Jan 23, 2010

CUSEC: Day 2 and 3

Day 2 of CUSEC started off much like the first, except there was a presentation in the morning instead of just hanging out. There were more interesting talks to be had, check them out:
  • First was Rob Tyrie from NexJ, which is a company that builds CRM software for the financial industry. It was a pretty good talk, he spoke about his startup experiences, mergers and acquisitions, etc. I like to hear stories about successful startups, so the talk was pretty good.
  • Greg Wilson, one of the editors of Beautiful Code and the other books in this series. He gave a presentation about empiricism in software development, or the lack thereof. Many programmers (myself included) make claims which tend to be based on popular opinion or anecdotal evidence rather than good data, which is not really a good way to make statements. I really liked this presentation because it showed me that even though I've done a fair bit of statistics in the economics program at Concordia, I haven't really applied that knowledge to determining whether or not my beliefs about software development are correct. In fact, I liked this thought so much that I think I'll write a few posts about how to apply some statistical techniques to analyzing software.
  • Dominic Duval from Red Hat gave a presentation on how to get started in Linux kernel hacking. Some of it was review for me, but other stuff was pretty interesting. Perhaps I will try to get my webcam working sometime.
  • At the end was Douglas Crockford, the guy who came up with JSON. His presentation was called "Quality", and the main point was that there is a lot of snake oil in the software industry, and no silver bullets. We come up with better ways of doing things but they still don't change the fact that we still have bugs, missed release dates, projects that go over budget, etc. The difference is that newer methodologies let us build software of greater complexity.
These were some good presentations. Unfortunately today I only saw the last presentation since I got to the conference late. The one I saw was given by Jacqui Maher from the NY Times who gave a talk about doing programming jobs for NGOs in the third world. It sounded like a really great experience and would definitely be a great way for us nerds to improve the world a bit. You can check out the stuff she did on github, and also CrisisCamp which is an organization that focuses on using technology to help people in crisis.

It was another good year for CUSEC, I certainly enjoyed the talks and hope that next year is just as good!

Jan 21, 2010

CUSEC: Day 1

Today was the first day of CUSEC 2010, and despite being tired and hopped up on caffeine all day (this entry might sound really odd, and is susceptible to slight changes when I am more coherent) it was an excellent start - in fact the day hasn't finished yet, there are still drinks to be had this evening!

The speakers today were:
  • Matt Knox - You'd probably know him better as that guy who wrote adware that was posted on Slashdot a while back, and he'll probably be known as that for the rest of his programming career ;) The talk was quite interesting. He began talking about his adware career and how he basically was slowly talked into doing shadier and shadier things for the company. The most interesting part in this section was the various security exploits in Windows he spoke about (and they scared the shit out of me, it really rationalizes my decision to not use Windows anymore). One of them is CreateRemoteThreadEx, which to paraphrase Matt you say, "hey, process over there, please execute this arbitrary code!" So basically you don't even need your process running anymore to have your code still executing. The second one (that I can remember) was that while Windows stores strings internally as 16-bit unicode strings, the Win32 API uses null-terminated ASCII strings. So if you have a null byte in say, a filename or a registry entry, the programs written using the Win32 API can see the file/registry entry but can't actually do anything about it. I don't know if this is true or not, I'd have to do some research, but that is how I remember it.
    The talk then went to explain the Milgram experiment, which I will leave to the reader to explore further. He explained that basically these tests show that about 70% of people will do evil if they are made to by an authority figure, and described this as basically a remote security exploit in 70% of the installed base. But, he wondered, if people have security exploits that cause them to do evil, is it possible that people have security exploits to make them do good? It was an interesting question, but what makes you (or perhaps only me) wonder more is that if the people knew that they had an "exploit" that caused them to do good, would the exploit still work? So yes, it was an interesting moral speech, and Matt is an entertaining speaker so when they post the videos (if ever) I recommend checking it out.
  • Pete Forde (music warning) from Unspace was one of the corporate speakers. Unfortunately for these speakers, there are two going on at the same time so I can only see one of them speak, but oh well. Pete spoke about his life, risk-taking, doing new things, etc. I really enjoyed the talk, even though I wasn't paying attention for half of it because when he started talking about side projects I'd start thinking about my side projects and forget that I was in a conference. I enjoyed the talk and hope to get a copy of the notes since there was a lot of suggestions for books and blog articles that I'd like to read but couldn't remember.
  • Sergei Savchenko from EA (I don't know of a link to put for his stuff) - he gave a talk about video game programming, focusing on network topologies and various memory management techniques. It was pretty neat since I'm interested in that kind of thing, however I felt like it was a bit more of a lecture than a conference presentation.
  • Reg Braithwaite (slides)- it seemed they saved the best for last. While I did like all the presentations, this one was packed full of insight in Reg's style of taking your brain out and prodding at it to figure out what makes it work and how to make it better. I feel like that once they publish the recording of this one I could download it, cut it up into 10 minute slices, watch each slice individually and after watching each slice get a class of wine, sit down in my thinking chair (yes, I do have a thinking chair) and dig down into what he is saying and determine if he's "a guy who smoked too much weed in the 70's" or a guy with some really good advice to give. He started off with a Ruby example and how to use his extension methods to fix the problem. However he said that the important thing about the example was not the extension methods themselves, but the fact that they were necessary in the first place. Basically if we're having to put dirty patches onto things in order to make them work, it is a pretty good indication that those things are broken. Another point was that if you listen to the single responsibility principle, then by using extension methods or monkey-patching then you're breaking that principle; however by breaking that principle and successfully creating good software with it, you're showing that perhaps it is not you that is the problem, but that the single responsibility principle itself is broken. Or to be more general, how much of what is considered "good practice" isn't really good practice, but rather holding us back from creating something better? It makes you think, what else are we taking for granted? Not only in software, but in the rest of our lives? The issue is even once we decide that there are things that we can do better, how do we find those things?
    There was a lot more, however I will wait until the video comes out before I talk about it in any more detail (all that coffee is having an effect on my memory).
This gives me great hopes for what tomorrow will bring!

Jan 19, 2010

Best Thing About Rails...

Q: What's the best thing about being a Rails programmer?
A: Hitting on homophobic Django programmers and watching them freak out.

Jan 16, 2010

The Joel Paradox

The Joel Paradox: n. A situation where a software company is determined to only hire the best developers, but fails to offer work which the best developers would find interesting.

Jan 12, 2010

Programmer's Cookbook

I've started up another site here called "The Programmer's Cookbook", where I take recipes for basic foods and turn them into code for my own amusement. Feel free to check it out if you want, and if you feel like submitting any recipe code, feel free ;)

I'm using the syntax gem for HTML highlighting, which is a great little tool for displaying Ruby in non-Ruby contexts (like your web browser).

Jan 11, 2010

What I'm Checking Out At The Moment

I'm revisiting a few things. I heard about these things a while back, but after re-watching Avi Bryant's CUSEC 2009 talk I decided to give them another whirl:

Rubinius: An alternative VM for Ruby, I'm sure most of the readers have already heard of it. Last I checked it wasn't a 1.0 release, now it is. So I'll be checking that out again.

Seaside and consequently, Smalltalk. Seaside is a web development framework written in Smalltalk which is supposedly "heretical", which is a bold enough claim to inspire interest (again). I haven't really done much with this yet, however right off the bat I am amazed by two things:
1) The installation process - there isn't really one. Grab the one-click installer here to see for yourself. There's a lot of extra junk with this installer, including the entire Pharo Smalltalk implementation and IDE (with Smalltalk there is no separation between the language and the IDE, which I find pretty cool) and the framework itself - not bad, considering it clocks in at about ~36MB. Anyway just run the executable and you're set - the zip includes the executables for Linux, Mac and Windows.
2) The speed - it takes about the same amount of time for the VM, the web server, and the entire dev environment to start up as it takes for GVim to start up. Some things inside are a bit slow like dragging windows around, but other than that it is blazingly fast. Seriously. You have to see it to believe it.

There's also some things I'm not really revisiting, but checking out for the first time. I've recently started grad studies (one of my profs was wondering last semester what the hell I was doing in another undergrad, and told me to apply for the Master's program. I got in, which is pretty cool), so I'm looking for something to write my thesis on. I know it's a bit early - I've technically only been in the program for a week - but I figure it couldn't hurt to get going on it. I'm looking at doing stuff in computational economics, and more specifically agent-based methods. Instead of the traditional approach to economics where you set up firms and individuals as rational agents that maximize some mathematical objective function, you put them into some sort of search space and they explore it in an attempt to find a better situation than the one they're currently in - although they don't necessarily have to do this, you could introduce some level of irrationality like fear of change, in which case the potential gain in utility from switching to another outcome would have to overcome some amount, but now I'm rambling and could probably continue like this all day.
Anyway if you're interested in this kind of stuff there's seems to be a bit of stuff going on at Iowa State University of all places and they have it fairly well organized. And of course there's the Santa Fe Institute which does this sort of stuff, although if you're interested in something specific you'll probably have to dig a bit.

Jan 7, 2010

Nearly Free Speech

I thought I'd give out a little thanks to a company called NearlyFreeSpeech.NET, which is a server hosting company with a rather unique model for their business. Most hosting companies will give you some space for a fixed amount per month, some even go as cheap as $5/month (CAD) - I'd provide a link here but I've forgotten who it was.

I like these guys because you only pay for the bandwidth you use. You put a certain amount of money onto your account, and then as your site(s) use bandwidth, they bill a few cents per day. You have to pay extra for dynamic sites and for a MySQL instance, but it's something like an extra 3 cents per day, which is like a dollar a month.
You can then easily set up extra sites and tie them to your same billing account. If you end up making a lot of small sites, this type of thing is really handy!

One catch though: they don't support anything that requires a persistent process other than the web server and database. So no Rails, unfortunately. Also they don't support mod_python, mod_ruby, or a few other things. Which kinda sucks, but oh well.

So if you're needing a small hosting company, maybe give these guys a try and see if you like them!