Shared posts

12 Sep 18:34

The Simplest Possible Step

by Richard Millington

The idea was simple; get the engineers actively engaged in our community.

If we could connect engineers directly with members, the engineers could get useful feedback on their plans, learn what members needed, and build better products.

But the engineers (like most engineers, frankly) were far too busy to spend time in the community.

In situations like these, we’ve typically found an escalating series of asks makes this successful. Usually, this looks like:

1) Open hours/AMAs. Have a product engineer spend an hour each month answering as many questions as they can from members. Members usually like this format and engineers find it convenient (and fun).

2) Unsolicited feedback. If the product feedback goes well for a few months, ask engineers what kind of feedback would be useful and collect/send it on at the right times (at the beginning of an engineering sprint works well).

3) Solicited feedback. If unsolicited feedback goes well, have engineers suggest questions they would love to know the answer to and post these to the community. This is pretty simple.

4) Proactively monitoring and engagement. Finally invite and guide product engineers to proactively monitor the community, respond to questions, ask questions, and gather feedback – especially after a big change.

Your mileage with each step will vary. But start small and expand the asks over time.

12 Sep 18:34

Live-hacking Dropbox @ H1-3120

by Nathanial Lattimer
H1-3120 Most Valuable Hacker mrtuxracer (Image source: HackerOne)

In 2018, Dropbox has focused on improving our world-class bug bounty program. From increasing bounties to protecting our researchers, we’re always looking for more creative and meaningful ways to stay ahead of the game when it comes to running this program.

As an example, we recently partnered with HackerOne to host their H1-3120 live-hacking event in Amsterdam. Live-hacking events let participants hack on a target—often in person—submit vulnerabilities, and receive bounties quickly, all during the course of the event. Live-hacking comes with a number of benefits over traditional bug bounty programs, such as real-time communication and relationship building, which makes finding vulnerabilities and receiving bounties much easier. The event was a huge success! We received plenty of stellar reports and doubled the highest amount we’ve ever paid in a single day for bug bounties.

H1-3120 planning

To prepare for the event, we sat down to determine how to get the most value possible out of the short time we had with the hackers. From that discussion, we came up with three objectives:

  • Significantly increase the research scope for the event
  • Provide a fast and efficient communication channel for the participants
  • Offer information and guidance to aid in bug bounty research

Increased scope

Dropbox aims to have one of the most permissive scopes in the bug bounty world. Scope is the predefined set of targets that bug hunters are allowed to test. In addition to Dropbox assets, we’ve begun to migrate some of our external partners into scope as well. For H1-3120, we required more of our vendors to take on the challenge of participating in bug bounty research. Five SaaS vendors we use were placed in scope for the event, with Dropbox handling all of the triage and paying bounties for any reports.

Both HackerOne staff and participants found this exciting. In fact, including vendors as part of the scope for a HackerOne live-hacking event had never been done before. For us, the decision just made sense: when Dropbox engages a vendor who will have access to sensitive Dropbox data, we hold them to very high security standards, including a commitment to welcome scrutiny by Dropbox and other security researchers.

Efficient communication

We wanted to ensure that our H1-3120 participants had the best possible opportunity to find vulnerabilities in Dropbox and our vendors. We made sure that someone was available to field questions over Slack the week prior to the event while the participants were doing reconnaissance. Additionally, we participated in a conference call with the hackers to answer questions and give advice.

Information and guidance

To help participants find more valuable bugs, we decided to show them a handful of vulnerabilities that Dropbox has had in the past as well as highlight places that we think have the highest risk for potential vulnerabilities. By getting more eyes on the least frequently tested parts of Dropbox, we help researchers—and ourselves—make Dropbox more secure.

The event

H1-3120 started off with a flurry of submissions. In the weeks prior, the hackers were already trying to find vulnerabilities in both Dropbox and our vendors. The plethora of submissions at H1-3120 showcased that effort. Within the first 30 minutes of the event, over 50 reports came in ranging from simple information disclosure to cross-site scripting. The hackers even found a remote code execution in the perimeter of one of our vendors!

The Dropbox Security team had a blast meeting researchers, hunting complex vulnerabilities, and improving the security of our product. After the last reward was paid out, Dropbox had distributed more than $80,000 in bounties to researchers at the event, with over $5,000 of that donated to charities.

Conclusion

The real value we’ve experienced from the event is the overall uptick in interest in our bug bounty program. Since H1-3120, we’ve had a 23% increase in submissions per day to our program, including a report from bug hunter detroitsmash with a $9,000 bounty.

In addition our new relationships with the researchers are proving to be invaluable. We’ve had a number of conversations with our more frequent bug bounty participants leading to HackerOne reports that we’ve subsequently awarded on. We’re planning to connect more with our recurring researchers to build on these important relationships.

Dropbox is committed to ensuring our bug bounty program draws the best bug hunting talent from around the world. When friendly hackers find the vulnerabilities before the bad actors do, that’s a huge win for the entire security community. Thanks to all the participants of H1-3120 as well as all the security researchers that send us reports every day!

12 Sep 18:33

"You only find out who is swimming naked when the tide goes out."

“You only find out who is swimming naked when the tide goes out.” - Warren Buffett
12 Sep 18:33

Watch Chinese Inflation, Closely

Inflation is creeping up in China, which could lead to a cascade of other problems since the country...
12 Sep 18:33

Cabin Cloud: bump-free travel on the night bus

by Alex Bate

Planes, trains, and automobiles — we all have our preference. And at one company in California, the team is trying to smooth bus travel to broaden commuters’ options for a blissful night’s sleep.

Cabin bus Raspberry Pi Wired

Leaving on a jet plane

Not everyone wants to fly. While many enjoy the feel of take-off and landing and the high speed at which they can travel from A to B, others see planes as worrisome tin cans of doom, suspended in the air by unreliable magic. I consider myself mostly the former, with a hint of the latter for balance.

In truth, I’d rather catch a train, where the smooth ride sends me into blissful sleep, only occasionally interrupted by a snap of “Damn, did I miss my stop?!”.

But trains are limited to where their tracks lead, which is why so many people still opt to travel by bus. But who can sleep on a bus when the roads are dotted with potholes and cracks? I can’t, and neither can many of the 10000 passengers of the Cabin bus, an overnight service running between Los Angeles and San Francisco.

Cabin bus travel

To address complaints about the road conditions affecting costumers’ sleep, the Cabin team decided to challenge gravity using a Raspberry Pi and the electric motor from a hoverboard in their new venture Cabin Cloud.

Introducing the first active suspension system designed specifically with passenger sleep in mind. Combining patent-pending software and hardware, our technology mutes ‘road turbulence’ and dramatically reduces vibration, so you can get a good night’s sleep while on a moving vehicle.

“We can isolate a passenger’s body, and input frequencies that help people relax and fall asleep,” explains Cabin CTO Tom Currier. “We have a set of sensors that are measuring the acceleration of the vehicle, and also the bed, to compute in real time what we should be cancelling out.”

Cabin bus Raspberry Pi Wired

The sensors are accelerometers, two per bed, that measure the bumps from the road and adjust the bed accordingly — up to 1000 times a second. The Cabin Cloud beds only adjust for motion up and down: the team isn’t too concerned about back-and-forth movements due to braking too hard or turning corners, since Cabin busses predominantly travel on wide, open highways.

Delve a little deeper

Check out this article from Wired for more about the project, and about how similar tech is implemented in trucks for long-haul drivers, and in aeroplanes for turbulence-free travel. You can also sign up for the Cabin Cloud newsletter here.

But the big question about Cabin Cloud is…

Does it have Bluetooth?

The post Cabin Cloud: bump-free travel on the night bus appeared first on Raspberry Pi.

12 Sep 18:33

The Luddites Were Right

Steve Levine talked with David Autor about a paper he published in March with Anna Salomons,...
12 Sep 18:33

Needing help

by Josh Bernoff

Someone I love dearly is having surgery today. You were probably starting your day by thinking about what happened 17 years ago. I will be starting my day thinking about what will happen this afternoon. I am a very public person in my professional life, and a very private person in my family life. So … Continued

The post Needing help appeared first on without bullshit.

12 Sep 18:33

Compiling and Exporting Chapters for My iOS 12 Review with Drafts 5

by Federico Viticci

Editor’s Note

Every year, we publish around 60 issues of MacStories Weekly and the Monthly Log for Club MacStories members. MacStories Weekly is packed with our favorite apps, app collections, advanced shortcuts, answers to Club members’ questions, iPads Around the World, which features people who use the iPad in unique and interesting ways, interviews, home screens, tips, and more. You can read a free sample here.

The Workflow Corner is a column of MacStories Weekly where I explain and share custom shortcuts (i.e. workflows) for Apple's Shortcuts app, as well as scripts and other automation techniques for other iOS apps. With my iOS 12 review on the horizon, I thought it would be useful for MacStories readers to learn how I've been using Drafts 5 to organize the chapters of the review and back everything up to multiple external locations. The following post has been adapted from the Workflow Corner section of Issue 133 of MacStories Weekly.

If you enjoy MacStories.net but want even broader and deeper coverage from the MacStories team, please consider joining Club MacStories. As a new member you’ll receive the newsletters, have access to our full archive of almost 200 back issues, and enjoy other perks throughout the year. We work hard to make each issue special for Club members and would love for you to be a part of it.

You can find out more about Club MacStories and subscribe here.


Back in June, I wrote on MacStories that I was evaluating whether Drafts 5 could replace Editorial for my Markdown automation and become the app I use to write my annual iOS review. Putting together these longform pieces involves a lot of writing, editing, and navigating between different sections; the more I can automate these tasks, the more time I can spend doing what actually matters for the review – testing the new version of iOS and ensuring the review is up to my standards.

Once I started looking into Drafts 5, I realized I could take advantage of its JavaScript automation engine to build a custom action that would compile the latest version of my iOS review draft and back it up to multiple locations as a single Markdown (.md) text file.

First, some context. I always like to write my iOS reviews in separate text files – one for each chapter – that are eventually compiled into a single "master" file; toward the end of August, I usually start editing this file in Editorial. As I mentioned on MacStories though, this year I wanted to move away from Editorial as I didn't think the app was going to receive major updates anymore; Drafts 5 felt like the safest and most promising bet.

At the same time, I also wanted to simplify my process so that I wouldn't end up writing my review in an app and editing it in another. For the past few years, I've experimented with Scrivener and Ulysses for this, but neither of them is well suited for the unique mix of longform writing and heavy Markdown automation I'm looking for. Drafts 5 felt like the spiritual successor to Editorial that I could fully script and customize to my needs. So for the past three months, I've been writing and editing my upcoming iOS 12 review entirely in Drafts.

Drafts 5 offers native tagging for notes, which can be combined with workspaces and scripting to create dedicated writing environments that can be tied to action groups. My idea was simple enough: given notes that had been tagged with "ios12", I wanted to sort them by title, merge them into a single text file, and save them in iCloud Drive, Dropbox, and Working Copy. With this system, I was able to:

  • Create a separate workspace for the iOS 12 review in Drafts;
  • Name each chapter something along the lines of ## 3. Shortcuts;
  • Sort everything by the order in which chapters would appear on MacStories;
  • Back everything up to three separate locations.

To build this action, I had to turn to JavaScript.

My iOS 12 Review workspace in Drafts 5.

My iOS 12 Review workspace in Drafts 5.

One function of the Draft object in Drafts 5 is the ability to retrieve an array of drafts by querying the app for items that match a specific search string, filter, or tag (or combination of all three). Essentially, this allows you to search Drafts 5 for items that match specific conditions; items can then be iterated upon in JavaScript for additional manipulation. My action involves querying Drafts 5 with a tag filter, which returns an array of drafts that can be read in a repeat loop and appended (one after the other) to a new variable, which then becomes the .md file to share with other apps.

The action is comprised of three steps: a JavaScript one plus two visual actions. Let's take a look at the full script first:

var drafts = Draft.query("", "all", ["ios12", "compile"]);

//Sort matched notes by title

drafts.sort((a,b) => {
return a.content.localeCompare(b.content);
});

//Create empty sections variable and iterate over notes to add them to the variable

var sections = [];

for (var i = 0; i < drafts.length; i++) {
    item = drafts[i];
    if (!item.isArchived){
        sections.push(item.content);
        sections.push("\n\n");
    }
}

var compile = sections.join("");

//Create first backup in Drafts 5 folder in iCloud Drive, runs in the background

var fmCloud = FileManager.createCloud(); // Cloud file in app container
var success = fmCloud.write("/Review.md", compile);

draft.setTemplateTag("file", compile);

Line 1 is where the Draft.query() function searches for all drafts that contain the "ios12" and "compile" tags. If you want to use this action yourself, you'll have to change the tag names between quotes. Also, as detailed in the app's documentation, you can optionally query the app for drafts that contain a specific string of text; for the purpose of this action, I just need to find all drafts that have been assigned two specific tags.

Once the action has an array of drafts, it can sort them by name (I have to thank Greg Pierce for the suggestion here) and append each one to an empty array created on Line 11. On Line 21, all the items in the new array are then joined in a single compile variable that is assigned the [[file]] template tag at the end of the script. This tag allows us to reference the newly generated file in other non-script steps of the same action, and it's one of my favorite features of Drafts 5's JavaScript as it provides a native bridge between scripting and built-in actions.

If you look at the script closely, you'll see that one of the first copies of the master file is saved from the script itself. On Lines 25-26, Drafts uses the FileManager object to turn the compile variable into a file named Review.md (again, you should change this) that is automatically saved in iCloud Drive/Drafts 5. While I would have preferred being able to save in any iCloud Drive folder via JavaScript (apps still can't programmatically write files outside of their container without manual user input), I still end up with a plain text copy of the file backed up in iCloud Drive with just two lines of code, which is remarkable.

Saving a compiled draft of the review in Dropbox.

Saving a compiled draft of the review in Dropbox.

The last two steps are native actions that use the [[file]] tag to save a compiled copy of the review in Dropbox and Working Copy, respectively. Dropbox is a built-in action that accepts a file name and path (which you should also change) and which can be set to overwrite an existing file of the same name. I choose to replace files because I have my editing history in Drafts and Working Copy anyway; plus, I don't want to end up with dozens of similarly named files in Dropbox.

Finally, because iOS doesn't have a way to save data directly into another app's container, saving the .md file to a GitHub repository in Working Copy is done via the share sheet. Just like other actions, we can use the [[file]] tag as input for the share sheet, which will then pass the file to the Working Copy extension. As in previous years, I relied on GitHub to keep track of changes to the review throughout the summer and share revisions of the draft with my editor and my colleagues at MacStories.

Even though Drafts still isn't nearly as intuitive or visual as Editorial or Shortcuts when it comes to automation (it still relies too much on JavaScript in my opinion; there should be more native actions that perform the same functionalities), I love the fact that I can fully customize my text editor and build actions based on tagging. Drafts 5 is the only app on iOS that can scale from being a minimalistic note-taking scratchpad to a viable BBEdit alternative powered by actions and scripts.

The more I look into Drafts 5, the more I see untapped potential for serious Markdown automation; I'm excited to continue my experiments for MacStories and the Club over the next few months.

You can download the action here.


Support MacStories Directly

Club MacStories offers exclusive access to extra MacStories content, delivered every week; it's also a way to support us directly.

Club MacStories will help you discover the best apps for your devices and get the most out of your iPhone, iPad, and Mac. Plus, it's made in Italy.

Join Now
12 Sep 18:33

Twitter To Livestream Apple’s Fall Keynote

by John Voorhees

TechCrunch has confirmed that Apple is expanding how its September 12th keynote can be consumed. In years past, Apple keynotes were limited to streaming in Safari and the Apple Events app. This past summer, Apple expanded browser-based streaming to include Firefox and Chrome.

Yesterday, Apple began offering reminders of its event via Twitter, which the company has done in the past. As Sarah Perez of TechCrunch notes, however, the wording for tomorrow’s event was a little different:

Instead of saying “follow” the event on Twitter, the tweet says “…watch the #AppleEvent live on Twitter.” (Emphasis ours).

Watch implies a live stream, and the tweet itself featured an animated GIF as another hint.

That wording kicked off speculation that Twitter would stream the keynote, which TechCrunch and other media outlets have since confirmed.

Apple will hold its special event at the Steve Jobs Theater tomorrow at 10 a.m. PDT. Besides the Apple Events app and Twitter livestream, the event will be available on apple.com.


You can follow all of our Apple event coverage through our September 12, 2018 hub, or subscribe to the dedicated September 12, 2018 RSS feed.

→ Source: techcrunch.com

12 Sep 18:33

Is Apple Neglecting Beats’ Headphone Business in Favor of Its Own?

by John Voorhees

The Verge has a story today by Micah Singleton in which he wonders whether Apple still cares about Beats, the company it acquired in 2014. As Singleton notes, no new products have been released under the Beats brand in 2018, and The Verge’s sources say we shouldn’t expect that to change at Apple’s keynote tomorrow.

Nonetheless, Beats continues to have marketing successes, like recently becoming the official headphones of the NBA and USA Basketball. However, the dearth of new products coupled with competition from Apple’s wireless AirPods and rumored premium over-the-ear headphones puts Beats in a tight spot, which Singleton argues is a mistake:

Apple has its eyes set on the high-end audio market to compete against the likes of Audio-Technica, Bose, and a rapidly improving headphone ecosystem. But neglecting the team that has been able to sell slightly above-average headphones at a breakneck pace for nearly a decade doesn’t seem like a smart business move for either party. If you are the official headphone company for United States Basketball, it seems wise to continue releasing new headphones. And if you are Apple — and your history with headphones and speakers has precisely one win, despite many attempts — you should lean on the company you own that hasn’t missed yet.

Beats jump-started Apple’s music streaming efforts, but other than adding the W1 chip to its wireless headphones in late 2016 and 2017, there have been few signs of Apple’s plans for Beats. I hope Singleton is wrong about Apple neglecting Beats because it would be a shame to squander the company’s valuable brand, though I suspect he may not be.

→ Source: theverge.com

12 Sep 18:27

Blogging at Scale with Google Sheets

by Reverend

When you go directly from several weeks of work travel into the beginning of the semester rush at Reclaim Hosting, the bava.blog necessarily gets neglected. But that changes now!

Back on August 22nd Tim and I sat down with John Stewart to talk about his ingenius work to use Google Sheets to enable near on 1000 students in University of Oklahoma’s biggest lecture classroom to blog at scale. Pretty brilliant to use Google Sheets as a kind of  WordPress Multisite stand-in wherein Google manages scaling the infrastructure for you. In this, the 8th episode of Reclaim Today, we discuss this experiment in detail, and I was really enthusiastic because it felt like a really creative and useful way to imagine getting a class using a simple form to blog up and running with very little financial overhead. Fast cheap, and out-of-control: edtech at its best.

You can read the first and second of the three post series John promised, and the video was recorded on location at Reclaim Video and comes in at a very manageable 23 minutes with a couple of the best looking ed-techs this side of proprietary. Here is the synopsis in case you need a more objective reason to watch:

Jim and Tim sit down with John Stewart of the University of Oklahoma to discuss a recent solution he blogged about in which he’s using Google Spreadsheets and APIs to drive a fast and scalable blogging infrastructure to support a course with 1,000 students.

And if you come away with nothing else, it should be mad kudos for John Stewart for a really creative, relatively light-weight  solution to a potentially expensive and resource intensive problem, the term innovation gets thrown around way too loosely but it makes resonates for me in this case.

12 Sep 18:27

Vancouver’s Worst Zoning: The Walking Tour (Sep 16)

by Colin Stein

Advocates from Abundant Housing Vancouver are hosting a walking tour with a bit of a bite this weekend…

Vancouver’s Worst Zoning: The Walking Tour
Sunday, Sep. 16
1:00 – 4:00pm

RSVP via Facebook

Here’s a little context to the event from the AHV folks…

“You might already know that townhouses and apartments are illegal on most of Vancouver’s residential land. But did you know that some neighbourhoods go further by effectively zoning for mansions that are many times more expensive than even the average multi-million-dollar westside Vancouver house?

…Join AHV members for a casual walking tour through West Point Grey. We’ll tour the ultra-exclusionary Belmont Avenue and Drummond Drive neighbourhood, discuss the City of Vancouver policies that keep it out of reach for most, and wind up on 10th or Broadway for drinks, food, and socializing.”

Here’s a map of the ‘hood, with a pin at the starting point:

12 Sep 18:26

Seventeen is (Almost) Just Another Day

by Anil Dash
Seventeen is (Almost) Just Another Day

For the first decade after the attacks, I basically didn’t go anywhere near that part of downtown. A business meeting would take me a few blocks away, and I’d feel that tightness in my chest, that presence, and I’d just keep moving.

But this morning, I’ll walk out of the (newly-opened!) A train access and walk through the Oculus as part of my commute, as I’ve done dozens of times before. Somehow, improbably, its all become routine.

To be clear, I do still deliberately steer away from the reflecting pools and the memorials. And I give an even wider berth to the tourists drawn to them. (“Which way is 9/11?”) But somehow this place is something more than its ghosts now, and I’m able to be a transit nerd who appreciates a beautiful, if absurd, train station, or to be a person who appreciates a farmer’s market, even as it sprawls just steps away from where I remember seeing that still-smoldering pile of rubble.


People don’t even really ask, “Where were you that day?” anymore. For all of the ironic “Never Forget”s, the whole moment has largely faded into history, even as the whole world really was reshaped. There’s a mall there now, a temple to the “go back to shopping” doctrine introduced in those first days of chaos and grief. In the current moment, it’s clearer than ever that those murderous attackers succeeded far beyond their wildest dreams, achieving forms of destruction and destabilization that they probably never even dreamed of.

But there’s something ordinary, too. If this has become the New Normal, the most unlikely part may be that it’s still a kind of normal.


I spent so many years thinking “I can’t go there” that it caught me completely off guard to realize that going there is now routine. Maybe the most charitable way to look at it is resiliency, or that I’m seeing things through the eyes of my child who’s never known any reality but the present one. I'd spent a lot of time wishing that we hadn't been so overwhelmed with response to that day, so much that I hadn''t considered what it would be like when the day passed for so many people with barely a notice at all.

In Past Years

Each year I write about the attacks on this anniversary, to reflect both on that day and where I'm at right now. I also deeply appreciate the conversation that ensues with those who check in with me every year.

Last year, Sixteen is Letting Go Again

So, like ten years ago, I’m letting go. Trying not to project my feelings onto this anniversary, just quietly remembering that morning and how it felt. My son asked me a couple of months ago, “I heard there was another World Trade Center before this one?” and I had to find a version of the story that I could share with him. In this telling, losing those towers was unimaginably sad and showed that there are incredibly hurtful people in the world, but there are still so many good people, and they can make wonderful things together.

Two years ago, Fifteen is the Past:

I don’t dismiss or deny that so much has gone so wrong in the response and the reaction that our culture has had since the attacks, but I will not forget or diminish the pure openheartedness I witnessed that day. And I will not let the cynicism or paranoia of others draw me in to join them.
What I’ve realized, simply, is that 9/11 is in the past now.

Three years ago, Fourteen is Remembering:

For the first time, I clearly felt like I had put the attacks firmly in the past. They have loosened their grip on me. I don’t avoid going downtown, or take circuitous routes to avoid seeing where the towers once stood. I can even imagine deliberately visiting the area to see the new train station.

In 2014, Thirteen is Understanding:

There’s no part of that day that one should ever have to explain to a child, but I realized for the first time this year that, when the time comes, I’ll be ready. Enough time has passed that I could recite the facts, without simply dissolving into a puddle of my own unresolved questions. I look back at past years, at my own observances of this anniversary, and see how I veered from crushingly sad to fiercely angry to tentatively optimistic, and in each of those moments I was living in one part of what I felt. Maybe I’m ready to see this thing in a bigger picture, or at least from a perspective outside of just myself.

From 2013, Twelve is Trying:

I thought in 2001 that some beautiful things could come out of that worst of days, and sure enough, that optimism has often been rewarded. There are boundless examples of kindness and generosity in the worst of circumstances that justify the hope I had for people’s basic decency back then, even if initially my hope was based only on faith and not fact.
But there is also fatigue. The inevitable fading of outrage and emotional devastation into an overworked rhetorical reference point leaves me exhausted. The decay of a brief, profound moment of unity and reflection into a cheap device to be used to prop up arguments about the ordinary, the everyday and the mundane makes me weary. I’m tired from the effort to protect the fragile memory of something horrific and hopeful that taught me about people at their very best and at their very, very worst.

In 2012, Eleven is What We Make:

These are the gifts our children, or all children, give us every day in a million different ways. But they’re also the gifts we give ourselves when we make something meaningful and beautiful. The new World Trade Center buildings are beautiful, in a way that the old ones never were, and in a way that’ll make our fretting over their exorbitant cost seem short-sighted in the decades to come. More importantly, they exist. We made them, together. We raised them in the past eleven years just as surely as we’ve raised our children, with squabbles and mistakes and false starts and slow, inexorable progress toward something beautiful.

In 2011 for the 10th anniversary, Ten is Love and Everything After:

I don’t have any profound insights or political commentary to offer that others haven’t already articulated first and better. All that I have is my experience of knowing what it mean to be in New York City then. And from that experience, the biggest lesson I have taken is that I have the obligation to be a kinder man, a more thoughtful man, and someone who lives with as much passion and sincerity as possible. Those are the lessons that I’ll tell my son some day in the distant future, and they’re the ones I want to remember now.

In 2010, Nine is New New York:

[T]his is, in many ways, a golden era in the entire history of New York City.
Over the four hundred years it’s taken for this city to evolve into its current form, there’s never been a better time to walk down the street. Crime is low, without us having sacrificed our personality or passion to get there. We’ve invested in making our sidewalks more walkable, our streets more accommodating of the bikes and buses and taxis that convey us around our town. There’s never been a more vibrant scene in the arts, music or fashion here. And in less than half a decade, the public park where I got married went from a place where I often felt uncomfortable at noontime to one that I wanted to bring together my closest friends and family on the best day of my life. We still struggle with radical inequality, but more people interact with people from broadly different social classes and cultures every day in New York than any other place in America, and possibly than in any other city in the world.
And all of this happened, by choice, in the years since the attacks.

In 2009, Eight Is Starting Over:

[T]his year, I am much more at peace. It may be that, finally, we’ve been called on by our leadership to mark this day by being of service to our communities, our country, and our fellow humans. I’ve been trying of late to do exactly that. And I’ve had a bit of a realization about how my own life was changed by that day.
Speaking to my mother last week, I offhandedly mentioned how almost all of my friends and acquaintances, my entire career and my accomplishments, my ambitions and hopes have all been born since September 11, 2001. If you’ll pardon the geeky reference, it’s as if my life was rebooted that day and in the short period afterwards. While I have a handful of lifelong friends with whom I’ve stayed in touch, most of the people I’m closest to are those who were with me on the day of the attacks or shortly thereafter, and the goals I have for myself are those which I formed in the next days and weeks. i don’t think it’s coincidence that I was introduced to my wife while the wreckage at the site of the towers was still smoldering, or that I resolved to have my life’s work amount to something meaningful while my beloved city was still papered with signs mourning the missing.

In 2008, Seven Is Angry:

Finally getting angry myself, I realize that nobody has more right to claim authority over the legacy of the attacks than the people of New York. And yet, I don’t see survivors of the attacks downtown claiming the exclusive right to represent the noble ambition of Never Forgetting. I’m not saying that people never mention the attacks here in New York, but there’s a genuine awareness that, if you use the attacks as justification for your position, the person you’re addressing may well have lost more than you that day. As I write this, I know that parked out front is the car of a woman who works in my neighborhood. Her car has a simple but striking memorial on it, listing her mother’s name, date of birth, and the date 9/11/2001.

In 2007, Six Is Letting Go:

On the afternoon of September 11th, 2001, and especially on September 12th, I wasn’t only sad. I was also hopeful. I wanted to believe that we wouldn’t just Never Forget that we would also Always Remember. People were already insisting that we’d put aside our differences and come together, and maybe the part that I’m most bittersweet and wistful about was that I really believed it. I’d turned 26 years old just a few days before the attacks, and I realize in retrospect that maybe that moment, as I eased from my mid-twenties to my late twenties, was the last time I’d be unabashedly optimistic about something, even amidst all the sorrow.

In 2006, After Five Years, Failure:

[O]ne of the strongest feelings I came away with on the day of the attacks was a feeling of some kind of hope. Being in New York that day really showed me the best that people can be. As much as it’s become cliché now, there’s simply no other way to describe a display that profound. It was truly a case of people showing their very best nature.
We seem to have let the hope of that day go, though.

In 2005, Four Years:

I saw people who hated New York City, or at least didn’t care very much about it, trying to act as if they were extremely invested in recovering from the attacks, or opining about the causes or effects of the attacks. And to me, my memory of the attacks and, especially, the days afterward had nothing to do with the geopolitics of the situation. They were about a real human tragedy, and about the people who were there and affected, and about everything but placing blame and pointing fingers. It felt thoughtless for everyone to offer their response in a framework that didn’t honor the people who were actually going through the event.

In 2004, Thinking Of You:

I don’t know if it’s distance, or just the passing of time, but I notice how muted the sorrow is. There’s a passivity, a lack of passion to the observances. I knew it would come, in the same way that a friend told me quite presciently that day back in 2001 that “this is all going to be political debates someday” and, well, someday’s already here.

In 2003, Two Years:

I spent a lot of time, too much time, resenting people who were visiting our city, and especially the site of the attacks, these past two years. I’ve been so protective, I didn’t want them to come and get their picture taken like it was Cinderella’s Castle or something. I’m trying really hard not to be so angry about that these days. I found that being angry kept me from doing the productive and important things that really mattered, and kept me from living a life that I know I’m lucky to have.

In 2002, I wrote On Being An American:

[I]n those first weeks, I thought a lot about what it is to be American. That a lot of people outside of New York City might not even recognize their own country if they came to visit. The America that was attacked a year ago was an America where people are as likely to have been born outside the borders of the U.S. as not. Where most of the residents speak another language in addition to English. Where the soundtrack is, yes, jazz and blues and rock and roll, but also hip hop and salsa and merengue. New York has always been where the first fine threads of new cultures work their way into the fabric of America, and the city the bore the brunt of those attacks last September reflected that ideal to its fullest.

In 2001, Thank You:

I am physically fine, as are all my family members and immediate friends. I’ve been watching the footage all morning, I can’t believe I watched the World Trade Center collapse…
I’ve been sitting here this whole morning, choking back tears… this is just too much, too big. I can see the smoke and ash from the street here. I have friends of friends who work there, I was just there myself the day before yesterday. I can’t process this all. I don’t want to.

12 Sep 18:26

2030 Barclay Street

by ChangingCity

The gradual infilling of the West End continues. Here’s a proposal designed by SHIFT Architecture with Henriquez Partners for a 10 storey 19 unit condo building on Barclay, near Stanley Park. If approved, it will replace a four storey strata titled hotel converted from residential in the early 1980s. The application notes that “all of the units in the 2,000 sf range and having 2 bedrooms and a den typically, with private outdoor spaces”.

 

12 Sep 18:26

Protecting Mozilla’s GitHub Repositories from Malicious Modification

by Hal Wine

At Mozilla, we’ve been working to ensure our repositories hosted on GitHub are protected from malicious modification. As the recent Gentoo incident demonstrated, such attacks are possible.

Mozilla’s original usage of GitHub was an alternative way to provide access to our source code. Similar to Gentoo, the “source of truth” repositories were maintained on our own infrastructure. While we still do utilize our own infrastructure for much of the Firefox browser code, Mozilla has many projects which exist only on GitHub. While some of those project are just experiments, others are used in production (e.g. Firefox Accounts). We need to protect such “sensitive repositories” against malicious modification, while also keeping the barrier to contribution as low as practical.

This describes the mitigations we have put in place to prevent shipping (or deploying) from a compromised repository. We are sharing both our findings and some tooling to support auditing. These add the protections with minimal disruption to common GitHub workflows.

The risk we are addressing here is the compromise of a GitHub user’s account, via mechanisms unique to GitHub. As the Gentoo and other incidents show, when a user account is compromised, any resource the user has permissions to can be affected.

Overview

GitHub is a wonderful ecosystem with many extensions, or “apps”, to make certain workflows easier. Apps obtain permission from a user to perform actions on their behalf. An app can ask for permissions including modifying or adding additional user credentials. GitHub makes these permission requests transparent, and requires the user to approve via the web interface, but not all users may be conversant with the implications of granting those permissions to an app. They also may not make the connection that approving such permissions for their personal repositories could grant the same for access to any repository across GitHub where they can make changes.

Excessive permissions can expose repositories with sensitive information to risks, without the repository admins being aware of those risks. The best a repository admin can do is detect a fraudulent modification after it has been pushed back to GitHub. Neither GitHub nor git can be configured to prevent or highlight this sort of malicious modification; external monitoring is required.

Implementation

The following are taken from our approach to addressing this concern, with Mozilla specifics removed. As much as possible, we borrow from the web’s best practices, used features of the GitHub platform, and tried to avoid adding friction to the daily developer workflows.

Organization recommendations:

  • 2FA must be required for all members and collaborators.
  • All users, or at least those with elevated permissions:
    • Should have contact methods (email, IM) given to the org owners or repo admins. (GitHub allows Users to hide their contact info for privacy.)
    • Should understand it is their responsibility to inform the org owners or repo admins if they ever suspect their account has been compromised. (E.g. laptop stolen)

Repository recommendations:

  • Sensitive repositories should only be hosted in an organization that follows the recommendations above.
  • Production branches should be identified and configured:
    • To not allow force pushes.
    • Only give commit privileges to a small set of users.
    • Enforce those restrictions on admins & owners as well.
    • Require all commits to be GPG signed, using keys known in advance.

Workflow recommendations:

  • Deployments, releases, and other audit-worthy events, should be marked with a signed tag from a GPG key known in advance.
  • Deployment and release criteria should include an audit of all signed commits and tags to ensure they are signed with the expected keys.

There are some costs to implementing these protections – especially those around the signing of commits. We have developed some internal tooling to help with auditing the configurations, and plan to add tools for auditing commits. Those tools are available in the mozilla-services/GitHub-Audit repository.

Image of README contents

Here’s an example of using the audit tools. First we obtain a local copy of the data we’ll need for the “octo_org” organization, and then we report on each repository:

$ ./get_branch_protections.py octo_org
2018-07-06 13:52:40,584 INFO: Running as ms_octo_cat
2018-07-06 13:52:40,854 INFO: Gathering branch protection data. (calls remaining 4992).
2018-07-06 13:52:41,117 INFO: Starting on org octo_org. (calls remaining 4992).
2018-07-06 13:52:59,116 INFO: Finished gathering branch protection data (calls remaining 4947).

Now with the data cached locally, we can run as many reports as we’d like. For example, we have written one report showing which of the above recommendations are being followed:

$ ./report_branch_status.py --header octo_org.db.json
name,protected,restricted,enforcement,signed,team_used
octo_org/react-starter,True,False,False,False,False
octo_org/node-starter,False,False,False,False,False

We can see that only “octo_org/react-starter” has enabled protection against force pushes on it’s production branch. The final output is in CSV format, for easy pasting into spreadsheets.

How you can help

We are still rolling out these recommendations across our teams, and learning as we go. If you think our Repository Security recommendations are appropriate for your situation, please help us make implementation easier. Add your experience to the Tips ‘n Tricks page, or open issues on our GitHub-Audit repository.

The post Protecting Mozilla’s GitHub Repositories from Malicious Modification appeared first on Mozilla Security Blog.

12 Sep 18:26

Photographing the Biggest, Oldest, and Rarest Trees on Earth

via Photographing the Biggest, Oldest, and Rarest Trees on Earth Photographer Beth...
12 Sep 17:48

Instagram is testing a video tagging feature

by Bradly Shankar
Instagram app on iOS

Instagram is currently testing a feature that allows users to tag one another in videos, according to a report from TechCrunch.

Previously, the social media giant only allowed users to be tagged in photos or stories.

Unlike in photos, where tagged profiles are overlaid on the image, users will be able to tap a button that brings up a list of all of the people tagged in the video.Currently, these videos don’t appear on a user’s profile, where tagged photos normally appear, although this functionality may come in the future.

Instagram confirmed to TechCrunch that video tagging is being tested among a “small percentage” of users. However, it’s unclear when the feature will be more widely rolled out.

“We’re always testing ways to improve the experience on Instagram and bring you closer to the people and things you love,” an Instagram spokesperson told TechCrunch. 

As noted in the report, the ability to tag profiles in videos may also pave the way for shoppable videos to be added in the future, just as Instagram has done with photos.

Originally introduced in March 2017 and later brought to Canada in March 2018, the shoppable photo feature allows businesses to tag products within a post to offer additional details like pricing and specifications.

Source: TechCrunch

The post Instagram is testing a video tagging feature appeared first on MobileSyrup.

12 Sep 17:48

Tesla now charges extra for every colour option besides default black

by Brad Bennett
Tesla Model 3 red and grey

Tesla always seems to be on the hunt for new ways to improve its production process, and now the company has decided to stop mass producing some colours to “simplify manufacturing.”

Elon Musk tweeted on September 11th that Tesla is moving two of seven colour options “off [the] menu.” The two colours will still be available via special request but consumers will need to pay more.

The two colours are ‘Obsidian Black and ‘Metallic Silver.’

Currently, on the Tesla’s Canada website, it costs an extra $2,000 CAD to order a Model 3 in Obsidian Black, though that’s still cheaper than the $2,600 CAD it costs to order a vehicle in the Red Multi-Coat option. At the moment, the only colour option that doesn’t cost extra is Solid Black.

The move makes sense for Tesla since it’s often trying a few new strategies to improve its sales and production numbers to sustain growth and keep its stockholders happy.

Source: CNBC

The post Tesla now charges extra for every colour option besides default black appeared first on MobileSyrup.

12 Sep 17:48

‘Da Vinci’ is Samsung’s Galaxy Note 10 codename: report

by Dean Daley

While Samsung only recently unveiled the Galaxy Note 9, The Bell, a South Korean publication, has already leaked the codename for the Galaxy Note 10: “Da Vinci”.

Da Vinci is an odd codename for a Note device considering the names Samsung has used in the past. The company codenamed the Note 9 ‘Crown‘ and the Note 8 ‘Great,’ neither of which are the names of a person.

The Bell’s report suggests that Samsung codenamed the phone after Leonardo Da Vinci, the famous Renaissance painter and inventor, to allude to improvements it plans to make the Note 10’s S Pen. However, codenames aren’t usually tied to any specific features, so this seems unlikely.

Additionally, the report quotes an industry source who claims that the phone will feature an Infinity Display and will not have a home button — an example of a device without a home button is the iPhone X.

Samsung’s Note 9 is now available in Canada. The phone doesn’t have many innovations compared to the Galaxy Note 8. However, with the all leaks related to the Galaxy S10 — in-display fingerprint scanner, 5G capable variants and possibly five cameras — the Note 10 is likely to impress.

Source: The Bell, The Investor, Via: Android Authority

The post ‘Da Vinci’ is Samsung’s Galaxy Note 10 codename: report appeared first on MobileSyrup.

12 Sep 17:48

Rogers to introduce ‘Ultra’ wireless rate plan on September 12th

by Sameer Chhabra

Toronto-based national carrier Rogers is set to introduce a new rate plan tier on September 12th, 2018.

Dubbed ‘Ultra,’ the new plan tier reduces upfront device costs by up to $250, but increases costs by $10 more per month when compared to select two-year Premium+ plans.

For example, a phone that currently costs $299 upfront on a $100/1GB two-year Premium+ plan, could cost $49 upfront on a $110/1GB two-year Ultra plan.

Rogers has yet to reveal the actual pricing for specific devices on the new Ultra plan, but the carrier said that subscribers can save up to $250 off the upfront cost of “select iconic devices.”

The new tier will be available in Ontario, Quebec, British Columbia and Alberta — incidentally, the four provinces where Freedom Mobile currently operates — and is expected to arrive in Atlantic Canada and the Prairies sometime soon.

“We know that many of our customers want to get their hands on the latest smartphones, but sometimes the upfront cost is a barrier for them,” said Brent Johnston, president of wireless at Rogers Communications.

“Our new Ultra tier gives customers more choice and flexibility so they can get the iconic devices they want for as low as $0 upfront.”

News of the new rate plan comes almost two months after Rogers confirmed to MobileSyrup that it planned on launching a new ‘Ultra Tab’ pricing structure in Quebec.

The Ultra Tab topped the carrier’s Premium+ Tab as the highest-priced plan tier.

Rogers is currently Canada’s largest wireless service provider, with approximately 10,626,000 subscribers as of the carriers Q2 2018 financial quarter.

Update 11/09/2018 12:25pm ET: Story updated to reflect that Ultra tier pricing has yet to be confirmed.

The post Rogers to introduce ‘Ultra’ wireless rate plan on September 12th appeared first on MobileSyrup.

12 Sep 17:47

Google Photos now integrates with third-party apps

by Brad Bennett

Google has created the Google Photos Partner Program to let developers utilize the power of its Photos app inside of their apps or services.

The program lets developers use the Photos API to integrate certain features into their app or website. These include features like Photos’ powerful search tool and cloud sync functionality.

When developers take advantage of the new API, they’ll get to store photos on Google’s servers, which should save developers some time.

All developers have access to the API without having to join the partner program. However, if their app exceeds the general availability quota (10,000 requests per day) or is using Photos for commercial goals, then Google recommends expressing interest in the partner program.

Partners get an increased quota, more support, the latest features and an official badge to use when marketing their apps. Google has more information on the program on its website.

Source: Google Via: Android Police

The post Google Photos now integrates with third-party apps appeared first on MobileSyrup.

11 Sep 05:46

How to Upgrade Your iPhone

by Nick Guy
How to Upgrade Your iPhone

Over the past few years, the default method of buying an iPhone has switched from carrier-subsidized two-year contracts to long-term leases, typically with the option to upgrade after about one year. This means most people are eligible to swap their old iPhone for the latest version every year. The caveats are that your current phone must be in good working order and—with most plans—at least 50 percent paid off.

Apple’s iPhone Upgrade Program makes the most sense for most people who want a new phone every year and also want the protection of Apple’s insurance program AppleCare+, which is included in the monthly cost. But most US carriers have plans that are on a par with Apple’s; we think T-Mobile’s Jump On Demand is a little more flexible and AT&T’s Next Up is a little worse.

If you’re happy with your existing handset, you can keep making payments until you own it outright. But if you are ready to upgrade, we wanted to make sure you have all the information you need to do so.

(The details of these leasing programs can change at any time, so we suggest consulting your program’s website prior to acting, just in case. You may also have to pay taxes and other fees; in some states, you must pay the entire sales tax up front, even if you’re spreading payments out over one or two years.)

Apple iPhone Upgrade Program

If you’re already part of Apple’s iPhone Upgrade Program and want to upgrade to a new phone, you must be at least six months into your plan and have made the equivalent of at least 12 payments. This means that if you’re eight months into your payment contract, for example, you must pay four additional months to be eligible for an upgrade.

A screenshot of the Apple Upgrade Program's upgrade page for an unidentified iPhone XR
Apple’s iPhone Upgrade Program gives you the option to accelerate payments to qualify for an early trade-in, even if you haven’t made all 12 monthly payments.

You can upgrade online, using the Apple Store iOS app, or in person at an Apple Store. If you’re upgrading in a store, come prepared with a valid US credit card, your Social Security number (for a credit check), and a photo ID (Apple’s site says you need two forms of ID, but a credit card with your name on it counts as one, according to an Apple employee we spoke to).

Apple also requires that the phone you turn in is in “good physical and operational condition.” If yours isn’t for any reason, you can take advantage of the AppleCare+ plan that’s included in the Upgrade Program: You simply pay the $30 deductible for screen damage or $100 for any other damage when you turn in the phone.

AT&T

AT&T offers an upgrade program in addition to its installment plan, which doesn’t include upgrade options. If you’re on the basic 30-month installment plan, you can opt to add AT&T Next Up—which, unlike all other carriers’ upgrade plans, costs an extra $5 per month that does not contribute to the carried balance on the phone—allowing you to upgrade after you’ve paid off 50 percent of the phone’s cost. This extra charge effectively places a $75 premium on your ability to upgrade, assuming you take 15 months to pay off 50 percent of the cost of the phone and take the upgrade every time. The phone you turn in must be “fully functional [and in] good physical condition.” You can mail your old phone, or turn it in at an AT&T store.

Sprint

Sprint’s iPhone Forever plan is an 18-month lease that lets you upgrade eligible phones after a year (or after paying the equivalent of 12 monthly payments). The iPhone has to be in good and functional condition. Sprint will send you packaging to mail your phone in; a Sprint representative told us you can also turn it in when upgrading in a Sprint store.

T-Mobile

T-Mobile has consolidated its three different upgrade programs into one. Jump on Demand allows more-frequent upgrades than any other program, with fewer constraints. You can upgrade your phone anytime, up to once a month, as long as you’re up to date on your payments—if, for example, you got an iPhone XR off-cycle in August 2019, right before the new models were announced, and still want to upgrade in October, you can turn in the XR just as easily as if you had leased it almost a year earlier. This program is limited in scope (the fine print says it’s limited to “flagship devices ... and other select affordable smartphones”), but does include the iPhone.

If you’re on the old Jump or Jump Plus programs and want to upgrade to the Jump on Demand program, the trade-in value of your current device will be applied to your installment plan balance, and once you pay off any remaining balance, you’ll be allowed to upgrade within its limitations.

You can turn in your phone at a T-Mobile store, or mail it in.

Verizon

Verizon offers an Annual Upgrade Program for iPhone that allows upgrades to eligible phones after the customer has been leasing for at least 30 days and has paid off at least half of the lease agreement. The old phone must be in “good working condition,” and you need to ship it back to Verizon within 14 days of receiving the new device. A customer service representative told us that mailing the old iPhone is the only way to return it to Verizon.

11 Sep 05:46

The Growing Popularity of Jupyter Notebooks…

by Tony Hirst

It’s now five years since we first started exploring the use of Jupyter notebooks — then known as IPython notebooks — in the OU for the course that became (and still is) TM351 Data management and analysis.

At the time, the notebooks were evolving fast (they still are…) but knowing the length of time it takes to produce a course, and the compelling nature of the notebooks, and the traction they already seemed to have, it felt like a reasonably safe technology to go with.

Since then, the Jupyter project has started to rack up some impressive statistics. Using Google BigQuery on public datasets, we can find how many times the Jupyter Python package is installed from PyPi, the centralised repository for Python package distribution, each month by querying the the-psf:pypi.downloads dataset (if you don’t like the code in this post, how else do you expect me to demonstrably source the supporting evidence…?!):

#https://langui.sh/2016/12/09/data-driven-decisions/
SELECT
  STRFTIME_UTC_USEC(timestamp, "%Y-%m") AS yyyymm,
  COUNT(*) as download_count
FROM
  TABLE_DATE_RANGE(
    [the-psf:pypi.downloads],
    DATE_ADD(CURRENT_TIMESTAMP(), -1, "year"),
    CURRENT_TIMESTAMP()
  )

WHERE file.project="jupyter"
GROUP BY yyyymm
ORDER BY yyyymm DESC
LIMIT 12

(Our other long term bet for TM351 was on the pandas Python package, and that has also gone from strength to strength…)

Google BigQuery datasets also include a Stack Overflow dataset (Stack Overflow is a go to technical question-and-answer site for developers), so something like the following crappy query will count the jupyter-notebook tagged questions appearing each year:

SELECT tags, COUNT(*) c,  year
FROM (
 SELECT SPLIT(tags, '|') tags, YEAR(creation_date) year
  FROM [bigquery-public-data:stackoverflow.posts_questions] a
  WHERE YEAR(creation_date) >= 2014 AND tags LIKE '%jupyter-notebook%'
)
WHERE tags='jupyter-notebook'
GROUP BY year, tags
ORDER BY year DESC

I had thought we might be able to use BigQuery to query the number of notebooks on Github (a site widely used by developers for managing code repositories and, increasingly, and educators for managing course notes/resources), but it seems that the Github public data tables [(bigquery-public-data:github_repos)] only represent a sample of 10% or so of public projects?

FWIW, here are a couple of sample queries on that dataset anyway. First, a count of projects identified as Jupyter Notebook projects:

SELECT COUNT(*)
FROM [bigquery-public-data:github_repos.languages]
WHERE language.name = "Jupyter Notebook"

And secondly, a count of .ipynb notebooks:

SELECT COUNT(*)
FROM [bigquery-public-data:github_repos.files]
#filter on files with a .ipynb suffix
WHERE RIGHT(path,6) = ".ipynb"

We can also look to see what the most popular Python packages imported into the notebooks are using a recipe I found here

numpy, matplotlib and pandas, then, perhaps not surprisingly… Here’s the (cribbed) code for that query:

#https://dev.to/walker/using-googles-bigquery-to-better-understand-the-python-ecosystem

#The query finds line breaks and then tries to parse import statements
SELECT
  CASE WHEN package LIKE '%\\n",' THEN LEFT(package, LENGTH(package) - 4)
    ELSE package END as package, n
FROM (
  SELECT REGEXP_EXTRACT( line, r'(?:\S+\s+)(\S+)' ) as package, count(*) as n
  FROM (
    SELECT SPLIT(content, '\n \"') as line
    FROM (SELECT * FROM [bigquery-public-data:github_repos.contents]
      WHERE id IN (
        SELECT id FROM [bigquery-public-data:github_repos.files]
         WHERE RIGHT(path, 6) = '.ipynb'))
       HAVING LEFT(line, 7) = 'import ' OR LEFT(line, 5) = 'from ')
  GROUP BY package
  ORDER BY n DESC)
LIMIT 10;

(I guess a variant of the above could be used to find out what magics are most commonly loaded into notebooks?)

That said, Github also seem to expose a count of files directly, as described in parente/nbestimate, from where the following estimates of growth in the the numbers of Jupyter notebook / .ipynb files on Github are taken:

The number returned by making the following request is approximate – maybe we get the exact count if we make an authenticated request?

https://github.com/search/count?q=extension%3Aipynb+nbformat_minor&amp;ref=searchresults&amp;type=Code

On Docker hub, where various flavours of official notebook container are hosted, there’ve been over a million pulls of the datascience notebook:

jupyter_-_Docker_Hub.png

Searching Docker hub for jupyter notebook also identifies over 5000 notebook related Docker container images at the current count, of which over 1500 are automatically built from Github repos.

Mentions of Jupyter notebooks are also starting to appear on ITJobswatch, a site that tracks IT and programming job ads in the UK:

By the by, if  you fancy exploring other sorts of queries, this simple construction will let you run a Google web search to look for .ipynb files that mention the word course or module on ac.uk websites…

filetype:ipynb site:ac.uk (course OR module)

Anyway, in the same way that it can take many years to get anything flying regularly on NASA space flights, OU courses take a couple of years to put together, and innovations often have to be proved to work for a couple of course presentations in another course before a second course will take them on; so it’s only now that we’re starting to see an uptick of interest in using Jupyter notebooks in other courses… but that interest is growing, and it’s looking like there’s a flurry of courses about to start production that are likely to be using notebooks.

We may have fallen a little bit behind places like UC Berkeley, where 50% of undergrads now take a core, Jupyter notebook powered, datascience course, with subject specifc bolt-on mini-modules, and notebooks now provide part of the university core infrastructure:

…but even so, there could still be exciting times ahead…:-)

Even more exciting if we could get the library to start championing it as a general resource…

n_campuJupyterhub

11 Sep 05:46

Can Cats Read Minds?

Ali Boyle, iAi News, Sept 24, 2018


Icon

I've thought a lot about the mental states. In the current case, we're not asking whether cats have ESP. Rather, if a cat does something, is it because the cat thinks we're thinking something, or is it simply reacting to behaviour. This article raises what is called 'the logical problem', because we can't change the evidence for our thinking something without also changing our behaviour. But it becomes odd and hard to explain a cat's actions without assuming they know what we're thinking. This article recounts the well-known instance of a cat sneaking up on you, but freezing when it thinks you're looking. OK, it could be responding to behaviour. But what about when the cat tries to deceive you, feigning disinterest when you have some food or something? But on the other hand - surely cats aren't capable of complex representational states involving human mental contents. Which to me raises the question - why do we assume humans are 'reading minds'?

Web: [Direct Link] [This Post]
11 Sep 05:46

Sincerity in the Insanity

by Gordon Price

In 2015, I gave a real downer of a lecture in Auckland.  Mainly because I predicted that those who were in denial about climate change would not be adverse to making it worse.  Not just continuing as we’ve been doing, with token efforts on the side to constrain carbon.  No, to make climate change happen faster – because as a test of sincerity, it would be a demonstration that their denial is founded in belief.  ‘Climate change isn’t consequential,’ so let’s double down.

That’s what’s happening.

 

11 Sep 05:45

Sonos plunges after first earnings report as public company

by Volker Weber

Sketch

In the letter Spence said the company wants to accelerate growth of sales directly to customers, as opposed to sales through third parties. Selling directly results in a profit margin "tends to be about 10 points better" that indirect sales, Spence said. About 12 percent of Sonos' sales is direct -- through the Sonos website, the company's app and its customer relationship management system -- since the beginning of the year, he said.

Umsatz ist YoY gefallen. Und jetzt will Sonos auch noch die Partner abziehen. Nicht gut. Ich schlage vor, weiterhin bei ueberall-musik.de zu kaufen.

More >

11 Sep 05:43

SFU City Conversations: Building the Cycling City – Sep 20

by Gordon Price
mkalus shared this story from Price Tags.

With 22.5 million bicycles for a population of 18 million, the Netherlands is undoubtedly the world’s top cycling nation. However, there remains an erroneous belief that – while the Dutch can provide encouragement – their methods are unrepeatable, and their results unattainable.

Can the country that has spent decades building comfortable cycling infrastructure provide a blueprint for Metro Vancouver?

To explore the issue, we’ve invited Chris and Melissa Bruntlett, founders of Modacity and authors of Building the Cycling City: The Dutch Blueprint for Urban Vitality. Joining them will be Councillor Linda Buchanan from the City of North Vancouver and Kati Tamashiro, Section Head for Active Transportation with the City of Vancouver.

Thursday, September 20
12:30 – 1:30 pm
Room 7000, SFU Vancouver at Harbour Centre

Register on Eventbrite

11 Sep 05:43

DesignStudio has given the Evernote elephant a makeover

by Josh Baines
mkalus shared this story from It's Nice That.

Evernote-designstudio-rebranding-graphic-design-itsnicethat-03

Change is afoot at note-taking specialists Evernote, and even its pet elephant Mads is feeling the effects. London-based digital agency DesignStudio has partnered with the app to present a rebrand that reflects that fact that the way people use the service has changed a decade on since its launch.

Read more

11 Sep 05:40

Google Go hits 10 million installs, could indicate success of Android Go

by Jonathan Lamont
Google Go app

Google Go, the search giant’s lighter Google app for Android Go, has passed 10 million installations in the Play Store.

Considering Google Go comes preinstalled on Android Go and that the company hasn’t released official sales information regarding the platform, Google Go could indicate the success of Android Go.

That being said, it doesn’t mean there are over 10 million Android Go devices out in the wild. That number is more of an upper ceiling.

Plenty of people could be using the app on regular Android devices. This could potentially throw the install number on the Play Store out of whack.

Furthermore, considering Android handset sales have topped 626 million units so far in 2018, 10 million Android Go isn’t a lot.

Ultimately, it’s not clear what Google expects from the Android Go line — 10 million isn’t a small number regardless.

Hopefully, this number continues to grow as more low-cost, good Android Go handsets become more available.

Source: Android Police

The post Google Go hits 10 million installs, could indicate success of Android Go appeared first on MobileSyrup.

11 Sep 05:40

An updated version of OnePlus’ Wireless Bullet headphones could be coming

by Brad Bennett
OnePlus Bullets

OnePlus is gearing up to announce its next flagship phone, the OnePlus 6T, and it seems like a new version of the company’s wireless Bullet headphones are on the way too.

An updated version seems to be passing through the FCC, with the label on product calling it ‘OnePlus Bullets Wireless.’ This is the same name as the last pair of wireless bullets, but this time the serial number is ‘BT32B’ instead of ‘BT31B.’

From what has leaked so far it seems like the design hasn’t changed, which means this new version of the earbuds are likely still neckbuds like Apple’s BeatsX earbuds.

Some users on Reddit seem to be hoping for a physical power button. Currently, the wireless Bullets turn off and on when users connect the left and right earphones using a magnet. Some have complained that the two earphones often come apart and drain the battery.

Overall MobileSyrup’s Igor Bonifacic thought highly of OnePlus’ original Bullet earphones, so they only stand to get better if OnePlus can maintain their decent battery life and sound quality.

Source: FCC Via: Droid Life

The post An updated version of OnePlus’ Wireless Bullet headphones could be coming appeared first on MobileSyrup.