not talking of the cross platform issue (BSD,linux, windows, MACOSX) would just be the end of JS.

How can you even accept the claim that it can be doable. Be real. This news is like an april's fool in july.

Use your brain.

[dead] 14 years ago

mouhahah okay read the code. It mainly writes: you have been hacked on a web page. End of the story.

[dead] 14 years ago

The code is obscure, therefore the idiots think it is profound. Or rephrased by JG: the bigger the troll, the easier it shall pass.

The more I read HN, the more bewildered I get at the gullibility that seems to prevail amongst self called geeks and smart entrepreneurs.

Give me a rope please.

most painful bugs are in the conception, thus at paper level.

And also most breakthrough are also in simple efficient conception.

Delivering is what most people calls craft.

I do pride myself in delivering, however, any monkey coder can deliver.

The core of programming is creativity.

No developers develop the same way, and even though there are some obvious ways, there seldom exists an absolute all cases best way.

It is the thesis of the mythical month (F. Brooks) and I do like this theory since its corollary the "no silver bullets syndrome" is quite accurate.

The essence of programming is creativity, thus no tools can improve software productivity in its essence.

The problem with school, is studious dull boys with no imagination thinks they worth something in programming by incanting mantras of pseudo tech gibbish. They have a 90K$ loan, no gift, and they pollute the eco system because else, they become hobos. At least, most of them are hired as java, C++ or PHP developpers where they fit best.

PHP: The Right Way 14 years ago

Right way to write PHP indeed. Sometimes I wish PHP itself was written this way.

Oh! The guide does not mention the case: if a class contains only one static method, please, use a function. It does not look as educated, but it's obviously a function.

Not PHP specific, I admit.

As described, static or lighttpd for static and reverse proxy for the domain achieves more than one goal:

* you can serve page faster; * you can mix on a same domain more than one app from different servers in the DMZ (for sharing domain based mechanism (flash, Cross site ajax) by rewriting the url; * you can have one front (nginx) and several servers, which with heartbeat mechanism can handle failover. * you could (when ssl certificate were only IP based) share one SSL certificate for more than one back (VIP)

It is a pretty low cost quite scalable architecture. I guess you could do it with apache, but I dropped apache since its licence is as understandable as its configurations.

Yes, it is about ideas not words. You can learn the word, it does not forcibly tell you about the ideas. Especially the new one.

If a software has been done, buy it! It will be almost always less expensive than building it. If it has not been done yet, no book or knowledge can tell you how to do it.

And if an idea you can code is new, you'll hardly have the word for it. It is easier to brag about «well (re)known ideas» than doing new stuff.

Colours you can't see are ideas we have not yet the word to describe them to those who can't see them.