HN user

meanguy

256 karma
Posts0
Comments60
View on HN
No posts found.

Thank you for having "developer at artsy.net" in your bio as I would have found this continued questioning odd otherwise.

The gallery cancelled the order claiming both pieces are out of stock. A direct email to the gallery said the pieces were in stock. Typically gallery scam nonsense.

And literally while I was typing this, Amazon called me, totally unprompted.

So there's your verdict. Art galleries still suck, Amazon is still awesome, and it's still virtually impossible to make a significant purchase on the internet in 2013.

Nothing that's Amazon's fault. Amazon purchase history shows order complete, paid via Amazon credit card. Gallery currently refuses to ship either piece.

Verdict: yes, Amazon has successfully brought the magical experience of dealing with art dealers online. Not sure earning their cut is going to be much fun for them, but like Prime I'll happily use it as long as they offer the implausible service.

I've never had a bad experience with Amazon or any of their third parties across hundreds (!) of transactions. Long time collector, I purchased two pieces of art yesterday via the beta. Known gallery, brick-and-mortar. It's already a total debacle.

Late 90s press quoted Bezos as saying he wanted Amazon to sell everything except livestock and gasoline. Compared to art galleries, there's less bullshit and more ethics among the beef and oil companies.

But I pushed the button yesterday specifically knowing Amazon had my back. That says a lot.

That was actually one of the key points of SOPA -- it extended DMCA-style service provider protection to payment providers and ad networks. As for the "streaming" provision, that was (inartfully) meant to penalize the day 0 crowd, especially for unreleased media. It was not intended to penalize people downloading, watching, or what people who read this site consider "streaming."

The language could and should have been cleaned up then; it all got lost amidst the SOPA screaming. Penalties for "streaming" are covered by the DMCA inside the US. It's how YouTube and UStream can exist. And I think we've seen precisely how many felonies and how much jail time resulted from cover songs and Justin Bieber lip dubs since that law passed 15 years ago.

But right now someone outside the USA can take another party's shady (or well-intentioned stream) of a pay per view, wrap ads from an ad network around it, and accept PayPal in order to see the "unrestricted stream" (scam). And there's no legal framework to deal with it.

That's obvious scammy theft regardless of where you stand on copyright. And all the "good guys" (ad networks, payment providers) remain liable whether they respond to takedown requests or not. SOPA let people take down the ads and PayPal links if they couldn't get the site down. It gave PayPal and Google the same kind of process and liability protection for payments and ads that YouTube already enjoys for video.

This needs to get fixed and techdirt, boingboing and others need to hire someone with minimal legal expertise (optimally Congressional litigation support experience) if they're going to keep hammering this for pageviews and anti-copyright cred.

For starters, it's ntoskrnl.exe. Dig out the original Windows NT stuff from the early 90s and you can infer Dave Cutler and team's original vision. The fact that Microsoft made hundreds of billions of dollars off it, layering all sorts of legacy chaos atop it, obscures the jewel at the core.

There's a third issue here, Tim: a perceived downward trend in the quality of the offerings of O'Reilly Media. My first O'Reilly book taught me sed/awk. Now you print magazines with "How to knit a robot" on the front cover.

I'm all for throwing stuff at the wall and seeing what sticks, but you seem spread awfully thin.

O'Reilly hired a pal to speak at RailsConf based on a popular Web 2.0 site he built. Unfortunately he didn't build it. Also the site was written in C#.

Click the Xamarin Dev Center link. You'll see Android and iOS but no Linux. They're focusing on mobile client tools.

They never got the full stack running on the server and they punted most of the Windows-specific client stuff from the start.

They landed on a super smart subset and seem to be kicking ass with it. A C# compiler with some odd omissions and cool enhancements + native bindings to iOS and Android equals a damn useful tool. If you're building .NET or even Java backends it's certainly a very sane way to hook into them from Android phones and tablets in the enterprise.

But it's not a cross-platform .NET environment by any stretch and certainly isn't on the path to becoming one.

After losing the support of Novell they refocused (see xamarin.com). They really did an amazing job with what they had, though.

That said, Mono benchmarked about 4x slower on my web apps.

For me, better to use two Windows instances rather than deal with the ongoing Mono compatibility drama across 8 Linux machines.

And here's where I flash pocket aces: I sat in a room with no windows and no computers, across from men with strong chins and short haircuts, reviewing Windows NT source code line by line. On friggin' paper.

Never heard of this guy. Never heard this story. It makes no sense, and I cannot even imagine what "automatically open the processor up to accept commands on start-up" means.

Mr. Curry eventually met with senior NSA/DoD officials, aired what he had -- while a major government lawsuit against Microsoft played out -- and nothing.

Also, Windows NT 4.0 very much did get C2 certification and had E3 (equivalent but not transferable) at the time. Which again doesn't help the story in hindsight.

I mean, seriously... read this nonsense (gcn.com). This stuff doesn't even qualify him for a Wikipedia entry. It's just the story of someone who cracked under the pressure of releasing a version of NT every year for four years straight. He certainly wasn't the only one.

-----

Curry also gave Schaeffer an updated document pulled from Microsoft’s Web site. Under a section of frequently asked questions on security, the site answered the question: “Is Windows NT a secure enough platform for enterprise applications?” by stating that the company recently enhanced the security of NT Server 4.0 through a service pack.

“Windows NT Server was designed from the ground up with a sound, integrated and extensible security model,” the Microsoft Web site said as late as last week. “It has been certified at the C2 level by the U.S. government and the E3 level by the U.K. government.”

Hodson said the passage claiming C2 certification cited by Curry refers to NT 3.5 with Service Pack 3, which is the only version of NT to meet the NSA’s C2 level requirements to date. But because the passage earlier mentions NT 4.0, Hodson said, the meaning could be misconstrued.

I hadn't heard this story before, but time isn't kind to this particular conspiracy. The moment of clarity: Mr. Curry wanted to sue Microsoft but "couldn't find a lawyer willing to take on the case" -- in 1998. EVERYBODY was suing Microsoft in 1998, including multiple governments. If you couldn't find someone to sue them that year, I'm afraid you don't have much credibility.

And this made my head hurt:

"All computer security systems begin with the Intel processor itself," Curry said. "I helped Intel develop their processor, so I know how they work and how vulnerable they can be if left exposed." ... "In fact," he added, "Microsoft NT 4.0 is the least secure of all the NT versions... Processors on Windows NT Version 4.0 are insecure because they have been designed to automatically open the processor up to accept commands on start-up."

Um, you know how Rails binds, right?

Also: MVC2 runs under NET 3.5 which doesn't even have the dynamic keyword. (I don't use dynamic in MVC3 or MVC4 either...)

The "stringly typed" (magic string) stuff was always avoidable. Regardless, see the [CallerMemberName] annotation and others which solves it back to INotifyPropertyChanged.

Now that the backlog of Microsoft tools have shipped, the scaffolding makes a bit more sense. The MVC team released multiple versions (open sourced!) instead of waiting for VS11. Which actually lines up with your core argument.

That's how similar products work. Some contain batteries to remember state. Some are full duplex and request state / update status. Some even work.

Another fun scenario: somebody crashes into a utility pole near your house, the power flickers, all your lights come on, the ceiling fans spin up 100%, and the ashes from your fireplace are distributed all over your house.

Or the lightning strike. Computer works, internet works, can't turn on any lights.

Visit a home automation forum for these and other tales of nerd homes gone bad.

The poor color rendering is what the comment above you is talking about. If a bulb makes your wood walls look funny and the picture of your girlfriend on the desk look like an alien, it's not going to go mainstream. Especially if it costs $50.

Mike Herf (of Picasa/F.lux fame) wrote some articles when CFLs were going to solve everything, you know, three years ago. Applies to LEDs as well. His wife is a painter. Let their struggle be your guide:

http://stereopsis.com/fullspectrum/

The home automation market has been an utter disaster for decades. I hoped the "green" movement would nudge it mainstream. Not yet, and Google even killed off their home electricity monitoring projects.

Here's a similar product:

http://www.smarthome.com/2672-222/INSTEON-LED-Bulb/p.aspx

No color change capability and requires some other stuff as part of the system, but once you start turning on lightbulbs you quickly realize you need relays and sensors to control other things, too. So then you want a "system." And the systems currently suck.

Requested it as part of the application. Perhaps I could have avoided the disclosure, but since a merchant account is effectively offering you credit (think about it) leveraging my personal rating yet incurring no liability was a pragmatic win.

The issue is that fraud prevention--like terrorism prevention--means the side that's doing the groping isn't going to tell you exactly what they're doing and why. This leads to a lot of confusion.

I can echo the same treatment with two different merchant account providers across three companies. Didn't matter if it was a $10k month or a $1MM month or if the company was new or old--it was a constant battle. In one case it was only my personal credit rating (which happened to be spotless) that saved my business.

Yes, think about that. A merchant account -- where they hold your company's money -- relies on your personal credit score.

Anecdata: I had two chargebacks in five years of web software sales. Both claims were buyers ripping me off. I provided signed FedEx receipts for boxed software shipments and IP addresses/dates/times when the customer registered the software and downloaded updates. I ate the full cost (plus investigation and chargeback fees) both times. (This is "cost of doing business" and not an opportunity for a blog post, IMHO.)

From the post: "And thank god I made that [five figure] withdrawal when I did, because yesterday came the second phone call, informing me that a reserve would indeed be placed on my account."

I believe this action is what actually triggered the issue. If he paid the costs of running his business out of his PayPal account and took consistent monthly paychecks, it would have been far less of a flag.

Sucks that you have to do it, and we software types are famously short-tempered when it comes to dealing with real-world bureaucratic nonsense, but sometimes a bit of careful planning and playing the game wins the race.

I did some work here.

There's a lot of problems with legibility research. It's very, very hard to test for "legibility" or "readability" -- as, not surprisingly, the typeface is only a small part of what's going on when the human brain turns symbols into thoughts then plays them back later.

To the extent that we could get valid data, people did best when they were familiar with the typeface in question. And back in the age of newspapers, the closer to the local newspaper layout and typography, the better they scored with news-like information.

melloclello's comment hints at this part: serifs are high-frequency data. So there's more "information" in a serif face than a sans-serif face. In fact, simple filtering of a serif face makes something that looks very much like a sans-serif face. But whether this extra information is helpful or distracting to readability or legibility depends on what the reader is used to. (But even that didn't matter much in our tests!)

Exactly. Sass/Less have functions to adjust brightness and saturation for just this reason. I routinely tweak saturation so link and hover colors "read" the same on a white background versus even a light grey header.

Historically Microsoft has flown by the seat of its pants with a lot of this stuff. You wouldn't believe how horrible the Windows 95 or Windows XP interfaces were right up to the last possible minute.

As might be expected with anything "flashy" or "cool" in a company not exactly defined by those adjectives, there was a shortage of skill and an overage of opinions. Only after true "ship it" crush set in did the less qualified people seem to scurry away and worry about little details like, oh, an entire laptop product line that didn't boot.

For example: kernel dev Mark Lucovsky got some perverse thrill by checking in the startup bitmap. In his mind, this granted him some sort of final authority over the branding of a product that sells a half billion copies. We'd let him yell at the testers and people providing feedback that it looked like shit -- then we'd giggle while Dave Cutler punched holes in the walls in the build lab. Then with egg on their faces and casts on their hands, they'd go do something they were good at while the designers and a few hand-picked nerds possessing the barest hint of aesthetic capability tried to save face at the last minute.

The variable now is Sinofksy who unfortunately seems to think he really knows design. This is the guy who thought that removing items from menus "based on the user's work habits!" was a great simplifying metaphor in Office 2000. You'd look at a menu for months gradually building familiarity with the product. Then that one day when you finally needed to insert a friggin' table, the damn option wouldn't be there any more.

I'm sure he has all sorts of data proving how great everything is. I can't tell you how much data we had "proving" that the original Xbox controllers were way better than the Nintendo or Sony controllers, too.

Your post confused me because it said a lot of things about App Engine's datastore that conflicted with my direct experience. Khan Academy is one of the few sites that I'm excited about at the moment, so I'm concerned.

I chose AppEngine because I was very much aware of the issues around big data and I thought I could avoid having to deal with it. I came away from your post with the feeling that you may be underestimating what you're up against. Step one: look at your data size and querying cost every day!

Right now you can access the datastore externally via the remote_api shim or an API you put on your app. Performance isn't great. (An OData-style HTTP interface to the datastore seems like an obvious addition.)

Specific to my query: you say you're excited about Google's EC2 equivalent. I'd be more excited about the managed Hadoop that's likely the next step along your dev path whether you're aware of it yet or not. Custom mapreduce operations against the Google App Engine datastore, ironically, really suck and are really expensive.

So... was this general excitement or is there something specific you want to do with App Engine but you can't yet? And have you estimated out the transactional costs for walking across your full record set even if they gave you access to it?

You're likely going to find yourself stuffing at least some things in a SQL store and talking to that.

It broke down for me on AppEngine. I had to move data out of the store to blobs, then use AppEngine queues to reduce the data into the store for reporting access.

Basically they promised me what they promised you and, after I got past a few TB of real data, the whole thing blew up.

Also what "front end user apps" are you unable to write on AppEngine itself that require something like EC2? Splatting data out the HTTP hole was the least of my worries.

It seems like AppEngine is saving your ass at the moment but aren't you worried about scale? This is sort of a classic "storage not data" problem where you mapreduce raw data to a structured store for reporting. Are you really still querying everything live? When do you expect this to break down?

I particularly disagree with the conclusion that Twitter would have become some sort of magical panacea as opposed to the screenshot he provides: https://twitter.com/#!/daltonc/media/slideshow?url=pic.twitt...

The problem there is yet another crappy "what's hot" or "what's trending" or "what's popular" block. Google can't solve it for news, Netflix can't solve it for movies, Amazon can't solve it for related products, and a half-borked, underfunded API for accessing the Twitter firehose is unlikely to create an ecosystem for startups that magically condense the entire world's real-time chit-chat into something I find compelling.

Yet isn't that block fundamentally the (false) promise of Twitter? We'll let you, Mr. Brandybrand [perhaps an individual], target your products and ideas and political manifestos that change the world and the blog posts and cat pictures and defamatory attacks and racist sentiments that don't -- somehow to people who'll find it interesting?

The World's Fairs promised us flying cars; Hollywood promised us a flying skateboard. Both still live on in our dreams, so I have a tough time thinking "marketing" killed 'em.

Especially given Twitter's very public technology missteps. Hash exclamation point, ya digg? Half a billion later and the site still loads correctly about as often as Gawker does. He's bitching that an API can't party on their data? Hell, I can't even retrieve my own direct messages from a year ago on the site itself.

Meanwhile: somebody just replied in email with "HAHAHAHA!" Gmail inserted a widget offering to translate it from Filipino and shows an ad for Coconuts beside it. Coconuts! Meanwhile my last Twitter notification is in the Spam folder.

Nope, this isn't "the marketing guys."

- SSL via SNI for $9/month (no Windows XP support, heck--limited Android support)

- ...or a virtual (not static) IP address for $99/month (!!)

- CDN via "PageSpeed" at .39/GB outgoing (plus .12/GB)

- new!!! datacenter in Europe!!!

I was an early adopter of App Engine who went through Ye Grande AppEngine Datastore Debacles. Months where it didn't work followed by a sudden tripling of the cost that turned App Engine into something that was no longer feasible for my app.

But this update has me really shaking my head.