Simon Willison’s Weblog

Subscribe

November 2008

Nov. 2, 2008

.. yet another ridiculous data breach: this time, people's passwords to the Government Gateway on a memory stick dropped in the road. Perhaps it is uncouth to point this out, but... if the system had been designed by people with any security clue whatsoever there would have been no passwords to put on a memory stick in the first place.

Ben Laurie

# 1:04 pm / security, ben-laurie, passwords

BBC Programmes via Instant Messenger. Neat jabber hack by Duncan Robertson.

# 3:58 pm / duncanrobertson, bbc, jabber, jabberbot

Nov. 3, 2008

Python gems of my own (via) Did you know you can pass 128 as a flag to Python’s re.compile() function to spit out a parse tree? I didn’t. re.compile(“pattern”, 128)

# 11:59 am / eric-holscher, python, regex

When visiting any Web page, the site owner is easily able to ascertain what websites you've visited (CSS color hacks) or places you're logged-in (JavaScript errors / IMG loading behavior). They can also automatically exploit your online bank, social network, and webmail accounts (XSS). Additionally, the browser could be instructed to hack devices on the intranet, including DSL routers and printers. And, if that's not enough, they could turn you into a felon by forcing requests to illegal content or hack other sites (CSRF).

Jeremiah Grossman

# 12:43 pm / jeremiahgrossman, security, xss, csrf

Obama v McCain—battleground graph (via) Paul Crowley provides the smartest election visualisation I’ve seen this cycle, using the current projections from fivethirtyeight.com and with a promise of a frequently updated version as the actual results roll in.

# 8:40 pm / paul-crowley, elections, visualisation, graph

Nov. 4, 2008

I'll put forth one central, overriding guideline for iPhone UI design: Figure out the absolute least you need to do to implement the idea, do just that, and then polish the hell out of the experience.

John Gruber

# 12:02 am / john-gruber, iphone, design, usability

Nov. 6, 2008

Just One More Grim Thing (via) Tim Schafer releases 72 pages of design documentation for Grim Fandango, my all-time favourite computer game.

# 7:51 pm / grimfandango, games, tim-schafer

Code your own election mashup with Google’s JSON data. The data that powered Google’s US election results map is available to download as a bunch of JSON files.

# 8:24 pm / google, json, data, uselection

It’s a purple world. Stuart Langridge made a purplish map of the US election results, using JSON data from Google and an SVG map of the US from Wikipedia.

# 8:26 pm / stuart-langridge, uselection, svg, wikipedia

Nov. 7, 2008

jQuery history plugin. I used this plugin to add back button support to a small Ajax app today, with great results. I tried it a while ago and it didn’t work in Safari, but someone has updated it since and now it works perfectly.

# 5:32 pm / jquery, history, ajax, javascript, plugins, backbutton

Introducing Acre. I’m losing track of all the server-side JavaScript hosted web application platforms now. Here’s the Freebase contribution to the genre, complete with IDE, templating language and strong integration with Freebase itself.

# 11:23 pm / javascript, freebase, acre, serversidejavascript

Nov. 8, 2008

The Tea Cosy. Our favourite Brighton tea room has redesigned their site—truly classy. Don’t forget to memorise the etiquette rules.

# 5:14 pm / the-tea-cosy, tearoom, brighton, tea, etiquette

Clearing up inaccuracies about the Google OpenID IDP launch. Google took some undeserved flack when they launched their OpenID provider. For the record, whitelisting providers fits my definition of the “Open” in OpenID perfectly (providers and consumers are free to impose whatever policies they like).

# 11:11 pm / whitelisting, openid, google

Secrets of the Django ORM. An undocumented (and unsupported) method of poking a Django QuerySet’s internal query to add group_by and having clauses to a SQL query.

# 11:49 pm / django, orm, queryset, sql, having, groupby, python

Nov. 10, 2008

iPhone Backup Extractor possibilities (via) Nick Ludlam points out that iTunes backs up your iPhone call records by copying across a sqlite database—which means it wouldn’t be at all hard to extract the logs in to a larger database. Could make for a really cool addition to a private lifestreaming application.

# 10:41 pm / nickludlam, iphone, sqlite, itunes, backup, lifestream

License Hacking. Wikipedia is making the switch to a CC license, by asking the Free Software Foundation to include that as an option in the latest version of the Free Documentation License which Wikipedia currently uses and which includes an auto-upgrade clause. Devious.

# 10:46 pm / licenses, open-source, wikipedia, freesoftwarefoundation, fsf, creativecommons, fdl

Worst. Bug. Ever. Android phones were executing every keystroke typed in to the phone in an invisible root shell! Text “reboot” to a friend and your phone rebooted. Wow.

# 10:51 pm / android, bug, security, root, phones

Nov. 11, 2008

Interview @MarsPhoenix (via) “For over a year, Veronica McGregor has been Twittering from Mars.”—an interview with the Twitter voice of the Mars Phoenix lander.

# 12:17 pm / marsphoenix, space, twitter, veronicamcgregor

It's funny, when I sit down to write something for Phoenix I feel like I have to get into my "Phoenix character." [...] I try to be the eternal optimist because people are getting so upset about the mission coming to an end, and I'm trying to lessen that grief.

Veronica McGregor

# 12:21 pm / marsphoenix, twitter, firstperson, veronicamcgregor

DRGBLZ. lolzeppelins?

# 3:13 pm / zeppelins, lolspeak, funny, airships

Nov. 12, 2008

lightningtimer.net. I’m fed up of having to dig out or knock up a timer script every time I manage lightning talks, so I’ve given one a domain name. You can use lightningtimer.net/#90 to set a different start time for the counter.

# 4:43 pm / lightningtimer, projects, javascript, lightningtalks

On UI Quality (The Little Things): Client-side Image Resizing. Two neat tips for cleanly scaling down images in IE 6 and 7 from Flickr’s Scott Schiller.

# 11 pm / scott-schiller, flickr, imagescaling, ie

Nov. 18, 2008

The new Lawrence.com. The world’s best local entertainment website, relaunched on Django 1.0 with an accompanying substantial redesign.

# 2:25 pm / lawrencecom, django, python, lawrence, kansas, redesign, design

Amazon CloudFront. The Amazon CDN front end for S3 has launched. Traffic is 2 cents per GB more than S3. I’d like to see a price comparison with existing CDNs; I have a hunch it’s an order of magnitude less expensive.

# 2:37 pm / amazon, cdn, cloudfront, s3

Hack Day at the Guardian. Video of the demos from the first Hack Day at the Guardian. I presented a crowdsourcing app I used to collect annotations for an SVG map of the UK.

# 5:58 pm / guardian, hackday

Notes from Hack Day at The Guardian. Our first hack day was a ridiculous amount of fun. Matt’s write-up includes a 15 minute highlight video, which includes my 90 second presentation of my crowdsourcing SVG-powered parliamentary constituencies hack.

# 11:42 pm / hacks, hackday, the-guardian, matt-mcalister

Nov. 19, 2008

The March of Access Control. The W3C Access Control specification is set to become a key technology in enabling secure cross-domain APIs within browsers, and since it addresses a legitimate security issue on the web I hope and expect it will be rolled out a lot faster than most other specs.

# 8:40 am / accesscontrol, john-resig, ie, browsers, security, crossdomain

Heck, I practically invented the formula of "tell a funny story and then get all serious and show how this is amusing anecdote just goes to show that (one thing|the other) is a universal truth." And everybody is like, oh yes! how true! and they link to it with approval, and it zooms to the top of Slashdot. And six years later, a new king arises who did not know Joel, and he writes up another amusing anecdote, really, it's the same anecdote, and he uses it to prove the exact opposite, and everyone is like, oh yes! how true! and it zooms to the top of Reddit.

Joel Spolsky

# 8:41 am / joel-spolsky, reddit, slashdot, anecdotes

Django 1.0.2 released. An update to last week’s 1.0.1 release, which I failed to link to. 1.0.2 mainly fixes some packaging issues, while 1.0.1 contains “over two hundred fixes to the original Django 1.0 codebase”. The team are holding up the promise to move to a regular release cycle after 1.0.

# 8:46 am / django, releases, python

2008 » November

MTWTFSS
     12
3456789
10111213141516
17181920212223
24252627282930