Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe
yeah sure dijkstra said lots of awesome stuff but theyre not quotable snarky one-liners

the one thing hes known for, "goto considered harmful", wasnt his idea. programmers dont want competent well thought out advice they want to pretend that theyre smart by saying somebody elses bad generalization

you remember "considered harmful", "now you have two problems", "reimplements half of lisp", "works on all genders", "one line that doesnt work", "bikeshed is always greener on the other side", etc.

why

Adbot
ADBOT LOVES YOU

Brett824
Mar 30, 2009

I could let these dreamkillers kill my self esteem or use the arrogance as the steam to follow my dream

Suspicious Dish posted:

yeah sure dijkstra said lots of awesome stuff but theyre not quotable snarky one-liners

the one thing hes known for, "goto considered harmful", wasnt his idea. programmers dont want competent well thought out advice they want to pretend that theyre smart by saying somebody elses bad generalization

you remember "considered harmful", "now you have two problems", "reimplements half of lisp", "works on all genders", "one line that doesnt work", "bikeshed is always greener on the other side", etc.

why

you seem real mad about dudes quotin a dead guy

Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe
your reading comprehension is that bad, eh

Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe
i'm mad about dudes not quoting a dead guy

Mug
Apr 26, 2005
qbasic supremacy sorry

double sulk
Jul 2, 2010

crazysim posted:

Open source? Is it on bitbucket then. I'll give it a go.

Personally, I used this to convert mercurial repositories when I needed to:

http://felipec.wordpress.com/2012/11/13/git-remote-hg-bzr-2/

project for work. they're using merc and we use git so i gotta convert it over. i've seen that method that you can just pull it with git and it converts? might just try that and make the modifications again. bunch of hosed up poo poo due to outdated gems makes it hard to get up and running

crazysim
May 23, 2004
I AM SOOOOO GAY

gucci void main posted:

project for work. they're using merc and we use git so i gotta convert it over. i've seen that method that you can just pull it with git and it converts? might just try that and make the modifications again. bunch of hosed up poo poo due to outdated gems makes it hard to get up and running

bingo. just pull and it should convert. i use this because the installation is easy (install mercurial pythonically and drop this file into your PATH). I also like this since you can easily upstream/downstream changes without extra repos of non-git nature lying around.

Nomnom Cookie
Aug 30, 2009



gucci void main posted:

project for work. they're using merc and we use git so i gotta convert it over. i've seen that method that you can just pull it with git and it converts? might just try that and make the modifications again. bunch of hosed up poo poo due to outdated gems makes it hard to get up and running

ur repo has a .git dir in it and github is bitching about it. if its just something dumb then git filter-branch can remove the .git from all ur commits. but im guessing that the hg repo contains a git repo of a dependency or something...in that case do something like filter-branch to remove the dependency and then add it as a submodule

ozymandOS
Jun 9, 2004

PleasingFungus posted:

hopefully my new game will also destroy much productivity




gonna need to tighten up the graphics on level 3 a bit first tho.

manufactoria is one of my favorite games ever. thank you.

PleasingFungus
Oct 10, 2012
idiot asshole bitch who should fuck off

Suspicious Dish posted:

what a good game manufactoria is

just want to give you some empty praise b/c it's an awesome game

wheres the yospos easter egg

tef posted:

empty quote

BP posted:

manufactoria is one of my favorite games ever. thank you.

I never know how to reply to people who like my game(s)

but thank you!

:swoon:

Suspicious Dish
Sep 24, 2011

2020 is the year of linux on the desktop, bro
Fun Shoe
whats the worst thing youve gotten related to manufactoria

i got my first death threat last month :allears:

tef
May 30, 2004

-> some l-system crap ->

pointers posted:

start with your old careposts

i did and i put them on a blog and i got front paged a couple of times from hacker news.



then i realized that i had a blog on the front page of hacker news and i was sad.

Sapozhnik
Jan 2, 2005

Nap Ghost
tef what is one technological thing that you think was really cool and wish you'd been in the right place in the right time to be part of?

Squinty Applebottom
Jan 1, 2013

1998 and in a 100 million dollar funded startup to sell consumers a personal e-assistant or something equally inane

Squinty Applebottom
Jan 1, 2013

pretty much i want to make bonzi buddy in an aeron chair all day

Posting Principle
Dec 10, 2011

by Ralp
i'm pretty sure there were only about 1000 aerons ever made, and they just circulate between failed startups

Squinty Applebottom
Jan 1, 2013

Jerry SanDisky posted:

i'm pretty sure there were only about 1000 aerons ever made, and they just circulate between failed startups

tef we just found another pithy and super original quote for your book

tef
May 30, 2004

-> some l-system crap ->

Mr Dog posted:

tef what is one technological thing that you think was really cool and wish you'd been in the right place in the right time to be part of?

i dunno i have the feeling i'd be just as miserable earlier on, and still have faux nostalgia for the time that I would miss. :3:

tef
May 30, 2004

-> some l-system crap ->

polpotpi posted:

tef we just found another pithy and super original quote for your book

sweet keep it up guys i'll have a book in no time.

Squinty Applebottom
Jan 1, 2013

itll go viral and then you will get a whitewashed tv show

s*!t my ~*teffu*~ says

tef
May 30, 2004

-> some l-system crap ->

Jerry SanDisky posted:

i'm pretty sure there were only about 1000 aerons ever made, and they just circulate between failed startups



this is the founders's aeron, elegant chairs for a more frivolous age

PleasingFungus
Oct 10, 2012
idiot asshole bitch who should fuck off

Suspicious Dish posted:

whats the worst thing youve gotten related to manufactoria

i got my first death threat last month :allears:

mostly I just get a stream of people offering to port the game to iOS/Android/w/e

I say 'sure, just give me some of the cash if you make any' and hand them a zip of the source & assets because who gives a gently caress, it's a 3-year-old flash game

then they vanish never to be seen again, because the sort of people who email you out of the blue to offer to port your game to a mobile platform are exactly the sort of people who will never do it

this surprised me exactly once, when a girl who was going to some kind of music/composition school in England contacted me about composing an original score to Manufactoria

we had an actual correspondence, talked for a week or two about cool ways to make a dynamic soundtrack for the game, and then she vanished & was never seen again

anyway I'm not sure I've ever gotten actual hate about Manufactoria; there are plenty of people who've complained about bugs (usually justly) or missing features (less so), but never real vituperation, that I recall. maybe the soothing classical score calms people too much to bother sending in their hate? idk.

PleasingFungus
Oct 10, 2012
idiot asshole bitch who should fuck off

tef posted:

this is the founders's aeron, elegant chairs for a more frivolous age

qntm
Jun 17, 2009

PleasingFungus posted:

mostly I just get a stream of people offering to port the game to iOS/Android/w/e

I say 'sure, just give me some of the cash if you make any' and hand them a zip of the source & assets because who gives a gently caress, it's a 3-year-old flash game

then they vanish never to be seen again, because the sort of people who email you out of the blue to offer to port your game to a mobile platform are exactly the sort of people who will never do it

this surprised me exactly once, when a girl who was going to some kind of music/composition school in England contacted me about composing an original score to Manufactoria

we had an actual correspondence, talked for a week or two about cool ways to make a dynamic soundtrack for the game, and then she vanished & was never seen again

anyway I'm not sure I've ever gotten actual hate about Manufactoria; there are plenty of people who've complained about bugs (usually justly) or missing features (less so), but never real vituperation, that I recall. maybe the soothing classical score calms people too much to bother sending in their hate? idk.

it's nice to make things that people like

Socracheese
Oct 20, 2008

i don't find aerons to be any more comfortable than a $75 officemax chair idk

If you're gonna drop some cash on a herman miller why would you get one of those nylon garbagebags instead of some ballin poo poo like this:

Sapozhnik
Jan 2, 2005

Nap Ghost
JSONP

:bang:

like i'm sure there's a good reason for it but I mean seriously? "JavaScript interpreter, pre-cache this image from a different domain" "ok np" "JavaScript interpreter, load some JSON data from that same domain so I know what to do with this image" "BEEP BOOP SECURITY BREACH GET hosed DAVE"

Squinty Applebottom
Jan 1, 2013

Mr Dog posted:

JSONP

:bang:

like i'm sure there's a good reason for it but I mean seriously? "JavaScript interpreter, pre-cache this image from a different domain" "ok np" "JavaScript interpreter, load some JSON data from that same domain so I know what to do with this image" "BEEP BOOP SECURITY BREACH GET hosed DAVE"

sure lets allow the client to arbitrarily run and execute any code from anywhere

Gazpacho
Jun 18, 2004

by Fluffdaddy
Slippery Tilde
That's specious, json libraries dont use eval anymore

You could encode arbitrary data in an image and extract it via canvas and then evaluate it, the problem is obviously the choice to call eval and not the cross domain request

Gazpacho
Jun 18, 2004

by Fluffdaddy
Slippery Tilde
I think it makes more sense when you remember that the script src attribute is from the folks who brought you "just put your script inline and use stupid comment tricks to keep it from confusing the parser"

Opinion Haver
Apr 9, 2007

Gazpacho posted:


You could encode arbitrary data in an image and extract it via canvas and then evaluate it

not if it's from a different domain you can't. drawing to a canvas using a font or image from a different domain taints the canvas and you can't read from a tainted canvas

Mr Dog posted:

JSONP

:bang:

like i'm sure there's a good reason for it but I mean seriously? "JavaScript interpreter, pre-cache this image from a different domain" "ok np" "JavaScript interpreter, load some JSON data from that same domain so I know what to do with this image" "BEEP BOOP SECURITY BREACH GET hosed DAVE"

the thing this is trying to stop is this:

suppose site X exposes sensitive information via some JSON REST endpoint at http://site.com/foo/my_data. if you could just request that data then any site could read your data b/c the request would get sent with the right cookies. if you want that information to be accessible you can either use JSONP or do the whole access-control-allow-origin thing to make it so any domain can XHR for that data

Sapozhnik
Jan 2, 2005

Nap Ghost
XMLHTTPRequest has the opposite problem, the theory is that if you stumble into shitheads.com and javascript on that site is allowed to issue arbitrary HTTP calls to burpandfartbanking.com with your cookies then that's bad. Also in theory if the remote site authenticates by IP then shitheads.com's javascript could load stuff off your intranet and then post it back to shitheads.com

so yes there's a reason for it, but it's still annoying to deal with.

e: yeah what that guy said

Gazpacho
Jun 18, 2004

by Fluffdaddy
Slippery Tilde

yaoi prophet posted:

not if it's from a different domain you can't. drawing to a canvas using a font or image from a different domain taints the canvas and you can't read from a tainted canvas
Nice!

prefect
Sep 11, 2001

No one, Woodhouse.
No one.




Dead Man’s Band

yaoi prophet posted:

not if it's from a different domain you can't. drawing to a canvas using a font or image from a different domain taints the canvas and you can't read from a tainted canvas

now i have that "bong bong" sound from soft cell's version of "tainted love" stuck in my head

thanks, i think

Gazpacho
Jun 18, 2004

by Fluffdaddy
Slippery Tilde
how about this, transmit arbitrary cross-domain data via the dimensions information in a sequence of image requests, checkmate security "experts"

Opinion Haver
Apr 9, 2007

Gazpacho posted:

how about this, transmit arbitrary cross-domain data via the dimensions information in a sequence of image requests, checkmate security "experts"

the point isn't that you can't do cross-domain data, you can just set Access-Control-Allow-Origin: * and then anybody can cross-domain you

the point is that unless you allow it you should only leak minimal data

my favorite stupid attack is the one where you set up a captcha that's like 'enter the number you see on this seven-segment lcd' except each individual segment is only green if you've visited a site so the user winds up telling you their browsing history

Squinty Applebottom
Jan 1, 2013

yaoi prophet posted:

my favorite stupid attack is the one where you set up a captcha that's like 'enter the number you see on this seven-segment lcd' except each individual segment is only green if you've visited a site so the user winds up telling you their browsing history

lol never heard of this

nice

Malcolm XML
Aug 8, 2009

I always knew it would end like this.

polpotpi posted:

lol never heard of this

nice

hell at one point all you had to do was load a bunch of links and check the color to see if a user had visited them or not. not sure if that was fixed

tef
May 30, 2004

-> some l-system crap ->

yaoi prophet posted:

my favorite stupid attack is the one where you set up a captcha that's like 'enter the number you see on this seven-segment lcd' except each individual segment is only green if you've visited a site so the user winds up telling you their browsing history

lololol owns.

Gazpacho
Jun 18, 2004

by Fluffdaddy
Slippery Tilde
here it is
http://www.ieee-security.org/TC/SP2011/PAPERS/2011/paper010.pdf

Adbot
ADBOT LOVES YOU

HORATIO HORNBLOWER
Sep 21, 2002

no ambition,
no talent,
no chance
trust nothing nowhere at no time

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply