HN user

tsally

4,792 karma
Posts87
Comments839
View on HN
www.fsf.org 16y ago

Bilski Oral Argument at the US Supreme Court (Software Patent Case)

tsally
13pts12
pub.needlebase.com 16y ago

Needle by ITA: Creating Databases from Data Anywhere On The Web

tsally
4pts0
www.engadget.com 16y ago

OS X 10.6.2 Is Out, No Atom Support

tsally
1pts0
www.hulu.com 16y ago

Hulu Has A Desktop Client For Linux

tsally
20pts13
github.com 16y ago

Github Rackspace Move Is Happening This Sunday

tsally
7pts1
www.realgeek.com 16y ago

Judge Tries To Order Facebook To Turn Over All Of Its Source Code

tsally
4pts0
www.schneier.com 17y ago

Social Security Numbers Are Not Random

tsally
6pts1
www.washingtonpost.com 17y ago

Lab Analysts Now Have To Testify In Court About Their Tests

tsally
1pts0
nsa.unaligned.org 17y ago

NSA@Home: Fast SHA1 Generator Using FPGA (RE: Engine Yard Hashing Contest)

tsally
38pts8
74.125.47.132 17y ago

Milw0rm Shut Down By Owner

tsally
31pts12
cr.yp.to 17y ago

Bernstein's New Mission Is To Cryptographically Protect Every Internet Packet

tsally
59pts21
www.l0pht.com 17y ago

L0pht Website Relaunched

tsally
20pts17
news.ycombinator.com 17y ago

Suggestion: Nominate For Color

tsally
1pts1
news.ycombinator.com 17y ago

Things I Think PG Monitors, But Probably Doesn't

tsally
4pts2
news.ycombinator.com 17y ago

Ask HN: Quick Graphic Mockup?

tsally
1pts0
www.perlmonks.org 17y ago

A Beginning Guide To Evolutionary Algorithms in Perl (2003)

tsally
2pts0
duriansoftware.com 17y ago

The Factor game framework

tsally
5pts0
www.britishcouncil.org 17y ago

Virtual Cocoon- VR By Stimulating All Five Senses

tsally
1pts0
news.ycombinator.com 17y ago

Ask HN: Examples of Excellent Python Code?

tsally
15pts3
www.guardian.co.uk 17y ago

Anti-missile defence details found on secondhand computer

tsally
5pts0
blog.aurel32.net 17y ago

Debian is switching to EGLIBC

tsally
47pts13
news.cnet.com 17y ago

Oracle buys integration challenge along with Sun

tsally
1pts0
www.eff.org 17y ago

In Warrantless Wiretapping Case, Obama DOJ's New Arguments Are Worse Than Bush's

tsally
1pts0
www.linuxdevices.com 17y ago

Linux game console ready to ship

tsally
1pts1
blogs.discovermagazine.com 17y ago

Countdown to Nuclear Fusion: National Ignition Facility Warms Up

tsally
1pts0
blogmaverick.com 17y ago

Are Tweets Copyrighted ?

tsally
13pts9
translate.google.com 17y ago

A Blatent Stack Overflow Ripoff

tsally
2pts0
sallye.posterous.com 17y ago

A Brief Explanation of the GPL and LPGL and Their Implications For Business

tsally
1pts0
www.flickr.com 17y ago

Splitting A Bullet with a Razor

tsally
1pts0
www.engadget.com 17y ago

DVD region code blocks British Prime Minister from enjoying Obama's gift

tsally
40pts15

It's been a while but last time I checked it was just a certain karma threshold. The idea was to prevent newly registered accounts from spamming downvotes.

But again, haven't actively participated in HN for a while. Things could be different now.

Your numbers are off in essentially every area. Car payment is $200-$250 a month, insurance is $100 a month, gas is $50 a month, and call it an amortized $100 a month for repairs and other expenses. In total, an average car costs $500 a month. And never mind the cost for parking. In contrast, passes for public transportation cost somewhere from $50-$100, _but_ you can usually get them subsidized and/or pre-tax. In Boston, I'm able to get an unlimited pass through my employer for $35 pre-tax a month and my car costs me $500 post-tax a month. In major cities, cars are strictly a luxury. Note, I bought one a few months ago and couldn't be happier, but I'm under no illusions: it is a luxury.

not a lot of folks would want people videotaping everything they did at work

Did you know if you get a Top Secret clearance, you have to have anything related to your work release reviewed for the rest of your life? Being awarded privileges by the government comes with additional responsibility. Videotaping the police is the same as monitoring people who work with classified information; it's just part of the job. If someone is uncomfortable with that s/he should find a different job.

I should have qualified. The only reason that might be reasonable to maintain a high GPA is an honors program or some other program with an arbitrary GPA requirement (i.e. 5 years BS/MS http://www.cs.vt.edu/undergraduate/degrees/5yr-BS-MS).

I will say that I started my college career in the honors program and on the 5 year BS/MS track. I just couldn't wait long enough to start doing real work. ;)

A note for when you go to college: On the surface college may seem like it rewards risk even less than high school. Don't be fooled. You just have to intelligently optimize your GPA (I wrote about optimization a bit here: http://news.ycombinator.com/item?id=1132222). If you take this approach, the challenge is no longer getting offered a job, but getting the interview in the first place. I've been offered a job for every interview I've had, but damn did I have to work hard to get my foot in the door. Once you DO get your foot in the door, you're pretty much guaranteed the job because your risk taking puts you many technical miles ahead of the competition. I hope (but have no empirical evidence yet) that the same effect will be true when applying to graduate school. Just use your ingenuity to get around the screening process. :)

EDIT: One last thing I thought of. You may be one of those people that will be able to get a 4.0 GPA and have time to work on creative processes. Your 4.0 GPA is still a waste of time. There is always more you can do that is ultimately more impressive than a high GPA (i.e. publishing in competitive conferences, starting a highly technical and useful open source project, working on the Linux/BSD kernel, etc).

For that it's worth, the DoD doesn't actually define "cyber warfare". In fact, in 2006 it depreciated the concept of "information warfare" (http://www.dtic.mil/doctrine/new_pubs/jp3_13.pdf). The closest concept the DoD has is "cyber operations" which are meant to "operate and defend the Global Information Grid" (http://www.dtic.mil/doctrine/new_pubs/jp1_02.pdf). Personally I don't think Scheiner focused enough on the fact that "cyber war" is essentially a media construction.

Similar discussion here: http://news.ycombinator.com/item?id=634986. My schedule is still similar, but I would be less social if I was trying to bootstrap. ;)

6:30AM Wake up, shower, eat breakfast, make coffee

7:30AM Catch the bus to work

5:00PM Finish work

5:07PM Catch bus home

6:00PM Get home, make more coffee, change clothes, eat dinner

6:15PM-10:00 Program or socialize. So far this has been a 50/50 split.

10:30PM Sleep

On weeekends I try to get up early and hit a coffee shop from 9:00-3:00. I get somewhere between 15-20 hours of programming in per week (outside of my job).

You're going to be tempted to skip exercises because you think you understand the exercise or it is not applicable to you. Don't fall into this trap, as we humans are notoriously bad at judging what will and will not be useful for our own learning. Do all the exercises.

The two month time frame seems very optimistic unless SICP is one of your only responsibilities. It's my understanding that most semester courses that use/used the book usually never even get/got through the last chapter.

You might consider reading How to Design Programs (HtDP) as an alternative or supplement to SICP. The authors of HtDP have published a paper comparing the two works (mostly detailing the perceived shortcomings in SICP that motivated them to write HtDP in the first place). Read it here: http://www.ccs.neu.edu/scheme/pubs/jfp2004-fffk.pdf.

Good luck. :)

Regardless of whether the exchange happened or not, the claim that "[the email headers] were legitimate, and that the entire thread would be extremely hard to fake, if not impossible" is an exaggeration. For reference, open up the headers of an email you've recently received from a Gmail address. Notice the DomainKey-Signature field?

  DomainKey-Signature: a=rsa-sha1; c=nofws;
          d=gmail.com; s=gamma;
          h=mime-version:in-reply-to:references:date:message-id:subject:from:to
           :content-type;
          b=IBLt9oYlFSwflVBrLP4Rq64gpUeIHJMkvAjbVoYin9vugJBa4E4hxqfKeFLp/Gw3XT
         2V/PR4M4M/Kz9CU8n7poGJ+JUBcxyT4LZc4SYNHTV1TD6nmk77Pvl7E7f8uY1sAMrR9c
         F+2HiY9MMKgb0SlPdRVqUUF0QX9XoQRzA3jFs=
That's there because Gmail (along with a few other providers such as Fastmail) implement what's called DomainKeys Identified Mail (http://en.wikipedia.org/wiki/DomainKeys_Identified_Mail). It can provide cryptographic assurance that the domain name associated with an email is valid. So using the DNS records on the Gmail domain, I can pull the public key and verify the cyptographic signature.
  mil:~ tim$ host -t txt gamma._domainkey.gmail.com
  gamma._domainkey.gmail.com descriptive text "k=rsa\; t=y\;   

  p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIhyR3oItOy22ZOaBrIVe9m/iME3RqOJeasANSpg2YTHTYV+Xtp4xwf5gTjCmHQEMOs0qYu0FYiNQPQo
  gJ2t0Mfx9zNu06rfRBDjiIU9tpx2T+NGlWZ8qhbiLo5By8apJavLyqTLavyP  
  Srvsx0B3YzC63T4Age2CDqZYA+OwSMWQIDAQAB"
If the signature is valid, I can be reasonably confident that the email is valid. (Note that some sort of DNS compromise or attack would allow an attacker to pass me a fake public key)

Now take a look back at the email headers in the article. There is no cryptographic signature that you can verify. Note that if these headers are made up, the forgery is quite good. There's even some nice SPF authentication going on in there. But it's not impossible to forge these headers. In a targeted attack, I could do just that. Depending on how much the guy got paid for the story, it might even be worth the time.

(If there's someone with domain knowledge/experience etc. in this area and has an addition or correction, I'd love to hear it)

As you say, legal torrents exist (indeed, many open source projects rely on torrents because they can't afford the bandwidth costs of direct download). Therefore, a torrent tracker has both legitimate and illegitimate uses. Similarly, I can find legal and illegal content via a Google search.

There isn't any ambiguity here. Torrents and web search are both multi-use technologies. In the case of multi-use technologies, we should prosecute the criminals based on their use of the technology in question.

Stealing a credit card is stealing in itself, you don't actually have to charge anything. The analogy isn't valid. The correct analogy is the fact that you can use Google to find numbers that look like credit card numbers. Similarly, hosting a copyrighted file is illegal. But providing the means in which to find said file is not.

There's a reason why the world should work this way. I can use a wide array of objects as a lock pick (i.e. a banana). To prosecute me for walking down the street with any of these objects (including actual lock picks) is just ludicrous. Hence why the law says that I actually have to demonstrate the intention to use a tool to steal something in order for it to be a crime. And in any case, the took maker is usually never liable.

It's a very simple idea. Prosecute the criminals, not the people who provide tools which might be used in a crime. Obviously there's an upper limit. For example, a grenade is a pretty unambiguous, single-use tool. That's why selling one is illegal. But most tools have many uses, some illegal and some not. It's an impossible task to go after the tool makers, so just go after the criminals.

Good thing you can't find copyright files to download via Google search. Otherwise it would be as bad as The Pirate Bay!

Enabling someone to break the law doesn't make the enabler culpable. We apply this standard to manufacturers of lock picks, crowbars, physical key-loggers, books detailing the security of computers, etc. I'm curious why you feel a different standard should apply to someone who provides hosting for torrent files. The onus is on the criminal, not those who provide tools which may or may not be used in a crime.

As Mahmud mentioned, you still have to know where things are, who is working on what, what's maintained and what's obsoleted by what. Sure.. Based on your choice of packages, you aren't current with these things and consequently had a bad experience. I'd be really interested in a pointer to a production web application deployed on Weblocks, because I'm pretty sure there isn't one (or very few). The choice of CLSQL as the back-end is dubious as well.

In any case, I'm not a fan of using CL as the end to end solution for a web application. It performs far better as the middleware between the web front-end and dbase back-end. From my understanding, this is what ITA does (details in this thread: http://news.ycombinator.com/item?id=1479107). Who cares that you can't throw up a shiny front end right away if the code that does your business logic is an order of magnitude more shorter/powerful?

Mahmud is one of the few HNers that actually has practicle experience deploying Lisp in the real world. You might be interested in what he has to say on the issue of practicality:

"Today, Lisp is nothing like what it was 8,7,6, even 2 years ago. It's not just "good" in the well-explored text book fashion; no, it's _good shit_. Get work done good. Think, hack, ship, bill for it good. 2-3 products per month good. You still have to know where things are, who is working on what, what's maintained and what's obsoleted by what. Sure. But there is absolutely no lack of libraries." (http://news.ycombinator.com/item?id=972423).

I'm curious if the author of the article has similar experience deploying CL or if this article is just theorycrafting. I notice some experience with Clojure, but this article was written in 2008.

[dead] 16 years ago

I find it unlikely that the flag threshold is a fixed number. I think I remember pg mentioning something about very new and very highly voted posts having a high and variable flag threshold.

It's my personal preference, so it's true whether you doubt it or not. :-p

Using undocumented code is like programming in a language I hate. Mentally it's a really shitty experience and I'm not in a position where I have to settle for that. If I needed to do it to put food on the table, obviously I would.

You're also creating this false dichotomy between getting stuff done and documenting your code. I've never been in a position to have to choose between the two. If you have time to write a good program but not enough time to document it, I would question whether the program you wrote is actually good. If I'm writing a paper, sure I can spew shit out on a page for a couple hours and produce a "paper". But realistically if I'm actually going to produce a paper I need time for outlining and proofreading.

(Note that "documentation" isn't really what matters, it's that the code is understandable. If the code is self-documenting or the program is small enough, I consider that documented code.)

Personally I'd rather someone not write an opensource project than write it and not document it. Understanding someone else's thought process is hard and it gets to be an order of magnitude more difficult without documentation. If it's easier for your average hacker to write his/her own implementation than use your library, you've failed.

You're doing something horribly wrong if you're spending half a million dollars on a degree. Even if you include opportunity cost, it's nowhere near that high on average. I'm not really sure what purpose that type of exaggeration serves.

Of course I agree with platitudes like "hard work and intelligent choices have far more of an effect on your life than a degree", but if you're going to frame the problem in that broad of a sense why should we even discuss it?

Bs. I do quite fine with high school.

Personal anecdotes aren't valid pieces of evidence...

The biggest advantage those growing up in today's environment have going for them is that everyone else their age is lazy. You can do far better today with the same work ethic of the previous generation.

... and neither are broad generalizations. In fact, the college admission process directly contradicts your misguided conceptions [1]. (Whether young people are working hard towards the right goal is another debate, but they are working hard.)

You're going to have to do much better if you want to argue that an extensively researched and reported global trend (degree inflation) doesn't exist [2,3,4,5]. Enough of this hurr-durr-pull-yourself-up-by-your-bootstraps-because-that's-what-I-did bullshit. People who point out the issues with education are hard working people who have valid concerns. They aren't "whining".

[1] http://thechoice.blogs.nytimes.com/2009/03/31/a-few-more-col...

[2] http://www.nytimes.com/2007/09/12/education/12masters.html

[3] http://www.cnn.com/2009/LIVING/worklife/05/27/cb.degree.not....

[4] http://www.timesonline.co.uk/tol/news/world/world_agenda/art...

[5] http://www.insidehighered.com/views/sloane/sloane20